Live data from Hacker News

Heartbleed hack case sees first arrest in Canada

bbc.co.uk

11–20 of 37 posts

Re: Heartbleed hack case sees first arrest in Canada

#11
post #6

Direct link to the CRA response http://www.cra-arc.gc.ca/gncy/sttmnt2-eng.html "Regrettably, the CRA has been notified by the Government of Canada's lead security agencies of a malicious breach of taxpayer data that occurred over a six-hour period." That seems to be implying that another government agency (RCMP? CSEC?) monitors at least the CRA network and does some kind of deep packet inspection and/or packet loggin…

Depends on the timeline. IDS rules for detecting attacks aren't all that complicated. But getting those rules into place before attackers went crazy is a whole other thing. So either their network security people were on the ball or they were possibly recording traffic and ran a playback of the data against a detection ruleset.

Also, the US may be similar to Canada in this respect. I believe the Department of Homeland Security[0] handles a lot of the network security for much of the federal government.

[0] http://www.dhs.gov/network-security-deployment

Re: Heartbleed hack case sees first arrest in Canada

#12
post #7

Earlier quoted context omitted.

Did you read the article? He was arrested for stealing 900 social insurance numbers from CRA (Canada Revenue Agency, Canada's IRS).

While he obviously behaved rather irresponsibly, talking openly about a hack he did, the word steal is probably a bit strong. Odds are the insurance numbers are just some of the things that passed through while he performed the hack, or the first thing he saw when he got in. Not something he intentionally took for his own gain.

Intent should count, but if someone broke into a company's building at night, picked the lock to a manager's desk, and stole all the papers he could see and ran out...obviously a theft has occurred.

Even if he was not looking for anything in particular, or did not plan on using any of the information found in the papers, he's committed a felony.

In this case I don't think it's clear whether or not he went ahead to parse out the insurance numbers and save those separately, and if so if he planned to do anything further with those (like sell them).

Re: Heartbleed hack case sees first arrest in Canada

#13
post #7

Earlier quoted context omitted.

Did you read the article? He was arrested for stealing 900 social insurance numbers from CRA (Canada Revenue Agency, Canada's IRS).

While he obviously behaved rather irresponsibly, talking openly about a hack he did, the word steal is probably a bit strong. Odds are the insurance numbers are just some of the things that passed through while he performed the hack, or the first thing he saw when he got in. Not something he intentionally took for his own gain.

the article features 2 different things/people/places

insurance numbers + arrest = canada

mumsnet + posting warning = uk

Re: Heartbleed hack case sees first arrest in Canada

#14
post #7

Earlier quoted context omitted.

While he obviously behaved rather irresponsibly, talking openly about a hack he did, the word steal is probably a bit strong. Odds are the insurance numbers are just some of the things that passed through while he performed the hack, or the first thing he saw when he got in. Not something he intentionally took for his own gain.

Intent should count, but if someone broke into a company's building at night, picked the lock to a manager's desk, and stole all the papers he could see and ran out...obviously a theft has occurred. Even if he was not looking for anything in particular, or did not plan on using any of the information found in the papers, he's committed a felony. In this case I don't think it's clear whether or not he went ahead to pa…

Yeah uh, your analogy is terribly wrong and just serves to perpetuate life-destroying punishments for innocuous actions. It's more like a street-level window was left open, and this guy stuck his head in and saw a bunch of papers strewn out on a desk, all while wearing a commonly-worn head-mounted camera. Any seriousness of the situation is related to his ultimate intent, not the hacking itself.

Re: Heartbleed hack case sees first arrest in Canada

#15
>>"I hope the actions of hijacking Justine's account help draw attention to how big a deal this is," the hacker wrote on the social network. "I suspect a lot of people would not have taken it seriously otherwise. Be thankful that the person who got access to the server information was kind enough to let you all know (and at least try and be funny with it) instead of simply sitting on the information."

It's not clear to me that the hacker was malicious.

That said, governments are _not_ hacker-friendly like Google, Facebook, Twitter, etc. Never hack the government thinking you're doing them a favor, they will never see it that way. You will be arrested.

Re: Heartbleed hack case sees first arrest in Canada

#17
post #16

Googled his name and found his Github profile: https://github.com/Stephsolis He mentions a school assignment for "CS2212" which means he is likely a CS student at Western University in Canada.

Why not let him choose to publicize his defense or have a trial first?

Edit: parent comment was edited after I posted this.

Re: Heartbleed hack case sees first arrest in Canada

#18
post #15

>>"I hope the actions of hijacking Justine's account help draw attention to how big a deal this is," the hacker wrote on the social network. "I suspect a lot of people would not have taken it seriously otherwise. Be thankful that the person who got access to the server information was kind enough to let you all know (and at least try and be funny with it) instead of simply sitting on the information." It's not clear…

[deleted]

Re: Heartbleed hack case sees first arrest in Canada

#19

Sounds like someone forgot to use Tor.

Probably relying on the claim by some that it was completely undetectable unless you have full packet capture which for the CRA is pretty much a guarantee.

...or that sysadmins are used to script kids the day a glitch comes out. (Hopefully)

Re: Heartbleed hack case sees first arrest in Canada

#20
post #16

Googled his name and found his Github profile: https://github.com/Stephsolis He mentions a school assignment for "CS2212" which means he is likely a CS student at Western University in Canada.

Why not let him choose to publicize his defense or have a trial first? Edit: parent comment was edited after I posted this.

No part of my comment accused him of being guilty. His name is on every news site around the world.

I found the fact he is a CS student relevant to the news article. As is the fact he has a git repo where he coded a Java crypto library, when he's being accused of exploiting a crypto library.

Post reply on HN