You have commented 339 times on Rantburg.

Your Name
Your e-mail (optional)
Website (optional)
My Original Nic        Pic-a-Nic        Sorry. Comments have been closed on this article.
Bold Italic Underline Strike Bullet Blockquote Small Big Link Squish Foto Photo
Science
U.S. Intelligence Got the Wrong Cyber Bear
2017-01-03
[Bloomberg] The "Russian hacking" story in the U.S. has gone too far. That it's not based on any solid public evidence, and that reports of it are often so overblown as to miss the mark, is only a problem to those who worry about disinformation campaigns, propaganda and journalistic standards -- a small segment of the general public. But the recent U.S. government report that purports to substantiate technical details of recent hacks by Russian intelligence is off the mark and has the potential to do real damage to far more people and organizations.

The joint report by the Department of Homeland Security and the Federal Bureau of Investigation has a catchy name for "Russian malicious cyber activity" -- Grizzly Steppe -- and creates infinite opportunities for false flag operations that the U.S. government all but promises to attribute to Russia.

The report's goal is not to provide evidence of, say, Russian tampering with the U.S. presidential election, but ostensibly to enable U.S. organizations to detect Russian cyber-intelligence efforts and report incidents related to it to the U.S. government. It's supposed to tell network administrators what to look for. To that end, the report contains a specific YARA rule -- a bit of code used for identifying a malware sample. The rule identifies software called the PAS Tool PHP Web Kit. Some inquisitive security researchers have googled the kit and found it easy to download from the profexer.name website. It was no longer available on Monday, but researchers at Feejit, the developer of WordPress security plugin Wordfence, took some screenshots of the site, which proudly declared the product was made in Ukraine.
Posted by:Pappy

#6  The hacking story is just disinformation aimed at Democrats hoping to get them mad and deligitimze the election in their eyes. Sadly it worked well and a large number thing voting machines were hacked or some such nonsense instead of it being Podesta fell for a fairly obvious Phishing trick.
Posted by: rjschwarz   2017-01-03 16:05  

#5  I lack the impolite words to respond to this properly.

How about closing the barn door after the cows have escaped?
Posted by: Abu Uluque   2017-01-03 12:36  

#4  But not for very much longer. :)
Posted by: Abu Uluque   2017-01-03 12:27  

#3  If Obama and his so called security experts really wanted to help they would publish the ranges of IP addresses in the .ru and .ua domains, those IP addresses that belong to Russia and Ukraine. That way, computer network administrators all over the country could put those addresses into their firewalls thereby blocking access from Russia and Ukraine. They should have done this years and years ago and they should have included the .cn, .ro, .tr, .ir domains as well. The fact that this has not been done indicates they really don't care about cyber security. That's the scariest part of this whole episode. I can say with all honesty that I fear Obama far more than Putin. Putin might be a bad guy but he is far away in Russia. Obama is right here and he has power over my own country.
Posted by: Abu Uluque   2017-01-03 12:26  

#2  Reference #1 - Here, let me be of assistance. Plan A: Target your wrath at the presidentially appointmented intelligence community directors. From there, take your wrath downstream among the literally thousands of Senior Executive Service employees empowered by the their directors over the past 10 years or so.

Too large an undertaking, too difficult to sort out? Too much fly shi* in die rooibos tin? I fully understand. Then initiate plan 'B' by sacking the entire organization and beginning anew.

Gov't hacking and monitoring of networks (theirs or ours) is not entirely unlike wanking. Denial is futile.
Posted by: Besoeker   2017-01-03 07:35  

#1  I lack the impolite words to respond to this properly.

And I lack the knowledge of whom to direct these impolite words towards, which might affect my selection of these words. So I find myself bound by a dilemma.

But there are a few RBers out there who don't have our limitations. :-)
Posted by: gorb   2017-01-03 01:16  

00:00