Everything All Right Down There?

Do you need Canada to step in and intervene, USA? Because things are getting weird.

Shock surprise, after repeated denials that the Kremlin influenced your election, Trump is whining that no-one is reporting the Kremlin influenced the election to hurt him. All right, all right, fine, I’ll signal boost the alleged “pee pee tape” that was reported in the New York Times, Washington Post, and a tonne of other mainstream outlets.

If it were just that, I’d declare this an ordinary Thursday. But we also have this:

“Who leaked that to you?” he asked. I said I couldn’t give him that information. He responded by threatening to fire the entire White House communications staff. “What I’m going to do is, I will eliminate everyone in the comms team and we’ll start over,” he said. I laughed, not sure if he really believed that such a threat would convince a journalist to reveal a source. He continued to press me and complain about the staff he’s inherited in his new job. “I ask these guys not to leak anything and they can’t help themselves,” he said. “You’re an American citizen, this is a major catastrophe for the American country. So I’m asking you as an American patriot to give me a sense of who leaked it.” […]

“They’ll all be fired by me,” he said. “I fired one guy the other day. I have three to four people I’ll fire tomorrow. I’ll get to the person who leaked that to you. Reince Priebus—if you want to leak something—he’ll be asked to resign very shortly.” The issue, he said, was that he believed Priebus had been worried about the dinner because he hadn’t been invited. “Reince is a fucking paranoid schizophrenic, a paranoiac,” Scaramucci said. He channelled Priebus as he spoke: “ ‘Oh, Bill Shine is coming in. Let me leak the fucking thing and see if I can cock-block these people the way I cock-blocked Scaramucci for six months.’ ” […]

“The swamp will not defeat him,” he said, breaking into the third person. “They’re trying to resist me, but it’s not going to work. I’ve done nothing wrong on my financial disclosures, so they’re going to have to go fuck themselves.”

Scaramucci also told me that, unlike other senior officials, he had no interest in media attention. “I’m not Steve Bannon, I’m not trying to suck my own cock,” he said, speaking of Trump’s chief strategist. “I’m not trying to build my own brand off the fucking strength of the President. I’m here to serve the country.”

If you haven’t guessed, that was Anthony Scaramucci less than a week into his job. It isn’t often that the most bonkers person in the news isn’t Donald Trump.

Incredibly, though, Scaramucci was sane next to much of your own Senate. Not only did a mainstream publication push a story titled “Senate Republicans hope their own Obamacare repeal won’t become law“, the headline is accurate.

Mitch McConnell is making one last frantic plea to his Senate Republican members to advance the party’s scaled-back Obamacare repeal, assuring them at a private lunch that the vote is merely aimed at getting to conference with the House rather than immediately becoming law.

The Senate majority leader picked up some key votes at lunch, with Sen. Rob Portman (R-Ohio) endorsing the shriveling repeal effort as a bridge to bicameral negotiations. Not everyone was sold, but GOP leaders were emphasizing that the bill, which would slash Obamacare’s coverage mandates and result in millions more uninsured, is not the ultimate goal.

“I believe the leader has been in communication with Speaker [Paul] Ryan on that topic,” said Senate Majority Whip John Cornyn (R-Texas). “The request to go to conference has to come from the House so that would probably be the best people to talk to. But I have every expectation we will.”

To sum up the process so far, the House just barely passed a healthcare bill thanks in part to a promise that they’d fix it in the Senate; today, some key Republicans held a press conference to trash the new Senate bill, with Lindsey Graham in particular saying it was “terrible policy and horrible politics” and a “fraud”… then announced they’d vote for it, provided the House promised not to follow usual procedure and put it to a vote. Instead, they want the House and Senate to hash out their vast differences and come up with a third version of this healthcare bill. If they fail on that task, these Senators want the House to abandon the legislation instead of put it to a snap vote, despite heavy pressure to pass something. All this is happening as no-one has any idea what’s in the Senate bill they’re due to vote on sometime in the next 24 hours, but they do know that critical portions will have to dropped to pass it with 50 votes.

We’re starting to get really worried for you up here. Should we call in France or the UN to help mediate?

Time To Mobilise, America

It’s official.

Mitch McConnell: Tomorrow, I will keep my commitment to vote to move beyond the failures of #Obamacare. I will vote yes on the motion to proceed.

The fight for your health care just kicked up a few notches. Republicans are desperate for a “win,” even though they don’t know what they’re fighting for, to the point that they’re flying in John McCain immediately after his blood clot surgery and brain cancer diagnosis. The vote happens tomorrow, so you’d better get active now. Ben Wikler has some good advice.

The first big tell is Tuesday morning, when Republicans need 50+1 votes to start final debate on… something bad, don’t know what yet. 2/

Nobody knows how Tuesday’s vote will go. I have a sinking feeling. As do others. Need constant, maximal pressure. Call: 202-224-3121 3/

Unlike earlier phases of this battle, the hard right is now fully engaged. Koch organizations, Trump admin, the works. We must be louder. 4/

If McConnell votes FOR the motion to proceed but it FAILS, he can’t bring it up again and you can exhale. 7/

that’s very unlikely. Leaders nearly always switch their votes to “nay” so they’re voting w majority and reserve right to bring back up. 8/

If the Rs win the Motion to Proceed, we enter 20 hours of debate. Surreally, that’s all the debate we’ll get on Trumpcare. 11/

In this case, though, the MTP isn’t necessarily a preview of final vote because we won’t know what the final bill will be. So TURN IT UP 13/

Tue-Wed, we’ll have 10 hours of R speeches, 10 hours of D speeches, furious dealmaking, & (your job) mega public outrage 14/

Then vote-o-rama: the weird Senate thing on budget reconciliation bills where each side proposes unlimited amendments & ALL get voted on 15/

This time, vote-o-rama will be used by Rs to propose radical restructurings of the health care system without time for debate or review 17/

Meanwhile, Dems will, I hope and expect, come ready with 100s or 1000s of amendments to extend vote-o-rama as long as possible 18/

That’s the only way Ds can delay the final vote. But the Parliamentarian could rule them dilatory. Or McConnell can change rules anytime 20/

At the end, McConnell will intro an amendment that wipes away all previous amendments. That’s the final bill. Possibly unseen till then 22/

And then the Senate will vote on Trumpcare, whatever Trumpcare is at that point. A mystery bill that could shape all of our futures. 23/

In a series of moments, each a second or two long, a handful of Republican senators will vote yay or nay—death or life for untold 1000s 25/

If the Senate votes yes on Trumpcare, it’s very likely that the House votes the bill through intact & with mind-blowing speed. 29/

If the GOP passes the Motion to Proceed on Tuesday, I’d suggest basically putting your life on hold until the Trumpcare final vote is over.

This is one of those extremely rare moments in politics when everything is on the line—AND nobody knows which way it’ll go.

His advice for what to do begins around here in the Twitter thread. One thing I’d like to point to directly are virtual call banks, where you repeatedly call your representatives from the comfort of your home, but Wikler details a lot of other ways you can help and dishes some great advice (eg. don’t call people who don’t represent you).

Now get moving! Your health depends on it.

Well, That Escalated Quickly

If you’d asked me about it six months ago, I would have been adamant that we’d never get an email from the Trump camp admitting to collusion. Anyone merely considering collusion would ensure there were multiple layers of plausible deniability, layering on handlers and indirection to throw smoke at anyone on the trail. [Read more…]

When Winning Becomes Everything

Before getting to the point, though, do you mind if I be a little petty? Emphasis mine:

I was asked about my observations on technical details buried in the State Department’s release of Secretary Clinton’s emails (such as noting a hack attempt in 2011, or how Clinton’s emails might have been intercepted by Russia due to lack of encryption). I was also asked about aspects of the DNC hack, such as why I thought the “Guccifer 2” persona really was in all likelihood operated by the Russian government, and how it wasn’t necessary to rely on CrowdStrike’s attribution as blind faith; noting that I had come to the same conclusion independently based on entirely public evidence, having been initially doubtful of CrowdStrike’s conclusions.

MMmmmm.

But on to the main point: the day after Thursday’s revelation that “a GOP operative who presented himself as working with Mike Flynn, … actively solicited Clinton emails from hackers he believed to be Russian and assumed to be affiliated with the Russian government,” one of the anonymous sources became nonymous. Meet Matt Tait, a British cybersecurity researcher who’s covered that angle of American politics. Said GOP operative, Peter Smith, approached him to validate the batch of emails that were claimed to be from Hilary Clinton’s private email server.

In my conversations with Smith and his colleague, I tried to stress this point: if this dark web contact is a front for the Russian government, you really don’t want to play this game. But they were not discouraged. They appeared to be convinced of the need to obtain Clinton’s private emails and make them public, and they had a reckless lack of interest in whether the emails came from a Russian cut-out. Indeed, they made it quite clear to me that it made no difference to them who hacked the emails or why they did so, only that the emails be found and made public before the election.

Ignore the whole attribution angle of the DNC hack. Instead, let’s focus on the actions of the Republicans. They had access to illegally-obtained dirt on a rival party, and didn’t care that this dirt was illegal. All that mattered to them was winning.

This isn’t a one-off, either; yesterday I pointed to an old story about another GOP operative, Aaron Nevins, who struck a deal with “Guccifer 2.0” to use the material they gathered from local DNC chapters in local races. That material wound up being used in attack ads, and may have swayed voters. But there was also a recent report which showed that Republicans had extensively gerrymandered electoral districts, guaranteeing themselves safer seats and a greater odds of winning. This lines up with prior reports. Republicans are also notorious for voter suppression, to the point that they openly brag about it and waste taxpayer funds to do it. Voter disenfranchisement? Also a Republican tactic.

This is a party devoted primarily to winning. Their policies and values are secondary, leading to an unending stream of hypocrisy. This explains a lot about why they have so much difficulty governing, the Republicans lack a unified vision to guide policy and rally everyone around. This makes it easy for outside groups to sway Republicans to their side, to the point that they even rely on them to draft some legislation.

This is poisonous for democracy. It must be opposed, no matter your political leanings.

The Good Ol’ Days

Do you remember the good old days? Back when political parties didn’t team up with foreign powers on multiple occasions to use illegally obtained material for personal gain?

[Aaron] Nevins confirmed to the [Wall Street] Journal that he told hacker Guccifer 2.0 to “feel free to send any Florida based information” after learning that the hacker had tapped into Democratic Congressional Campaign Committee (DCCC) computers last summer. From the DCCC, Guccifer 2.0 released internal assessments of Democratic congressional candidates, known as “self-opposition research,” to GOP operatives using social media. Nevins told the Journal that, after receiving the stolen documents from the hacker, he “realized it was a lot more than even Guccifer knew that he had.” The stolen DCCC documents also contained sensitive information on voters in key Florida districts, breaking down how many people were considered dependable Democratic voters, undecided Democrats, Republican voters and the like. Nevins made a war analogy, describing the data he received to Guccifer 2.0 as akin to a “map to where all the troops are deployed.”

After Nevins published some of the material on the blog HelloFLA.com, using his own pseudonym, Guccifer 2.0 sent a link of the information to close Trump associate Roger Stone — who is currently under federal investigation for potential collusion with Russia.


What the Journal story does indicate, however, is that a GOP operative who presented himself as working with Mike Flynn, a top Trump adviser with numerous dodgy Russian ties himself, actively solicited Clinton emails from hackers he believed to be Russian and assumed to be affiliated with the Russian government. Once he obtained a stash of unverified emails presented as the deleted Clinton emails, this operative then suggested the hackers release the cache to WikiLeaks one month after the DNC WikiLeaks dump and a month before the Podesta WikiLeaks dump.

*sigh*, I sure miss those days.

Russian Hacking and Bayes’ Theorem, Part 4

Ranum’s turn! Old blog post first.

Joking aside, Putin’s right: the ‘attribution’ to Russia was very very poor compared to what security practitioners are capable of. This “it’s from IP addresses associated with Russia” nonsense that the US intelligence community tried to sell is very thin gruel.

Here’s the Joint Analysis Report which has been the focus of so much ire, as well as a summary paragraph of what the US intelligence agency is trying to sell:

Previous JARs have not attributed malicious cyber activity to specific countries or threat actors. However, public attribution of these activities to RIS is supported by technical indicators from the U.S. Intelligence Community, DHS, FBI, the private sector, and other entities. This determination expands upon the Joint Statement released October 7, 2016, from the Department of Homeland Security and the Director of National Intelligence on Election Security.

They aren’t using IP addresses or attack signatures to sell attribution, they’re pooling all the analysis they can get their hands on, public and private. It’s short on details, partly for reasons I explained last time, and partly because it makes little sense to repeat details shared elsewhere.

I agree with most experts that the suggestions given are pretty useless, but that’s because defending against spearphishing is hard. Oh, it’s easy to white list IP access and lock down a network, but actually do that and your users will revolt and find workarounds that a network administrator can’t monitor.

The reporting on the Russian hacking consistently fails to take into account the fact that the attacks were pretty obvious, basic phishing emails. That’s right up the alley of a 12-year-old. In fact, let me predict something here, first: eventually some 12-year-old is going to phish some politician as a science fair project and there will be great hue and cry. It really is that easy.

I dunno, there’s a fair bit of creativity involved in trickery. You need to do some research to figure out the target’s infrastructure (so you don’t present them with a Gmail login if they’re using an internal Exchange server); research their social connections (an angry email from their boss is far more likely to get a response); find ways to disguise the URL displayed that neither a human nor browser will notice; construct an SSL certificate that the browser will accept; and it helps if you can find a way around two-factor encryption. The amount of programming is minimal, but so what? Computer scientists tend to value the ability to program above everything else, but systems analysis and design are arguably at least as important.

I wouldn’t be surprised to learn of a 12-year-old capable of expert phishing, any more than I’d be surprised that a 12-year-old had entered college or ran their own business or successfully engineered their own product; look at enough cases, and eventually you’ll see something exceptional.

By the way, there are loads of 12-year-old hackers. Go do a search and be amazed! It’s not that the hackers are especially brilliant, unfortunately – it’s more that computer security is generally that bad.

And yes, the state of computer security is fairly abysmal. Poor password choices (if people use passwords at all), poor algorithms, poor protocols, and so on. This is irrelevant, though; the fact that house break-ins are easy to do doesn’t refute the evidence that someone burgled a house.

Hey, that was quick. Next post!

Hornbeck left off two possibilities, but I could probably (if I exerted myself) go on for several pages of possibilities, in order to make assigning prior probabilities more difficult. But first: Hornbeck has left off at least two cases that I’d estimate as quite likely:

H) Some unknown person or persons did it
I) An unskilled hacker or hackers who had access to ‘professional’ tools did it
J) Marcus Ranum did it

I’d argue the first two are handled by D, “A skilled independent hacking team did it,” but it’s true that I assumed a group was behind the attack. Could the DNC hack be pulled off by an individual? In theory, sure, but in practice the scale suggests more than one person involved. For instance,

That link is only one of almost 9,000 links Fancy Bear used to target almost 4,000 individuals from October 2015 to May 2016. Each one of these URLs contained the email and name of the actual target. […]

SecureWorks was tracking known Fancy Bear command and control domains. One of these lead to a Bitly shortlink, which led to the Bitly account, which led to the thousands of Bitly URLs that were later connected to a variety of attacks, including on the Clinton campaign. With this privileged point of view, for example, the researchers saw Fancy Bear using 213 short links targeting 108 email addresses on the hillaryclinton.com domain, as the company explained in a somewhat overlooked report earlier this summer, and as BuzzFeed reported last week.

That SecureWorks report expands on who was targeted.

In March 2016, CTU researchers identified a spearphishing campaign using Bitly accounts to shorten malicious URLs. The targets were similar to a 2015 TG-4127 campaign — individuals in Russia and the former Soviet states, current and former military and government personnel in the U.S. and Europe, individuals working in the defense and government supply chain, and authors and journalists — but also included email accounts linked to the November 2016 United States presidential election. Specific targets include staff working for or associated with Hillary Clinton’s presidential campaign and the Democratic National Committee (DNC), including individuals managing Clinton’s communications, travel, campaign finances, and advising her on policy.

Even that glosses over details, as that list also includes Colin Powell, John Podesta, and William Rinehart. Also bear in mind that all these people were phished over roughly nine months, sometimes multiple times. While it helps that many of the targets used Gmail, when you add up the research involved to craft a good phish, plus the janitorial work that kicks in after a successful attack (scanning and enumeration, second-stage attack generation, data transfer and conversion), the scale of the attack makes it extremely difficult for an individual to pull off.

Similar reasoning applies to an unskilled person/group using professional tools. The multiple stages to a breach would be easy to screw up, unless you had experience carrying these out; the scale of the phish demands a level of organisation that amateurs shouldn’t be capable of. Is it possible? Sure. Likely? No. And in the end, it’s the likelihood we care about.

Besides, this argument tries to eat and have its cake. If spearphishing attacks are so easy to carry out, the difference between “unskilled” and “skilled” is small. Merely pulling off this spearphish would make the attackers experienced pros, no matter what their status was beforehand. The difference between hypotheses D and I is trivial.

There’s even more unconscious bias in Hornbeck’s list: he left Guccifer 2.0 off the list as an option. Here, you have someone who has claimed to be responsible left off the list of priors, because Hornbeck’s subconscious presupposition is that “Russians did it” and he implicitly collapsed the prior probability of “Guccifer 2.0” into “Russians” which may or may not be a warranted assumption, but in order to make that assumption, you have to presuppose Russians did it.

Who is Guccifer 2.0, though? Are they a skilled hacking group (hypothesis D), a Kremlin stooge (A), an unknown person or persons (H), or amateurs playing with professional tools (I)? “Guccifer 2.0 did it” is a composite of existing hypothesis subsets, so it makes more sense to focus on those first then drill down.

I added J) because Hornbeck added himself. And, I added myself (as Hornbeck did) to dishonestly bias the sample: both Hornbeck and I know whether or not we did it. Adding myself as an option is biasing the survey by substituting in knowns with my unknowns, and pretending to my audience that they are unknowns.

Ranum may know he didn’t do it, but I don’t know that. What’s obvious to me may not be to someone else, and I have to account for that if I want to do a good analysis. Besides, including myself fed into the general point that we have to liberal with our hypotheses.

I) is also a problem for the “Russian hackers” argument. As I described the DNC hack appears to have been done using a widely available PHP remote management tool after some kind of initial loader/breach. If you want a copy of it, you can get it from github. Now, have we just altered the ‘priors’ that it was a Russian?

This is being selective with the evidence. Remember “Home Alone?” Harry and Marv used pretty generic means to break into houses, from social engineering to learn about their targets, surveillance to verify that information and add more, and even crowbars on the locks. If that was all you knew about their techniques, you’d have no hope of tracking them down; but as luck would have it, Marv insisted on turning on all the faucets as a distinctive calling card. This allowed the police to track down earlier burglaries they’d done.

Likewise, if all we knew was that a generic PHP loader was used in the DNC hack, the evidence wouldn’t point strongly in any one direction. Instead, we know the intruders also used a toolkit dubbed “XAgent” or “CHOPSTICK,” which has been consistently used by the same group for nearly a decade. No other group appears to use the same tool. This means we can link the DNC hack to earlier ones, and by pooling all the targets assess which actor would be interested in them. As pointed out earlier, these point pretty strongly to the Kremlin.

I don’t think you can even construct a coherent Bayesian argument around the tools involved because there are possibilities:

  1. Guccifer is a Russian spy whose tradecraft is so good that they used basic off the shelf tools
  2. Guccifer is a Chinese spy who knows that Russian spies like a particular toolset and thought it would be funny to appear to be Russian
  3. Guccifer is an American hacker who used basic off the shelf tools
  4. Guccifer is an American computer security professional who works for an anti-malware company who decided to throw a head-fake at the US intelligence services

Quick story: I listened to Crowdstrike’s presentation on the Russian hack of the DNC, and they claimed XAgent/CHOPSTICK’s source code was private. During the Q&A, though, someone mentioned that another security company claimed to have a copy of the source.

The presenters pointed out that this was probably due to a quirk in Linux attacks. There’s a lot of variance in which kernel and libraries will be installed on any given server, so merely copying over the attack binary is prone to break. Because of this variety, though, it’s common to have a compiler installed on the server. So on Linux, attackers tend to copy over their source code, compile it into a binary, and delete the code.

You can see how this could go wrong, though. If the stub responsible for deleting the original code fails, or the operators are quick, you could salvage the source code of XAgent.

“Could.” Note that you need the perfect set of conditions in place. Even if those did occur, and even if the source code bundle contains Windows or OSX source too (excluding that would reduce the amount of data transferred and increase the odds of compilation slightly), the attack binary for those platforms usually needs to be compiled elsewhere. Compilation environments are highly variable yet leave fingerprints all over the executable, such as compilation language and time-stamps. A halfway-savvy IT security firm (such as FireEye) would pick up on those differences and flag the executable as a new variant, at minimum.

And as time went on, the two code bases would diverge as either XAgent’s originators or the lucky ducks with their own copy start modifying it. Eventually, it would be obvious one toolkit was in the hands of another group. And bear in mind, the first usage of XAgent was about a decade ago. If this is someone using a stolen copy of APT28/Fancy Bear’s tool, they’ve either stolen it recently and done an excellent job of replicating the original build environment, or have faked being Russian for a decade without slipping up.

While the above is theoretically possible, there’s no evidence it’s actually happened; as mentioned, despite years of observation by at least a half-dozen groups capable of detecting this event, only APT28 has been observed using XAgent.* None of Ranum’s options fit XAgent, nor do they fit APT28’s tactics either; from FireEye’s first report (they now have a second, FYI),

Since 2007, APT28 has systematically evolved its malware, using flexible and lasting platforms indicative of plans for long-term use. The coding practices evident in the group’s malware suggest both a high level of skill and an interest in complicating reverse engineering efforts.

APT28 malware, in particular the family of modular backdoors that we call CHOPSTICK, indicates a formal code development environment. Such an environment would almost certainly be required to track and define the various modules that can be included in the backdoor at compile time.

And as a reminder, APT28 aka. Fancy Bear is one of the groups that hacked into the DNC, and is alleged to be part of the Kremlin.

Ranum does say a lot more in that second blog post, but it’s either similar to what Biddle wrote over at The Intercept or amounts to kicking sand at Bayesian statistics. I’ve covered both angles, so the rest isn’t worth tackling in detail.

  • [HJH: On top of that, from what I’m reading APT28 prefers malware-free exploits, which use existing code on Windows computers to do their work. None of it works on Linux, so its source code would never be revealed via the claimed method.]

Dreams Come True?

Oh man, that British election… early results are a disaster for the Tories. No time for analysis now, but I’ll try and type something up later. Until then, watch that link.


As I type this, at about 6AM on June 9th in Britain, the Conservatives sit at 307 seats. They need an additional 19 to earn a majority… yet there are only 18 up for grabs. Overall, they’ve lost 12 seats while their rivals the Labour party gained 30. That majority is lost, let alone the gain they wished would signal a mandate. The Scottish National Party has suffered major losses, but UKIP have been wiped out of parliament. The Liberal Democrats, a former powerhouse that’s fallen on hard times, have seen impressive gains. There’s a chance Labour could form a coalition and take control of government.

Add in the record number of women elected as MPs (192, out of 650), and this is a night for progressives to cheer. It’s not a perfect outcome, as Labour also want to leave the EU, but it’ll do nicely.

Rather than chew your ear off with further details, I’ll defer to H. Bomberguy‘s setup for the election.

A Trump Controversy, in Tweets

Donald Trump:
Crooked Hillary Clinton and her team “were extremely careless in their handling of very sensitive, highly classified information.” Not fit!

Washington Post:
President Trump’s disclosures jeopardized a critical source of intelligence on the Islamic State, officials said

CBS News:
“Highly damaging”: Ex-CIA deputy director on WaPo report that Pres. Trump revealed classified info to Russians

TheUnsilentMAJORITY:
Think about this… Lavrov & Kislyak given classified info from #Trump bc his need for their approval is stronger than his loyalty to U.S

Matthew Chapman:
Lavrov will share the classified info Trump gave him with the Syrians and the Iranians. Americans fighting in the region are going to die.

Ricky Davila:
Just to be clear, Reuters, NYT, & Buzzfeed have all confirmed the #WaPo‘s report about trump giving highly classified info to the Russians.

Adrian Carrasquillo:
Per @TreyYingst, Bannon, Mike Dubke, Sarah Sanders and Spicer walked into cabinet room just now. They did not look happy.
Can now hear yelling coming from room where officials are.
WH comms staffers just put the TVs on super loud after we could hear yelling coming from room w/ Bannon, Spicer, Sanders

Hayley Byrd:
Dianne Feinstein exits Senate subway and is surrounded by reporters. “Oh my goodness. What’s happened?” (She hasn’t seen the WaPo story.)
Lindsey Graham tells us the WaPo report is “troubling” if true. I ask him if it’s only troubling. “Yeah, because I don’t know if it’s true.”
I wonder how many GOP senators will say they’re troubled before calling for more information.

Thomas Burr‏:
Asked whether @jasoninthehouse still trusts Trump with classified info, Chaffetz says, “Of Course.”

Scott Wong‏:
.@SpeakerRyan spox on WaPo story: “The speaker hopes for a full explanation of the facts from the administration.”

Alice Ollstein:
.@SenatorRisch defends Trump revealing classified info to the Russians: “It’s no longer classified the minute he utters it.”

Yashar:
Hannity right now: “Clinton Email Server Scandal”

Kurt Schlichter‏:
So: HR McMaster, author of Dereliction of Duty, sat back as Trump disgorged critical classified info, then went outside and lied about it?

The Baxter Bean:
Self-serving Republicans ignoring Trump gave highly classified info to foreign adversaries in the WH, but here’s what they said about email

Tony Posnanski:
“He defended Trump when he gave the Russians classified security info!” – The opening line to everyone running against GOP in 2018


Al Weaver:
MCCONNELL react to Wapo story: “We could do with a little less drama from the White House.”
Full quote. [this is worth clicking through, trust me – HJH]

Norah O’Donnell:
“We had lengthy interactions w/ White House all day yesterday. McMaster never said it was false until after it was published” @gregpmiller

Donald Trump:
As President I wanted to share with Russia (at an openly scheduled W.H. meeting) which I have the absolute right to do, facts pertaining….
…to terrorism and airline flight safety. Humanitarian reasons, plus I want Russia to greatly step up their fight against ISIS & terrorism.
I have been asking Director Comey & others, from the beginning of my administration, to find the LEAKERS in the intelligence community…..

They Got Al Capone on Tax Evasion

I’m not much of a TV watcher, but I think I’ll set aside some time to watch this.

Investigations conducted by ZEMBLA show that Bayrock has formed a business construction in the Netherlands, which may have been used to siphon off one and a half million dollars. In this enterprise, Bayrock collaborated with Viktor Khrapunov, a fugitive ex-mayor and governor from Kazakhstan. The Kazakhstan government accuses Khrapunov of systematically looting hundreds of millions of public assets.

It doesn’t sound like riveting TV, until you read a bit further.

The hub of the enterprise is the Dutch letter box company KazBay B.V. In the act of incorporation it states that KazBay is owned by two companies: the Dutch firm Bayrock B.V. and the Swiss company Helvetic Capital S.A. This email explains that Trump’s business partner Bayrock Group L.L.C. is behind Bayrock BV, and that the actual owner of Helvetic Capital S.A. is none other than the wife of Viktor Khrapunov.

This mail clearly refers to the use of a Dutch go-between company. Its contents also reveal that the Dutch construction was formed by the law firm of Rudy Giuliani who, at the time, was a partner in Bracewell & Giuliani LLP, and is also a Trump confidante.

Trump and Giuliani? Tied up in international money laundering?! It could explain his stance on national monuments, according to James Henry.

“This is a land grab,” said Henry. “If you don’t get that Putin and the Russians transferred a hell of a lot of wealth of the Russian government to a handful of 25 oligarchs. Right now there are five states in the U.S. that are roughly 80 percent or more owned by the federal government. Trump has just issued executive orders that will open up a lot of that land, either to outright privatization or to mining deals like we’ve never seen before.”

“There’s nothing ideological,” Henry said. “What connects all of these people in the Trump government is they are all about money. This is going to be a huge payday for these people and their friends. At the end of the day, they take care of themselves.”

This might also explain why Trump was so eager to fire Comey; the FBI was shifting focus from Russian collusion with Trump to organized crime involvement. It would also explain why Democrats questioned Comey about Felix Sater.

There’s a lot of speculation here, alas, and I’d rather see Trump investigated for collusion. But it might also be solid grounds for impeachment and a major scandal for the Republicans.

What if the simplest solution was just to fire Comey and to pressure McConnell to go along? Not that the Senate Majority Leader needed much persuading.

“McConnell received a million-dollar contribution from Russians back in October that we know about,” Henry said. “There was a million-dollar contribution to the Senate leadership PAC in the name of a New York company owned by Len Blavatnik.” Blavatnik is a Russian-born billionaire-oligarch who invested in aluminum companies in Russia and became a U.S. citizen decades ago.

It’s not the ideal path to get Trump out of office, but it could work.