3 ms·
> the US government accuses Russia of hacking the DNC, either because they have some kind of proof (unlikely) "two competing cybersecurity companies, Mandiant
by joshmaker 10y ago
> the US government accuses Russia of hacking the DNC, either because they have some kind of proof (unlikely)
"two competing cybersecurity companies, Mandiant (part of FireEye) and Fidelis, confirmed CrowdStrike’s initial findings that Russian intelligence indeed hacked the DNC. The forensic evidence that links network breaches to known groups is solid... etc etc"
http://motherboard.vice.com/read/all-signs-point-to-russia-being-behind-the-dnc-hack http://motherboard.vice.com/read/all-signs-point-to-russia-b...
- mtgx 10y agoAttribution is hard. The NSA likely never hacks someone's systems from US IPs. They hack Russian and Chinese computers first, from where they launch their exploits. I would imagine the NSA is not the only country that does this. I don't know how good the two security firms are and whether they could actually identify something like this, though.
- phaus 10y agoAttribution is difficult, but your comment shows a lack of understanding. Everyone already knows that you can't attribute activity based solely on the geographical association of IP addresses.
- cloakandswagger 10y agoRead the whitepaper that CrowdStrike wrote on the HammerToss virus. They attribute it to Russia for two reasons: 1) It is "sophisticated", because it uses public services like Twitter/Github and embeds command & control scripts into images. Any mid-level application developer could write a similar virus in a weekend. 2) The work required to keep the virus operating (registering Github/Twitter accounts, posting messages) was done during the Russian workday. Because the Russian hackers are highly sophisticated enough to write this virus but incompetent enough to not cover their tracks. This is the clearest, most blatant example of the US propaganda machine at work. With no concrete evidence whatsoever they have accused a nuclear power of performing these attacks, and the media and a bunch of "infosec researchers" (who most in tech recognize as charlatans) fell in line.
- deeth_starr_v 10y agoDid you read the link? There's actually a lot more evidence than that. "a reused command-and-control address—176.31.112[.]10—that was hard coded in a piece of malware found both in the German parliament as well as on the DNC’s servers. Russian military intelligence was identified by the German domestic security agency BfV as the actor responsible for the Bundestag breach. " Also, occam's razor.