Live data from Hacker News

Hackers selling hacked police emails to request user data from TikTok, Facebook

404media.co

11–20 of 53 posts

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#11

Ok if these social media giants are authenticating LEOs by origin email only, without benefit of GPG, or secure token, or whatever, then they are stuck on stupid, and deserve any hacking they get. Ouch.

To many normal people the "from" field in an email means that it came from there. I am wondering how they get the data back though, unless they demand it is faxed, or sent to another email address. (Or the person replying doesn't notice the different reply-to address.)

If the email account has been hacked (which it has in this case) then it can just go back to the original hacked email.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#12
post #3

This is a great example of why E2EE is important even if you trust your government.

According to Meta Whatsapp is E2EE and Data requests by government agencies can only reveal metadata like recipients, durations of calls, frequency of messages, but not content of messages.

That's enough to tell you if a given request is being seriously discussed.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#13

Ok if these social media giants are authenticating LEOs by origin email only, without benefit of GPG, or secure token, or whatever, then they are stuck on stupid, and deserve any hacking they get. Ouch.

You'll be horrified to learn exactly how much business is conducted through unsecured fax machines.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#14

Ok if these social media giants are authenticating LEOs by origin email only, without benefit of GPG, or secure token, or whatever, then they are stuck on stupid, and deserve any hacking they get. Ouch.

Tech companies don't give a shit, it's the same reason why they're handing over data when just simply asked.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#15
post #3

This is a great example of why E2EE is important even if you trust your government.

According to Meta Whatsapp is E2EE and Data requests by government agencies can only reveal metadata like recipients, durations of calls, frequency of messages, but not content of messages.

> only

"We kill people based on metadata." - General Michael Hayden, former director NSA and CIA

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#16

Ok if these social media giants are authenticating LEOs by origin email only, without benefit of GPG, or secure token, or whatever, then they are stuck on stupid, and deserve any hacking they get. Ouch.

I don't think most law enforcement agencies have any second factor to authenticate themselves online. And it's not the social media companies that suffer but their users whose privacy is being violated.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#17
post #3

This is a great example of why E2EE is important even if you trust your government.

According to Meta Whatsapp is E2EE and Data requests by government agencies can only reveal metadata like recipients, durations of calls, frequency of messages, but not content of messages.

Meta data is often as valuable or even more valuable than the data itself.

Because you might be talking to the mob boss about the weather. But the fact that you are talking to the mob boss is an extremely interesting data point. It pins you to the map in a way that you are immediately a POI and causes a file to be opened on you and your other contacts to further map your place in the network. Who talks to who is very powerful information.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#18
post #3

Earlier quoted context omitted.

According to Meta Whatsapp is E2EE and Data requests by government agencies can only reveal metadata like recipients, durations of calls, frequency of messages, but not content of messages.

Meta data is often as valuable or even more valuable than the data itself. Because you might be talking to the mob boss about the weather. But the fact that you are talking to the mob boss is an extremely interesting data point. It pins you to the map in a way that you are immediately a POI and causes a file to be opened on you and your other contacts to further map your place in the network. Who talks to who is very…

[flagged]

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#19
post #3

This is a great example of why E2EE is important even if you trust your government.

According to Meta Whatsapp is E2EE and Data requests by government agencies can only reveal metadata like recipients, durations of calls, frequency of messages, but not content of messages.

"Hey Timmy I noticed you talk to Susan 5 times a day sometimes for 5 minutes and sometimes for 2 hours. Always right after you say goodnight to us. Sometimes I see you call her late at night from outside her house for 10 seconds when you were supposed to be in your room and then you don't use your phone again for a couple hours -- No no, im not invading your privacy, it's only metadata"

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#20

Ok if these social media giants are authenticating LEOs by origin email only, without benefit of GPG, or secure token, or whatever, then they are stuck on stupid, and deserve any hacking they get. Ouch.

Email actually has very well thought out authentication mechanisms such that its not unreasonable to expect a domain is not spoofed, and it came from the server it says it came from

but if some baddies have logged into your server and sending messages as you, then DKIM can't save you

so say social media companies want a higher standard of proof that emails are coming from a particular institution, what mechanisms are available that doesn't involve onboarding every individual officer to the subtleties of public key crpyotgraphy?

Post reply on HN