HomeLatest ThreadsGreatest ThreadsForums & GroupsMy SubscriptionsMy Posts
DU Home » Latest Threads » Forums & Groups » Retired » Retired Forums » 2016 Postmortem (Forum) » NSA Chief: Hillary Clinto... » Reply #1

Response to magical thyme (Original post)

Thu Sep 24, 2015, 09:16 PM

1. How Team Clinton screwed up the security on her server

What we know so far:

1) Communications with her server were not encrypted for the first 3 months.
https://www.venafi.com/blog/post/what-venafi-trustnet-tells-us-about-the-clinton-email-server/

2) They left the default VPN keys installed on her server
http://www.bloomberg.com/news/articles/2015-03-04/clinton-s-e-mail-system-built-for-privacy-though-not-security

Using those addresses, McGeorge discovered that the certificate appearing on the site Tuesday appeared to be the factory default for the security appliance, made by Fortinet Inc., running the service.


3) They were using, and continue to use, self-signed SSL certificates
http://gawker.com/how-unsafe-was-hillary-clintons-secret-staff-email-syst-1689393042

4) They set up a .com domain, enabling the typosquater who has registered clintonmail.com (no "e" before "mail". Whoever registered that domain is in a perfect position to steal login information or perform spear phishing attacks.

5) Her ISP was repeatedly hacked by China
http://www.democraticunderground.com/?com=view_post&forum=1251&pid=615632

Reply to this post

Back to OP Alert abuse Link to post in-thread

Always highlight: 10 newest replies | Replies posted after I mark a forum
Replies to this discussion thread
Arrow 44 replies Author Time Post
magical thyme Sep 2015 OP
LineReply How Team Clinton screwed up the security on her server
jeff47 Sep 2015 #1
DisgustipatedinCA Sep 2015 #6
jeff47 Sep 2015 #17
DisgustipatedinCA Sep 2015 #20
jeff47 Sep 2015 #21
bigtree Sep 2015 #2
magical thyme Sep 2015 #4
Fred Sanders Sep 2015 #7
magical thyme Sep 2015 #10
Fred Sanders Sep 2015 #11
magical thyme Sep 2015 #15
roguevalley Sep 2015 #24
bigtree Sep 2015 #8
Fred Sanders Sep 2015 #9
magical thyme Sep 2015 #12
Fred Sanders Sep 2015 #13
bigtree Sep 2015 #18
roguevalley Sep 2015 #25
bigtree Sep 2015 #27
jeff47 Sep 2015 #16
bigtree Sep 2015 #22
jeff47 Sep 2015 #23
bigtree Sep 2015 #28
jeff47 Sep 2015 #44
840high Sep 2015 #31
emulatorloo Sep 2015 #3
jeff47 Sep 2015 #19
emulatorloo Sep 2015 #36
jeff47 Sep 2015 #38
emulatorloo Sep 2015 #39
jeff47 Sep 2015 #42
Fred Sanders Sep 2015 #5
hootinholler Sep 2015 #14
kelliekat44 Sep 2015 #26
Fawke Em Sep 2015 #30
840high Sep 2015 #32
kelliekat44 Sep 2015 #33
magical thyme Sep 2015 #34
jeff47 Sep 2015 #43
Fawke Em Sep 2015 #29
Fred Sanders Sep 2015 #35
ljm2002 Sep 2015 #37
DanTex Sep 2015 #40
Zorra Sep 2015 #41
Please login to view edit histories.