Hacktivism, leaktivism and the future
ddosecrets.substack.com
ddosecrets.substack.com
The hero worship of MalwareTech, despite the fact that he absolutely committed crimes _which he plead guilty to_ is often the biggest clue.
As much as you can think you're on Team GoodGuy, if you commit crimes there are consequences for it. The feigned surprise and rallycrying needs to end. grugq's talk on OPSEC is step one. You're not a brand, don't sell fucking merch!
If you're doing "research" or "freedom-fighting" and it runs afoul of local laws, don't be surprised that the fuzz breaks your door in one night just because you couldn't stop yourself from chasing a bit of personal fame in the process. And as someone who knows most of these people, the vast majority are ego-driven.
At least the black hats are honest about who they are and what they do. And you don't hear about most of them because constantly seeking attention hurts their wallet.
As a result, I've seen so much recycled research trying to be passed around as new work by people trying to make a name for themselves it's unbearable.
This especially happens in the crypto space, where you can take any basic concept like "Basic XSS Vulnerabilities", but applied to popular crypto exchanges and conferences will book your talk.
The number of people out there doing genuine cool shit (the kinda stuff you see in PoC||GTFO) are few and far between these days.
I know a large number of them personally, some of them are nice people, but most of them are pretty insecure and constantly looking for acknowledgement. To a degree I guess we all are.
The number of people that want to skip working in IT / understanding other parts of business and go directly to their Offensive Security Cert and be called a hacker is numbing. Theres a reason most of the training programs within the leading firms / govt agencies, require following the apprentice / journeyman process much like other trades. It takes time and a deep understanding.
But nah.. i'll skip all that because check out mah tweeets.
edit: I believe [0] was the feature I read.
[0]: https://www.wired.com/story/confessions-marcus-hutchins-hack...
What you posted is a good story to tell though. Turning your life around after doing dumb shit in your real name and getting caught is plenty convenient but not worthy of hero worship.
The only reason MalwareTech served no time is because Ollam and his wife used their influence, political connections and their bank accounts to lobby aggressively on his behalf.
He realized that he sucked at making money by developing malware and decided to pivot to working for other people.
> "As a show of gratitute[sic], the U.S. government had the Swiss police move up a raid of Tillie's apartment by a week.
Maybe that had to do with the Nissan hack a few months prior, or the intel hack in 2020...
> "In January 2021, Kottmann was involved in a source code leak from Nissan,"
> "On August 6, 2020, Kottmann uploaded more than 20 gigabytes of Intel's proprietary data and source code to Mega"
I recently listened to the latest episode of the Darknet Diaries and it really opened my eyes to how careful actual white hat hackers are. There are huge/subtle lines that they dare do not cross, which Tillie, sure as hell crossed :
https://darknetdiaries.com/episode/87/
> "The group collected about 5 gigabytes of data, including live security camera footage and recordings from more than 150,000 cameras in places like a Tesla factory, a jail in Alabama, a Halifax Health hospital, and residential homes"
Exploiting the data breach AND THEN disclosing is not "white hat" hacking
And as much as I personally prefer full disclosure to "responsible disclosure", this isn't that either.
If it isn’t apparently already, hacktivists are by and large just a criminal arm of the progressive political machine. You aren’t going to find these groups exposing the activities and private communications of left leaning groups. Using criminality for political goals is terrorism, and this group should be labeled as such. Twitter and other platforms seem to be giving them safe harbor, however, even though they’re willing to censor others so readily.
(I do think your guess is a plausible one)
That is much more plausible than assuming they are a leftist criminal arm. Actually, had that been the case, we would have seen hacktivists that support both sides, because, as you said, they are 'just a criminal arm' and can be bought.