Man who mass-extorted psychotherapy patients gets six years
krebsonsecurity.com
krebsonsecurity.com
But it was a mistake that the hacker made himself that led police to a treasure trove of information found on a server that Kivimäki owned.
Unprecedented digital forensics and cryptocurrency tracking also helped secure the conviction.
What mistake did he make?
Was incriminating evidence found on that server?
Is there any direct evidence Kivimäki did it?
The use of "unprecedented" is worrying, and extremely vague.
edit: saw the sibling comment explaining what happened. even dumber than I had imagined.
https://krebsonsecurity.com/2023/11/alleged-extortioner-of-p...
tar cvf /var/www/html/vastaamo/vastaamo.tar . -C /var/www/html/vastaamo --exclude vastaamo.tar
Once he added the command to crontab, the command was executed from the root user's home directory and it created a 7.5 GB tarball before running out of space on the server two minutes later. The server didn't crash but started malfunctioning, as for example no logs could be written on disk. The police found that the maximum time that anyone was able to download the tarball was for 1 hour and 41 minutes before the TOR service had stopped responding.The admin of the server logged back about 10 hours after the tarball was created and tried to figure out how many downloads of the tarball had been made, but because the server had no space left, there was really no way to get a realistic image of the situation.
He was given a suspended three-month prison sentence last year.
The company which was once a highly regarded and successful business in Finland collapsed after the hack.”
It's like if "automobiles" all had cell modems in them, ran some minimum viable functionality Swiss cheese security embedded software, could be remotely controlled from the Internet, and the only things keeping mass destruction at bay is the lack of documentation and the fact that individual humans generally don't want to hurt one another. uh, maybe I need a different example.
And nobody outside of Hacker News cares about any of that. All they care about is getting from point A to point B, never mind that ~1,300,000 people are killed by by crashes every year and that we're poisoning our planet with them[1].
It's possible that I chose them as an example deliberately and cynically, as opposed to pedantically.
---
[1] Both of which are far more pressing concerns than some Martian super-hacker pwning my car, but it's all worth the convenience of not having to get into a bus, or on a train.
The same cannot be said for the average unprotected database scanner.
You probably don't bring all of your notes from your whole practice with you on the train to lose. If you do bring some of your notes with you and leave them on the train, there's a good chance they will be returned without being accessed by the returner, or be collected as trash, again with no access. Even if there is some access, it's less likely that they'll be widely distributed, because they'd need to be digitized or otherwise copied first, and that's a lot of effort.
If the person who picks up your notes on the train is nefarious or even maybe just curious and happens to know the people in your notes, there's potential for negative outcomes for your patients, but IMHO, the probability of a negative outcome for patients given an incident of unauthorized access is lower with paper records than digital records. I don't know if I can really opine on the probability of unauthorized access --- digital records open up the possibility of more effective controls on access than a filing cabinet; you can't audit which records were read when an authorized person opens a cabinet to get some records and looks around at others.
That's a quarter of a million people who never explicitly consented to their records being digitized in the first place given to someone who they've never met for them to just leave it somewhere to be stolen.
That's the difference in scale and consent of a digital record system and non digital.
Not a problem then?
The recent controversies about online (and even genAI) psychotherarpy have largely left many to suffer unaided, out of fear of hacking or selling of their most secret of secrets.
Did he have some history with the profession / company that he's acting out against? Or was it just a random mark with a lot to lose?
All they offer is some credit monitoring... there should be real consequences for companies or they will never prioritize keeping our data safe.
> Investigations found that the databases were vulnerable and open to the internet without proper protections.
> He was given a suspended three-month prison sentence last year.
> The company which was once a highly regarded and successful business in Finland collapsed after the hack.
Copy and pasted from the article.
> Kivimäki has been sentenced to six years and three months in prison
Well I guess see you in six years and three months for the next round of crimes.
First time recidivism is low.
Also, according to this comment (https://news.ycombinator.com/item?id=40211782): he's HN's own https://news.ycombinator.com/user?id=ryanlol.
Maybe we hold off on pointing fingers unless there is concrete proof?
>> Zee/"ryanc" has indeed been involved in things like these for many years. HTP (Linode + much more) is just a small part of it.
>> I'm also very surprised it's taken this long for him to be arrested. He's completely brazen and has committed countless crimes despite knowing full well the general public and law enforcement know exactly who he is.
ryanlol responded:
> Just because someone knows who I am does not mean that'll matter when it comes to proving things in court, which in real life isn't as easy as one might imagine.
>> he probably won't get out for a while
> If only I'd get sentenced in the first place.
This Krebs comment lists more HN accounts:
https://krebsonsecurity.com/2023/11/alleged-extortioner-of-p...
> PS: Want to read some of his Hacker News comments? Usernames are ryanlol, FDSGSG, rosnd, rosndo, prvit, lfodofod, ryanl0l, bbbbb5, gggggg5 (which stopped posting right after his arrest).
[1]https://itwire.com/business-it-news/security/krebs-accused-o...
[2]https://itwire.com/business-it-news/security/infosec-researc...
Edit: Your edited comment including some non-Krebs stuff is more interesting, thanks for digging that up for me.
I actually cited a comment on Krebs, not Krebs himself.
But that's kind of moot. More digging found the ryanlol account confessing to be Julius Kivimäki. It appears he was pretty open with his identity.
That's even worse? More random people lol.
But yeah, the other stuff you dug up straight from his account is certainly more damning, thanks.
And yet we are always scolded for accusing people of sockpuppeting and similar
nearly 10 times the voting weight of normal users.
2nd one is yet another random person?
https://news.ycombinator.com/item?id=17696035
https://news.ycombinator.com/item?id=15729517
https://news.ycombinator.com/item?id=25529743
Source: Keskusrikospoliisi / National Bureau of Investigation
—black mirror type stuff
Given the guy’s arrest record (and implied lack of rehabilitation), a longer sentence would serve the goal of incapacitation.
This sounds a little like an appeal to tradition, unless I'm misunderstanding you. Removal from society is absolutely one of the intended purposes of prison, but as with all traditions it must be open to challenge and debate.
You present this as an argument for a shorter sentence. But from another perspective, it's an argument for never letting him out.
Prison isn't primarily meant to rehabilitate; you are almost certainly right that it will do the exact opposite in this case. Its power to deter is also limited. But what it can do, if we are simply willing to use it for that purpose, is contain dangerous people and prevent them from harming others again by simply not giving them the opportunity to do so.
It is an argument, although that might count as unusually cruel or disproportionate for a crime like this. Even murderers in Finland are typically pardoned and released after 12-15 years.
What about serial murderers? The damning part—to me—isn’t the crime per se but the repeat offenses.
The Finnish system is famously good at rehabilitating criminals. But what do you do with the edge cases? (I guess our system, which excels at incapacitation and retribution, has its edge cases in the unjustly imprisoned. Put that way, having the edge default to letting out a few incurable criminals from time to time might be the fairer solution.)
https://apnews.com/article/science-norway-europe-oslo-crime-...
> While the maximum prison sentence in Norway is 21 years, the law was amended in 2002 so that, in rare cases, sentences can be extended indefinitely in five-year increments if someone is still considered a danger to the public.
Blackstone's ratio[0]
He's a scumbag, but the folks that didn't secure that data were also complicit (although unintentionally). I know that the company went belly-up, but I'd suggest the company that wrote and sold the software also shares culpability, as they likely sold it as some kind of magic beans.
There's really no substitute for not collecting the information in the first place, but in this community, that's heresy.
Prisons are meant for rehabilitation in Finland, where the case was decided. And the system maintains a lower recidivism rate than the US with a lower incarceration rate + less crime.
The underlying stats show that rehabilitative models with lighter sentences are better.
> From a post war crime boom and relatively high incarceration rates, Finnish prisons have emerged to be counted among the most humane correctional facilities in the world and yet, recidivism is very low compared to international standards.
Sounds similar to that of Norway which is known for its kind/compassionate treatment of prisoners.
I get that if you’re used to the US criminal justice system you believe the goal is to punish people as long as possible - with a side order of slave labor and electoral disenfranchisement - but all of the statistics show that that policy has worse outcomes across the board. It has higher costs, higher rates of recidivism, and lower trust in the judicial system - which encourages an us vs them mentality that further increases crime rates. Not to mention that if a child spends a decade in prison they’re coming out the other end with little to know ability to earn a non-crime living afterwards.
Some people get stuck in shitty life situations and resort to crime. Some people are legitimately bad and enjoy harming people.
This man should be executed. It would be a fitting punishment for both of those reasons and more. He caused at least one suicide and victimized tens of thousands. This is a crime that calls for the death penalty.
This is very clearly in "spend somewhere between 1 and 2 decades turning big rocks into little rocks" territory to my punishment-focused American lizard brain.
> Asked about it today, Kivimäki denies posting as ryanlol, though that contradicts his admission in a police interrogation submitted at his trial—and is hard to square with a 2017 post in which ryanlol detailed a personal rap sheet including “50,700 counts of aggravated unauthorized access to computer systems.”