Live data from Hacker News

RaidForums gets raided, alleged admin arrested

krebsonsecurity.com

191–197 of 197 posts

Re: RaidForums gets raided, alleged admin arrested

#191
post #150

Earlier quoted context omitted.

That’s freenet in a nutshell

Freenet is technically safe. It doesn't allow JavaScript, unlike onion sites.

Freenet is very much not safe. Accessing any kind of dissident/illegal content is a quick way to get a visit from the FBI/FSB party van.

Re: RaidForums gets raided, alleged admin arrested

#192
post #183

Earlier quoted context omitted.

They focus on payment information as those are the most serious crimes and would provide the harshest sentence. Trading hacked emails does not carry the same weight as trading hacked credit card details.

What weight does trading hacked emails carry? As far as I can tell, lawmakers simply have not criminalized this. Many things that obviously should be illegal are not illegal.

If trading hacked emails wasn't illegal, you'd have legitimate and big businesses trading them. You don't see any businesses like that because it is infact illegal.

As someone else mentioned, an 'access device' actually refers to many things, including emails. You have an extremely poor understanding of the law if you even remotely think that trading hacked emails would somehow be legal.

Re: RaidForums gets raided, alleged admin arrested

#193
post #96

Earlier quoted context omitted.

https://www.namecheap.com/legal/general/court-order-and-subp... https://www.cloudflare.com/media/pdf/transparency-report.pdf - and https://developers.cloudflare.com/registrar/why-choose-cloud... indicates Cloudflare retains "the registrant email on file for that domain." WHOIS redaction is extremely useful for shielding personal information from non-governmental entities! But US government entities have full access t…

Why is everyone expected to put in real data into your who is domain data? Last time I bought a domain, I did "1,lol,NYC, Dubai,90210" and other nonsense in the four fields. Is it a compulsion to use real data and then rely on registrars promise to not disclose it?

It's required for legal purposes. If legal notices are served on the domain, the registrars need to know where to send them. Using fake details are fine until you need to prove ownership for some reason or a legal notice is given.

Easy way to get a domain seized is to have it not be responding to legal notices.

Re: RaidForums gets raided, alleged admin arrested

#194
post #2

"Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent." Not really the sharpest knife in the drawer, to do things like th…

> Coelho landed on the radar of U.S. authorities in June 2018, when he tried to enter the United States at the Hartsfield-Jackson International Airport in Atlanta. The government obtained a warrant to search the electronic devices Coelho had in his luggage and found text messages, files and emails showing he was the RaidForums administrator Omnipotent I called complete, total and utter bullshit. That's a parallel con…

I mean, yes, obviously. They don't just get a search warrant for no reason.

Re: RaidForums gets raided, alleged admin arrested

#195
post #191

Earlier quoted context omitted.

Freenet is technically safe. It doesn't allow JavaScript, unlike onion sites.

Freenet is very much not safe. Accessing any kind of dissident/illegal content is a quick way to get a visit from the FBI/FSB party van.

Do you have any proof of that?

Re: RaidForums gets raided, alleged admin arrested

#196
post #193

Earlier quoted context omitted.

Why is everyone expected to put in real data into your who is domain data? Last time I bought a domain, I did "1,lol,NYC, Dubai,90210" and other nonsense in the four fields. Is it a compulsion to use real data and then rely on registrars promise to not disclose it?

It's required for legal purposes. If legal notices are served on the domain, the registrars need to know where to send them. Using fake details are fine until you need to prove ownership for some reason or a legal notice is given. Easy way to get a domain seized is to have it not be responding to legal notices.

in the case of raidforums, was the admin going to respond to legal notices? probably not because what they were doing was not legal anyways so why bother.

>Easy way to get a domain seized is to have it not be responding to legal notices.

for such a website, seizure is ultimately going to happen regardless of response so why put themselves at more risk?

Re: RaidForums gets raided, alleged admin arrested

#197
post #192

Earlier quoted context omitted.

What weight does trading hacked emails carry? As far as I can tell, lawmakers simply have not criminalized this. Many things that obviously should be illegal are not illegal.

If trading hacked emails wasn't illegal, you'd have legitimate and big businesses trading them. You don't see any businesses like that because it is infact illegal. As someone else mentioned, an 'access device' actually refers to many things, including emails. You have an extremely poor understanding of the law if you even remotely think that trading hacked emails would somehow be legal.

> If trading hacked emails wasn't illegal, you'd have legitimate and big businesses trading them.

But there are in fact big infosec businesses trading them. They just brand it as “data leak monitoring” or “darknet intelligence” or whatever. Equifax does this, NortonLifeLock does this as do many others. There are also products aimed specifically for pentesters.

> As someone else mentioned, an 'access device' actually refers to many things, including emails

>”Access device" is defined at 18 U.S.C. § 1029(e)(1). Instead of using the term "credit card," or "debit/credit instrument," the term "access device" is used in the statute and is defined broadly as any "card, plate, code, account number, electronic serial number, mobile identification number, personal identification number, or other telecommunications service, equipment, or instrument identifier, or other means of account access that can be used, alone or in conjunction with another access device, to obtain money, goods, services, or any other thing of value, or that can be used to initiate a transfer of funds...." The only limitation, i.e., "other than a transfer originated solely by paper instrument," excludes activities such as passing forged checks.

Post reply on HN