Live data from Hacker News

LulzSec: 50 Days of Lulz statement

pastebin.com

61–70 of 97 posts

Re: LulzSec: 50 Days of Lulz statement

#63
post #48

Earlier quoted context omitted.

I'm pretty sure confidential informants are tailor made for covering up illegal or undisclosed investigation techniques. It's not like they haven't had a little practice trying to protect wiretaps. Which isn't to say that I think the feebs have compromised TOR, because I think that's pretty unlikely.

That's an interesting perspective. Still, in order for the anonymous source's testimony to carry any weight, there'd have to be some solid evidence. Either they'd have to show traffic logs, or they'd have to show the results of forensics done on the suspect's hdd. If you've properly distanced yourself from your activities, then there shouldn't be anything on your hard drive to implicate you. Ultimately, it comes down…

[deleted]

Re: LulzSec: 50 Days of Lulz statement

#64

Damn, the AT&T-release is especially juicy. It contains a lot of highly confidential information about technology and strategy that their competitors would love to get their hands on. I'm a quite technical guy and I barely understand a thing. No wonders AT&T are having troubles with fixing their network troubles, it looks like a massive, massive beast of technology. I found the frequency chart fascinating. It's avail…

Given the juiciness of this, I'm surprised that more companies don't have corp espionage groups to carry out little lulsec attacks.

Re: LulzSec: 50 Days of Lulz statement

#65

Damn, the AT&T-release is especially juicy. It contains a lot of highly confidential information about technology and strategy that their competitors would love to get their hands on. I'm a quite technical guy and I barely understand a thing. No wonders AT&T are having troubles with fixing their network troubles, it looks like a massive, massive beast of technology. I found the frequency chart fascinating. It's avail…

My first job out of college was at Nortel, coding their 4G data network infrastructure. I still think I only understood about 20% of the big picture by the time I left. So many moving parts, massive code base and tons of acronyms.

Re: LulzSec: 50 Days of Lulz statement

#66
post #26

Earlier quoted context omitted.

Even if authorities were able to track down someone through TOR, I doubt they'd publish it. More easy to let black hats think they are safe.

If you are interested in some hypothetical pondering about how secure Tor is not, here's some food for thought: http://sheddingbikes.com/posts/1293530004.html

"P.S. I have a long bet that SELinux is an NSA backdoor. Any takers?" Really? Zed Shaw lost the credibility to talk about anything security related with that one sentence ...

Re: LulzSec: 50 Days of Lulz statement

#67
post #36

What about analyzing their writing? They release quite a bit of text...somebody likes to write. Considering there are efforts to identify people by typing patterns, I wonder if this is how they'll get caught: http://petsymposium.org/2011/papers/hotpets11-final8Chairunn...

Unfortunately given the scope of that paper, it doesn't sound like typing patterns can be used just yet. A sample size of 36 participants doesn't handle the scale involved when going against 'The Internet'.

Also, the paper collected timestamps of each keystroke, something that'd need to done on suspects; however, if they are already suspecting you, they probably have other ways to identify you.

Finally, how in the world does a paper like this get away with having 'nowadays' in it? I know its a legit word, but, just seems awkward.

Re: LulzSec: 50 Days of Lulz statement

#68
Looks like they were a getting a bit anxious that they were going to be outed, which will ultimately still happen anyway. Regardless, it was a fun reading their Pastebins and Twitter feeds every few days making a mockery of multiple corporations information security.

Re: LulzSec: 50 Days of Lulz statement

#69

Earlier quoted context omitted.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

Just like the low security systems they crack, the weakest link in their own chain is the human element. Think password reuse is a problem? So is screen name reuse. So is having the same friends over time. So is trusting people. A person's digital fingerprint is huge these days, and a human weakness can break the chain apart. And once one person's in custody? How much discipline do you think each member has to not sn…

The human element is clearly the weak point, but it's also the easiest to overcome. The cracker who speaks to no one is secure beyond reproach. That they inevitably speak to others in search of recognition and respect is a flaw in the operators, not the system.

Re: LulzSec: 50 Days of Lulz statement

#70
post #48

Earlier quoted context omitted.

I'm pretty sure confidential informants are tailor made for covering up illegal or undisclosed investigation techniques. It's not like they haven't had a little practice trying to protect wiretaps. Which isn't to say that I think the feebs have compromised TOR, because I think that's pretty unlikely.

That's an interesting perspective. Still, in order for the anonymous source's testimony to carry any weight, there'd have to be some solid evidence. Either they'd have to show traffic logs, or they'd have to show the results of forensics done on the suspect's hdd. If you've properly distanced yourself from your activities, then there shouldn't be anything on your hard drive to implicate you. Ultimately, it comes down…

If they were serious about the investigation they'd probably get a sneak and peak warrant to install a keylogger/etc. (either electronically or physically) instead of just a smash and grab. That way they'd have some good trial evidence, because as you say relying on forensics for computer crime is quite dicey - something the bureau is all too familiar with. If they can beat the system electronically this also gives them a chance to see whether there is anything that'd make a quick seizure worth it.

The law enforcement exposure they just did undoubtedly made it much easier to get warrants or FISA approval if they did have some targets.

Post reply on HN