Live data from Hacker News

Doxing the hero who stopped WannaCry was irresponsible and dumb

thenextweb.com

51–60 of 117 posts

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#51
post #37
post #19

Earlier quoted context omitted.

If some journalists were able to find his identity, he can safely assume that the people behind wannacry are also able to do it. How do you figure? Digging through information and finding out this sort of stuff is literally what journalists do for a living.

I occasionally offer to dox people to show them how bad their OpSec truly is or as an example of why I don't use social media like Facebook for privacy concerns. Doxing people is often trivial since nearly anyone contributing to discussions online have large online profiles. It isn't a very difficult task - just a game of connecting the dots and knowing how to construct specific Google search queries (eg: "site:___ +…

I often think about the Witness Protection Program and how much harder it must be to be a part of it in the age of social media and new forms of instant communication. While it's hard enough to cut off ties with family and friends, etc., it must be much worse when there are so many ways to keep in touch with people. Worse, I can't imagine someone in the program would be able to have any kind of online presence. It would be too easy to leak details about yourself.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#52
post #35

I respect the intent of the article, but I feel that the author completely misjudges the intentions and perspective of the mainstream journalists and their readership. It looks more like a culture clash than malice. > MalwareTech doesn’t give out his name on his Twitter page or blog. There are no headshots. It’s obvious that he just wants to be left alone to get on with what he enjoys – hacking shit, and figuring out…

"for the general public, the concept of "anonymous hacker" is not associated with anything good" An association that's largely created by these tabloids in the first place. "that's what "general public" wants to read about" Maybe, but if that's what's required, they should be requesting an interview with him and only reveal what he agrees to reveal. If he wishes to, that could lead to a more insightful look at a man…

I feel that you're trying to argue against some of my points, but we're not in disagreement.

I'm not saying that the current state of affairs is good or defending it; however, I think that the blame is misplaced and the problem lies in culture clash, not in malice (as often happens with the media).

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#53

I respect the intent of the article, but I feel that the author completely misjudges the intentions and perspective of the mainstream journalists and their readership. It looks more like a culture clash than malice. > MalwareTech doesn’t give out his name on his Twitter page or blog. There are no headshots. It’s obvious that he just wants to be left alone to get on with what he enjoys – hacking shit, and figuring out…

I think some of this is true, but it doesn't really excuse anything. I mean, you're right about his age and pizza and hobbies. They turn a tech-news story ("Major malware attack stops") into a human-interest one ("Meet the man who saved the internet"), which plays way better for these papers. The general public, or at least their readership, probably does enjoy those details. And I suspect they didn't exactly conside…

I didn't mention anything about "excuse" or "justify" in my comment; trying to project these things onto the moral axis is pointless and kind of boring, actually. I think it's far more interesting in figuring out _why_ people do certain things and how to change it than to assign "good" and "evil" labels to their acts.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#54

I respect the intent of the article, but I feel that the author completely misjudges the intentions and perspective of the mainstream journalists and their readership. It looks more like a culture clash than malice. > MalwareTech doesn’t give out his name on his Twitter page or blog. There are no headshots. It’s obvious that he just wants to be left alone to get on with what he enjoys – hacking shit, and figuring out…

> [...] but for the general public, the concept of "anonymous hacker" is not associated with anything good.

It's absolute no excuse for the doxer.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#55
post #49

Earlier quoted context omitted.

I've been wondering if it is possible to dox my Reddit account. I like to think I've been careful not to give too much away but I wonder if it is true. I would like to find a white hat site that prepares a report on what they can find about you. (For the record, my reddit account has a different username than my HackerNews account)

>I would like to find a white hat site that prepares a report on what they can find about you. This would be difficult to start as it would require trust. I already do exactly this ("white hat doxing") but do you trust that that is actually what I'm doing? Maybe it would be easier as an established corporation with an explicit privacy policy. >I've been wondering if it is possible to dox my Reddit account. You can ma…

I hate it when people use these scripts and do have a rule against deleting posts that have replies in one subreddit I moderate. There are two kinds of things harmed by this behavior:

* In communities where people buy and sell things, or offer pay for services (e.g. /r/forhire), a glance at someone's account history provides some insight into their likely reliability. It's not much to go on, but that's inherent to doing business with strangers online.

* In many communities, previous discussions are full of useful information for future readers. Removing half of a conversation often ruins that utility.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#57
What does "dug through a ton of OSINT" mean?

Also can anyone point me to resources on preventing doxing while hosting a website? I want a checklist of things that can possibly leak my identity. For example:

- Some basic stuff is use whoisguard and don't reuse any existing hosting / cloud infrastructure or even google analytics accounts

- But for new accounts, does using real credit card information matter? I am not sure how easily a company will give that information up. For example how hard is it to social engineer or get a court order/subpoena for it?

- Even then you can still be fingerprinted by ip, browser agent, hardware if you ever even log in with the same computer. For example HN certainly knows who my alts are just by checking request logs ip.

- What about sharing similar coding style / code base? Or even just speech/writing patterns? Is NLP sufficiently advanced to fingerprint you by that yet?

Are some of these too paranoid? I really think there's no way to fully prevent doxing for anyone sufficiently motivated. What's actually good enough in practice?

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#58

What does "dug through a ton of OSINT" mean? Also can anyone point me to resources on preventing doxing while hosting a website? I want a checklist of things that can possibly leak my identity. For example: - Some basic stuff is use whoisguard and don't reuse any existing hosting / cloud infrastructure or even google analytics accounts - But for new accounts, does using real credit card information matter? I am not s…

https://en.wikipedia.org/wiki/Open-source_intelligence

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#59
post #55
post #49

Earlier quoted context omitted.

>I would like to find a white hat site that prepares a report on what they can find about you. This would be difficult to start as it would require trust. I already do exactly this ("white hat doxing") but do you trust that that is actually what I'm doing? Maybe it would be easier as an established corporation with an explicit privacy policy. >I've been wondering if it is possible to dox my Reddit account. You can ma…

I hate it when people use these scripts and do have a rule against deleting posts that have replies in one subreddit I moderate. There are two kinds of things harmed by this behavior: * In communities where people buy and sell things, or offer pay for services (e.g. /r/forhire), a glance at someone's account history provides some insight into their likely reliability. It's not much to go on, but that's inherent to do…

>In communities where people buy and sell things, or offer pay for services (e.g. /r/forhire), a glance at someone's account history provides some insight into their likely reliability. It's not much to go on, but that's inherent to doing business with strangers online.

Trivially solvable with an alias used exclusively for such dealings where you don't scrub history. Also, as mentioned, it isn't necessarily that good of a rule anyway. Better than nothing but not necessarily by much.

>In many communities, previous discussions are full of useful information for future readers. Removing half of a conversation often ruins that utility.

I value my personal privacy (and time) more than any use my conversations will have for future readers. I don't have the time to selectively edit/delete hundreds of posts. One argument against this would be to "post less" but then many of those "useful posts" may not have ever been made to begin with so there isn't a net difference.

Also - quoting the most relevant bits of a post in your own post helps retain at least some context. Even if you were to edit/remove your post now - I have two pieces of it quoted that a future reader would at least have some context as to our conversation.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#60
post #37

Earlier quoted context omitted.

I occasionally offer to dox people to show them how bad their OpSec truly is or as an example of why I don't use social media like Facebook for privacy concerns. Doxing people is often trivial since nearly anyone contributing to discussions online have large online profiles. It isn't a very difficult task - just a game of connecting the dots and knowing how to construct specific Google search queries (eg: "site:___ +…

I've been wondering if it is possible to dox my Reddit account. I like to think I've been careful not to give too much away but I wonder if it is true. I would like to find a white hat site that prepares a report on what they can find about you. (For the record, my reddit account has a different username than my HackerNews account)

Do you think it would be possible to link your HN and reddit accounts?

I just creeped your whole comment history and you only leak a small pattern of facts here (country, gadget, a couple repeated interests).

The interest related subreddits would likely still be a pretty huge haystack.

Post reply on HN