Live data from Hacker News

Analysing the alleged Minneapolis police department “hack”

troyhunt.com

81–90 of 102 posts

Re: Analysing the alleged Minneapolis police department “hack”

#81
post #55

Earlier quoted context omitted.

Amazon did this for a long time. I don't know if they still do.

They do. I used that "feature" by accident recently. I think one of the accounts was a shopping account, the other started as an AWS account. Both accounts have the same name, same billing address, same credit card. I think the logical next step is to give them the same password and see how bad my foot hurts afterwsrd.

I did this in the past. Aparently I forgot I had an account, setup a new one, then found my older account, after some email migrations, they ended up on the same email with the same password. I think it was pretty consistent about which account I logged into, but changing the email (or the password, I guess) of that account let me access the otherwise hidden account. They still have no merge feature, but at least they let you change your email address, unlike some sites.

Re: Analysing the alleged Minneapolis police department “hack”

#82

Earlier quoted context omitted.

shopify has a similar thing, a two stage login where you sign in with your email then choose your account.

Microsoft has their notorious "is this account personal or issued by company it department" (or something like that) question when you login. Which is the reason it very often takes two tries and several minutes to get logged in as I never seem to guess the correct answer to that question...

I think the difference is between Microsoft online accounts where you can register an account with them using any email address and Azure AD accounts (e.g. for Office/Microsoft 365). The catch is that you can register for a Microsoft online account using an account that is also in Azure AD - so you end up with two accounts of different types with the same email address as username and (hopefully) different passwords. So hence the question asking which one of your accounts you want to log in with.

Yes, this can be confusing.

Re: Analysing the alleged Minneapolis police department “hack”

#83
post #61
post #31

Earlier quoted context omitted.

From overseas this looks like someone abjectly refusing to face it's countries problems. I don't think Russia or any other nation could possibly have anything more than the most minimal effect on what happens when you have an underclass, who have just lost their jobs on mass and with it their health insurance looking at whether Bezos who pays no tax is going to become a trilionaire while the disease of police brutali…

> Bezos who pays no tax is going to become a trillionaire You realize this is misinformation twice over, yes? Doesn't do credit to your argument.

https://www.google.com/amp/s/www.foxbusiness.com/money/amazo...

1.2%

Everything is fine. Where do i donate to his employees sick leave fund again?

Must be the Russians that has everyone angry.

Russians == Saddam's WND until you see hard, overwhelming evidence.

But if you're really not seeing where the anger is coming from, maybe that's a much more significant reason for it than Putin could ever be in his wildest, wettest dreams.

Re: Analysing the alleged Minneapolis police department “hack”

#84
post #16

What is the point of fabricating this attack?

Sad that nobody recognized this bit of social engineering for what it probably is: another way for the feds to vacuum up IPs for anyone dumb enough to try to log in using one of them. No, they're not going to SWAT your apartment tonight if you violate federal CISA laws. It's simply another data point (of thousands or millions) on you in MAIN CORE to profile you. For what? Who knows. If you already have an 'interesting' profile, maybe they will drop by.

You: "But the password didn't work - I didn't get in!" Judge: "You and your cellmate Brutus will have, oh... five years or so to discuss the finer legal points of your case... when you two are not 'otherwise' occupied. Baliff, let's not keep Brutus waiting."

Re: Analysing the alleged Minneapolis police department “hack”

#85
post #12

Earlier quoted context omitted.

My heuristics is, By default, Anything controversial I see on the internet is fake until it's proven to be true. I've been advocating this to my parents and a few others for quite a while. Especially from a country like India where there are people being lynched and killed just based on WhatsApp videos (mostly fake), Skepticism is required more than ever.

This rule means you have to consider almost everything as fake. Like say, a video of police brutality filmed by one person. How do you "prove" it to be non fake?

> a video of police brutality filmed by one person. How do you "prove" it to be non fake?

You might have almost answered your own question. If there are many videos shot by random bystanders in multiple angles of the event, even if one is fabricated, another video can disprove it; making it harder to fake the event.

This would mean that one would have to 'fake' all the videos and angles from other people which is difficult to do, especially if it is live. So with that, it can be proved to 'have happened' but only if the bystanders are un-related to each other. Otherwise it will look 'staged'.

Re: Analysing the alleged Minneapolis police department “hack”

#86

Earlier quoted context omitted.

shopify has a similar thing, a two stage login where you sign in with your email then choose your account.

Microsoft has their notorious "is this account personal or issued by company it department" (or something like that) question when you login. Which is the reason it very often takes two tries and several minutes to get logged in as I never seem to guess the correct answer to that question...

That's a confusing and annoying UI, to be sure - but for these systems, the email adress is not the identifier. The (email,account issuer) pair is the identifier.

So you can have two accounts, say for (vimslayer@contoso.com, Microsoft Account) and (vimslayer@contoso.com, Contoso AD) - and there is no collision and no possible confusion on the system end. All the confusion is on the human end.

And there is a lot of confusion on the human end :)

Re: Analysing the alleged Minneapolis police department “hack”

#87
post #31

Earlier quoted context omitted.

From overseas this looks like someone abjectly refusing to face it's countries problems. I don't think Russia or any other nation could possibly have anything more than the most minimal effect on what happens when you have an underclass, who have just lost their jobs on mass and with it their health insurance looking at whether Bezos who pays no tax is going to become a trilionaire while the disease of police brutali…

It's not about fabricating an otherwise nonexistent problem into being. It is about applying the right pressure in the right place at the right time. For example: jumping in with some social media accounts to schedule a protest for just before sundown (or finding one that happens to be scheduled that poorly to begin with) and using bot accounts to boost it's visibility, increase turnout, and increase the chances that…

I strongly doubt Putin has any effect.

This: https://twitter.com/search?q=bricks%20no%20construction

Seems quite unlikely to be Putin. Do you think it's a conspiracty theory to wonder aloud if the J. Edgar Hoover Building had any hand in this at all. Mere idle speculation... Because J. Edgar Hoover. after whom the FBI continue to name their building tried to get Dr King to commit suicide using surviellance and blackmail. That we know of. But keep the name on the building. No need to lie about it. Putin probably told them to keep the name because he wants the USA to look bad, right? See how silly all this Putin garbage is? Laugh at it, hard. It's what it deserves and what it has always deserved.

Re: Analysing the alleged Minneapolis police department “hack”

#88

> it's extremely unusual to see the same email address with multiple different passwords in a legitimate data breach as most systems simply won't let an address register more than once I've actually built a system which did this years ago, over our initial protestations, and the reasoning went like this: Our client (this was a white label product) has lots of elderly couples as customers, these are our end users and…

  nice.old.couple+alice@gmail.com

  nice.old.couple+bob@gmail.com

Re: Analysing the alleged Minneapolis police department “hack”

#89

> it's extremely unusual to see the same email address with multiple different passwords in a legitimate data breach as most systems simply won't let an address register more than once I've actually built a system which did this years ago, over our initial protestations, and the reasoning went like this: Our client (this was a white label product) has lots of elderly couples as customers, these are our end users and…

nice.old.couple+alice@gmail.com nice.old.couple+bob@gmail.com

That works for GMail but not for a lot of other email providers.

Re: Analysing the alleged Minneapolis police department “hack”

#90
post #89

Earlier quoted context omitted.

nice.old.couple+alice@gmail.com nice.old.couple+bob@gmail.com

That works for GMail but not for a lot of other email providers.

Isn't that part of the email RFCs for 2 decades or so? Postfix certainly supports this for quite a while now.

Edit: sendmail and qmail, too, apparently: https://www.cs.rutgers.edu/~watrous/plus-signs-in-email-addr...

Post reply on HN