Ugh. Not downloadable (unless you want to download each page individually by saving it as an image), and it keeps giving me one of those shaking "Congratulations! You have WON!" banners. Here's a site with these indictments as downloadable PDFs and without the annoying shaking ad: http://publicintelligence.net/lulzsec-indictments/
LulzSec indictment published
41–50 of 70 posts
Re: LulzSec indictment published
#42Ugh. Not downloadable (unless you want to download each page individually by saving it as an image), and it keeps giving me one of those shaking "Congratulations! You have WON!" banners. Here's a site with these indictments as downloadable PDFs and without the annoying shaking ad: http://publicintelligence.net/lulzsec-indictments/
no ads, change doc to fullscreen in the url: http://www.scribd.com/fullscreen/84156085/
Re: LulzSec indictment published
#43They didn't get him via TOR. If you start reading on page 26, it states that Jeremy hammond revealed personal info to the confidential witness (CW-1). It was this personal info he shared that was used to identify Hammond as the suspect.
Despite all that, their "correlation attack" was distinctly low-tech. They watched the traffic leaving his residence and confirmed with a confidential informant logged into the chat server that he was online. It just shows that despite all the paranoia of the crypto-nerd crowd, even the second most sophisticated government agency in the world (perhaps after the NSA), pursuing a high value target, still can't or doesn't want to perform those kinds of attacks (maybe because they aren't reliable enough to hold up in a court of law).
And the CCC was claiming that they could fingerprint encrypted connections with 40% reliability. That's so far from being an effective real-world attack by even the most sophisticated organizations, that you'd be wasting your time ever worrying about it.
Re: LulzSec indictment published
#44They didn't get him via TOR. If you start reading on page 26, it states that Jeremy hammond revealed personal info to the confidential witness (CW-1). It was this personal info he shared that was used to identify Hammond as the suspect.
It's interesting because the FBI was in a perfect position to perform the most well-known attack on Tor: a correlation / timing attack. "If your adversary can watch both ends of the connection, you lose." They could watch his end and probably knew where the chat server was located. If it was located in the US, it would have been pretty straightforward to send an agent / install a device at the data center and watch t…
Re: LulzSec indictment published
#45They didn't get him via TOR. If you start reading on page 26, it states that Jeremy hammond revealed personal info to the confidential witness (CW-1). It was this personal info he shared that was used to identify Hammond as the suspect.
It's interesting because the FBI was in a perfect position to perform the most well-known attack on Tor: a correlation / timing attack. "If your adversary can watch both ends of the connection, you lose." They could watch his end and probably knew where the chat server was located. If it was located in the US, it would have been pretty straightforward to send an agent / install a device at the data center and watch t…
I think Hollywood and perhaps even our own fascination with technology misleads us, blinding our eyes to what has been proven to be simple and effective time and time again.
Re: LulzSec indictment published
#46They didn't get him via TOR. If you start reading on page 26, it states that Jeremy hammond revealed personal info to the confidential witness (CW-1). It was this personal info he shared that was used to identify Hammond as the suspect.
It's interesting because the FBI was in a perfect position to perform the most well-known attack on Tor: a correlation / timing attack. "If your adversary can watch both ends of the connection, you lose." They could watch his end and probably knew where the chat server was located. If it was located in the US, it would have been pretty straightforward to send an agent / install a device at the data center and watch t…
Re: LulzSec indictment published
#47see page 31: "...An FBI TOR network expert analyzed the data from the Pen/Trap and was able to determine that a significant portion of the traffic from the CHICAGO RESIDENCE to the Internet was TOR-related traffic..." Guess they did not want to provide too much info on that - otherwise they would have had to acknowledge that they are actually screening all traffic with deep inspection.
The FBI has TOR network experts? Hmm. I wonder if they use it themselves?
Re: LulzSec indictment published
#48This was all detailed by Ars Technica a couple of days ago: http://arstechnica.com/tech-policy/news/2012/03/stakeout-how...
Compare the photo of him from Ars Technica to this one from 2007: http://www.chicagomag.com/Chicago-Magazine/July-2007/The-Hac... Reading through the indictment it becomes clear that he outed himself through many statements that narrowed down his identity. Not too smart.
Re: LulzSec indictment published
#49Earlier quoted context omitted.
The FBI has TOR network experts? Hmm. I wonder if they use it themselves?
What's so surprising in that? FBI can probably hire an expert in any existing technology. I'm sure they have very smart people working for them, and if they need they can always use outside consultants. I'd be pretty surprised and disappointed if they didn't have some experts with knowledge in everything that pertains to internet security, cracking, etc. There's a whole industry about that, for years now, so why not?
Re: LulzSec indictment published
#50Earlier quoted context omitted.
If you're monitoring the encrypted wireless traffic of a wifi router without busting the encryption, then what good are IP addresses? Do you even see IP addresses if the traffic is encrypted. Wouldn't you just see MAC addresses? And even if you did "see" IP addresses, wouldn't you just see the wireless client and the router's IP addresses?
correct, you would not see IP header, if you were snooping encrypted wireless traffic. But thats not really what was described.. They describe a "wireless router monitoring device"...however I don't think think they mean "wireless router", but wireless "router". My guess, this is a physical 'wired' device, attached to, or installed in a router, that transmits data to nearby monitoring (FBI)agent 'wirelessly'. This is…