Showing posts with label CrowdStrike. Show all posts
Showing posts with label CrowdStrike. Show all posts

Friday, August 19, 2016

Trump Is the Ruse de Guerre That Justifies Every Other Ruse de Guerre

Yesterday's word-of-the-day from the Oxford English Dictionary was "ruse de guerre," defined as "A stratagem; esp. one intended to deceive an enemy in war. Hence: a justifiable trick or deception."

The idea that deceptions and betrayals are acceptable under certain circumstances is really the defining feature of the Hillary Clinton campaign.

Clinton's supporters aren't just willing to overlook the lies and corruption of their candidate. They're positively eager to do so in the name of defeating Donald Trump.

Do they know that she's lying about her opposition to the Trans-Pacific Partnership? Yes, but they have to support her anyway . . . because Trump!

But wouldn't they prefer it if she would just be honest about her support for the TPP? No--because honesty might cost her some votes. 

Will they be disappointed when she signs the TPP into law as president? Of course not, since her phony opposition to it is simply a ruse de guerre to defeat Trump.

The same logic applies to every lie Clinton tells, every question from a reporter that she dodges, every vulnerable community that she sacrifices on the altar of "centrist appeal." It's all justifiable--every bit of it . . . because Trump!

As long as Clinton supporters accept Trump as the "existential threat" to the U.S. that he's made out to be, they will feel completely justified about their own betrayals of the democratic process, the Constitution, and their fellow citizens.

But Trump isn't an existential threat to anything.

He's simply the ruse de guerre that makes it easy for the Clinton media machine to justify every other ruse de guerre.

Trump is the neo-fascist strawman that allows Clinton to define herself negatively (as "not-Trump") instead of positively (which would be impossible, since there isn't any "there" there with Clinton).

I've been on the fence about Trump's intentions until today. Sometimes it looks like he doesn't know what he's doing, but sometimes it looks like he's trying to lose.

I considered the rumors that his campaign is a false flag operation for Clinton. I understood why some people believed that, but I never saw evidence that struck me as conclusive.

But when Fortune reported that the Trump campaign hired CrowdStrike to deal with a recent hacking episode, the scales fell from my eyes.

Cybersecurity companies like CrowdStrike can't do what they're hired to do without having access to the computer networks of their clients, so such clients must be willing to trust their data guardians with their most important secrets. 

The fact that CrowdStrike is a high-profile cybersecurity firm with a track record of investigating hacks of political campaigns is perhaps a good reason to trust them.

But the fact that CrowdStrike is already working for the DNC is a much better reason for the RNC candidate not to trust them.

I don't know what this hire looks like to the rest of the world, but to me, it's a plain signal that the data networks of the Clinton campaign and the Trump campaign have now been fused through CrowdStrike.

And when we later learn that CrowdStrike was able to coordinate Clinton's coronation through an analysis of data voluntarily provided to them by Trump's campaign, the Clinton supporters will smile at the impoverished and imprisoned people of a toxic, smoldering planet and say that merging the campaigns was a ruse de guerre. 







Thursday, August 18, 2016

Crony Conspiracy Mongering: Getting in on the Ground Floor of the "Blame Russia" Industry

U.S. government officials have been reluctant to blame Russia for hacks of the Democratic National Committee (DNC) and the Democratic Congressional Campaign Committee (DCCC). We should expect the same reluctance from them in response to recently reported hacks of the Clinton Foundation.

But private cybersecurity firms have spent months echoing (as shrilly and stridently as possible) the hysterical accusations of the DNC (whose former head, Debbie Wasserman-Schultz, casually invoked "Russian spies" to divert attention from her own professional failings in a recent debate with Tim Canova).

The most clear-headed and technologically competent analysis of the (mis)attribution of the cyberattacks to Russia is Jeffrey Carr's "Can Facts Slow the DNC Breach Runaway Train." However, my own summary of connections between various private cybersecurity firms remains relevant to the discussion.

One of the first companies to "corroborate" CrowdStrike's assertion of Russian involvement was FireEye/Mandiant. The Washington Post accepted Mandiant's conclusion as "independent" even though it was based on data provided to Mandiant not by the DNC itself, but by CrowdStrike as an intermediary.

Earlier today, The Daily Caller reported that FireEye has now been retained by the Clinton Foundation (CF) to investigate a suspected hack of that organization. We shouldn't expect FireEye to waste any time before assuring us that the same Russian fingerprints from the DNC hack are all over the CF hack.

This hire is significant for the Clinton media machine in two ways.

In the first place, it addresses the chief rhetorical weakness of the DNC's exclusive reliance on one private company (CrowdStrike) to diagnose the breach. Wherever we used to see "CrowdStrike" in stories about hacks relating to the Clintons and the Democrats, we'll start seeing "the cybersecurity industry" invoked as a whole.

But the second (and more insidious) development we should be able to foresee is that more and more cybersecurity firms will begin to issue press releases of their own in support of whatever CrowdStrike and FireEye have to say. Any such firms that have been paying attention have just learned that those who chime in with the appropriate take on the "blame Russia" campaign (as FireEye did back in June) will be first in line to receive consideration for contracts from the various outfits connected to Hillary Clinton's candidacy.

I predict that the next few months will show us that the Clinton media machine can play cybersecurity experts in exactly the same way that it currently plays journalists. The Clintons don't have to pay people to say whatever magic words they want to hear; they simply allow potential shills to observe that the easiest way to get a seat on the Clinton gravy train is to parrot whatever is being said by the people who are already on board.








Monday, August 1, 2016

Politifact Uses Sneaky Language (and Sneakier Punctuation) to Present Speculation as Fact in DNC Breach

Yesterday, Politifact's Lauren Carroll released an article entitled "What we know about Russia's role in the DNC email leak." The purpose of the article is to make speculation seem more factual than it is.

Carroll is an artful writer who knows how to create the illusion of objectivity by placing almost all (but not quite all) of her quoted material within quotation marks. She also understands how balanced it makes her article seem for her to begin and end with arguments (one from Julian Assange and the other from Jeffrey Carr) that challenge its preconceived conclusion.

Carroll certainly seems meticulous in the presentation of her evidence with paragraphs such as this one:
"The consensus that Russia hacked the DNC is at this point, very strong, albeit not unanimous," said cybersecurity consultant Matt Tait, who has been critical of Clinton's email practices. "The consensus that Russia hacked the DNC in support of Trump is, by contrast, plausible, but something for which the jury at this stage is very much still out."
Did you notice all the signifiers of non-partisan objectivity? First, Tait is no shameless Clinton surrogate, since he dares to be critical of her patently careless email practices. Second, he admits that the consensus about Russia's guilt isn't unanimous. And third, he is positively eager to concede the point that even if Russia is responsible for the DNC breach, that doesn't mean the purpose of the hack was to support Trump in the election (which suggests that asking "Have you stopped beating your wife?" is more reasonable than asking "Have you stopped beating your wife for her bad singing voice?" because the former question doesn't foreclose possible answers with as much specificity as the latter).

Caroll is equally artful in her construction of this paragraph:
The U.S. government is not ready to publicly name the suspected perpetrators behind the DNC hack, but the New York Times has reported that intelligence agencies have "high confidence" regarding the Russian government's involvement.
See what she did there? She's a responsible journalist who recognizes and maintains distinctions between the accusations of private cybersecurity companies (such as CrowdStrike) and the findings of official government intelligence agencies. But she also wants her readers to know that even though she can't say the U.S. government blames Russia for the attack, the New York Times says it (which is analogous to the argument that Clinton campaign chairman Robby Mook used to support his redbaiting analysis of the breach on CNN on July 24th: "This isn't my assertion; there are a number of experts that are asserting this").

However, Carroll is at her most artful not when she couches quotations in slanted ways, but when she eschews quotation marks entirely so as to blur her own voice (the voice of a presumably disinterested journalist) with the voice of her interviewees (some of whom are shameless partisan shills):
Translation: The agencies have likely corroborated the technical evidence with other intelligence, like human or financial sources, said Susan Hennessey, a Brookings Institution fellow and a former lawyer for the National Security Agency.
As of yet, there’s no evidence anyone other than Russia breached the DNC. So unless someone hacked the Russian agencies, the Russian government is likely WikiLeaks’ source, Hennessey said. Additionally, Assange and the Russian government have a well-documented relationship, for example the fact that Assange has hosted a television show on RT, a state-owned network. [Emphasis added.]
Just look at the first sentence of that second paragraph (the one in bold type), and ask yourself what effect it's likely to have on most readers skimming through the article. It completely dispenses with the question of whether Russia is behind the DNC breach by wondering only whether any other entities might also have participated. And the absence of quotation marks doesn't even warn readers that the incredibly lazy logic of such an argument belongs to Susan Hennessey rather than Lauren Carroll--not until they reach the end of the next sentence (which some skimmers never do).

The most positive thing I can say about Carroll's article is that it at least mentions Jeffrey Carr, whose "Can Facts Slow The DNC Breach Runaway Train?" is the single most cogent analysis of the DNC breach written from the perspective of someone with the relevant technological expertise.

I can't say the Politifact article is bad because it's actually a brilliant example of propaganda. Carroll has chops as a writer; she knows better than to try to jam an argument down her readers' throats without first coating it in FD&C Yellow #34 (a synthetic coloring and flavorizer designed by muckrakers to make arguments taste more objective than they are). So read the Politifact article if you want to know what the corporate media wants you to think about the DNC breach.

But read Carr's article if you want reasoned, relevant analysis.


Friday, July 1, 2016

Even if Guccifer 2.0 Is a Disinformation Puppet, Russians Aren't Necessarily the Ones Pulling His Strings

Anything is possible with Guccifer 2.0. He may be an independent Romanian hacker (as he says). He may be part of a disinformation campaign managed by Russia (as CrowdStrike suggests). He may even be part of a disinformation campaign managed by CrowdStrike (as I fear). Given the secrecy with which hackers necessarily cloak themselves, there are infinite other possibilities.

After Guccifer 2.0 posted his latest leak in the early hours of June 30th, corporate media was silent about the freshest documents--but loud about wondering whether Guccifer 2.0 is who he says he is or who CrowdStrike says he is (as if there are no other possibilities). Here's a representative paragraph from an Inverse article that received a lot of attention yesterday:
CrowdStrike said it is investigating whether the hacker’s public statements are part of a Russian disinformation campaign or just a lone hacker looking to steal credit, but as of June 15, they said their internal findings that Guccifer 2.0 was connected to Russian intelligence services had not changed.
Is the purpose of that paragraph to raise questions about Guccifer 2.0 in the spirit of open and honest inquiry--or to foreclose discussion by setting up a false dichotomy?

Based on a DM exchange I had with Guccifer 2.0 two days ago, I remain concerned about the possibility that he is neither who he says he is nor who CrowdStrike says he is.

In the course of our conversation, Guccifer 2.0 gave me permission to summarize his remarks as long as I don't quote him directly. It's a weird request, but one that I'll honor just in case he turns out to be genuine.

The most thrilling (and terrifying) moment of the conversation came when he offered to send me hacked files from the DNC for analysis on my blog. I suspect (though he didn't say so) that he made similar arrangements with The Smoking Gun for the article that appeared on the 28th concerning the Clinton campaign's method of monitoring journalists. However, since that article focuses on the "spear phishing" method of entry via Gmail (the central premise of CrowdStrike's argument) instead of a zero-day exploit providing access to NGP VAN (Guccifer 2.0's own central premise), The Smoking Gun's perspective leaves me more confounded than enlightened.

As an independent blogger, I don't have the legal resources (or protections) available to writers at The Smoking Gun. So here's the response I gave (which is fair game, since I can quote myself without quoting the hacker):
Of course I'm interested, but I'll have to get some legal advice before sharing such documents publicly--or even reviewing them. I hope you're familiar with the U.S. government's "chilling effects" campaign and the way it impacted Barrett Brown. I fully intend to exercise all the rights I'm guaranteed as a U.S. citizen, but I'm unwilling to do anything illegal. I hope that's a satisfactory answer.
In fact, this post is far less about what Guccifer 2.0 said to me than what I said to him--and what I fear other bloggers with short memories (or shallow educations concerning recent U.S. history in the cybercrime arena) might have said instead.

Guccifer 2.0 appears to be overwhelmed by the amount of information at his disposal. If his situation is what he claims, then he needs help, and I hope that qualified journalists with the appropriate resources will give him just the help he needs.

However, an unsuspecting blogger who uncritically publicizes hacked information from an unknown source such as Guccifer 2.0 could very easily fall into a far worse trap than the one that landed Barrett Brown in jail.

I know I'm a broken record on this subject, but the Stratfor hack (which happened on Shawn Henry's watch at the FBI) brought all sorts of hacktivists together in a spirit of cooperation and trust. By connecting Hyriiyya (the still unidentified hacker with a zero-day exploit for cracking Stratfor) with Jeremy Hammond (the activist who was subsequently imprisoned for using that exploit) and Brown (the journalist who was subsequently imprisoned merely for posting a link to data made available through that exploit), the FBI's informant Hector Monsegur (aka Sabu) set hacktivism back even as he coordinated a stunt that seemed likely to advance its cause.

To this day, Monsegur claims that even though he was working as an FBI informant at the time of the Stratfor hack, AntiSec operated essentially on its own--without guidance from his FBI handlers.

But how can he know that?

How can he know that the person hiding behind the Hyrriiya screen name wasn't a government operative enticing him to do exactly what he ended up doing? As Ars Technica reports:
At the instruction of the FBI, Monsegur offered Hammond a server to store the data being extracted from Stratfor. Hammond agreed, and told others that they would use Monsegur's server as a "first base of operations" before moving it elsewhere.
It's undeniable that Henry's FBI allowed the Stratfor hack to proceed long after they knew it was underway, so why should we assume that they had nothing to do with selecting the target?

And why should we rule out the possibility that Guccifer 2.0 is a pawn (witting or unwitting) of Henry's CrowdStrike? If you think that's outrageous because Guccifer 2.0 only brings more attention to the DNC hack, which is a major source of embarrassment to CrowdStrike, think again. In the first place, the narrative from the DNC and CrowdStrike has put Henry's company in a no-lose situation because it wasn't brought in until after the breach was detected. In the second place, the Guccifer 2.0 story is receiving scant media coverage, and what little coverage it does receive has nothing to do with the leaked information itself. And in the third place, the entire Guccifer 2.0 affair could quite easily end up taking the air out of the forthcoming leak from WikiLeaks.

Like Sabu, Guccifer 2.0 comes across as a lovable hacktivist who is giving the finger to the powers that be in a world that is turning into one giant surveillance state before our eyes. Of course he's a sympathetic figure. Of course we want to help him. Of course he seems trustworthy: He's doing exactly what we all wish we could do by exposing what he's found behind a curtain of corruption.

But that doesn't mean we should trust him any more than Brown and Hammond should have trusted Monsegur.




Thursday, June 30, 2016

The Latest Leak from Guccifer 2.0 Goes Unnoticed by Media

As of 2 p.m. EST, a Google search for news on the latest Guccifer 2.0 leak returned just three results:

1) "Clinton hacker teases identity and calls Snowden and Assange heroes" (from International Business Times UK);
2) "DNC Hacker Denies Russian Link, Says Attack Was His 'Personal Project'" (from Motherboard); and
3) "Dem party hacker answers skeptics on nationality, politics" (from The Hill).

Please note that all three headlines accurately signal the purpose of the articles, which is to focus on the identity of Guccifer 2.0 instead of analyzing the information he leaked. (Note also that since Guccifer 2.0 identified himself as a male in his latest blog post, I will no longer use gender-ambiguous pronouns such as s/he to refer to him.)

Televised coverage of the latest leak from Guccifer 2.0 appears to be non-existent here in the U.S., and high-profile corporate print media outlets are staying mute.

It's almost as if CrowdStrike is suddenly as adept at controlling the national media as the Clinton machine has been for years. Weird.

So now seems like an opportune time to share the wisdom of a purported "professional penetration tester" named Nathan McGinty who commented on a sloppy article that Cory Doctorow churned out for BoingBoing immediately following the appearance of the Guccifer 2.0 blog. Near the middle of his lengthy comment, McGinty observes:
However, it is important to remember that a company such as CrowdStrike -- or Mandiant, with Sony -- a big gun, serves multiple roles in such an incident. First is to prevent further damage. Second is to gather evidence and gain attribution. Third is PR and damage control. The third job of CrowdStrike can at times be orthogonal to the public truth. Nowhere in their job description is included the public truth. There is no penalty (that I am aware of) for them to disclose a non-truth or shade the truth. Heck there's almost no penalty for a politician to do so, and they are ostensibly called upon to serve such a thing as the public truth. [Emphasis added.]
Either my Google-fu is weak or Nathan McGinty is a more common name than you might expect. But for whatever reason, I have been unable to contact Mr. McGinty to confirm his expertise or request further analysis concerning the DNC hack. (Unfortunately, comments on the Doctorow article are now locked, so I can't simply reply to McGinty's remarks.)

Whether McGinty is an expert pen tester or not, the fact remains that the DNC, the Clinton media machine, and CrowdStrike all share jobs that "can at times be orthogonal to the public truth." Since Clinton and the Democrats routinely push for war and Shawn Henry of CrowdStrike routinely uses scare-and-sell tactics to promote his approach to cyberdefense for "the homeland," we should all be wary of these articles that focus on whether Guccifer 2.0 is really a Russian spy or not. Even when the articles leave that question up in the air, they frame the discussion in such a way that Russian cyberespionage remains the central topic.
 
Obviously, the central topic of the Guccifer 2.0 discussion should be the materials he leaked. And that's the one topic that the DNC, the Clintons, and CrowdStrike all have a vested interest in burying, as they're doing right now with a little help from their friends in the corporate media.



Wednesday, June 29, 2016

The Gotcha Moment in Motherboard's Interview with Guccifer 2.0

On June 21st, Motherboard presented readers with two versions of their Guccifer 2.0 interview: a transcript and a summary.

Since both documents were prepared by the same writer (Lorenzo Franceschi-Bichhierai), I was surprised to discover that the summary and the transcript bear little resemblance to one another on the subject of Guccifer 2.0's facility with Romanian.

Of the summary's fourteen paragraphs, exactly one is dedicated to evaluating just how Romanian Guccifer 2.0's Romanian really is:
But when we asked him to explain to us how he hacked into the DNC in Romanian, he seemed to stall us, and said he didn’t want to “waste” his time doing that. The few short sentences he sent in Romanian were filled with mistakes, according to several Romanian native speakers.
Got that? He only gave them a "few short sentences" of Romanian before losing patience.

In fact, Guccifer replied in Romanian to eleven out of thirty questions. But instead of debating whether eleven qualifies as a "few" of anything, let's focus on the aggravating feature of Motherboard's sudden switch from Romanian to English to Russian in a transparent attempt to trick Guccifer 2.0 into exposing himself as the Russian cyberspy that CrowdStrike and the DNC say he is:
De ce faci toate astea? [Why are you doing this?]
Asta e din partea următoare [That's the next]
What?
Am spus deja, e un filigran, un semn special [I have already said, it's a watermark, a special sign]
Do you like Trump?
I don't care at all
кто-то говорит мне, что ты румынская полна ошибок [Someone tells me that your Romanian is full of mistakes.]
What's this? Is it russian?
You don't understand it?
R u kidding? Just a moment I'll look in google translate what u meant. "Someone tells me that you are full of mistakes Romanian."
Hai sa-ti pun cateva intrebari, ca sa vad ca esti cu adevarat roman [Let me ask you a few questions to see that you are truly native.]
Man, I'm not a pupil at school.
What do you mean?
If u have serious questions u can ask. Don't waste my time. 
Although I can understand Motherboard's impulse to do some linguistic sleuthing on an unknown source of unverified information, I can also understand Guccifer 2.0's display of impatience (under these circumstances) as far more justifiable than the summary made it out to be.

But is this seeming discrepancy even worth mentioning? Shouldn't our primary task concerning anything leaked in the public interest be to focus on what was leaked rather than who leaked it?  

I thought so a few days ago. I'm less certain now. As I see the Guccifer 2.0 story dissipating into background noise, it's plain that the main takeaway CrowdSource wanted to impose on the public is almost the only part of the story that is sticking in the public consciousness: "That DNC hack was probably done by Russians, though you can never tell with cybercrime, but it was definitely probably Russians, including that Guccifer 2.0, who was undeniably and indisputably part of a Russian disinformation campaign in all probability."

Even if Guccifer 2.0's claims regarding her/his ethnicity and first language are irrelevant (as I think they are, since hackers generally rely on anonymity and deception), it's still a good idea to keep facts separate from rumors. The fact is that Motherboard's interview proved nothing conclusive about Guccifer 2.0's Romanian-ness, and yet the interview was used to support rumors about the hacker being a Russian who couldn't convincingly impersonate a Romanian in an online interview with web translation tools at his disposal.

That's how things feel today. But I had a DM conversation with @Guccifer_2 this afternoon that makes me think things won't feel that way for long. More on that tomorrow. 



Wednesday, June 22, 2016

Is Guccifer 2.0 a Pseudohacktivist Puppet Working for Shawn Henry of CrowdStrike?

Earlier today, Guccifer 2.0 announced via his Twitter feed (@Guccifer_2) that he would accept and respond to direct messages.

Here's the DM I sent him:
Hi Gucc! I hope you are the real deal, but I worry that you may be a pseudohacktivist puppet working for Shawn Henry of CrowdStrike the same way Sabu turned out to be a pseudohacktivist puppet working for Shawn Henry of the FBI. Can you allay my concerns? (If you don't remember LulzSec and AntiSec, I can send you some articles.)
I'll update this post if s/he a) responds and b) gives me permission to share. Note that Guccifer 2.0 has already indicated that not all questions will be answered and that answers will appear on the Guccifer 2.0 blog.


Update #1 (12:52 p.m. EST): Guccifer 2.0 has replied to indicate that s/he will be answering the "most popular" questions he receives via DM, which suggests that if there is a question s/he doesn't want to answer s/he can simply claim that not enough people asked questions in that vein. I therefore encourage anyone who doubts the authenticity of a hacker whose "leaks" to this point have consisted mostly of information that is a matter of public record to DM @Guccifer_2 with iterations of the question I posted above.


Tuesday, June 21, 2016

Why Should We Doubt Anything Asserted by the DNC, Repeated by the Company They Hired (CrowdStrike), and Confirmed by that Company's Industry Partner (Fidelis)?

According to news sources all over the internet, the verdict is in concerning the hack of the Democratic National Committee. A headline from Business Insider UK reads "Yes, Russia Really Did Hack the Democratic National Committee." Similar headlines have poured in from other sources, such as The Washington Post ("Cyber researches confirm Russian government hack of Democratic National Convention"), Computerworld ("Russian hackers were behind DNC breach"), and Neowin ("The Russian government hacked the DNC after all").

Apparently the world can breathe a sigh of relief and rest assured that the matter has been settled once and for all.

These headlines are generated with such certainty primarily because a cybersecurity outfit called Fidelis has independently corroborated the assertions of CrowdStrike, the company hired by the DNC to mitigate the damage done by the breach.

But none of the stories attached to the headlines question how "independent" the analysis of Fidelis really is. Certainly none of them mention that Fidelis joined a 7-member intelligence exchange program sponsored by CrowdStrike in August of 2014. Nor do they point out that a press release from General Dynamics that same month characterized Fidelis and CrowdStrike as "partners" rather than competitors in the cybersecurity industry.

The Washington Post attempts to bolster its case by referring to a statement from Marshall Heilman, a researcher from Mandiant (long considered a genuine rival of CrowdStrike), according to which "the malware and associated servers are consistent with those previously used by 'APT 28 and APT 29,' which are Mandiant’s names for Fancy Bear and Cozy Bear, respectively."

The Post article doesn't explain how Heilman obtained his malware samples, but gives us a hint in its invocation of yet a fourth cybersecurity firm, ThreatConnect, which "followed up on CrowdStrike’s analysis by looking at computer Internet protocol addresses that CrowdStrike said it had found while investigating the DNC intrusion." (Neither Mandiant nor its parent company, Fireeye, responded to my queries about how Heilman obtained the DNC malware samples.)

So for those keeping score, we know that Russians hacked the DNC because 1) The DNC told us so; 2) CrowdStrike (the cybersecurity firm hired by the DNC) told us so; 3) Fidelis (one of CrowdStrike's industry partners) told us so; 4) Mandiant (based on an examination of malware samples presumably provided to them by CrowdStrike) told us so; and 5) ThreatConnect (based on an examination of IP addresses admittedly provided to them by CrowdStrike) told us so.




Thursday, June 16, 2016

Perhaps CrowdStrike : Guccifer 2.0 :: FBI : Sabu

Less than five years ago, when Shawn Henry headed cybercrime investigations for the FBI, he oversaw multiple cases involving an informant known as Sabu.

Numerous hacktivists (such as Jeremy Hammond) offered their assistance to Sabu because they assumed that his AntiSec movement worked in opposition to the FBI and the surveillance state.

Where did they get that idea? It may have had something to do with a weekly AntiSec event that took social media by storm: the #FuckFBIFriday campaign (a cointelpro operation that was in fact monitored by the FBI).

Many of Sabu's hacktivist accomplices failed to learn (until it was too late) that he was working for the FBI even as he whipped up hacktivist enthusiasm against the surveillance state.

As journalist Quinn Norton points out, just three days after the FBI shut down its AntiSec operation, Shawn Henry retired from his government post to join a cybersecurity company called CrowdStrike, the same outfit recently hired by the Democratic National Committee to investigate an alleged data breach.

Henry's CrowdStrike lost no time in blaming the breach on Russian hackers (supposedly associated with two groups known as "Cozy Bear" and "Fancy Bear"). Almost immediately, however, a real or fabricated hacker with the handle Guccifer 2.0 claimed individual responsibility for the theft of opposition research from the DNC concerning Donald Trump.

Just as Sabu was fond of showing public scorn for the FBI, Guccifer 2.0 enjoys taunting CrowdStrike: “Shame on CrowdStrike: Do you think I’ve been in the DNC’s networks for almost a year and saved only 2 documents? Do you really believe it?"

In fact, it wasn't enough for Guccifer 2.0 to boast about turning the hacked goodies over to WikiLeaks. The hacker contextualized that revelation within a direct jab at Henry's cybersecurity firm: "The main part of the papers, thousands of files and mails, I gave to WikiLeaks. They will publish them soon. I guess CrowdStrike customers should think twice about [the] company’s competence."

My title asserts something that I cannot prove--but that I nevertheless deeply suspect: that the relationship of Guccifer 2.0 to Shawn Henry's cybercrime outfit in 2016 (CrowdStrike) is precisely analogous to the relationship of Sabu to Shawn Henry's cybercrime outfit in  2011 (the FBI). And since we now know that the FBI was deeply complicit in the infamous Stratfor hack, I can't help wondering who's really responsible for the DNC breach.

So when Donald Trump suggests that instead of being hacked by outsiders, the DNC simply handed its opposition research over to CrowdStrike, I'm not as quick as those unfamiliar with Shawn Henry to dismiss his claim as conspiratorial fantasy.

Is Donald Trump irresponsible with his rhetoric? Plainly. Is he incendiary when it comes to interpreting the world around him for his rabid supporters? Certainly. But is he nuts for suggesting that the story we're getting from CrowdStrike and the DNC is more likely to be a devious media ploy than a genuine breach of cybersecurity? I'm not sure--because I've seen this page from Shawn Henry's playbook before.

Henry knows how to establish credibility for an informant by having that informant heap public scorn on the agency that controls him. Just because we know for a fact that it happened less than five years ago with Sabu doesn't mean that it's definitely happening now with Guccifer 2.0--but it could be.

Those who want to cheer Guccifer 2.0 should remember how Sabu betrayed Hammond and do their cheering from a safe distance.