Wednesday, February 15, 2017

The real issue with the leaks of General Flynn


There is a major difference between the hacks of the DNC and Hillary Clinton, and the hack resulting in the leaked transcript of General Flynn.  This difference should alarm all Americans.  As an IT security expert for nearly thirty years I will display the difference and try to simplify the two hacks.  The difference in this case is that General Flynn's hack is an inside job, initiated and acted on by at least one rogue agent in the US Government.  The leak is not the first inside job by someone inside the Government, and until the administration and FBI can find the culprit or culprits probably won't be the last.

Of course the Democratic Party, and Corrupt US Media have turned this all into a political garbage fest, and they will wallow in it for as long as possible.  They already stink, and seem to enjoy the smell.

Hillary Clinton's illegal server (sorry if you don't like the adjective but it was) was found to be running un-patched version of Microsoft's Exchange.  This was according to the FBI analysis of the server.  The particular version was vulnerable to exploits with simple tools available as a commodity for hackers.  Claims of "There is no evidence it was hacked" are as moronic as you can hear.  The goal of a hacker on a high value target, like the Clinton mail server, is not to get caught.  The hackers would have setup a persistent connection to move data off of the server at will, and most likely in real time.  Leaving love notes, or "ha ha we hacked you" would result in removing access and patching the server.  The majority of hacked servers run for months without knowledge, and in most cases high value targets run for years without the hacker being detected.

The hacking of her server was not just likely, but the FBI released reports stating that it probably was.  It was an amateur setup as well as illegal.  No special software was needed, and very little skills were needed.

The DNC email hack was even worse, but before we get there: I have yet to see any proof, or even evidence, that the Phishing mails were related to Russia.  What was related to "Russia" was a hackers name on software used to break into boxes and some emails.  Unfortunately for the people claiming "Russia did it", these tools were also released to the hacker community by the developer.  Not a Russian, but a Romanian, and quite possibly a group instead of an individual.  The Federal Government did NOT claim Russia did it, because the FBI was denied access to analyze the servers, even though they requested it.  There were two independent agencies paid by the DNC to perform the analysis, meaning they could have easily been incentivized to claim a foreign intelligence agency was responsible for political purposes.

I did some analysis myself of the hacks.  The answering server for the Phishing emails was located in France, and Name Services information was also hosted in France.  The purchase of the Domain was in France, the the admin was listed in the US.  That does not mean France or the US were involved, because with Internet technology it's very hard to say.  To be frank, you need to catch hacks in the act and be able to back trace their connections.  It simply means that there is no indication that "Russia did it."  Claims to that fact are quite simply dishonest and lack any fact.

The amount of work and knowledge it takes to generate official looking emails for Phishing is trivial, and I could teach anyone to do it in 5 minutes.  But I don't.

As with Hillary's server, this was an amateur job and simply poor security.  No special skills were needed, and no special software.

Now lets jump to the leaks coming out of the White House, why and how they are different.  Wiretapping US Citizens is against at a half dozen Federal Laws.  The "leaks" from the White House came from Wiretaps which were done without warrant.  The act of wiretapping an Official in office is considerably worse.

In addition to the illegal wiretapping, the calls were transcribed.  What is interesting here for people to know is that the transcripts have not been leaked.  What was done is fragments were cherry picked and allegations made.  If there was actually wrong doing, the proper action would not be to leak to the Press "anonymously" but to turn the information over to the US DOJ for processing.  If there was actual wrong doing, the transcripts which were cherry picked for allegations would have been leaked to show beyond a doubt that there was wrong doing.

For the people worried that President Trump and his Administration talked to ambassadors in foreign Governments, including Russia, don't be.  There is nothing illegal about that act, and every prior candidate and their team has done the same.  In 2008 Candidate Barack Obama sent an ambassador to Iran to talk to the Mullahs and told them not to negotiate with then President Bush because his administration was coming into office and would give them better deals.  Candidate Barack Obama flew to dozens of foreign countries to gain support for himself and his campaign, including nations Hostile to the US.

Lies by omission are the absolute worst kind of lie, because people have no chance to know the truth without the full set of facts.  Lies by omission are what the Main Stream Media in the US has become exceptional at.  Yes, that is right.  They are professional liars, and there is plenty of evidence and reporting already out there to back that assertion.

If you happen to still believe anything you hear on main stream media, I have pity on you but will ask you to open your eyes and find facts.  What we are seeing is an open attempt to destroy the administration that the people elected.  It may take a few minutes longer to fact find, but you will find virtually none on TV or Radio.



No comments:

Post a Comment