Live data from Hacker News

Tampa teen accused of being ‘mastermind’ behind Twitter hack

wfla.com

281–290 of 702 posts

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#281

Earlier quoted context omitted.

Bitcoin is actually explicitly designed to enable recourse and refunds. Every single transaction is permanently and immutable tied to a verifiable identity. Through common practice, these identities are treated as disposable and therefor generally ignored. But stating that the currency is explicitly designed to disallow accountability is not an accurate representation of reality. -- Edit to add a practical example fo…

Transactions are not reversible by legal authority in bitcoin, only by the receiving party willingly doing the transaction in reverse. What you are talking about is establishing reputability, not about refund-ability or the ability of authorities to reverse illicit transactions. You can see that as a feature of bitcoin or not, but if you want protections from a system you need to act within that system.

This is like saying that gold coins are explicitly designed not to allow recourse and refunds and that transactions in gold are not reversible by any legal authority.

In both BTC and solid gold, reversibility is not a property of the currency. It is a part of the system which uses that currency.

However, with Bitcoin (unlike with gold) the currency is explicitly designed with verifiable identity being fundamental to every transaction.

With Bitcoin, an individual can prove that they participated in a transaction that was later determined to be fraudulent. This is a fact of the currency. It is explicitly built in to Bitcoin at a foundational level.

Whether existing systems use that specific aspect of the currency to do anything meaningful is a separate matter.

But the fact is that bitcoin itself has more accountability than other currencies. Not less.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#282

Is there any way I could prove that I was a victim of this crime?

I'd start your legwork here with a phone call to your nearest FBI field office. Make sure you have the paper trail showing from your end you sent crypto to the perpetrators, and ask what the next step would be for claiming your defrauded property. It may also be worth consulting with a lawyer to see what your legal recourse might be here.

Fair warning: there may be no next step. I have no idea if the US government even considers cryptocurrency "property" in any legally-meaningful sense.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#283
post #268

> Washington DC Field Office Cyber Crimes Unit analyzed the blockchain and de-anonymized bitcoin transactions allowing for the identification of two different hackers. Anyone with Bitcoin Transaction knowledge, what's this de-anonymization of Bitcoins transaction? >Today’s announcement proves that cybercriminals can no longer hide behind perceived global anonymity,” said Thomas Edwards, Special Agent in Charge, U.S.…

> Anyone with Bitcoin Transaction knowledge, what's this de-anonymization of Bitcoins transaction?

Since Bitcoin is not anonymous but pseudonymous, it can be as simple as finding one or more transactions that link a wallet to a real identity (such as one tied to purchase of physical goods with an identified recipient and shipping information) and from there tieing every other transactions from.that wallet to the same identity. I would guess in practice it often involves more steps of connection.

> This reads like an Ad copy of a company that's against perceived anonymity.

The DoJ isn't a company, but it is very much against perceived lack of accountability, which is one of the reasons people choose systems that offer perceived anonymity.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#284
post #268

> Washington DC Field Office Cyber Crimes Unit analyzed the blockchain and de-anonymized bitcoin transactions allowing for the identification of two different hackers. Anyone with Bitcoin Transaction knowledge, what's this de-anonymization of Bitcoins transaction? >Today’s announcement proves that cybercriminals can no longer hide behind perceived global anonymity,” said Thomas Edwards, Special Agent in Charge, U.S.…

Bitcoin is anonymous until you tie it to something that requires a real identity. For most people, it's probably tied to an exchange that has their real identity, credit card info, and maybe bank account info.

What they should've done is generate a new wallet with no previous transactions and just used that to buy things.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#285

Earlier quoted context omitted.

I'm not sure what your criticism of the quote means here. The biggest weakness of BTC for criminal enterprise is the fact that every transaction must be logged to a global public ledger. The hard part is aligning the public keys with private keys, but if you have enough additional information (such as, say, the private keys' owners sitting in a prison cell and the private keys themselves flayed out of their unencrypt…

I know the quote was accurate. I thought it was common knowledge that bitcoin is not anonymous, therefore making "de-anonymized the bitcoin transactions" a bit of an overstatement.

Ah, now I follow. I assume they intended "de-anonymized" to mean "tied the public keys to identifiable human beings IRL."

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#286
post #268

> Washington DC Field Office Cyber Crimes Unit analyzed the blockchain and de-anonymized bitcoin transactions allowing for the identification of two different hackers. Anyone with Bitcoin Transaction knowledge, what's this de-anonymization of Bitcoins transaction? >Today’s announcement proves that cybercriminals can no longer hide behind perceived global anonymity,” said Thomas Edwards, Special Agent in Charge, U.S.…

Bitcoin transactions take place between addresses, which are hashes of public keys. It's actually better to call bitcoin "pseudonymous", since the addresses are pseudonyms that may or may not be tied to an irl identity.

So if you, a hacker, tell someone to submit Bitcoin to an address, that address is only really "anonymous" until you use your private keys to reroute the money to other addresses. As soon as the graph of transactions touches some known node (perhaps at the edges of the Bitcoin network that interact with the monetary system), you can trace back to figure out who might have controlled the original address.

It's very silly to try to cash in on ill-gotten bitcoin...

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#287
post #265

Earlier quoted context omitted.

Having bad security is not criminal. If it was we wouldn't have a voting village at defcon cracked by pre-teens and there would be a lot more irresponsible CEO's in prison (so probably a better world).

Is bad security ok for, say, a bank or a nuclear power plant?

No, and that's why we (basically all nations that have banks or nuclear power plants) have specific laws governing them.

Look, if you want to pass a law saying all internet business having X personal data needs to prove Y security, then I'd probably be for it (depending on X and Y). We already have PCI-DSS and similar today for payment providers. I'm just saying that there is nothing like that today, and if there was we'd have a lot more irresponsible people in prison.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#288
post #131

Hitting a 17yo with 30 felony charges feels a bit steep to me. Also should any repercussions be considered against Twitter that a 17yo was able to gain access to the private messages of potentially some of the most important individuals in the world? If a 17yo could do it, I'm sure a nation state could do it.

I think the fact that "a 17yo was able to gain access to the private messages of potentially some of the most important individuals in the world" does pretty serious damage to their reputation — that is in itself a repercussion.

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#289
post #192

Earlier quoted context omitted.

A man has a hotdog stand that he never cleans. One day, a health inspector comes by and tells him that unless he cleans his grill every day, he can’t keep selling hotdogs. The man shouts “I’ve never cleaned the grill in my life! It’s impossible, nobody does it! And who’s going to pay for the cleaner and the five minutes every day, me? No, I’ll just go sell my hotdogs somewhere else.” And he leaves. Later a regular co…

See it's all a matter of opinion. I personally don't really care about online privacy and GDPR just gets in my way. I know that's not a very popular opinion on this site but it's the way I feel.

"Those who don’t care much about privacy might say that they have nothing to hide. Those who do worry about it might say that keeping their personal data safe protects them from being harmed by hackers or unscrupulous companies. Both positions assume that caring about and protecting one’s privacy is a personal matter. This is a common misunderstanding."

https://www.newstatesman.com/science-tech/privacy/2019/10/pr...

Re: Tampa teen accused of being ‘mastermind’ behind Twitter hack

#290

Earlier quoted context omitted.

It's been quite awhile now since the GDRP protections have been around. If they haven't finished removing tracking by now, then they're lying when they say "your privacy matters to us". No, it doesn't. If it mattered, then you would act like it.

This isn't the New York Times. I don't think it's reasonable to expect the local news for a mid-sized American city to prioritize implementation of the EU's data rules.

Sure, but it's plenty of time to just remove tracking cookies altogether. Which would have been easier to implement than what they're doing now (geolocating visitors, serving custom messages depending on jurisdiction, etc.)

I mean, if my privacy matters to them.

I know the online news business is difficult to monetize. Only a handful of major news orgs can put paywalls up and charge subscribers directly. I get that.

So, what they do instead is use 3rd party ad networks and analytics, and traffic in my personal data, while telling me that my privacy matters.

That's why this is doublespeak. They're saying one thing (my privacy matters) while doing another (funding their operations in part on my personal data).

Is it the only viable model for them? Maybe. That's not really relevant, though.

Post reply on HN