Live data from Hacker News

Doxing the hero who stopped WannaCry was irresponsible and dumb

thenextweb.com

101–110 of 117 posts

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#102

Earlier quoted context omitted.

A better way to put it would be to say all of the UK tabloid papers (the Mirror was also mentioned in the article). Tabloid journalism doesn't exactly have a stellar history of responsibility. Unfortunately this sells for some reason.

Is the Telegraph really a tabloid? It's hardly on the same scale as the others presented here (and in the article).

The Telegraph is a broadsheet, yes.

However, I've seen some rumblings on the Internet that it used to be high quality journalism, but lately it had been going more downmarket of late. This is "Internet opinion" of course, so I'm not sure what the real truth is. That being said, if they are engaging in tabloid-style stunts like this these day, this would sort of confirm what I've read.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#103
post #84
post #3

they came to the wrong conclusion that someone who bought a kill switch domain, would have been one of the hackers. when it fact the kill switch was firewall check (look for 502 rather than 404) and the person who bought the domain kill switched it for everyone. Sucky journalism strikes again.

Where did you come to the conclusion that they think he was one of the hackers? Neither the link, nor the Telegraph article said anything like that AFAIK.

you know the media, they'll let the reader make the conclusion.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#104
post #37

Earlier quoted context omitted.

I occasionally offer to dox people to show them how bad their OpSec truly is or as an example of why I don't use social media like Facebook for privacy concerns. Doxing people is often trivial since nearly anyone contributing to discussions online have large online profiles. It isn't a very difficult task - just a game of connecting the dots and knowing how to construct specific Google search queries (eg: "site:___ +…

I've been wondering if it is possible to dox my Reddit account. I like to think I've been careful not to give too much away but I wonder if it is true. I would like to find a white hat site that prepares a report on what they can find about you. (For the record, my reddit account has a different username than my HackerNews account)

Have you ever gilded someone and paid by credit card? If so, your credit card is linked to your account.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#105
post #19

If some journalists were able to find his identity, he can safely assume that the people behind wannacry are also able to do it. Maybe he'll take some measures to protect himslef more now. I would've liked to see the journalists find the hackers behind this. That would've been an achievement indeed.

If some journalists were able to find his identity, he can safely assume that the people behind wannacry are also able to do it. How do you figure? Digging through information and finding out this sort of stuff is literally what journalists do for a living.

If they had enough money behind them it would not have been hard to hire a private detective or similar professional to find him.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#106
post #55
post #49

Earlier quoted context omitted.

>I would like to find a white hat site that prepares a report on what they can find about you. This would be difficult to start as it would require trust. I already do exactly this ("white hat doxing") but do you trust that that is actually what I'm doing? Maybe it would be easier as an established corporation with an explicit privacy policy. >I've been wondering if it is possible to dox my Reddit account. You can ma…

I hate it when people use these scripts and do have a rule against deleting posts that have replies in one subreddit I moderate. There are two kinds of things harmed by this behavior: * In communities where people buy and sell things, or offer pay for services (e.g. /r/forhire), a glance at someone's account history provides some insight into their likely reliability. It's not much to go on, but that's inherent to do…

These scripts are why I'm surprised Reddit doesn't have sub specific edit permissions. I mean, on traditional forums, we avoid these issues by simply blocking the edit function after a certain time limit. Or limiting who can remove content.

Not sure I'd want to see a community where people removed useful content on a whim because they were that worried others would use it against them.

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#107
post #85

Earlier quoted context omitted.

> I would like to find a white hat site that prepares a report on what they can find about you. To me there seems to be an inherent catch-22 involved in that. To be responsible, you have to confirm the person requesting the information is the person that wants doxxing. In providing evidence you are who you say you are, you're seeding that company with information to better find you that might not be easily found othe…

What if the service/whitehat did an ID verification before releasing the info they uncovered? Basically ask a few things generally like what credit report agencies sometimes ask (Which of these addresses are yours? What is your username on this site? etc). Only release the info if there's a match. Presumably you'd want to get paid up front, since you'd have done all the work in either case.

"Please provide your ID" "Ok so here's what we found on you" reads content of ID

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#109
post #97

Earlier quoted context omitted.

So you expect journalists to be something other than whores? Good luck with that.

Please comment civilly and substantively on Hacker News or not at all. https://news.ycombinator.com/newsguidelines.html

A "slang" term for a perfectly legal profession (where I'm from) used in a derivative but substantive manner--it's obviously short for the phrase "attention whore" (which is really the main reason why you shouldn't have moderated this remark) and this type of journalist is doing it just for the attention to make money, which is relevant because it sheds light on their motivation behind their questionable actions. The phrase couldn't be more on-point, actually.

Which leaves the "civil" part. Because he said "whore" instead of "prostitute".

Certainly from now on, you'll be moderating people for using the ugly word "hacker" instead of "security consultant/researcher", right? It really (still) has the same bad name among people not well-acquainted with the biz. And no, it doesn't matter that some people chose to wear the "hacker" title with pride, because guess what? So do most whores.

To add substantively to the discussion myself, here's an open question. I'm having a real hard time coming up with a phrase two words or less, that communicates this aspect of journalism as accurately as "attention whoring". How would you say it?

Re: Doxing the hero who stopped WannaCry was irresponsible and dumb

#110
post #86

If some journalists were able to find his identity, he can safely assume that the people behind wannacry are also able to do it. Maybe he'll take some measures to protect himslef more now. I would've liked to see the journalists find the hackers behind this. That would've been an achievement indeed.

Maybe the wannacry people had more profitable ways to invest their resources, but the cost of pursuing this guy is much lower now.

This. It's the added opportunity that put this researcher in unnecessary danger.

It's like, almost every front door lock can be broken, or circumvented by smashing a window. Leaving your front door unlocked and open however, creates opportunity, that really increases the danger of burglary.

Post reply on HN