German politicians targeted in mass data attack
bbc.co.uk
bbc.co.uk
I wrote an encrypted pastebin that uses IPFS: https://hardbin.com/
I run a public gateway for it on the hardbin.com domain to make it easy for beginners to use without running their own IPFS node.
Earlier today I got my first ever takedown request for a hardbin paste! CERT-Bund ("the national cyber security authority in Germany") gave me a link to a paste with encryption key and asked me to take it down. I have blocked the link in my nginx config, but I don't know whether that was the right thing to do or not. I'm interested in hearing opinions either way. Obviously it can still be accessed through other IPFS nodes.
The paste contained a bunch of German political party names, alongside links to RAR files, which I presume contained this leaked data.
It is on the leaker to find methods to share files that can not be easily traced to a public server or a named owner. This is no different than if someone running one of the many reverse tor proxies (public to hidden network) were told to block access to something. They risk losing their server, domain, accounts and much worse. When dealing with embarrassment of government officials, laws get a little muddy and some people will look the other way.
It seems more like a waste of public resources to take down links to encrypted files on a distributed file system? The nodes dont even know what theyre hosting and the cataloger to the pointers has pure discretion
How badly I wish this was true in other parts of the world!
The law was changed in 2002, where it was still legal in non-German context and not concerning foreign public officers. Now that is illegal too.
That doesn't mean there is non though, I wish it was true in Germany as well.
I've never been to Germany, but from what I've read/heard, Germany will probably score pretty high by my standard
There's also things like John Stossel's short documentary on setting up businesses in HK and in India.
While I am against cheating, of course, I have to think that having all those cars junked just due to that scandal was a far bigger waste and far worse for the environment.
It was about sending a message. And probably also about the fact that VW is a foreign car manufacturer. Let's not forget the bailouts that the American car companies got just a few years ago.
They basically just doxxed them, put up photos, names, account info of famous people, politicians and their families (at one point publishing photos and personal data of the little children of the host of a German late night show), and for a handful of them also published their entire iCloud content as well as all messages they ever sent/received on social media.
There's nothing fishy in there, just a very unethical and bad hack. Especially considering the hack only targeted left-wing people[1] a political motivation isn't be out of the question.
Footnotes:
[1] The hack targeted all parties that were at the time in parliament, but also many private people such as musicians, artists, TV hosts, etc. All of these people were politically left-leaning.
In addition to hacking the systems of political parties, they also hacked many left-wing musicians, artists, TV hosts of late night shows, etc.
I've clarified my original post with a footnote.
But here in Germany, CDU was always considered "right".
For example, CDU/CSU politicians didn't want gay people to call what they have a "marriage". Merkel said so back in 2017, and eventually voted against the law together with more than 2/3rds of her party; the law passed anyway with the votes of the CDU's coalition partner SPD and the opposition parties. So there are some commonalities with the US right wing politicians and their policies, after all.
1) not true, FDP and CDU are certainly not left-wing
2) even if it were true, would it be more ethical to hack right-wingers?
The current speculation indicates no political leaning whatsoever (apart from one password of one leak for one socialist politician was "linkenshit" which could be either neutral, positive or negative).
Considering the age of the leaked data, it is speculated that during the time of gathering data, the AfD was not part of the targeted parliaments.
I guess the thinking is "it's targeted against one side, so probably look at the other to find the perp". Would be just as true with hacked right-wingers.
(and the corollary: "it's a flag-flag operation by the very same side, so look there", which also comes up no matter what side is affected)
As mentioned in the footnote, I was referring to the individuals hacked, not the parties. In addition to the political parties, the hack also targeted youtubers, artists, musicians, etc.
These include Christian Ehring, Jan Böhmermann, Oliver Welke (all hosts of left-leaning late night or satire shows), Marteria, Casper, K.I.Z. (left-leaning rappers/music groups, or in case of K.I.Z. even explicitly anti-capitalist), and several YouTubers.
Additionally, the twitter account doing the hacks has mocked Böhmermann's Reconquista Internet explicitly.
The problem is that any side was targeted.
In the US that would probably just lead to a minor apology. I remember a teutophone math professor mentioning that when she was explaining how serious plagiarism was.
After the Guttenberg scandal a wiki sprung up which investigated more past academic works from people, first mostly politicians.
Now, plagiarism is a serious issue, but these politicians were not “faking” their academic records. They actually had those titles, the universities had just failed to identify their plagiarism and given them the titles in spite of it.
As such hacking them won’t likely reveal such scandals, only actually looking at those (already public) academic works and searching for plagiarism will … which is what has already been happening.
—
† Annette Schavan resigned two years earlier because of plagiarism-accusations, so his wasn’t the first case, even when only looking at recent cases.
'Faking' is a word not even strong enough. Those people acquired titles by fraud and deception.
Schavan resigned in 2013, two years after Guttenberg.
It would indeed be awkward and something politicians everywhere would be reluctant to implement but it would work and respect human rights which is more than can be said about many measures in intelligence.
This argument is strong in theory, but not so much in practice.
This is like arguing for monarchy because democracy is a huge amount of time/effort and is imperfect anyway so why not save time. I've heard many bad arguments for monarchism as it happens, but none are quite so bad as "Why bother even trying to have good government?"
I believe that shows the popularity and image contest of democratic politics.
1) It seems, that these documents or a majoritiy of them are tied to the personal lifes of these people, not to the political institutions they are affiliated with.
2) There are non-political targets: journalists, show hosts, singer / rapper -- people affiliated with media in general.
3) Some of these published materials were photos and docs of family members, children etc. When they are made targets of this form of intelligence gathering, something seems horribly wrong. They become victims because their spouse / mother / whatever is pursuing a political career -- this is just wrong on so many levels.
It also filters against politicians with unrelated personal problems beyond their control. Maybe they have an abusive ex-spouse they divorced years ago. Do the details of the divorce need to be public? Maybe they have a family member in prison that they visit (San Francisco mayor London Breed's brother is in prison for murder, for instance). Given the state of our political discourse it will be very easy to attack politicians on the grounds that they have, or previously had, relationships with imperfect people, and those usually don't mean they'll use their office to help those people, or that their character is actually doubtful. And again it seems like it would unduly hurt those who come from backgrounds that aren't already the powerful class/group/ethnicity/whatever in the country.
Twitter* suggests there are at least evidence of nepotism amongst the leaked documents, so one would assume there will be some kind of fallout because of this. If this is common practice then I'd assume that demands for future transparency will be met with heavy resistance.
* https://mobile.twitter.com/JulianRoepcke/status/108108941972...
(On the other hand, exposing nonconsensual or coercive personal relationships is a benefit)
There's one exception
When one of those holier-than-though gay bashers (George Alan Rekers[1] being a great example) is caught with a rent-a-boy in an airport bathroom in a compromising situation (why always airport bathrooms?) is outed I think it's great and fitting justice.
For the hipocrisy and the immense damage those people do to society at large and to individuals specifically.
Else than that I totally agree with you. Consensual relationships and sexual orientation is nobody's business.
Do you really expect that politicians should publish the kind of data that was stolen in this case?
Were the computers of the individuals targeted directly via spearphishing, or was it done by compromising iCloud,etc. directly or (id say most likely) password bruteforce account and no 2FA.
If anyone finds an article with more details, please share.
2FA would likely have protected that person.
It's not really that complicated to just create a magnet of a folder and then spend time spreading the magnet link.
If so (as probable, according to Occam), just the usual incompetence, irresponsibility, and self-inflicted damage. If you keep confidential data under no better protection than a Mickey Mouse password, ought you not be held accountable when it is - inevitably - leaked?
so there are two explanations: 1) the AfD is not affected, because they just entered federal parliament a year ago and the hack happened before then. 2) whoever did this has no interest in harming the AfD.
hmm. editor?
>Only AfD appears to have escaped
AfD is a right-wing political party in Germany. Their focus is migration, Islam and strengthening ties to Russia.
Democracy and public policy do NOT benefit from this kind of "transparency." This is the "ad hominem" of hacks: vacuous, mean-spirited and — hopefully — entirely ineffectual.
I also disagree that there is no potential benefit. Maybe it reminds those in power that any data retained may come back to haunt you. And it might dampen attempts to weaken encryption. Even legislation which explicitly exempts politicians from mass surveillance would probably make the public more aware of the problem.
I don't think the reverse holds, though. Politicians will not end up understanding private people's concerns over surveillance, because to them it's something else entirely. One is a frivolous attack on the individual, the other is a more abstract policy goal for the Good Cause™. I'm not saying this line of thought is legitimate, but instead that I have the strong suspicion this will not be interpreted as a message for "Datensparsamkeit" by the powers that be.
I'm also wary of the argument that they "deserve" it. A lot of people who have nothing to do with said decisions were targeted, and maybe even some who opposed surveillance. The notion that "politicians" "deserve" to have their private data exposed by virtue of being politicians is Sippenhaft — collective punishment.