Live data from Hacker News

NSA.gov Site Defacement

praetorianprefect.com

11–16 of 16 posts

Re: NSA.gov Site Defacement

#11
post #7

Earlier quoted context omitted.

1 or 2 months later an offer of employment (to a Canadian!) arrived at his doorstep. This is a standard way to catch people who do this type of stuff. Once he sets foot on American soil, he would be arrested. You actually have to be pretty dense to fall for it. ~99% of employment at the CIA requires some form of security clearance, which in turn requires you to be a US citizen.

While I see the point, I'm not sure I believe you that easily. Not all clearance forms require you to be a citizen (besides there must be some way to cooperate with companies from other countries). Why are you sure he would get arrested? Has there been a documented case of something like that happening before? Isn't the offer of employment an official document that's legally forcing to hire someone if they accept? (n…

Here's a case of Valve coordinating with the FBI, attempting to do what I described: http://gadgets.boingboing.net/2008/11/13/the-job-is-a-lie-va.... As for why extradition is not used, the lure is far quicker and much cheaper. The hacker you mention is a perfect example. "The order to extradite McKinnon was approved by the U.K. government in July 2006, but his legal team continued to challenge the order, holding up his transfer." [1] That's over three years ago. That's just when the approval went through mind you. He was indicted in the US in 2002.

Also, I'm fairly certain you are incorrect about security clearances (at least for Confidential, Secret, and Top Secret). Even dual citizens have to shred their extra passport and renounce their additional citizenship. The FBI website mentions that for Top Secret, citizenship is verified through investigation: "For a Top Secret security clearance, the background investigation includes additional record checks which can verify citizenship...." [2] If you're working at an intelligence agency like the CIA, Top Secret is pretty much required.

[1] http://www.pcworld.com/article/173397/uks_high_court_rejects...

[2] http://www.fbi.gov/clearance/securityclearance.htm

Re: NSA.gov Site Defacement

#12
post #5
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

Do you know how he encrypted his email?

I'm guessing here, but it was probably something like: "The attached encrypted word doc exposes an IT security flaw of one of your systems. It is weakly encrypted and should be easy for you to break."

Or he could have just emailed them the document and called them to tell them the password.

Re: NSA.gov Site Defacement

#13
post #6
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

Did he accept the offer of employment?

No, he was at university at the time and wanted to earn big money in the banking system. He has since graduated and is working for a financial firm.

Re: NSA.gov Site Defacement

#14
post #8
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

> encrypted email This tells us nothing of whether the NSA is good at finding people on the internet, however. Was the email anonymous? Did he use a proxy?

He was open about who he was. He sent the email from an easily identifiable email account.

Re: NSA.gov Site Defacement

#15
post #7
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

1 or 2 months later an offer of employment (to a Canadian!) arrived at his doorstep. This is a standard way to catch people who do this type of stuff. Once he sets foot on American soil, he would be arrested. You actually have to be pretty dense to fall for it. ~99% of employment at the CIA requires some form of security clearance, which in turn requires you to be a US citizen.

That is extremely interesting! I don't think they have him on any terrorism list though. He traveled to New York recently without any fuss.

Re: NSA.gov Site Defacement

#16
post #7
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

1 or 2 months later an offer of employment (to a Canadian!) arrived at his doorstep. This is a standard way to catch people who do this type of stuff. Once he sets foot on American soil, he would be arrested. You actually have to be pretty dense to fall for it. ~99% of employment at the CIA requires some form of security clearance, which in turn requires you to be a US citizen.

I would tend to believe that some significant portion of CIA tasks would require (or at least largely benefit from) some form of security clearance elsewhere in the world, which in turn would require (or at least largely benefit from) the said cleared person being a national from the country in question.

Otherwise I believe you are right in most cases. One would have to be rather naive to simply accept such an offer blindly.

Post reply on HN