Russian government hackers penetrated DNC, stole opposition research on Trump(washingtonpost.com)
washingtonpost.com
Russian government hackers penetrated DNC, stole opposition research on Trump
https://www.washingtonpost.com/world/national-security/russian-government-hackers-penetrated-dnc-stole-opposition-research-on-trump/2016/06/14/cf006cb4-316e-11e6-8ff7-7b6c1998b7a0_story.html
9 comments
Is blase indifference how we respond to national level security breaches now?
If this was somebody's health records, the organization responsible for the disclosure would be under serious investigation (HIPPA), and throwing down retainers to every law firm in town.
Thomas, is it your opinion that those responsible for securing this data shouldn't be held responsible?
If this was somebody's health records, the organization responsible for the disclosure would be under serious investigation (HIPPA), and throwing down retainers to every law firm in town.
Thomas, is it your opinion that those responsible for securing this data shouldn't be held responsible?
I think it's awfully silly to pretend that campaign IT organizations should be falling on their swords when the largest, most-talented, best-funded software security organizations in the industry do only a marginally better job when evaluated by outcome.
But, more importantly: I meant what I said. The only interesting thing about this story is that whoever hacked the DNC got attributed. You think the GOP isn't owned up?
But, more importantly: I meant what I said. The only interesting thing about this story is that whoever hacked the DNC got attributed. You think the GOP isn't owned up?
Now? The only thing opensource advocates, hobbyist developers, large tech companies, the "security" industry and the government have been able to consistently agree on for the last 15 years is that there should be little enforcement of quality standards, in contrast with essentially every other industry.
[deleted]
> What, you think the people that build the software and IT environments for campaigns ... are the creme de la creme of software security talent?
No, but I've always considered the competence of the IT people to likely fluctuate wildly from person to person, as I assumed many were politically motivated and donating at least some of their expected compensation level. I think the bigger problem would be in an organization with lots of volunteers, at least at the lower levels, and that gets at least partially rebuilt every few years, operational security is probably very hard to enforce for multiple reasons.
No, but I've always considered the competence of the IT people to likely fluctuate wildly from person to person, as I assumed many were politically motivated and donating at least some of their expected compensation level. I think the bigger problem would be in an organization with lots of volunteers, at least at the lower levels, and that gets at least partially rebuilt every few years, operational security is probably very hard to enforce for multiple reasons.
Who would you say has the creme de la creme of software security talent, and can you with a straight face say that they have not been compromised at some level?
Security is hard, but I wonder if it's P VS NP?
Security is hard, but I wonder if it's P VS NP?
Google, Facebook, Apple, Microsoft. And, no.
No mention of Intel, IOActive, Matasano, Rapid7, FireEye, CheckPoint, Trend Micro, Kaspersky Labs, UCF, JHU, APL, MITRE, and of course, NSA?
Sure, the ones you mentioned have the biggest paychecks. But they won't give you indemnity and extended resources to find weaknesses in critical infrastructure. Some people like breaking bigger toys.
Sure, the ones you mentioned have the biggest paychecks. But they won't give you indemnity and extended resources to find weaknesses in critical infrastructure. Some people like breaking bigger toys.
Just the tech giants have the best security people? How about large banks, hedgefunds and other financial services, security contractors/private military and governments?
We have large banks blocking pasting in password fields [1], and suggesting users not use password managers.
I'd actually say security research firms have pretty high quality security people, however, and not just the tech giants.
1. http://www.iphoneincanada.ca/news/1password-open-letter-bank...
I'd actually say security research firms have pretty high quality security people, however, and not just the tech giants.
1. http://www.iphoneincanada.ca/news/1password-open-letter-bank...
This doesn't mean all financial institutions are bad at security. Some are cutting edge and hire some of the best.
Everyone you know in infosec is also probably not highly motivated to work around politics. Those that do will be trying to work either directly for a campaign, or the DNC, or companies like NGP VAN, the largest tech contractor for Democratic campaigns. Those people are motivated to do their jobs well so their candidate/party will win.
That said, the CIA & NSA probably owned them all up well before, and whomever has them in their pocket will have an upper hand as well. It's not like blackhats and foreign states are the only interested parties.
That said, the CIA & NSA probably owned them all up well before, and whomever has them in their pocket will have an upper hand as well. It's not like blackhats and foreign states are the only interested parties.
The interesting implication is that campaign IT has to have protection, similar to the way that the candidates themselves get SS protection.
Further, that private email servers for public function should never be again. The damage wasn't that a classified email was read; it was that any information was read before it was deemed safe for the rest of the world to read.
It's astounding to me that NSA and DHS hasn't been all over this for years. Although I suppose if all those systems were secure it would be harder for NSA to spy on their owners.
Further, that private email servers for public function should never be again. The damage wasn't that a classified email was read; it was that any information was read before it was deemed safe for the rest of the world to read.
It's astounding to me that NSA and DHS hasn't been all over this for years. Although I suppose if all those systems were secure it would be harder for NSA to spy on their owners.
Watergate comes to mind. That was in 1972.
I'm really not liking the cream comparison for a couple reasons. One is that I like cream.
I'm really not liking the cream comparison for a couple reasons. One is that I like cream.
State sponsored attackers had "thoroughly compromised" access for over a year and were "expelled" over a weekend? Not bloody likely.
But some people still hope for online voting. This is a preview of how other countries could decide your elections if you switch to online voting now (and that's assuming your own intelligence agencies don't compromise it first to support whoever is more favorable to them and to an expansion of their powers).
Chinese state actors even get involved in municipal council politics in Canada http://www.theglobeandmail.com/news/politics/government-infi...
Insecure online voting would be icing on the cake
Insecure online voting would be icing on the cake
Bingo.
If you can't be bothered to vote in person, which I will argue needs to have fewer obstacles in its' own right, then I don't care about your vote.
If you can't be bothered to vote in person, which I will argue needs to have fewer obstacles in its' own right, then I don't care about your vote.
This is not about online voting. Though I'm in agreement that it's certainly not going to be securely implemented in the near future, especially given the way government (state and federal) IT contracts are generally handled (read: poorly).
E-voting machines are already generally internet accessible though right?
There was a time when if you wanted to transport yourself or your goods across say Europe or China, you needed to hire mercenaries and they would protect your business from bandits on the way.
At various times (Mongols, US Navy vs pirates etc) governments stepped in and provided that protection (for a lesser price) and trade grew.
I'm not too sure how governments can provide protection in the online realm. Perhaps by providing minimal standards of security? (I know the standards exists but enforcing them?)
However, now my iPhone is FBI-resistant, and public keys are fairly easy to share, it seems that secure peer to peer communication is feasible.
So the shape of a more secure, bandit free internet is clearer - hardened mobile devices, and much much stricter standards that are enforced, but it seems an odd new world.
At various times (Mongols, US Navy vs pirates etc) governments stepped in and provided that protection (for a lesser price) and trade grew.
I'm not too sure how governments can provide protection in the online realm. Perhaps by providing minimal standards of security? (I know the standards exists but enforcing them?)
However, now my iPhone is FBI-resistant, and public keys are fairly easy to share, it seems that secure peer to peer communication is feasible.
So the shape of a more secure, bandit free internet is clearer - hardened mobile devices, and much much stricter standards that are enforced, but it seems an odd new world.
Why wouldn't the intruders change anything while they were there?
For example, filtering out some important emails, with a goal of hamstringing the organization.
Also... The older I get, the more I realize that adults are just kids with very fancy tree houses. MY treehouse doesn't have rats. Get your leaders from here, not from there.
For example, filtering out some important emails, with a goal of hamstringing the organization.
Also... The older I get, the more I realize that adults are just kids with very fancy tree houses. MY treehouse doesn't have rats. Get your leaders from here, not from there.
Very little technical information. Still interesting article in its own right.
Some more technical information is available on CrowdStrike's blog: http://www.crowdstrike.com/blog/bears-midst-intrusion-democr...
I would say more than usual.
We have the info about how long were they inside of the network, we have some basic idea about how they are discovered to be connected to Russia (basically groups were previously linked to Russia, and now they were probably discovered by analyzing the code style and/or by re-using some of the code), we got to know how the incident response went, we discovered that they used 0 days targeting Windows, that they masked their traffic as legit Windows services, that they have created some kind of pattern analyzing tool that analyzes the code they got on every machine so they could detect if the attackers try breaching into the system again...
I'd say that this is a pretty hefty amount of information we got from a single article when it's not really a post mortem by the company, but an article on Washington Post.
We have the info about how long were they inside of the network, we have some basic idea about how they are discovered to be connected to Russia (basically groups were previously linked to Russia, and now they were probably discovered by analyzing the code style and/or by re-using some of the code), we got to know how the incident response went, we discovered that they used 0 days targeting Windows, that they masked their traffic as legit Windows services, that they have created some kind of pattern analyzing tool that analyzes the code they got on every machine so they could detect if the attackers try breaching into the system again...
I'd say that this is a pretty hefty amount of information we got from a single article when it's not really a post mortem by the company, but an article on Washington Post.
“It’s the job of every foreign intelligence service to collect intelligence against their adversaries,...”
Hah. Translation: We've a firm foothold in their systems as well.
Putin is an autocrat, what equivalent is there to the DNC for him?
I think democracies are more at risk at this kind of thing because they have real elections and the data mined during elections is important. Its managed by a non-profit political party and as such usually has lax security.
I think democracies are more at risk at this kind of thing because they have real elections and the data mined during elections is important. Its managed by a non-profit political party and as such usually has lax security.
Yeah, but the problem with their systems is, it's all written in chinese. Our systems store information in english, which is a much easier language to read. So they have a natural advantage there...
What does it look like when a Russian downloads these files? Is it PDFs? Text files? What do they see?
ck2(3)
Is there anyone here who really believes that every major campaign organization since, say, 2004 hasn't been completely owned up? What, you think the people that build the software and IT environments for campaigns --- sites that by design have millions of users with persistent accounts, and thousands of staff members at varying levels of privilege --- are the creme de la creme of software security talent?
Because, sure, I mean, everyone I know in software security and pentesting tells me "my first career choice is to go work in IT for the DNC and the GOP", but somehow along the way Google manages after a mighty struggle to outbid the 70k/year cost-center IT organizations offer for security talent.
If there was any interesting "oppo research" on McCain in the DNC servers during the '08 election, I will bet all the money in my pocket versus all the money in yours that the Chinese read all of it long before everyone on the official CC list did.