Live data from Hacker News

How one man tracked down Anonymous—and paid a heavy price

arstechnica.com

111–120 of 162 posts

Re: How one man tracked down Anonymous—and paid a heavy price

#111
post #95

Earlier quoted context omitted.

I am not a lawyer, but I'd like to address your legal points. Just as I don't need a warrant to view a publicly available website, he shouldn't either. What you are proposing is that it should be illegal to view public pages in a certain order or time. What is the difference of me viewing 100 of my new crushes friends pages over 2 days vs 2 years? There isn't, but the first is rifling, the second is innocent curiosit…

Wouldn't communicating an "untrue statement of fact" that certain people are leaders of an allegedly law-breaking group to government officials or other people constitute defamation (assuming that their reputations were harmed as a result)?

I think there are two issues here:

1. The first is that he did not release the report publicly, which is what would cause the defamation. Anonymous did. Thus he wouldn't be responsible for the release of the data. The issue here is really the publishing of it. He did not publish it, and selling it to a private law enforcement agency, in my mind at least is not publishing it.

2. The second issue is related to false police reports. In America, it is illegal to file a false police report. However, this is not what is happening here. He is not claiming to police that a crime was actually committed, instead he is providing information related to that crime. He is basically selling criminal leads to law enforcement. He's basically doing a crime stoppers like program, but generating the leads himself and going straight to the feds.

Re: How one man tracked down Anonymous—and paid a heavy price

#112

I can't believe this guy has a job in a security company doing work for the federal government. I'm getting a strong vibe that he's schizophrenic. I've known an unmedicated schizophrenic, and this is the way they talked and acted. Self-aggrandizing, convinced they have comprehended great secrets based on little to no data (schizophrenics often believe that have "other ways of knowing" or extremely heightened intuitio…

IANAL but it doesn't sound like he did anything criminal to me. He's obviously misguided and silly, thinking he can draw statistical relevance from assumptions based on his personal reading of Facebook profiles, but there is nothing illegal about reading information that someone posts on the internet. Cyberstalking, to the best of my non-lawyer knowledge, involves real, disruptive harassment, not just a guy who saw y…

Yes, I should have been more clear.

I believe what is illegal is that he was threatening these people, by dropping hints in IRC and national media. He used his fake persona to notify the people he had identified as "leaders" that a security company was researching them and had leadership information, etc.

I don't think it should be illegal to browse facebook, twitter, etc. But, the social engineering aspect of things and the kind of shitstorm he was cooking up was definitely evil and irresponsible. I believe some of the stuff he did does constitute bullying or harassment, and many of his targets are underage.

Regardless of the legality, which was just an afterthought in my post, honestly (I had to even search to see if cyberstalking and such had any legal meaning, and it turns out it does), I find what he was doing disturbing as hell.

Re: How one man tracked down Anonymous—and paid a heavy price

#113

Based on my own minimal experience, the majority of these IRC channels are just a small group of "Anonymous" doing whatever they want, different channels will get publicised at different times through different means, "Anonymous" doesn't exist in any way beyond being a label people use, I guess it could be compared to "emo" or "jock" in high school; they have no "leadership" but people join these groups and label the…

Q is probably a reference to Star Trek character's Q: http://memory-alpha.org/wiki/Q

Huh. Maybe, but I assumed James Bond's Q was more likely:

http://en.wikipedia.org/wiki/Q_(James_Bond)

Re: How one man tracked down Anonymous—and paid a heavy price

#114

Earlier quoted context omitted.

I would guess that such groups are being manipulated by exceptionally smart people for specific ends, some significant fraction of the time.

I would guess that such groups are being manipulated by exceptionally smart people for specific ends, some significant fraction of the time. I think that's a tempting theory to have. Explains a lot and is easy to understand, but I think it gives individuals too much credit. I would guess exceptionally smart people drift in and out at random and attempt to use the group for specific ends. I think their success rate is…

I would guess exceptionally smart people drift in and out at random and attempt to use the group for specific ends. I think their success rate is slim and random.

I think that's what they want you to think. It may even be true. It's not a reason to give up on the "smart core group" theory, though.

I think it gives individuals too much credit.

This is a long running debate. There is a camp that thinks individual personalities have significant effects on History. I'd be willing to believe that Anonymous is entirely emergent, but in that case, there would be a "fossil record" of its evolution. (Great. Now that I've posted that, some smartass Anon is going to create one!)

What this means is that trying to control or predict the actions of the group is a fool's game. At best you may be able to influence them occasionally in some small way, its pure chaos theory.

There's no good way to guarantee which way a buffalo herd will stampede. Doesn't mean there's zero utility in doing so, or that no one can be held accountable.

Re: How one man tracked down Anonymous—and paid a heavy price

#115
post #42

I'm astounded at both the CEO's (Aaron's) lack of basic grammar skills, and predeliction for "script kiddie" talk. How do you get to be CEO of anything when you communicate (even informally) at the level of an 8th grader? (edit: I meant Aaron; Penny was decently well spoken)

1. drink brain away 2. become "social media" expert 3. lie to get funding 4. ??? 5. ceo

I think you've just described at least two startups I've worked for.

Re: How one man tracked down Anonymous—and paid a heavy price

#116

Earlier quoted context omitted.

Regardless of whether the ones he called out are innocent (though I suspect most are, since his methods are the work of a madman), he trawled through hundreds of profiles, twitter feeds, IRC conversations, and basically cyberstalked the hell out of every friend of every person he thought might be a "leader" of Anonymous; many of them underage, and the vast majority completely oblivious about Anonymous. He even create…

he trawled through hundreds of profiles, twitter feeds, IRC conversations, and basically cyberstalked the hell out of every friend of every person he thought might be a "leader" of Anonymous...This is the stuff pedophiles and con-men do to get closer to their victims might do. That's also what private investigators and intelligence agents might do. By your logic, all private investigators using the same methods are p…

"If I were deliberately smearing AB, I'd try to concoct a reason to mention him as you do in posts also mentioning "pedophile" and "schizophrenic" as often as possible, only I'd use logic that wasn't such an indiscriminate stretch."

Yeah, I would, too.

But, I'm being sincere. This is creepy behavior from a guy who was not listening to reason from anyone around him.

I don't think anyone needs to smear him...anyone who reads the emails can't come away thinking this guy is a good guy. I'm just ranting because this whole thing is terrifying to me.

The thought that our government might be funding this kind of insanity under the guise of "national security" is...well, have you ever seen The Lives of Others? It's a great film about the Stasi in East Germany, and how they read everything, watched everyone, kept dossiers on everyone, and basically just kept an eye on every single person on the off chance they might be up to something. This, to me, is the modern equivalent...though I would hope it's not taking place in any actual police office.

Re: How one man tracked down Anonymous—and paid a heavy price

#117
post #101

Earlier quoted context omitted.

> If their aim was the highest level of security Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong. Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else. If their source code was stolen, the…

Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong. Putting words in my mouth. No one said anything about perfect security. Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else. And they did…

> Putting words in my mouth. No one said anything about perfect security.

No, you mentioned the highest level which I took to read as perfect. If that's not what you meant then I'm sorry for reading too much into it.

> And they did not do this

Which I feel more inclined to agree with rather than claiming they failed because they didn't meet the highest level of security. However, a compromise doesn't necessarily mean that they didn't do enough - as TJX would be happy to tell you. Compromises happen, if they didn't we wouldn't be in business.

> Of course. It does not follow that breaking into the web server should compromise the mail server, or vice-versa. You're really losing me there.

It depends - it's not clear whether or not these are the same server. As well as this what's important is that someone somewhere in HBGary considered the possibility of getting hacked as part of a process to determine what countermeasures they should look to put in place.

It might not have been a small amount of money, they might have saved a lot or nothing. Having mail servers compromised is embarrassing but shouldn't be the end of the world - because anything that would cause real pain you would have to expect countermeasures for. Where this gets interesting is that with some of the documents Mr. Barr has not considered the possibility that his account might get hacked. If you don't consider your defences compromised to begin with, you're likely to compromise on your defences. The issue isn't 4 Gig of mail has been leaked, the issue is more to do with whether or not anything sensitve should've been encrypted. Of course, we're all only human and make mistakes, but dealing with this will be part of paying for them.

> I bet I could find a company that could set up an email server that couldn't be compromised just because the web server was compromised.

I've no doubt you could find someone who'd claim that they could do it, but it's all going to depend on the architecture, configuration, software and maintenance involved. FWIW I don't believe that HBGary used a company for their mail, I read somewhere that Aaron Barr was the administrator - perhaps that was an oversight on HBGary's part given comments about his personality by other staff members.

Re: How one man tracked down Anonymous—and paid a heavy price

#118
post #95

Earlier quoted context omitted.

I am not a lawyer, but I'd like to address your legal points. Just as I don't need a warrant to view a publicly available website, he shouldn't either. What you are proposing is that it should be illegal to view public pages in a certain order or time. What is the difference of me viewing 100 of my new crushes friends pages over 2 days vs 2 years? There isn't, but the first is rifling, the second is innocent curiosit…

I agree with you up to a point. And here's that point: "Before the release of the data, and while this was going on, those on the list were unaware of what was occurring. Just as a reasonable person isn't threatened until they become aware of the stalking, threats, etc in real life." People did become aware of it before the release, which is why the exploits of his servers happened, and why Anonymous got butthurt and…

The only real legal point you have is the hints and threats issue. There isn't a good public record of what was said. From the article, it appears as though he said he wasn't going to publish names publicly. Although, it seems to suggest this was post DDOS.

There isn't a clear enough public documentation of what happened to fully say one way or another. My suspicion is that those on the list did not tell him to stop, which is one way legally of measuring when harassment starts.

Re: How one man tracked down Anonymous—and paid a heavy price

#119

I can't believe this guy has a job in a security company doing work for the federal government. I'm getting a strong vibe that he's schizophrenic. I've known an unmedicated schizophrenic, and this is the way they talked and acted. Self-aggrandizing, convinced they have comprehended great secrets based on little to no data (schizophrenics often believe that have "other ways of knowing" or extremely heightened intuitio…

"Self-aggrandizing, convinced they have comprehended great secrets based on little to no data (schizophrenics often believe that have 'other ways of knowing' or extremely heightened intuition), and a belief that once they tell the whole story of the truths that have been revealed to them the world will take notice and be amazed." Are you describing a schizophrenic or a newbie entrepreneur? ;)

Point conceded. Maybe this guy is merely recklessly arrogant and has drunk the Koolaid of entrepreneurship, and is not actually insane.

Re: How one man tracked down Anonymous—and paid a heavy price

#120
post #117

Earlier quoted context omitted.

Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong. Putting words in my mouth. No one said anything about perfect security. Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else. And they did…

> Putting words in my mouth. No one said anything about perfect security. No, you mentioned the highest level which I took to read as perfect. If that's not what you meant then I'm sorry for reading too much into it. > And they did not do this Which I feel more inclined to agree with rather than claiming they failed because they didn't meet the highest level of security. However, a compromise doesn't necessarily mean…

> Putting words in my mouth. No one said anything about perfect security.

No, you mentioned the highest level which I took to read as perfect.

Given the opportunity, you choose a mediocre interpretation instead of the most intelligent one. (Actually, that's charitable. You ascribed an idea to me that everyone knows doesn't exist.) This results in a lower level of discussion.

> I bet I could find a company that could set up an email server that couldn't be compromised just because the web server was compromised.

I've no doubt you could find someone who'd claim that they could do it, but it's all going to depend on the architecture, configuration, software and maintenance involved. FWIW I don't believe that HBGary used a company for their mail, I read somewhere that Aaron Barr was the administrator

And how isn't this a red flag for organizational incompetence at HBGary?

Post reply on HN