Analysing the alleged Minneapolis police department “hack”
troyhunt.com
troyhunt.com
I've actually built a system which did this years ago, over our initial protestations, and the reasoning went like this:
Our client (this was a white label product) has lots of elderly couples as customers, these are our end users and although they're on the Internet (makes sense, this is after all a web site you've white labelled so if you have customers without Internet that's a red flag right there) they only have one email address between them. So some end users want two accounts, but with one email address.
This made the login procedure a bit hairy and obviously there are scary corner cases for things like change password (Alice decides to use the same password as her husband Bob, now we can't tell their accounts apart!) but we felt that arguing with clients about why they should do Single Sign On (and thus eliminate the separate login for our white label product altogether) was more valuable than trying to change old people's minds about what constitutes a reasonable thing for two people to share.
I think the logical next step is to give them the same password and see how bad my foot hurts afterwsrd.
Also the fact that when you ask your login to be remembered the will just show you the email at the next login, without telling you if it's the personal or work account.
It is the worst login experience Iv've ever had, bar none, I am constantly amazed how they could ship that and always wonder what hellish dungeon of reasons there must be behind the decision to keep it as it is.
Yes, this can be confusing.
So you can have two accounts, say for (vimslayer@contoso.com, Microsoft Account) and (vimslayer@contoso.com, Contoso AD) - and there is no collision and no possible confusion on the system end. All the confusion is on the human end.
And there is a lot of confusion on the human end :)
However your organization may then do a deal with MS for Azure, or MSDN subscriptions, etc. And they’ll issue a login with the same email* address you@work.com — you now have two accounts tied to the same email, one which you created by yourself and one which your IT department created for you. There’s no way for you to change this second one. Typically authentication for the second one will happen via your org’s single sign on.
So the answer to “is this account personal or issued by your IT dept” really means — did you create the account yourself? Or was it provisioned for you by IT?
* Many orgs by default don’t use email to log in. Instead a “username” like jsmith is used instead. However while interfacing with Azure it seems to be a best practice to use email.
https://www.abc.net.au/news/2020-06-01/scammers-stealing-tho...
I had a family tech support session on this exact issue last week. A relative cleared her cookies and found her saved email and password for Facebook were logging her into a profile she'd never seen before. At some point Facebook had decided name@netzero.net and name@netzero.com were the same thing. We got around the issue by logging in using her account name gleaned from someone on her friends list.
nice.old.couple+alice@gmail.com
nice.old.couple+bob@gmail.comEdit: sendmail and qmail, too, apparently: https://www.cs.rutgers.edu/~watrous/plus-signs-in-email-addr...
Easier to remember than a username because it's guaranteed to not be taken, so you can use the same email everywhere: email+name@provider.tld. Where as "alice" probably is taken.
Also should work with any email provider, it's part of the standard.
If the intent is to allow two people to have independent accounts even while using an email they both control, offloading that to the email protocol seems broken to me. It's the exact same email address from the perspective of security. Anything coming after the plus sign should be ignored for the DB key, but kept around for sending emails, so it can still be used for filtering those emails (for convenience, not security). So they could sign up either as
alice <couple@notgoogle.com>
bob <couple@notgoogle.com>
or as alice <couple+alice@notgoogle.com>
bob <couple+bob@notgoogle.com>
but that difference should only ever matter for their email filtering, not for identifying them.> But anger shouldn't mean throwing logic and reason out the window and I cannot think of a time where fact-checking has ever been more important than now, not just because of the Minneapolis situation, but because so much of what we see online simply can't be trusted. So by all means, be angry, but don't spread disinformation and right now all signs point to just that - the alleged Minneapolis Police Department "breach" is fake.
The above text really does question what we see on the internet since it is very easy to fabricate news and evidence like this. With that being disproved, we should take such news on social media with a grain of salt until the full evidence from each side and analysis is available.
Once we do that we will be less susceptible to being deceived unlike the retweeter at the bottom of the blog post.
You might have almost answered your own question. If there are many videos shot by random bystanders in multiple angles of the event, even if one is fabricated, another video can disprove it; making it harder to fake the event.
This would mean that one would have to 'fake' all the videos and angles from other people which is difficult to do, especially if it is live. So with that, it can be proved to 'have happened' but only if the bystanders are un-related to each other. Otherwise it will look 'staged'.
There are systemic issues all throughout the government, and as long as cops keep killing people the riots will continue. Maybe they'll temporarily subside, but when the next killing happens it will flare right back up. Cops operate with impunity, and the politicians go on TV apologizing for them because they're afraid of the police too. Just look what happened to de Blasio's daughter, who was arrested by the NYPD under questionable circumstances.
It's crazy watching this all unfold, but if real change isn't implemented soon it will continue to foment. It doesn't help that along with racism, there's significantly economic inequality. Real unemployment is somewhere around 24%[0], food prices keep going up[1], and many still haven't been able to access unemployment benefits.
[0]: https://fortune.com/2020/05/28/us-unemployment-rate-numbers-...
> The account also posted de Blasio’s internal arrest file, which included her home address (Gracie Mansion, the mayor’s residence), ID number and other personal information.
[0] https://talkingpointsmemo.com/news/nypd-sergeants-union-twee...
apparently the address is public knowledge anyway, if that wasn't true the doxing would be a lot worse.
I don't think this will change much when it comes to governing. Hopefully there will be change with how the police work in the US, but the political play is going to stay the same. Some people might just end up being switched out.
Just think of it this way: almost all of the rioting/protesting is happening in blue areas. They have a Democratic mayor, police chief, state representatives etc. The police are under the control of these local officials, not federal officials. At the same time, many of protestors are angry at Trump and other Republicans on a federal level. So who do they vote for to enact change? Voting for those same Democrats in local ejections keeps the status quo, but at the same time they don't like the opposition (Republicans). They can elect a different federal president, but that isn't going to change the police issue as long as the local status quo remains.
All in all, I would say that politically not much is going to change.
There’s lots of people cheering on the violence. The strangest are the white collar professionals, the celebrities, and the executives. I will say, in a few instances it felt good when these Twitter agitators got spooked as the violence they wished upon others neared their own gated neighborhoods (and I don’t say this lightly as my neighborhood is being terrorized right now).
https://pjmedia.com/instapundit/wp-content/uploads/2020/05/c...
"The protesters are now threatening officers at home, all methods of force to end this disturbance shoulders be tolerated."
You: "But the password didn't work - I didn't get in!" Judge: "You and your cellmate Brutus will have, oh... five years or so to discuss the finer legal points of your case... when you two are not 'otherwise' occupied. Baliff, let's not keep Brutus waiting."
such as?
This is impossible because Anonymous isn't an "actual group". It's any one who does anything and calls themselves Anonymous (a word that means "unknown name").
> So by all means, be angry, but don't spread disinformation and right now, all signs point to just that - the alleged Minneapolis Police Department "breach" is fake.