Hacker News new | ask | show | jobs
by breck 2051 days ago
Anyone else find it ironic that the country that is responsible for democratizing access to scientific research (via support of SciHub), the country protecting a whistleblower against government overreach (Snowden), the country pointing out how fundamentally insecure closed source, proprietary software is (SolarWinds), is...Russia?

How did we get here?

6 comments

So you're saying that Russia's interests are entirely altrustic? That's quite a stretch. I don't think they hacked SolarWinds to "prove how insecure closed source, proprietary software is". Why don't they prove how "insecure" Kaspersky AV is, in that case? Seems strange to pick a software package that nobody's heard of, but happens to be used by thousands of juicy industrial espionage targets of their primary political enemy.
OP's comment should likely be read as satiric self criticism.
I have no idea what Russia's interests are. I'm just genuinely curious and in the dark. I've never been to the country and grew up in the West during the Cold War, so when I think of Russia I was indoctrinated to think of "the bad guys".

The country is an enigma to me—very good at math but from what I read a corrupt place with rule by power and not law. So yeah, I'm just genuinely asking, how are they the ones doing these things which make the world a better place, and why isn't it us leading the charge in these 3 issues? Maybe it is just a coincidence that those 3 things align with their selfish interests, and their is no altruism involved? Or maybe there's a group in Russia that loves the ideals of the USA, and is able to actually help implement those ideals from there, because if you tried to do those 3 things from here you would be thrown in prison due to some bad laws/people here?

Hum... Most of it seems sarcastic, but a simple antagonistic view towards the US explains a lot:

> protecting a whistleblower against government overreach

Becomes protecting an enemy of their enemy, and one that commands a high press influence.

> pointing out how fundamentally insecure closed source, proprietary software

Becomes just exploiting the enemy infrastructure.

The one thing that I'm not comfortable with a simple explanation of "the Russian government doesn't like the US" is their support of SciHub. It can explain the support quite well, but it is not the only simple explanation available, so there may be other reasons.

I assume huge percentage of this site is IT professionals and software engineers.

I’ll have to ask then, what proof is there that Russia did this hack? Do you realise how hard it is to track professional hackers? You will have to trace the entire network commands up to a source and hope that it is registered under their name.

I genuinely cannot believe people here think that government managed to find the source of the hack in couple of days, that is just pure propaganda aimed for people with little to no knowledge about computer security.

Attribution is not from tracing connections or domain ownership, it's from looking at the coding style, the "Tactics, Techniques and Procedures" and the choice of targets.
It's a complex combination of all of those things, in addition to more "offensive" type intelligence collection (spying on GRU/SVR buildings, communications, and officers, essentially, and compromising their infrastructure).

You might be surprised about how even the world's top intelligence agencies sometimes do make simple mistakes with domain and network registration which really are just genuine fuckups rather than false flag subterfuge. This is very rarely a matter of something silly like "Russian IP = Russian intelligence" and more like sloppily re-using an ostensibly non-attributable network or nameserver they didn't realize was already burned.

We're still kind of in the infancy of cyberwarfare. Attribution will probably be harder in a few decades.

But, yes, it's generally a matter of TTPs, target selection, goal analysis, and style.

You can see it in Bellingcat's investigations - carelessly reusing burners, calling from GRU offices, reusing passports, calling from two burners one immediately following the other.
Yep, all enabled by the fact that Russia is so corrupt, anyone can pretty easily buy any data about anything on anyone. So any private citizen with a bit of money and some skills can effectively act like a para-intelligence agency, which is essentially what Bellingcat is.

For anyone curious, they have two excellent articles on this from a few days ago:

https://www.bellingcat.com/resources/2020/12/14/navalny-fsb-...

https://www.bellingcat.com/news/uk-and-europe/2020/12/14/fsb...

There was also an amazing investigation into this published yesterday by a Russian outlet, interviewing some of the black market data brokers and law enforcement officers (both of whom claim some of the brokers will be hunted and killed by the state, now):

https://translate.google.com/translate?sl=auto&tl=en&u=https...

That's just fancy technical terms to justify the propaganda. If these kinds of "hard proof" which definitively link hacks to nation state actors exist, why are they never publically revealed?
> why are they never publically revealed?

To protect the source(s)?

Yes just like all the "anonymous sources" commonly cited in the news.
Might still be backed by old fashioned humint - maybe an asset in Russia told someone. If so, that might be trustworthy, but also needed to be kept secret. If I needed to publicize and justify such information, I might try to claim that "the coding of the exploit was consistent with Russian trade craft" or something like that...
A hack this big is bound to have plenty of HUMINT. I think it would be hard for either government to cover that up.
Not really a new thing. The Soviets would point out the defects in US society as much as the US would highlight defects in the USSR.

And granting asylum to persons who have fallen out of favour with an enemy/rival has a been a thing back to at least the time of the Peloponnesian War and probably before.

It's only ironic of you buy into the narrative that Russia is somehow more evil or malicious than your average superpower.
> The country pointing out how fundamentally insecure closed source, proprietary software is (SolarWinds), is...Russia?

I think this research was pioneered by US with Stuxnet/Flame? No?

I feel this is tongue in cheek but at the same time I've personally benefited from 2/3 of these already. I find that very interesting that I'm benefiting from the shit stirring that Russia is doing.