LulzSec Leaks 62,000 Email/Passwords of writerspace.com
thehackernews.com
thehackernews.com
Is there any way we can help these 62,000 people? I'm reading through the password list now, and many of these passwords are to people's gmail accounts. I see a comcast account too ... you could probably access billing info just with that password alone.
It feels like our duty, somehow, as good internet citizens, to help these people out. Many of them are probably mom'n'dad-types ... they have no idea what a "Database" is, let alone what it means for one to be leaked.
But we can't just go and change their passwords, even if it's for their protection, since it's the password to their email account and we have no way of notifying them.
A more realistic alternative might be to notify Google with a machine-readable list of email addresses the passwords for which have been compromised so they can do a system notification of these users without fear of getting eaten by spam filter.
As a good internet citizen you should be more worried about the companies that you have accounts with and getting them to improve their security before this kind of thing happens to you.
If you blog about it and submit it, I'll upvote it.
I really thought about sending them an e-mail, but then I'd be an easy target to blame.
edit: My PR senses started tingling on further reflection.
The best way for LulzSec to be countered is in the PR arena. Since they're already bad guys, and since they've already worn out their folk hero sheen, it does no good to villify them.
The best way is to steal their thunder. An organization of people who make a concerted, publicized effort to mitigate damage to the random victims caught in LulzSec's blast radius would definitely steal the limelight.
It's similar to responding to a forum troll by making fun of them. Take away their momentum and make them a pawn in your press releases.
The chickens are coming home to roost on the ATF thing and I sincerely hope that, if my suspicions are true, they do the same on this.
I'm not sold on this being one gigantic government conspiracy. I wouldn't doubt the existence of this being one giant social engineering tactic, but something in the back of my head tells me otherwise. I stand by the belief however that this group is just further enabling the US and other nations to take actions against internet freedom by their tactics against it.
Yes, I'm advocating some well-thought-out censorship in this case.
Anonymity + audience = lulzsec. If we remove the audience, we remove LulzSec.
1. You will give far more publicity to LulzSec than they are already getting by acknowledging them as such a severe concern you've pulled your engineers off other more valuable tasks to enact draconian and totally meaningless interdiction efforts
2. It won't actually shut them up. LulzSec is an example the ultimate asymmetrical enemy. They have fewer numbers, fewer financial resources and less technology, but have a mastery of the terrain. You don't defeat a guerrilla by pretending they don't exist. You do not attack them where they are strongest.
3. You're not actually achieveing anything here. Twitter isn't exposing itself to legal vulnerability here, and you certainly wouldn't shut up LulzSec for even a split second by just taking away their Twitter account.
I mean, honestly, have you thought this through at all? Have you paid attention to anything in the last 20 years? This kind of short-sighted feel-good finger-in-the-dyke measure is exactly why we're all sitting here screaming into the wind about copyright and piracy. What a shame that there are so many people who think this is the way to handle serious issues on the Internet.
Nope.
You're correct. When I'm presented with a problem, I tend to point out the first solution that comes to mind. If there are secondary problems, I refine the solution until the problem is solved.
In this case, the secondary problems would be that LulzSec would gain more audience, rather than be effectively censored, due to the Streisand effect. (http://en.wikipedia.org/wiki/Streisand_effect)
Do you have any ideas for a solution?
Those things just depend on which side of the fence you stand; that's why they shouldn't be considered.
As Voltaire said or Evelyn Beatrice Hall wrote: “I disapprove of what you say, but I will defend to the death your right to say it.”
Why would you do that when there are more dangerous things happening, such as companies not securing their websites and databases or governments that are trying to lock down the internets?
I'm more worried about governments having LulzSec's capabilities than LulzSec.
The horror.
I imagine he's made a killing lately with all the Lulzsec drama that gets reflex upvoted. Just more noise and blogspam. He submits several stories a day exclusively from that domain, thehackernews.com
And all companies should be on red alert, because if nothing else, this is an amazing wake-up call about security.
Assuming that most people use the same username and password for most things, and that AOL users will be the least sophisticated I thought it would be interesting to verify 10 of the combinations which had an AOL address against AOL. Not a single one of them actually worked and I'm inclined to wonder whether (happily) this isn't just a hoax.
If they are going to keep on hitting targets like this just because they can then, they could at least release only the email addresses and not the passwords, which will illustrate the point and allow affected users a chance to know they are at risk from the sites policies whilst reducing the immediate risk to their data.
Obviously what the could actually do is just release nothing and work with administrators to correct the errors, but then they wouldn't be garnering the publicity they so obviously crave.
Nothing good will come of this..