Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Hillary’s Secret Email Was a Cyberspy’s Dream Weapon
daily beast ^ | 3-7-15 | shane harris

Posted on 03/07/2015 3:38:55 PM PST by doug from upland

Hillary’s Secret Email Was a Cyberspy’s Dream Weapon

When a notorious online break-in artist got a hold of the Secretary of State’s now-infamous email address, he gave himself the power to use it to target the global elite. The private email address for Hillary Clinton, which became the talk of Washington this week and created her first major speed bump on her road to the White House, has actually been freely available on the Internet for a year, thanks to a colorful Romanian hacker known as Guccifer.

On March 14, 2013, Guccifer—his real name is Marcel-Lehel Lazar—broke into the AOL account of Sidney Blumenthal, a journalist, former White House aide to Bill Clinton, and personal confidante of Hillary Clinton. Lazar crowed about his exploits to journalists, disclosing a set of memos Blumenthal had written to Clinton in 2012, as well as the personal email address and domain she’s now known to have used exclusively for her personal and official correspondence.

Few journalists noticed that at the time, and it caused no ruckus in Washington. But the fact that Clinton’s private email was now public means she was not just putting her own information at risk, but potentially those in the circle of people who knew her private address.

Her email account was the ultimate hacker’s lure. It’s a common technique to impersonate a trusted source via email, in order to persuade a recipient to download spyware hidden inside seemingly innocuous attachments. Indeed, Clinton’s own staff had been targeted with such highly targeted “spear phishing” emails as early as 2009, the year she took office. And according to U.S. authorities, Lazar, who’s now serving a seven-year prison sentence in Romania and is accused of hacking the accounts of other Washington notables like Colin Powell, did commandeer other people’s email accounts. Then he used them to send messages exposing the private correspondence of his other victims.

When her address was exposed, Clinton was running her private email account on equipment in her home in New York, which security experts say is an inherently weak setup that made her more vulnerable to hacking.

It’s not clear whether Lazar tried to hack Clinton’s domain or if he used his access to Blumenthal’s account to do so. But he was within digital striking distance of the secretary, inside the email of a Clinton ally who, as one longtime Blumenthal friend told The Daily Beast, is “a blooded member of Hillaryland, perhaps the personification of that corps who are closest to her inner circle.”

Blumenthal sent Clinton a range of missives covering topics such as U.S.-Egyptian relations to how she was recovering from a concussion. Once he was inside Blumenthal’s account, Lazar could have easily “spear phished” this most senior member of President Obama’s cabinet.

Had security experts checked the system, they might not have liked what they saw. One security scan this week revealed that Hillary’s domain uses “obsolete and insecure” protocols and gave it an overall F rating. Blumenthal still maintains the once-hacked AOL account. Requests for comment sent there weren’t returned.

Before Lazar exposed the email domain, it would have been known to people with whom Clinton was trading emails, as well as to a tight inner circle lucky enough to be given @clintonemail.com accounts. Those included Clinton’s daughter, Chelsea, and aide Huma Abedin, whom the former secretary treats like family. Maybe Clinton and her staff thought the relative anonymity of her email domain would have given her a measure of security. It’s hard to say, since they and State Department officials have consistently refused to answer journalists questions about what security measures Clinton took to protect her “homebrew” email system.

But “assuming that the domain is ‘secret’ is a dangerous assumption,” Johannes Ullrich, a computer security expert with the SANS Institute, told The Daily Beast.

“A not-well-published domain does not provide significant protection,” Ullrich said. “As seen in the Guccifer incident, it is easy to unmask such domains if just one of the individuals she is corresponding with is breached. At the same note, running a mail server securely is difficult.”

Ullrich said that because email servers communicate with many different outside systems, “e-mail is probably the most dangerous attack vector” that a hacker could use. The fact that Lazar had exposed her private account a year ago suggests that Clinton could have taken steps at the time to better protect herself. Whether she did or not, her aides aren’t saying.

“We have no indication the account was hacked or compromised,” a senior State Department official told The Daily Beast. But unless State inspected the system, officials have no way of knowing that. By the department’s own admission, officials didn’t contact Clinton about turning over emails on her account until October 2014, nearly two years after she’d left office, when the law on official records was being changed to cover emails sent on private accounts.

Had security experts checked the system, they might not have liked what they saw. One security scan this week revealed that the domain uses “obsolete and insecure” protocols and gave it an overall F rating.

The only Blumenthal emails Lazar is known to have disclosed, within days of hacking the account, were four memos from September 2012, marked “classified,” and containing what Blumenthal described as on-the-ground intelligence about the attack on the U.S. consulate in Benghazi. The disclosure tipped off Blumenthal to the breach, allowing him to change the password on his account and regain control.

Perhaps fortunately for Clinton, Lazar was more interested in snooping than spying. That may explain why he may have passed on a golden opportunity to get inside Clinton’s email account, as well. He’s “just a smart guy who was very patient and persistent” and who “wanted to be famous” for showing that he could embarrass Washington power brokers and other celebrities, a Romanian prosecutor told the New York Times, which published a profile of Lazar last year. Among the purloined correspondence he disclosed were emails between Powell and a Romanian diplomat, which were so intimate that Powell had to publicly declare the woman was just a friend and nothing more.

In an interview with the the Times, the imprisoned hacker rambled about “a potpourri of conspiracy theories” he tied to the so-called Illuminati, whom he described as the “very rich people, noble families, bankers and industrialists from the 19th and 20th century” that he said run the world, are responsible for the death of Princess Diana and the 9/11 attacks, and whose email the world deserves to see.

He now seems hardly much of a threat, and was apprehended by Romanian authorities after bragging about his high-profile American victims secretly running the world. He’d also targeted Romanian officials, making him a wanted man in his own country.

But plenty of people were trying to spy on Clinton and the people around her, and Lazar arguably made their job easier.

Indeed, Clinton had been targeted by hackers and cyber spies practically from the moment she took office. In 2009, a senior member of Clinton’s staff received a spear phishing email that purported to come from a colleague in the office next door, according to former officials with knowledge of the matter. The email contained an attachment that the sender claimed was related to a recent meeting, but the recipient couldn’t recall that the meeting had ever occurred. When he inquired with his colleague, he was met with a blank stare.

Had the Clinton staffer opened the attachment, it would have installed spyware on his computer and potentially allowed a hacker to spy on other people using the State Department network. Former officials said the spear phishing email likely came from China.

That same year, in a separate hacking attempt, five State Department employees who were negotiating with Chinese officials on efforts to reduce greenhouse-gas emissions received spear phishing emails claiming to come from a prominent Washington journalist, Bruce Stokes.

Signs pointed to the email being legitimate: The U.S. climate change envoy, Todd Stern, was a friend of Stokes’, and the subject line of the email read “China and Climate Change,” which seemed like a reporter’s inquiry. Stokes is also married to Ambassador Wendy Sherman, a seasoned diplomat who went on to lead U.S. negotiations with Iran over its nuclear program. The body of the message included comments related to the recipients’ jobs and their work at the time.

The spear phishing incident was documented in a State Department cable, part of a massive cached disclosed by WikiLeaks. It’s unclear whether anyone opened an attachment in the email that contained a virus, which could siphon information off the infected computer. But whomever sent the message had studied Stokes, knew who his associates were, and understood what would prompt them to trust the email.

It’s that kind of information that a reasonably sophisticated hacker could glean from someone in touch with the secretary of state. What was on her mind? What did she care about? What was likely to get her to open an attachment? Knowing the private domain Clinton used would have made any spear phishing email look more legitimate.

“At the very least, she should have been worried about individuals impersonating the [clintonemail.com] domain,” Ullrich said. Setting up standard mail filtering mechanisms and proper security certificates “would be a first step, but that should have happened right from the start,” he said.

Right from the start would have been in the days before her Senate confirmation in 2009, when the private email account was set up. If Clinton didn’t realize then that she was a security risk then, the Chinese hackers trying to break into her office should have tipped her off.


TOPICS: Crime/Corruption; News/Current Events; Politics/Elections
KEYWORDS: classifiedemails; crime; email; guccifer; hillary; hillarycriminalprobe; nationalsecurity; romania
Navigation: use the links below to view more comments.
first 1-2021 next last

1 posted on 03/07/2015 3:38:55 PM PST by doug from upland
[ Post Reply | Private Reply | View Replies]

To: doug from upland
On March 14, 2013, Guccifer—his real name is Marcel-Lehel Lazar

Clearly, this guy Lazar hacked into Hillary's email system and got all these foreign governments to donate 2-3 billion dollars to the Clinton Foundation. He should get life in prison and apologize to Secretary Clinton. Post haste.

2 posted on 03/07/2015 3:44:30 PM PST by Zuben Elgenubi (NOPe to GOPe)
[ Post Reply | Private Reply | To 1 | View Replies]

To: doug from upland
Using your own little email server makes it easier to sell secrets to State enemies, does't it?

This is gonna be hugh. Bill had his cigar. Hillary's shown him how to really abuse power.

3 posted on 03/07/2015 3:52:14 PM PST by 9thLife ("Life is a military endeavor..." -- Pope Francis)
[ Post Reply | Private Reply | To 1 | View Replies]

To: doug from upland

4 posted on 03/07/2015 3:53:27 PM PST by Travis McGee (www.EnemiesForeignAndDomestic.com)
[ Post Reply | Private Reply | To 1 | View Replies]

To: doug from upland

This article smacks of blaming a burglar who breaks into a home, finds a pit full of children forced to be sex slaves, and reports it to the police.


5 posted on 03/07/2015 3:56:08 PM PST by SpaceBar
[ Post Reply | Private Reply | To 1 | View Replies]

To: doug from upland

An AOL email account??? ...and these are supposed to be the smartest people on earth.


6 posted on 03/07/2015 3:56:30 PM PST by The Great RJ (Pants up...Don't loot!)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SpaceBar

7 posted on 03/07/2015 3:57:49 PM PST by caww
[ Post Reply | Private Reply | To 5 | View Replies]

To: doug from upland

Spying, snooping and concealment are second nature to Hillary. I wonder if decades back, when she was the Governors’ wife, did she collect and compile data streams on the parents of any students in Chelsea’s classrooms?
Hillary missed her calling. If the CIA was hiring women when she was younger, she should have joined them.


8 posted on 03/07/2015 4:01:34 PM PST by lee martell (The sa)
[ Post Reply | Private Reply | To 1 | View Replies]

To: The Great RJ

I was unaware that people still used AOL. This company was bought out many years ago in a company buyout, right?


9 posted on 03/07/2015 4:08:30 PM PST by Freedom of Speech Wins
[ Post Reply | Private Reply | To 6 | View Replies]

To: caww
June 15th with be the 800th anniversary of the Magna Carta It appears that in eight centuries, we have come full circle, where the rulers regain their monarchical power.
10 posted on 03/07/2015 4:13:26 PM PST by fhayek
[ Post Reply | Private Reply | To 7 | View Replies]

To: doug from upland

Despite Hillary’s private server being known for at least TWO YEARS, Obama actually said live on CNN that he didn’t know until he saw it on the news! Not satire!


11 posted on 03/07/2015 4:17:48 PM PST by jjotto ("Ya could look it up!")
[ Post Reply | Private Reply | To 1 | View Replies]

To: fhayek

12 posted on 03/07/2015 4:18:04 PM PST by caww
[ Post Reply | Private Reply | To 10 | View Replies]

To: doug from upland

Doug, not only is it possible that all E-Mails coming to and from Hillary’s various accounts were intercepted, but it is also possible that a lot of the people who sent her E-Mails also had their accounts hacked. The media still won’t consider the possibility that this could be one of the most disastrous national security disasters in the last 20 years.


13 posted on 03/07/2015 4:33:29 PM PST by Enterprise ("Those who can make you believe absurdities can make you commit atrocities." Voltaire)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Enterprise

Agreed. Just by having her IP address, they could have taken the files from her computer.


14 posted on 03/07/2015 6:13:59 PM PST by doug from upland (Obama and the leftists - destroying our country one day at a time)
[ Post Reply | Private Reply | To 13 | View Replies]

To: Enterprise

A hacker could have sent out false emails appearing to be from her in order to troll for information. If an .exe file was sent from what they thought was her email, they would think it was ok to open it. Who knows what info was gained?


15 posted on 03/07/2015 6:15:34 PM PST by doug from upland (Obama and the leftists - destroying our country one day at a time)
[ Post Reply | Private Reply | To 13 | View Replies]

To: doug from upland
and created her first major speed bump on her road to the White House

Yeah, up until now, she's been completely scandal free.

16 posted on 03/07/2015 6:17:28 PM PST by dead (I've got my eye out for Mullah Omar.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: doug from upland
“Our Constitution is being shredded. We know about the secret wiretaps, the secret military tribunals, the secret White House email accounts. It’s a stunning record of secrecy and corruption, of cronyism run amok. It is everything our founders were afraid of, everything our Constitution was designed to prevent.” - Hillary Clinton 2007
17 posted on 03/07/2015 6:21:12 PM PST by McGruff (Maybe my comments were too nuanced for you)
[ Post Reply | Private Reply | To 1 | View Replies]

To: doug from upland

Doug: Those are questions the media need to be asking! As Secretary of State, she is automatically a HIGH VALUE TARGET for espionage. Luckily for the hackers, she is also a colossal moron, and she made their job much easier. This is the equivalent of leaving briefcases of top secret documents at the local McDonald’s, and then asking what’s all the fuss.


18 posted on 03/07/2015 7:17:40 PM PST by Enterprise ("Those who can make you believe absurdities can make you commit atrocities." Voltaire)
[ Post Reply | Private Reply | To 15 | View Replies]

To: Enterprise

You are quoted here -— http://www.mediaite.com/online/state-dept-releases-first-email-from-hillary-clinton%E2%80%99s-private-account/

I have been educating some of the nitwits.


19 posted on 03/07/2015 8:22:38 PM PST by doug from upland (Obama and the leftists - destroying our country one day at a time)
[ Post Reply | Private Reply | To 13 | View Replies]

To: doug from upland

Who knows what info was gained?

Everything was gained. Everything.

And the bozos in the administration said nothing. They could easily see that the emails were not coming from a .gov account. (secure and monitored constantly for intrusions)

Anybody who received an email from her is complicit.


20 posted on 03/07/2015 8:49:28 PM PST by Jet Jaguar
[ Post Reply | Private Reply | To 15 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson