Live data from Hacker News

LulzSec: 50 Days of Lulz statement

pastebin.com

81–90 of 97 posts

Re: LulzSec: 50 Days of Lulz statement

#81
post #4

Quitting or rebranding is the question I find myself asking.

Like a wave they will again become sea, only to rise later as a different wave.

Or to put my high school poetics into plain English:

They will want to blend in with the Anonymous masses, until they deem it safe to once again to craft new identities for themselves.

Re: LulzSec: 50 Days of Lulz statement

#82

Earlier quoted context omitted.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

You're assuming they're safe because their technology stack is safe, but there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Cops work like hackers in the sense that both groups attack vulnerabilities. The vulnerabilities here are clear: these guys have big mouths and they're overconfident. They'll talk to somebody someday, and when that happe…

> there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz.

Would be interesting to hear some of them.

Re: LulzSec: 50 Days of Lulz statement

#83
post #41
post #39

Earlier quoted context omitted.

Hm, are you sure? I have a couple accounts there (and they are appearing in the dump) and they are not simply md5(password). Of course they were long, random passwords and I don't play this game anymore, but I'm curious. Where did you read that?

I didn't read it anywhere. I downloaded the database and checked all my friends against a known password database. They're plain md5(password).

Then the dump must be old. I have changed my password months ago and the hash does not match my current password.

Re: LulzSec: 50 Days of Lulz statement

#84
post #33

Earlier quoted context omitted.

Pretty simple really, at least in the UK. Just get someone to make an allegation against them (underage porn, etc), and their computers get seized. If the police just happen to discover a ton of other things they're really involved in whilst analysing them, there you go. If encrypted, under UK law you have to divulge the keys or go to jail, so you're guaranteed to get them some jail time.

Just get someone to make an allegation against them (underage porn, etc), and their computers get seized. Is that legal in the UK? Because in the US it'd be unconstitutional.

In the UK they can seize your computers from your home for creating a public nuisance or wasting police time (they actually did this to a journo a few years back). Oh, and they don't give them back. I mean yeah I think they're supposed to but they don't exactly get around to it quickly.

Re: LulzSec: 50 Days of Lulz statement

#85
post #15

Earlier quoted context omitted.

I'd have to agree. Even now I think that with time they will all be outed - if they've not already. Some of these 'raids' have just been too daring to expect to get away with forever.

Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…

Well, I think its just a matter of the amount of pressure a group puts on the feds for finding them. TOR is not 100% percent, iirc there are some rather successfull attacks against it, so once a group like LulzSec starts releasing stuff that is really hot (millitary documents, e.g. US war logs or the nuclear weapon codes :D ) the feds or rather the nsa will think of something new. I guess they have the monetary means to setup a few TOR nodes...

Re: LulzSec: 50 Days of Lulz statement

#86
post #73
post #44

Earlier quoted context omitted.

Ahhh, didn't know they went onto hacked machines. So - some people should be getting some knocks on their door soon?

Yup, you use a compromised Windows machine or Linux server in a third world country as a proxy. When you're done, you wipe the disk.

3rd world country only? You mean nothing else outside your own country works? tsk tsk.

Re: LulzSec: 50 Days of Lulz statement

#87
post #82

Earlier quoted context omitted.

You're assuming they're safe because their technology stack is safe, but there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Cops work like hackers in the sense that both groups attack vulnerabilities. The vulnerabilities here are clear: these guys have big mouths and they're overconfident. They'll talk to somebody someday, and when that happe…

> there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Would be interesting to hear some of them.

Most any overlap between your "secret" identity and your "normal" identity can provide an opening.

This might involve (erroneously) shared contacts. Shared VoIP numbers. Shared MAC addresses, or shared IP addresses. Shared passwords. IRC channels or web sites.

Even what times you are active, what words and what phrases you use, and your browser strings can provide clues.

A group within (IIRC) Lebanon was reportedly identified a while back because of an opsec error; one of the folks involved in the group used a "restricted" cellular phone to call his girlfriend, and that broke open the identities.

The German Ultra encryption system was targeted and was sometimes vulnerable due to opsec errors. Opening such as key reuse, or sending duplicate messages, can provide openings that allowed decryption.

This area is related to the classic "covert channels" discussions within information security; on the expected information leakage, and around how a "defender" wants to keep leakage at a minimum, and how an "attacker" is looking for clues and errors.

This is also a corollary to the classic difficulties with maintaining server security; leave one sufficiently egregious opening in your security, and you can be toast.

Re: LulzSec: 50 Days of Lulz statement

#88
post #25
post #21

Earlier quoted context omitted.

That's also what strikes me in this story. Anyone can explain this?

After thinking about it for a few moments, I would guess that they largely sell books and research papers and suchlike on subjects that are of interest to those in member militaries, but aren't of sufficient general interest to make it to Amazon or otherwise. EDIT : or, I could've spent a single moment to read the contents of the aforementioned link.

My question was badly phrased. I'm not that surprised that there are books/documents produced by NATO. I'm surprised they sell them. I think everything (public) produced by NATO should be freely accessible to everyone. This was so obvious to me that I'm surprised it's not the case, another little reminder of the world we live in.

Re: LulzSec: 50 Days of Lulz statement

#89
post #73

Earlier quoted context omitted.

Yup, you use a compromised Windows machine or Linux server in a third world country as a proxy. When you're done, you wipe the disk.

3rd world country only? You mean nothing else outside your own country works? tsk tsk.

Third world governments aren't exactly known for being cooperative with western governments. I'd rather have a rooted box in China or Pakistan than in North America or Europe.

Re: LulzSec: 50 Days of Lulz statement

#90
post #82

Earlier quoted context omitted.

You're assuming they're safe because their technology stack is safe, but there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Cops work like hackers in the sense that both groups attack vulnerabilities. The vulnerabilities here are clear: these guys have big mouths and they're overconfident. They'll talk to somebody someday, and when that happe…

> there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Would be interesting to hear some of them.

I just named one.
Post reply on HN