Two U.S. men charged in 2022 hacking of DEA portal
krebsonsecurity.com
krebsonsecurity.com
-tricking customer service employees;
-submitting fraudulent legal process to social media companies to elicit users’ registration information;
-co-opting and corrupting corporate insiders;
-searching public and private online databases;
-accessing a nonpublic United States government database without authorization
-unlawfully using official email accounts belonging to other countries.
>Prosecutors say they tied Singh to the government portal hack because he connected to it from an Internet address that he’d previously used to access a social media account registered in his name. When they raided Singh’s residence on Sept. 8, 2022 and seized his devices, investigators with Homeland Security found a cellular phone and laptop that allegedly “contained extensive evidence of access to the Portal.”
>The complaint alleges that between February 2022 and May 2022, Ceraolo used an official email account belonging to a Bangladeshi police official to pose as a police officer in communication with U.S.-based social media platforms.
Is the implication here that the US gov has broad access to accounts IDs->IP address which access social media accounts? Or can the FBI/three letter agencies can go to Twitter/FB/etc (or some NSA db) and ask which accounts logged in via x IP address? Or, less conspiratorial, the investigators had some leads on x group of accounts -> got warrants for account IP addresses -> confirmed hypothesis.
Failure to install and maintain wiretapping devices incurs a penalty of $130,000 per day, with a maximum of $1,325,000 per violation (unlimited violations).
Assume every ISP is compromised and that every government agency can see everything.
https://en.wikipedia.org/wiki/Communications_Assistance_for_...
Remember "SSL added and removed here :^)"?
Not to mention, there's really no reason for the feds to try and break/work around HTTPS in this case when they have more than enough to subpoena the provider and they'll happily surrender the logs.
Yes, and surveillance has become even more entrenched since then.
>HTTPS and encryption since became commonplace.
HTTPS only protects the information in transit. It can't protect you from a backdoored load balancer or other endpoint, which is what that infamous slide was about.
The NSA wasn't breaking encryption, but rather compromising the devices that were communicating via HTTPS with you. The little padlock icon in your browser says nothing about the trustworthiness of the server on the other end. It's like talking on a secure line with someone who is actually a spy.
It does not make sense that the police should be able to get a warrant for data from every single website in the western world based only on a single IP. But Snowden already proved that PRISM is a thing.
Also why stop at Facebook/Twitter/Discord? Should police also get warrants for AshleyMadison.com, Tryst.link, UnitedNuclear.com, DonateToPoliticalParty.org, INeedAnAbortion.org, etc etc? "Hey did anyone with this IP perform a transaction on your site and can you give us their name?"
Why not?
The police can go around every single business in town, and ask if a man matching some particular description patronized it.
This isn't a fishing expedition, this is the police asking for particular information about a particular person, who they are investigating for a particular crime. This is... Normal police work.
If what you're saying is true, these guys will walk because they'll challenge the lack of warrant in court. I have strong doubts that they are going to be walking anytime soon.
Unless you mean you think it's "normal" for police to ask Google/Twitter/etc for data dumps of every single account that ever connected from x IP address?
I don't see where "data dumps of every account" is substantiated anywhere, you're introducing that as a prior. They no doubt had a suspect[1], got something incriminating, took it to a judge and that was enough to get Meta or whoever to cough up the logs. If you're genuinely curious just wait for the court case and follow it. The defense will be presented with all the warrants and will challenge things if they don't look legal.
[1] No doubt because someone got sloppy with opsec and posted something from the wrong account. It's always something like that. Crime is actually really hard to do anonymously.
So literally what I said in my original comment:
>> Or, less conspiratorial, the investigators had some leads on x group of accounts -> got warrants for account IP addresses -> confirmed hypothesis.
Source? Why is this likely?
“Look familiar?” Singh allegedly wrote tthe victim. “You’re gonna comply to me if you don’t want anything negative to happen to your parents. . . I have every detail involving your parents . . . allowing me to do whatever I desire to them in malicious ways.”
I struggle to understand what could be so important about an Instagram account that you threaten someone’s family.
I struggle to understand how having random personal information of that sort would be considered a threat.
Oh noes, not my address! You're threatening me with the same information that tmobile already pissed all over the web a year or two ago...
I guess I could use some excitement in my life.
Really? You really struggle to see the threat? Really?
Google your own name and the first hit you'll get is your address.
Psychologically to someone not IT savy, the instagram hack might seem like someone means business. If I made the same threat and showed someone photos of their children, they’d surely feel similar, despite the fact that all that proves is that I know where they live and I own a camera.
Even if the robber has no intention of actually killing the victim and just wants their money, this is still very much a threat, and whether it was a bluff or not, it still causes distress and possibly trauma.
The problem here is definitely the hackers that broke into this portal and not the fact that these databases can be accessed by police without a warrant at any time just by lying.
Weakest link for awhile; far easier than SIM swapping the ATT/Verizon duopoly.
Any social media site can be used as horizontal stepping ladder with a little leverage from an ignorant CSR at a smaller social media site.
I suspect they will be doing some serious rolling-over on their buddies. The cops really don't like it, when you hack them.
In these online crime communities and other groups are lousy with feds everyone suspects everyone else is a fed and engages in opsec to protect themselves accordingly. Anything they "know" about the people they talk to and work with is going to be mostly stuff the glowies have reported long ago.