Live data from Hacker News

How police found Twitter user accused of sending seizure-triggering GIF

documentcloud.org

1–10 of 148 posts

Re: How police found Twitter user accused of sending seizure-triggering GIF

#4
TL;DR

Twitter gave the police information about the phone number which registered the account that sent the seizure-triggering gif

AT&T gave the police information that is was a Tracfone prepaid account with an associated toll record that was an iphone

Apple gave them access to his cloud account which had all the incriminating details needed including email / picture of him with his drivers license and data about the victim

Re: How police found Twitter user accused of sending seizure-triggering GIF

#7
post #2

That seems like a very reasonable process. Nothing unusual anyways.

Agreed. This appears to be the ordinary process. Can anyone point out what might be of interest here.

The only thing I can point to us this is one of the few cases where some piece of atrocious online harassment actually ended up with someone being held accountable in anyway. There have been plenty of cases of death threats and bomb threats and other such things that didn't seem to trigger any kind of real response.

Re: How police found Twitter user accused of sending seizure-triggering GIF

#8
Dumb question, but what is the meaning of AT&T "toll records" used to link the user to an iPhone 6?

> "AT&T responded and a review of the subscriber information showed the telephone number was associated with a Tracfone prepaid account with no subscriber information. However, a review of the AT&T toll records showed an associated Apple iPhone 6A Model 1586"

That is, if you are a Tracfone user and Tracfone uses AT&T to provide service, AT&T effectively sees the Tracfone user information?

Also, Twitter tracks the type of client used to send a tweet and reveals it in the metadata accessible to the public API -- the `source` attribute [0], e.g. "Twitter for iPhone", "Twitter Web Client", "TweetDeck". And Twitter probably captures more about the device/client that isn't publicly revealed, such as the browser agent for when a tweet is sent via the web client.

If the suspect had tweeted using the iPhone client, or via the iPhone Safari browser, would the police have enough info to subpoena Apple for Apple Account tied to that specific phone number? In other words, skipping the process of subpoenaing AT&T/Tracfone because the suspect was dumb enough to register the Twitter account using that phone number?

[0] https://dev.twitter.com/rest/reference/post/statuses/update

Re: How police found Twitter user accused of sending seizure-triggering GIF

#9
post #5

Desktop browsers allow you to disable auto-playing animated images. I'm surprised mobile browsers don't seem to have this. If I suffered from this, I'd want some sort of reasonable protection from asshats.

That's a good place point. I see Apple's disability servies praised on a regular basis.

One would have thought this scenario would have been thought of.

Is it possible on iOS to disable animations / autoplay within an app?

Re: How police found Twitter user accused of sending seizure-triggering GIF

#10
post #2

That seems like a very reasonable process. Nothing unusual anyways.

Agreed. This appears to be the ordinary process. Can anyone point out what might be of interest here.

It was interesting to me because of how ordinary it was. I just assumed the user would be doing this from a regular computer, and that the police tracked down the IP. Not that the suspected troll would be dumb enough to use his own phone number to register for Twitter. And be someone who is "Clever" enough to use a pre-paid account but then dumb enough to sync data to iCloud. But I guess it's easy to erroneously conflate Apple's device security with iCloud security.
Post reply on HN