Live data from Hacker News

RaidForums gets raided, alleged admin arrested

krebsonsecurity.com

151–160 of 197 posts

Re: RaidForums gets raided, alleged admin arrested

#152
post #150

Earlier quoted context omitted.

This is pure speculation but if I were the Feds, I'd let insecure, incompetently run forums to keep operating and shut down any secure, tightly run forums. The insecure forum can simply be hacked and basically become honeypots.

That’s freenet in a nutshell

Freenet is technically safe. It doesn't allow JavaScript, unlike onion sites.

Re: RaidForums gets raided, alleged admin arrested

#153

What are the legal implications of having registered on this forum once with a personal email account but not having ever engaged in any transaction or downloading any leaked data, just lurking a few threads of nothing interesting at most. Asking for a friend, of course...

Your name will end up on a list. Such lists can be queried by those that are properly connected, typically LE/three (and in some countries four) letter agencies if your name ever turns up in some other context and then it might be given some weight, but other than that I wouldn't expect anything to come of it assuming that you are telling the truth. Such inter-service requests for information on particular individual…

Unless you have some reason to be there, eg negotiating with someone who hacked your service.

Re: RaidForums gets raided, alleged admin arrested

#154

Earlier quoted context omitted.

With all digital interactions recorded forever, it only takes a single idle mistake.

True. I always feel like the people who are involved in these illegal forums would have better OpsSec. The fact the feds got all of his electronic devices and within a few hours had plenty of damning information is always kind of shocking to me. I guess that's the difference between the real criminals who never get caught and others who get greedy or too lazy in covering their tracks.

Proper OpSec is a pain in the ass and requires constant vigilance as being correct 99% of the time is not good enough.

If I got a magic gift of $10 million in crypto but I had to start doing proper OpSec to hide everything on my devices and digital life, that would be a huge downgrade in my quality of life; it's not worth it.

Re: RaidForums gets raided, alleged admin arrested

#155
This forum kinda reminds me of HackForums[1], but the owner of that forum co-operates with law enforcement and makes good money while staying above board on things. At one point, he even directed members interested in certain blackhat activities (carding, mainly) to a site that later ended up to be an FBI setup.

[1] https://hackforums.net/

[2] https://krebsonsecurity.com/2012/06/carderprofit-forum-sting...

Re: RaidForums gets raided, alleged admin arrested

#156
post #102

Am just curious how hackforums is still around?

I swear Hackforums is an FBI honeypot for especially stupid criminals. Nothing happens there (remember back in the day someone was talking about stealing from a gamestop and a bunch of people called the store to warn them lol), and anyways anyone who does anything remotely illegal immediately gets arrested.

It is and at one point the owner even redirected people interested in more illegal things to a site that ended up being an FBI sting lol.

https://hackforums.net/printthread.php?tid=5656430

Re: RaidForums gets raided, alleged admin arrested

#157
Stories like this make me wonder how well full disk encryption really holds up. Maybe LUKS is good, but I don't have 100% confidence that FileVault or BitWarden aren't backdoored. Of course in the UK, refusing to give the password is a crime, so some jurisdictions have you either way.

Also, in this day of the internet, why would you need to travel with your laptop if you store the compromising data on a secure server, and then download it on a fresh computer when you get where you are going.

Re: RaidForums gets raided, alleged admin arrested

#158
post #3

Earlier quoted context omitted.

Not to mention the following paragraph: >“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums…

I don’t exactly disagree with this point, but in mitigation, being constantly vigilant must be exhausting, and even bright people with strong executive function are going to slip up once in a while. It’s just too hard to keep your guard up 100% or the time. Most deceptions, even comically absurd ones like “dude who has two families in different cities” do not require perfect vigilance, whereas running a cybercrime fo…

Yeah, "never slipping up" is a high bar. But there's slipping up once, and then there's continuing to commit crimes using an account for at least two years after you've personally told the US federal government that it belongs to you.

Re: RaidForums gets raided, alleged admin arrested

#159
post #68

Earlier quoted context omitted.

dude, opsec is really really hard, the slightest mistake and it's over.

It's only that hard if the person in question is dumb enough to be using a pseudonym instead of opting for anonymity, since having a name opens up your attack surface and chance to fail. Hosting a site or some kind of infrastructure that you have to actively interface with also counts towards this.

opsec is really really really hard. because you don't get used to it as time goes by, you get tired of it. you will discover that sooner or later
Post reply on HN