Showing posts with label Russian hacking. Show all posts
Showing posts with label Russian hacking. Show all posts

Monday, September 25, 2017

Trump Administration Says 21 States Were Targets of Election Hacking



On Friday, the Department of Homeland Security notified 21 states that they were targets of hacking during the 2016 election. DHS did not identify the states publicly, but several states did confirm that they had been informed of the hacking by the federal government.

The Associated Press contacted every state election office regarding the hacking. States that confirmed that they had been targeted included Alabama, Alaska, Arizona, California, Colorado, Connecticut, Delaware, Florida, Illinois, Iowa, Maryland, Minnesota, North Dakota, Ohio, Oklahoma, Oregon, Pennsylvania, Texas, Virginia, Washington and Wisconsin.

The notifications were a rare confirmation from the Trump Administration that the Russian attempts to interfere with the election were real. The notifications came on Friday, the day of the week typically reserved for announcements the Administration prefers to have overlooked.

Some state election officials and congressmen were critical of the Administration for its slow pace in sharing information about the cyberattacks. “It is completely unacceptable that it has taken DHS over a year to inform our office of Russian scanning of our systems, despite our repeated requests for information,” California’s Democrat Secretary of State Alex Padilla said. “The practice of withholding critical information from elections officials is a detriment to the security of our elections and our democracy.”

“We have to do better in the future,” said Senator Mark Warner (D-Va.), a member of the Senate committee investigating Russia’s actions.

The DHS report did not specify the source of the hacking attempts, saying in a statement, “We are working with them to refine our processes for sharing this information while protecting the integrity of investigations and the confidentiality of system owners.”

Several state election officials did specifically name Russia as the culprit, however. Alaska Elections Division Director Josie Bahnke said that computers in Russia had looked for vulnerabilities in the state’s networks. A statement by the Wisconsin Election Commission referred to “Russian government cyber actors.”

In most cases, the state computer systems were not breached, but Illinois was an exception. A previous report indicated that hackers gained access to the Illinois voter registration computers and tried to alter or delete data.

A secret NSA document leaked to The Intercept by Reality Winner last June showed that the Russians had also targeted private companies that contract with state governments to provide software for electronic voting machines. Voting machines are typically not tied to computer networks, but could be vulnerable through software updates. The document said the GRU, Russian military intelligence, was responsible for the attacks.

So far, there is no evidence that any attempts to alter software or data was successful. “There remains no evidence that the Russians altered one vote or changed one registration,” Judd Choate, president of the U.S. National Association of State Election Directors, told Reuters.

Russia has denied any involvement in the cyberattacks on the US voting infrastructure.


Also on Friday, President Trump referred to the Russian hacking as a “hoax” in a tweet. Since the election, the president has had little to say about the Russian cyberattacks even though there is widespread agreement among intelligence agencies that the Putin government was directly involved.

  
Originally published on The Resurgent 

Sunday, July 9, 2017

Trump Presses Reset Button on Russia

A notable moment for Secretary of State Hillary Clinton was her presentation of a “reset” button to Russian Foreign Minister Sergei Lavrov in 2009. In February 2017, President Trump rightly criticized Clinton for the reset, which came the year after Vladimir Putin had invaded the country of Georgia and seized two of the nation’s provinces, although his criticism seemed to concentrate more on style than substance.

“Hillary Clinton did a reset, remember, with the stupid plastic button that made us all look like a bunch of jerks?” Trump said in the Washington Examiner. “[Russian Foreign Minister Sergei Lavrov] looked at her like, ‘what the hell is she doing with that cheap plastic button?’”

Now, eight years later, President Trump is attempting his own reset with Russia. Less than a year after Putin’s hackers attempted to influence the American presidential election and succeeded in penetrating voter databases in at least 39 states, Donald Trump appears to be ready to forgive and forget.

After a rousingly strong speech in Poland in  which he criticized the Russian president for “destabilizing” Europe and the Middle East, two days later Trump seemed to make a 180 degree turn after a private meeting with Vladimir Putin at the G20 summit in Germany.

The two men seemed to hit it off in Hamburg. An hour into the 30-minute meeting, First Lady Melania Trump was sent in to get the two billionaire world leaders to break it up. Despite the First Lady’s efforts, the men talked for another hour and 15 minutes before moving along to the next items on their respective schedules.

When President Trump emerged from his conversation with Putin, he was far less critical of Russia than he had been a few days earlier. Immediately after the meeting, Secretary of State Rex Tillerson said in a press conference that, with respect to Syria, “by and large, our objectives are exactly the same” as Russia, despite the fact that Trump has just called Russia’s influence “destabilizing.” Russia intervened to support the Assad regime while the US position is still that “there will be a transition away from the Assad family.”

With respect to Russian interference in the American presidential election, Tillerson said, “The president pressed President Putin on more than one occasion regarding Russian involvement. President Putin denied such involvement, as I think he has in the past.”

“The two leaders agreed, though, that this is a substantial hindrance in the ability of us to move the Russian-U.S. relationship forward,” Tillerson continued, “and agreed to exchange further work regarding commitments of non-interference in the affairs of the United States and our democratic process as well as those of other countries. So, more work to be done on that regard.”

The work must have been quick and productive because today President Trump said, “It is time to move forward in working constructively with Russia.” Shockingly, the president even said that he and Putin “discussed forming an impenetrable Cyber Security unit,” a move that Marco Rubio (R-Fla.) said was “akin to partnering with Assad on a ‘Chemical Weapons Unit.’”

Trump’s statements translate to an “aw, shucks, I just can’t stay mad at you” moment in which he proposes to put the proverbial fox on guard duty at the henhouse. In addition to meddling with the 2016 elections, Russia is the state actor that is widely suspected of cyberattacks on US energy companies that were apparently occurring even as the men talked in Hamburg.

Donald Trump and Hillary Clinton are not the only US officials that have fallen prey to the Putin’s apparently considerable charm and personal magnetism. In 2001, George W. Bush famously described the man he nicknamed “Pootie-Poot” as “very straightforward and trustworthy.”

Barack Obama seemed to be more honest with Putin than with his own constituents. In March 2012, President Obama told then-Russian President and Putin lackey Dmitri Medvedev that he would have “more flexibility” after the US election that year. A few months later, Obama pooh-poohed Mitt Romney’s statement that Russia was a “geopolitical foe.” In a presidential debate, Obama poked fun at Romney saying, “The 1980’s are now calling to ask for their foreign policy back because the Cold War has been over for 20 years.”

Putin played them all for fools.

George W. Bush closed out his presidency with the Russian invasion of Georgia, a US ally. Five years after Hillary Clinton’s reset and two years after Obama claimed the Cold War was over, Russia annexed Crimea, a territory of the Ukraine, and then launched into a shooting war with Ukraine itself. Obama’s administration ended with Russia meddling in the core institution of American democracy, the presidential election.

The previous resets with Putin’s Russia have been disappointments. Vladimir Putin will undoubtedly take advantage of President Trump’s naiveté as well. The Russian president has shown himself to be a man who sees an outstretched hand as a sign of weakness and who responds only to strength.

“A productive conversation would be one where President Trump clearly communicates to Putin that the US won’t be quick to offer concessions, but to the contrary, that Trump is going to be a tough negotiator, one who Putin feels is committed to protecting American interests and values, and someone who he will back his talk with action, not just as a one-off, but on a consistent basis,” Anna Borshchevskaya, an expert on Russia’s foreign policy at the Washington Institute for Near East Policy, advised in Business Insider before the meeting.

Unfortunately, the conciliatory Trump, not the tough negotiator, is the man who met with Putin. Trump didn’t bring a cheap, plastic reset button, but he may as well have.


 Originally published on The Resurgent


Wednesday, June 7, 2017

Reality Winner Just Provided Evidence of Russian Election Hacking


The news of the arrest of Reality Winner, the inappropriately named NSA contractor who allegedly leaked classified information to The Intercept, is overshadowing the real news. In a looking-at-the-forest-versus-the-trees moment, the world seems focused on Ms. Winner herself, a 25-year-old blonde, and the details of her arrest rather than the content of her leak.

The big news is that Ms. Winner has provided what many Russia skeptics have been asking for over the past few months: evidence of Russian meddling in the election. The report contains direct, unfiltered insight into the NSA findings on Russian hacking of election officials and companies.

The Intercept published many details of the report that Ms. Winner purloined from an NSA facility at Ft. Gordon, Georgia. The report, dated May 5, 2017, “indicates that Russian hacking may have penetrated further into U.S. voting systems than was previously understood. It states unequivocally in its summary statement that it was Russian military intelligence, specifically the Russian General Staff Main Intelligence Directorate, or GRU, that conducted the cyberattacks” on US companies that provide election software. The NSA found that the Russians stole data that they then used to conduct “a voter registration-themed spear-phishing campaign targeting U.S. local government organizations.”

The report does not assess the impact of the cyberattacks, but there was previously no indication that Russia had targeted computers connected to actual voting in the election. “It is unknown,” the NSA notes, “whether the aforementioned spear-phishing deployment successfully compromised the intended victims, and what potential data could have been accessed by the cyber actor.”

While electronic voting machines are not connected to the internet, Alex Halderman, director of the University of Michigan Center for Computer Security and Society and an electronic voting expert, told The Intercept that a major risk would be if the Russian attacks compromised vendors who program voting machines prior to Election Day.

“Usually at the county level there’s going to be some company that does the pre-election programming of the voting machines,” Halderman said. “I would worry about whether an attacker who could compromise the poll book vendor might be able to use software updates that the vendor distributes to also infect the election management system that programs the voting machines themselves. Once you do that, you can cause the voting machine to create fraudulent counts.”

Another possibility would be a denial of service attack. Pamela Smith, president of Verified Voting, an elections watchdog group, said, “If someone has access to a state voter database, they can take malicious action by modifying or removing information. This could affect whether someone has the ability to cast a regular ballot, or be required to cast a ‘provisional’ ballot — which would mean it has to be checked for their eligibility before it is included in the vote, and it may mean the voter has to jump through certain hoops such as proving their information to the election official before their eligibility is affirmed.”

The Intercept article noted that polling station computers that deal with registration and check-in are tied to the internet and connect directly to country voter databases. A virus spread by the polling equipment could quickly infect other government computers. Malware that changed or deleted voter rolls could throw an election into confusion.

At this point, the investigation is still ongoing and most of the results are still secret, like Reality Winner’s report should be, but this glimpse that the report provides into what is already known by the government is disturbing. Even if the attacks were ultimately unsuccessful, the mere fact of the attempt could undermine public faith in the outcome of the elections.

“It’s not just that [an election] has to be fair, it has to be demonstrably fair, so that the loser says, ‘Yep, I lost fair and square.’ If you can’t do that, you’re screwed,” said Bruce Schneier, a cybersecurity expert at Harvard. “They’ll tear themselves apart if they’re convinced it’s not accurate.”


Originally published on The Resurgent

Friday, March 31, 2017

Russian Cyberattack Targeted Rubio Staff As Recently As This Week



Russian cyber-attacks and hacking attempts were not limited to Democratic candidate Hillary Clinton in the past election. Cybersecurity experts testifying before the Senate Intelligence Committee said that several prominent Republicans including Speaker of the House Paul Ryan and Senator Marco Rubio (R-Fla.) were targeted by “coordinated social media attacks” that apparently originated in Russia per CNN.

Senator Rubio testified that members of his campaign staff were targeted at least twice. “Former members of my presidential campaign team who had access to the internal information of my presidential campaign were targeted by IP addresses with an unknown location within Russia,” Rubio said Thursday. “That effort was unsuccessful. I would also inform the committee within the last 24 hours, at 10:45 a.m. yesterday, [Wednesday, March 29] a second attempt was made, again, against former members of my presidential campaign team who had access to our internal information -- again targeted from an IP address from an unknown location in Russia. And that effort was also unsuccessful.”

Clinton Watts, a former FBI agent and Senior Fellow at the George Washington Center for Cyber and Homeland Security, said that the attacks were not limited Rubio, but that all Republican candidates, with the exception of Donald Trump, were targeted by the Russians.

Watts noted that the attacks were ongoing. “This past week we observed social media campaigns targeting speaker of the House Paul Ryan hoping to foment further unrest amongst US democratic institutions,” he said.

Watts said later on CNN that Trump and his advisors, either knowingly or unknowingly, espoused Russian propaganda stories during the campaign. “What we can’t tell is whether President Trump realized he was actually citing Russian propaganda at times, which did happen. What did happen was his campaign manager [Paul Manafort] cited Russian propaganda seven days after it had been debunked in August 2016,” Watts said. “We see lots of lines that are pushed by the Kremlin that are fed into information briefings.”

“The other part is the coordination,” he continued. “We see hacks, we see leaks and those are very synchronized or come out very quickly with the campaign back in August, September, October. And that tends to lead to the belief that there was coordination.”

“The ultimate objective [of Putin] is to destroy democracies from the inside out,” Watts told CNN’s Wolf Blitzer.

When asked during the Senate hearing by Senator Ron Wyden (D-Oreg.) how the Intelligence Committee could track the cyberattacks to their source, Watts said that investigators should follow the money trail to determine who is bankrolling the many “fake news outlets, conspiratorial websites” run from Eastern Europe. Watts said that his best guess was that the outlets were funded by “some Russian intel asset.”


Watts also said that investigators should “Follow the trail of dead Russians.” He continued, “There have been more dead Russians in the past three months that are tied to this investigation, who have assets in banks all over the world. They are dropping dead even in western countries.”

Originally published on The Resurgent