6 ms·
"Working off the IP address, U.S. investigators identified Guccifer 2.0 as a particular GRU officer" Not a network whizz but doesn't that sound unlikely? They
by alva 9y ago
"Working off the IP address, U.S. investigators identified Guccifer 2.0 as a particular GRU officer"
Not a network whizz but doesn't that sound unlikely? They would have to have 1. Static IPs 2. Deep enough penetration of their systems to have IP/Officer mapping -> in which case they would have known this was going on anyways?
Seems necessary to edit:
I understand the NSA is the most powerful player and likely had penetrated their systems. My point is that if their networks were penetrated anyways, why are receiving this reasoning about the accident with the VPN? The only plausible explanation I can see is what another commenter put out which is the Officer had also used the non-VPNd connection to something personal. Now this would be a big fuck up
Saying they could identify an individual officer from an IP leads you to assume they had penetrated the network. In which case, why not disclose that? That would be the assumption from the other side.
- ryanlol 9y agoIf it was a residential IP, this would have been very easy. But would GRU officers really work from home?
- jlgaddis 9y agoThe rest of the sentence quoted above is "... working out of the agency’s headquarters on Grizodubovoy Street in Moscow."
- zrobotics 9y agoWhich could also mean an intelligence officer('s personal machine, who is known to be) working out of the agency's hq... It implies that the IP was from GRU HQ, but the only definite statement is that it is this specific officer, who works at this specific location.
- erric 9y agoIt wouldn’t be too hard for the Russian govt to set up shop in a residential neighborhood.
- rbanffy 9y agoOr, at least, have a network exit point at an unsuspecting family home.
- alva 9y agoYes I suppose that could be the other explanation
- runciblespoon 9y ago@walshemj: "But would they actually work from a known location id assume that US offensive operations are not done directly from Langley" You forget this story is aimed at people who mostly get their news from Faux Television ..
- walshemj 9y agoBut would they actually work from a known location id assume that US offensive operations are not done directly from Langley
- deleted 9y ago[deleted]
- erric 9y ago>But on one occasion, The Daily Beast has learned, Guccifer failed to activate the VPN client before logging on. As a result, he left a real, Moscow-based Internet Protocol address in the server logs of an American social media company, according to a source familiar with the government’s Guccifer investigation. He forgot to use the VPN that was masking him.
- jlgaddis 9y agoRest assured that all of the evidence they have of this identification is not included in this article.
- avn2109 9y agoThis might be true and probably is, but I'm in general not the sort of person who is convinced by "We have more evidence but we're not showing it here, just believe us!" It just strikes me as very sloppy epistemology, and sort of insulting to my abilities to draw my own conclusions.
- dragonwriter 9y ago“Working off” does not mean it was a one-step IP -> name mapping, orn that the IP address was the only relevant piece of information, just the thing that got them past the VPN exit point in France that was the dead end before that unprotected access was discovered. The IP address could have led to GRU HQ (specifically identified as where he was working out of), and other information could have narrowed it down from there to a particular officer.
- avn2109 9y agoI agree that this is possible, but I too would like to see them explain precisely how they narrowed it down to a single workstation in a building full of workstations, and then how they mapped a workstation to a human. A comment downthread suggests that he logged into a real-name service from the same IP without a VPN. This too is possible, but I find it at least somewhat surprising that an intelligence service doesn't prohibit logging in to real-name services from State computers. For example, some civilian employers prohibit this, even when they provably have nothing to hide.
- ramphastidae 9y agoAre you really expecting the NSA to publish 0-days they are actively exploiting for intelligence gathering operations? :)
- dragonwriter 9y agoOr, even worse, expecting other involved intel agencies to reveal HUMINT sources that were used to narrow the identification once technical means got them something past the VPN exit?
- gwern 9y agoThere's a lot of possibilities. Remember how the Dutch hacked Cozy Bear's security cameras? One could do a lot with info like that, and it seems unlikely that those were the only vulnerable cameras, since that's not usually how IoT ('the S stands for Secure') stuff works.
- NN88 9y agoDo you all ever stop and think "Hey, maybe even knowing this much means the government knows more?" No. You just come in with the: "This doesn't seem right. Isn't the NSA basically on college 101 level?" Dude, they did it. Dutch intel even pwn3d their networks and video cameras.
- deleted 9y ago[deleted]
- YarickR 9y agoOh rly ? They just showed a bunch of camera-quality records and told everyone this is IRA headquarters' CCTV footage . Any reason to believe that ?
- croon 9y agoNSA is the NSA, but they could probably corroborate it with stuff like this: https://yro.slashdot.org/story/18/01/28/0529257/dutch-intelligence-agents-watched-russia-hack-the-dnc https://yro.slashdot.org/story/18/01/28/0529257/dutch-intell...
- stordoff 9y agoIf it's a GRU machine, I find it highly likely that the NSA would at least be trying to monitor communications from it[1]. It's possible that they can't get an active tap on the GRU's internal network (at least on-going, and doing so might not immediately reveal the source if the documents are only transferred over the active VPN connection -- having network access doesn't necessarily imply access to endpoints), but can tap the upstream connection. Once the source has been identified as a particular connection/building, I can think of a number of ways it could then be narrowed to an individual: * Agent embedded in the office - they might not know about the operation beforehand if it's well compartmentalised, but may be able to find out more now they have that initial information, or rule out enough people to narrow it down * Breach the internal network, knowing that access will be short-lived and discovered, but for long enough to get the information you need * A further slip-up that, e.g., includes a name or some other identifying piece of information (e.g. cookie to a non-HTTP site), or accessing GRU systems that the US have previously breached or are otherwise improperly secured from the same machine * Forge the VPN set up so that the user connects to NSA-controlled servers -- doesn't seem out of the realm of the NAS's capabilities; or * Work with Elite VPN (unlikely--they appear to be a Russian company) or breach their systems (I imagine their security is less than GRU's, especially if they have servers in France which would likely allow the NSA or their French counterparts to compel physical access) to gain access to the VPN traffic. Once you have that, insert a zero-day into the traffic to gain access to the GRU machine * Use a QUANTUM-style attack to embed a zero-day into non-VPN requests made over that connection It's unlikely that you could immediately go from IP address to GRU officer, but working from that IP address you certainly have options that could lead you to an individual. I think it's quite clear why NSA would not want to reveal which technique(s) they used, particularly as it could lead GRU's countermeasures to be specifically targeted against useful methods. I'm also not particularly sure it matters all that much. It's quite possibly the work of a team (even if the actual postings come from an individual) and will at least (presumably) have command authorisation. The article notes "[s]ometime after its hasty launch, the Guccifer persona was handed off to a more experienced GRU officer". Attributing it to an individual, rather than just the GRU, doesn't seem to make much difference. [1] I find it possible that traffic analysis was used to uncover this -- find that Guccifer 2.0 is posting via Elite VPN, then correlate traffic in to Elite with possible sources. I'm surprised that GRU wouldn't use a machine that is forced to connect to a VPN for this, particularly if the machine's public IP points back to GRU/Russia, so it being something more that "agent forgot to enable VPN" would not be shocking. Edit: fix list formatting