2016 Postmortem
Showing Original Post only (View all)Some of the many dumb things about the Guccifer story. [View all]
The most obvious is that Guccifer's MO is to break into people's emails and then publish them, because he got a thrill out of it. So believing that he hacked Hillary's server and then published nothing and got no glory out of it is a bit like believing that Joseph Smith found golden plates with the word of god on them but then forgot where he put them. What is believable is that Guccifer, who is now going to be spending a long time in prison, would try to draw attention to himself by claiming to have hacked Hillary or claiming that he can prove the Rockefellers were part of some Illuminati conspiracy, or any of the other crazy things he has said.
The way Guccifer hacked people is by social engineering or guessing security questions, not by actually exploiting technical vulnerabilities. He was good at that, but there is no indication that he had the skills necessary to perform a technical hack, and there also isn't any indication that he socially engineered his way into Hillary's email account. The truth is, it's harder to socially engineer your way into a private server than a gmail or AOL account because there are no security questions to guess or tech support people that you can convince to reset your password.
He claims he described how he got into her server, by scanning for open ports, but scanning for open ports doesn't get you into a server. If he had actually gotten in, he would have described which port he used, and how he was able to use whatever service was running on it to obtain access. Finding open ports is easy, anyone can do it, but getting access to the computer through an open port is hard. An open port is not itself a vulnerability unless the service running on that port is vulnerable. Saying you hacked a server by scanning for open ports is a bit like saying that you were able to break into a bank vault by using google to figure out the bank's address and business hours.
One last thing. I see people thinking that because the server was "unsecured" for a few months that somehow means it would be easy for Guccifer to break into. But the thing that was unsecured was the email server running on the computer, not the computer itself. What that means is that communications to and from the server were not encrypted, and could be vulnerable to for example a man-in-the-middle attack. But that does not make it any easier to get in by scanning ports. For a man-in-the-middle attack, you actually have to be "in the middle", and Guccifer wasn't. If you connect to an unencrypted email server using hotel wi-fi, the hotel is in the middle, and they can read your correspondence, possibly spoof you or get your password. But there was no way for Guccifer to place himself "in the middle", nor is there any indication that he has ever done this kind of attack or would even know how.
Is it possible that someone broke into Hillary's server? Sure, after all, with Snowden and Manning and the rest, we know that no digital information is really secure. But Guccifer saying so doesn't make it any more likely.