Live data from Hacker News

How one man tracked down Anonymous—and paid a heavy price

arstechnica.com

101–110 of 162 posts

Re: How one man tracked down Anonymous—and paid a heavy price

#101
post #87

Earlier quoted context omitted.

We don't know if the security of the mailserver was at stake here. A web app was compromised through SQL injection, then lateral movement was used to get to the mailserver (which may or may not have been on the same box). The rootkit.com mail server has nothing to do with HBGary AFAIK. To put it in perspective, HBGary's (not HBGary Federal) technology is a thing called Digital DNA that cuts down the amount of time it…

A web app was compromised through SQL injection, then lateral movement was used to get to the mailserver (which may or may not have been on the same box). If their aim was the highest level of security, then such lateral movement should not have been possible.

> If their aim was the highest level of security

Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong.

Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else.

If their source code was stolen, then yes you could say that the level of protection was inappropriate because if the source code is the highest value asset they have, it probably shouldn't be accessible from the Internet.

That an Internet-facing web app was broken into and an email server for receiving and sending email to and from the Internet means that they have to be connected to the Internet to work. If these systems contained information assets that were sufficiently sensitive to the point of considering post-compromise lateral movement then they probably shouldn't be connected to the Internet.

Re: How one man tracked down Anonymous—and paid a heavy price

#102
post #62
post #54

Earlier quoted context omitted.

Yes, grr... my bad :)

obvious symmetry to the Read-Eval-Print Loop.

The unifying concept is the half-life (exponential decay) of plans and information. The older your intel, the less valuable the plans you have built off of that information.

Top-down and waterfall approaches institutionalize this in order to provide an illusion of control to the executives and shareholders. Agile development and maneuver warfare each seek to tighten their feedback loops.

Re: How one man tracked down Anonymous—and paid a heavy price

#103
post #101

Earlier quoted context omitted.

A web app was compromised through SQL injection, then lateral movement was used to get to the mailserver (which may or may not have been on the same box). If their aim was the highest level of security, then such lateral movement should not have been possible.

> If their aim was the highest level of security Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong. Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else. If their source code was stolen, the…

Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong.

Putting words in my mouth. No one said anything about perfect security.

Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else.

And they did not do this.

That an Internet-facing web app was broken into and an email server for receiving and sending email to and from the Internet means that they have to be connected to the Internet to work.

Of course. It does not follow that breaking into the web server should compromise the mail server, or vice-versa. You're really losing me there. What you're saying is that they saved what was likely a small amount of money in exchange for a large amount of security. (All of the corporate emails.) I wouldn't want security work from a company as short sighted as that.

If these systems contained information assets that were sufficiently sensitive to the point of considering post-compromise lateral movement then they probably shouldn't be connected to the Internet.

I bet I could find a company that could set up an email server that couldn't be compromised just because the web server was compromised.

Re: How one man tracked down Anonymous—and paid a heavy price

#104
post #95

I can't believe this guy has a job in a security company doing work for the federal government. I'm getting a strong vibe that he's schizophrenic. I've known an unmedicated schizophrenic, and this is the way they talked and acted. Self-aggrandizing, convinced they have comprehended great secrets based on little to no data (schizophrenics often believe that have "other ways of knowing" or extremely heightened intuitio…

I am not a lawyer, but I'd like to address your legal points. Just as I don't need a warrant to view a publicly available website, he shouldn't either. What you are proposing is that it should be illegal to view public pages in a certain order or time. What is the difference of me viewing 100 of my new crushes friends pages over 2 days vs 2 years? There isn't, but the first is rifling, the second is innocent curiosit…

Wouldn't communicating an "untrue statement of fact" that certain people are leaders of an allegedly law-breaking group to government officials or other people constitute defamation (assuming that their reputations were harmed as a result)?

Re: How one man tracked down Anonymous—and paid a heavy price

#106

Isn't anonymous less an organized group with leaders and more a bunch of people who hang out and occasionally someone says "hey, it would be cool if we all did " and whoever is listening joins in?

Isn't anonymous less an organized group with leaders and more a bunch of people who hang out and occasionally someone says "hey, it would be cool if we all did " and whoever is listening joins in?

This idea is repeated so often, I suspect that there's a group of people somewhere that wants that particular message to be repeated and believed. If I were manipulating a group like Anonymous from behind the scenes, that's exactly what I'd want the net at large to think.

On the other hands, if Anonymous were really as decentralized as implied in this meme, I should think everyone would want the media to think there was a shadowy conspiracy inolved -- if nothing then just for the LULZ.

My best guess is that the truth is somewhere in the middle. Anonymous is somewhat decentralized, but there is also a core group (are core groups) that started a self-perpetuating process toward some end. This core group is a little worried that things are a little out of hand, so they are now covering their tracks using the same social-media manipulation techniques used to start Anonymous itself.

Re: How one man tracked down Anonymous—and paid a heavy price

#107
post #95

I can't believe this guy has a job in a security company doing work for the federal government. I'm getting a strong vibe that he's schizophrenic. I've known an unmedicated schizophrenic, and this is the way they talked and acted. Self-aggrandizing, convinced they have comprehended great secrets based on little to no data (schizophrenics often believe that have "other ways of knowing" or extremely heightened intuitio…

I am not a lawyer, but I'd like to address your legal points. Just as I don't need a warrant to view a publicly available website, he shouldn't either. What you are proposing is that it should be illegal to view public pages in a certain order or time. What is the difference of me viewing 100 of my new crushes friends pages over 2 days vs 2 years? There isn't, but the first is rifling, the second is innocent curiosit…

I agree with you up to a point.

And here's that point:

"Before the release of the data, and while this was going on, those on the list were unaware of what was occurring. Just as a reasonable person isn't threatened until they become aware of the stalking, threats, etc in real life."

People did become aware of it before the release, which is why the exploits of his servers happened, and why Anonymous got butthurt and went on a crusade.

He was dropping hints and threats in IRC, national media, and in email, that he was doing this stuff. He also "leaked" via his fake persona some of the kinds of information he was gathering to his victims so in order to drum up more publicity and to scare them into action. And, it now turns out, he planned to do a lot more than that.

I don't have a problem with him idly browsing facebook or twitter, though I have to question the mental stability of someone that spends all their time voluntarily reading and logging the incoherent ramblings of teenagers all day and trying to build a conspiracy out of it.

The legal issue is that he was threatening people with exposure, via major media outlets. When seeing this stuff, anyone who ever happened to drop in on the IRC channels had to think, "Crap. When is the FBI gonna show up to question me because I made a joke about Egypt on IRC?" You and I both know the government are wholly incompetent at dealing with issues on the Internet, and they try to make up for that incompetence by being extremely heavy-handed in execution of their misguided policies. I'd be scared as hell if I thought someone, apparently trusted by the government, was going to "reveal" my involvement in some wacky Internet conspiracy to the FBI.

Re: How one man tracked down Anonymous—and paid a heavy price

#108

I'm astounded at both the CEO's (Aaron's) lack of basic grammar skills, and predeliction for "script kiddie" talk. How do you get to be CEO of anything when you communicate (even informally) at the level of an 8th grader? (edit: I meant Aaron; Penny was decently well spoken)

I assumed that all those garbled messages were from typing on an iPhone. One particular error reeked of autocorrect. If you've seen the things people post on Damnyouautocorrect...

Still no excuse for not writing professionally and at least checking up on what you just typed.

Re: How one man tracked down Anonymous—and paid a heavy price

#109
post #101

Earlier quoted context omitted.

A web app was compromised through SQL injection, then lateral movement was used to get to the mailserver (which may or may not have been on the same box). If their aim was the highest level of security, then such lateral movement should not have been possible.

> If their aim was the highest level of security Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong. Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else. If their source code was stolen, the…

I'm not sure what all this beating around the bush is about.

They're calling themselves a "security firm" (at least that's how everyone refers to them) and they engage in cyber-warfare against anonymous.

Having your mailserver compromised on that premise, during what was probably the first serious attack, disqualifies you from that game.

And by the way, how do you know their source code was not stolen or backdoored?

There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong.

Excuse me? "Absolutely perfect security"?

This was not some minor breach into some peripheral webserver. 4.71GB of their E-Mail is on BitTorrent[1].

[1] http://thepiratebay.org/torrent/6156166/HBGary_leaked_emails

Re: How one man tracked down Anonymous—and paid a heavy price

#110

Isn't anonymous less an organized group with leaders and more a bunch of people who hang out and occasionally someone says "hey, it would be cool if we all did " and whoever is listening joins in?

At least one person on Barr's list as one of 'leaders' of Anonymous has responded: http://blogs.crikey.com.au/thestump/2011/02/07/i-confess-im-...

He could be using the Richard Feynman gambit.

"Feynman! Did you take the doors?"

"Oh, yeah!" I said. "I took the door.

Post reply on HN