Showing posts with label anonymous. Show all posts
Showing posts with label anonymous. Show all posts

Monday, October 16, 2017

"Not The Russians" - British MPs Blame Iran For "Brute Force" Hack

Yet another purported example of Russia-linked hackers infiltrating the email accounts of powerful government officials    has been conclusively debunked.


The Guardian is reporting that a June incident where the accounts of dozens of UK ministers of parliament were infiltrated by shadowy hackers has been traced back to Iran. The UK intelligence community’s initial conclusion – that the attacks originated in Russia – has been refuted by an as-yet-unpublished report on the incident compiled by British intelligence.


Indeed, the intelligence community’s initial assumption appears to be another example of investigators jumping to a conclusion before a thorough analysis of the evidence has been completed. In a way, it echoes the response by several US states last month to the revelation that hackers had attempted to compromise their voting systems. Some states, including California and Wisconsin, apparently assumed the attacks were linked to Russia, until DHS informed them that it had found no evidence to support this conclusion.



The June 23 cyberattack affected the accounts of dozens of MPs, including Prime Minister Theresa May and several senior other senior ministers. The network that was compromised is used by every MP for interactions with constituents, the Guardian reported.


Initially, UK intelligence determined that hackers had attempted to gain access to accounts protected by weak passwords – despite repeated warnings to choose strong, hard-to-crack passwords.


An anonymous “security source” cited by the Guardian said the hackers used unsophisticated “brute force” attacks where the hackers use specifically designed programs to test out hundreds of thousands of different passwords combinations. “It was a brute-force attack. It appears to have been state-sponsored. The nature of cyber-attacks means it is notoriously difficult to attribute an incident to a specific actor.”


Conservative MP Andrew Bridgen added that the attack “absolutely” could leave some people open to blackmail. “Constituents want to know the information they send to us is completely secure,” he said.


Initially, suspicion had fallen upon foreign governments such as Russia and North Korea, both of which have been accused of orchestrating previous hacking attempts in the UK.


Liam Fox, the international trade secretary, said the incident reinforced the notion that MPs need to take extra precaution when securing their data.


“We know that our public services are attacked, so it is not at all surprising that there should be an attempt to hack into parliamentary emails,” he said. “And it’s a warning to everybody, whether they are in parliament or elsewhere, that they need to do everything possible to maintain their own cybersecurity.”


Given the furor that erupted after DHS ordered US government agencies to immediately remove security software designed by Russia-based firm Kaspersky Labs, the revelation about Iran’s involvement in the UK hacks should give intelligence agencies – not to mention lawmakers who seemingly blame Russia for every incidence of cyber meddling uncovered by US intelligence – pause. After the WSJ reported that Kaspersky’s software was essentially being leveraged by the Russian government to create an international spy network, German intelligence announced that they had found no evidence to support this claim.


And while many have blamed Russia-linked hackers for last year’s hack of DNC emails, including emails sent by Hillary Clinton Campaign Chairman John Podesta, Wikileaks’ Julian Assange is reportedly offering President Donald Trump conclusive evidence that he says would debunk this claim.


However, Chief of Staff John Kelly has rebutted one Congressman’s attempts to bring the deal to President Trump. But as the multiple investigations into whether Trump campaign colluded with the Russian government to sway the election in the president’s favor have apparently hit a wall, Assange’s evidence might be the key to silencing these suspicions, which have cast an unsubstantiated pall of illegitimacy over Trump’s first term in office.
 

Friday, July 28, 2017

How To Stay Hidden Online, In A World Of Hackers & Snoopers

How To Stay Hidden Online, In A World Of Hackers & Snoopers

Image source: Pixabay.com



Are “privacy” and “anonymity” mere synonyms, at least, when placed in the context of online safety and IT security? Simply put, no. While privacy and anonymity may have similar tradecraft practices and protocols, the very heart of their differences lay in the desired objective.


Perhaps the most succinct way to tell the two apart is this: think of online privacy measures as a defensive deployment to deter attackers that operate under the stealth of anonymity. In other words …


Privacy uses an active approach to prevent the leakage of data, which is usually executed at the software level. It’s a bit like using camouflage so that the bombers can’t find your bunker.


Anonymity is what makes a stealth bomber, stealthy. Whatever that bomber decides to do next, however, is up to the bomber. Whether or not it decides to kill its target or not, it is kept safe because stealth (anonymity) means missiles can’t find it.


Discover How To Become Invisible In Today’s Surveillance State!


One such service that employs these tactics would be Protonmail. Their end-to-end encryption of your email keeps your communications private. However, their proxy-server location in Switzerland ensures that even if the NSA wanted to take a peek at who sent an email, they’d have no idea who they actually were looking at.


What Is Online Privacy?


  • Privacy is seen as an objective with higher legitimacy.

  • In a traditional modern democracy, government agencies aren’t usually allowed by law to invade the digital privacy of law-abiding individuals (and would only do so in secret).

  • Privacy is seen as a defensive security measure.

  • Privacy can be achieved through the use of firewalls, ad-blockers, anti-malware and anti-virus software, and other deterrents to data mining and individual attackers.

What Is Online Anonymity?


  • Anonymity is the mode-of-operation.

  • Anonymity is often used to prevent governments from tracking the individual’s online activities via the use of special networks, such as Tor and VPN services. In this sense, online anonymity is a lifeline to intelligence operatives and reporters in hostile countries.

Everyone Can Be Found. Not Everyone Wants to Try That Hard.


Whether you seek a titanium wall of privacy or total anonymity, it’s important to realize that the moment an impregnable system exists, it’s already on its deathbed. The world of IT security and Internet privacy is one that is ruled by a gargantuan arms race. Regardless of how strong and robust the defenses, any digital castle can be brought to its knees if an attacker possesses the necessary determination to do so. For this reason, the winner in this game tends to be the stealthy, swift sniper, and not the slow, massive tank.


Goofy Gadget Can Recharge Your Laptop — And Jump-Start Your Car!


Wired’s Andy Greenberg, in an article titled How to Be Anonymous Online, argued that by using “cryptographic anonymity tools to hide your identity,” network eavesdroppers “may not even know where to find your communications, let alone snoop on them.”


“Hide in the network,” security guru Bruce Schneier said. “The less obvious you are, the safer you are.”


However, it’s not always about the software, adding layer after layer of protections, rerouting your communications from node to node, bouncing your data packets from Beijing to Jamaica in order to access some private server in Sweden. It’s about being a needle in a field of needles. It’s about not being noticed by the people who may be looking for you. It’s about achieving the transformation into a non-obvious digital being just like the rest of them, and blending in with the billions of others in the information sea.


To trade your uniqueness is engaging in this global shell-game of titanic proportions, the Holy Grail of digital anonymity.


What are your best tips for staying anonymous online? Share your advice in the section below:


You’re Being Watched: 7 Sneaky Ways The Government Is Tracking Your Every Move. Read More Here.

Tuesday, May 23, 2017

Seth Rich Plot Thickens: "DC Insider" Speaks Of "Complete Panic" At Highest Levels Of DNC

Last week, Fox News dropped a bombshell report officially confirming, via anonymous FBI sources, what many had suspected for quite some time, that murdered DNC staffer Seth Rich was the WikiLeaks source for leaks which proved that the DNC was intentionally undermining the campaign of Bernie Sanders. In addition to exposing the corruption of the DNC, the leaks cost Debbie Wasserman Shcultz her job as Chairwoman.


Of course, if it"s true that WikiLeaks" emails came from a DNC insider it would end the "Russian hacking" narrative that has been perpetuated by Democrats and the mainstream media for the past several months.  Moreover, it would corroborate the one confirmation that Julian Assange has offered regarding his source, namely that it was "not a state actor."


Meanwhile, the plot thickened a little more over the weekend when Kim Dotcom confirmed via Twitter that he was working with Seth Rich to get leaked emails to WikiLeaks.




Which was followed up by the following posts on 4Chan’s /pol/ subgroup that high-ranking current and former Democratic Party officials are terrified of the Seth Rich murder investigation.





“Anons, I work in D.C.



I know for certain that the Seth Rich case has scared the shit out of certain high ranking current and former Democratic Party officials.



This is the reason why they have backed away from impeachment talk. They know the smoking gun is out there, and they’re terrified you will find it, because when you do it will bring the entire DNC, along with a couple of very big name politicians.



It appears that certain DNC thugs were not thorough enough when it came time to cover their tracks. Podesta saying he wanted to “make an example of the leaker” is a huge smoking gun.”



The post went on to claim that a "smoking gun in this case is out of the hands of the conspirators" which has resulted in near "open panic" in DC circles.





“The behavior is near open panic. To even mention this name in D.C. Circles [sic] will bring you under automatic scrutiny. To even admit that you have knowledge of this story puts you in immediate danger.



If there was no smoke there would be no fire. I have never, in my 20 years of working in D.C. Seen [sic] such a panicked reaction from anyone.



I have strong reason to believe that the smoking gun in this case is out o [sic] the hands of the conspirators, and will be discovered by anon. I know for certain that Podesta is deeply concerned. He’s been receiving anonymous calls and emails from people saying they know the truth. Same with Hillary.”



And here is the original tweet:




Meanwhile, Kim Dotcom has promised more information will be released on his interaction with Seth Rich by tomorrow.




This raises several questions.  First, if Kim Dotcom knew that Seth Rich was, in fact, the WikiLeaks source, why is he just now coming forward with such information?  Second, while Seth Rich may explain the DNC leaks we still don"t know who is responsible for the "Podesta Files" which we"re certain will continue to be attributed to "Russian hackers."


Which leads to the most improtant queistion of all: is this all just another fake news diversion, or is there more to the Seth Rich murder?

Thursday, May 11, 2017

How World War 3 Will Happen: “The citizen will be the last to know.” (VIDEO)

How World War 3 Will Happen: “The citizen will be the last to know.” (VIDEO) | world-war-3 | Anonymous Multimedia Special Interests US News War Propaganda World News


Anonymous has released a video that puts all the pieces into place – and those pieces point straight to World War 3.


Unlike the proxy wars fought in Syria and Afghanistan, Anonymous says of the upcoming conflict.



“…There will be ground troops. The battle is likely to be fierce, brutal and quick. It will also be globally devastating, both on the environmental and economic levels. This is a real war with real global consequences.”




In  Part 1 of the World War 3 series, we talked about likely shortages and effects on Americans.  Part 2 of the series discussed an offshore conflict.


In this part, Anonymous clearly lays out the chilling path that will lead to the beginning of a war like nothing the world has ever seen. We’ve already witnessed the “drills” and “tests” of different country’s weapons systems. Japan has issued a warning to its citizens that they’ll only have a 10-minute warning should a nuclear strike occur.


Australia..


North Korea…


South Korea…


China…


Japan…


It’s escalating. Here’s what we can expect next.



Time is running out to prepare for what could be a dire future.


Are you prepared for what comes next?  It’s going to be brutal. There will be many casualties, both military and civilian.


If you can’t look at your preps and say, “Yeah, I’m absolutely ready for food shortages, gasoline shortages, and conflict in the streets,” sign up today for our next Prepping Intensive or Advanced Prepping Intensive. You can talk to experts who have lived through the worst case scenarios and learn vital information that could mean the difference between life and death. The guest speakers influenced me so profoundly that I changed our entire long-term survival plan.


Check out the rest of the World War 3 Series.



Part 1: Is World War 3 Coming? 18 Preppers Discuss Effects, Shortages, and How to Get Ready


Part 2: How to Survive World War 3: Prepping for an Off-Shore Conflict


Part 3: How World War 3 Will Happen: “The citizen will be the last to know.”


Part 4: How to Survive World War 3: Prepping in Case the Fight Comes to Us (coming soon – sign up for the newsletter so you don’t miss it!)

Wednesday, May 10, 2017

Mainstream Media Freaks out over New Anonymous Video Predicting WWIII

(ANTIMEDIA) The hacktivist group known as Anonymous is almost impossible to nail to the wall. The computer whizzes have undergone a huge transformation since their humble beginnings, and today the beast that once brought major corporate and government websites to their knees seems to be content growling in the shadows. Former leader Christopher X is on the run in Canada, and the collective appears to have moved on to other interests. They did a lot of sabre-rattling during the 2016 election but came up with little ground-shaking information.





However, the mainstream media hasn’t forgotten that with the right group of hackers assembled for an “operation,” the group can still be dangerous, and when a YouTube channel using the Anonymous banner uploaded a video last week, people took notice.




In the video, the group warned of an upcoming world war, declaring “all the signs of a looming war on the Korean peninsula are surfacing.”







The video continues:


“Unlike past world wars, although there will be ground troops, the battle is likely to be fierce, brutal and quick.”


What follows is a brief run-down of the escalating situation on the Korean peninsula; however, there is little new information other than the suggestion that Australia will play a pivotal role in the coming confrontation.







Mainstream news sites had a field day with the Anonymous video. Since it was the first time the group has spoken in a while, every outlet was eager to push a story. Pieces summarizing the video appeared on The Daily Mail, The New York Post, The Independent, and a number of other sites. The Courier Mail‘s Facebook page described the video as “chilling.” Even the right-leaning Drudge Report linked to the story.


anonymous


Of course, there’s always a good chance that Anonymous has inside information–that they’ve hacked into the Pentagon and listened in on Trump and his generals talking war. However, if they have, they didn’t share it in this video. But, eager to get a few clicks, the mainstream media has sensationalized headlines and helped us remember that the Guy Fawkes mask is never far away — and neither is the mainstream’s penchant for pushing fear-based narratives about war.


Creative Commons / Anti-Media / Report a typo






'Anonymous' Issues Ominous World War 3 Warning: "The Citizens Will Be The Last To Know"

Using their signature Guy Fawkes character, the infamous hacktivist group Anonymous has issued an ominous new video - warning people around the world to "prepare" for World War 3 as the US and North Korea continue to move "strategic pieces into place" for battle.





All the signs of a looming war on the Korean Peninsula are surfacing... we’re watching as each country moves strategic pieces into place... but unlike past world wars... although there will be ground troops the battle is likely to be fierce, brutal and quick.



It will also be globally devastating on the environmental and economic levels.



... This is a real war with real global consequences... With three super powers drawn into the mix... Other nations will be coerced into choosing sides.



... The citizens will be the last to know...



As The New York Post reports, Anonymous - described online as a global network of hackers, intent on spreading “facts the government doesn’t want you to know” - claims the US and South Korea have been working together to keep the peace in the region, along with China and the Philippines, but their pleas have fallen “on deaf ears.”





They claim that the Trump administration has been also working closely with the Australians, sending a rotational deployment of more than 1,000 US troops to the country, along with a large fleet of military aircraft. Australia is ultimately considered to be a “strategic location in the Indian ocean,” Anonymous says.



“The citizen will be the last to know, so it is important to understand what the other nations are doing,” the group states, citing China’s warning last week to its people in the North. “The pragmatic Chinese, it seems, are starting to lose their patience.”



Another surefire sign that war is imminent, according to Anonymous, are the recent talks between President Trump and Philippines President Rodrigo Duterte.



The group concludes the video with an eerie message for those watching around the world.





“Prepare for what comes next,” they say. “We are Anonymous. We are Legion. We do not forgive. We do not forget.”




As SHTFplan.com"s Mac Slavo points out, both China and Russia are mobilizing troops to the North Korean border, and the United States now has a Naval strike group directly off the coast of the rogue state. With the North threatening to continue testing missiles and weapons of mass destruction, and the Trump administration officially stating that past policies of “patient diplomacy” no longer apply, it appears confrontation is imminent.


North Korea has responded to President Trump’s deployment of an aircraft carrier, surveillance drones and missile tests by saying that if even a single bullet is fired they will nuke the United States.


The geo-political strain in the region could lead to any number of potential triggers. The growing concerns have not gone unnoticed in Japan, which recently saw panic buying of emergency shelters and air purifiers skyrocket.


In the United States, retailers report that the sale of NBC/CBRN gas masks and anti-radiation pills has spiked in recent weeks amid fears of impending global disaster.


Elite billionaires are building bunkers and long term preparedness plans to survive disaster, while governments around the world are positioning pieces on the grand chessboard.


All signs point to serious trouble in the very near future.


The world sits on the brink of a war unlike anything mankind has ever witnessed.

Tuesday, May 9, 2017

Anonymous Warns: ‘Globally Devastating’ World War III This Year

Anonymous Warns: ‘Globally Devastating’ World War III This Year


World War III will start this year and will begin on the Korean peninsula, the hacker group Anonymous has predicted.


“All the signs of a looming war on the Korean peninsula are surfacing,” a masked spokesperson for the anarchist hacker group says in a YouTube video. “Watching as each country moves strategic pieces into place, but unlike past world wars, although there will be ground troops, the battle is likely to be fierce, brutal and quick.”


Are You Prepared For A Downed Grid? Get Backup Electricity Today!


“This is a real war with global consequences, with three superpowers drawn into the mix,” the Anonymous spokesperson said. “Other nations will be coerced into choosing sides.”



The spokesperson added that it “will also be globally devastating on the environmental and economic levels.”


Anonymous believes war is imminent because of the deployment of US F-22 Stealth fighters to Australia, a U.S. test of a Minuteman III Intercontinental Ballistic Missile (ICBM), and the Chinese government’s order for its citizens to leave North Korea, The Independent reported. The group also raised the possibility of a preemptive Japanese strike on North Korea.


What is your reaction? Share it in the section below:   

Saturday, May 6, 2017

France Warns Media Not To Publish Hacked Macron Emails, Threatens With Criminal Charges

After 9 gigabytes of Macron-linked documents and emails were released on an anonymous pastebin website on Friday afternoon in what Macron"s campaign said was a "massive and coordinated" hacking attack, France - fearing a similar response to what happened with Hillary Clinton after 35,000 John Podesta emails were released one month before the US presidential election - cracked down on the distribution of the files, warning on Saturday it would be a "criminal offense" to republish the data, and warning the French media not to publish content from any of the hacked emails "to prevent the outcome of the vote being influenced."



Quoted by Reuters, the French election commission said in a statement that "on the eve of the most important election for our institutions, the commission calls on everyone present on internet sites and social networks, primarily the media, but also all citizens, to show responsibility and not to pass on this content, so as not to distort the sincerity of the ballot." Following a rushed meeting on Saturday morning, the commission which supervises the electoral process, said that the data been "fraudulently obtained and could be mixed with false information." It is unclear, however, how it hopes to enforce any punitive claims, especially when much of the initial document distribution appears to have taken place offshore.


Domestically, in a similar reaction to the US media"s response to the Podesta emails, French TV news channels chose not to mention the hack, although the left-leading Liberation prominently featured the news on its website. Liberation author Cedric Mathiot wrote that the leak, and its timing, "wants to create chaos" adding that the information was distributed in an "unethical method."


On Friday night, as news of what has been hashtagged as @MacronLeaks on twitter spread, Florian Philippot, deputy leader of the National Front, tweeted "Will Macronleaks teach us something that investigative journalism has deliberately kept silent?" In a tweeted response, Macron spokesman Sylvain Fort called Philippot"s tweet "vile".


In another parallel to the Clinton leaks, Macron"s En Marche! party said the leaked documents dealt with "the normal operations of a campaign and included some information on campaign accounts." It said the hackers had mixed false documents with authentic ones to "sow doubt and disinformation."


But in the biggest parallel to the Clinton hacking, few have touched upon the actual contents of the documents, which some say confirm prior allegations of illicit financial dealings and offshore accounts, and instead merely sought to attack the messenger. Indeed, as journalist Kim Zetter noted overnight, "Telling journos to not report on hacked emails misses point that nearly all important leaks occur because someone broke law or a contract" and then followed up with the following rhetorical question, flipping the situation by 180 degrees: "If GRU, intending to assault dem., hacks Trump & publishes emails showing his direct connection to Russia, should journos report on those."




As reported on Friday evening, WikiLeaks tweeted that the leak contained "many tens of thousands" of emails, photos and attachments dated up to April 24, but it noted that it had come "too late" to affect the election results. In a follow up tweet, the controversial whistleblowing organization posted a tweet sharing the location of all #MacronLeaks archives which are "now available as uncensorable magnet links http://archive.is/aULcm"



Since there has been no suggestion WikiLeaks is responsible for this hack, speculation about the source of the hack has grown, with Russia once again emerging as the "usual suspect."


Cited by Reuters, Vitali Kremez, director of research with New York-based cyber intelligence firm Flashpoint, said his review indicates that APT 28, a group tied to the GRU, the Russian military intelligence directorate, was behind the leak. He cited similarities with U.S. election hacks that have been previously attributed to that group. Kremez also said that APT28 last month registered decoy internet addresses to mimic the name of En Marche, which it likely used send tainted emails to hack into the campaign’s computers. Those domains include onedrive-en-marche.fr and mail-en-marche.fr.





"If indeed driven by Moscow, this leak appears to be a significant escalation over the previous Russian operations aimed at the U.S. presidential election, expanding the approach and scope of effort from simple espionage efforts towards more direct attempts to sway the outcome," Kremez said.



We expect the Kremlin to deny all allegations shortly.


To cover all bases, others have also accused the "Alt Right" of being responsible for the leak:





Ben Nimmo, a UK-based security researcher with the Digital Forensic Research Lab of the Atlantic Council think tank, said initial analysis indicated that a group of U.S. far-right online activists were behind early efforts to spread the documents via social media. They were later picked up and promoted by core social media supporters of Le Pen in France, Nimmo said.



The leaks emerged on 4chan, a discussion forum popular with far right activists in the United States. An anonymous poster provided links to the documents on Pastebin, saying, "This was passed on to me today so now I am giving it to you, the people."



The hashtag #MacronLeaks was then spread by Jack Posobiec, a pro-Trump activist whose Twitter profile identifies him as Washington D.C. bureau chief of the far-right activist site Rebel TV, according to Nimmo and other analysts tracking the election. Contacted by Reuters, Posobiec said he had simply reposted what he saw on 4chan.



“You have a hashtag drive that started with the alt-right in the United States that has been picked up by some of Le Pen’s most dedicated and aggressive followers online,” Nimmo told Reuters.



Sunday"s election, whose result is expected in just over 24 hours, is seen as "the most important in France for decades, with two diametrically opposed views of Europe and the country"s place in the world at stake." Tune in then to find out if Wikileaks is correct, and the #MacronLeaks is nothing more than a tempest in a teapot, unable to chisel away at Macron"s lead over Le Pen which the latest polls calculate to be as much as 25 points.

Friday, January 6, 2017

Trump Set To Receive "Intelligence" Briefing On "Russian Hacking"

After some early confusion on timing, Trump is finally set to receive his "intelligence" briefing from the Director of National Intelligence James Clapper, CIA Director John Brennan and FBI Director James Comey later this afternoon.  The meeting comes just one day after the same three people briefed the Senate"s Armed Services Committee on their "Russian Hacking" discoveries, which actually turned out to be nothing more than a repeat of the numerous allegations leaked to the mainstream media by "anonymous sources" over the past three weeks.


Of course, the meeting took a bizarre twist earlier this week when Trump suggested via Twitter that it had been pushed back to allow more time "to build a case."




Of course, the entire "Russian hacking" narrative has drawn very serious questions from the start leading many to question whether the intelligence community was on a crusade for the truth or to simply delegitimize President-elect Trump.  One question that has been raised repeatedly is why the Obama administration and intelligence community waited until after the election to assert their very procative claims.  Meanwhile, new details have emerged in recent days that, after allegedly being attacked by vicious "Russian hackers," the DNC refused to cooperate with the FBI.  Per NBC:





A senior law enforcement official said the FBI repeatedly stressed to DNC officials the importance of obtaining direct access to the servers "only to be rebuffed until well after the initial compromise had been mitigated." The official said the FBI had to rely on a "third party" for information, but did get access to the material it needed.



The Washington Post, citing anonymous U.S. officials, reported Thursday that intelligence agencies have identified parties who delivered stolen Democratic emails to WikiLeaks. The officials also said there were disparities between efforts to infiltrate Democratic and Republican networks, and said the U.S. intercepted communications in which Russian officials celebrated Trump"s victory. It was not clear which of those details were included in the classified report.



Which prompted Trump to ask the very obvious question of why the DNC would refuse help if they were so certain about Russian hacking from the start?





Then there is, of course, the other issue that the "Russian hacking" narrative seems to continue to evolve over time.  At first, Russia was deemed to be the source of Wikileaks" leaked emails from the DNC and John Podesta.  But after Julian Assange appeared on Fox News earlier this week to assert, once more, that his source was neither the Russian government nor "any state actor", even this seemingly basic detail of the narrative had to be modified by the "intelligence community."  As we pointed out yesterday, the new narrative morphed to suggest that while "Russian hackers" stole the data from DNC servers, it was provided to Wikileaks through a "third party."  So basically, Russia stole DNC emails then provided those stolen emails to a DNC insider who then provided them to Wikileaks...that seems reasonable.





And finally there is, of course, the continued collusion between the Obama administration, the "intelligence community" and the mainstream media, which has been crucial in spreading the "Russian hacking" narrative via "anonymous officials" ever since Hillary"s defeat.  The latest evidence of collusion came just yesterday when the Washington Post, CNN and NBC all were seemingly given a sneak peak of the 50 page intelligence report even before President-elect Trump was briefed on it"s findings. 


Which obviously drew even more questions from Trump.




Despite the many controversies surrounding the investigation, Trump"s top aides have assured the concerned mainstream media he will maintain an open mind during his briefing this afternoon while confirming that he has "a healthy skepticism of everything."  We look forward to the live Twitter updates from the President-elect throughout the briefing.

Monday, January 2, 2017

If There Really Was Evidence Of Russian Hacking, The NSA Would Have It

Submitted by David Spring via TurningPointNews.org,


On December 29, 2016, the Hill posted an article discussing a 13 page report by the FBI and DHS claiming that their 13 page report was “evidence” of Russian hacking in US elections.
http://thehill.com/policy/national-security/312132-fbi-dhs-release-report-on-russia-hacking


Wikileaks has repeatedly stated that the source of its leaks was a disgruntled Democratic Party insider.
http://www.dailymail.co.uk/news/article-4034038/Ex-British-ambassador-WikiLeaks-operative-claims-Russia-did-NOT-provide-Clinton-emails-handed-D-C-park-intermediary-disgusted-Democratic-insiders.html


However, President Obama issued a press release on December 29 2016 using the DHS-FBI report to justify increasing sanctions against Russia.
https://www.whitehouse.gov/the-press-office/2016/12/29/statement-president-actions-response-russian-malicious-cyber-activity


I therefore decided to see what the evidence was of Russian involvement in US Elections. The Hill article linked to this 13 page government press release as its proof of Russian hacking.
https://www.us-cert.gov/sites/default/files/publications/JAR_16-20296.pdf


The government press release written by DHS-FBI did not mention Wikileaks in its report. Nor did the report provide any evidence of Russian hacking in the US elections. Instead, the press release stated that “technical indicators” of Russian hacking were in the “CSV file and XML file attached with the PDF.” However, there was no CSV or XML file or link attached with the PDF. I was eventually able to find these two files at this link.
https://www.us-cert.gov/security-publications/GRIZZLY-STEPPE-Russian-Malicious-Cyber-Activity


To see the evidence of Russian hacking first hand, I downloaded the CSV file and converted it into a spreadsheet. The CSV file and the XML file both contained the same data. Here is the XML link to this data which can be viewed online in a web browser.
https://www.us-cert.gov/sites/default/files/publications/JAR-16-20296.xml


Both files provide a list of 895 “indicators” of Russian Hacking. Unfortunately, nearly all of these indicators are simply IP addresses. In other words, it is a list of 895 servers from from more than 40 countries around the world. But the list also includes a few website domain names. (Domain names are simply the name of the website such as Youtube.com). I looked up these website domain names with the the following tool which tells us who owns the domain names and where they are located:
https://www.whois.net/


My review of these domain names confirmed that none of these domain names have any relationship to Russian government hackers. Here are the results for four of the domain names provided by the DHS and the FBI as evidence of Russian hacking:





ritsoperrol.ru is not in use. It is registered to a private person. The named server hosting the domain is nserver: ns0.xtremeweb.de. This is a German web hosting and consulting company whose address and phone number are publicly listed on their website. It is highly unlikely that Russian hackers would use a public German web host to register and host their domain names.



littlejohnwilhap.ru is not in use and is available to be purchased. It is unlikely that Russian hackers would use a domain name like this to launch a cyber attack on the US.



wilcarobbe.com is taken and is not in use. It is registered to Arsen Ramanov in Groznenskaya Russia. His address, phone number and email address are all publicly listed. It is highly unlikely that Russian hackers would use a domain name that was publicly listed. Hackers are not idiots.



one2shoppee.com is taken and is registered with GoDaddy.com. It is not currently in use. But it is highly unlikely that Russian Hackers would register their domain names with GoDaddy – which is a US server. In fact, it is very unlikely that Russian hackers would ever use any US servers. They would only use their own servers.



How did these four domain names get on a list of Russian hackers? It is possible that some unknown agents took over these domain names and may have used them for some kind of hacking activity. However, the agents could have just as easily been from the US as from Russia. In fact, it is not likely that these domain names were taken over by Russian hackers for the simple reason that Russian hackers are way to smart to be using these silly tactics.


None of the 885 IP addresses have any confirmed relationship to Russian Government Hackers


An IP address is simply a numerical designation for a server. The 885 IP addresses listed in the DHS – FBI CSV file were even more interesting. The IP addresses were located on servers from the US and more than 40 nations around the world including more than 30 IP addresses supposedly located in China. Here are a few of the IP addresses


  • 167.114.35.70

  • 185.12.46.178

  • 46.102.152.132

  • 178.20.55.16

I looked up several of these IP addresses using the following tool:
http://whatismyipaddress.com/ip-lookup


Here are a four examples of IP addresses in the DHS-FBI report:





167.114.35.70 is a Canadian Corporate server specializing in the promotion of Bitcoin. They are within a few miles of the US border.



185.12.46.178 is a Swiss corporate server associated with the domain name leavesorus.com. The domain name leavesorus.com is currently available to be purchased. This indicates that this is a fake domain name and likely a fake corporation.



46.102.152.132 is another Swiss corporate server this one specializing in emails and associated with the domain name maxsultan.xyz which is a fake domain name. This also indicates that this is another fake corporation.



178.20.55.16 is a proxy server with no known location but has been used as a TOR router exit node. A proxy server is another name for a mirror or server used to bounce information from one server to another in order to hide the true location of the original server. This proxy server is associated with the domain name nos-oignons.net. This domain name was registered on December 31 2012 and is valid until December 31 2017. In other words, whoever got this domain name paid for its use for 5 years. But they did registered the domain name anonymously. The website associated with this server appears to be a group in France promoting the TOR router. They became an association in May 2013 – 5 months after getting the domain name. The group currently has 5 members and it costs one Euro to join this group. Their website was reported 9 days ago as having been infected with the Zues virus. This infection does not leave tracks on server logs. So it is difficult to tell where it came from. Removal of this virus requires a complete rebuild of the server. In short, some agency decided to take out this server and then use it to make a cyber attack on some US government agency and thus have the IP address listed on the DHS-FBI list as one of 895 indicators of Russian hacking.



Many of the IP addresses yielded the same dead end or otherwise highly suspicious result - meaning that some very large agency is using hundreds of servers in various countries around the world as a front for hacking attacks. I recently researched a series of attacks on my personal websites from hundreds of IP addresses using hundreds of servers that were supposedly located in the Ukraine. I was able to confirm the exact location in the Ukraine that was supposedly being used to launch literally thousands of attacks on my websites. However, it is not credible that anyone in the Ukraine has the millions of dollars needed to be running hundreds of servers in a remote Ukrainian location. Nor is it likely that anyone in rural Ukraine would even have the knowledge to take care of hundreds of servers even if they did have the millions of dollars needed to plow into buying these servers. Nor are they likely to have the knowledge needed to be running very complex cyber attacks. Ukraine is just not a good location for servers. This experience convinced me that attacks were being launched from other locations and were merely being routed through Ukraine in order to mislead people about where the attacks were really coming from.


Next, the CSV file provided by DHS-FBI listed the physical location of all 885 IP addresses. What is most ironic is that, only two of the 885 IP addresses were from servers in Russia. The most common location of the hacking servers was the United States. Over 30 of the servers were supposedly located in China. But it is known that the NSA has the ability to use satellite mirrors to hide the locations of their servers – making folks believe that the attacks are coming from China (or Ukraine or Mongolia) when in fact they are coming from servers located in the US.


01


Here are 50 more servers. Again, no Russians:


02


Here are 50 more servers. How can servers in the US be used as evidence of Russian hacking?


03


Here is another batch of 50 servers. Again, no Russians.


04


Wait a Minute… Is this the Smoking Gun???
Actually, there were two Russian servers located on lines 259 and 261. Here are the IP addresses.


  • 93.171.203.244

  • 95.105.72.78

Here is more information about each of these:





93.171.203.244 This is a clean broadband server located near Ufa which is a city in Russia with one million people. It is associated with an organization called Miragroup Ltd. The website is rxbrothers.ru. Naturally, this is a fake domain name which is available to be purchased. Miragroup is actually a corporation located in Great Britain.



95.105.72.78 is another clean broadband server located near Ufa. The organization is JSC Ufanet and the website is ufanet.ru which is a public broadband service started in 1997. Someone apparently is using this broadband service to hack the US government. Could this be the smoking gun that the Russian government is attacking the US? Think about it. If you were a Russian hacker, would you really use a public server located in some Russian town? I don’t think so. This is more like evidence that some hacker was using the local public library.



Imagine someone launching a cyber attack from the Seattle Public library – and then our government declaring that they have evident that the mayor of the City of Seattle was responsible for the attack because “nothing happens in Seattle without the approval of the Mayor!”. This is worse than a silly accusation. It is ridiculous. It is irresponsible.


Real Russian Hackers do not use Windows Servers


Only three of the servers provided in the DHS/FBI report included detailed information (despite the fact that the IP addresses provided information on all 895 servers and that DHS/FBI certainly have detailed information on all of the servers). All three servers listed in the report were Windows servers. It is highly unlikely that Russian hackers or Chinese hackers would be using Windows servers. Instead, all real hackers use Linux servers because Linux servers are much more secure than Windows servers.
https://techlog360.com/top-15-favourite-operating-systems-of-hackers/


If there really was evidence of Russian hacking, the NSA would have it


Former NSA leader turned whistleblower William Binney recently stated that if the Russians really did hack the Democratic Party servers, the NSA would certainly have real evidence (not the nonsense put out in the DHS-FBI CSV file). Here is his quote from a December 29 2016 article by Glenn Greenwald: “The bottom line is that the NSA would know where and how any “hacked” emails from the DNC, HRC or any other servers were routed through the network. This process can sometimes require a closer look into the routing to sort out intermediate clients, but in the end sender and recipient can be traced across the network.”
https://theintercept.com/2016/12/29/top-secret-snowden-document-reveals-what-the-nsa-knew-about-previous-russian-hacking/


Edward Snowden has not only confirmed that the NSA has this ability – but that he himself used an NSA program called XKEYSCORE to monitor such attacks.
https://theintercept.com/2016/07/26/russian-intelligence-hack-dnc-nsa-know-snowden-says/


Anyone with any kind of technical background in defending against hacker attacks would understand that what Binney, Snowden and Greenwald are saying is true. The evidence of their truth – most of which was supplied by Snowden from NSA documents – is overwhelming.


05


Conclusion


An important research principle is to follow the money. People around the world need to ask themselves who has the money and technical ability to be running hundreds and perhaps thousands of real servers and real IP addresses from fake corporations using fake websites in fake locations in more than 40 nations around the world? What agency has already been proven to be running mass surveillance on billions of people in more than 40 nations all around the world? Whose military cyber budget is more than 10 times larger than the cyber warfare budget of the rest of the world combined? There is certainly an elephant in the room – but it is not a Russian elephant.


At a televised press conference on April 2016, former NSA agent, Edward Snowden asked the Russian leader Vladimir Putin if the Russian government engaged in mass surveillance of millions of people in a manner similar to the NSA. Putin replied that Russian law prohibited the Russian government from engaging in mass surveillance. Putin then pointed out that the Russian military budget was less than 10% of the US military budget. So even if they wanted to engage in mass surveillance, they simply did not have the money.
https://www.theguardian.com/world/video/2014/apr/17/snowden-putin-russia-surveillance-phone-in-video


People also need to ask themselves why the FBI DHS chose to place their evidence in a CSV file and XML file rather than a normal document or spreadsheet. If this were real evidence, it would have been placed directly in the PDF report for everyone to read – not hidden away in a file the general public has little ability to read.


Finally, for the FBI or the DHS to claim that the XML-CSV file contains evidence or even indicators of Russian hacking is simply a false statement. It is a perfect example of fake news. Any news agency promoting this claim without doing even the most basic of research that would easily confirm it is false, should be listed as a fake news agency.


The real question that we should all be asking is why the DHS and FBI would destroy their reputation by posting such a fake report?


Several years ago, our CIA claimed that Iraq had weapons of mass destruction. We now know that Iraq had no weapons of mass destruction – meaning that we went to war and spent over a trillion dollars on a fake report. Is this new fake report a pretext for launching a cyber war against Russia? Is it intended to justify increasing US military spending?


It is hard to say what the real purpose of this fake DHS-FBI report is. But the fact that this silly list of IP addresses was the best evidence they could provide should be a strong indication that there really is no evidence of Russian hacking. Instead, it is more likely that Wikileaks is telling the truth in stating that they got the emails from a disgruntled Democratic Party insider.