Live data from Hacker News

LulzSec brought down by own leader

foxnews.com

61–70 of 139 posts

Re: LulzSec brought down by own leader

#61
post #18

We are still in the stage of these groups being very amateurish. It will take few rounds of purges until really committed+careful+smart organizations emerge.

How do you know they haven't already? Committed+careful+smart probably wouldn't issue press releases.

For a group, that would take lots of discipline. Not impossible, but not very likely. Even Feds, Chinese and Israeli "teams" suffer unwanted leaks --and these are trained people. People who go thru psychological profiling, shaping, and get reminded by the bureaucracy probably on a frequent basis.

It's hard for me to imagine a loose-knit group being able to pull this disciple off long-term.

Re: LulzSec brought down by own leader

#62

I reckon a huge proportion of blackhats in the scene are working for the feds. Some kid with no record gets thrown in a van by men with guns, and the full force of police psychological manipulation is brought to bear on them. They get told they're irrevocably destined for a lifetime of being brutally raped in the showers. Is it any surprise that these young men with no experience of foul-play or maliciousness outside…

Groups allow information trading. It is basically essential if you want to cash for your hacking activities, such as carding and 0-day selling. I am not totally familiar with "the scene", but I'm pretty sure there are plenty of incentives for hackers to regroup

Grouping to trade 0-days is totally different than grouping to DDOS a website. I'm pretty sure the former won't end you up in jail, either.

But, I think the OP is right. The only successful (for lack of a better word) black hat is going to be a loner.

Re: LulzSec brought down by own leader

#63
post #7

Oh Fox News. Even when reporting on something legitimately interesting and out of the ordinary, they have to use very un-journalistic phrases like "...allegedly commanded a loosely organized, international team of perhaps thousands of hackers ..." "Perhaps thousands"? Perhaps millions! Perhaps five. Ugh.

They use lots of confusingly contradictory language to puff up the arrest, like: "the head of LulzSec" then immediately following with "the loose network of hackers", and contrasting "loosely organised" with Sabu being at the "nerve centre", and also "perhaps thousands of hackers" whereas they claim to know they're arresting "top-ranking members".

So simultaneously acknowledging they taking out a member of a distributed network but also talking up the importance of that member. Strange.

Re: LulzSec brought down by own leader

#64
post #3

I wonder what will happen to Sabu after this?

Probably lots of phone calls, some random unsolicited pizza appearing on his doorstep, and all kinds of slander on every chan board ever made. Oh, you mean IRL? Dunno. You'd think they'd have cut him a deal for helping them out.

They will have cut a deal with him already, however that deal usually means reduced jail time in an easy prison, he still has to be charged with the offences. His "good behaviour" is then taken into account by the prosecuting authorities when sentencing him.

They arrest him and publicise his arrest as psyops, any other hackers out there see that the #1 from lulzsec was caught and turned therefore who knows how many lower level hackers have also been turned, thus it increase the paranoia within hacker circles.

Of course this works 2 ways, first off it scares people off from hacking or being involved in it and makes them more likelyo to turn tail and rat out anyone they know who is undertaking nefarious online activity in an effort to protect themselves. The second response is the one they dont like, these groups become more security concious, go deeper underground, become less likely to admit new members, etc. This is counter productinve for the FBi as it makes it more difficult to catch them later down the line.

Re: LulzSec brought down by own leader

#65
post #33
post #28

Earlier quoted context omitted.

Of course you can't kill an idea. Wait, what was the idea again?

The 21st century equivalent of setting a poop-filled bag on fire on someone's porch, or something along those lines. But without actually requiring anything so taxing as getting up from the computer, going outside, and running.

Although I would agree their politics and aims were pretty scattershot and unfocused - that's a little unfair don't you think?

Re: LulzSec brought down by own leader

#66
post #61

Earlier quoted context omitted.

How do you know they haven't already? Committed+careful+smart probably wouldn't issue press releases.

For a group, that would take lots of discipline. Not impossible, but not very likely. Even Feds, Chinese and Israeli "teams" suffer unwanted leaks --and these are trained people. People who go thru psychological profiling, shaping, and get reminded by the bureaucracy probably on a frequent basis. It's hard for me to imagine a loose-knit group being able to pull this disciple off long-term.

Sure, but people are aware of the US, Chinese and Israeli teams, and they actively try to sabotage them, often with some pretty fantastic resources.

Nobody's stolen my social security number (knock on wood), but Todd Davis has had his identity stolen over a dozen times.

Re: LulzSec brought down by own leader

#67
post #58
post #16

Earlier quoted context omitted.

[deleted]

The difference w/ terrorism is that it intentionally targets civilians. It is always odious. The ends do not justify the means. Note: there is a lot of grey in the world, but intentionally targeting the innocent is black & white.

Careful here, civillian is not the same as innocent. For simple obvious cases of this: technically NSA, FBI and CIA people are civillians, as are government contractor employed security forces... It gets fuzzy pretty quickly.

There is also the question of who's version of innocent you use, for example if my moral/ethic system says X is a terrible offense and your system says X is just OK, which is most applicable to the classification of innocent? (for a simple concrete instance of this, look at the global variations of views on homosexuality, ranging from "it's nothing we should care about societally" to "we should care and embrace" to "it is a death penalty offense" -- not making any statements here on the debate, that is tangential to this). The situation needs to be looked at with an eye towards intent as well as just questions of innocence.

Re: LulzSec brought down by own leader

#69

I reckon a huge proportion of blackhats in the scene are working for the feds. Some kid with no record gets thrown in a van by men with guns, and the full force of police psychological manipulation is brought to bear on them. They get told they're irrevocably destined for a lifetime of being brutally raped in the showers. Is it any surprise that these young men with no experience of foul-play or maliciousness outside…

I also think that a lot of black hats are working for the feds. But I think it has more to do with their lack of integrity and morals rather than threats and intimidation.

Legal advice is a big part of black hat literature, so I don't think any of them can claim ignorance.

Re: LulzSec brought down by own leader

#70
post #37

This article claims billions of dollars in damage. If this is what the FBI is saying, they are wrong. Lulzsec damages don't even approach a million dollars, most likely. Billions of dollars is how much money it costs to do things like provide universal health care for a small state. The FBI should investigate real cases and not treat a bunch of merry pranksters like they're a bunch of super terrorists.

Costs in hacking cases are mostly measured by time spent investigating & repairing * fully loaded employee costs. If you have to dump a bunch of servers and reload everything and audit your backups the costs rise very quickly.

True, but companies on the receiving end often end up also including the cost of things that they would need to do even in a responsible-disclosure scenario. For example, if you discover a major flaw in a company's system that allows high levels of access, and disclose it to them, they'll typically incur considerable costs patching it, rolling out the updates, doing a security audit to make sure it wasn't already quietly discovered earlier by a blackhat who might've backdoored something, etc.

When they do all those same things upon an actual intrusion, they often attribute the expenses to the hacker, but imo they're really attributable to the security flaw, since they'd be incurred even in the whitehat case. I'd only attribute to the hacker the delta between what blackhat disclosure and whitehat disclosure would cost.

Post reply on HN