Live data from Hacker News

Phineas Fisher's account of how he took down HackingTeam

ghostbin.com

81–90 of 105 posts

Re: Phineas Fisher's account of how he took down HackingTeam

#81
i'm really happy to see the translation getting around this far. it's an amazing text, & i'm glad my quick & dirty translation job got it out there mostly intact. i never really gave it a proper proofread, so thanks for catching those mistakes. more importantly, though, Phineas Fisher himself has just released his own translation. and, having just discovered that ghostbins are editable, i added a url to his version at the top of the text. here it is again: http://pastebin.com/raw/0SNSvyjJ

Re: Phineas Fisher's account of how he took down HackingTeam

#82
post #17

For anyone who doesn't follow infosec: This guy is responsible for two of the most impressive hacks recently and still hasn't been doxed or arrested. And so the linked doc is awesome if only for the opsec tips it provides. And it provides much more than that. It really gives you some perspective on how much work an attacker will put into breaking into your network and the kind of structured approach they're taking. P…

He's likely to be identified as he gets more brazen. Even authoring this volume of text is risky, and there are other notes from the same author linked within. Spelling can be used to approximate region and phrases or errors such as "the hard of the business" ("heart of") and "passtime" ("pastime") are even stronger markers. Of course there's no way to tell if these are unintentional or planted errata. I'm grateful f…

The Unabomber was turned in by his brother and sister in law who recognized his writing.

Re: Phineas Fisher's account of how he took down HackingTeam

#84
post #53

Is there any reason to believe this doc was (or was not) produced by a state-level actor?

That is my thought as well, for a few reasons.

Well, the author's day job might be as a "whitehat" for a state sponsored entity -- its even possible/plausible the author could be one of the HackingTeam -- perhaps motivated by company politics to expose them.

Re: Phineas Fisher's account of how he took down HackingTeam

#85
post #4

Earlier quoted context omitted.

Could you expand on your comment? My understanding is that if a party can't tie a wallet to an identity then it is anonymous. So if you can acquire bitcoins (eg. mining) and purchase something (eg. VPS) without giving up your identity then you are solid.

I've heard conflicting information as far as this goes. Thinking this through- an adversary who's watching the block chain probably knows some inputs and some outputs. As in, these addresses belong to an exchange, these addresses belong to a hosting company. Okay, fine. Now remember than any user can literally create wallets out of thin air, and in fact doing so is considered basic security hygiene. Let's say Joe Use…

Graph analysis.

Re: Phineas Fisher's account of how he took down HackingTeam

#87

> I want to dedicate this guide to the victims of the assault on the Armando Diaz school, and to all those whose blood has been spilled at the hands of Italian fascism. For those who don't know, they are referring to the 2001 Armando Diaz school attack [1] (warning: graphic), where hundreds of G8 pacific protesters were brutalized and tortured by Italian police. Whilst the police has been found guilty of this, none o…

Italian police too scared to deal with mafia, beat students instead. Italian police have no balls.

Please don't do this here.
Post reply on HN