Both US Presidential Campaigns Hacked

The US intelligence chief say cyber-hackers working for foreign governments are targeting the candidates in this year's presidential election.

James Clapper, director of the Office of National Intelligence, said he expects more attempted hacks as the campaigns intensify. This would follow a pattern established in the last two presidential elections. The FBI is working with the campaigns to make their networks more secure.

The Department of Homeland Security is also assisting, but cyber-security experts said political campaigns have not done much to improve their defences since 2008.

Hacking was widespread during the 2008 election cycle. The Office of National Intelligence described its scale as "like no other" in a report released earlier this month. 

V Newtown Miller, a data security consultant advising government agencies, said the hackers' attempts could have a huge effect on presidential politics. "It's a matter of when and how serious of an impact it is going to have on this election," said Mr. Miller, who believes these foreign hackers attempt to extract sensitive information, rather than commit cyber vandalism.

If a hacker is able to reveal embarrassing information about a candidate, it could sway how people vote in the election. But simply taking down a candidate’s website for a few hours could also have an effect, as it limits the campaign's ability to online fundraise, as happened to Mitt Romney in 2012 for several hours.

The global hacking collective, Anonymous, declared a cyber war against Republican candidate Donald Trump several weeks ago. They are encouraging their members to target Mr. Trump's business interests as well as his campaign resources.

In 2008, hackers thought to be working for the Chinese government obtained a letter by Senator John McCain expressing support for Taiwan. A Chinese diplomat called the McCain campaign to complain about the letter before it had been sent.

Former Secretary of State Hillary Clinton has drawn criticism for operating a private email server during her time as the nation's top diplomat. She is being investigated by the FBI to determine whether classified information was sent through the unsecured server.

James Clapper has not had to officially answer for apparent perjury. It has been 1165 days since James Clapper according to Snowden lied to Congress and the American people.

On March 12th, 2013, during a United States Senate Select Committee on Intelligence hearing, Senator Ron Wyden asked Director of National Intelligence James R. Clapper the following question: "Does the NSA collect any type of data at all on millions or hundreds of millions of Americans?"

Director Clapper responded "No, sir."
Incredulously, Senator Wyden asked "It does not?"
Director Clapper responded "Not wittingly. There are cases where they could inadvertently perhaps collect, but not wittingly."

Now US lawmakers are pressing the nation’s top intelligence official to estimate the number of Americans ensnared in email surveillance and other such spying on foreign targets, saying the information was needed to gauge possible reforms to the controversial programs. They requested that Clapper provide the information about data collected under a statute, known as Section 702, by May.

That law, set to expire at the end of 2017, enables an internet surveillance program called Prism that was first disclosed in a series of leaks by former National Security Agency contractor Edward Snowden some three years ago.

Prism gathers messaging data from Alphabet’s Google, Facebook, Microsoft, Apple and other major tech companies that is sent to and from a foreign target under surveillance. Intelligence officials say data about Americans are “incidentally” collected during communication with a target reasonably believed to be living overseas. Critics see it as “back-door” surveillance on Americans without a warrant.

A recently declassified November opinion from the US Foreign Intelligence Surveillance Court, a secretive body that oversees the legality of US spy programs, rejected a constitutional challenge to rules permitting the FBI to access foreign intelligence data for use in domestic criminal investigations.

The Republican-controlled House of Represenatives has voted overwhelmingly since the Snowden leaks to require US agencies obtain a warrant before searching collected foreign intelligence for data belonging to Americans, but those proposals have gained minimal traction in the Senate.

BBC:       HasJamesClapperBeenIndictedyet:      Guardian

« March Of The Machines
Open Access To The Snowden Archive »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Directory of Cyber Security Suppliers

Directory of Cyber Security Suppliers

Our Supplier Directory lists 7,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Sonatype

Sonatype

Sonatype protects the world's enterprise software from security, compliance, licensing risks, while reducing application development and deployment time.

CERT.br

CERT.br

The Brazilian national Computer Emergency Response Team

ThaiCERT

ThaiCERT

ThaiCERT is the national Computer Security Incident Response Team (CSIRT) for Thailand.

OneVisage

OneVisage

Our award-winning 3DAuth digital identity platform turns any consumer mobile device into a real-time 3D facial scanner that securely authenticates the user in seconds.

NuCrypt

NuCrypt

NuCrypt is developing technology that is applicable to ultrahigh security data encryption as well as key distribution.

r00tz Asylum

r00tz Asylum

r00tz Asylum is a nonprofit dedicated to teaching kids around the world how to love being white-hat hackers.

OnSecurity

OnSecurity

OnSecurity replaces the overhead of traditional penetration testing firms with a simple online interface, making it easy to book tests as and when needed.

Saporo

Saporo

Saporo helps organizations increase their cyber-resistance. Continuously map your attack surface and get the recommendations you need to make your organization more resistant to attacks.

Diligent

Diligent

Diligent's SaaS GRC platform gives leaders a connected view of governance, risk, compliance and ESG across their organization.

Core to Cloud

Core to Cloud

Core to Cloud provide consultancy and technical support for the planning and implementation of sustainable security strategies.

Scybers

Scybers

Scybers are a global cybersecurity advisory and managed services company. With our deep expertise, we help our clients reduce their cyber risks with confidence.

Cyber Suraksa

Cyber Suraksa

We make security simple and hassle-free by offering a sustained and secure IT environment with next-gen cybersecurity solutions through a scalable security-as-a-service model.

ProjectDiscovery

ProjectDiscovery

ProjectDiscovery is an open-source, cybersecurity company that builds a range of software for security engineers and developers.

Tryaq

Tryaq

Tryaq are a group of cybersecurity experts and enthusiasts who share the mission to make the world feel safer online.

DART Consulting & Training

DART Consulting & Training

DART is a leading cyber training and consultancy company. We enhance our clients’ cyber capabilities by growing and strengthening their frontline defense – the cyber teams.

Softanics

Softanics

Softanics’ ArmDot protects .NET apps with advanced obfuscation, control flow protection, and virtualization, securing code against reverse engineering without requiring agents or environment changes.