Live data from Hacker News

A Hacker Has Wiped a Spyware Company’s Servers

motherboard.vice.com

111–120 of 120 posts

Re: A Hacker Has Wiped a Spyware Company’s Servers

#111

Earlier quoted context omitted.

Their security was bad, no doubt. I don't see how that justifies deleting their data, though.

As TFA describes it, the first deletion last year by the heroic hacker actually interrupted another hacker's access to the data. Why hadn't that other hacker deleted it? Maybe he enjoyed having access to private pictures and communications of children, teens, and adults... Does that sound like a good situation?

No, that doesn't sound like a good situation. You want to know some other big companies that have been hacked? - LinkedIn, MySpace, Adobe, Dropbox, DailyMotion, Sony, Kickstarter, Equifax... ad infinitum. Do these companies also deserve to have their data deleted?

Re: A Hacker Has Wiped a Spyware Company’s Servers

#112

I see no reason to praise the hacker. He destroyed a legitimate company's private data for no purpose other than his flawed moral reasoning. The company provides a way for parents to monitor their children and other legitimate business practices. Obviously, the software can be used for nefarious purposes but so can almost any other software. U.S. representatives and senators try to ban encryption using the same exact…

> legitimate business practices Whenever I read this phrase, it always has a sense something like legal, therefore ethical or legal, therefore OK , and.. (this is not an easy sentence to finish) I wonder where people learn to think like that. OK, apart from the pressure of the entire commercial/corporate/advertising apparatus.. Maybe it's surprising it isn't more common. I guess it's the norm, in some circles. I'm na…

The reason to think and speak in such a manner (with regard to law) is because we live in a society where we have a social contract with all of the other people and businesses in it. It is frowned upon for individuals to go around and commit illegal acts that they deem ethical because of that social contract. It would be chaos if we did not adhere to the laws that society has agreed upon. This is why we come together and vote on what we deem to be unethical and make it illegal.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#113

I see no reason to praise the hacker. He destroyed a legitimate company's private data for no purpose other than his flawed moral reasoning. The company provides a way for parents to monitor their children and other legitimate business practices. Obviously, the software can be used for nefarious purposes but so can almost any other software. U.S. representatives and senators try to ban encryption using the same exact…

Well, I side with that hacker for this, taken from this article — "I don't want to live in a world where younger generations grow up without privacy." While parents make a lot of decisions for children in their best interests, this certainly wasn't one of them. The fact that children might later suffer for no fault of theirs and live with something for life because of such a company makes me a lot more angry. It's be…

That's very noble, but I don't want to live in a world where one moral vigilante hacker cowboy dictates what world we live in. It seems much more reasonable to come together as a people and vote on what we can and cannot do. After we vote, we can write down what the majority has decided and then demand individuals adhere to those policies. We could then call those policies "law". Seems much more reasonable to me.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#114
post #84

Earlier quoted context omitted.

No, you should never commit your secrets, not even to a private github repo, and not even to a privately hosted git server. Doing so increases your attack surface, sometimes in surprising ways. Now, if your secrets are encrypted before being committed (using something like ansible vault) and the encryption key is not stored in the repo, that may be ok. However, you still need to be aware that any time you rotate that…

So how do you do version the configuration management for the cluster that runs everything? It needs to be versioned, and yet with just the data in it you need to be able to recreate your entire environment from scratch.

If you want your secrets under version control, then they should be encrypted.

There are lots of ways of doing this. git-crypt is one that is configuration management agnostic. Most CM tools have their own way of dealing with secrets and there are CM agnostic tools like git-crypt. I'm not personally familiar with anything besides ansible-vault, but this article seems to provide a pretty good summary of several options: https://www.threatstack.com/blog/cloud-security-best-practic...

Re: A Hacker Has Wiped a Spyware Company’s Servers

#115
post #69
post #48

Earlier quoted context omitted.

Do you have a recommended security checklist for something like this? I remember seeing an old github repo with a bunch of good information but I cannot seem to find it and my search results are... unhelpful at best.

Checklists are cool and all. But, you shouldn't need a checklist to know that you shouldn't ship API keys.

Can't disagree with that.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#116
post #35

Earlier quoted context omitted.

I get what you are saying, but there can be legal/financial concerns attached to these things.

Monitoring usage of a corporate issue piece of equipment is very different than using it against a private individual without their knowledge

My point is that if they can catch a significant other cheating, the divorce settlement equation can change significantly.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#117

Earlier quoted context omitted.

As TFA describes it, the first deletion last year by the heroic hacker actually interrupted another hacker's access to the data. Why hadn't that other hacker deleted it? Maybe he enjoyed having access to private pictures and communications of children, teens, and adults... Does that sound like a good situation?

No, that doesn't sound like a good situation. You want to know some other big companies that have been hacked? - LinkedIn, MySpace, Adobe, Dropbox, DailyMotion, Sony, Kickstarter, Equifax... ad infinitum. Do these companies also deserve to have their data deleted?

None of those firms collected private pictures without consent. All of them actually made some attempt to fix their vulnerabilities when notified. Any one of them that allowed random strangers to delete their data "deserved" to have that done. No firm has a right to success in business.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#118
post #77
post #2

This is one of those cases where I probably should feel bad for the company being repeatedly hacked to the point of being ripe for being shut down, but I just can't muster the will right now. If you are in the business of collecting data without users' explicit permission, and can't protect that data from being accessed or deleted, you shoudln't be in business.

> If you are in the business of collecting data without users' explicit permission, or a warrant from a court, you shouldn't be in business. Fixed that for you

But where would all the mathematicians go?

Re: A Hacker Has Wiped a Spyware Company’s Servers

#119
post #38

Earlier quoted context omitted.

??!? Their 'data' includes all the photos YOUR KIDS take on their phones. Do you not realize how much absolutely idiotic shit kids do with their smartphones these days? Which they store in an an obviously unsafe way, as evidenced by the fact that they've been hacked via a super-super-super obvious software flaw... twice (that was widely reported on, most likely many more times). They deserve, and they should get, no…

You know what other services have data that contains photos of your "YOUR KIDS"? Google, Facebook, Amazon, Apple, Microsoft, Sony, Photobucket, and pretty much every other tech company with hosting services. If these companies get hacked, do they deserve to have their data deleted? The answer is no.

No, they would deserve a hefty, HEFTY fine and regulation barring them from providing services to anyone under 18 years of age, and then they deserve to delete all the relevant data themselves (with oversight). However Google, Facebook, Amazon, Apple, Microsoft, Sony, Photobucket are not in the business of selling shady ass spyware whose sole reason for existing is for stalkers, creeps, jealous ex-lovers and helicopter parents to invade people's privacy and personal security, so they have at least a little bit going for them over this sleazeball company. _Very_ little, but a little still.

Re: A Hacker Has Wiped a Spyware Company’s Servers

#120
This might not directly answer your question but i’m sure it would help you a lot.. No one deserves to be cheated on, especially when your full loyalty lies with the betrayer of your trust. Initially, I thought I was just feeling insecure when my wife would just be on her phone at odd hours, until I decided to take a chance to know, knowing is better than self doubts and it was exactly what happened when I employed the services of this particular guy(MASTERSHIELD55@GMAIL .COM) I came across by chance to help check her phone out thoroughly. Now I know when she’s telling the truth and how to curtail her, I think it is not a drastic step if it'll make you feel better. My life got better, I stopped using my precious time to bother about her indiscretions and channeled my energy positively. His services includes: phone call hacks,messages,contacts,social media(viber, whatsapp,facebook, kik e.t.c),emails,Gallery and videos hack,gps location tracking,calendars and reminders.. You can reach him through his email or on WhatsApp Messenger +1 (628) 203 7309 .
Post reply on HN