Live data from Hacker News

Doxing the hero who stopped WannaCry was irresponsible and dumb

thenextweb.com

61–70 of 117 posts

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#62
post #26

Earlier quoted context omitted.

It publicly releasing the IRL identity (name, address, etc) of the person behind an anonymous online identity. The term applies more to places like reddit/twitter/4chan than to someone's own blog, but it's generally considered a form of harassment because it's an invasion of privacy.

Ah! I didn't realize it was an English dictionary word. I really thought it was an "inner circle" term that needed defined for the layperson. My mistake.

It's not a word in common usage. Neither me, nor anyone else here that I asked had ever heard of that word at all. I had to google for it.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#63

What does "dug through a ton of OSINT" mean? Also can anyone point me to resources on preventing doxing while hosting a website? I want a checklist of things that can possibly leak my identity. For example: - Some basic stuff is use whoisguard and don't reuse any existing hosting / cloud infrastructure or even google analytics accounts - But for new accounts, does using real credit card information matter? I am not s…

Use Tails or Whonix. Buy Bitcoin with cash via mail on Localbitcoins.com. Depending on your level of paranoia, don't use bills directly withdrawn from the bank/ATM.[1] Be careful to not get fingerprints/hair/traceable writing on the envelope. What I've done is ask someone at the store (buy a card/envelop at CVS or something) to write the address for you. With BTC-via-mail, the only thing you leak is a rough physical location. Running the coins through Monero or something should blind things and render all this moot, but hey just in case?

With anonymized currency, then you're free to start signing up for stuff. If a site doesn't accept Bitcoin, use Localbitcoins.com to buy a prepaid debit card (Visa/Mastercard). If a site insists on a phone number for confirmation, use a darknet market to buy a pre-made Google Voice account. You can't access it over Tor or it'll get blocked, so use darknet markets to rent a Windows client box ($10-20 a month) so you have a "clean" IP and Google won't block you.

Then it's a matter of not giving away your info. You should adopt an entire persona when you're doing anything related to your site. Come up with a backstory (name, location, etc.). Ideally, none of this would matter: You're over Tor and using an entirely separate system for everything related to the site. But from the indictments I've read, it seems like a lot of first steps in finding someone's ID are just going off small hints. The way they write, mentioning the weather, etc. I would assume it to be very effective to fake these things. (For instance, notice a flood in a part of the country. Stay offline during the flood. When you get back on, write a small note that you had to be away due to flooding.)

None of this will protect you from an adversary that can correlate your home-connected-to-Tor times with site-gets-updated-times. But it'll stop people without that access, even if they're willing to fake a subpoena/warrant/etc. to your registrar/hosting provider (easier than you'd think). And hell, it doesn't always take a legal order to get those details; social engineering can do it just fine.

The Whonix wiki goes into lots of details on all this: https://www.whonix.org/wiki/DoNot

1: I asked Wells Fargo and they claimed they don't keep track of serial numbers and have no way to do so, but it seems so trivial I wouldn't believe it.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#64

They failed to find creators of wanacry, so they found the guy that didn't hide and made him look like he did something bad.

No, they presented him as a hero, because that's what he is, and that's what people want to hear about.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#65

They failed to find creators of wanacry, so they found the guy that didn't hide and made him look like he did something bad.

No, they presented him as a hero, because that's what he is, and that's what people want to hear about.

Did you happen to read his tweets?

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#66

Earlier quoted context omitted.

No, they presented him as a hero, because that's what he is, and that's what people want to hear about.

Did you happen to read his tweets?

Yes, just did. Did you read the articles? Certainly sounds like they're calling him a hero:

http://www.telegraph.co.uk/news/2017/05/14/revealed-22-year-...

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#67

Earlier quoted context omitted.

Did you happen to read his tweets?

Yes, just did. Did you read the articles? Certainly sounds like they're calling him a hero: http://www.telegraph.co.uk/news/2017/05/14/revealed-22-year-...

Where did that link come from? How could i possibly know about your link if the topic link is different?

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#68

I respect the intent of the article, but I feel that the author completely misjudges the intentions and perspective of the mainstream journalists and their readership. It looks more like a culture clash than malice. > MalwareTech doesn’t give out his name on his Twitter page or blog. There are no headshots. It’s obvious that he just wants to be left alone to get on with what he enjoys – hacking shit, and figuring out…

[deleted]

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#69

Earlier quoted context omitted.

Yes, just did. Did you read the articles? Certainly sounds like they're calling him a hero: http://www.telegraph.co.uk/news/2017/05/14/revealed-22-year-...

Where did that link come from? How could i possibly know about your link if the topic link is different?

I assumed by "they" you meant the Telegraph. If not, then please clear up the confusion...
Post reply on HN