Showing posts with label coordinated narrative. Show all posts
Showing posts with label coordinated narrative. Show all posts

Monday, July 18, 2016

The DNC Has "Deployed the Recommended" to Deal with Guccifer 2.0--Whatever That Means

Joe Uchill of The Hill has written three articles about Guccifer 2.0 since July 13th. All three conclude in much the same way (by reminding readers that unidentified sources consider Guccifer 2.0 to be part of a Russian disinformation campaign).

Here's the final paragraph of "Guccifer 2.0 releases new docs" (7/13):
“Our experts are confident in their assessment that the Russian government hackers were the actors responsible for the breach detected in April, and we believe that the subsequent release and the claims around it may be a part of a disinformation campaign by the Russians,” a senior DNC official said in a written statement.
Here's the antepenultimate paragraph of "Celeb phone numbers included in Guccifer 2.0 hack" (7/18):
Many have suggested that Guccifer 2.0 is a front for Vladimir Putin in the Russian leader’s efforts to influence American politics, something Guccifer 2.0 denies.
And here are the final two paragraphs of "New Guccifer 2.0 dump highlights 'wobbly Dems' on Iran deal" (7/18):
The DNC declined to issue a new comment but reiterated a prior statement from a senior official.

“Our experts are confident in their assessment that the Russian government hackers were the actors responsible for the breach detected in April,” that statement read, “and we believe that the subsequent release and the claims around it may be a part of a disinformation campaign by the Russians. We’ve deployed the recommended.”
Note that the last conclusion is almost identical to the first. However, Uchill knows better than to conclude two out of three articles on the same subject in less than a week in exactly the same way. So he presents the illusion of changing things up by moving the attribution of his unnamed source to the middle of the paragraph and tacking on a puzzling piece of extra information: "We've deployed the recommended."

The recommended what? It seems as though the article ends on a challenge to the reader to fill in the blank--something that's very easy to do if we remember one of Guccifer 2.0's earlier leaks concerning "Reporter Outreach" strategies from the DNC: "pitch stories with no fingerprints and utilize reporters to drive a message."

I therefore suspect that if Uchill had included the final sentence of his latest conclusion in full, it would have read something like this: "We've deployed the recommended strategy of ensuring that reporters muddy the waters around Guccifer 2.0 by concluding every single article they write about the hacker with speculation about his being part of a Russian disinformation campaign."


Tuesday, June 21, 2016

Why Should We Doubt Anything Asserted by the DNC, Repeated by the Company They Hired (CrowdStrike), and Confirmed by that Company's Industry Partner (Fidelis)?

According to news sources all over the internet, the verdict is in concerning the hack of the Democratic National Committee. A headline from Business Insider UK reads "Yes, Russia Really Did Hack the Democratic National Committee." Similar headlines have poured in from other sources, such as The Washington Post ("Cyber researches confirm Russian government hack of Democratic National Convention"), Computerworld ("Russian hackers were behind DNC breach"), and Neowin ("The Russian government hacked the DNC after all").

Apparently the world can breathe a sigh of relief and rest assured that the matter has been settled once and for all.

These headlines are generated with such certainty primarily because a cybersecurity outfit called Fidelis has independently corroborated the assertions of CrowdStrike, the company hired by the DNC to mitigate the damage done by the breach.

But none of the stories attached to the headlines question how "independent" the analysis of Fidelis really is. Certainly none of them mention that Fidelis joined a 7-member intelligence exchange program sponsored by CrowdStrike in August of 2014. Nor do they point out that a press release from General Dynamics that same month characterized Fidelis and CrowdStrike as "partners" rather than competitors in the cybersecurity industry.

The Washington Post attempts to bolster its case by referring to a statement from Marshall Heilman, a researcher from Mandiant (long considered a genuine rival of CrowdStrike), according to which "the malware and associated servers are consistent with those previously used by 'APT 28 and APT 29,' which are Mandiant’s names for Fancy Bear and Cozy Bear, respectively."

The Post article doesn't explain how Heilman obtained his malware samples, but gives us a hint in its invocation of yet a fourth cybersecurity firm, ThreatConnect, which "followed up on CrowdStrike’s analysis by looking at computer Internet protocol addresses that CrowdStrike said it had found while investigating the DNC intrusion." (Neither Mandiant nor its parent company, Fireeye, responded to my queries about how Heilman obtained the DNC malware samples.)

So for those keeping score, we know that Russians hacked the DNC because 1) The DNC told us so; 2) CrowdStrike (the cybersecurity firm hired by the DNC) told us so; 3) Fidelis (one of CrowdStrike's industry partners) told us so; 4) Mandiant (based on an examination of malware samples presumably provided to them by CrowdStrike) told us so; and 5) ThreatConnect (based on an examination of IP addresses admittedly provided to them by CrowdStrike) told us so.