Hacker News new | ask | show | jobs
by shimon_e 3156 days ago
Does a phishing attack and leaking that podesta's passwords were p@ssw0rd and runner1234 on to 4chan need explanation? I was monitoring 4chan when the password leaks happened. People were posting screenshots of tracking his iPad. Changing his bus schedule from NY to DC on Nov 8 to Nov 11. Tweeting that he converted and became a Trump supporter ( https://archive.fo/Cv6hK - note the "hi pol" this is a reference to the pol board on 4chan). And eventually wiping his iPad. Maybe the Russians downloaded a copy of all his emails during this chaos but trust me at least another dozen people did the same. He didn't realise his passwords were leaked onto 4chan for at least 12 hours. Quite honestly I do not trust any report that doesn't document what was happening on 4chan during these "hacks" as trust worthy.

So far I haven't seen any journalist go to the effect to document exactly what happened to Podesta on the day his passwords were leaked to 4chan.

Edit: I found this on slashdot from the time of the password leaks. https://mobile.slashdot.org/story/16/10/13/2025257/4chan-hac...

Edit 2: More proof that regular people gained access to his Gmail account. Seemingly whoever gained access to his twitter account did so via a password reset using his Gmail address. https://twitter.com/pwnallthethings/status/78662164964259840...

This for me is the ultimate card that the leaks weren't a grand conspiracy to elect Trump. Rather a security illiterate person got completely owned by trolls on the internet.

Edit 3: Further more, if the Russians were really behind the phishing to capture Podesta's passwords why would they leak on 4chan where they would end up losing their control of his accounts? A state actor would try to maintain access for as long as possible. A troll would rather see everything explode.

1 comments

All of the events you mention were in October after the emails were released by Wikileaks.

The spearphishing attack happened in March.

https://wikileaks.org/podesta-emails/emailid/34899#efmAAGAAb...

Also his password was never p@ssword, that was his Windows machine default pass.

Nice, fill us in on what we don't know. I also think there is a lot of confusion as people aren't separating the DNC hacks and the Podesta email leaks.

From the Twitter hack it seems that people still had access to his Gmail in October. Unless they someone how got that password a different way. Or it was password re-use.