UK sets up fake booter sites to muddy DDoS market
krebsonsecurity.com
krebsonsecurity.com
Used to frequent these forums.
I'm not sure if this is part of the anti immigration/brexit campaign or not, but it certainly caused me to cancel my previous idea/fantasy of living in the UK, so good job there!
"In English tort law, a super-injunction is a type of injunction that prevents publication of information that is in issue and also prevents the reporting of the fact that the injunction exists at all."
The BBC suspended Gary Lineker for a couple of day's. They were massively criticisdd and he is back on air now.
The sports presenter's comments raised questions on impartiality rules.
You can have any opinion you like, but if you're getting a large wage from an institution funded by the taxpayer, you can't use the platform like your own personal soapbox.
It was a clear case of goverment interference using the impartiality rules, only the conversation around impartiality went right above Gary to the powers that be immediately after his removal which is why he is back.
The BBC's impartiality rules cover this.
> Personal Activity
> Expressions of Opinion on Social Media
> Where individuals identify themselves as being linked with the BBC, or are programme makers, editorial staff, reporters or presenters primarily associated with the BBC, their activities on social media have the potential to compromise the BBC’s impartiality and to damage its reputation.
> Our audiences must be able to trust the integrity of BBC programmes and services and be confident that the outside activities of our presenters, programme makers and other staff do not undermine the BBC's impartiality or reputation or that their editorial decisions are not perceived to be influenced by any commercial or personal interests.
> They should not:
> state or reveal publicly how they vote or express support for any political party
> express a view for or against any policy which is a matter of current party political debate
> This guidance note is intended to help BBC staff operate appropriately in every aspect of their activities on social media
He isn't BBC staff.
That's not a fait accompli, and is why this situation arose:
> Do the policies apply to Lineker? The answer is yes. The policies apply to everyone who works for the BBC.
https://www.russells.co.uk/own-goal-for-bbc-with-gary-lineke...
> “I think there’s quite a lot of confusion about the extent to which the impartiality guidelines extend outside of news and extend to freelancers rather than staff, and until that’s cleared up we’re going to go on having these kinds of (problems).”
https://www.independent.co.uk/news/uk/gary-lineker-bbc-confu...
The public face of the BBC is not affected by whether or not the person is a permanent employee, but rather how prominent that person is in the organisation. It's disingenuous to suggest otherwise.
This BBC is not funded by taxation. It's funded by a subscription paid by owners of TV reception equipment. Some people who pay the licence fee also pay taxes, but some don't.
> you can't use the platform like your own personal soapbox.
Lineker didn't express his opinion on the BBC's platform. He used his personal account on Twitter, which is clearly separate from the BBC.
Whether licence-fee payers expect BBC sports presenters to refrain from expressing political opinions outside of their work for the BBC is debatable - as far as I know, nobody has consulted them in a systematic way.
Netflix is funded by a subscription paid by owners of TV reception equipment.
The BBC is funded by a mandatory licence, i.e. a tax.
> Lineker didn't express his opinion on the BBC's platform. He used his personal account on Twitter, which is clearly separate from the BBC
Not according to the policy that Lineker agreed to, in order to work at the BBC.
> Personal Activity
> Disclaimers written in biographies such as ‘my views not the BBC’s’ provide no defence against personal expressions of opinion on social media that may conflict with BBC guidelines.
> They should not:
> express support for any political party express a view for or against any policy which is a matter of current party political debate
https://www.bbc.com/editorialguidelines/guidance/social-medi...
Football commentators are not such individuals.
> There are also others who are not journalists or involved in factual programming who nevertheless have an additional responsibility to the BBC because of their profile on the BBC. We expect these individuals to avoid taking sides on party political issues or political controversies and to take care when addressing public policy matters.
Having such a public face of the BBC hyperbolically compare government policy to those of the Nazis in 1930s Germany is inappropriate.
It's due to policies on the left, and the integration of those policies into institutions that should be neutral, such as the police force, as detailed by https://freespeechunion.org/
If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html and taking the intended spirit of the site more to heart, we'd be grateful.
Do people really give they actual contact details to do crimey activities ? I'm not a cybercriminal so I don't know about these sites. But if I had to do something illegal, I wouldn't use my actual name.
It seems more like how you set someone up. And they release the news about this site just days before the 1st of April. Why ?
This is why we need a robust crypto system.
So that you can pay for whatever you want without worrying about giving away who you are.
I don't think the need to be able to buy DDoS without getting caught is the most compelling argument. Do you think being able to packet people is a social good?
For profit DDOS attacks using significantly stolen bandwidth from compromised machines are clearly a different thing entirely. Where you draw the line between them is a discussion topic.
The current system of thought is to make it harder for Peter to buy a coffee in the morning to try and stop Paul from paying for DDOS traffic.
Decouple it the way that WhatsApp decoupled itself from the problem of three letter agencies wanting to know message contents with E2EE.
As it stands, if some hedge fund doesn't like your product it can pressure VISA to stop letting people to buy it. And that's it game over. It doesn't need to be legally wrong, or even morally wrong. Just don't what some rich dude wants going on.
You don't want your personal morals to prevent others from paying for child prostitutes, hitmen, nerve gas, fissile material or smallpox samples?
It's a false equivalency.
Major banks have been found to actively facilitate all those things.
So why not have a convenient currency in crypto and just use law enforcement to enforce the law!
The only way for it to not be traced outside of monero and maybe a few others that have no adoption is buy in cash in person and transfer it to a never before used address. Mine it yourself and never mix it with your other funds.
I expect most of the people who'd fall for it are young or immature people, trying to get back at someone who beat them in a game or argued with them on social media. For whatever reason many of these folks see DDoSing, sending death threats and even swatting as "pranks" instead of crimes. A friendly reminder that doing this stuff can get them in serious trouble could nip that behavior in the bud before something tragic happens.
We have nontechnical people making legislation about technical things, why do you think police are any different
Do you really imagine a patrol cop gets given a computer and told to 'find the suspect'? The legislators have someone else write what they put their name to, so that's not comparable.
No, just one that got promoted to detective
Of course, swatting is worse. An on-demand terrorist attack by phone call is hard to top. But this one can be pretty bad too. Well, or maybe not, because it's not the starting evidence that makes it bad.
Gotta be USA.
Edit: found it: RentAHitman.com
https://boingboing.net/2022/01/11/how-rentahitman-com-went-f...
https://www.reddit.com/r/AMA/comments/v5422p/i_operate_a_fak...
That is hilarious. I’ve always wondered what HIPPA was, now I know. ;)
You'd hope not, but lots of people do when it comes to piracy. Private trackers often require accounts and interviews which can cause someone to leave a pretty extensive digital trail if they aren't careful including a clear record of everything they uploaded and when.
On one hand we could say that anything helps: if they catch the stupid ones, that's still great. One the other hand, that may be all they're after, if they're compensated or promoted based on cases solved. "Last quarter we caught 120 criminals in our clever snare". That looks very nice on a report so it maybe be that's all they're happy doing.
I trust that law enforcement knows the pattern with this one.
Sorry, James - someone's gotta go to jail.
Yes, the "genpop" indulging in casual crimey activities are shockingly lax about basic opsec.
I did some work consulting for the NCA a few years back (they're a very weird mix of some extremely tech-competent folks, and some parts total luddite) scraping "dark web" forums looking for high-value law enforcement targets -- and it was ludicrously simple to identify "retail" participants who were, for example, trying to buy credit card/bank info dumps,
FWIW unless there was some sort of big metrics-driven or politically motivated push, these retail-type small fry were generally ignored in favour of trying to identify and trace down more organised efforts.
I used to wonder why so many scam e-mails use such poor English until I realized this.
A lot of infrastructure struggles under basic scaling situations, much less coordinated attacks on specific endpoints.
I wonder why they chose to tell the users when they registered, instead of waiting? Could they have gone ahead and let them place orders for DDOS attacks, to capture more proof of the users' criminal intent, or would that count as entrapment? Someone who 'merely' registered could try to claim that they were a researcher, but if you hit the button to DDoS someone, that's going to be more difficult to deny responsibility for.
[Edit: Now that's making me imagine a disgruntled user suing the NCA for breach of contract: "I paid money for a DDoS and they didn't provide the service!"]
Maybe as simple as the action being illegal and since they are not providing the advertised service then no crime is committed? I don't know how broadly applicable this is but in at least one state the local drinking laws boil down to 'you will not serve minors', perhaps something similar here.
It wouldn't be entrapment unless the NCA was proactively coercing people into placing orders. (you can't have a contract for something illegal so there'd be no right of action)
It's relatively readable, it's probably enough to note that a "stay" means that a trial will not proceed (at all).
A quote from that section:
"Police conduct which brings about state-created crime is unacceptable and improper, and to prosecute in such circumstances would be an affront to the public conscience. However, if the accused already had the intent to commit a crime of the same or a similar kind, and the police did no more than give him the opportunity to fulfil his existing intent, that is unobjectionable."
How does wire fraud fit? What's the fraud?
Edit: The real pros don't use Booter-as-a-Service sites, they infect a bunch of IoT devices using tools they made themselves and hammer a specific IP or range of IPs.
Dressing it up in terms like "protest" is a smokescreen.