7 ms·
The only problem is there is no way to prove that that address actually belongs to the GRU. The transaction referenced in the indictment clearly happened, but
by craigc 8y ago
The only problem is there is no way to prove that that address actually belongs to the GRU.
The transaction referenced in the indictment clearly happened, but Mueller and his team could have easily searched through the Bitcoin blockchain to find any transaction that paid for a VPN, hosting, or domain registration using Bitcoin on or around the date of the hack.
The indictment makes it sound like the request for 0.026043 BTC came via email. I think that is a bit strange. If you are Russian Military Intelligence about to hack the government of the United States, why would you include references and payment info related to your Bitcoin transactions in hundreds of emails? Surely just keeping track of the Bitcoin addresses on the blockchain would be enough since that is the entire point of the Blockchain. Keeping a reference via email sounds like a good plot for an episode of America’s Dumbest Criminals, not the Russian military.
It is certainly possible that this is exactly what happened, but I think the American people deserve to see some evidence.
- rhizome 8y agoYou might be interested in Micah F. Lee's take: https://theintercept.com/2018/07/18/mueller-indictment-russian-hackers/ https://theintercept.com/2018/07/18/mueller-indictment-russi...
- duxup 8y agoTY, that is very interesting... also surprisingly lazy by the Russians. I would have thought there would have been clear protocols about VPNs, some "we're 99.999% sure this is a clean laptop, don't do anything else here, and only do thing here and inside this brand new VM each day..." kinda stuff that would prevent such mistakes.
- TangoTrotFox 8y agoThe problem with these allegations is they always seem to have this sort of issue, as well as logical problems. Some of the things in the article don't really make any sense. For instance they state that they way they decided that Guccifer was part of the GRU is that on one occasion the IP for that Twitter account was from the GRU. They then state that that must mean that the Russians must have forgotten to log onto their VPN first. But I mean, what? Using a dedicated VPN makes no real sense in the era of TOR, and such a mistake would have been literally impossible with TOR. It's also mentioned in the article that "The US (or a partner)" hacked at least two GRU computers. If this is the case then it's safe to assume other actors could have as well, and suddenly what exactly does a login from the GRU IP actually mean? Or in the machines that the GRU allegedly hacked, their behavior was discovered by the presence of logs that the hackers apparently had to manually delete? State level malware does not automatically delete logs? Wow. And then they allegedly rented servers in Arizona and Illinois for illicit activities, knowing full well that their are a gazillion different domestic digital surveillance programs being carried out by the NSA? And then apparently they were exchanging emails, literally discussing theft of DNC materials, in plain text without encryption? These things just never really make any logical sense. It simultaneously tries to paint Russians as these super hackers capable of achieving anything. And then it also shows them getting busted making mistakes that I'd like to call amateur, but that implies that these are mistakes even an amateur might reasonably make, which is probably doubtful. It's bizarre.
- duxup 8y agoI really don't see your descriptions as that odd or "problems." So some Russians didn't use Tor because you think they should have (it's not like the US government isn't already aware of TOR...). I just don't see that as a big deal or at all surprising... Beyond that are you saying that some other actor hacked a GRU computer and framed them or something? That's a pretty big leap there without anything to it. As for logs having your malware just delete logs automatically could be useful at times... less so other times. I would think you would want to choose to do it when you wanted. A lot of malware does log wiping, I'd be tempted to look for log changes over time just to find malware based on that alone..... suddenly missing logs would be a big sign. Beyond that I'm not going to get into it. These seem like just you and me logicing things out in our head and that doesn't mean we're right or wrong. Humans don't make sense at times, they dork up, that isn't surprising to me. Just because some of it is curious to me and maybe choices I wouldn't have made, doesn't make it not true, or those choices as odd or wrong as we might thing anyway.
- craigc 8y agoTwo other points worth noting 1. The FBI never had physical access to the hacked servers and were relying completely on the report from a third party company, CrowdStrike: http://thehill.com/policy/national-security/313555-comey-fbi-did-request-access-to-hacked-dnc-servers http://thehill.com/policy/national-security/313555-comey-fbi... 2. The former tech director of the NSA, William Binney, claimed that the data could not have been copied remotely because the download speed was around 22 MB/s (176 Mb/s) which he and a team concluded was not possible for a remote hack with servers in Russia and routing through a commercial VPN service: https://consortiumnews.com/2017/07/24/intel-vets-challenge-russia-hack-evidence/ https://consortiumnews.com/2017/07/24/intel-vets-challenge-r...
- reefoctopus 8y ago>During former FBI director James Comey’s testimony to the House Intelligence Committee, Comey was asked whether the FBI had ever received the DNC’s hacked hardware. >He said they did not, but obtained access from a review of the system performed by CrowdStrike, a third-party cybersecurity firm. >"We got the forensics from the pros that they hired which -- again, best practice is always to get access to the machines themselves, but this, my folks tell me, was an appropriate substitute," Comey said. >DNC spokeswoman Adrienne Watson told PolitiFact that the DNC cooperated with the FBI’s requests, which resulted in the DNC providing a copy of their server. >"An image of a server is the best thing to use in an investigation so that your exploration of the server does not change the evidence (just like you don’t want investigators leaving their own DNA around a physical crime scene) and so that the bad actors cannot make changes to the evidence while you are looking at it," Watson said. "Any suggestion that they were denied access to what they wanted for their investigation is completely incorrect." http://www.politifact.com/truth-o-meter/statements/2018/jul/16/donald-trump/missing-servers-donald-trump-vladimir-putin/ http://www.politifact.com/truth-o-meter/statements/2018/jul/...
- gasull 8y agoThat's a great article, but it misses a point: There were two batches of emails published by WikiLeaks. The second batch wasn't published by GRU's front DCLeaks / Guccifer 2.0. So it's possible that the source of that second batch is a different one, and it's certainly possible it could be Seth Rich. https://archive.is/6MKz4#selection-1021.1-1025.3 https://archive.is/6MKz4#selection-1021.1-1025.3
- downandout 8y agoThe only problem is there is no way to prove that that address actually belongs to the GRU. They don't have to. This case isn't going to trial; it was basically a PR stunt. It wouldn't survive a trial. The strategy is simple: Indict a bunch of people that you cannot extradite, and you get a PR win with just some broad strokes and have to prove nothing. You get to keep your unlimited budget to continue the investigation, and the press keeps listening to you.
- civilitty 8y agoThat's idiotic and completely ignorant of how large scale criminal prosecutions work. Conspiracy and RICO charges necessitate many low level indictments to demonstrate to the court that there is probable cause to the indict the bigger fish and restrict them until trial. Since indictments have a lower threshold than convictions, they are easily challenged when they are brought up as relevant evidence. Mueller has already brought these charges in front of a judge and he decided that the evidence warrants serious consideration of the allegations. Until another judge says otherwise, you are doing nothing but spreading clearcut propaganda.
- throwawayou812 8y agoConspiracy and RICO charges necessitate many low level indictments to demonstrate to the court that there is probable cause to the indict the bigger fish If you cannot arrest the people in the "low level indictments" or threaten them with prison then they aren't going to help you with the "bigger fish". Mueller has already brought these charges in front of a judge You're entirely wrong. This went in front of a grand jury, not a judge. That shows that your understanding of this whole process may not be what it needs to be to make the arguments you are making. Anger in no way makes up for lack of knowledge.
- civilitty 8y ago> That shows that your understanding of this whole process may not be what it needs to be to make the arguments you are making. You don't even know that judges preside over grand jury proceedings. That's, like, the most fundamental aspect of the entire legal system: there is a judge deciding things. You have no business criticizing someone's understanding of the judicial system.
- dragonwriter 8y ago> The only problem is there is no way to prove that that address actually belongs to the GRU. Sure there is; for instance, you could have surveillance (video, keylogger, etc.) of the GRU officer at the GRU computer in GRU headquarters executing transactions on it. > If you are Russian Military Intelligence about to hack the government of the United States, why would you include references and payment info related to your Bitcoin transactions in hundreds of emails? Surely just keeping track of the Bitcoin addresses on the blockchain would be enough since that is the entire point of the Blockchain. Even if one grants that this is correct in some ideal sense, “government bureaucracy has operational staff proficient with new technology but imposes counterproductive documentation processes” is something literally no one would be surprised about int their own government. > It is certainly possible that this is exactly what happened, but I think the American people deserve to see some evidence. If Mueller files a report, and Congress decided to make it public, concerning the one subject of the investigation for whom normal criminal process is not likely to be the first response to any apparent crimes, and the evidence is directly germane to the findings of the report, the American people will have a legitimate right to demand the evidence. If the indictment under discussion, or any other to which the allegation is necessary, goes to trial, the defendants will have a legitimate right—a Constitutional right—to demand the evidence.