Transcripts For CSPAN2 The Communicators 20161024 : vimarsan
CSPAN2 The Communicators October 24, 2016
Cspan, where history unfolds daily. In 1979 cspan was created as a Public Service by americas cable its companies its companies and is brought to you today by your cable or satellite provider. Host james lewis is a former state Department Official and is cybersecurity expert who now serves as the Senior Vice President of the center for strategic and and international studies, and hes our guest this week on the communicators. The topic, Cyber Attacks and cybersecurity. Mr. Lewis, what proof, if any, is there and what is it that the russians are behind the recent Cyber Attacks in the United States . Guest at this point theres three kinds of proof. The first is forensic evidence found by a commercial company. You know, when you hack into a computer, very often something will be left behind that points to the perpetrator. Not intentionally, its just like a footprint. And be in this case the footprints lead back to moscow. The second source of evidence is our own intelligence agencies which now are fully confident that it was the russian government behind these hacks using their own sources and technologies. And the third one is the smirk on Vladimir Putins face. I mean, he has not denied this. He seems to be enjoying it. So the evidence is pretty solid it was the russian government. Host how did they get this information . Guest it was host how does the attack happen . Guest oh. Well, it, its pretty straightforward. Most people still suffer from the illusion that email is somehow private when its actually like a postcard. And most people dont secure the data that they keep on their own networks. And and thats largely what happened. The russians got in through one of the traditional techniques, probably a phishing email, and then were able to get control of the network, sit there for a period of time and extract data including emails. Host joining our conversation today is Mark Hosenball whos with reuters, an investigative reporter. Thank you. My understanding, by the way, is that and we reported this a while ago that the intelligence agencies briefed congress, or the gang of eight, i guess its called, the leaders of both houses of congress and the leaders of the intelligence committees. Last summer. I mean, not this past summer, a year ago this summer, that this was going on the. So the u. S. Government has known about this for quite some time, but oddly enough, ive spoken to people in the Democratic Party about this, and they said they were approached by the fbi some months after the congress was briefed by about maybe a year ago, and then the fbi were kind of very to pick in the way that opaque in the way that they broached this to the people in the Democratic Party. So they were asking questions but didnt actually tell the Democratic Party, we know youve been hacked. The Democratic Party and its organizations didnt even realize they had been hacked until, i think, march or april. And finally they called a consultant and found out they had been hacked. And as you may or may not know, the Clinton Campaign as an Organization Still denies that as an organization its been hacked, although i had heard and reported that leading figures in that campaign have been, had their personal emails hacked. We now know clearly thats the case given that my understanding is that literally the russian ares got 50,000 of podestas, the Campaign Chairman i guess he is, emails. And theyre dribbling it out which gives them enough to dribble out every day 2 or 3,000 a day between now and the election which they seem to be doing via wikileaks. Guest yeah. Wikileaks has become the favorite tool for the russians, and theres some questions about the relationship between the russian government and Julian Assange. I dont think he can be called an unwitting agent anymore. He knows what hes doing. He knows where the stuff coming from. But, no, it took a while for the u. S. To decide when to go public with this, because they didnt want a confrontation with russia. And they had well, they also didnt want to compromise intelligence methods. Guest but they had the pious hope that maybe they could get some sort of deal on syria. Host it sounds like the fbi knew prior to the dnc knowing that they had been hacked. Oh, yeah. Host how did the fbi know about that ahead of time . The fbi and other u. S. Intelligence agencies, its my understanding, knew well before they told the dnc because they had intelligence be information. Guest thats a little different from my experience because theyve come, the fbis come to csis and told us weve been hacked by the russians, and theyre usually pretty forthright about who is responsible for it. But, yeah, they have their own sources. They monitor russian activity. And then when they see it coming in, they usually, im a little surprised at that. I think the victim not knowing for months is, thats common place. But normally the fbis pretty straightforward. I know that they were very explicit in briefings to the hill some months ago. So why the delay . They may not have known. I mean, its clear to me that what i told you i is true, the reasons behind it, i think have to do with sources and methods. Its absolutely clear to me because ive spoken to the democratic who actually directly dealt with them. They were confused for several months as to what this was about. Guest its not that unusual because the russians hacked into both campaigns in both 2012 and 2008. Whats different time is the release of the data. Before they took email donor lists, campaign strategy, opponent research. This is the third time theyve done that. Whats different now is the overt political use. Host but i dont mean to beat this, but, mr. Lewis, you said that the fbis come to csis and said, hey, youve been hacked. Was csis surprised to learn this . Guest maybe the first time. [laughter] host right. You didnt have any knowledge it was happening, correct . Guest no. This is one of the interesting things about this incident, is the russians are, its not the best in the world. If not the best in the world, theyre at least tied for being best in the world. And in the past, prior to these incidents they were very, very discreet, very, very determined not to be caught. One of the things that was a hallmark of russian activity was not seeing them doing things for months as it turns out. And in this case theyre very alert. Theyre sending us a signal, and its not a very polite one. Host Vice President biden brought up the potential of a cyber attack back on russia. And you laugh, but what would that entail . Guest oh, theyve gone through a lot of scenarios. Almost all of them are silly. One was leak the records of Vladimir Putins botox treatments, and its like pictures of his girlfriend or his bank account, and its like youre not going to embarrass Vladimir Putin. And then theres this, well, we should unplug their networks. That ones probably not going to work. So it looks to me like it will be sanctions and perhaps some sort of covert activity against the attacking infrastructure. My sense is also that obama, that the white house which has not said anything about this, theyve left it up to the intelligence community, although theyre as involved in this as anybody, that obamas not that interested in this stuff and, in fact, any such retaliation, if thats what you want to call it, may have to await the, you know, swearing in of presumably her, anticipated swearing in of president Hillary Clinton. Guest although i would like to see the botox pictures. I think that would be great. Host is the u. S. Conducting on a regular basis cyber warfare, for lack of a better word, against other countries . Guest currently where you could call it cyber warfare would be the decision to use Cyber Command against isis or daish, and that is the only place where you could say the military is engaged that weve publicly admitted. The intelligence community, both cia and nsa, are routinely engaged largely in espionage efforts though. So it would be unusual and perhaps unwise to start a cyber war with russia. And interestingly enough, i mean, ive actually looked at this a little bit, the real power of Islamic State or daish, whatever you want to call it, in cyberspace is not so much to their hacking or whatever because, in fact, their hacking is known to be pretty pathetic, but its their use of social media for recruit arement purposes. And the state department and British Government as well are set up, you know, fairly extensive efforts to try can counter try and counter that messaging. And generally, the western efforts including the american efforts are just terrible. Theyre pathetic, in fact, arguably theyre counterproductive. So in terms of social media use, the bad guys in this case, from what ive seen, are way, way, way ahead of the governments. Which is sort of a little bit disturbing. Guest traditional, weve always been bad at propaganda, its not our thing. Host can you put a dollar figure on how much the u. S. Government spends on cybersecurity or Cyber Intelligence gathering . Guest the last number i saw was 14 billion, i think, and that might be that includes both Network Defense and some of the, it probably underestimates the intelligence spending, because that would be part of other intelligence budgets. Host is it well allocated, in your view . Guest i think so. The problem we have is largely political which is how much can we, unlike the u. K. , for example, how much can we tell Critical Infrastructure companies that they must do something . That, of course, leads to angst among those who like reading ayn rand. It just we have a hard time with that. But on the intelligence side, on the military side, weve done quite well. Host Mark Hosenball of reuters, you had one of your emails was involved in the john podesta yeah. One of my emails turned up and has now been, become the subject of trolls attacking me on the internet. [laughter] i, apparently because i didnt remember the email until i saw it in but its a totally genuine email, so i dont suggest its forged or anything. I sent john podesta an email, i guess it was in the winter of 2015 saying id run across some document related to the Benghazi Committee which seemed to suggest the Benghazi Committee was not operating necessarily honestly. And i wanted to ask him, i wanted to show him the document and ask him what he thought of it. Again, im almost positive i never showed it to him. Im not even sure what the document is. Its not a document of consequence, although some of thing toes accused trolls accused me of getting a secret document and feeding it to the Clinton Campaign. Well, i didnt do that. I did write a story about that a few days later after this email about how the Benghazi Committee was getting some more emails from the state department, and they didnt prove of that Hillary Clinton knew or was making huge decisions about the security situation in benghazi right around the time of the attack there. And insofar as i could tell, the Public Record and history has vindicated that story. Theres still no evidence of that. And, i mean, i wrote a lot of really tough stuff about benghazi. I reported literally within hours of the attack that it was a terrorist attack, not that it was a protest against the film that went out there. And i stayed, stuck with that story even though the administration tried to tell a different story. So, i mean, the problem is these things are taken out of context, or at least that one was guest it would be a badge of honor to have russian and trumps trolls go after you, so i dont think thats necessarily a bad thing. And nobody, literally nobody outside that kind of circle has attacked me. Guest one part of this that hasnt gotten as much attention is the russians hire hundreds, if not a few thousand people to go on to western web sites, go on to newspapers here and put proputin, antiobama comments. So you cant always tell, is it russian . Is it a trump supporter . Who is it . But they have an active disinformation campaign. And bots as well. Guest yeah. Theyve used bo to ts at least to try to swing some of these postdebate polls, although as i understand it, it was actually done from inside the United States in terms of the majority of the botting, although the russians were involved. Guest its a new kind of politics. Host james lewis, what does that forensic evidence you referred to look like . Guest you know, we havent seen it, it hasnt been released. One, perhaps, apocryphal story is that perhaps the code was written in russian that was left behind, and it had references that would point back to the russian intelligence service. Thats usually what it is, is theres fragments or traces that point to the identity of the attacker. You can also, to some extent, trace back the command and control network to find out the computers from which the attack was launched and to which the data was sent. Those also point to the fsb. So theres both remnants left behind and pathways leading back to moscow. And also Julian Assange has some fairly obvious links with russia in the sense that, i mean, i know witnesses, for example, who are involved in the original discussions with Edward Snowden in hong kong when he went there, and then he went to moscow, and they said Julian Assange personally arranged for edward noden to go to snowden to go to moscow in the company of this woman, Sarah Harrison who was, in fact, Julian Assanges girlfriend. And julian as imaginesanqe at ot had a talk show, he claims i guess that he didnt get money directly from the russian government. I dont know. Guest that just means it went through a middleman. Right. Host so lets say all this information that were seeing, if it were in the u. S. Postal service in a sealed letter, would with it be illegal to publish it . Guest the internet has given the russians and others opportunities they did not have are before. If you think about preinternet elections, they would have had to send dozens or even hundreds of agents with bags of money. They would have been easily detectable. They would have had to do a watergatestyle breakin which we know didnt work out so well. So the internet makes it so much easier. You can hack in, you can get data, you can cover your traces to some extent. It would not have worked without the internet. Well, to use the watergate analogy, i mean, whats happened here and, again, you know, we havent seen the court proof that the russians did it but whatevers happened here, whoever did it and im perfectly willing to believe the russian ares did it guest there should be no doubt the right. You know, i certainly have been reporting that myself. Guest yeah. The amount of data involved is much bigger than watergate. Guest ing sure. I mean, it just guest they didnt have to rent a truck. Right. Watergate is literally tiny by comparison. Host is it illegal in any way to publish this information . Guest thats a good question. Its clearly illegal to break in and take it, and then the argument has been, well, wikileaks is receiving stolen goods. I dont think that would stand up. So if you got a mysterious document, the times with the trump tax returns, for example, its probably not illegal. One of the complications in trying to determine what an appropriate or proportionate response would be is the u. S. Wants to be very careful not to do anything that would appear to compromise peoples First Amendment right ares. A complication we have and russians dont. Host why could we not, as you say, shut down their internet . Guest well, we could shut down the internet. The questions that i think senior policymakers ask at the white house, they ask two questions; are you sure its them on the attribution front. Were sure its the russians. And the second question they ask is tell me how you will keep this from escalating out of control, and that one is some risk here. I mean, the president of russia, perhaps not one of your more stable actors although certainly better than kim of north korea, he could do something violent or unpleasant in response. Hes not bound by the same constraints we are. So i think theyre being very careful to do manager that is both supported something that is both supported by fact and does not lead to a greater conflict. I mean, our concern as journalists is not so much the law, you know, is it legal to print this stuff. Our concern much more importantly is, is it real. And, again, you know, oddly enough, the United States government has at least tried to put out stories saying be very careful, there could be fake documents planted in there. Well, thats entirely true. There could be fake documents planted by russia or assange or anybody, but insofar as ive seened in terms of the seen in terms of the wikileaks and the john Podesta Emails, its all real. Guest its the russian tactic to tweak or amend, but as you say, theres no evidence so far. Its been suggested to me that maybe what were seeing is just selective stuff and that theres other stuff in there that somehow mitigates the meaning of some of these things. Again, that could be true, but i havent seen any evidence of that. Most of the stuff seems to be in the context. I looked at my own email archive, and that was the only email from me and john to podesta that i found. Host are there any dangers to the u. S. Electoral system at this point . Illinois, arizona have experienced hacking of their public file. Guest probably not because one advantage of being a disorganized federal system is that you have dozens of actors hat the state level. At the state level. You have the 50 states plus the district, and then you have thousands of counties, each of which does its own thing, and they have different systems. So it woulda very hard target to break in and change the vote count. What you can do is you can create doubt, uncertainty. You can perhaps mess up the ability to vote on election day. But were not going to see its not going to turn out that one candidate will appear with 98 of the vote. Things like that are only possible in russia. But our system is too complicated to be easily hacked. But our politics are such that they lend themself to this kind of disruption. Well, russia, uzbekistan, kazahkstan, whatever, theres, in fact, at this point the investigators literally zero evidence that any actual voter, voting systems have been compromised in my way. D in any way. But as you say, in fact, my understanding is that 20 state Voter Registration databases have been at least faced with hacking attacks. Guest yeah. More than the two you mentioned, illinois and arizona, but less than six have been actually attacked. But, again, its not clear guest you could see that on election day if people show up to the polls and theres difficulty in verifying their legitimacy as a voter, that would add complications or delays that could affect the vote. Thats probably the most youre going to get out of it. And the republicans have a history, in fact, openly engage in, you know, efforts to increase voter id guest right. Or Voter Registration hurdles. And, you know, the democrats say, and i think theres some justification to this, these are Voter Suppression efforts. That has nothing to do with the russians. Guest to be fair, i think the russians have identified and exploited patterns in american politics. I dont think its that one party or the other is in any way witting or cooperating with the russians. So the russians know how our politics works, they take advantage of it. Host have the republicans been hacked . Guest ing they said, chairman mccaul of the House Homeland Security Committee Said they were hacked. Certainly they were hacked in the two previous president ial elections, so it wouldnt surprise me at all. Weve reported that the republicans, that multiple republican organizations and individuals have been hacked. We report ared even somebody in the Trump Campaign got hacked. Theres no evidence well, in fact, the only evidence that i know of offhand of hacked republican materials being made public is some e emails, i believe, belonging to or related to two people named Lindsey Graham, senator Lindsey Graham and senator john healthcare cane have a mccain, have appeared on the internet, and believe it or not, theyre not friendly to donald trump. [laughter] guest there does seem to be a pattern. On the other hand, in terms of large scale, i mean, i do believe that the republicans have been hacked in the sense probably for intelligencegathering purposes. Theres no evidence of anything like this sort of publication of material like is happening to the democracy. Host james lewis, i want to go back to this, and i dont mean to beat this, but how is it that the fbi knew before the organizations that were hacked . Whats the evidence that they saw . Specifically . Guest in some instances the fbi has gotten the authority to monitor some networks not always in the u. S. , but you could monitor, say, a Russian Network and see outgoing traffic. You could monitor with the help of nsa some Domestic Networks to see if they were being hacked. But if theres its hard to explain in an open setting, but if you knew what a russian attack looked like, you could look for that attack on the network and then trace it back to where it might live. Host a few weeks ago there was a story in the New York Times about this young man up in siberia who has a is set of servers in a set of servers in his office and that hes been kind of the source of this. And he was very open talking about it. Well, its kind of a switchboard more than guest yeah. Hell sell a server to anyone. I mean, dutch pornographers, you name it. Hell, so hes just, hes just the mailbox. Host so does a lot of traffic go through him . A lot of this kind of traffic that were talking about . Guest no. The russians are good, they use multiple individuals like that around the world. Some of which theyve used in the past, and that was one way that, one thing that pointed to them being responsible this time is they had previously now, to be look, the fsb does not call itself fuzzy bear. Something that an American Pr Firm made up. Its hard to see these very thuggish guys saying, im fuzzy bear. Theyre not fuzzy bear. But they do have units and a Collection Program that has a global scope that goes after politicians, intelligence targets that emanates from the fsb, and this was part of that. And that is what is detectable. If youre going after 30 countries, youre going to leave some kind of footprint. Its also worth noting that the government of ecuador confirmed the other day that theyve cut off, allegedly cut off Julian Assanges access to the internet because, remember, hes been hanging out in the Ecuadoran Embassy in london since june of four years ago. But, but the wikileaks twitter feed is still going, and my understanding is thats principally, hes the principal, if not Sole Proprietor of that. And moreover, wikileaks is continuing to publish these Podesta Emails that are, you know, several thousand a day which suggests one way or another hes found outside mechanisms that can do all this stuff. I mean, i think he had servers in sweden, but maybe other places as well, iceland. So, you know, there are ways around this for both, again, you know, people like assange, but the russian government. Guest within the limits of the law, theres not a lot you can do to assange. And so we could fry his devices, but that would probably not be legally justifiable. Host would a stuxnetlike attack against russia be considered an act of war . Guest well, act of war is a political decision. Its not actually, the legal terms are that its supposed to be an armed attack that triggers your inherent right to selfdefense. And no one has defined what an armed attack is. So it would be up to Vladimir Putin to decide that. Now, stuxnet probably was the use of force. It caused destruction. He could be justified in calling it an act of war. But its a political decision when the russians pardon me. When the United States allegedly hacked the Iranian Nuclear facility, the iranians chose not to call it an act of war. When the russians hacked a german Blast Furnace last year, the germans chose not to call it an act of war. It depends how much you want to have a fight, and he might be in the mood to have a fight. He could benefit from that. Its also true that the law and for that report in that matter the u. S. Constitution were not drafted to account for the issues of cyberspace. And, you know, particularly in the United States government. Im talking to lawyers about this recently in a slightly different context. They believe that, basically, the constitution of the United States in terms of dealing with some of these cyber issues is out of date, its obsolete. Guest ing those werent government lawyers, were they . They were, actually. Guest okay. And theyre trying to figure out ways to, you know, somehow alter statute or, for that matter, convince the courts to help them get around this issue. Guest i think the president probably feels like he has the authority he needs if he wanted either under title l or title x, the military authorities, he has the authority to do some sort of retaliatory act. But the politics of whether to do that, the wisdom of doing that are and im talking a little bit more about surveillance activities than offensive activities. Guest ing sure. Host Mark Hosenball is with reuters, and james lewis, our guest, is Senior Vice President with the center for strategic and international studies. Thank you, gentlemen. Guest thank you. Thank you very much. Cspan, where history unfolds daily. In 1979 cspan was created as a Public Service by americas Cable Television companies and is brought to you today by your cable or satellite provider. The three face one another during a recent debate focused on energy, infrastructure, National Security and the economy. This is 30 minutes. Welcome to Prairie Public coverage of election 2016. Im matt olien