I really don't care much about the people in this thread who seem to be calling me names and laughing at me for learning stuff. That's not really what's happening at all, anyway, because they don't actually believe what they say. I mean, if they actually believed what they said, they would never have learned to tie their shoes. It would be impossible for them to even type on this forum, so they clearly aren't as dumb as they act.
Clearly, what is happening here, is that they are all post-graduate level experts in evaluating aptitude, and they all think I'm not too bright. I think that's a lovely conversation to have, and I would never dream of interrupting them.
For people who are just skimming the thread, though, these aptitude experts might give you the wrong impression regarding the Durham hack. I did make a mistake, but my conclusion has not changed.
This hack is absolutely more significant than the Clinton defenders would have you believe. Follow along in your browser with me, and I'll show you why...
According to reports, the hackers got Trump's DNS request data from his upstream provider. Just to kind of give you an idea of what that might look like, lets look at your browser history. The browser history is not actually the same as DNS history from an ISP, but it's a starting point to show you what kind of data we are talking about.
So open your browser history by hitting ctrl-H, or hitting the sidebar button in Firefox, or the kebab > history > history in Chrome. If you are in Firefox, in the History side bar, click the view drop down and select "By Date and Site." If you are in Chrome, you won't be able to follow along as easily, because Chrome does not sort sites like this. Just imagine that each web domain in your history has only one entry.
Now, when this conversation started, I thought what was hacked was the entire URL for every site visited, because I was confusing traffic logs with DNS request history. Traffic logs are absolutely one of the most valuable types of file for an attacker to target. Sometimes, the traffic logs are all the attacker wants. Like, this history file could be the entire end game, because it could reveal enough information to arrest, blackmail or embarrass a target. At the very least, it almost always gives enough technical information to know what hardware and software you are trying to hack in order to take over the machine, if you wanted to. It also tells you about the technical skill level and general life of the target. If you have a stalker, this is not information you want them to have.
So I was wrong assuming that the Durham attack was about traffic history. Why did I make such a bad assumption? Because nobody ever goes straight after DNS history at the ISP level. That just seems bizarre to consider, at first. Thankfully, Argent and Essence set me straight.
What's the difference between this list and the DNS history from an ISP?
When you go to a URL, your browser needs to take the domain from the URL, and tranalate that domain into an IP address. To do that, it checks it's own cache first. Your history is a version of this cache. If it doesn't find it there, then it goes up a level. If you are at a big company, you probably have your own company DNS server. If somebody else in the company has been to this domain since the cache was last cleared, then it gets the IP address and goes from there. If not, it goes up a level, and maybe another level, and eventually it goes up to the ISP level. This is where Verizon's DNS server lies. If nobody from your company has gone to the URL since all the DNS servers below it, then you get the IP address here. It can go up from there, all the way to the 13 root DNS servers that the internet runs on. So it's a hierarchy.
So lets say you have DNS history from Trump tower, directly from their ISP. I don't know who their ISP is, but lets say it's Verizon, just to keep things less wordy. What does this DNS history look like?
It looks like the history in your browser, but with only domains specified, and no domain is repeated more than once. It also is time sensitive, because if cache was cleared on the client's broswer or in the client's company DNS server, then it shows almost every domain visited. So lets say we assume the caches were cleared a month ago. Could be a few hours ago, could be a month, lets just use a month to illustrate this on your browser.
If you are in Firefox, and still have your history sidebar open, then click the View drop down, and select This month. Don't open any of the folders inside This month, just open this month and see what's in there. This is kinda what it would look like, if we got your DNS history from your ISP. Obviously, there would be no (local files) entry, and there would be more holes, because of the caching, but this is a general idea of what Clinton's attacker had on Trump.
The ISP's DNS history would also have history from applications other than your browser. If your software or operating tries to resolve a URL to run updates, or if your drivers try to update they will create logs, as well. I probably won't know which model of video board you have from this, but I can probably tell if you are running intel or AMD. I can also tell if you have Windows, BSD, Linux, or Apple OS. Did your Adobe products check for updates today? Got that, too. Probably can't tell what products, exactly, but I know adobe is there. Did your browser check for updates? You see where this is going...
You can't see frequency of requests, or the full URLs of requests, but you can see what requests are being made to what domains, and that is useful, on a technical level.
That's just the information I get from this file that's useful for a technical hack, where I determine the software and hardware I need to exploit in order to break in and do bad things.
What about more social attacks?
Social engineering attacks commonly involve calling somebody up or spear phishing them or generally doing whatever it takes in order to get them to click on something, or fill out a form on your web site. In order to do that, one common attack vector is spoofed web sites. This DNS history is a directory of sites that are going to be easier to spoof, because the target may have seen them before. If the target sees a brand new web site, they might scrutinize it, but if you see a site you go to all the time, like NPR or VVO, then your eyes might glaze over, and you might just do as it says, when it asks you to log in with 2 factor authentication. If it's a spoofed site, the attacker now has your 2 factor auth information.
If you want to see an example of how this works in the wild, check out
Kitboga's YouTube channel. He uses social engineering to screw with scammers by using spoofed web sites on them. It's hilarious. Also, I love what he does with his voice. He's like a one man Crank Yankers for Gen Z.
So in the end... yeah, that file is meaningful. Not as meaningful as full network logs, but still very meaningful, and damaging for somebody to have. You do not want your stalker to have this information!
The crazy thing is, how did the attacker get this? Like Argent said, to get something like this by purely hacking it with a technical attack, you would have to hack the entire perimeter of Trump's network, in which case, you would be pulling all kinds of crazy stuff, and DNS logs like this would be small ball kiddie stuff. Either that, or you hacked Verizon's DNS server, in which case, again, just reading this file is small ball stuff. It would be like killing a fly with a howitzer. This is why I thought they had full network logs at first. Nobody targets an ISP's DNS history log. It's just weird.
I say the only way it makes sense for an attacker to get this file is if a Verizon representative just gave it to them. I am not a lawyer, but my understanding of the law says that this would have been legal for Verizon to do.
Everybody agrees that this is unethical, though. I bet if you go back to historical VVO forum posts regarding ISP's ability to sell your traffic history, you will find that absolutely nobody here is defending their right to do this kind of thing. You might even find some of the aptitude experts who posted above freaking out about such things. Why defend the practice now? Seems like they are defending this hack because it helps Hillary Clinton. They don't care about ethics, beyond what helps and hurts their political candidates. I find that disturbing.
Anyway, the point is that this Durham hack is a much bigger deal than the neolibs would have you believe. It is probably legal, but that does not mean you should not be outraged about it. It was wrong.