Showing posts with label Russia. Show all posts
Showing posts with label Russia. Show all posts

Friday, September 16, 2016

The Claim that Guccifer 2.0 Is Part of a Disinformation Campaign Is Itself a Disinformation Campaign

Some folks say there was a time when the primary function of the mainstream media was to inform people.

That sounds pretty crazy in 2016, when the obvious function of the mainstream media is to keep us misinformed.

Consider Thomas Fox-Brewster's article in Forbes concerning Guccifer 2.0 earlier this week. Brewster, a journalist specializing in cybersecurity, couldn't be bothered to maintain the distinction between Guccifer and Guccifer 2.0 beyond the first sentence of his article.

An editorial appeal to journalistic style when it comes to shortening names after their first appearance might make sense under ordinary circumstances, but not in a case in which so many details have become blurry in the public mind.

Do most casual readers of the Forbes article really know the difference between Guccifer (who has recanted his claims of access to the clintonemail.com server) and Guccifer 2.0 (who has repeatedly demonstrated his access to internal documentation from the DNC)?

Regrettably, Guccifer and Guccifer 2.0 have morphed into a collective headache in the minds of readers who aren't sure which one (if either) has anything to do with the Clinton email scandal. (The correct answer is Guccifer, who discovered the clintonemail.com account when he hacked Sidney Blumenthal's AOL account.)

How many of the news aggregating applications that quote snippets from paragraphs 2-6 of Fox-Brewster's article (without including the first paragraph--as routinely happens with sample excerpts in Google searches) will insert [2.0] for clarification in a sentence such as this one: "By extension this would suggest Guccifer worked for Putin’s regime"?

Poll 100 Forbes readers. How many know the claim doesn't concern a Romanian hacker named Michel Lazar Lehel who is serving time in a Virginia prison? 

And does anyone really think that the way the mainstream media handles the Guccifer 2.0 story is meant to enlighten readers? On the contrary, it seems calculated to make us confused and susceptible to propaganda, as when Fox-Brewster writes:
America’s politicos fear Russia is attempting to disrupt the upcoming election. US intelligence specialists and security companies – most notably CrowdStrike – have blamed Russia for the attacks on the DNC. By extension this would suggest Guccifer worked for Putin’s regime. Guccifer has previously denied any association with the Russian government, whilst the latter has claimed innocence.
The blur cultivated by the stylistic standards to which Fox-Brewster adheres is typical of a mainstream media that wants to keep the public confused about the motives, reliability, and identity of Guccifer 2.0 instead of focused on the content of the material the hacker has revealed.

For instance, in CNN's 7-paragraph report on Guccifer 2.0's latest leak, Daniella Diaz uses her first paragraph to indicate that the authenticity of the material has not been confirmed ("released more DNC documents Tuesday that reportedly reveal more information about the group's finances"--emphasis added), her second to point out that the materials aren't "damaging," her third to acknowledge the resignation of Debbie Wasserman-Schultz as head of the DNC, her fourth (the centerpiece of the article) to warn readers against looking at the leaked materials--since they might include malware, her fifth to quote Donna Brazile's remarks about Donald Trump (an odd choice in an article that doesn't quote one word from its putative subject, Guccifer 2.0), her sixth to point out that Guccifer 2.0's conference remarks were delivered by proxy (an opportune spot to quote some of those remarks if the article is really about Guccifer 2.0 instead of Donna Brazile), and her seventh to repeat the obligatory claim that unnamed people somewhere in the world continue to assert that Guccifer 2.0 is probably a Russian operative (without mentioning that the loudest such people work for CrowdStrike and are therefore on the DNC payroll).

Use of passive constructions and unidentified sources is typical of mainstream media commentary on Guccifer 2.0, as in the latest piece of cyber-alarmism that Cory Bennett churned out for Politico:
Guccifer 2.0 has claimed responsibility for both the DNC and DCCC hacks, although multiple private cybersecurity firms have tied the digital assaults back to a hacking group known as “Fancy Bear,” which is believed to be connected to Russia’s military intelligence service. Researchers believe Guccifer 2.0 is a front for these Moscow-backed hackers.
The last thing a journalist in 2016 would want to do in such a paragraph would be to indicate WHO is doing the relevant believing or which specific researchers were consulted.

But the grand prize for nebulous attribution for the week has to go to the L.A. Times for resorting to meta-reporting instead of assertion concerning purported ties between Russian intelligence and DCLeaks (a website with ties of its own to Guccifer 2.0):
The emails were obtained by the website DCLeaks.com, which has been reported to have links to Russian intelligence, MSNBC reported.
See how that works? The L.A. Times isn't saying that DCLeaks has ties to Russian intelligence. In fact, it's not even saying that MSNBC says so. It's just saying that once upon a time, MSNBC said somebody else said so.

All of which is a tiresome but effective way of not engaging anything substantive about the leaks at all, which suits corporate journalists and their oligarchic sponsors just fine.











Friday, September 9, 2016

If You Don't Realize that Propaganda Trumps Truth, Then Somebody Needs to Tell You So a Few More Times

As Joseph Goebbels observed, "The most brilliant propagandist technique will yield no success unless one fundamental principle is borne in mind constantly - it must confine itself to a few points and repeat them over and over."

The propagandist relies on repetition--not evidence. And repetition appears to be doing the trick as far as public perception of Guccifer 2.0 is concerned.

Once upon a time (as recently as June of this year), there was no Guccifer 2.0.

Then Guccifer 2.0 appeared out of nowhere with a blog and some leaked documents.

Immediately, CrowdStrike (which is a private cybersecurity firm, not a governmental agency) warned us that Guccifer 2.0 might be a Russian cyberspy. Note that in this first, tentative effort to overwrite reality with propaganda, CrowdStrike relied on a whether-or-not construction to articulate the accusation without quite asserting it: "Whether or not [the Guccifer 2.0 blog] is part of a Russian Intelligence disinformation campaign, we are exploring the documents’ authenticity and origin."

CrowdStrike's leaders (including former FBI Assistant Director Shawn Henry, who revolving doored his way into the presidency of a cybersecurity firm shortly after retiring from his government post in 2012) never got around to commenting on the authenticity of the leaked documents, but they lost no time in assembling a squadron of cybersecurity experts at similar firms who were willing to repeat the claims about Russian agency--based on the analysis of data provided to those firms by CrowdStrike.

Meanwhile, Guccifer 2.0 claimed to be a lone Romanian hacker who had named himself after the original Guccifer (also Romanian) as a point of national pride.

We shouldn't trust Guccifer 2.0. He's a hacker who has all sorts of motives for concealing his identity. But neither should we trust CrowdStrike. They were brought in to handle the DNC data breach after it was detected, which suggests that their role in this affair has more to do with managing public relations than keeping data secure.

So it wouldn't matter at all to me if people responded skeptically to both positions by saying, "Who knows whether Guccifer 2.0 is Russian or Romanian?"

But that's not what people are saying because they haven't heard Guccifer 2.0's side of the story--even though they've heard CrowdStrike's assertions about Russian operatives from the New York Times, the Wall Street Journal, and every major television network in the country.

This disheartening phenomenon was evident yesterday in one reader's comment on an article from Russia Today about how frustrated Guccifer 2.0 claims to be about the media's obsession with linking him to Russia:

Even though the comment plainly comes from a reasonable perspective, the writer appears to be completely unaware that Romania is even in contention as Guccifer 2.0's nation of origin. No one should be faulted for distrusting Guccifer 2.0. (I distrust him too!) But those who are interested in the story of whether he really is Russian should at least be familiar with what the hacker himself has claimed on the subject.

If the media's role is to inform us, then readers who are engaged enough by the Guccifer 2.0 story to comment on it should be able to demonstrate an awareness of the most basic claims being made by those involved.

But our media's job is not to inform us. Its job is to manufacture consent among the common folks for the agenda of the elites. And since the war profiteers backing Hillary Clinton's candidacy are eager to take us to war with Russia as soon as she is elected, the media's primary job in connection with Guccifer 2.0 is to use the hacker as evidence that America is already under attack.

The more frequently our newspapers and television pundits repeat that our electoral process is being manipulated by Vladimir Putin, the easier it will be to manufacture public consent for escalating the current proxy war in Syria into something bigger and more profitable (much as the the proxy war in Spain in the 1930s escalated into World War 2).

In January of 2017, after we're well and truly on the warpath against Russia, what will happen if a Romanian hacker surrenders himself to authorities to prove that he really was the lone individual responsible for the DNC leaks?

We'll go to war anyway. That much is obvious. But it's equally obvious that millions of Americans will say, "If he was just some random Romanian all along, why didn't anybody tell us so?"

He did tell us so. But realities that aren't discussed always seem less convincing than fictions that are.










Monday, August 1, 2016

Politifact Uses Sneaky Language (and Sneakier Punctuation) to Present Speculation as Fact in DNC Breach

Yesterday, Politifact's Lauren Carroll released an article entitled "What we know about Russia's role in the DNC email leak." The purpose of the article is to make speculation seem more factual than it is.

Carroll is an artful writer who knows how to create the illusion of objectivity by placing almost all (but not quite all) of her quoted material within quotation marks. She also understands how balanced it makes her article seem for her to begin and end with arguments (one from Julian Assange and the other from Jeffrey Carr) that challenge its preconceived conclusion.

Carroll certainly seems meticulous in the presentation of her evidence with paragraphs such as this one:
"The consensus that Russia hacked the DNC is at this point, very strong, albeit not unanimous," said cybersecurity consultant Matt Tait, who has been critical of Clinton's email practices. "The consensus that Russia hacked the DNC in support of Trump is, by contrast, plausible, but something for which the jury at this stage is very much still out."
Did you notice all the signifiers of non-partisan objectivity? First, Tait is no shameless Clinton surrogate, since he dares to be critical of her patently careless email practices. Second, he admits that the consensus about Russia's guilt isn't unanimous. And third, he is positively eager to concede the point that even if Russia is responsible for the DNC breach, that doesn't mean the purpose of the hack was to support Trump in the election (which suggests that asking "Have you stopped beating your wife?" is more reasonable than asking "Have you stopped beating your wife for her bad singing voice?" because the former question doesn't foreclose possible answers with as much specificity as the latter).

Caroll is equally artful in her construction of this paragraph:
The U.S. government is not ready to publicly name the suspected perpetrators behind the DNC hack, but the New York Times has reported that intelligence agencies have "high confidence" regarding the Russian government's involvement.
See what she did there? She's a responsible journalist who recognizes and maintains distinctions between the accusations of private cybersecurity companies (such as CrowdStrike) and the findings of official government intelligence agencies. But she also wants her readers to know that even though she can't say the U.S. government blames Russia for the attack, the New York Times says it (which is analogous to the argument that Clinton campaign chairman Robby Mook used to support his redbaiting analysis of the breach on CNN on July 24th: "This isn't my assertion; there are a number of experts that are asserting this").

However, Carroll is at her most artful not when she couches quotations in slanted ways, but when she eschews quotation marks entirely so as to blur her own voice (the voice of a presumably disinterested journalist) with the voice of her interviewees (some of whom are shameless partisan shills):
Translation: The agencies have likely corroborated the technical evidence with other intelligence, like human or financial sources, said Susan Hennessey, a Brookings Institution fellow and a former lawyer for the National Security Agency.
As of yet, there’s no evidence anyone other than Russia breached the DNC. So unless someone hacked the Russian agencies, the Russian government is likely WikiLeaks’ source, Hennessey said. Additionally, Assange and the Russian government have a well-documented relationship, for example the fact that Assange has hosted a television show on RT, a state-owned network. [Emphasis added.]
Just look at the first sentence of that second paragraph (the one in bold type), and ask yourself what effect it's likely to have on most readers skimming through the article. It completely dispenses with the question of whether Russia is behind the DNC breach by wondering only whether any other entities might also have participated. And the absence of quotation marks doesn't even warn readers that the incredibly lazy logic of such an argument belongs to Susan Hennessey rather than Lauren Carroll--not until they reach the end of the next sentence (which some skimmers never do).

The most positive thing I can say about Carroll's article is that it at least mentions Jeffrey Carr, whose "Can Facts Slow The DNC Breach Runaway Train?" is the single most cogent analysis of the DNC breach written from the perspective of someone with the relevant technological expertise.

I can't say the Politifact article is bad because it's actually a brilliant example of propaganda. Carroll has chops as a writer; she knows better than to try to jam an argument down her readers' throats without first coating it in FD&C Yellow #34 (a synthetic coloring and flavorizer designed by muckrakers to make arguments taste more objective than they are). So read the Politifact article if you want to know what the corporate media wants you to think about the DNC breach.

But read Carr's article if you want reasoned, relevant analysis.


Friday, July 1, 2016

Even if Guccifer 2.0 Is a Disinformation Puppet, Russians Aren't Necessarily the Ones Pulling His Strings

Anything is possible with Guccifer 2.0. He may be an independent Romanian hacker (as he says). He may be part of a disinformation campaign managed by Russia (as CrowdStrike suggests). He may even be part of a disinformation campaign managed by CrowdStrike (as I fear). Given the secrecy with which hackers necessarily cloak themselves, there are infinite other possibilities.

After Guccifer 2.0 posted his latest leak in the early hours of June 30th, corporate media was silent about the freshest documents--but loud about wondering whether Guccifer 2.0 is who he says he is or who CrowdStrike says he is (as if there are no other possibilities). Here's a representative paragraph from an Inverse article that received a lot of attention yesterday:
CrowdStrike said it is investigating whether the hacker’s public statements are part of a Russian disinformation campaign or just a lone hacker looking to steal credit, but as of June 15, they said their internal findings that Guccifer 2.0 was connected to Russian intelligence services had not changed.
Is the purpose of that paragraph to raise questions about Guccifer 2.0 in the spirit of open and honest inquiry--or to foreclose discussion by setting up a false dichotomy?

Based on a DM exchange I had with Guccifer 2.0 two days ago, I remain concerned about the possibility that he is neither who he says he is nor who CrowdStrike says he is.

In the course of our conversation, Guccifer 2.0 gave me permission to summarize his remarks as long as I don't quote him directly. It's a weird request, but one that I'll honor just in case he turns out to be genuine.

The most thrilling (and terrifying) moment of the conversation came when he offered to send me hacked files from the DNC for analysis on my blog. I suspect (though he didn't say so) that he made similar arrangements with The Smoking Gun for the article that appeared on the 28th concerning the Clinton campaign's method of monitoring journalists. However, since that article focuses on the "spear phishing" method of entry via Gmail (the central premise of CrowdStrike's argument) instead of a zero-day exploit providing access to NGP VAN (Guccifer 2.0's own central premise), The Smoking Gun's perspective leaves me more confounded than enlightened.

As an independent blogger, I don't have the legal resources (or protections) available to writers at The Smoking Gun. So here's the response I gave (which is fair game, since I can quote myself without quoting the hacker):
Of course I'm interested, but I'll have to get some legal advice before sharing such documents publicly--or even reviewing them. I hope you're familiar with the U.S. government's "chilling effects" campaign and the way it impacted Barrett Brown. I fully intend to exercise all the rights I'm guaranteed as a U.S. citizen, but I'm unwilling to do anything illegal. I hope that's a satisfactory answer.
In fact, this post is far less about what Guccifer 2.0 said to me than what I said to him--and what I fear other bloggers with short memories (or shallow educations concerning recent U.S. history in the cybercrime arena) might have said instead.

Guccifer 2.0 appears to be overwhelmed by the amount of information at his disposal. If his situation is what he claims, then he needs help, and I hope that qualified journalists with the appropriate resources will give him just the help he needs.

However, an unsuspecting blogger who uncritically publicizes hacked information from an unknown source such as Guccifer 2.0 could very easily fall into a far worse trap than the one that landed Barrett Brown in jail.

I know I'm a broken record on this subject, but the Stratfor hack (which happened on Shawn Henry's watch at the FBI) brought all sorts of hacktivists together in a spirit of cooperation and trust. By connecting Hyriiyya (the still unidentified hacker with a zero-day exploit for cracking Stratfor) with Jeremy Hammond (the activist who was subsequently imprisoned for using that exploit) and Brown (the journalist who was subsequently imprisoned merely for posting a link to data made available through that exploit), the FBI's informant Hector Monsegur (aka Sabu) set hacktivism back even as he coordinated a stunt that seemed likely to advance its cause.

To this day, Monsegur claims that even though he was working as an FBI informant at the time of the Stratfor hack, AntiSec operated essentially on its own--without guidance from his FBI handlers.

But how can he know that?

How can he know that the person hiding behind the Hyrriiya screen name wasn't a government operative enticing him to do exactly what he ended up doing? As Ars Technica reports:
At the instruction of the FBI, Monsegur offered Hammond a server to store the data being extracted from Stratfor. Hammond agreed, and told others that they would use Monsegur's server as a "first base of operations" before moving it elsewhere.
It's undeniable that Henry's FBI allowed the Stratfor hack to proceed long after they knew it was underway, so why should we assume that they had nothing to do with selecting the target?

And why should we rule out the possibility that Guccifer 2.0 is a pawn (witting or unwitting) of Henry's CrowdStrike? If you think that's outrageous because Guccifer 2.0 only brings more attention to the DNC hack, which is a major source of embarrassment to CrowdStrike, think again. In the first place, the narrative from the DNC and CrowdStrike has put Henry's company in a no-lose situation because it wasn't brought in until after the breach was detected. In the second place, the Guccifer 2.0 story is receiving scant media coverage, and what little coverage it does receive has nothing to do with the leaked information itself. And in the third place, the entire Guccifer 2.0 affair could quite easily end up taking the air out of the forthcoming leak from WikiLeaks.

Like Sabu, Guccifer 2.0 comes across as a lovable hacktivist who is giving the finger to the powers that be in a world that is turning into one giant surveillance state before our eyes. Of course he's a sympathetic figure. Of course we want to help him. Of course he seems trustworthy: He's doing exactly what we all wish we could do by exposing what he's found behind a curtain of corruption.

But that doesn't mean we should trust him any more than Brown and Hammond should have trusted Monsegur.