Live data from Hacker News

How to own an airline in 3 easy steps and grab the TSA nofly list along the way

maia.crimew.gay

31–40 of 677 posts

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#31
post #18

Earlier quoted context omitted.

No - please do not use "it" as a catch-all pronoun for an unknown person. "It" is generally a dehumanizing term for a transgender person - though a minority use it as a pronoun (in those cases, go for it).

I can't even remember people's names after they introduce themselves how am I meant to remember their pronouns as well.

Same way you learn nouns in German.

(Die/der/das are genders).

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#32
From the accompanying (and linked) Daily Dot article[1]:

> On the list were several notable figures, including the recently freed Russian arms dealer Viktor Bout, alongside over 16 potential aliases for him.

> [...]

> Numerous names included aliases that were common misspellings or slightly altered versions of their names.

For non-natively-Latin names, the US government is thorough to the point of hilarity in including every possible romanization and misspelling of one, and they list full names not their individual parts so combinatorics ahoy, as well. For example, if you know a bit of any Slavic language written in Cyrillic, browse the Russian sanction lists, it’s going to give you a chuckle.

In all seriousness, this actually makes perfect sense given the prospective consumers of the lists may not have any clue about the languages the targeted people speak. It’s just that the article makes 16 aliases sound vaguely sinister, whereas if you’re a Russian—or, for that matter, a Ukrainian or a Belarusian—that’s just a reasonably low estimate for how many romanizations of your name people may think up. (Not that Bout isn’t sinister as hell.)

[1] https://www.dailydot.com/debug/no-fly-list-us-tsa-unprotecte...

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#33
post #18

Earlier quoted context omitted.

I’m curious to learn: if “they” is being added to style guides as a way to refer to a singular human without implying any gender, is “it” the same or is there a somewhat different meaning behind the usage?

No - please do not use "it" as a catch-all pronoun for an unknown person. "It" is generally a dehumanizing term for a transgender person - though a minority use it as a pronoun (in those cases, go for it).

To quote her home page "hello i am maia arson crimew (it/she)"

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#34

This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.

Yeah cause we should totally have a top secret no fly list

Though I don’t like the idea of it, I’m also not certain that I know better than people whose careers are in national defence. I’m not convinced that it’s a black and white thing. There are bad actors out there, and sometimes it’s clearly advantageous to hide information from them, which means hiding it from everyone.

Maybe there are reasons this is short sighted or I’m missing a greater point. I’d be interested to hear ideas in any case.

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#35
post #22
post #9

Earlier quoted context omitted.

Am I missing something? It seems Maia didn't share the data at all, and only offers to if someone can demonstrate they will use it responsibly. Moreover, depending on the contents of the list, this likely offers proof of what is generally suspected, that the no fly list is a form of discrimination and authoritarian overreach, targeting people that haven't been convicted of a crime but are "suspected" due to race, rel…

>>demonstrate they will use it responsibly. The problem is to define "demonstrate" and the criteria. Remember the gatekeeper is now an unemployed gal who "know lot's of things about cyber security" according to her main page. Seems likely a competent bad actor could easily impersonate a well-meaning reporter... Yes, security through obscurity isn't security, but this also seems incredibly irresponsible for any "secur…

>>Remember the gatekeeper is now [...] unemployed [...] who "know lot's of things about cyber security" according to [its] main page. Seems likely a competent bad actor could easily impersonate a well-meaning reporter...

...and it has a Wikipedia article (https://en.wikipedia.org/wiki/maia_arson_crimew), and has demonstrated in other cases (cf. https://www.dailydot.com/debug/feelyou-mental-health-app-dat...) that it has at least a reasonable grasp on what to leak and what not to leak.

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#36

This is clearly on the darker side of gray-hat. Hate to be preachy but anyone seeking to emulate this sort of attack-finding should consider their ethical obligations as a computer scientist and follow best practices for responsible disclosure. It appears this was completely ignored here, including sharing stolen sensitive data of normal people with whoever can plead a case.

And incidentally some of it is entirely illegal but sense she is already facing extradition for a federal indictment - in for a penny, in for a pound.

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#37

Earlier quoted context omitted.

Maybe we should or shouldn't, but the potential victims of this aren't just some greedy corporation. Leaking the no fly list could cause irreparable harm to individuals whose names are on it or even similar, causing discrimination by employers and other organizations.

Top secret stazi lists should absolutely be shared. It's why we have 'we have right to know' laws, so the government can't just lock people up in a jail and disappear them.

If someone was on a no fly list and they wanted the general public to know, they could just put it out there themselves. No? This seems more likely to be used as a form of public shaming than a way to expose injustice.

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#38

Earlier quoted context omitted.

Maybe we should or shouldn't, but the potential victims of this aren't just some greedy corporation. Leaking the no fly list could cause irreparable harm to individuals whose names are on it or even similar, causing discrimination by employers and other organizations.

Top secret stazi lists should absolutely be shared. It's why we have 'we have right to know' laws, so the government can't just lock people up in a jail and disappear them.

I think you may not be reading the parent comment correctly. They're saying that those on the list have a right to privacy, therefore outright leaking the list is wrong. Being able to find out whether or not you are on the list is not incompatible with maintaining others' right to privacy.

Re: How to own an airline in 3 easy steps and grab the TSA nofly list along the way

#39

Earlier quoted context omitted.

maia[0] (it/she pronouns) is almost certainly aware of that this is illegal, and has been indicted by a grand jury for other government hacks. shodan[1] is a search engine that deals in hosts and ip addresses rather than web pages, and is a goldmine for finding everything from exposed ip webcams to jenkins instances. [0]: https://en.wikipedia.org/wiki/Maia_arson_crimew [1]: https://www.shodan.io/

US law is neither a universal law nor an international one. Accessing computer systems owned by a US company based in the US might constitute a violation of US law, but the hacker is based in Switzerland - where US law does not apply. As you can see in the linked Wikipedia article, accessing these systems is probably not illegal in Switzerland, thus, for all intents and purposes, no crime was committed.

Here's an indictment from 2019 for similar activities. It's a crime in the U.S., thus prosecutable in the U.S. The question is whether Swiss authorities cooperate, not the jurisdiction.

https://www.justice.gov/usao-wdwa/pr/swiss-hacker-indicted-c...

Post reply on HN