But some people still hope for online voting. This is a preview of how other countries could decide your elections if you switch to online voting now (and that's assuming your own intelligence agencies don't compromise it first to support whoever is more favorable to them and to an expansion of their powers).
This is not about online voting. Though I'm in agreement that it's certainly not going to be securely implemented in the near future, especially given the way government (state and federal) IT contracts are generally handled (read: poorly).
We have the info about how long were they inside of the network, we have some basic idea about how they are discovered to be connected to Russia (basically groups were previously linked to Russia, and now they were probably discovered by analyzing the code style and/or by re-using some of the code), we got to know how the incident response went, we discovered that they used 0 days targeting Windows, that they masked their traffic as legit Windows services, that they have created some kind of pattern analyzing tool that analyzes the code they got on every machine so they could detect if the attackers try breaching into the system again...
I'd say that this is a pretty hefty amount of information we got from a single article when it's not really a post mortem by the company, but an article on Washington Post.
I'm not a moderator but FWIW:
This link is regarding a technical exploit of an IT system.
Whether the goal of this exploit is profit, blackmail, political, activism, curiosity, etc -- there is nonetheless definitely a technical/IT angle that makes it interesting for visitors like myself.
I imagine HN wanted to protect it's community from something they viewed as tangential to their focus but possibly highly vitriolic in content (to the degree that they influenced the submission, which I'm not sure the level of). Alternatively, it could have been a community self-policing, by flagging articles that they thought were poisonous, or that were viewed as promoting misinformation (do the degree that happened. I haven't followed this closely, but that seems to be a common occurrence shortly after a disaster).
Prince was a powerful creative figure and a direct inspiration to many hackers. He was also a technology pioneer, one of the first to take multimedia seriously and see how it could be combined with art.
If you're ignorant of all this I can't help you. Put the pieces together yourself.
Even Reddit had "troubles" discussing the Orlando shootings.
I think the upcoming election creates an environment amongst many media that downplays certain subjects that may propel mr. Trump into the White House.
The big attacks in France made it to HN frontpage though:
The only thing interesting about this story is that whoever did it got caught. Sort of.
Is there anyone here who really believes that every major campaign organization since, say, 2004 hasn't been completely owned up? What, you think the people that build the software and IT environments for campaigns --- sites that by design have millions of users with persistent accounts, and thousands of staff members at varying levels of privilege --- are the creme de la creme of software security talent?
Because, sure, I mean, everyone I know in software security and pentesting tells me "my first career choice is to go work in IT for the DNC and the GOP", but somehow along the way Google manages after a mighty struggle to outbid the 70k/year cost-center IT organizations offer for security talent.
If there was any interesting "oppo research" on McCain in the DNC servers during the '08 election, I will bet all the money in my pocket versus all the money in yours that the Chinese read all of it long before everyone on the official CC list did.
> What, you think the people that build the software and IT environments for campaigns ... are the creme de la creme of software security talent?
No, but I've always considered the competence of the IT people to likely fluctuate wildly from person to person, as I assumed many were politically motivated and donating at least some of their expected compensation level. I think the bigger problem would be in an organization with lots of volunteers, at least at the lower levels, and that gets at least partially rebuilt every few years, operational security is probably very hard to enforce for multiple reasons.
Is blase indifference how we respond to national level security breaches now?
If this was somebody's health records, the organization responsible for the disclosure would be under serious investigation (HIPPA), and throwing down retainers to every law firm in town.
Thomas, is it your opinion that those responsible for securing this data shouldn't be held responsible?
I think it's awfully silly to pretend that campaign IT organizations should be falling on their swords when the largest, most-talented, best-funded software security organizations in the industry do only a marginally better job when evaluated by outcome.
But, more importantly: I meant what I said. The only interesting thing about this story is that whoever hacked the DNC got attributed. You think the GOP isn't owned up?
Now? The only thing opensource advocates, hobbyist developers, large tech companies, the "security" industry and the government have been able to consistently agree on for the last 15 years is that there should be little enforcement of quality standards, in contrast with essentially every other industry.
Who would you say has the creme de la creme of software security talent, and can you with a straight face say that they have not been compromised at some level?
Just the tech giants have the best security people? How about large banks, hedgefunds and other financial services, security contractors/private military and governments?
No mention of Intel, IOActive, Matasano, Rapid7, FireEye, CheckPoint, Trend Micro, Kaspersky Labs, UCF, JHU, APL, MITRE, and of course, NSA?
Sure, the ones you mentioned have the biggest paychecks. But they won't give you indemnity and extended resources to find weaknesses in critical infrastructure. Some people like breaking bigger toys.
> Because, sure, I mean, everyone I know in software security and pentesting tells me "my first career choice is to go work in IT for the DNC and the GOP", but somehow along the way Google manages after a mighty struggle to outbid the 70k/year cost-center IT organizations offer for security talent.
There is no security talent at google, only fuckboys.
The interesting implication is that campaign IT has to have protection, similar to the way that the candidates themselves get SS protection.
Further, that private email servers for public function should never be again. The damage wasn't that a classified email was read; it was that any information was read before it was deemed safe for the rest of the world to read.
It's astounding to me that NSA and DHS hasn't been all over this for years. Although I suppose if all those systems were secure it would be harder for NSA to spy on their owners.
Everyone you know in infosec is also probably not highly motivated to work around politics. Those that do will be trying to work either directly for a campaign, or the DNC, or companies like NGP VAN, the largest tech contractor for Democratic campaigns. Those people are motivated to do their jobs well so their candidate/party will win.
That said, the CIA & NSA probably owned them all up well before, and whomever has them in their pocket will have an upper hand as well. It's not like blackhats and foreign states are the only interested parties.
“It’s the job of every foreign intelligence service to collect intelligence against their adversaries,...”
Hah. Translation: We've a firm foothold in their systems as well.
Yeah, but the problem with their systems is, it's all written in chinese. Our systems store information in english, which is a much easier language to read. So they have a natural advantage there...
Have you ever heard the old joke about the country bumpkin who argues against bilingual education by saying "If English was good enough for Jesus, then it's good enough for our schoolchildren"?
I've had the pleasure of speaking to people who have actually said that - or something along the lines. "Why are you studying Japanese? Don't they teach English in Japanese schools? You can just speak English with Japanese people."
I enjoy introducing English-only speakers to "The Chaos" by Gerard Nolst Trenité. It gives them a good idea of how terrible English can be - as even people who consider themselves "fluent" in English will struggle through the poem and mispronounce many of the words. ( http://ncf.idallen.com/english.html )
As a person that is not a native english speaker I find english extremely powerful language, with hundreds of nuanced words that convey different aspects and facets of seemingly same ideas - like emotions! Thesaurus raids can be fun! As well as reading well written, witty prose (#Fuck poetry)
I also love how it can compress complex ideas into one word - it actually makes speaking in my native tongue hard, because a lot of such words siply do not have translations (or just are translated into way more general ones)
Putin is an autocrat, what equivalent is there to the DNC for him?
I think democracies are more at risk at this kind of thing because they have real elections and the data mined during elections is important. Its managed by a non-profit political party and as such usually has lax security.
Why wouldn't the intruders change anything while they were there?
For example, filtering out some important emails, with a goal of hamstringing the organization.
Also... The older I get, the more I realize that adults are just kids with very fancy tree houses. MY treehouse doesn't have rats. Get your leaders from here, not from there.
There was a time when if you wanted to transport yourself or your goods across say Europe or China, you needed to hire mercenaries and they would protect your business from bandits on the way.
At various times (Mongols, US Navy vs pirates etc) governments stepped in and provided that protection (for a lesser price) and trade grew.
I'm not too sure how governments can provide protection in the online realm. Perhaps by providing minimal standards of security? (I know the standards exists but enforcing them?)
However, now my iPhone is FBI-resistant, and public keys are fairly easy to share, it seems that secure peer to peer communication is feasible.
So the shape of a more secure, bandit free internet is clearer - hardened mobile devices, and much much stricter standards that are enforced, but it seems an odd new world.
52 comments
[ 5.1 ms ] story [ 205 ms ] threadInsecure online voting would be icing on the cake
If you can't be bothered to vote in person, which I will argue needs to have fewer obstacles in its' own right, then I don't care about your vote.
We have the info about how long were they inside of the network, we have some basic idea about how they are discovered to be connected to Russia (basically groups were previously linked to Russia, and now they were probably discovered by analyzing the code style and/or by re-using some of the code), we got to know how the incident response went, we discovered that they used 0 days targeting Windows, that they masked their traffic as legit Windows services, that they have created some kind of pattern analyzing tool that analyzes the code they got on every machine so they could detect if the attackers try breaching into the system again...
I'd say that this is a pretty hefty amount of information we got from a single article when it's not really a post mortem by the company, but an article on Washington Post.
But over 100 people shot is not okay. Very confusing.
Whether the goal of this exploit is profit, blackmail, political, activism, curiosity, etc -- there is nonetheless definitely a technical/IT angle that makes it interesting for visitors like myself.
So Price overdosing = okay.
100 people being shot = not okay.
Trump on the front page of HN = okay.
100 people being shot = not okay.
I still cannot figure out why.
If you're ignorant of all this I can't help you. Put the pieces together yourself.
I think the upcoming election creates an environment amongst many media that downplays certain subjects that may propel mr. Trump into the White House.
The big attacks in France made it to HN frontpage though:
https://news.ycombinator.com/item?id=10562679
Is there anyone here who really believes that every major campaign organization since, say, 2004 hasn't been completely owned up? What, you think the people that build the software and IT environments for campaigns --- sites that by design have millions of users with persistent accounts, and thousands of staff members at varying levels of privilege --- are the creme de la creme of software security talent?
Because, sure, I mean, everyone I know in software security and pentesting tells me "my first career choice is to go work in IT for the DNC and the GOP", but somehow along the way Google manages after a mighty struggle to outbid the 70k/year cost-center IT organizations offer for security talent.
If there was any interesting "oppo research" on McCain in the DNC servers during the '08 election, I will bet all the money in my pocket versus all the money in yours that the Chinese read all of it long before everyone on the official CC list did.
No, but I've always considered the competence of the IT people to likely fluctuate wildly from person to person, as I assumed many were politically motivated and donating at least some of their expected compensation level. I think the bigger problem would be in an organization with lots of volunteers, at least at the lower levels, and that gets at least partially rebuilt every few years, operational security is probably very hard to enforce for multiple reasons.
If this was somebody's health records, the organization responsible for the disclosure would be under serious investigation (HIPPA), and throwing down retainers to every law firm in town.
Thomas, is it your opinion that those responsible for securing this data shouldn't be held responsible?
But, more importantly: I meant what I said. The only interesting thing about this story is that whoever hacked the DNC got attributed. You think the GOP isn't owned up?
Security is hard, but I wonder if it's P VS NP?
I'd actually say security research firms have pretty high quality security people, however, and not just the tech giants.
1. http://www.iphoneincanada.ca/news/1password-open-letter-bank...
Sure, the ones you mentioned have the biggest paychecks. But they won't give you indemnity and extended resources to find weaknesses in critical infrastructure. Some people like breaking bigger toys.
There is no security talent at google, only fuckboys.
I'm really not liking the cream comparison for a couple reasons. One is that I like cream.
Further, that private email servers for public function should never be again. The damage wasn't that a classified email was read; it was that any information was read before it was deemed safe for the rest of the world to read.
It's astounding to me that NSA and DHS hasn't been all over this for years. Although I suppose if all those systems were secure it would be harder for NSA to spy on their owners.
That said, the CIA & NSA probably owned them all up well before, and whomever has them in their pocket will have an upper hand as well. It's not like blackhats and foreign states are the only interested parties.
Or in other words: 说话像一个男人谁不说第二语言
I enjoy introducing English-only speakers to "The Chaos" by Gerard Nolst Trenité. It gives them a good idea of how terrible English can be - as even people who consider themselves "fluent" in English will struggle through the poem and mispronounce many of the words. ( http://ncf.idallen.com/english.html )
I think democracies are more at risk at this kind of thing because they have real elections and the data mined during elections is important. Its managed by a non-profit political party and as such usually has lax security.
For example, filtering out some important emails, with a goal of hamstringing the organization.
Also... The older I get, the more I realize that adults are just kids with very fancy tree houses. MY treehouse doesn't have rats. Get your leaders from here, not from there.
At various times (Mongols, US Navy vs pirates etc) governments stepped in and provided that protection (for a lesser price) and trade grew.
I'm not too sure how governments can provide protection in the online realm. Perhaps by providing minimal standards of security? (I know the standards exists but enforcing them?)
However, now my iPhone is FBI-resistant, and public keys are fairly easy to share, it seems that secure peer to peer communication is feasible.
So the shape of a more secure, bandit free internet is clearer - hardened mobile devices, and much much stricter standards that are enforced, but it seems an odd new world.