LulzSec's 'Topiary' arrested
nakedsecurity.sophos.com
nakedsecurity.sophos.com
I'm not sure what your point is here.
Our governments have no comprehension or understanding of the prospects or implications that the internet has on modern civilization. When an individual can take down an organizations method of operation (mastercard/visa/paypal), it isn't the individuals fault (regardless of their actions) it is the organizations fault.
You don't blame someone for stealing from a bank when they pile gold bullion in the entrance without a guard in sight. You blame the bank because that's fucking stupid.
Being able to dDOS mastercard isn't the individuals fault, it's mastercards. I've never heard of someone dDOSing Google, why? Because Google only makes money when people access it and their system can support insane amounts of instantaneous traffic. It's a simple fact that sooner or later mastercard/visa would have been taken down by a normal traffic spike.
Is it the users fault when mastercard gets dDOS'd by a few million people placing midnight orders on Black Friday?
Seriously, look at the world rationally. If I can spend $5 on a padlock, it's my fault when someone steals my $500 BBQ from my back yard. Someone committed a crime, yes, but I'm going to be buying a padlock like I should have in the first place.
Why didn't mastercard/visa/paypal/sony/sony/sony/(sony x 27 fucking times) front the goddamn cash so they wouldn't lose hundreds of thousands.
Who cares whose fault it is? It's illegal, they get arrested, it's simple really.
> You don't blame someone for stealing from a bank when they pile gold bullion in the entrance without a guard in sight. You blame the bank because that's fucking stupid.
Sure, you can do that. That, and arrest the person too because, you know, they broke the law.
I think it's more relevant that what they did was willfully malicious. I probably regularly violate laws that I'm not even aware of, but the fact that I'm not intentionally doing harm to anyone establishes some kind of innocence.
"The rationale of the doctrine is that if ignorance were an excuse, a person charged with criminal offenses or a subject of a civil lawsuit would merely claim that he or she is unaware of the law in question to avoid liability, even though the person really does know what the law in question is. Thus, the law imputes knowledge of all laws to all persons within the jurisdiction no matter how transiently."
I get the impression reading some of the blogs that some of the arrests recently have in fact picked up people who were 'known' to other people who might very well become somewhat more cautious.
Which kinda makes me grin and roll my eyes at the same time.
You can kill a man, but you can't kill an idea.
###########################################################################
###########################################################################
ooooooooooooo o8o
8' 888 `8 `"'
888 .ooooo. oo.ooooo. oooo .oooo. oooo d8b oooo ooo
888 d88' `88b 888' `88b `888 `P )88b `888""8P `88. .8'
888 888 888 888 888 888 .oP"888 888 `88..8'
888 888 888 888 888 888 d8( 888 888 `888'
o888o `Y8bod8P' 888bod8P' o888o `Y888""8o d888b .8'
888 .o..P'
o888o `Y8P'
###########################################################################
###########################################################################
Now we have Topiary. Probably the lamest one of the bunch. He doesn't
actually do anything except give interviews. There are plenty of logs of
him all over the internet being a complete idiot. His "d0x" are all over
the internet also. He tries to deny it but there are logs of him bitching
about being d0x'ed int he #hq logs that Laurelai leaked.
Name: Daniel Ackerman Sandberg
Location: SwedenYes, it was the only realistic part of the movie. It is a bit frightening to be woken up by a man pointing a shotgun in your face when you are 13.
IIRC, there was a well known NYC hacker who was getting ready for school, and was in the shower, when the SS burst in and the scene was loosely based on him.
I'm not sure if it is SOP, or the Secret Service thought they were dealing with violent criminals. But they knocked down the front door with one of those rams you see on TV , ran room to room "securing" everything. Once they realized they were dealing with a scared 13 year old they seemed more embarassed than anything.
In addition to the local cops, and the Secret Service, there was a postal inspector involved, that guy was kind of a dick, he kept sneering and telling me stuff like "you are going down buddy", even at that young age I figured he didn't get out of the office much. The Secret Service spent post of their time bullshitting and telling me stories of various trips abroad with the president. Some of the nerds bagging up all my equipment would sometimes come in and peer at me, asking me minor questions like "Why do you have so many batteries" until they were reminded that I was a minor and they did not have parental permission to ask me questions.
I waited for years for the other shoe to drop, and be indicted, but I never was.
I still have all the equipment, still tagged, and even have some disks they put in the drives labeled "SS transport disk"
seems possible the bulk of them had first learned about hackers at the same time they learned about the raid -- perhaps from someone who exaggerated the average size of a hacker's fangs. in any event it doesn't seem likely that in preparation for sundevil they'd have consulted with anyone that would have urged a relaxed and moderated view of what was at that time an unexplored frontier of law enforcement.
Sounds like good cop, bad cop to the extreme. I think I'd deal in 5 seconds if a cop offered me milk and cookies over handcuffs.
I'd think the FBI would in on it too.
- obvious digital connection (forgot to use tor / ipredator / hacked vpn)
- timing attacks (keeping normal waking hours for his home country, using a vpn instead of tor)
- word frequency attacks (since he wrote a lot of press releases, his word choices may have been cross correlated with a personal blog)
- bragging to a friend
- getting flagged after showing up at a political/high-suspicion meet up (which might be enough to allow for a timing attack)
- voice analysis from interviews he did w/o a voice transformer being matched to other audio
- opsec blunders (loose lips when talking to press / on IRC / wherever anon talks)
Anyone else have any guesses?
* setup numerous honeypot open proxies and tor gateways
* work with journalists to have all emails and communications forwarded
* isolate ddos clients and reverse-engineer command and control. surprisingly many of these trojans are poorly written and have security holes themselves
* setup numerous fake twitter profiles and provoking them into responses - things like posting images, replying, etc.
* setup fake hacker groups. stage defacements etc. in order to get in touch with them
* I would write a system that tracks and stores every bit of communication they make and plot out their social communication graphs and when they are talking, who to, etc.
* ask ISP's or proxy providers to grep for traffic patterns.
* get user-agent info from twitter, or provoke them into visiting a link, and possibly load malware. no browser is really safe in a targetted attack
* word/speech tracing. this is why 1337 5p34k was invented, so you can not be traced via your vocab/grammar/spelling/phrases etc. it doesn't take a large sample to start narrowing it down
probably more - haven't really thought about it, but when i did see that they started using twitter I gave them 3-4 months, tops.
This is certainly the most direct way. I'd be pushing exploits from the twitter data center and sharing links to funny/cool #antisec whatever in irc hangouts. The client is almost always the weakest link here, and with people using multiple devices you get lucky once or twice and get some malware on a phone or pc.
If you're investigating foreign hackers on foreign soil you have a lot of leeway in terms of back hacking them, the US is definitely using this kind of approach in anti-terror.
Once you get the right guy and know it's him, share the details with the local authorities and let them figure out what legal info they have to build a case now that they know who they're after.
The other way I'd do it is with a fleshed out honeypot. Set up something tempting with two stages of flaws and some good documents. Bring the first flaw to on of the farm irc channels with something semi-juicy you got out of it. They'll probe the rest of the system and find the second dangled SQLi flaw and some juicy data. If you can set up and watch them in advance some mistakes will generally be made, and whatever documents and executables you leave to get stolen will probably end up being handled in an unsafe fashion. Think how tempting a VPN software token authenticator would be to run, and I highly doubt that stuff would get RE'd before it got run. If you can get them to voluntarily run some software they stole from you you won't be needing a warrant in advance.
What about txt msg spk?
"* setup numerous honeypot ... tor gateways"
What would that achieve?One of the better broadsheet newspapers here in the UK had an article on Lulzsec/Anonymous, and one of the best comments they made was:
"Hackers fear other hackers more than law enforcement."
In this community it seems there is no honour amongst thieves. I very much suspect they grabbed a bunch of people around the world who were less talented at hiding themselves, and one of them knew enough to plea bargain in return for information.
>One important feature of a conspiracy charge is that it relieves prosecutors of the need to prove the particular roles of conspirators. If two persons plot to kill another (and this can be proven), and the victim is indeed killed as a result of the actions of either conspirator, it is not necessary to prove with specificity which of the conspirators actually pulled the trigger.[1]
I'd assume English law has something equivalent -- it's a really old problem, and involving computers won't change the principles involved.
[1] http://en.wikipedia.org/wiki/Conspiracy_%28crime%29#Conspira...
LulzSec isn't anything new, this kind of hacking has been going on since the 80s - they've just taken a different approach with the media. And snitching is always how hacker groups fall.
This is essentially how all law enforcement investigations work, actually. Drugs, hacking, graffiti, white collar crime, whatever. Get a good snitch and you'll get the whole organization eventually.
Everyone succumbs (snitches) with the right encouragement (threat)
Catch a weak link, offer them a deal in exchange for information that leads to the conviction of someone higher up in the organization, repeat until you make it to the top.
http://www.guardian.co.uk/technology/2011/jul/27/lulzsec-hac...
The source is the Metropolitan Police Service of London, a.k.a. Scotland Yard.
Frank Abagnale Jr. comes to mind.
The people who are worth catching for the sake of their minds ... don't get caught. At least not nearly as easily as this group.
I suppose teenagers enjoy more freedom in Europe, maybe it's more appropriate there.
http://nakedsecurity.sophos.com/2011/07/20/arrests-lulzsec-a...
Not a good time to be a hacktivist
A criminal is a rigidly-defined adjective meaning an entity which breaks or broke laws.
An activist is a rigidly-defined term meaning an entity which acts to further some idea and bring it to public perception.
A hacktivist isn't well-defined, but we'll assume here that it's a form of activist.
Now based on this, the Anonymous and Lulzsec hackers were hacktivists, at least according to their own statements of their intent. They also were criminals, at least according to my reading of the laws of the US. Now, what you may be looking for is whether they were ethically good --- but don't conflate lawfulness with morality, that's worked out poorly in both directions.
But of course, you acknowledge that this is a horribly simplistic view of things. Even DnD got this, after all (clearly Anon is Chaotic, and whether it's Neutral or Good depends on whom you talk to).
So perhaps you might say "I don't believe Anon's actions were for the good", or even "weren't well-intentioned", but please recognize that passing judgement beyond noting the factual statement that they are criminals, is a personal judgement. Not that personal opinions shouldn't be argued, defended, and spread --- just that they should not be conflated with fact.
But, what cause or idea have they furthered? Computer security? Social injustices? Tax evasion by corporate amarica? I can't find one other then their own personal enjoyment.
I can not point to a single action they have taken and describe it as "constructive." The issues they do occasionally allude to could be furthered much more successfully, legally and in a morally responsible fashion (respecting individuals privacy) by other means.
As for their harm, it is fairly self explanatory, but to make it clear, releasing innocent individual's personal information and encouraging others to use it to commit further crimes is most decidedly not neutral.
I don't believe LulzSec's actions helped anyone. If you think they did some good, please enlighten me, point it out. I can't see it.
PETA nailing people with red paint on the street is incredibly counter-productive to their cause. Hell, it probably actually increases sales of fur. They are still however activists.
No, they aren't. Lets review the definition.
"An activist is a rigidly-defined term meaning an entity which acts to further some idea and bring it to public perception."
If you agree that PETA's red paint stunts are counter-productive, how can you then turn around and argue that the same red paint stunt is furthering (is productive) to the cause?
While some of their attacks have stated goals that appear to be activism, some of them, like the attacks on Nintendo, pron.com and Minecraft appear not to serve any type of activism I'm aware of.
That was the core message between the lulz. That said, dumping the full data was not necessary to make that point, even though it probably increased the media coverage, hence the spread of their message.
Far better cause than saving whales or impeaching presidents.
I see that we are keeping this classy. Why am I not surprised?
On the other hand, I feel that you should understand why your comment is not smart. "X bad/useless activity is better than Y bad/useless activity, therefore X is ok" is always a stupid argument.
> They're criminals.
So was Martin Luther King.The civil rights movement has been historically full of criminals. Lets question the legitimacy of all their claims!
Lulz puts as much effort in to remaining anonymous as anything and, it would seem the consensus opinion here, folds like paper houses when they get caught. I didn't see MLK Jr trying to negotiate a sentence down by selling out the rest of his leadership. Instead, he actually accepted prison time rather than pay a fine because he truly believed in what he doing.
Not quite an equal comparison.
It's not. It's much more complicated than that.
The idea that we would arrest another human being for sitting at a lunch counter, etc, is designed to provoke outrage at the unjust situation.
The Crito is an excellent place to start in examining I suppose the philosophical roots of civil disobedience: http://en.wikipedia.org/wiki/Crito
An arrested hacker activist is a hacker inactivist. Expecting them to allow themselves to become arrested is absurd.
Living as I do in the San Francisco bay area, I encounter all forms of activists from people living in trees on college campuses (illegally) to folks who provide services to undocumented workers, to folks who expose security flaws on web sites. Of the ones with whom I've been able to talk briefly about their goals, all of them did not grasp that the results of activism are later perceived through the dialog of what the people that 'win' write. (sort of a variation on the winners write the history)