Live data from Hacker News

RaidForums gets raided, alleged admin arrested

krebsonsecurity.com

181–190 of 197 posts

Re: RaidForums gets raided, alleged admin arrested

#181
post #145
post #3

Earlier quoted context omitted.

Not to mention the following paragraph: >“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums…

having the ability to get an infosec job isnt = intelligence. tbh most of the people ive met in the last 5 years who were working corprate infosec / cyber are not particularly skilled or creative just good at filling out reports doing the greyface suit thing.

Absolutely. I'm definitely not saying ability to get an infosec job implies intelligence. But what do you think is implied when someone (with a clean record) is unable to even get jobs like the ones you describe?

Re: RaidForums gets raided, alleged admin arrested

#182

Earlier quoted context omitted.

You're absolutely right that there is a lot of survivorship bias here. But I think even when controlling for that, my hypothesis is still likely true.

I’m not sure it would still be true. Your hypothesis that smart people can still make good money without unnecessarily doing illegal things sounds logical, but people with high risk tolerance sometimes do things simply _because_ they’re high risk. The book “The Mastermind” was about a guy who operated a nearly legal business that broke open the telemedicine industry, only to use the proceeds to fund wet works, piracy…

(From a comment I wrote below)

>Legitimite employment might not give them the needed liberty to do what they see fit.

That's true; that's why I tried to qualify it with "generally". There certainly are some very intelligent, skilled people who are capable of finding legitimate employment and instead choose to immerse themselves in the criminal underworld, for various personal reasons. In practice, though, I've found them to be pretty rare.

Even among the ones who do have a desire for ultimate liberty and who see themselves as above the law, most feel like the risks greatly outweigh the rewards. Some temporary liberty in exchange for likely many years of zero liberty in a prison cell isn't a great deal. Especially when it's so easy for them to get a comfortable, high-paying legitimate job. (Admittedly, this trade-off may differ in places outside the US, where good jobs may be scarce and criminal activity may pay very well and almost always go unpunished. Assuming one has no ethical compunction, at least. Or feels certain illegal actions are ethically justifiable, like how many hacktivists feel.)

I'll also add as a note that another potential explanation could be a criminal record. Someone may have all the necessary skills and experience, but may not be able to get one due to past criminal convictions.

Re: RaidForums gets raided, alleged admin arrested

#183

Earlier quoted context omitted.

> Trading in hacked data might not be illegal unless it’s credit card information Dangerous nonsense. Trafficking in stolen data is illegal, please read the full indictment.

But it really isn’t… The indictment mostly sticks to payment information for a reason. And besides, indictments are not law.

They focus on payment information as those are the most serious crimes and would provide the harshest sentence. Trading hacked emails does not carry the same weight as trading hacked credit card details.

Re: RaidForums gets raided, alleged admin arrested

#184
post #183

Earlier quoted context omitted.

But it really isn’t… The indictment mostly sticks to payment information for a reason. And besides, indictments are not law.

They focus on payment information as those are the most serious crimes and would provide the harshest sentence. Trading hacked emails does not carry the same weight as trading hacked credit card details.

What weight does trading hacked emails carry?

As far as I can tell, lawmakers simply have not criminalized this.

Many things that obviously should be illegal are not illegal.

Re: RaidForums gets raided, alleged admin arrested

#185
post #159

Earlier quoted context omitted.

It's only that hard if the person in question is dumb enough to be using a pseudonym instead of opting for anonymity, since having a name opens up your attack surface and chance to fail. Hosting a site or some kind of infrastructure that you have to actively interface with also counts towards this.

opsec is really really really hard. because you don't get used to it as time goes by, you get tired of it. you will discover that sooner or later

The point of my comment was that, if [actor] is not using any pseudonym but is instead nameless, then there is almost no active way to pursue that actor, aside from its adversary running malware on every machine in the world and scanning the disk/memory for relevant data- and even then, the machine can be encrypted/wiped and airgapped. An action can be taken and then once completed, as long as it was properly anonymized on a technical level (easier) and social level (harder) against a given adversary, there is no more heat.

The actor never needs to interface with anything related to their activity ever again in any way, and can only screw themselves if they deliberately tell people what they did. And even if a nameless actor does 1000 things and gets caught for only 1, because they had no name/common set of characteristics, those 1000 things cannot be tied together. They're just caught for the one thing.

So opsec is hard... if you have a big huge ego or want to maintain some kind of central infrastructure.

Re: RaidForums gets raided, alleged admin arrested

#186

Earlier quoted context omitted.

We had one running for president just a couple years back. Sadly, I don't like him much, nor do many from his home state. But it's kind of cool that he went from hacker to political candidate.

Isn't he running for governor there now? People might like him better if he didn't keep making 180-degree changes to his stance on major constitutional questions. Whichever side of that issue you find yourself on, it's disturbing how easily he could his tune.

My initial reaction to that is just that he likely was too green and not groomed enough. We expect normal people to not know everything already and be willing to change their stance on something when new information comes to light (even if it's just new to them). When that happens to someone in power, we're upset because how could they not already have thought deeply about all the specific aspects anyone could bring up about that topic, as well as the 20,000 other things that might be asked of them randomly.

And the only thing that's worse for them than changing their mind is when they admit they haven't come to a decision on that yet, which is just admitting up front that they don't know as much as they should and are fallible.

It's not just that we don't expect politicians to by truthful, we disincentivize and sometimes outright punish any natural and truthful behavior that we would expect in a normal person, and force them into the mold we so like to criticize.

Re: RaidForums gets raided, alleged admin arrested

#187
post #166

Earlier quoted context omitted.

I think this is one of those "knowing what you don't know" problems. Most 21 year old kids will not know enough about opsec to understand that they don't know shit about opsec. If you know a little bit you might think "if I just do X, Y, and Z I'll be safe". I suspect once you learn a bit more about the area you will quite quickly decide that it's not actually possible to get away with this kind of thing once the cop…

Proving the truth of the old adage again: it's luck not skill if you're getting out of an impossible situation - the skill is to never get into such a situation to begin with. Applying that to this scenario: evading/postponing arrest after the cops started to look into you is luck, never giving them reason to look for/into you is what could be considered skill. Or even more specific: it became luck as soon as it beca…

Playing 33 bits against a nationstate is pretty dumb.

Re: RaidForums gets raided, alleged admin arrested

#188
post #183

Earlier quoted context omitted.

They focus on payment information as those are the most serious crimes and would provide the harshest sentence. Trading hacked emails does not carry the same weight as trading hacked credit card details.

What weight does trading hacked emails carry? As far as I can tell, lawmakers simply have not criminalized this. Many things that obviously should be illegal are not illegal.

What do you think 'access device' means in this context?

Re: RaidForums gets raided, alleged admin arrested

#189
post #96

Earlier quoted context omitted.

Some context for those that do not know. I believe some time ago raidforums.com was transferred from NameCheap to Cloudflare registrar (pre-seizure) and it was under data redaction with an address in the territory of Cyprus in Whois data. Some sort of attempt at P.O box or shell company voodoo is my guess. With Cloudflare registrar I would not be surprised if they were a cooperating party in this case.

https://www.namecheap.com/legal/general/court-order-and-subp... https://www.cloudflare.com/media/pdf/transparency-report.pdf - and https://developers.cloudflare.com/registrar/why-choose-cloud... indicates Cloudflare retains "the registrant email on file for that domain." WHOIS redaction is extremely useful for shielding personal information from non-governmental entities! But US government entities have full access t…

Why is everyone expected to put in real data into your who is domain data?

Last time I bought a domain, I did "1,lol,NYC, Dubai,90210" and other nonsense in the four fields.

Is it a compulsion to use real data and then rely on registrars promise to not disclose it?

Re: RaidForums gets raided, alleged admin arrested

#190

Earlier quoted context omitted.

Isn't he running for governor there now? People might like him better if he didn't keep making 180-degree changes to his stance on major constitutional questions. Whichever side of that issue you find yourself on, it's disturbing how easily he could his tune.

My initial reaction to that is just that he likely was too green and not groomed enough. We expect normal people to not know everything already and be willing to change their stance on something when new information comes to light (even if it's just new to them). When that happens to someone in power, we're upset because how could they not already have thought deeply about all the specific aspects anyone could bring…

I think that goes to the matter of leadership. Politicans aren't normal people. They're supposed to be the best people, who surround themselves with the other kinda-best people. We expect them to be better than us. We want them to be better than us. We want elites. And then we ask them to not make us feel bad about it by pretending to be the same as the rest of us. But it's pretend. It's a game we play. At the end of the day, elites are supposed to act like elites, and that means knowing what they're talking about, and making us feel like someone competent is at the wheel and everything is going to be okay.
Post reply on HN