Live data from Hacker News

Phineas Fisher's account of how he took down HackingTeam

ghostbin.com

71–80 of 105 posts

Re: Phineas Fisher's account of how he took down HackingTeam

#73
post #61

The border between what is "right" and what is "wrong" is very thin. What he did is illegal but it was right. I think people should be grateful to the ones that as he did, fight against what is legal but definitely wrong.

Did you get a chance to vote on the law that made what he did illegal? Better yet, when was the lat time you got to vote on a law that was passed in your country?

I can't understand what you really meant with your questions, but no, usually you don't get the chance to vote law. As a citizen (at least an italian one) you are allowed to vote for parties which in the end vote for the laws. So i don't have the right to directly vote for a law. I can only delegate someone to decide laws for me and this is a broken system at least in 2016 when i think we have all the technology to allow individual votes or at least a better delegation mechanism.

Re: Phineas Fisher's account of how he took down HackingTeam

#74
post #47

> I want to dedicate this guide to the victims of the assault on the Armando Diaz school, and to all those whose blood has been spilled at the hands of Italian fascism. For those who don't know, they are referring to the 2001 Armando Diaz school attack [1] (warning: graphic), where hundreds of G8 pacific protesters were brutalized and tortured by Italian police. Whilst the police has been found guilty of this, none o…

An interesting movie about what happened at the Diaz school: https://en.wikipedia.org/wiki/Diaz_%E2%80%93_Don't_Clean_Up_...

Where to find it though? I'm having a hard time finding it through legal or illegal means.

Re: Phineas Fisher's account of how he took down HackingTeam

#75
post #47

Earlier quoted context omitted.

An interesting movie about what happened at the Diaz school: https://en.wikipedia.org/wiki/Diaz_%E2%80%93_Don't_Clean_Up_...

Where to find it though? I'm having a hard time finding it through legal or illegal means.

If you can deal with arabic subtitles on top of the english ones, it's at https://vimeo.com/150492784 and https://vimeo.com/150597736

Re: Phineas Fisher's account of how he took down HackingTeam

#76
post #50

> I want to dedicate this guide to the victims of the assault on the Armando Diaz school, and to all those whose blood has been spilled at the hands of Italian fascism. For those who don't know, they are referring to the 2001 Armando Diaz school attack [1] (warning: graphic), where hundreds of G8 pacific protesters were brutalized and tortured by Italian police. Whilst the police has been found guilty of this, none o…

>> "hundreds of G8 pacific protesters were brutalized and tortured by Italian police. Whilst the police has been found guilty of this, none of the policemen is serving any jail time." If police commit crimes, they must be held accountable.

Or America

Re: Phineas Fisher's account of how he took down HackingTeam

#78
Wow, this was a real eye-opener.

>Thanks to the hardworking Russians and their exploit kits... many businesses already have compromised machines in their network. Almost all of the Fortune 500, with their enormous networks, have a few bots on the inside

I could definitely believe that, having worked at a few, they have massive infrastructure and many users that are extremely relaxed about security in general.

What then struck me was the way he casually decided to hack a VPN (!) is it really so straightforward? And the way he seemed confident about testing his exploit on other compromised machines without detection.

I'm always paranoid every time I type 'last' on my Linux box, wondering if the thing is really compromised and totally lying to me - now I'm even more so!

Re: Phineas Fisher's account of how he took down HackingTeam

#80

Wow, this was a real eye-opener. >Thanks to the hardworking Russians and their exploit kits... many businesses already have compromised machines in their network. Almost all of the Fortune 500, with their enormous networks, have a few bots on the inside I could definitely believe that, having worked at a few, they have massive infrastructure and many users that are extremely relaxed about security in general. What th…

> What then struck me was the way he casually decided to hack a VPN

He's intentionally vague, but given he mentions two routers and two vpn systems, it's highly probable that he's referring to one of the two routers (which is embedded, and has firmware). Furthermore, he refers to a website[1] which predominately deals with routers.

> is it really so straightforward?

Routers, yes[2], VPN daemons, not as much.

[1]: http://www.devttys0.com/training/ - which can also contain a vpn daemon of course.

[2]: https://github.com/darkarnium/secpub/tree/master/Multivendor...

Post reply on HN