Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

kennetha

(3,666 posts)
Mon Jan 2, 2017, 12:15 AM Jan 2017

Slate: Was a Trump Server Communicating With Russia?

This story is from the end of October. It takes on new light in light of recent revelations. I suspect the FBI and CIA may well have a smoking gun on Trump's collaboration. This is also mentioned in a New York Times article, but hardly anywhere else, it seem.

n late spring, this community of malware hunters placed itself in a high state of alarm. Word arrived that Russian hackers had infiltrated the servers of the Democratic National Committee, an attack persuasively detailed by the respected cybersecurity firm CrowdStrike. The computer scientists posited a logical hypothesis, which they set out to rigorously test: If the Russians were worming their way into the DNC, they might very well be attacking other entities central to the presidential campaign, including Donald Trump’s many servers. “We wanted to help defend both campaigns, because we wanted to preserve the integrity of the election,” says one of the academics, who works at a university that asked him not to speak with reporters because of the sensitive nature of his work.

Hunting for malware requires highly specialized knowledge of the intricacies of the domain name system—the protocol that allows us to type email addresses and website names to initiate communication. DNS enables our words to set in motion a chain of connections between servers, which in turn delivers the results we desire. Before a mail server can deliver a message to another mail server, it has to look up its IP address using the DNS. Computer scientists have built a set of massive DNS databases, which provide fragmentary histories of communications flows, in part to create an archive of malware: a kind of catalog of the tricks bad actors have tried to pull, which often involve masquerading as legitimate actors. These databases can give a useful, though far from comprehensive, snapshot of traffic across the internet. Some of the most trusted DNS specialists—an elite group of malware hunters, who work for private contractors—have access to nearly comprehensive logs of communication between servers. They work in close concert with internet service providers, the networks through which most of us connect to the internet, and the ones that are most vulnerable to massive attacks. To extend the traffic metaphor, these scientists have cameras posted on the internet’s stoplights and overpasses. They are entrusted with something close to a complete record of all the servers of the world connecting with one another.

In late July, one of these scientists—who asked to be referred to as Tea Leaves, a pseudonym that would protect his relationship with the networks and banks that employ him to sift their data—found what looked like malware emanating from Russia. The destination domain had Trump in its name, which of course attracted Tea Leaves’ attention. But his discovery of the data was pure happenstance—a surprising needle in a large haystack of DNS lookups on his screen. “I have an outlier here that connects to Russia in a strange way,” he wrote in his notes. He couldn’t quite figure it out at first. But what he saw was a bank in Moscow that kept irregularly pinging a server registered to the Trump Organization on Fifth Avenue.

More data was needed, so he began carefully keeping logs of the Trump server’s DNS activity. As he collected the logs, he would circulate them in periodic batches to colleagues in the cybersecurity world. Six of them began scrutinizing them for clues.




http://www.slate.com/articles/news_and_politics/cover_story/2016/10/was_a_server_registered_to_the_trump_organization_communicating_with_russia.html
12 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Slate: Was a Trump Server Communicating With Russia? (Original Post) kennetha Jan 2017 OP
WAPO is no friend of Trump and they published an in depth article critical of these findings. Snarkoleptic Jan 2017 #1
So did the New York Times kennetha Jan 2017 #3
If true, I hope it breaks open like a pinata and rains shit down on Trump. Snarkoleptic Jan 2017 #4
Yes hurple Jan 2017 #2
K&R... spanone Jan 2017 #5
K & R! densan Jan 2017 #6
Yes nm AmericanActivist Jan 2017 #7
The only way to get to the bottom of all this is a trial. may I suggest for "Treason" world wide wally Jan 2017 #8
K & R shraby Jan 2017 #9
Groper Don the Con appears very nervous re the hacking malaise Jan 2017 #10
K&R True_Blue Jan 2017 #11
K&R Maru Kitteh Jan 2017 #12

Snarkoleptic

(6,001 posts)
1. WAPO is no friend of Trump and they published an in depth article critical of these findings.
Mon Jan 2, 2017, 12:58 AM
Jan 2017
https://www.washingtonpost.com/news/the-fix/wp/2016/11/01/that-secret-trump-russia-email-server-link-is-likely-neither-secret-nor-a-trump-russia-link/

To understand what's likely happening, we need to establish a few basics. First of all, the Trump server wasn't really a Trump server. It was much less of a Trump email server, for example, than Hillary Clinton's email server was hers. Clinton had a physical server that hosted her email. The trump-email.com domain that Alfa was connecting to was hosted by a company called Cendyn. Cendyn runs marketing systems for the hospitality industry, meaning that it offers an out-of-the-box solution for a company that owns a bunch of hotels to push out sales pitch emails to its customers. In other words, trump-email.com isn't the email server Trump used to send emails from his closet. It was a domain name that linked back to a Cendyn server.

This is important for a few reasons. The first, Jeewa said, was that the trump-email.com was configured to reject a certain type of query from another server. Since its job was simply to push out thousands of enticements to come stay at Trump Soho (or whatever) it didn't need to receive many incoming requests (like incoming email). The second is that the conspiracy theory hinges on Trump's team using an offsite server hosted by someone else for its quiet communications with its Russian allies. Instead of, say, their own server, under their own control. Or an encrypted chat app. Or a phone call.

So why were the Alfa Bank servers communicating with trump-email.com in a rhythm that both seems to mirror human communication patterns and seems to have increased over the course of the campaign? To the latter point, the researchers looking at the traffic only began tracking communications in July, so everything's been within the context of the campaign. A graph created by the researchers seems "to follow the contours of political happenings in the United States," in Foer's words.

kennetha

(3,666 posts)
3. So did the New York Times
Mon Jan 2, 2017, 01:10 AM
Jan 2017

at one point.... but then in a subsequent article they seemed to backtrack.

The FBI spent the entire summer chasing this lead, apparently.

Then thought maybe not.

Here's an excerpt from their 10/31 article about the bank:

In classified sessions in August and September, intelligence officials also briefed congressional leaders on the possibility of financial ties between Russians and people connected to Mr. Trump. They focused particular attention on what cyberexperts said appeared to be a mysterious computer back channel between the Trump Organization and the Alfa Bank, which is one of Russia’s biggest banks and whose owners have longstanding ties to Mr. Putin.

F.B.I. officials spent weeks examining computer data showing an odd stream of activity to a Trump Organization server and Alfa Bank. Computer logs obtained by The New York Times show that two servers at Alfa Bank sent more than 2,700 “look-up” messages — a first step for one system’s computers to talk to another — to a Trump-connected server beginning in the spring. But the F.B.I. ultimately concluded that there could be an innocuous explanation, like a marketing email or spam, for the computer contacts.

http://www.nytimes.com/2016/11/01/us/politics/fbi-russia-election-donald-trump.html



But subsequently the FBI seem to have changed their tune. Here's what the Time's 12/11 article says about the bank.


The F.B.I. began investigating Russia’s apparent attempts to meddle in the election over the summer. Agents examined numerous possible connections between Russians and members of Mr. Trump’s inner circle, including former Trump aides like Paul Manafort and Carter Page, as well as a mysterious and unexplained trail of computer activity between the Trump Organization and an email account at a large Russian bank, Alfa Bank.

At the height of its investigation before the election, the F.B.I. saw some indications that the Russians might be explicitly seeking to get Mr. Trump elected, officials said, and investigators collected online evidence and conducted interviews overseas and inside the United States to test that theory.

http://www.nytimes.com/2016/12/11/us/politics/cia-judgment-intelligence-russia-hacking-evidence.html


In the subsequent article the activity is characterized as "mysterious and unexplained" (I assume by their sources). That is not a dismissal at all. That is not a debunking.

We know that the FBI and the CIA are now on the same page about the Russians and their goals.

hurple

(1,306 posts)
2. Yes
Mon Jan 2, 2017, 01:00 AM
Jan 2017

This story "broke" earlier the same day that Comey released his letter (if I remember correctly). I was watching the news diligently all day waiting for it to filter up to TV, but then the Comey story broke and this one died an instant death.

That, I say, is ample evidence that not only was the Trump campaign colluding with Russia, but Comey was also in on it.

I think Trump, Gulianni, Comey, McConnel et al should be arrested for TREASON. NOW!

(OK, actually, a few months ago, but now would be good too)

That's just my thoughts.

malaise

(269,157 posts)
10. Groper Don the Con appears very nervous re the hacking
Mon Jan 2, 2017, 05:34 AM
Jan 2017

remember now he knows more than anyone else on this topic

Latest Discussions»General Discussion»Slate: Was a Trump Serve...