• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

Cont: Breaking: Mueller Grand Jury charges filed, arrests as soon as Monday pt 2

Status
Not open for further replies.
I never said anything about Podesta. And your own link confirms the FBI was never given access to the actual servers.

You didn't say much of anything. That was the closest thing I found in a quick google. I also asked you to provide a source for your claim.

ETA: My link also says the FBI had copies of all the data on the physical servers, signed off on the third party ops forensics, and worked closely with the FBI.

What are you referring to?
 
Last edited:
So let’s put ourselves here in Donald Trump’s shoes,” Morell said. “What does he see?
That's a narcissistic moron's shoes. Not Morell's. Morell's not telling us what he thinks, but what he pictures Trump thinking.

hqdefault.jpg
 


I never said anything about Podesta.


Neither did Upchurch.

Trump certainly did, however, making Podesta a central character in the torrent of tweets he spewed out on the subject.

What you did say was;

The FBI never seriously investigated the DNC hacking, because the DNC prevented them from doing so.


And your own link confirms the FBI was never given access to the actual servers.


And his link made it clear that the FBI did indeed investigate the DNC server hacking. Not sure what you mean by the qualifier "seriously". Can you offer some support to your claim that the investigation they did was not done "seriously"?

His link also confirms that the FBI was satisfied with the access they were given, which, since it included both the work of a third party whose expertise they recognized and accepted as well as complete copies of the servers in question, makes the claim that they were not given access to the "actual servers" seem rather desperate.
 
Last edited:
Not sure what you mean by the qualifier "seriously". Can you offer some support to your claim that the investigation they did was not done "seriously"?

Just a guess, but it sounds like Zig credulously accepted Dear Leader's tweet as gospel because it agreed with his personal biases.
 
What exactly the president believes is difficult to know. He does lie consciously without remorse or apology. Take for instance the lies about the Trump Tower meeting with the Russians. But he lies with such sincerity that it difficult to figure out what his view of reality is.
It helps if you decide in advance what his view of reality is.
 
And your own link confirms the FBI was never given access to the actual servers.
Why is that relevant?

Information on the servers can easily be replicated and copied to other locations (which was what they did). There's no real value in having access to the physical hardware itself in this case, unless you think the FBI needs to dust it for Russian fingerprints, or think they will find graffiti scrawled in magic marker on the hard drive saying "Boris the Hacker was here".
 
Why is that relevant?

Information on the servers can easily be replicated and copied to other locations (which was what they did). There's no real value in having access to the physical hardware itself in this case, unless you think the FBI needs to dust it for Russian fingerprints, or think they will find graffiti scrawled in magic marker on the hard drive saying "Boris the Hacker was here".

If you don't access the physical hardware itself, there's a lot you cannot be certain of. For example, BIOS hacks won't generally get replicated. Depending on how careful you are about copying the contents of a hard drive (you can't just do a copy/paste), those contents may not be fully duplicated either. And if you want to evaluate the possibility of an inside job, then yes, actually, dusting for fingerprints is potentially useful.

There's really no good reason for the FBI to not access the actual physical servers.
 
If you don't access the physical hardware itself, there's a lot you cannot be certain of. For example, BIOS hacks won't generally get replicated. Depending on how careful you are about copying the contents of a hard drive (you can't just do a copy/paste), those contents may not be fully duplicated either. And if you want to evaluate the possibility of an inside job, then yes, actually, dusting for fingerprints is potentially useful.

There's really no good reason for the FBI to not access the actual physical servers.

That doesn't support your claim that "The FBI never seriously investigated the DNC hacking, because the DNC prevented them from doing so."

You took Trump's word for it, didn't you?
 
If you don't access the physical hardware itself, there's a lot you cannot be certain of. For example, BIOS hacks won't generally get replicated. Depending on how careful you are about copying the contents of a hard drive (you can't just do a copy/paste), those contents may not be fully duplicated either. And if you want to evaluate the possibility of an inside job, then yes, actually, dusting for fingerprints is potentially useful.

There's really no good reason for the FBI to not access the actual physical servers.

Standard forensic practice uses bit-by-bit cloning of hard drives, usually to image files at this point, and will also include pulling copies of the BIOS and similar. This has been true for quite some time. This is also in the requirements used by government in general.

In fact, forensic examination is almost never done on the original hardware, partly to preserve any physical evidence that may be on the actual hardware. If there is reason to suspect physical access (such as a break-in), then that could be examined, but it's very rare.

Unless there's reason to suspect standard practice was not followed in this case, this is a large amount of speculation with nothing to back it up.

ETA: Found this, that gives some general guidelines: https://www.ncjrs.gov/pdffiles1/nij/199408.pdf. One thing to note is that seizing the actual servers would require warrants; not sure if those were obtained or if there was enough probable cause for it (considering my understanding is that they were trying to determine if a crime had occurred, rather then looking for who committed a crime that they new occurred). Also a note that physical evidence on the computers themselves is likely to be limited/compromised due to time if nothing else. Also, were these physical or virtual servers/cloud-based? For a virtual server there's no real hardware to examine (although logs and other information form the VM Host would be useful).
 
Last edited:
[see above]

Yes, how would BIOS hacks be more detectable with the actual hard disk versus with a clone of the contents of the hard disk?

My expectation and understanding is that forensic evaluation of a hard disk would use a cloned image principally or exclusively.

How long is this going to go on? Ziggurat was wrong. If his strategy is to deny being wrong regardless of the facts, could he just state that so we can move on?
 
Yes, how would BIOS hacks be more detectable with the actual hard disk versus with a clone of the contents of the hard disk?

My expectation and understanding is that forensic evaluation of a hard disk would use a cloned image principally or exclusively.

How long is this going to go on? Ziggurat was wrong. If his strategy is to deny being wrong regardless of the facts, could he just state that so we can move on?

Actually, the BIOS is on a flash chip on the mainboard, not part of the hard drive at all. But modern forensics tools will generally make a copy of the system BIOS, as well as various other firmware (such as for GPUs, the hard drive firmware, network cards, etc).

We've been doing this for a while. While not an expert myself, I was the Information Security NCO for a regional command in the Army. I've been involved in forensic investigations before, and we were trained in collecting digital evidence. Rarely were we asked to send the actual computer hardware on to whoever would be doing the examination.
 
Yes, how would BIOS hacks be more detectable with the actual hard disk versus with a clone of the contents of the hard disk?

My expectation and understanding is that forensic evaluation of a hard disk would use a cloned image principally or exclusively.
I don't think BIOS is usually stored on the primary storage. However, I was trying to work out why BIOS wouldn't be included either in the third party analysis OR in the server copy. I probably shouldn't have given Zig the benefit of the doubt that he knew what he was talking about.

How long is this going to go on? Ziggurat was wrong. If his strategy is to deny being wrong regardless of the facts, could he just state that so we can move on?
Since some time in the Obama administration, I think.
 
Status
Not open for further replies.

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom