7 ms·
If all it takes is "one occasion" for investigators to believe you're Russian, it's also definitely easy to throw investigations off course.
by CapacitorSet 9y ago
If all it takes is "one occasion" for investigators to believe you're Russian, it's also definitely easy to throw investigations off course.
- kbenson 9y agoOne very hard to fake set of connected facts that corroborate each other, validate a suspicion, and match a motive. It generally only takes one occasion of a videotape catching you stealing and an eyewitness corroboration for you to be believed the thief as well.
- vageli 9y agoThis isn't video evidence though, it's an IP address. I don't think this metaphor is similar at all.
- pwtweet 9y agoThere was real time video surveillance of the building, both external/internal by Dutch and another unnamed European agency. Also RT published the names of the two officers who controlled the G2 account: Sergei Afanasyev, GRU Deputy Chief and Grigoriy Viktorovich Molchanov, Head of the GRU Academy.
- rdtsc 9y ago> Also RT published the names of the two officers who controlled the G2 account: Sergei Afanasyev, GRU Deputy Chief and Grigoriy Viktorovich Molchanov, Head of the GRU Academy. It's surprising that RT published those. I thought it was an entity controlled by the Russian government. Why would it be publishing the names of its own officers when supposedly the said officers went out of their way to appear Romanian and not Russian.
- SlowRobotAhead 9y agoYea... I’m going to call BS on RT posting embarrassing Russian Intellegence mistakes - that are true.
- geofft 9y agoIt's very hard to spoof a log of a TCP connection in one country from an IP address assigned to the residential internet connection of an intelligence official in another country. It's certainly not impossible, but it's not as easy as just adding an email header or something.
- threeseed 9y agoYou also have to know which IP address to spoof. That means that if it it wasn't Russia then it must be some "deep state" conspiracy. Which so far hasn't been backed up by any decent evidence.
- thelittleone 9y agoSeems like a massive opsec hole. Why not force all outbound connections through an offshore VPN or proxy at their internet gateway.
- mistermann 9y agoIt's odd on a site like HN that ideas like this occur to hardly anyone. Well, on certain subject matter of course. Lets see what Jonathan Haidt has to say on the matter: https://www.youtube.com/watch?v=v6nNT0JtHT8 https://www.youtube.com/watch?v=v6nNT0JtHT8
- kenbaylor 9y agoSomething like this? "“With UMBRAGE and related projects the CIA cannot only increase its total number of attack types, but also misdirect attribution by leaving behind the ‘fingerprints’ of the groups that the attack techniques were stolen from,” Wikileaks said in a statement." https://www.usatoday.com/story/news/2017/03/07/wikileaks-cia-hacking-group-umbrage-stockpiled-techniques-other-hackers/98867462/ https://www.usatoday.com/story/news/2017/03/07/wikileaks-cia... and for remote control: "In April this year, WikiLeaks disclosed a brief information about Project Hive, revealing that the project is an advanced command-and-control server (malware control system) that communicates with malware to send commands to execute specific tasks on the targets and receive exfiltrated information from the target machines. Hive is a multi-user all-in-one system that can be used by multiple CIA operators to remotely control multiple malware implants used in different operations." https://thehackernews.com/2017/11/cia-hive-malware-code.html https://thehackernews.com/2017/11/cia-hive-malware-code.html
- Lazare 9y ago> If all it takes is "one occasion" Depends on the occasion, no? There's a difference between "the target account once used phrasing more typical of a Russian speaker than a Romanian speaker" and "the target connected to the server from inside GRU headquarters". > it's also definitely easy to throw investigations off course Connecting to a server from GRU headquarters isn't something I'd call "definitely easy". If the claim is true, Occam's Razor suggests that the GRU was involved in some fashion. What's the alternative? That the DNC compromised the network of a Russian intelligence agency? (How much faith to put in an anonymously sourced claim about what was in the logs of an unnamed social network is a separate question, of course.)
- vageli 9y agoTeenagers can hack NASA [0] so I don't think a sufficiently motivated attacker, possibly backed by a nation state, couldn't pull off something like this as a false flag. [0]: https://abcnews.go.com/Technology/story?id=119423&page=1 https://abcnews.go.com/Technology/story?id=119423&page=1
- gruez 9y ago...and NASA is known to have top opsec?
- stordoff 9y agoWhy would NASA's defences be comparable to GRU?
- Nomentatus 9y agoAnd it's still 1999?
- Lazare 9y ago> Teenagers can hack NASA [...] so I don't think a sufficiently motivated attacker [...] couldn't pull off something like this Right, the fact someone could compromise a random government agency in the 90s clearly means someone else could compromise Russian military intelligence in 2016, because NASA's IT security in the 90s is totally comparable to the GRU today, absolutely. > possibly backed by a nation state Which nation state, exactly?
- jasonlotito 9y agoThat's literally not what happened. There is a lot of other evidence to support this claim. It wasn't just this one simple thing that pointed to Russia.
- nl 9y agoTrue. Except the Russians haven't worked very hard to try to deny it. And - more importantly - everything else they do aligns with this same goal. It's like during WW2 finding a person spying in London, finding they were passing information on English plans to attack German air defenses to someone in Berlin and saying "Well.. they might have been American, because the US and the UK were rivals during the Washington Naval treaty process during the 1920s". Yes.. they might. But there's a lot of evidence pointing the other way, and German actions indicate it was the kind of thing they would like. Same here.