Stakeout: how the FBI tracked and busted a Chicago Anon
arstechnica.com
arstechnica.com
The document also claimed that more than $500,000 had
been charged to credit cards and given to "charities
and revolutionary organizations."
Usernames and e-mail addresses were also released;
people were exhorted to "use and abuse these password
lists and credit card information to wreak unholy
havoc upon the systems and personal e-mail accounts
of these rich and powerful oppressors."
First, a lot of those credit cards belonged to ordinary people, not the "rich and powerful oppressors".Second, when the credit card owners see the charges, they will dispute them. The credit card companies then will take the money back from the "charities and revolutionary organizations", and hit them with a $15-$30 chargeback fee per card.
He's better known to me and my online pals as "tylerknowsthis", a reference to Tyler Durden and his philosophy of destroying the capitalist system to "free the people." Say what you will about his ideals, his methods and actions are beyond retarded.
Here he is at Defcon in 2004 talking about how they need more "footsoldiers" to "fuck shit up in the streets" - to the point that Priest has to come on stage and denounce violent acts or acts that hurt people. http://video.google.com/videoplay?docid=1269112265902193941 In general he defends the use of violence as the last act of a person who is desperate to defend freedoms for people who didn't ask to be helped. His website HackThisSite is a sort of propaganda and training tool used to entice young black hats to join his cause.
You can find a list of his previous run-ins with the law on his wikiepdia page: http://en.wikipedia.org/wiki/Jeremy_Hammond (My favorite is where he attacked a 70-year-old holocaust denier that was having dinner at a restaurant.... what productive direct action!)
He claims he steals his power, water and internet access and at times squats abandoned buildings and eats "freegan" so he isn't helping the capitalist system flourish. At the same time he kept a part-time computer programming job to make spare cash. So he can keep fighting the good fight against capitalism.
I think he may have still been on probation during the events of the Stratfor hack, so he may be royally fucked by the prosecution unless he too snitches - something he has repeatedly said is the worst thing any good hacktivist can do.
He's one of the longest-running jokes my online friends and I have. His rants against "the system" and hypocritical actions which seem to have little purpose serve to foster flame wars and is frequently banned when people get tired of his shit. He then comes back and threatens to "curbstomp" or "shiv" anyone who disliked or banned him. Basically, nobody but the LulzSec freaks like this guy.
Yet again the same people who try to get away with petty online crime get caught due to negligence, bragging and misplaced trust in other criminals. If only they'd learn that trusting a criminal is probably not a good idea they might not be arrested right now.
edit: In case anyone wants to verify this account (in a WikiLeaks-style full transparency way), here is a brief dump of a public chatroom on a public irc server of his comments. I don't have the entire log, just his comments. http://pastebin.mozilla.org/?dl=1506078 http://tinypaste.com/a104418f (it's around 1.8MB)
Blogging is not poking. Blogging is not tweeting. Blogging is not programming. Blogging is not learning. Blogging is not making. Blogging is not sharing. Blogging is not networking.
Blogging is not something you do.
Blogging is how you blog.
At any rate, calling yourself a hacker (Without chops to back it up if your using it in the heroes of the computer revolution sense.) to anyone who knows better is either some serious bragging, or braindead stupid depending on which definition you're using.
In fact, the last thing anyone who does stuff like Lulzsec should admit to being is a "Hacker" (Even if they mean it benignly.) because you can bet the farm that the first people the Feds look at are self described "Hackers". I just can't believe the kind of information these people leak about themselves. Doesn't "I trust you today, but not necessarily tomorrow..." mean anything to black hats?
EDIT: Saying anything about the state of the real world should be considered an incredibly bold release of entropy or invasion of privacy if the only thing that keeps you safe at night is your mask.
EDIT2: Sorry, thought the above quote was from Jeremy Hammond's blog. At any rate most of my points still stand from the hypothetical perspective of "If I were a blackhat..."
Regardless, as an outsider peering inside, it does seem a bit strange. One of the things effecting my perception is the simple question I ask myself looking at posts like the one you describe. "Does this have any chance of making money?"
Because if it doesn't, I always wonder what the motivation was for making a service for which there are 50 implementations already. I've probably written under 500 lines of code in my life, because I can't justify it to myself to build an application nobody needs, even for practice.
At any rate, the "hack" itself is it's own sort of art. With an almost intangible feeling of delight when executed successfully. I can't really quantify it myself to be honest. And I've only experienced it once.
TL;DR: The short answer is, people here find that stuff fun.
PS. Quit trolling HN.
(Baader-Meinhof, not the air force).
I myself have some very intense sides of my personality, but I've always channeled it into productive pursuits. When I was younger I daydreamt of being a nefarious black hat hacker, but I soon realized that startups, lifestyle design, social dynamics and personal development are far more rewarding ways of hacking reality :)
These anonymous guys are complete effing idiots..meaning any training FBI is doing in catching these folks is actually doing the FBI more harm than good in that its not preparing them for the hard serious hacker threats such as China hackers..
As far as I'm concerned there is evidence of some high profile hacking teams somewhere in the world doing some nasty stuff (such as the fraudulent certificates and hacks on companies that was tied back to Stuxnet). We don't know for sure who does it but a lot of people assume the chinese based off of (what I think) is IP traces.
Its all speculation. We know that someone is hacking, just not who. Its obvious that they're good because there hasn't been enough evidence to pin it on anyone. As anyone on this site should know: IP isn't a very good identifier and even less so for professionals.
You want to smash the state? You want to end the tyrrany of capitalism? You want "freedom" ? Running around the streets in bandannas disabling vehicles and "fucking shit up" ain't gonna get you there buddy. Neither is stealing money from the majority of the people who used a service as a better-filtered newswire in the name of some hokey idea that the "security state" needs to be brought down.
He's a bully and a closed-minded bigot and he's too radical to ever be able to introduce any real change other than making the police remove more of our rights in order to combat people like him. He's a terrorist. And an idiot.
But that's just my opinion.
The FBI describes its device as a "wireless router monitoring device” that captures addressing and signaling information and transmits it wirelessly through the air to FBI agents watching the home. It was installed the same day and was soon showing agents what Hammond was up to online.
I'm curious about this device; it would have to be able to fully decrypt 802.11 frames just to be able to see the layer 3 IP information, so in theory it is able to see all of the traffic but the agents aren't allowed to look at (or use) anything beyond the IPs because that would be considered wiretapping. I have to imagine the guy arrested was technically competent enough to use WPA2 with a fairly strong non-dictionary-word key, yet this device was able to crack that key in a short enough amount of time for this sting operation.
...anything beyond the IPs because that would be considered wiretapping.
But that is exactly what it appears they had the authority to do no?
Probably a good call, really. It requires physical presence, but done right it could be nigh undetectable, whereas reporting over the target's uplink could alert a very sharp target, and possibly even reveal who its masters are (based on destination).
I'm perturbed by the number of hackers getting taken down who blather on about their personal lives, use a VPN with no encryption and think it's safe, and still manage to break into these rather large systems. Either they're skilled but reckless and cavalier, they're idiots and security everywhere is a joke, or both.
Not sure which of those scenarios is more disturbing. Either way, I suspect that, in the wake of these latest arrests, we'll see both better opsec from Anon, as well as an increased focus on security from those who are likely to be targets. In the meantime, I'll get 15 messages on my facebook wall saying, "see who's visited your profile!"
sigh
The only thing they had was the Tor IPs, and SSL doesn't hide IPs.
and there isn't really such a thing as a 'VPN without encryption'
This is nothing surprising. If you listen to the (public) disclosures of wiretaps on e.g., Mob bosses, etc., it's full of mundane chatter about what they had for lunch, who they met, their bowling scores, etc. The reality is that after some time of being secretive and not getting caught, it's human nature to just act normally and let your guard down. If you think about it, the criminal only has to make one mistake out of thousands of individual actions to be caught and prosecuted.
Criminals are just ordinary people, not supervillains!
Doing this does not count as wiretapping, as it was ruled to be akin to a dump of phone records, rather than listening on the conversation itself. Yes, they are splitting hairs, but that is how justice has to work.
I'd be a little irritated if my credit card number was released while the FBI sat back and watched it happen. I'd be a lot more than irritated if I owned Stratfor, and the FBI sat back and watched some people hack my business. (Yes, Stratfor's security was awful. But it's still a crime.)
I'm not a lawyer, but I'm curious -- why isn't the FBI liable for this sort of thing? Surely there has to be some precedent here one way or the other.
My wild guess is that Sabu was not responsible for the idea, but was instructed by his FBI supervisors to just play along and help people with the attack to build up credibility. Meaning - the feds didn't modify the data at all, they probably just used the server to track down the IPs.
Anyway, the fact that Sabu was an informer is surprising to me, a lot. Especially when he was still posting tweets, accusing OTHERS of being informers.
It seems it is an American custom nowadays.
They have no legally enforceable duty to protect...
". a government and its agents are under no general duty to
provide public services, such as police protection, to any
particular individual citizen...
-- Warren v. District of Columbia, 444 A.2d 1 (D.C. App.181)"It always looks worse when you view it in hindsight. If the FBI had enough evidence to work with then they would have done something. Acting early without the evidence they need would have done more damage and not necessarily stopped anything from happening.
The police have no duty to uphold the law or to protect you.
http://www.expeditersonline.com/forum/soapbox/48007-fbi-wrec...
http://en.wikipedia.org/wiki/Sovereign_immunity
The FBI doesn't get to be sued for a bunch of stuff because they claim sovereign immunity.
It's all fucked up.
If I had been him, I'd have put Tor on top of a couple of vpses in some select countries around the world.
That being said, he was reckless and too ideological without considering he wouldn't be furthering his ideals. Its one thing to dump company secrets, its another to dump personal CCs.
Now if I was the FBI, I'd be trying to combine the successful methods of having undercover agents pose as terrorists with a hacker bent. Its the same sort of system, albeit purely digital.
I honestly think they already knew who he was from his comments - by reviewing Sabu's chat logs they found he had slipped up and identified himself.
I guess what I'm trying to say is, we have no data either way. Tor may be secure, or it may not.
Take-aways seem to be:
1. IRC logs do not contain identifying info - unless you reveal youself
2. IRC active / away status leaks information about your schedule
3. Using multiple identities online works pretty well
4. Trusting criminals = fail
5. Committing federal crimes = fail
The FBI had a pretty solid case against him. By the time they were doing the IP sniffing and identifying Tor nodes, they already had the guy under 24/7 surveillance. It sounds like they were solidifying their case.
If this were hollywood, I bet he would have sensed the surveillance somehow - and tried to make a run for it. But it didn't sound like he had many friends who would have hidden him.
You'd be surprised. I was about six years old when I realized I could tell who was walking upstairs by the sound of their footsteps.
I can identify code that my co-workers have written by their individual styles. And that's after conforming to our coding standard.
It's common knowledge that individual (prose) writing style can be as identifiable as a fingerprint.
In short, pretty much every action you take has the potential of adding to a list of identifying information about you. If your actions are watched long enough, you will be identified.
http://www.fbi.gov/newyork/press-releases/2012/six-hackers-i...
Apparently some of the names published were real (including Sabu's - even though under different nickname).. and he was arrested just month later. If someone in the group would recognize any known real name references, they should have immediately ceased their activities and went undercover, as they should have expected raids!
FBi loves turning caught people to informants to catch the others. It's been that way 10 years ago, when one caught member worked half a year helping to betray the whole warez group, and it seems to be all the same.. FBI is still too lame to advance without informants.
And if you're hanging out on IRC a little too much, your linguistic fingerprint is probably strong enough to match up to something somewhere else on the Internet with your name on it.
If he really wanted to fight 'the man', he could have gotten a nice cushy job and donated what he made to EFF.