Live data from Hacker News

Paige Thompson, Capital One Hacking Suspect, Left a Trail Online

nytimes.com

11–20 of 52 posts

Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online

#12
post #8

If we assume that Ms. Thompson is generally terrible at opsec, then presumably she is also terrible at offensive security, which leads to one of two conclusions: Either: A: She is being framed. or B: Capital One's security was (and probably still is) laughable. She doesn't seem to be being framed. If Capital One's security is horrendous, they are unlikely to be exceptional... so we will see much more of this.

This tweet alone seems to indicate she definitely did it...

https://twitter.com/0xA3A97B6C/status/1151901325598187521

Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online

#13
post #8

If we assume that Ms. Thompson is generally terrible at opsec, then presumably she is also terrible at offensive security, which leads to one of two conclusions: Either: A: She is being framed. or B: Capital One's security was (and probably still is) laughable. She doesn't seem to be being framed. If Capital One's security is horrendous, they are unlikely to be exceptional... so we will see much more of this.

> She

Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online

#14
post #8

If we assume that Ms. Thompson is generally terrible at opsec, then presumably she is also terrible at offensive security, which leads to one of two conclusions: Either: A: She is being framed. or B: Capital One's security was (and probably still is) laughable. She doesn't seem to be being framed. If Capital One's security is horrendous, they are unlikely to be exceptional... so we will see much more of this.

> If we assume that Ms. Thompson is generally terrible at opsec, then presumably she is also terrible at offensive security,

One can possess great technical skills and still be a braggart. Nothing about a lack of OPSEC implies she cannot exploit a vulnerable system.

Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online

#15
I was confused by this line in the affidavit (page 9):

> An April 19, 2019, post in the Github account of "paige•••••thompson" includes a "Server List" of IP addresses associated with the account.

What Github "post" could this be referring to? A README.md/issue/comment in which she for some reason posted the IP addresses she uses with that account?

https://www.justice.gov/usao-wdwa/press-release/file/1188626...

Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online

#16

How are we getting past the NYT PayWall now?

If you paste the link into archive.is, it’ll often be already archived or it will save a fresh copy.

I would encourage people — if they can afford it — to pay for a few media sites online.

Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online

#19
I used to feel what you likely feel about paying for news—why would i pay for this when some other site will have it up for free or with ads, capitalism at work, competition driving the price down to reasonable levels, etc...

Then I realized after seeing what has happened as the masses all came online, while many of us here can probably distinguish between a reliable news source and a hack site or a propaganda outlet—a disturbingly large segment of the population can not.

And to make matters worse, there seems to be a huge number of people who don’t realize they don’t have what it takes to do reliable research to write a story and they don’t have what it takes to understand nuanced subjects in order to explain the subject to readers. Or even worse, they fully realize how ill-equipped they are but don’t care because vulnerable people will still click their ads.

Long story short, I now have just short of 20 subscriptions. Including a few that I rarely read but to me it’s worth it. The collective We really need to increase the signal levels in order to hear over the noise.

Journalism is definitely one of those cases where The Market can easily lead to a race to the bottom situation. Hopefully we’ll see it correct and good journalism will overtake trash, but wow what a rough spot.

Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online

#20
post #15

I was confused by this line in the affidavit (page 9): > An April 19, 2019, post in the Github account of "paige•••••thompson" includes a "Server List" of IP addresses associated with the account. What Github "post" could this be referring to? A README.md/issue/comment in which she for some reason posted the IP addresses she uses with that account? https://www.justice.gov/usao-wdwa/press-release/file/1188626...

The first thing that comes to mind is a gist.
Post reply on HN