Live data from Hacker News

Who Hacked Ashley Madison?

krebsonsecurity.com

191–200 of 308 posts

Re: Who Hacked Ashley Madison?

#191
post #117

Earlier quoted context omitted.

You don't leave that one hanging. What's the story? Care to share?

It's really not that interesting. I was 15 and played around with some computers that belongs to the US Navy. Then one day at 6 am I heard a loud knock on the front door.

indeed, a common story. i get the feeling the fbi did a lot of before-school visits to teenagers dicking around on irc in the mid 90s.

they showed up to my place once. the guy said to contact him after i graduated if i was looking for work, lol.

for what it's worth, they had binders and binders full of efnet logs.

Re: Who Hacked Ashley Madison?

#192

Earlier quoted context omitted.

I'd argue the opposite. The AM hack hasn't helped at all, since enough people view it as a just retribution due to it being about a pet moral value that is held dear, namely marital fidelity. And to others, it's all a big joke. The cheating cheaters (who likely never got the opportunity to cheat) have been named and shamed, and because of those asserting that it's acceptable to do this if it strokes their personal mo…

Yeah, well if you engage in a promise with someone that you're going to be in a monogamous relationship -- let's be real, that's what marriage is for the vast majority -- you're a prick if you attempt to break that commitment, and again, that's what being on AM is about. Pretending otherwise is delusional, and having morals isn't a bad thing. Is doxxing always unethical?

So...basically a large scale version of ruining someone's life for being an asshole? I dunno about you but while I'm not married and have never cheated on a spouse, I've certainly been an asshole before and I'm glad my life wasn't completely screwed over it.

Re: Who Hacked Ashley Madison?

#193
post #117

Earlier quoted context omitted.

You don't leave that one hanging. What's the story? Care to share?

It's really not that interesting. I was 15 and played around with some computers that belongs to the US Navy. Then one day at 6 am I heard a loud knock on the front door.

Most of the people I know who got busted back then were into telco systems so they ended up with a fine, usually around 1-2k.

I'm guessing the navy wasn't so kind :/

Re: Who Hacked Ashley Madison?

#194

Earlier quoted context omitted.

It's really not that interesting. I was 15 and played around with some computers that belongs to the US Navy. Then one day at 6 am I heard a loud knock on the front door.

indeed, a common story. i get the feeling the fbi did a lot of before-school visits to teenagers dicking around on irc in the mid 90s. they showed up to my place once. the guy said to contact him after i graduated if i was looking for work, lol. for what it's worth, they had binders and binders full of efnet logs.

I keep hearing this and it makes me realize I wasn't as cool as I thought I was in the 90s :P

The FBI visited once, my dad freaked out and told me before he answered the door.

Turns out someone was exposing themselves to kids on Halloween.

Re: Who Hacked Ashley Madison?

#195

Earlier quoted context omitted.

Well, I reviewed the argument that I was referring to and it wasn't what you are claiming. Here's the text: >Then that's a breach of contract between two private parties which is of absolutely no relevance to outside observers. The argument claimed that the breach was "of absolutely no relevance". Yes, the word "meaningful" wasn't used, but I dare you to provide a definition of the word "meaningful". >The argument is…

I'd say the part where vezzy-fnord talks about the couple's "prerogative" and "things that are none of your concern " set the context in terms of moral rights, not whether it can possible affect the other person. I can see where one might read it differently, though, but I confess I fail to see the point in discussing from that POV.

Eh, there's very little here that has much point in discussion.

I only wanted to point out that this particular sub-thread was going off the rails (as many are, but I can't respond to all of them due to time constraints and HN's hard rate limit).

The information can't be destroyed now, so there is little point in discussions about what should or shouldn't have happened in this specific instance.

If someone breached a contract and this provides evidence to those ends, then it's simply a fact. I completely understand that facts can upset people.

If someone didn't breach a contract...well I'm not sure what the worry is in this specific instance.

In any case, it obviously sucks when information you gave in trust is leaked out and there is certainly a lesson to learn in data security here. There also seems to be a lesson to perhaps not trust companies who apparently fundamentally produce and specifically market a trust violation product. Of course, if you are in the market for such a product, formal calculation of your preference function may not be a priority.

>I'd say the part where vezzy-fnord talks about the couple's "prerogative" and "things that are none of your concern" set the context in terms of moral rights, not whether it can possible affect the other person.

This makes it sounds like vezzy-fnord is arguing for some kind of thought control regime; a regime where one may selectively engineer the exact perception to create in others. If someone can perceive something, they should be able to contemplate it.

Just as it is a couple's prerogative to seek court mediation for their breached contracts (this is the right the argument afforded the couple), it is another's prerogative to act on information that is known to them.

Re: Who Hacked Ashley Madison?

#196

Earlier quoted context omitted.

If your philosophy involves your opinions mattering in people's private concerns, no, it's not valid.

No. I think marriages actually affect people not involved in the marriage commitment itself. Especially when you consider populations and not just hypothetical individuals.

Yeah, but what does that have to do with random unassociated outside observers? Are you saying society at large has some kind of right to intimate details of personal relationships?

Re: Who Hacked Ashley Madison?

#197
post #2

I don't condone this hack, but morals/ethics aside for a moment: The one positive thing this hack has done is really give serious ammo to the battle for online privacy, because the demographic hit by this hack is the most politically & economically powerful demographic in the world....

Not really. If anything, it's done the opposite, because people were all happy that "a bunch of cheaters got what they deserved."

Re: Who Hacked Ashley Madison?

#198
post #31

Earlier quoted context omitted.

http://digg.com/2015/ashley-madison-hack Not a complete answer, but: "MOTHERBOARD: How did you hack Avid Life Media? Was it hard? The Impact Team: We worked hard to make fully undetectable attack, then got in and found nothing to bypass. MOTHERBOARD: What was their security like? The Impact Team: Bad. Nobody was watching. No security. Only thing was segmented network. You could use Pass1234 from the internet to VPN t…

I googled "Pass1234" assuming it was some sort of exploit tool but didn't find anything. Can anyone explain what this answer means?

It is one of many passwords used to reset a password for someone who forgot their password.

Popular password resets:

password passme abcdefg pass1234 reset changeme late4work

I am sure there are others, once the password is changed to one of these easy passwords, someone who owns the account is support to change it to a harder password.

I used to work as a federal contractor and in IT departments and handled password resets.

One time as a federal contractor someone phoned in from Florida to pretend to be me or someone in my group to get our account password changed to one of the above. They used social engineering and might have been someone who worked there but retired.

When you have a weak password, people can easily break in.

Re: Who Hacked Ashley Madison?

#199

Earlier quoted context omitted.

I'd argue the opposite. The AM hack hasn't helped at all, since enough people view it as a just retribution due to it being about a pet moral value that is held dear, namely marital fidelity. And to others, it's all a big joke. The cheating cheaters (who likely never got the opportunity to cheat) have been named and shamed, and because of those asserting that it's acceptable to do this if it strokes their personal mo…

Yeah, well if you engage in a promise with someone that you're going to be in a monogamous relationship -- let's be real, that's what marriage is for the vast majority -- you're a prick if you attempt to break that commitment, and again, that's what being on AM is about. Pretending otherwise is delusional, and having morals isn't a bad thing. Is doxxing always unethical?

"Is doxxing always unethical?"

YES

Re: Who Hacked Ashley Madison?

#200

Earlier quoted context omitted.

I'd argue the opposite. The AM hack hasn't helped at all, since enough people view it as a just retribution due to it being about a pet moral value that is held dear, namely marital fidelity. And to others, it's all a big joke. The cheating cheaters (who likely never got the opportunity to cheat) have been named and shamed, and because of those asserting that it's acceptable to do this if it strokes their personal mo…

Yeah, well if you engage in a promise with someone that you're going to be in a monogamous relationship -- let's be real, that's what marriage is for the vast majority -- you're a prick if you attempt to break that commitment, and again, that's what being on AM is about. Pretending otherwise is delusional, and having morals isn't a bad thing. Is doxxing always unethical?

"Is doxxing always unethical?"

YES

Post reply on HN