3 ms·
> Strong Attribution is definitely a difficult task and unless someone admits guilt, you'll have to rely on probabilities but the combined CrowdStrike, SecureWo
by problems 10y ago
> Strong Attribution is definitely a difficult task and unless someone admits guilt, you'll have to rely on probabilities but the combined CrowdStrike, SecureWorks, and ThreatConnect reports give a fairly strong basis of where to place blame for the DNC servers.
That's the thing though - you can place that blame whereever you want simply by making it look that way - buying servers from the right providers, modifying existing malware to suit your purposes via reverse engineering, etc. It's fairly straightforward stuff for someone in the know to do.
The probabilistic analysis does not and cannot account for fakery of this sort - the posts you linked do not attempt to account for this at all, instead assuming blindly that "hey, this looks vaguely like this russian attack group". I read his posting there - it seemed sketchy to me - then I read his Twitter account and it explained why it seemed sketchy. He's a blatant partisan, looking only to prove his side.
I'm not saying it's not possible it's Russia. It's quite possibly Russia. Probable even. Just that I don't trust the only possible analysis methods at a deep level such that I don't feel blame can be reliably laid in such a case.