Live data from Hacker News

Doxing the hero who stopped WannaCry was irresponsible and dumb

thenextweb.com

91–100 of 117 posts

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#91
post #49

Earlier quoted context omitted.

I've been wondering if it is possible to dox my Reddit account. I like to think I've been careful not to give too much away but I wonder if it is true. I would like to find a white hat site that prepares a report on what they can find about you. (For the record, my reddit account has a different username than my HackerNews account)

>I would like to find a white hat site that prepares a report on what they can find about you. This would be difficult to start as it would require trust. I already do exactly this ("white hat doxing") but do you trust that that is actually what I'm doing? Maybe it would be easier as an established corporation with an explicit privacy policy. >I've been wondering if it is possible to dox my Reddit account. You can ma…

I just delete accounts every ~3 months.

Used to, when I really used reddit. Now I basically have a different account in each device to upvote/downvote.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#92
I agree with this article, but though I am no expert in this topic I do wonder how much the wannacry perpetrators would actually go after this guy. Consider:

1. The fact that it was disabled so trivially was ultimately their own fault.

2. As we have seen, it was easy enough for them to change the logic to remove the web request on the nonexistent domain and start spreading again.

3. Retaliation would not be without cost and risk. Acting on #2 instead is a less costly, less risky action.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#93

It’s obvious that he just wants to be left alone to get on with what he enjoys – hacking shit, and figuring out how stuff works No, he wants to be left alone because it endangers his life to reveal his identity. Jesus, do people seriously expect someone that's done heroic deeds like this to jump out and scream "I am Batman"???

The author talks about this further down in the article.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#94
post #37

Earlier quoted context omitted.

I occasionally offer to dox people to show them how bad their OpSec truly is or as an example of why I don't use social media like Facebook for privacy concerns. Doxing people is often trivial since nearly anyone contributing to discussions online have large online profiles. It isn't a very difficult task - just a game of connecting the dots and knowing how to construct specific Google search queries (eg: "site:___ +…

I've been wondering if it is possible to dox my Reddit account. I like to think I've been careful not to give too much away but I wonder if it is true. I would like to find a white hat site that prepares a report on what they can find about you. (For the record, my reddit account has a different username than my HackerNews account)

Have a look at snoop snoo and see what it says about you based on your Reddit comments.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#95
>> The Telegraph talks a little bit about how he’s self-taught, and how he stopped WannaCry by figuring out it had a kill-switch.

The reasearcher's blog (posted on HN earlier) said that although originally he thought it was a kill switch he now thinks it was just a clumsy attempt at detecting whether the worm was runnign inside a sandbox.

Apparently, worms will often do that sort of thing- call out to an unregistered domain to check whether they get a response indicating that they're not really connected to the internet. Except the ones that do it right call out to some random domains and this one had it hard-coded (either because the creator of the worm was a numpty or because they forgot it) (and therefore, a numpty).

So it probably wasn't a kill-switch in the sense of a failsafe, as it was reported in the press.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#96
post #73

Earlier quoted context omitted.

I've been wondering if it is possible to dox my Reddit account. I like to think I've been careful not to give too much away but I wonder if it is true. I would like to find a white hat site that prepares a report on what they can find about you. (For the record, my reddit account has a different username than my HackerNews account)

There's a reddit account summarizer (I know you said you don't own /u/spare_account on reddit, this is just an example): https://www.snoopsnoo.com/u/Spare_Account

I just used this for my reddit account... holy crap its kinda scary how accurate it is. All it takes is for you to slip up in a comment here or there, add in a detail somewhere once, and its all there. I think i need to start using temp reddit accounts, and just jump ship every few months.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#97
post #13

Earlier quoted context omitted.

I would have liked to see a story from the journalists on how easy it was for them to find the guy and then they had responsibility alerted the person on those points w/o revealing his name (you know like what security researchers do)

So you expect journalists to be something other than whores? Good luck with that.

Please comment civilly and substantively on Hacker News or not at all.

https://news.ycombinator.com/newsguidelines.html

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#98
post #85

Earlier quoted context omitted.

I've been wondering if it is possible to dox my Reddit account. I like to think I've been careful not to give too much away but I wonder if it is true. I would like to find a white hat site that prepares a report on what they can find about you. (For the record, my reddit account has a different username than my HackerNews account)

> I would like to find a white hat site that prepares a report on what they can find about you. To me there seems to be an inherent catch-22 involved in that. To be responsible, you have to confirm the person requesting the information is the person that wants doxxing. In providing evidence you are who you say you are, you're seeding that company with information to better find you that might not be easily found othe…

What if the service/whitehat did an ID verification before releasing the info they uncovered? Basically ask a few things generally like what credit report agencies sometimes ask (Which of these addresses are yours? What is your username on this site? etc). Only release the info if there's a match.

Presumably you'd want to get paid up front, since you'd have done all the work in either case.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#99
This whole thing is not adding up. You would think that MalwareTech being the great "ethical hacker" that he is, that he would at least have information hidden and his identity hidden, but a simple DDOX was able to expose his identity. This does not add up. If you're part of the community,you would know better to protect your identity,unless you intend it to be exposed. Take me for example. I dare anyone to find anything about me. I dare you to even find my real IP address. This whole thing with WannaCry and MalwareTech seems like a publicity stunt. It is as if it all had been planned for, from the beginning. What if MalwareTech is the one responsible for WannaCry? He sure is, but it is hard to draw such conclusion, until you look at his Twitter account and his willingness to talk to the public, and his nonchalant attitude about being known in the public as the person who stopped a huge cyber attack. Anyone in his place would be freaking the fuck out,because anyone in the community knows not to mess with a hacker, let alone stop a cyber attack of presumably several hackers. MalwareTech is not scared,because there is no one behind the attack besides himself, and the whole thing is a publicity stunt. It's a hoax. He probably wants a job in California or somewhere in the US working with an antivirus company with a high salary. To that I say that he was clever in doing so.
Post reply on HN