Live data from Hacker News

LulzSec: 50 Days of Lulz statement

pastebin.com

31–40 of 97 posts

Re: LulzSec: 50 Days of Lulz statement

#31
post #30

Earlier quoted context omitted.

I was going to say something snarky, but I checked your comment history and it seems you are on here seldom enough to explain an honest lack of knowledge about them. Basically, LulzSec is a hacking group that has been attacking many targets very publicly over the past 2 months. They've been all over HN, /., reddit, etc. They've even earned some mentions in the MSM. Basically, they're notable for a) the number of targ…

I was being sarcastic :-)

And here I was, sparing you my snark. You've made me re-evaluate humanity, sir, and I'm not impressed with the results.

Re: LulzSec: 50 Days of Lulz statement

#33
post #26

Earlier quoted context omitted.

Even if authorities were able to track down someone through TOR, I doubt they'd publish it. More easy to let black hats think they are safe.

Right, but then they'd be prosecuted, and the means would come out. You wouldn't be able to both put people in jail based upon evidence gained from compromising TOR, as well as keep secret the fact that TOR was compromised. Not for long, at any rate.

Pretty simple really, at least in the UK. Just get someone to make an allegation against them (underage porn, etc), and their computers get seized. If the police just happen to discover a ton of other things they're really involved in whilst analysing them, there you go. If encrypted, under UK law you have to divulge the keys or go to jail, so you're guaranteed to get them some jail time.

Re: LulzSec: 50 Days of Lulz statement

#34
post #15

Earlier quoted context omitted.

I'd have to agree. Even now I think that with time they will all be outed - if they've not already. Some of these 'raids' have just been too daring to expect to get away with forever.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

How do they use Tor for such large projects? I tried using that thing like 5-6 yrs ago and it was slower than 56k...

Re: LulzSec: 50 Days of Lulz statement

#37

Earlier quoted context omitted.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

Just like the low security systems they crack, the weakest link in their own chain is the human element. Think password reuse is a problem? So is screen name reuse. So is having the same friends over time. So is trusting people. A person's digital fingerprint is huge these days, and a human weakness can break the chain apart. And once one person's in custody? How much discipline do you think each member has to not sn…

Exactly right. We have images of government forces tracing connections across a glowing map thanks to movies, but really they just tap their network of informants, or do personal research.

In my imagination, they'll start with Aurenheimer's hdd. The world isn't that big. Think how the head of the CIA is probably 7 people away from anyone in luzsec.

Re: LulzSec: 50 Days of Lulz statement

#38
post #34

Earlier quoted context omitted.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

How do they use Tor for such large projects? I tried using that thing like 5-6 yrs ago and it was slower than 56k...

how much traffic does a terminal session really need?

Re: LulzSec: 50 Days of Lulz statement

#39
post #16
post #2

The torrent appears to contain hacked personal data from: * EA (Battlefield Heroes) * Hackforums.net * Nato-bookshop.org * Misc other forums The first of these purports to be 200K+ users.

The Battlefield Heroes passwords are unsalted MD5. Way to go EA.

Hm, are you sure? I have a couple accounts there (and they are appearing in the dump) and they are not simply md5(password). Of course they were long, random passwords and I don't play this game anymore, but I'm curious. Where did you read that?

Re: LulzSec: 50 Days of Lulz statement

#40
post #34

Earlier quoted context omitted.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

How do they use Tor for such large projects? I tried using that thing like 5-6 yrs ago and it was slower than 56k...

What do you mean by large projects? The size of the files they transfer?

Your machine -> TOR -> hacked home user or server -> your target.

This way you only transfer the files between the target and the hacked server, and from there on to a torrent, and heck, why not let that machine seed it too.

Chances are that they even used a chain of hacked machines to get to their target. It gets pretty complicated pretty quickly if you (as in FBI et al) have to raid several companies to get your hands on machines to do forensics on.

I doubt these files (or much of anything else) ever touched the criminal's physical machine. Unless, of course, they fucked up by, say, posting to pastebin or a tweet or something else that is seemingly insignificant (at the time) using their own IP.

Most tend to.

Post reply on HN