Live data from Hacker News

Phineas Fisher's account of how he took down HackingTeam

ghostbin.com

31–40 of 105 posts

Re: Phineas Fisher's account of how he took down HackingTeam

#31
post #26
post #17

Earlier quoted context omitted.

He's likely to be identified as he gets more brazen. Even authoring this volume of text is risky, and there are other notes from the same author linked within. Spelling can be used to approximate region and phrases or errors such as "the hard of the business" ("heart of") and "passtime" ("pastime") are even stronger markers. Of course there's no way to tell if these are unintentional or planted errata. I'm grateful f…

Who exactly would be trying to track him down? Is there some global force that would be active on him?

HT, Gamma, victims we aren't aware of, or any government who could believably threaten to prosecute then offer a deal for cooperation?

Some people even do it out of curiosity: https://news.ycombinator.com/item?id=11304752

Re: Phineas Fisher's account of how he took down HackingTeam

#32

Earlier quoted context omitted.

I've heard conflicting information as far as this goes. Thinking this through- an adversary who's watching the block chain probably knows some inputs and some outputs. As in, these addresses belong to an exchange, these addresses belong to a hosting company. Okay, fine. Now remember than any user can literally create wallets out of thin air, and in fact doing so is considered basic security hygiene. Let's say Joe Use…

You have to use your bitcoins someday. Either to buy real currency or real goods. Then you know where the money went TO. Tracing the transactions back (where the money came FROM) is then not a big deal - full history is in the blockchain. So as long as you don't do a transaction that connects your identity to any bitcoin address, you are fine. but to use bitcoins you are almost always required to do it (its an electr…

Only as you say if you convert them into a "real" currency. If they only used their Bitcoin to purchase goods (such as VPS) which was not tied to a physical address, then they could still remain anonymous.

As for where the Bitcoins came from, I'm sure the author of this document would have some digital assets they could sell on the darknet to acquire some Bitcoin. Where those Bitcoin originated then would not be their problem.

Re: Phineas Fisher's account of how he took down HackingTeam

#33
post #26
post #17

Earlier quoted context omitted.

He's likely to be identified as he gets more brazen. Even authoring this volume of text is risky, and there are other notes from the same author linked within. Spelling can be used to approximate region and phrases or errors such as "the hard of the business" ("heart of") and "passtime" ("pastime") are even stronger markers. Of course there's no way to tell if these are unintentional or planted errata. I'm grateful f…

Who exactly would be trying to track him down? Is there some global force that would be active on him?

[deleted]

Re: Phineas Fisher's account of how he took down HackingTeam

#34

> Hacking Team was a company that [...] AFAIK, they are still operating and still doing exactly the same thing.

They just lost their export license.

More information:

http://motherboard.vice.com/read/hacking-team-has-lost-its-l...

Quote:

"We can sell everywhere in Europe without a license. We can sell everywhere in the world but we have to ask for a license every time we sell."

Re: Phineas Fisher's account of how he took down HackingTeam

#35
post #17

Earlier quoted context omitted.

He's likely to be identified as he gets more brazen. Even authoring this volume of text is risky, and there are other notes from the same author linked within. Spelling can be used to approximate region and phrases or errors such as "the hard of the business" ("heart of") and "passtime" ("pastime") are even stronger markers. Of course there's no way to tell if these are unintentional or planted errata. I'm grateful f…

This text is a translation. The original is in Spanish. It might have its own mistakes and traces, although I am not knowledgeable to detect country-specific patterns. http://pastebin.com/raw/GPSHF04A Presumably, given that they talk about EU culture^W^W^W^W (see comment below) have a https://securityinabox.org/es/… link, the author is from Spain, which would make it easier to pinpoint an origin, as Spain has a wider…

After reading the original doc, by the style used and some slang (although it could be on purpose), I would say the author is from Chile.

I'm glad to find people that still fight the system in this side of the world.

Re: Phineas Fisher's account of how he took down HackingTeam

#36
post #4

Earlier quoted context omitted.

Could you expand on your comment? My understanding is that if a party can't tie a wallet to an identity then it is anonymous. So if you can acquire bitcoins (eg. mining) and purchase something (eg. VPS) without giving up your identity then you are solid.

I've heard conflicting information as far as this goes. Thinking this through- an adversary who's watching the block chain probably knows some inputs and some outputs. As in, these addresses belong to an exchange, these addresses belong to a hosting company. Okay, fine. Now remember than any user can literally create wallets out of thin air, and in fact doing so is considered basic security hygiene. Let's say Joe Use…

Just by following the flow of the money between wallets? Assuming that at least one of the wallets can be connected to an identity, guessing that the others belong to the same person shouldn't be too difficult, just by observing transaction patterns.

Re: Phineas Fisher's account of how he took down HackingTeam

#37

> I want to dedicate this guide to the victims of the assault on the Armando Diaz school, and to all those whose blood has been spilled at the hands of Italian fascism. For those who don't know, they are referring to the 2001 Armando Diaz school attack [1] (warning: graphic), where hundreds of G8 pacific protesters were brutalized and tortured by Italian police. Whilst the police has been found guilty of this, none o…

Italian police too scared to deal with mafia, beat students instead.

Italian police have no balls.

Re: Phineas Fisher's account of how he took down HackingTeam

#38

> I want to dedicate this guide to the victims of the assault on the Armando Diaz school, and to all those whose blood has been spilled at the hands of Italian fascism. For those who don't know, they are referring to the 2001 Armando Diaz school attack [1] (warning: graphic), where hundreds of G8 pacific protesters were brutalized and tortured by Italian police. Whilst the police has been found guilty of this, none o…

Thanks. I'm shocked, I had no idea this had happened.

Re: Phineas Fisher's account of how he took down HackingTeam

#40

> Hacking Team was a company that [...] AFAIK, they are still operating and still doing exactly the same thing.

Here's a rather technical article on what they are apparently up to: https://reverse.put.as/2016/02/29/the-italian-morons-are-bac...

HackingTeam latest sample is a very fresh sample compared with what we got in the past, it is a sample created post July 2015 hack, and it’s using the same code base as before. HackingTeam is still alive and kicking but they are still the same crap morons as the email leaks have shown us.

Post reply on HN