Live data from Hacker News

How one man tracked down Anonymous—and paid a heavy price

arstechnica.com

131–140 of 162 posts

Re: How one man tracked down Anonymous—and paid a heavy price

#131
post #95

Earlier quoted context omitted.

I am not a lawyer, but I'd like to address your legal points. Just as I don't need a warrant to view a publicly available website, he shouldn't either. What you are proposing is that it should be illegal to view public pages in a certain order or time. What is the difference of me viewing 100 of my new crushes friends pages over 2 days vs 2 years? There isn't, but the first is rifling, the second is innocent curiosit…

Wouldn't communicating an "untrue statement of fact" that certain people are leaders of an allegedly law-breaking group to government officials or other people constitute defamation (assuming that their reputations were harmed as a result)?

Defamation and libel are civil offenses, meaning (in my lay understanding) a person can be held financially liable if sued but cannot be imprisoned or otherwise restricted except as far as he can be constrained to pay the judgment filed against him.

Re: How one man tracked down Anonymous—and paid a heavy price

#132
post #66

Earlier quoted context omitted.

HBGary's proposed plan of attack against Wikileaks http://www.thetechherald.com/article.php/201106/6798/Data-in...

Here's the actual document, rather than a summary: http://wikileaks.ch/IMG/pdf/WikiLeaks_Response_v6.pdf

It appears that document outlines a conspiracy to commit Federal computer crimes.

Re: How one man tracked down Anonymous—and paid a heavy price

#133

Earlier quoted context omitted.

"If I were deliberately smearing AB, I'd try to concoct a reason to mention him as you do in posts also mentioning "pedophile" and "schizophrenic" as often as possible, only I'd use logic that wasn't such an indiscriminate stretch." Yeah, I would, too. But, I'm being sincere. This is creepy behavior from a guy who was not listening to reason from anyone around him. I don't think anyone needs to smear him...anyone who…

Now you bring in the East German secret police. Masterstroke!

You think I would go for Nazis? I'm no Philistine.

Re: How one man tracked down Anonymous—and paid a heavy price

#134
post #87
post #82

Earlier quoted context omitted.

HBGary is a good company with some insanely great technology Insane would be to trust security-related products or advice from a company that can't even secure its own mailserver.

We don't know if the security of the mailserver was at stake here. A web app was compromised through SQL injection, then lateral movement was used to get to the mailserver (which may or may not have been on the same box). The rootkit.com mail server has nothing to do with HBGary AFAIK. To put it in perspective, HBGary's (not HBGary Federal) technology is a thing called Digital DNA that cuts down the amount of time it…

> To put it in perspective, HBGary's (not HBGary Federal) technology is a thing called Digital DNA that cuts down the amount of time it takes to analyse memory fragments. That's their focus.

naive question here. Why don't they market themselves as a memory analysis or debug toolsmiths or something else, instead of security firm?

Re: How one man tracked down Anonymous—and paid a heavy price

#135
post #134
post #87

Earlier quoted context omitted.

We don't know if the security of the mailserver was at stake here. A web app was compromised through SQL injection, then lateral movement was used to get to the mailserver (which may or may not have been on the same box). The rootkit.com mail server has nothing to do with HBGary AFAIK. To put it in perspective, HBGary's (not HBGary Federal) technology is a thing called Digital DNA that cuts down the amount of time it…

> To put it in perspective, HBGary's (not HBGary Federal) technology is a thing called Digital DNA that cuts down the amount of time it takes to analyse memory fragments. That's their focus. naive question here. Why don't they market themselves as a memory analysis or debug toolsmiths or something else, instead of security firm?

Mainly because the DDNA looks for indicators of potentially malicious activity, but I have used one of the tools before on exploit dev for a demo.

Re: How one man tracked down Anonymous—and paid a heavy price

#136
post #88

FTA, from one of Barr's e-mails: "... accept during hightened points of activity..." Did this drive anyone else bonkers ? I think "accept" or "hightened" alone wouldn't have bugged me. But for some reason the juxtaposition of the two in this sentence made me nerdrage.

"except" -> "accept" could be explained by autocorrect or speech recognition but "hightened" suggests the use of neither.

Re: How one man tracked down Anonymous—and paid a heavy price

#137
post #84

I've yet to see anyone address the behavior of anonymous, and it appears as though it's been justified by most because this dude was an asshole - but why not point a finger at them both?

Well, there's no story to really address there. Barr was dangerously ignorant and naive. He had a complete misconception of how these things were organized and how they worked while claiming to know all of the identities of "the leaders" by correlating Twitter posts with what someone in IRC was talking about.

If you get on the news and say, "Hello Criminal Group. We have a bunch of information on your leaders that will get them arrested, we are meeting with the FBI next week", it is only reasonable to expect some attempted retaliation. I think that no one is surprised that the targeted group compromised HBGary's servers -- there are, after all, much worse things that could happen -- except maybe the HBGary people themselves, who, as we see here, were already in way over their heads.

No one addresses the behavior of Anonymous because it is completely and totally the expected reaction. The shocking thing about the story is Barr's personality and behavior, not the idea that someone will retaliate if you threaten to decapitate their organization.

Re: How one man tracked down Anonymous—and paid a heavy price

#138
post #25

A message from HBGary Federal: http://www.hbgary.com/

https://twitter.com/#!/anonymousirc/status/35578771021111296 Apparently the S/MIME signatures match just fine ... it is possible they got ahold of their private keys as well to sign messages, but that would be more difficult than hacking the central servers as private keys are stored locally on the clients machine.

Not necessarily. You can copy private keys to different machines just as easily as you can copy anything else. Since it's important not to lose private keys, it's plausible that lazy and/or ignorant persons would copy them to central servers for easy retrieval. It's much more hassle to burn to a CD and put them in a safe deposit box at the bank, after all.

Re: How one man tracked down Anonymous—and paid a heavy price

#139

I can't believe this guy has a job in a security company doing work for the federal government. I'm getting a strong vibe that he's schizophrenic. I've known an unmedicated schizophrenic, and this is the way they talked and acted. Self-aggrandizing, convinced they have comprehended great secrets based on little to no data (schizophrenics often believe that have "other ways of knowing" or extremely heightened intuitio…

> The coder in this story is an hero Oh man, I'm not sure if this is funnier if you meant it, or not... > in a just world, this nutjob would end up in prison. Yup. I'm interested to see what happens in the weeks ahead. I really doubt that anything bad (other than getting his SSN posted to Twitter...) will actually happen to him, though.

Subtlety is a art.

Re: How one man tracked down Anonymous—and paid a heavy price

#140
post #117

Earlier quoted context omitted.

Which nobody has stated was there aim. There's a big misconception that somehow security firms should strive to have absolutely perfect security, which is completely wrong. Putting words in my mouth. No one said anything about perfect security. Security firms should aim for the most appropriate level of security to protect their information assets based on a reasonable approach. As should everyone else. And they did…

> Putting words in my mouth. No one said anything about perfect security. No, you mentioned the highest level which I took to read as perfect. If that's not what you meant then I'm sorry for reading too much into it. > And they did not do this Which I feel more inclined to agree with rather than claiming they failed because they didn't meet the highest level of security. However, a compromise doesn't necessarily mean…

[deleted]
Post reply on HN