Live data from Hacker News

LulzSec: 50 Days of Lulz statement

pastebin.com

71–80 of 97 posts

Re: LulzSec: 50 Days of Lulz statement

#71
post #64

Damn, the AT&T-release is especially juicy. It contains a lot of highly confidential information about technology and strategy that their competitors would love to get their hands on. I'm a quite technical guy and I barely understand a thing. No wonders AT&T are having troubles with fixing their network troubles, it looks like a massive, massive beast of technology. I found the frequency chart fascinating. It's avail…

Given the juiciness of this, I'm surprised that more companies don't have corp espionage groups to carry out little lulsec attacks.

Because if they ever got caught the company would be sued out of existence (probably bought by competitors at that point). They have too much to lose in most cases.

Re: LulzSec: 50 Days of Lulz statement

#72
post #40

Earlier quoted context omitted.

What do you mean by large projects? The size of the files they transfer? Your machine -> TOR -> hacked home user or server -> your target. This way you only transfer the files between the target and the hacked server, and from there on to a torrent, and heck, why not let that machine seed it too. Chances are that they even used a chain of hacked machines to get to their target. It gets pretty complicated pretty quick…

This mirrors an idea that I had. TOR is a military project, and you know at least some of the exit nodes are controlled by the US gov't. Why not replicate TOR with a botnet? Bounce your communications around a plethora of average joes and you have yourself a more stable tor. If you spread the botnet without a CnC server and have the infected machines bounce random traffic around, it would be damned difficult to break…

> you know at least some of the exit nodes are controlled by the US gov't

http://www.google.com/search?q=high+traffic+colluding+tor+ro...

Re: LulzSec: 50 Days of Lulz statement

#73
post #44
post #40

Earlier quoted context omitted.

What do you mean by large projects? The size of the files they transfer? Your machine -> TOR -> hacked home user or server -> your target. This way you only transfer the files between the target and the hacked server, and from there on to a torrent, and heck, why not let that machine seed it too. Chances are that they even used a chain of hacked machines to get to their target. It gets pretty complicated pretty quick…

Ahhh, didn't know they went onto hacked machines. So - some people should be getting some knocks on their door soon?

Yup, you use a compromised Windows machine or Linux server in a third world country as a proxy. When you're done, you wipe the disk.

Re: LulzSec: 50 Days of Lulz statement

#74
post #15

Earlier quoted context omitted.

I'd have to agree. Even now I think that with time they will all be outed - if they've not already. Some of these 'raids' have just been too daring to expect to get away with forever.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

What's the point of the VPN? A place to store data that is in a country that isn't US friendly?

Re: LulzSec: 50 Days of Lulz statement

#77
post #66

Earlier quoted context omitted.

If you are interested in some hypothetical pondering about how secure Tor is not, here's some food for thought: http://sheddingbikes.com/posts/1293530004.html

"P.S. I have a long bet that SELinux is an NSA backdoor. Any takers?" Really? Zed Shaw lost the credibility to talk about anything security related with that one sentence ...

Yeah -- as if the NSA would be unable to crack software if it were not for SELinux.

Re: LulzSec: 50 Days of Lulz statement

#78
post #34

Earlier quoted context omitted.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

How do they use Tor for such large projects? I tried using that thing like 5-6 yrs ago and it was slower than 56k...

Try again. Tor is being improved all the time, browsing is fun with today's speeds. ~100 Kilobytes/s are normal, sometimes much more.

Re: LulzSec: 50 Days of Lulz statement

#79
post #64

Earlier quoted context omitted.

Given the juiciness of this, I'm surprised that more companies don't have corp espionage groups to carry out little lulsec attacks.

Because if they ever got caught the company would be sued out of existence (probably bought by competitors at that point). They have too much to lose in most cases.

[deleted]

Re: LulzSec: 50 Days of Lulz statement

#80
post #67
post #36

What about analyzing their writing? They release quite a bit of text...somebody likes to write. Considering there are efforts to identify people by typing patterns, I wonder if this is how they'll get caught: http://petsymposium.org/2011/papers/hotpets11-final8Chairunn...

Unfortunately given the scope of that paper, it doesn't sound like typing patterns can be used just yet. A sample size of 36 participants doesn't handle the scale involved when going against 'The Internet'. Also, the paper collected timestamps of each keystroke, something that'd need to done on suspects; however, if they are already suspecting you, they probably have other ways to identify you. Finally, how in the wo…

Was it written by an ESL speaker? Sometimes non-English speakers feel insecure starting a point without "However", "Because of this", and other conjunctions. If you don't need a conjunctions, you can say "Nowadays", but you don't need it. It's like the "auto" keyword in C. Because ESL speakers cram a lot of grammar into a few years, rather than spending years making simple sentences, they often use advanced patterns when simpler ones would suffice.
Post reply on HN