, 20 tweets, 10 min read Read on Twitter
What convinced so many people so quickly that the Russian Secret Service is behind the Wikileaks DNC-Leaks?
Was it that Guccifer2.0 could hardly speak Romanian?
Was it that Guccifer2.0 used a Russian VPN service?
Was it that Guccifer2.0 sent emails from a French AOL account?
No.
The most convincing argument was Cyrillic characters in the first file uploaded by Guccifer2.0.
There are two versions of this file, a DOC file and a PDF file, although Guccipher2.0 only uploaded one DOC file, which is still available.
guccifer2.wordpress.com/2016/06/15/dnc/
What has never been considered anywhere - at least I couldn't find a source - is that it is an old WORD 97-2003 formatted file. This means that the encoding is actually an RTF file. The difference is obvious when you open the file in a text editor like Notepad.
The Windows charset 1252 is used in an English or German file. If you also need Cyrillic characters, you have to use charset 1251. The RTF command for the font is "ansicpg" and is located in the first line of the document.
So you only have to change one digit in Notepad and you have a Russian document. Try it out! It doesn't even take 30 seconds.
If you've come this far, you'll be looking for the entries
\operator
\creatim
\revtim
and write anything you can think of right now.
Use a ASCII-RTF Character Chart to write cyrillic!
Within 2 minutes you have a DOC file that was last edited by Феликс Новичок (ASCII-RTF: \'d4\'e5\'eb\'e8\'ea\'f1 \'cd\'ee\'e2\'e8\'f7\'ee\'ea). He saved and edited the document a minute before Guccipher2.0 and it was last printed in the year 1900.
But what do we do with the Russian error messages for broken hyperlinks?
Spoiler: They do not exist!!
The hyperlinks in the original DOC refer to local files of those editors who collected the dirt.
One file was located in C:\users\KotkinT\Desktop\Jindal\ (and T. Kotkin is an American name) another file was located in C:\users\KauffmanN\AppData\Roaming\Microsoft\Word\.
The error messages are not included in the document. You need to have Russian language setting for your local computer and get an automatic message. I have German language settings and get German error messages.
Conclusion: You got screwed.
What's bad, though, is that the one who put the Cyrillic error messages into circulation knew exactly what he was doing. He must have set his computer to Russian in order to take screenshots of Russian error messages.
Of course, the operator name "Felix Edmundovich Dzerzhinsky" (en.wikipedia.org/wiki/Felix_Dze…) is as flashy as Novichok. Only an idiot of hackers would call himself that way and OOPS forget to delete the metadata. Unfortunately, there are a lot of people who believe it.
Last note: Why would a hacker upload the file to a server (which certainly isn't at Guccipher2.0's home), print it, and then change it minutes before publishing? To print from a server you need special rights + the paper comes out of the printer at the other end of the world.
However, you can easily change all times with a simple code.
Broken links non-tech sidenote:
Tyler Kottkin (kotkint@dnc.org) researched e.g. Republican Piyush "Bobby" Jindal
Nathan Kauffman (kauffmanN@dnc.org) researched e.g. Trump / Putin
Thanks @ClimateAudit & @HRIMark for linking the Forensicator analysis. Read it and agree 99% because apparently not the html "%20" caused the problem (the KotkinT link also included the %20 without error) and you don't need Word2007.
Even the very last Office365 will do, if...
...you save a DOC with errors (probably the length caused the Error) as RTF. Here my german version:
There is one detail that strongly supports the Forensicator hypothesis of a Word2007 bug, namely another Word2007 bug that makes some spaces disappear when opening a Word2010 DOC in Word2007.
At this point, however, I wonder if anyone seriously believes that the Russian Secret Service is using a cracked, outdated version of Word to influence world politics. ...in the name of Феликс (Felix), of course.
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to Michael Kobs
Profile picture

Get real-time email alerts when new unrolls (>4 tweets) are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Follow Us on Twitter!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3.00/month or $30.00/year) and get exclusive features!

Become Premium

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!