Live data from Hacker News

Who Hacked Ashley Madison?

krebsonsecurity.com

21–30 of 308 posts

Re: Who Hacked Ashley Madison?

#21
post #15

So Krebs has no conclusive proof for anything? As he himself admits: > It is possible that Zu is instead a white hat security researcher or confidential informant Jeez, how about talking to the police and let them do their job, or at the very least censor the name. This is just a witch hunt.

unclear if its a witch hunt or if Krebs wants to be on record with his reasoning in order to secure some of that $500K bounty if it turns out to be this guy?

I've never figured out how they actually decide who gets what if they have to split that up.

Re: Who Hacked Ashley Madison?

#22

> They said Avid Life employees first learned about the breach on July 12 (seven days before my initial story) when they came into work, turned on their computers and saw a threatening message from the Impact Team accompanied by the anthem “Thunderstruck” by Australian rock band AC/DC playing in the background. This reads like a scene straight out of Hackers or some other campy tech movie. Life imitates art.

It's art imitating life. Old school warez, demoscene and hacker groups have always had a very "campy" countercultural aesthetic to them. Hackers the film doesn't hold a candle to the real-life cDc. These types of groups are a dying breed, though.

Re: Who Hacked Ashley Madison?

#24
post #2

I don't condone this hack, but morals/ethics aside for a moment: The one positive thing this hack has done is really give serious ammo to the battle for online privacy, because the demographic hit by this hack is the most politically & economically powerful demographic in the world....

This is going to have some long-lasting repercussions on the industry. I fully expect there to be a push in the legislature to require PCI-like compliance from anyone who takes "sensitive data". That would have very serious effects for the startup community.

This is exactly my concern as well.

Re: Who Hacked Ashley Madison?

#26
post #2

I don't condone this hack, but morals/ethics aside for a moment: The one positive thing this hack has done is really give serious ammo to the battle for online privacy, because the demographic hit by this hack is the most politically & economically powerful demographic in the world....

What I find weirdest about the whole thing is the data wasn't sold back to Ashley Madison. The hacker(s) could have leaked 10 or 20 juicy names then probably cleared $10 million dollars or better. It would have been a bargain to Ashley Madison at that price.

Re: Who Hacked Ashley Madison?

#27
post #15

So Krebs has no conclusive proof for anything? As he himself admits: > It is possible that Zu is instead a white hat security researcher or confidential informant Jeez, how about talking to the police and let them do their job, or at the very least censor the name. This is just a witch hunt.

unclear if its a witch hunt or if Krebs wants to be on record with his reasoning in order to secure some of that $500K bounty if it turns out to be this guy? I've never figured out how they actually decide who gets what if they have to split that up.

He could have not posted the twitter handle but a hash instead?

echo "The Twitter handle Brian Krebs anonymized in this blog post is..." | sha256sum

There you go, you can prove it to anyone at any point in time.

Re: Who Hacked Ashley Madison?

#29

Earlier quoted context omitted.

This is going to have some long-lasting repercussions on the industry. I fully expect there to be a push in the legislature to require PCI-like compliance from anyone who takes "sensitive data". That would have very serious effects for the startup community.

I wish the push was more of a law that let users delete their data immediately and completely from a service with the click of a button.

I second those wishes, but thats feasibly impossible without vast auditing resources. DB backups, logging, and the general "archive-first" nature of the modern web essentially prevents this from happening.....even if service providers wanted to give this opportunity to its users...and most do not.

Re: Who Hacked Ashley Madison?

#30
post #2

I don't condone this hack, but morals/ethics aside for a moment: The one positive thing this hack has done is really give serious ammo to the battle for online privacy, because the demographic hit by this hack is the most politically & economically powerful demographic in the world....

I hadn't considered that, but it's an interesting point. That said, all the standard moralizing accompanying this is so gross.
Post reply on HN