Live data from Hacker News

Who Hacked Ashley Madison?

krebsonsecurity.com

131–140 of 308 posts

Re: Who Hacked Ashley Madison?

#131

Earlier quoted context omitted.

It exposes what is already human nature. Okay, it was a potential enabler... you have a fair point. But it having a large male populous turns out to be a popular gay hub. The people on this site were going to cheat anyway. I don't disagree with it being run by sleazy people with sleazy business practices. From everything I've read, I'd concur with this statement. An epidemic of cheating over the internet is no more a…

I find the prospect of people making promises to people that we can assume that they love and being unable to keep those promises to be terrifying. If I believed that we weren't able to control our behavior and we were overrun with animalistic desire, I would kill myself. The same ideology is used to justify violence, rape, etc., and if I did not believe that these problems could be addressed or improved upon, I pers…

That's your call. People break promises all the time. I find the prospect that you choose to believe peoples promises will uphold over time naive - that's my perspective and equally as valid to me as yours is to you.

People do things for many reasons you are not privvy to all the time and while they may seek comfort in the arms of someone outside their relationship, doesn't automatically justify violence and rape. I find this argument to be as laughable as those making arguments that same sex marriage is comparable to marrying animals.

If understanding and accepting human nature for what it is makes your life not worth living, then only you can evaluate that.

I choose to believe that people are inherently good. I choose to believe that while their interests align with my own, they're likely to make good on that promise. But I equally believe that accepting someone else's promise without question or qualification is naive at best. I cannot expect them to honour that promise when their interests are no longer aligned with mine.

Does that make my life not worth living? Of course not. I love people, I enjoy being around them. People are amazing, wonderful and fascinating creatures.

...but to expect that one person uphold a promise they had no hope of truly understanding when they made it, for the entire duration of the remainder of their life... and then holding them accountable for failing to keep it. That's beyond ridiculous, I don't care what religion you are.

Re: Who Hacked Ashley Madison?

#132

> They said Avid Life employees first learned about the breach on July 12 (seven days before my initial story) when they came into work, turned on their computers and saw a threatening message from the Impact Team accompanied by the anthem “Thunderstruck” by Australian rock band AC/DC playing in the background. This reads like a scene straight out of Hackers or some other campy tech movie. Life imitates art.

I heard a similar story from a Sony employee about the Sony hack. Was able to find it mentioned in a Vanity Fair article: >...this morning, as she began her day, she discovered that a bizarre specter had hijacked her computer. The screen glowed with a blood-red skeleton baring its fangs, and the words “Hacked By #GOP.” [0] http://www.vanityfair.com/hollywood/2015/02/sony-hacking-set...

Partial screenshot of the affected systems: http://arstechnica.com/security/2014/11/sony-pictures-hacker...

Re: Who Hacked Ashley Madison?

#133

> They said Avid Life employees first learned about the breach on July 12 (seven days before my initial story) when they came into work, turned on their computers and saw a threatening message from the Impact Team accompanied by the anthem “Thunderstruck” by Australian rock band AC/DC playing in the background. This reads like a scene straight out of Hackers or some other campy tech movie. Life imitates art.

This is actually something used by Stuxnet, believe it or not. http://www.theverge.com/2014/8/7/5977885/hackers-made-irans-...

Re: Who Hacked Ashley Madison?

#134
My reaction is still mostly schadenfreude.

If/when these people are caught, they should face the consequences of their actions but I'm not going to wrap paranoia over my own peccadillos in fake outrage over internet privacy.

I'm opposed to people doing unauthorized things with other people's property on general principles. I'm far more concerned with the IRS's data breach because every victim was legally compelled to submit certain personal information to the IRS. Everyone on Ashley Madison was there voluntarily for nefarious purposes.

Catch them and prosecute them but don't cry crocodile tears either.

Re: Who Hacked Ashley Madison?

#136
post #114
post #46

Earlier quoted context omitted.

Probably one should do something similar to this: echo "The Twitter handle Brian Krebs anonymized in this blog post is @user and this a random salt qF7KKAUxtrEtQbnj4LPkUZM4." | sha256sum

The inclusion of a salt only protects against precomputed hashes. It makes almost no difference to how many millions of hashes one can perform per second.

I think the idea is not to publicize the salt. The proof still works (after both user name and salt are publicly known), but a dictionary attack with all twitter handles won't work.

Re: Who Hacked Ashley Madison?

#137
post #59
post #31

Earlier quoted context omitted.

http://digg.com/2015/ashley-madison-hack Not a complete answer, but: "MOTHERBOARD: How did you hack Avid Life Media? Was it hard? The Impact Team: We worked hard to make fully undetectable attack, then got in and found nothing to bypass. MOTHERBOARD: What was their security like? The Impact Team: Bad. Nobody was watching. No security. Only thing was segmented network. You could use Pass1234 from the internet to VPN t…

Wow! It's easy to make jokes, but actually this is serious -- a lot of people are going to be hurt, and so far already two have died. Sounds like AM's computing was all f__ked up! In US Army terminology, FUBAR. Or SNAFU. Gads. Wonder how AM paid, maybe I should say, compensated , their server farm system administration staff? Their server farm security was wide open ? Should the users have expected something else?

1.) They could be lying.

2.) My read is that, instead of no security, (or else AM would be have been compromised instantly by script kiddies) they used manufacturer default passwords on internal firewall appliances.

Re: Who Hacked Ashley Madison?

#138
post #126
post #40

Earlier quoted context omitted.

The future is a future where no semblance of privacy exists. In the year 3000: "Truth about the ugliness of the human race will finally be revealed when every single detail about anyone's life is public knowledge available to all."

1998 is calling: http://www.davidbrin.com/transparentsociety.html Also, from 1999, "You have zero privacy anyway, ... Get over it." (Scott McNealy - http://archive.wired.com/politics/law/news/1999/01/17538 )

As a counterargument, I can strongly recommend reading Peter Watts' talk on The Scorched Earth Society:

http://www.rifters.com/real/shorts/TheScorchedEarthSociety-t...

(Sorry, PDF.) (Also, for the record, I agree with neither Watts nor Brin.)

Re: Who Hacked Ashley Madison?

#139
post #84

Earlier quoted context omitted.

One could argue privacy is a more natural right than, for example, property rights since strong encryption can give you absolute privacy, even against the state.

I think you and I have different ideas of what absolute means. Encryption protects infromation as long as A) the computation power, time and desire available to break your encryption does not exceed the level you encrypted, B) the underlying math principles on which the encryption was based do not see a change in some manner reducing the effectiveness of the algorithm for this task, or C) The implementation of the en…

While one could be wrong about the basics of physics and math, you can encrypt things, cheaply and quickly, that would take a computer made of all the matter and all the energy in the universe to break in more time than the universe has existed.

You have to take some care. But an NSA magic code breaking machine is in the same category as flying saucers at Area 51. Exceedingly unlikely.

That's about as good a guarantee as nature can offer.

Re: Who Hacked Ashley Madison?

#140
The AM hack is similar in tenor to the Sony hack. Nothing about the hack has the feel of a lone wolf or black hat operation. I have no doubt someone will get pinned for the hack, but I also think if it wasn't an inside job it was state-sponsored.
Post reply on HN