Earlier quoted context omitted.
he trawled through hundreds of profiles, twitter feeds, IRC conversations, and basically cyberstalked the hell out of every friend of every person he thought might be a "leader" of Anonymous...This is the stuff pedophiles and con-men do to get closer to their victims might do. That's also what private investigators and intelligence agents might do. By your logic, all private investigators using the same methods are p…
"If I were deliberately smearing AB, I'd try to concoct a reason to mention him as you do in posts also mentioning "pedophile" and "schizophrenic" as often as possible, only I'd use logic that wasn't such an indiscriminate stretch." Yeah, I would, too. But, I'm being sincere. This is creepy behavior from a guy who was not listening to reason from anyone around him. I don't think anyone needs to smear him...anyone who…
How one man tracked down Anonymous—and paid a heavy price
121–130 of 162 posts
Re: How one man tracked down Anonymous—and paid a heavy price
#122Earlier quoted context omitted.
> If their aim was the highest level of security Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong. Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else. If their source code was stolen, the…
I'm not sure what all this beating around the bush is about. They're calling themselves a "security firm" (at least that's how everyone refers to them) and they engage in cyber-warfare against anonymous. Having your mailserver compromised on that premise, during what was probably the first serious attack, disqualifies you from that game. And by the way, how do you know their source code was not stolen or backdoored?…
Random acts of stupidity by individual actors that should know better do not qualify as cyber-warfare.
> Having your mailserver compromised on that premise, during what was probably the first serious attack, disqualifies you from that game.
I sincerely doubt that was the first attack on their infrastructure and applications. We're routinely attacked by targeted threats and we're even smaller than HBGary.
> And by the way, how do you know their source code was not stolen or backdoored?
I don't, but I will be asking about it when I speak to them, as will everyone else they speak to. Hopefully they will segregate the code from the Internet.
> Excuse me? "Absolutely perfect security"? > This was not some minor breach into some peripheral webserver. 4.71GB of their E-Mail is on BitTorrent
And what's the value of the information assets stored in that e-mail? Is it 4.71Gb of subscription reminders for icanhazcheezburger? What proportion of that mail is actually sensitive and unencrypted, or decryptable within a timeframe where the sensitivity is still relevant?
This is the thing, it's easy to scream about volume, but the fact is that there's a lot of data to go through. We've already seen stuff leak out from it that realistically was not best placed to be sent around unencrypted, but the same would apply in any company that had their mail servers broken into, the mail stolen and then distributed across the Internet.
Re: How one man tracked down Anonymous—and paid a heavy price
#123Earlier quoted context omitted.
> If their aim was the highest level of security Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong. Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else. If their source code was stolen, the…
I'm not sure what all this beating around the bush is about. They're calling themselves a "security firm" (at least that's how everyone refers to them) and they engage in cyber-warfare against anonymous. Having your mailserver compromised on that premise, during what was probably the first serious attack, disqualifies you from that game. And by the way, how do you know their source code was not stolen or backdoored?…
Re: How one man tracked down Anonymous—and paid a heavy price
#124My read: The piece is based on Anonymous propaganda. Anonymous itself is actually an amorphous propaganda outfit. The primary purpose of their actions is to produce media. Anonymous achieves these ends in part by taking on opponents with good story value, but no consequential power. They also engage in actions against significant players, like credit card companies, but these actions are most effective in creating me…
They get to be anonymous by all assuming the same name, "Anonymous"; it's tricky to talk about them as a unified group because it's a group of groups, all with the same name. "This Anonymous" versus "that Anonymous" is hard to talk about. (It's a disclosed exploit in language.)
Re: How one man tracked down Anonymous—and paid a heavy price
#125Earlier quoted context omitted.
I'm not sure what all this beating around the bush is about. They're calling themselves a "security firm" (at least that's how everyone refers to them) and they engage in cyber-warfare against anonymous. Having your mailserver compromised on that premise, during what was probably the first serious attack, disqualifies you from that game. And by the way, how do you know their source code was not stolen or backdoored?…
> They're calling themselves a "security firm" (at least that's how everyone refers to them) and they engage in cyber-warfare against anonymous. Random acts of stupidity by individual actors that should know better do not qualify as cyber-warfare. > Having your mailserver compromised on that premise, during what was probably the first serious attack, disqualifies you from that game. I sincerely doubt that was the fir…
Random acts of stupidity by individual actors that should know better do not qualify as cyber-warfare.
A firm that can have their entire email database compromised by one individual's "Random acts of stupidity" doesn't have enough safeguards.
And what's the value of the information assets stored in that e-mail? Is it 4.71Gb of subscription reminders for icanhazcheezburger?
We know it's not that. Ask any random company what they think of having their email db out there as a torrent. No one is going to like that idea. It may not be the end of the world, but no one credible is going to say it's not a big deal. No one is going to say it's worth the money saved by not isolating your mail server.
This is the thing, it's easy to scream about volume
No one is screaming about volume. That wasn't even central to the point being made. You seem to be trying to pretend it is, though.
but the fact is that there's a lot of data to go through.
But then you turn around and invoke "security through too-much-stuff."
Re: How one man tracked down Anonymous—and paid a heavy price
#126Earlier quoted context omitted.
> Putting words in my mouth. No one said anything about perfect security. No, you mentioned the highest level which I took to read as perfect. If that's not what you meant then I'm sorry for reading too much into it. > And they did not do this Which I feel more inclined to agree with rather than claiming they failed because they didn't meet the highest level of security. However, a compromise doesn't necessarily mean…
> Putting words in my mouth. No one said anything about perfect security. No, you mentioned the highest level which I took to read as perfect. Given the opportunity, you choose a mediocre interpretation instead of the most intelligent one. (Actually, that's charitable. You ascribed an idea to me that everyone knows doesn't exist .) This results in a lower level of discussion. > I bet I could find a company that could…
The red flags as you call them are not the facts nor the means of the compromise alone, it's the data that is lost and whether or not HBGary Federal a) practiced what they preached and b) followed appropriate processes and policies to protect the information assets according to their sensitivity.
My hope is that on balance they did b fairly well and maybe some of a. My expectation is that they did some of a and probably not a lot of b, the results of which would be the red flag.
Again, I don't think that security companies should be held to higher standards than others as on balance we tend to hold less sensitive data than our customers (although that which we hold we should handle correctly). If this were an online pet shop people would talk about the attacks being quite advanced, laugh a little and move on. HBGary Federal aren't the first security firm to get hacked into and won't be the last.
Re: How one man tracked down Anonymous—and paid a heavy price
#127Earlier quoted context omitted.
> Putting words in my mouth. No one said anything about perfect security. No, you mentioned the highest level which I took to read as perfect. Given the opportunity, you choose a mediocre interpretation instead of the most intelligent one. (Actually, that's charitable. You ascribed an idea to me that everyone knows doesn't exist .) This results in a lower level of discussion. > I bet I could find a company that could…
I think we're talking across purposes here. I'm asserting that the fact that they were compromised isn't particularly bad. People get hit all the time. The fact that they were hit by an SQL injection bug is unfortunate and should've been picked up but these things happen all the time. I'd also say that while they're a security firm they should still be held to the same standards as everyone else, there's nothing inhe…
A word of advice: If a plumber gets a leak, it's no big deal. If a plumber's office gets massive but avoidable water damage through their short-sighted incompetence, don't hire them.
Re: How one man tracked down Anonymous—and paid a heavy price
#128Wow, this was almost like a cyber crime thriller! Anyone for writing a book on Anonymous ?
Re: How one man tracked down Anonymous—and paid a heavy price
#129I can't believe this guy has a job in a security company doing work for the federal government. I'm getting a strong vibe that he's schizophrenic. I've known an unmedicated schizophrenic, and this is the way they talked and acted. Self-aggrandizing, convinced they have comprehended great secrets based on little to no data (schizophrenics often believe that have "other ways of knowing" or extremely heightened intuitio…
I'm not sure that schizophrenia is any better an explanation than straightforward arrogance. Assuming that the leaks of his work are reasonably accurate I'd be concerned if the government actually started using his research to arrest people though. I'm not sure that Barrs interest in finding patterns in publicly available information in order to sell his intelligence is any different to advertising analysts doing the…
The CIA has shown interest in Facebook's database for a long time, because, besides the normal detective work a normal detective can do if he reads through a Facebook page, if you get a handful of real mathematicians working with that dataset, they can certainly rig something up that would at least return really interesting results.
Re: How one man tracked down Anonymous—and paid a heavy price
#130My read: The piece is based on Anonymous propaganda. Anonymous itself is actually an amorphous propaganda outfit. The primary purpose of their actions is to produce media. Anonymous achieves these ends in part by taking on opponents with good story value, but no consequential power. They also engage in actions against significant players, like credit card companies, but these actions are most effective in creating me…
Some of them are. The Guy Fawkes masks are sort of a good way of describing them: a bunch of completely unrelated people assuming the same identity for a time. Likewise, the "Anonymous" you hear of is usually the "Anonymous" that pulls this sort of stunt and then publicizes it. There are a number of people hanging out on /b/ doing nothing but humorous (depending on your sense of humor) image manipulation, also callin…
People have been doing something like that for thousands of years. That's never meant that everything done under that name was wholly aimless and spontaneous.