Hackers acting in Turkey's interests believed to be behind recent cyberattacks
reuters.com
reuters.com
All of this makes a convincing story for media and laymen, but surely a competent hacker could pull of a hack and trivially modify the evidence to implicate any state actor/group who's modus operandi are known in hacking circles, no?
Which, incidentally, is why I had issue with the certainty with which croudstrike, for example, pointed to Russia over the DNC hack. Deliberately engineering your attack to mimic one from another group is an excellent way to keep people off your trail...and these are hackers we're talking about, after all.
But guess what, they're human and they fail, sometimes, not always.
Attribution becomes a playable game once you're a nation state, thanks to many "unfair advantages".
... In the end, many thing gets known.
In for a penny, in for a pound?
In any case, the fact that "anti vaxxers" use certain lines of questioning doesn't mean that the truth seeking methods are themselves suspect. Some people are pessimists, and rightly so; isn't that what hacking is all about?
The specialty here isn't software, really. It's intelligence. That's a very different field and knowing something generally about how computers work might not translate into as much relevant expertise as one could hope for.
I know my expertise in software security doesn't equip me to do this kind of intelligence analysis. IMO, that doesn't leave me with a lot of standing to comment substantively on many - even most - aspects of such analysis.
There's more to it than that, and often attribution is the result of the "bigger picture" of multiple clues, rather than a single smoking gun. Group operations develop patterns over time that are much greater than just a timestamp somewhere. Also, identifying a 0-day exploit somewhere often allows you to discover previous deployments of the same exploit, which have their own blast radius of evidence, contributing to these patterns that are identified over time.
>but surely a competent hacker could pull of a hack and trivially modify the evidence to implicate any nation/state who's modus operandi are known in hacking circles, no?
>Deliberately engineering your attack to mimic one from another group is an excellent way to keep people off your trail...
Yes, misdirection is the name of the game here, all bets are off and nothing is off limits. But covering your tracks leaves tracks of its own, and again, even when an attacker thinks all their bases are covered, they will never be sure there wasn't something somewhere they left behind that points back to them.
> and these are hackers we're talking about, after all.
Who do you think "hacker-hunters" are, if not hackers themselves?
1. How much evidence do we have?
2. How hard would it be for the hackers fake this evidence?
3. Are there any signs of forgeries? For instance logs that don't agree, file system artifacts, etc...
4. What were the capabilities of the attacker?
The longer a hack goes on and the larger its scale the harder it gets to forge 100% of the evidence.
>All of this makes a convincing story for media and laymen, but surely a competent hacker could pull of a hack and trivially modify the evidence to implicate any nation/state who's modus operandi are known in hacking circles, no?
I would say no, doing that is very difficult and is not trivial to do. All cases I've read up on, such as stuxnet, flame, APT-1 etc..., had clues as to the origin of the malware and such clues were left in the malware accidentally.
It's interesting - it's people who know a little bit who are doubtful about attribution, while those who actually know this understand it's possible to be pretty confident in many cases. It's hard to tell in this case, but the Crowdstrike report gives a lot of evidence which would persuade most in the field.
Generally speaking the best form of evidence is unique binaries which have been used in other attacks. Then you cluster attacks based on this information and other signatures. It's pretty hard to fake all of the required signatures at once, and most of the time a group doesn't really care.
It's much more robust than you seem to think - spoofing it occasionally is viable for a once-off attack, but doing the spoofing usually burns your access and methods so it's really expensive. It's not the kind of thing one burns on something like this attack or the DNC hack.
The DNC hack is a good example really - they had no idea how effective the misinformation campaign would be at the time, so why would they complicate it by trying to make it misattributable.
The attribution was already solid without that, but that’s icing on the cake.
Another glaring hole in Wifi is that there's no open + encrypted option. Your options are basically open with no encryption at all, personal mode (shared key for authentication and encryption), or enterprise mode (username + password, certificate-based, or similar).
The Wifi authentication standards should really be modernized to address these issues.
Anyone know which TLD orgs were hacked?
(1) Yesterday I noticed Wikipedia was way slower than normal. Article pages took ~30 seconds to load sometimes. (Down Detector agrees this: https://downdetector.com/status/wikipedia/)
(2) Yesterday, Hacker News had a headline Wikipedia was accessible in Turkey for the first time in years. (See https://news.ycombinator.com/item?id=22153304) Some people in that thread also noticed the coincidence between this and #1.
(3) Now this story about cyberattacks from (or on behalf of) Turkey.
I don't understand what the original post is implying then.
These aren't denial of service attacks, so what is the connection between Wikipedia being slow and some attacks that started in 2018 and are continuing now?
It looks like the new information here is that intelligence officers are confident enough to link the group to Turkey. Previously FireEye thought it was an Iranian group.
[1] https://www.zdnet.com/article/hackers-breached-greeces-top-l...
[2] https://techcrunch.com/2019/04/17/sea-turtle-talos-dns-hijac...
[3] https://blog.talosintelligence.com/2018/11/dnspionage-campai...
[4] https://www.fireeye.com/blog/threat-research/2019/01/global-...
My money is on this being similar to the leaks of tapes where a bunch of high ranking Turkish military & members of the administration were discussing false-flag attacks from Syria to have a reason to invade, basically the US feeling they have exhausted their diplomatic channels to Ankara and dropping pieces of intel into the wild to get Turkey to stop what they are doing.
The most simple explanation is usually true, so I think a security firm like NCC group ( GCHQ still holds a stake in them ) is creating waves for business.
Still very much possible that it's FUD/PR, there's likely information, misinformation, PR and news hyping in any such report, with degrees of each varying.
Disclaimer: I'm a Turkish citizen. I don't support what our government have been doing since 2006 except for some small stuff about healthcare and such. I could never vote for the winning party since I was given the right to vote.
But more likely is a regime spewing conspiracy theories so the people can no longer tell truth from fiction.
The last disastrous piece on the alleged hack of firmware at AWS and Apple by the Chinese was built on anonymous sources as well and the cyberhacking article was not retracted or apologized by Bloomberg.
https://www.bloomberg.com/news/features/2018-10-04/the-big-h...
Time will not be forgiving to the authors of this article.
Maybe Reuters has article quotas on cyberattacks per month and it’s close to the end of the month and they need to fill it somehow. It’s the journalistic equivalent of being pulled over by cops for no reason towards the end of the month so they can issue a ticket and fulfill their quota.
And my favorite part is Turkish interests. Is that a couple of script kiddies who speak Turkish sitting in a basement in their pjs taking a break from Fortnite or PUBG?
This article makes Judith Miller look like a real journalist like Walter Cronkite. Judith Miller of NY Times wrote stories based on multiple western anonymous and credible sources covering WMD in Iraq.
>According to two British officials and one U.S. official, the activity bears the hallmarks of a state-backed cyber espionage operation conducted to advance Turkish interests.
So the evidence is that it's a state sponsored attack done to pursue Turkish interests. You can choose not to believe it, but that's what western experts are saying.
Which public internet records?
So acting basically like a pirate and threating each day with war. Let me give you a few examples and you can verify them later any way you wish.
In Cyprus the sent -not one but two- drilling ships and research vessels to search for oil, with the escort of Turkish Navy of course. They failed to find gas in one location and are moving to the next. To add insult to the injury they even say they will share what the find, like a thief saying he will sell your stuff and share with you the money...
In Greece were I live, there is a lot of up-heat with the recently signed Turkish-Lybian moratorium which basically ignores the Greek island of Crete (as well others smaller ones) and declares EEZ with Lybia, which they call "neighbours" (look at a map please), at the same time ignoring the rights of Greece, Cyprus, and Israel.
Also search for the clean water crisis in Iraq, which Turkish government is ...also to be blamed. Basically they build dams cutting Euphrates river flow and DENYING their neighbor's RIGHT for clean water, violating other International agreements.
And doing a DDOS attack is quite trivial and any script kiddie could launch one from their computer or if they are slightly more adept from other peoples computers.
Turkey in fact is one of the most backward countries in terms of cybersecurity (and cyberattacks).
Turkey was just attacked recently with DDOS attacks and whole countries Internet came to a standstill. Did the anonymous sources have any thoughts on that?
Just look at Shodan to see how vulnerable and backward Turkey is in cybersecurity matters:
> The weakest sources are those whose names we cannot publish. Reuters uses anonymous sources when we believe they are providing accurate, reliable and newsworthy information that we could not obtain any other way. We should not use anonymous sources when sources we can name are readily available for the same information.
> Unnamed sources must have direct knowledge of the information they are giving us, or must represent an authority with direct knowledge. Remember that reliability declines the further away the source is from the event, and tougher questions must asked by reporters and supervisors on the validity of such information.
http://handbook.reuters.com/?title=The_Essentials_of_Reuters...