Showing posts with label hacktivism. Show all posts
Showing posts with label hacktivism. Show all posts

Tuesday, June 21, 2016

Why Should We Doubt Anything Asserted by the DNC, Repeated by the Company They Hired (CrowdStrike), and Confirmed by that Company's Industry Partner (Fidelis)?

According to news sources all over the internet, the verdict is in concerning the hack of the Democratic National Committee. A headline from Business Insider UK reads "Yes, Russia Really Did Hack the Democratic National Committee." Similar headlines have poured in from other sources, such as The Washington Post ("Cyber researches confirm Russian government hack of Democratic National Convention"), Computerworld ("Russian hackers were behind DNC breach"), and Neowin ("The Russian government hacked the DNC after all").

Apparently the world can breathe a sigh of relief and rest assured that the matter has been settled once and for all.

These headlines are generated with such certainty primarily because a cybersecurity outfit called Fidelis has independently corroborated the assertions of CrowdStrike, the company hired by the DNC to mitigate the damage done by the breach.

But none of the stories attached to the headlines question how "independent" the analysis of Fidelis really is. Certainly none of them mention that Fidelis joined a 7-member intelligence exchange program sponsored by CrowdStrike in August of 2014. Nor do they point out that a press release from General Dynamics that same month characterized Fidelis and CrowdStrike as "partners" rather than competitors in the cybersecurity industry.

The Washington Post attempts to bolster its case by referring to a statement from Marshall Heilman, a researcher from Mandiant (long considered a genuine rival of CrowdStrike), according to which "the malware and associated servers are consistent with those previously used by 'APT 28 and APT 29,' which are Mandiant’s names for Fancy Bear and Cozy Bear, respectively."

The Post article doesn't explain how Heilman obtained his malware samples, but gives us a hint in its invocation of yet a fourth cybersecurity firm, ThreatConnect, which "followed up on CrowdStrike’s analysis by looking at computer Internet protocol addresses that CrowdStrike said it had found while investigating the DNC intrusion." (Neither Mandiant nor its parent company, Fireeye, responded to my queries about how Heilman obtained the DNC malware samples.)

So for those keeping score, we know that Russians hacked the DNC because 1) The DNC told us so; 2) CrowdStrike (the cybersecurity firm hired by the DNC) told us so; 3) Fidelis (one of CrowdStrike's industry partners) told us so; 4) Mandiant (based on an examination of malware samples presumably provided to them by CrowdStrike) told us so; and 5) ThreatConnect (based on an examination of IP addresses admittedly provided to them by CrowdStrike) told us so.




Thursday, June 16, 2016

Perhaps CrowdStrike : Guccifer 2.0 :: FBI : Sabu

Less than five years ago, when Shawn Henry headed cybercrime investigations for the FBI, he oversaw multiple cases involving an informant known as Sabu.

Numerous hacktivists (such as Jeremy Hammond) offered their assistance to Sabu because they assumed that his AntiSec movement worked in opposition to the FBI and the surveillance state.

Where did they get that idea? It may have had something to do with a weekly AntiSec event that took social media by storm: the #FuckFBIFriday campaign (a cointelpro operation that was in fact monitored by the FBI).

Many of Sabu's hacktivist accomplices failed to learn (until it was too late) that he was working for the FBI even as he whipped up hacktivist enthusiasm against the surveillance state.

As journalist Quinn Norton points out, just three days after the FBI shut down its AntiSec operation, Shawn Henry retired from his government post to join a cybersecurity company called CrowdStrike, the same outfit recently hired by the Democratic National Committee to investigate an alleged data breach.

Henry's CrowdStrike lost no time in blaming the breach on Russian hackers (supposedly associated with two groups known as "Cozy Bear" and "Fancy Bear"). Almost immediately, however, a real or fabricated hacker with the handle Guccifer 2.0 claimed individual responsibility for the theft of opposition research from the DNC concerning Donald Trump.

Just as Sabu was fond of showing public scorn for the FBI, Guccifer 2.0 enjoys taunting CrowdStrike: “Shame on CrowdStrike: Do you think I’ve been in the DNC’s networks for almost a year and saved only 2 documents? Do you really believe it?"

In fact, it wasn't enough for Guccifer 2.0 to boast about turning the hacked goodies over to WikiLeaks. The hacker contextualized that revelation within a direct jab at Henry's cybersecurity firm: "The main part of the papers, thousands of files and mails, I gave to WikiLeaks. They will publish them soon. I guess CrowdStrike customers should think twice about [the] company’s competence."

My title asserts something that I cannot prove--but that I nevertheless deeply suspect: that the relationship of Guccifer 2.0 to Shawn Henry's cybercrime outfit in 2016 (CrowdStrike) is precisely analogous to the relationship of Sabu to Shawn Henry's cybercrime outfit in  2011 (the FBI). And since we now know that the FBI was deeply complicit in the infamous Stratfor hack, I can't help wondering who's really responsible for the DNC breach.

So when Donald Trump suggests that instead of being hacked by outsiders, the DNC simply handed its opposition research over to CrowdStrike, I'm not as quick as those unfamiliar with Shawn Henry to dismiss his claim as conspiratorial fantasy.

Is Donald Trump irresponsible with his rhetoric? Plainly. Is he incendiary when it comes to interpreting the world around him for his rabid supporters? Certainly. But is he nuts for suggesting that the story we're getting from CrowdStrike and the DNC is more likely to be a devious media ploy than a genuine breach of cybersecurity? I'm not sure--because I've seen this page from Shawn Henry's playbook before.

Henry knows how to establish credibility for an informant by having that informant heap public scorn on the agency that controls him. Just because we know for a fact that it happened less than five years ago with Sabu doesn't mean that it's definitely happening now with Guccifer 2.0--but it could be.

Those who want to cheer Guccifer 2.0 should remember how Sabu betrayed Hammond and do their cheering from a safe distance.