'I want your Instagram account': a deadly campaign over coveted handles
businessinsider.com
businessinsider.com
Traditional phone companies absolutely should do a better job vs spoofing (and I believe there is supposed to be at least some progress there via STIR/SHAKEN in the US at least), but I'm a lot more inclined to blame services and particularly armed response services that still treat them as secure in a way they have long long LOOONNNGGG since proven they aren't. Telephone numbers simply were never ever a particularly secure thing, predate the entire net let alone widespread use of cryptographic protocols, and retrofitting real security onto that legacy has proven non-trivial. They shouldn't be blindly depended on for something like SWAT deployment. Security services live in a world where they can be lied to and they act like it in other circumstances. They're the ones sanctioned by the state to responsibly employ lethal force, and have been given ludicrous amounts of outright military grade gear. They should be investing in tools and techniques to evaluate reports and gather intel on site before "storming the house". Even basic old humint like "asking the neighbors if they heard any shots" seems to have been tossed aside. Like take this very reported case:
>The caller told the dispatcher he had killed his girlfriend. He had barricaded himself inside his home in a quiet, affluent neighborhood on the eastern edge of Palo Alto.
OK, so maybe there is a criminal there, but by his own (suspicious) words nobody is in any immediate danger. The supposed body he's killed isn't going anywhere. Surround the place from a distance, sure, and if someone does start shooting from the house obviously that's clear enough. But if the police have the place covered and nothing happens, maybe ask some neighbors. Send in a drone or two. Get on the line with a judge for a quick order to use IR or terahertz imaging or whatever and see if that reveals anything. Get a megaphone and ask everyone to "come out with their hands up" even! If the police though just go and storm the place though they could well cause the very situation they seek to avoid, what if someone is fast asleep and hears a break in and opens fire to defend themselves? Hardly an impossible thing particularly in America. It's happened.
Everyone in tech knows all about blindly trusting user input. Yes absolutely it'd be good to deal with trivial spoofing but that alone isn't going to mean there can't be malicious input. Or even non-"malicious" per se, there are people out there on bad trips or with untreated disorders who might report fake stuff fully believing it. The human mind is an imperfect thing. Stopping spoofing also won't stop someone from making a real call from a real phone that they've stolen or hacked into some business network and used their VoIP, calls from the victim's number could just as easily be calls from "a neighbor who heard shooting and saw flashes through the window" or "concerned passerby". E911 is supposed to have a variety of standards for including location information and in principle that should cut back on this as well, if someone claims to be in a house and the location doesn't show they're at the house that should be a red flag. But that still leaves holes due to legacy and risk aversion from bad incentives. At the end of the day, I think any service for the general public needs to be careful about considering their inputs. Ask for money upfront for that pizza for the first order. Trust but verify and all that.
Edit: One useful thing the government could perhaps provide here would be something along the lines of a national "known harassed number(s) registry", where someone could report getting this kind of thing at their local police station in person, show proof of identity, and ask for their number to be flagged for a year along with a code word. Any future 911 calls could automatically be flagged in turn, the operator could ask for the code word, or at least let responders know that there was a history of spoofing and everyone should be extra careful.
Yeah, I've suggested this very thing myself on several occasions, but basically people who are against engaging in self-defense and prefer to use police officers as their own personal security are dead set against any kind of reform on this point. You're really not going to get any kind of reform on this point until it's more than just little people who are being inconvenienced by this. Basically unless and until SWAT shoots someone "who matters" it won't change... because some people are REAL sure they need a militarized police force who can kick in your door at any time on the word of an anonymous jackass on the other end of an unsecured line.
I'd agree, were it not for my knee-jerk tendency to argue the contrary - the girlfriend may in fact not be dead, but only in shock. Also how do you know there isn't anyone in the house?
But probably those would be outlier situations, and the steps you suggest would be better than storming in.
What is more important is how society will act with said regulations/decisions, and then you'll have no choice but accept that the best way forward is the one that's hardest to abuse.
The aggressive approach is extremely easy to abuse and there are currently no dangers associated to the abuser, which is why SWATing is on the rise.
In 2016 someone figured out how to successfully repeatedly reset the password without my knowledge (via support maybe?). But since my e-mail was not compromised they didn't manage to change the password (or I was quick enough to set it again before they executed some second step of their scheme). I upgraded the security measures to 2FA and some insanely long password and it ceased.
Since November 2020 I am subjected to a brute-force attack - someone is trying to log in and I am getting an email notification about it each time. In the beginning it was once every five (!) minutes, later every 15 minutes. It went like this for over a year, now it seems to be throttled with emails arriving once every few days.
I am suprised that for such a long time Instagram didn't implement anything to counter such activities.
But luckily, no pizzas yet.
This should be standard stuff really!
This is, IMHO, the key part. Mr Eberle found himself in a situation that would result in criminal charges for the "attackers" if they could be found, but the police simply gives up.
I have this problem also! I thought it was rare. In my case I think the person is very bad with computers and doesn't know what their email address is. I've gotten emails from their bank, cell phone, and even online dating. I tried mailing them a letter once to tell them they are making a mistake but nothing changed.
One day I decided to take action and sent a expletive filled email to them telling them that I was not the person they thought I was and to stop emailing me.
They then sent me an email telling me I was fired.
It's not a super-common lastname, but there are probably several hundred people with it in the US.
I get all sorts of email for people whose address is some variant of it, like <firstname.lastname>@gmail.com. I've gotten plane tickets, paypal payments, cancer diagnoses, Bar Mitzvah and Wedding invitations, college transcripts, all sorts of personal information.
In many cases, I don't think it's the fault of the person with the email; I think they give their email as "firstname.lastname@gmail.com" and some clerk just uses "lastname@gmail.com"
Someone registered their brand new truck to my email address. I started getting a ton of automated email regarding the truck. The manufacturer didn't offer any options whatsoever to disentangle myself from that account. I even filled their support form and asked them to phone call the owner and sort it out. The only thing that did work was installing their app and honking the (parked) car horn from the other side of the world. A couple of days later, the account was magically deactivated and spam stopped.
My every day email is my name@myname.com, and I’ve had to purchase several typo domains and alias them.
There are other stories of people forgetting which company it was with (gmail vs yahoo) and even of google accidentally giving out emails with a period and then silently removing periods.
It shouldn't be this easy to use someone else's email address.
>It shouldn't be this easy to use someone else's email address.
This though, seems hard. I don't think this is a "security" thing per se (though I dearly wish there was a modernized "email" system built with modern crypto from the ground up). But for any sort of communications at all it seems like there is an inherent tension between how low friction one wants for the world to communicate vs protection. Like, there is nothing stopping anyone from doing a pure whitelist system for email right now. I even do in fact do that for a few accounts like specific ones for client contacts, only active client addresses will be accepted everything else is blackholed. Those obviously receive zero spam or misuse of any kind [0]. But obviously the tradeoff for that is no new potential clients could ever "cold call" it either. One could imagine technical solutions like "only accept stranger email from accounts with a signed ID" or "vouched for by known address" (ie, WoT) or "only address with a signed time token >N from providers X, Y or Z", or some kind of challenge/response, but all would have privacy tradeoffs, complexity, and still wouldn't inherently do anything about honest mistakes.
We could have more powerful options for this, but it'd still involve subjective tradeoffs between how open to new communications one wants to be vs cutting down on noise. No one right answer there.
----
0: Forged from fields are of course possible but in practice someone would at the least have to know which handful of the total planetary email addresses were whitelisted, never mind flags that show up in the headers from that
Ask me how I know :( PP money was not recoverable that one time my ex sent it to the wrong email address.
Thankfully it was only $500 bucks or so, not $45,000.
I have a very common english <firstname><lastname>@outlook.com address. My inbox is always full of bank statements, invoices, and all sorts of business correspondence and bills from all over the world.
It made the address unusable.
Looks like it is popular among some ethnic groups.
I get applications for waitress for Black Lion Pub in the middle of the England, tons of registrations to any and each popular service which doesn't require e-mail validation, receipts from all around the world for online purchases (from dresses to drugs to surgical treatment of cats and dogs). I don't mention registrations in several recruitment agencies for low-wage workers ("I" was offered positions of forklift operator, gas station worker, etc).
There was whole year+, when PA of some real estate agency in Florida used this e-mail to book airline tickets and hotels for her boss. It was at least a trip each week, all around Florida and neighboring states. I've wrote to hotels, I've wrote to public e-mail of this agency - to no success. I've cancelled these bookings - they were re-booked, sometimes for much higher price. One time Ive canceled non-refundable booking for hotel 6 times in a row. It was re-booked each time, nothing changed! In the end I've filtered out all messages addressed to this person (name was always the same, it is what allowed me to figure out firm & person). After year or year and the half it stopped.
Gmail: A lot of people seem to think email, then "Gmail". I get emails of at-least 4 (or is it 5) people who have used some variation and also exact ID of my Gmail account (created when it came out in beta). I get details of their Credit Card, Bank, Phone, and what not. I just ignore/delete them but someone with time and fun/bad intention can do some serious harm. I have tried sending emails, contacting them few times but to no good result. One got angry that I have access to "his email". From the mail history, I feel really sorry for them. They are definitely not well-off and I feel I should protect this part of their digital identity. :-)
My name is also uncommon but it's very English, so I get weird email from England, Scotland, Ireland, Canada, South Africa, Australia, and New Zealand—anywhere there was an Anglo diaspora. I've given up trying to do anything about it, and it really isn't a problem because the volume is very low.
I have tried sending emails, contacting them few times but to no good result.
As someone who's had this same Gmail address for 18 years, I'm here to tell you it is absolutely a pointless waste of your time and almost never results in the sender changing their address book, workflow, or typing skills.
2. They gave that as their email (Gmail) ID when the banks, ISPs, asked and the institutes never validated it. To the other Brajeshwars, they are like "Oh! Email/Gmail, then it must be brajeshwar@gmail.com." But then I end up getting their emails.
It was hard to filter it at first since people kept exploring areas of the trial that generated novel message templates and the messages seemed to come from an endless supply of unique hosts.
At one point I contacted the SaaS company about it but they told me there was "nothing they could do" even when I promised I was the only user at that domain and I had no intent to sign up to their service with it.
I used to just log into their trial and delete the account, but while trying to automate this I figured out a better way to do my filters so the emails don't really bug me anymore (except in the cases when someone picks an alias I already have in use).
I think it's a mix of room temperature IQ and Main Character syndrome thinking they're the only ones with their own name (especially if it's common)
Or even easier: make them into a paid product, potentially even a small subscription. now you can milk people that want them
So, now 1001 is highly coveted, so lets exclude that as well. Oh, now 1002 is the lowest, lets exclude it as well. And so on.
That fact, plus the stories in this article is making think of really closing off my social media visibility a lot more than it currently is.
It seems like once law enforcement engaged it was quick since they arrested 3 days after someone died from a swat. But getting law enforcement to be interested is the problem.
“ The police quickly traced the 415 number and determined that it belonged to Chris Eberle, a midlevel Netflix executive. When calls to the number went unanswered, the police descended in force. ”
> I can’t call the cops from my phone and say I’m XYZ and have killed my girlfriend and am going to kill more people
You totally can. You think the cops won’t show up with force if they get a call from a voip number or prepaid sim? They will.
I’d argue that spoofing the victims number is in fact more likely to result in an unsuccessful swat, as the cops might end up calling you back and reaching the target.
Fuck, kids have been swatting each other using TTS relays since at least the early 2000s.
I'm curious to see how laws and law enforcement around the world actually perceive this, especially considering the very different ways in which things like order bombing or swatting exist/don't exist in various countries.
As far as I'm aware that's very usual in my country. We have no shortage of delivery services but they all need to be paid up front with a credit card.
It's like the US food industry has made itself a willing part of the harassment industry. The only reason I can think of for them to really want to offer this service is as a tax dodge.
I'm sure that there's no end of alternative ways that the inventive scumbag can think of to annoy people but that one at least is not open to them here.
they are callee the unbanked. They are poor.
its part of the ideals of this country that everyone deserves equal opportunity of transacting with a businesa.
Its part of our freedom of association.
EU elite love their restrictions. They say EU elites love democracy or something, but after watching top bureucrats try to hold UK hostage over brexit, im not that convinced.
"We do sometimes recycle usernames when they're well and truly dormant, i.e. no logins for many years. But we only do this for established community members.
What I usually tell people in situations like this is to create a new account and build up a track record of being a good community contributor, and that if they do that, they're welcome to email again in the future and ask us to recycle the old username for them. We can always rename your account at that point."
If someone is already a good community contributor and has already built up such a track record, we're more likely to give them what they want. But only if the username they're asking for has shown no sign of life for many years.
-----
Edit: the above comment generated quite a few emails, which has forced me to think about what makes me uncomfortable about this. Here it is:
Obvious/hot usernames don't really fit the intended spirit of this site, which is (intellectual) curiosity: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor.... That spirit is more likely to come up with a new, creative username than to seek the one that's better for branding or vanity.
Branding is about being obvious and repeating things. That's out of sync with the spirit of this site. Similarly, vanity—though perfectly human and something we all have—is not particularly sympatico with curiosity. Put those together and you get the worst of both: "personal branding", which is particularly boring and uncurious.
Curious conversation is about some $thing that is interesting. It is not about $me, and when $thing is merely a means to $me (or $my-startup or $buy-what-im-selling), that's lame. You can usually feel it and smell it in the content, too, because the content wasn't produced out of interest or for its own sake.
Optimizing HN for curiosity (see link above) is a constant fight against the forces of promotion, which forever seek to pull people's attention away from things that are actually interesting and glue it instead to ulterior matters like marketing and messaging and sales. I'm not saying those things are bad in any absolute sense, but they're bad relative to the mandate of this site.
So this whole thing of "can I please have me this generic / obvious / presumably-high-status username that hasn't posted anything since 2008" makes me feel like someone doesn't really get what HN is for, and I get queasy.
I think if they choose to avoid any kind of verification of contact information they don't have good reason to complain in cases like this.
This ended in the funniest way possible: being banned for using third party client Ripcord (presumably, no other offenses, happened shortly after trying it out).
My prediction for a system similar to the one parent suggests is that people will continually keep creating accounts until they get something like "Max a0a0a0a" or "Max 000000e" or something by chance, and then that becomes """valuable""" and the same thing happens.
A solution is to display the random nonsense as a unique image. More pleasant to look at, much easier to discern differences. There exist competing standards and services to generating images from random numbers, because it turns out the most universal way of doing this is abstract colorful shapes, which fall into that uncanny valley of approximating but not quite successfully imitating abstract art; And most people seem to think that's ugly.
Maybe that dall-e thing could generate good images to represent hashes? What does it output if one inputs nonsense?
2. User is free to change avatar and username, except there must be no visually similar avatar-username combinations across userbase. The restriction is enforced any time the user changes avatar or username.
3. System ID is shown to screen readers in place of avatar.
4. Whenever user interacts with another, if they have not communicated before, profile image or system ID is made more prominent for validation.
"Easy" solution: all account names must be at least ten characters long, single dictionary words and common first names are illegal. Make everyone spend some time picking a Good Handle.
There are people that professionally grow accounts, while the regular users do the same for a little dopamine kick with little efficacy and the most 'heretical' thing they'll do is buy disengaged followers. But it has much greater efficacy to just get an already professionally grown account and rebrand it based on the audience that found the account. I've made a lot from rebranding accounts for marketing strategies. I've lost a bit trying to buy from unscrupulous sellers. Apparently we violated the Terms of Service, oh no.
Meta could definitely support this behavior and amplify it. They need to re-educate consumers about not coveting followers, but just the content. Currently, people think how you got followers is important. But its not.
That said... I wonder if the deceased's estate has filed a civil suit against this jerk? Would serve him right to lose everything he's got.
My accounts are not the most important. However, I'm now beginning to accept that anything can be hacked, locked, and the day I have no access to a particular account, I should be able to walked out and not care (wherever possible and makes sense). I have also begun to offload accounts/IDs to a common family entity that can be run by "trustees" instead of being a personal one.
I've though about this for about 15 seconds, but you get my point.
It wasn’t spoofing per se that caused the word “deadly” appear in this article’s title.
[1] https://news.ycombinator.com/item?id=31862994
[2] https://support.sms.to/support/solutions/articles/4300056265...
Ok... this is terrible journalism. They're failing to correctly and accurately identify the parties in play. These aren't "haters", they're unhinged individuals or it's organized crime.
I guess you could argue that the only reason that people troll is because they are "unhinged" but that is a bit too hand wavy for my tastes.
It's imprecise, it's from the subject's point of view (which makes it a poor statement to make from the journalist's pov), and it potentially leads the readers to make ill-informed opinions about the wrong people.
Names - whether they be DNS names or Instagram handles or trademarks - are valuable.
Someone could still decide that being @ginger@prestigious.domain is Worth Something and start harassing you for having it but it's a lot less likely.
> A man who enlisted his cousin to break into a Cedar Rapids man’s home and order him at gunpoint to transfer an Internet domain was sentenced today to 14 years in federal prison.
https://www.justice.gov/usao-ndia/pr/social-media-influencer...
The name space of domains is also a lot larger now that we have tons of TLDs.
But not letting other people send messages over the internet through platforms created for the purpose because you don't like it is a special level of heavy-handed dictating.
I'm sure GP meant the former.
Police organizations are usually pretty primitively organized. They don't have the concept of studying a common body of work or anything. So they suck at what they do and they don't get better at it.