Hacker Publishes Personal Info of 20,000 FBI Agents
motherboard.vice.com
motherboard.vice.com
Not really a useful comment, I know, but I had to show my appreciation for this guy for pulling down the FBI's pants!
That the data is out there isn't important. It's not being looked at by me or other humans reading these news articles.
Furthermore, collection and access to this information is critical to the fight against terrorism. If professionals aren't able to identify individuals who may be endangering this country, that puts all of America at risk.
/congressional hearing
<p> 20,000 FBI EMPLOYEES NAMES, TITLES, PHONE NUMBERS, EMAILS, COUNTRY <a href="</p">penis </a> <a href="https://twitter.com/DotGovs/statuses/696796442850156545">Feb... 8, 2016</a> </p>
Notice the weird <a> tag in the middle.
Also, I can indeed imagine how this would be caused by improper parsing of double quotes and angled brackets.
With public facing sites like Amazon -- who have necessarily engineered and refined security solutions to manage a wide surface area of attack from its customer base -- getting successfully social engineered on occasion, I shudder to think what the situation is at a large, multidecade bureaucracy where internal-only legacy technology stacks and access control procedures have probably resulted in a mindset of "oh just put that on a sticky note" workarounds just to get work done.
That took 2 calls.
Trust me, your local FBI field office wouldn't fare any better.
This did not require multiple attempts. The employees believed everything they were told and both remained on the calls for as long as they were asked to, demonstrating utter lack of training.
Some of the screenshots have dates in them
>Did you do this or you just had screens lying around?
:)
>Can you recommend any cloud provider that is half sane?
Cloud providers suck. But I suppose google, softlayer and rackspace might suck a little less. But why not run on metal? It's cheaper and more secure.
Maybe you want to keep your text messages private from your employer, or your browsing history private from your children, or your maximum driving speeds private from your local law-enforcement, or your sexual preference separate from your wife, or etc, etc.
Embarassed. :)
Lesson: Never misinterpret, especially when feeding the ego.
https://en.wikipedia.org/wiki/Irony_punctuation
Most of the marks historically used for insincerity or irony would fail today because they cannot be typed on any keyboards.
Edit: 5 downvotes, really?
That's a common argument used by various agents of the government to justify their actions that violate peoples right to privacy.
There isn't any privacy violations happening here, nobody affected seems to be very bothered.
Edit: GP, please, learn that being clear is important, especially considering how many people are non-native speakers of your language.
If you collect my data, I consider you just as bad as a hacker who publishes everything personal of me. Yes, that's why I hate Google so much.
Doesn't matter if you trust or mistrust the government - everyone leaves a digital back-gate unlocked without realizing it once in a while.
Unfortunately no matter how noble the institution, mistake-prone carelessness humans are behind them all.
As another commenter pointed out, they can't even keep their own stuff secure. In addition, if politically it's useful, you can bet that somehow it'll find a way to get out: the Justice Department aren't the only folks able to do parallel construction. Plus folks in government agencies leak confidential stuff all the time on deep background, or as a way of scoring political points.
This is a terrible thing, but it's a terrible thing because people procuring and owning massive datasets on other people is wrong. I understand that society's morals haven't caught up with that yet, but that's the only solution that makes any sense: I own my data, I store my data, under certain conditions I may lease/lend you my data for a limited time only -- and all other uses of it, whether by private or governmental bodies -- is theft.
Out of curiosity, how do you feel about DRM (which is based on exactly the same idea but applied to creative works and not information on a person or people)?
I don't know. I need to think about this some more. Thanks again.
Perhaps in an 'ideal' world, IP wouldn't exist. This is far from an ideal world, though, and besides, the so-called "ideal world" would be extremely boring.
I think DRM takes it too far, though. My computer is my physical property. I may not have built it entirely from scratch, instead relying on vendors like Intel to manufacture the components, but it's mine and if I want it to perform a certain way, then the only thing which should be able to stop me is the law itself - not some DRM designed to help me stay in compliance with some company's idea of the law, which is inevitably biased towards their own needs.
[edit: To be clear, since I realise I sound a little extreme here - EULAs are designed to be legal contracts. As such, if you think I've broken (accidentally or intentionally) a clause in your EULA, then unless it's obvious to all involved parties that I've broken the contract (and thus broken the law), it should be up to a court to decide if a) the EULA is a valid contract, and b) if I have in fact broken said contract. If so, go ahead and punish me. Until then, it doesn't make sense to treat, for example, legal paying customers as if they were pirates when they're not.]
Please don't give us the "we weren't hacked. It was a company we used that was!" Nonsense. I'm tired of hearing this. It's the same thing blue shield said when its/my/your data was pilfered. YOU are responsible for it! If you pass it off to some incompetent third party, then that reflects even more poorly on you!
Trust me, you could hack any recruiting company and they'd be sitting on much more data than this.
[1] Which I'm sure intelligence agencies are thankful for, because all the tin-foil hatters are misplacing their resources in designing conspiracy theories about an incompetent "private intelligence organization" which amounts to a bunch of people who could easily be outsmarted by a 4chan-er with good Google-fu. You know all those stories you heard about the KGB being incompetent, or now hear about how the Party is in modern China w/r/t information control? Yeah.. the FIVEEYES are about on par when it comes to incompetence.
Is this for real?
https://www.youtube.com/watch?v=R8xlUNK4JHQ
(I would like to see corresponding movies warning students coming to study in the U.S. about U.S. government attempts to recruit them.)
Due to the amount of turnover and lack of upper management effort you can "hack" almost any recruiting company. Most new recruiters have access to all internal records and are using a basic password (12345678 or password123)
It's not uncommon for recruiters to access other companies database to find numbers and email addresses.
Honestly if you have ever sent your resume to a recruiting agency your information is fairly accessible to anyone who cares to look for it. I can find cell phone numbers of most managers in the city because they applied for some recruiting agencies entry level positions 10+ years ago.
[citation needed]Edit: I just remembered, there is (of course) a relevant xkcd for this: https://xkcd.com/932/
This is just dead wrong. I think you're conflating "Government" and "Politicians". The government pays tech very well and hires intelligent people. I once did a consulting gig and went in with your exact mindset. It was the only time I've ever been fully confident that I was the dumbest person in the room.
The reason they'll always lose is the sheer quantity of attacks. Every day we have front page posts critical of the US government. That sentiment (clearly) extends far beyond the front page of hacker news. I'd wager you wouldn't have to put much effort into finding anti-governmental rhetoric in the comments section of a cooking website.
Beyond that, the weak link is rarely the technical side, e.g. Snowden. I think we all can be confident they will lose the information, but I really don't believe it's because they are technically incompetent.
No they don't. Or at least, not the parts I worked in. Maybe the really secure stuff gets paid well, but from what I've seen government jobs are one of the worst paying jobs for an IT individual.
They'll never admit it gets stolen either.
Why, it's funny you should ask! I just got a letter from the Office or Personnel Management about three months ago, proudly informing me that all that data is now in the hands of some foreign intelligence service.
Of course, they claimed it was the result of a "sophisticated" attack, which is government fail-speak for "We left your data on a bus, and a hobo took it".
No it isn't. The hack of OPM was very well publicized. It was a long time project of the Chinese government to break into OPM's computers. I don't believe everything I read, but in this case I know is exactly what happened.
That doesn't prove the data was well secured or that the attack was especially sophisticated, but surely China is a capable adversary.
"The very first thing University of Washington Center for Information Assurance and Cybersecurity (accredited by U.S. Department of Homeland Security, whatever that means) teaches you about becoming a CIO is precisely delegating responsibility :)"
So, you'll excuse my potty mouth, but I have to repeat myself - EVERYONE engaged on either side of this practice is a certifiable idiot.
Internal email addresses and phone numbers might be a little more problematic, since they could be spam targets. But it'd be a pretty brave/dumb spammer or prank caller who targets the FBI.
> “This unauthorized access is still under investigation; however, there is no indication at this time that there is any breach of sensitive personally identifiable information,” DOJ spokesperson Peter Carr said in a statement.
The reality in cyber security is that people provide the weakest and easiest point of entry to compromise any computer system. Until the business side and process side of things improve, shit like this will remain common.
Except, you know, names. Merely being identified as a person moves you from not existing in the criminal universe to target. From name and other information comes yet other information, comes economic damage, or in this case, possibly life threatening damage.
These guys are cops and detectives, not secret agents and spies.
At least in my case the agents refused to give me their full names, citing personal safety concerns.
Sure an intranet only computer can be compromised as well, usb drive, social engineering, etc. but it is exponentially harder.
Really hoping ICBM systems are not on the internet because some general wanted to monitor them from his smartphone.
$ nslookup cryptobin.org
Server: 8.8.8.8
Address: 8.8.8.8#53
** server can't find cryptobin.org: NXDOMAIN
It can still be accessed directly via https://151.236.7.117 Domain Status: serverHold https://www.icann.org/epp#serverHold
Yes, the domain has been suspended.I wouldn't want this happening to me.
It makes me think either the supposed motivation for this hack isn't what it seems, or it was perpetuated by someone who's incredibly naive. It just doesn't seem to add up.
However, if you're in possession of 20k FBI agents' private information, you could probably contact Palestinian politicians, and they could use it in negotiations. It's valuable information to governments at war.
My attempt to summarize the new meaning of the word hacker is "any person who employs (especially technological) ingenuity to solve a problem".
Full explanation: https://scott.arciszewski.me/blog/2014/08/cause-and-infect-w...
Federal prison for what was effectively WGET'ing something that was, again, readily available. Still, in the eyes of the public and the law, hacker and cracker are the same thing. The guy is a racist liar but he didn't deserve federal prison. His conviction was later vacated on a venue technicality, which sucks, because had it been overturned in a higher circuit with the judge offering an Opinion, case law would have been set and Aaron Schwarz would have at least some vindication[1].
[1] In no way am I comparing the character of these two men, just the injustice they both suffered at the arms of the technically illiterate law enforcement/legal system. If I were a medical doctor who was before the board being judged for malpractice, I wouldn't want a jury of 12 of my 'peers' deciding my fate - I'd want other doctors.
Everybody repeatedly says this while ignoring his behavior during and after obtaining the information, which is what he was really convicted on. He said so himself.
Also, I didn't realize the surname Acevedo was so popular...
This breaks the HN guidelines. On this site, please comment civilly and substantively, or not at all. Your comment would be fine without that sentence.
Your other comments in this thread make it sound like you're knowledgeable about this space in a way that most of us aren't. The way to communicate here is to share that knowledge in a civil way, so we all learn something.
We detached this comment from https://news.ycombinator.com/item?id=11064557 and marked it off-topic.
I'm waiting for the day that script kiddies do something useful, like emptying out everyone's credit file or deleting all the pending bills in a major hospital system's computer. Embarrassing and/or exposing normal individuals doesn't provide any real macro-level help to anybody.
"We're all equal now!" Yeah, and we're now all paying for it.
Same exact thing with hospital billing - wipe that slate clean, the hospital has to take out loans to stay solvent, and they increase rates to compensate. And you know that they aren't going to be able to get anywhere with Medicaid or the insurance companies... so they're going to hit the people who are least equipped to take the even higher prices for medical care. Thanks, Mr. Script Kiddie!
You'd think that. I know a person that has gone bankrupt 5 times. He's always able to coax his credit score up within 2-3 years to rack up another 100k in credit card debt before he files for bankruptcy again, right on schedule.
I also know responsible people who've been completely fucked over by insurance companies who refuse to pay claims based on their own clerical errors, among many other horror stories.
Credit reporting is an unreliable, oppressive system, where your financial well-being is left in the hands of 3 companies that have minimal oversight and exist primarily to help lenders fuck the consumer out of money.
Anyone who has your social security number can start reporting derogatory accounts on your credit and seriously hurt your life that way. Think twice before you fork that number over to the dental receptionist.
The idea of this type of hack is to force a change in the methodology, not just to reset the counter. These hacks would have to be continuous service disruptions to be effective. They can't just do it once and let everything go back to normal.
For what it's worth, my credit score is currently in the mid-700s.
I personally believe this type of thing is inevitable. There are people in the government who recognize this too, and have been pushing for cybersecurity initiatives to prevent it (though these concerns have been co-opted by politicians for use in forcing down oppressive copyright and surveillance legislation, pleasing media company donors).
There is a great deal of latent risk in this hyperconnected world. It'll be amazing and frightening to watch hacks at this type of scale play out. Like I said, I have no doubt whatsoever that they will.
You could always just not borrow money.
Cell phone bills, internet bills with cap charges, medical bills; just to name a few.
They bill you later, and in the case of medical bills, you don't even have a clue what it will remotely be.
In a creep of scope, credit scores are now used to determine whether or not you can be trusted to rent a domicile, the size (if any) of a deposit for utilities, increase/lower rates of one's auto insurance, and even some employers now use credit rating as part of screening candidates.
Even if you never borrow money, your credit scores impact your life.
Many people don't know how to make money as adults without borrowing money to go to university (and student loans are non-dischargeable debt), so as soon as you become an adult, before you can even enter the productive workforce, you're saddled with tens of thousands of dollars in debt and interest payments that'll follow most people around for decades.
Culturally, people in the U.S. are pressured to buy a home as quickly as possible. If you're in your 30s and still renting people assume you don't know how to manage money. Renting and tenancy in most places in the U.S. is configured such that if you want stability, you need to "buy" (meaning, you need to pay rent to the bank instead of a landlord).
If you want a decent car that doesn't break down constantly (which is a functional requirement in most places in the U.S.), one generally needs to borrow money to afford that, at least until he's well into his career and has the opportunity to redirect some student loan money into paying cash for a car.
You have to borrow money on credit cards to get a decent credit score that'll make it so you're not immediately underwater in these fixed collateral-backed installment loans.
While it is theoretically possible to go without borrowing much money, it's not practical for the majority of people. It was made that way on purpose, because banks like money. The system is structured so that the average American pays at least 2x the real cost of goods all the way through to retirement (pays once to the vendor/seller, and once or more in interest to the lender that financed the purchase).
I personally find this disgusting and really hope we can see changes that make interest and borrowing truly and practically optional for average people in future generations.
If I worked at FBI I'd be angry and motivated. The retaliation won't come in the form of a zip file, either. It completely boggles the mind that someone thought that this was a smart step toward their own goals.
"Let's shut down Mastercard!" I guarantee that someone somewhere in the world was attempting to pay for an urgent medical bill during that time-period. What did the hack actually change? Nothing. It merely proved the hack was possible.
You don't just hack someone and automatically change the world for the better, for the worse most likely.
Also, this is very dangerous information. For people who download it. There's huge potential for life-altering asshattery.
I absolutely agree that there would be far-reaching consequences from hacks that neutralized the medical billing/insurance systems and the credit reporting systems, but I disagree with your assessment that those consequences would be a net negative. I believe they would be net positive.
Looking forward to the next act of transparency.
Edit: actually the most realistic scenario - whoever's on call in IT gets to work the night restoring backups. Meanwhile doctors are pissed off and lose time, because they may not be able to update or trust the medical records, unless it can be proven they were not changed.
The concept is to make it impossible to do business under the existing conditions. If hospital systems are unable to bill their patients because their systems are constantly scrambled by vigilantes, it'll affect the cost-benefit calculation involved in continuing operation under their existing business model.
Undoubtedly there would be confusion and misapplied bills involved. I don't see that as detrimental to the overarching cause. The only reason these systems are able to operate as-is is because their architects have devised a carefully fragmented and extremely confusing system that splits American society such that unity on the issue can't be achieved without substantial personal cost to the members of the more powerful/useful social factions.
If someone can level that playing field, we'll be well on our way to substantive change. When the powerful people have to feel the indignity of getting their credit wrecked for a decade or more because their kid fell down at a playground and got a concussion, even though they took every precaution that the man said they'd have to take to survive this kind of routine nightmare semi-intact, the rules will change much faster.
At present, the poor get their medical care pretty well taken care of through Medicaid. The rich don't care because they can throw infinity money at health problems (which is not to say they actually have to). It's the middle class that's getting raked over the coals, because they're not rich enough to force a change through monetary influence and they have too much to lose to force a change through social action.
I'm really not even a single-payer or socialized medicine kind of guy, but the current system is the worst of all worlds. The ACA provided a few useful tweaks but overall the system is just getting worse and worse. It shouldn't be allowed to stand.
I also do not really care what system we have in the US single or federal, we just can not continue to ignore the repeated failures that "sorta" socialized programs leave in their wake.(CRA) Just one or the other.