Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News Editorials & Other Articles General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

2016 Postmortem

Showing Original Post only (View all)

YouDig

(2,280 posts)
Thu May 5, 2016, 08:50 AM May 2016

Some of the many dumb things about the Guccifer story. [View all]

The most obvious is that Guccifer's MO is to break into people's emails and then publish them, because he got a thrill out of it. So believing that he hacked Hillary's server and then published nothing and got no glory out of it is a bit like believing that Joseph Smith found golden plates with the word of god on them but then forgot where he put them. What is believable is that Guccifer, who is now going to be spending a long time in prison, would try to draw attention to himself by claiming to have hacked Hillary or claiming that he can prove the Rockefellers were part of some Illuminati conspiracy, or any of the other crazy things he has said.

The way Guccifer hacked people is by social engineering or guessing security questions, not by actually exploiting technical vulnerabilities. He was good at that, but there is no indication that he had the skills necessary to perform a technical hack, and there also isn't any indication that he socially engineered his way into Hillary's email account. The truth is, it's harder to socially engineer your way into a private server than a gmail or AOL account because there are no security questions to guess or tech support people that you can convince to reset your password.

He claims he described how he got into her server, by scanning for open ports, but scanning for open ports doesn't get you into a server. If he had actually gotten in, he would have described which port he used, and how he was able to use whatever service was running on it to obtain access. Finding open ports is easy, anyone can do it, but getting access to the computer through an open port is hard. An open port is not itself a vulnerability unless the service running on that port is vulnerable. Saying you hacked a server by scanning for open ports is a bit like saying that you were able to break into a bank vault by using google to figure out the bank's address and business hours.

One last thing. I see people thinking that because the server was "unsecured" for a few months that somehow means it would be easy for Guccifer to break into. But the thing that was unsecured was the email server running on the computer, not the computer itself. What that means is that communications to and from the server were not encrypted, and could be vulnerable to for example a man-in-the-middle attack. But that does not make it any easier to get in by scanning ports. For a man-in-the-middle attack, you actually have to be "in the middle", and Guccifer wasn't. If you connect to an unencrypted email server using hotel wi-fi, the hotel is in the middle, and they can read your correspondence, possibly spoof you or get your password. But there was no way for Guccifer to place himself "in the middle", nor is there any indication that he has ever done this kind of attack or would even know how.

Is it possible that someone broke into Hillary's server? Sure, after all, with Snowden and Manning and the rest, we know that no digital information is really secure. But Guccifer saying so doesn't make it any more likely.

43 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
I don't put much stock in it. cherokeeprogressive May 2016 #1
I look at the main issue being Sid's was hacked and then her server could be tracked. mmonk May 2016 #2
He hacked his e-mail address. As the OP states that's different than hacking a server. DemocratSinceBirth May 2016 #3
You didn't need to hack Sid's email to get Hillary's email address. YouDig May 2016 #5
I doubt many thought that email address was SoS official business. mmonk May 2016 #8
Any lie about Hillary Clinton will be plausible enough to those deep enough into derangement. IamMab May 2016 #4
It really is derangement on their part. LiberalFighter May 2016 #39
Kick! mcar May 2016 #6
K'n'R ucrdem May 2016 #7
Sigh. Go to the "Smoking Gun" website and search for Guccifer. IdaBriggs May 2016 #9
The internet is full of RW noise. ucrdem May 2016 #10
Is that from the "data is for losers" playbook? Lol! nt IdaBriggs May 2016 #12
That one's been reissued as "Shining Path to Victory." nt ucrdem May 2016 #16
Screenshots of Sid Blumnethal's emails, yes. YouDig May 2016 #11
Guess you'll just have to wait for the FBI report to explain. IdaBriggs May 2016 #14
The extradited him because he is a wanted criminal in the US. YouDig May 2016 #15
For hacking NWCorona May 2016 #18
Yes, for hacking, via social engineering. Hacking other people, not Hillary. YouDig May 2016 #19
A bit. Why what's up? NWCorona May 2016 #20
Just curious if, for example, you understand that "scanning open ports" like Guccifer claimed YouDig May 2016 #21
Of course it doesn't NWCorona May 2016 #22
OK, so Guccifer's explanation of how he got in is bogus. YouDig May 2016 #25
Um pinebox May 2016 #32
Yes, that's what I said. He's a social engineerinig hacker who hit some high-profile YouDig May 2016 #33
I see it as both personally pinebox May 2016 #35
Who was already in jail in Romania. IdaBriggs May 2016 #24
What you have is a conspiracy theory, with no evidence. YouDig May 2016 #26
I believe the term will end up being IdaBriggs May 2016 #30
"I'm not a lawyer but I've watched enough Law & Order..." YouDig May 2016 #31
Probably extradited to establish probable cause unc70 May 2016 #23
Actually, it was because he hacked several high-level US officials. YouDig May 2016 #27
Your OP argued he did not hack Clinton unc70 May 2016 #28
You're right. Because he didn't. YouDig May 2016 #29
Hacked or not, Clinton still has troubles unc70 May 2016 #37
Thanks. Kick. lamp_shade May 2016 #13
K&R! stonecutter357 May 2016 #17
k&r obamanut2012 May 2016 #34
Great post. And I love how you shred the bullshit within this thread as well. SunSeeker May 2016 #36
Thank you for the post! Very informative! Lucinda May 2016 #38
There are a lot of things wrong with what you are saying. bobbobbins01 May 2016 #40
Brute forcing only works in movies, or if you're the NSA. YouDig May 2016 #41
You don't really know what you're talking about. bobbobbins01 May 2016 #42
Hilarious, coming from someone talking about brute forcing through SSH. YouDig May 2016 #43
Latest Discussions»Retired Forums»2016 Postmortem»Some of the many dumb thi...»Reply #0