How are we getting past the NYT PayWall now?
Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
11–20 of 52 posts
Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
#12If we assume that Ms. Thompson is generally terrible at opsec, then presumably she is also terrible at offensive security, which leads to one of two conclusions: Either: A: She is being framed. or B: Capital One's security was (and probably still is) laughable. She doesn't seem to be being framed. If Capital One's security is horrendous, they are unlikely to be exceptional... so we will see much more of this.
Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
#13If we assume that Ms. Thompson is generally terrible at opsec, then presumably she is also terrible at offensive security, which leads to one of two conclusions: Either: A: She is being framed. or B: Capital One's security was (and probably still is) laughable. She doesn't seem to be being framed. If Capital One's security is horrendous, they are unlikely to be exceptional... so we will see much more of this.
Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
#14If we assume that Ms. Thompson is generally terrible at opsec, then presumably she is also terrible at offensive security, which leads to one of two conclusions: Either: A: She is being framed. or B: Capital One's security was (and probably still is) laughable. She doesn't seem to be being framed. If Capital One's security is horrendous, they are unlikely to be exceptional... so we will see much more of this.
One can possess great technical skills and still be a braggart. Nothing about a lack of OPSEC implies she cannot exploit a vulnerable system.
Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
#15> An April 19, 2019, post in the Github account of "paige•••••thompson" includes a "Server List" of IP addresses associated with the account.
What Github "post" could this be referring to? A README.md/issue/comment in which she for some reason posted the IP addresses she uses with that account?
https://www.justice.gov/usao-wdwa/press-release/file/1188626...
Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
#16How are we getting past the NYT PayWall now?
I would encourage people — if they can afford it — to pay for a few media sites online.
Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
#17Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
#18How are we getting past the NYT PayWall now?
Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
#19Then I realized after seeing what has happened as the masses all came online, while many of us here can probably distinguish between a reliable news source and a hack site or a propaganda outlet—a disturbingly large segment of the population can not.
And to make matters worse, there seems to be a huge number of people who don’t realize they don’t have what it takes to do reliable research to write a story and they don’t have what it takes to understand nuanced subjects in order to explain the subject to readers. Or even worse, they fully realize how ill-equipped they are but don’t care because vulnerable people will still click their ads.
Long story short, I now have just short of 20 subscriptions. Including a few that I rarely read but to me it’s worth it. The collective We really need to increase the signal levels in order to hear over the noise.
Journalism is definitely one of those cases where The Market can easily lead to a race to the bottom situation. Hopefully we’ll see it correct and good journalism will overtake trash, but wow what a rough spot.
Re: Paige Thompson, Capital One Hacking Suspect, Left a Trail Online
#20I was confused by this line in the affidavit (page 9): > An April 19, 2019, post in the Github account of "paige•••••thompson" includes a "Server List" of IP addresses associated with the account. What Github "post" could this be referring to? A README.md/issue/comment in which she for some reason posted the IP addresses she uses with that account? https://www.justice.gov/usao-wdwa/press-release/file/1188626...