Live data from Hacker News

LulzSec brought down by own leader

foxnews.com

71–80 of 139 posts

Re: LulzSec brought down by own leader

#72

Earlier quoted context omitted.

Groups allow information trading. It is basically essential if you want to cash for your hacking activities, such as carding and 0-day selling. I am not totally familiar with "the scene", but I'm pretty sure there are plenty of incentives for hackers to regroup

Grouping to trade 0-days is totally different than grouping to DDOS a website. I'm pretty sure the former won't end you up in jail, either. But, I think the OP is right. The only successful (for lack of a better word) black hat is going to be a loner.

The most successful ones work for the feds while squirreling away the proceeds. The feds don't mind cultivating crime if it's increasing their numbers.

Re: LulzSec brought down by own leader

#73
post #18

We are still in the stage of these groups being very amateurish. It will take few rounds of purges until really committed+careful+smart organizations emerge.

How do you know they haven't already? Committed+careful+smart probably wouldn't issue press releases.

Sure they would, they'd just be smarter about it. The point of hacktivism is publicity. If no one knows what you're doing, you're not being particularly effective.

Re: LulzSec brought down by own leader

#74

Earlier quoted context omitted.

Groups allow information trading. It is basically essential if you want to cash for your hacking activities, such as carding and 0-day selling. I am not totally familiar with "the scene", but I'm pretty sure there are plenty of incentives for hackers to regroup

Grouping to trade 0-days is totally different than grouping to DDOS a website. I'm pretty sure the former won't end you up in jail, either. But, I think the OP is right. The only successful (for lack of a better word) black hat is going to be a loner.

Actually, criminal copyright infringement is a $250k fine, 5 year felony, in the US. Pretty amazing. You are vastly more likely to be prosecuted criminally if you're part of a group, and especially if you focus on 0-days. Even more likely if you sell things, charge for advertising on your site, etc.

The DrinkOrDie people got a lot of 3-5 year sentences. http://en.wikipedia.org/wiki/Operation_Buccaneer

Re: LulzSec brought down by own leader

#75
As a former blackhat and ID thief who used to spend a lot of time in "underground" chatrooms and forums this doesn't surprise me at all. This is a standard pattern LE follows. Start with small arrests, work your way up, get someone at the top level to be an informant, take everyone down. Works for any type of group.

This always works because people are foolish and too trusting. The best rule is to assume everyone is LE trying to catch you. That means never revealing info that can lead back to you, never telling anyone personal info, your general location (eg the weather), always using 7 proxies, etc.

People who don't break the law would probably be surprised how much personal info crackers give to their online "friends". Less so on fraud forums but it still happens.

As some other people mentioned read "Kingpin: How One Hacker Took Over the Billion-Dollar Cybercrime Underground" for more info on how LE works. The FBI took over a few carding forums and Secret Service also had high level CIs.

Re: LulzSec brought down by own leader

#76
post #60
post #37

Earlier quoted context omitted.

Costs in hacking cases are mostly measured by time spent investigating & repairing * fully loaded employee costs. If you have to dump a bunch of servers and reload everything and audit your backups the costs rise very quickly.

Plus, takeout for the guys working the case.

The cost in donuts alone would be staggering.

Re: LulzSec brought down by own leader

#77

This article claims billions of dollars in damage. If this is what the FBI is saying, they are wrong. Lulzsec damages don't even approach a million dollars, most likely. Billions of dollars is how much money it costs to do things like provide universal health care for a small state. The FBI should investigate real cases and not treat a bunch of merry pranksters like they're a bunch of super terrorists.

But terrorists are hard to catch, and you have to find them in dirty, unfriendly places.

These guys are relatively easy pickings, and the work is more fun because it's urban.

Ambitious federal agents and prosecutors are much more enticed by the latter.

Re: LulzSec brought down by own leader

#78
post #37

Earlier quoted context omitted.

Costs in hacking cases are mostly measured by time spent investigating & repairing * fully loaded employee costs. If you have to dump a bunch of servers and reload everything and audit your backups the costs rise very quickly.

True, but companies on the receiving end often end up also including the cost of things that they would need to do even in a responsible-disclosure scenario. For example, if you discover a major flaw in a company's system that allows high levels of access, and disclose it to them, they'll typically incur considerable costs patching it, rolling out the updates, doing a security audit to make sure it wasn't already qui…

You're absolutely correct - there are a lot of things that get rolled into damage cost estimates that aren't legitimate. I was just trying to explain how it's pretty easy for the actual & legitimate costs to be quite high as well.

Re: LulzSec brought down by own leader

#80
post #74

Earlier quoted context omitted.

Grouping to trade 0-days is totally different than grouping to DDOS a website. I'm pretty sure the former won't end you up in jail, either. But, I think the OP is right. The only successful (for lack of a better word) black hat is going to be a loner.

Actually, criminal copyright infringement is a $250k fine, 5 year felony, in the US. Pretty amazing. You are vastly more likely to be prosecuted criminally if you're part of a group, and especially if you focus on 0-days. Even more likely if you sell things, charge for advertising on your site, etc. The DrinkOrDie people got a lot of 3-5 year sentences. http://en.wikipedia.org/wiki/Operation_Buccaneer

Parent posts are probably talking about 0-day exploits rather than 0-day warez.
Post reply on HN