Live data from Hacker News

The 'untouchable hacker god' behind Finland's biggest crime

theguardian.com

161–170 of 183 posts

Re: The 'untouchable hacker god' behind Finland's biggest crime

#161
post #55

Earlier quoted context omitted.

But this is not “absolutely everything”. No one is saying CEOs should be accountable for every action of an individual employee. So if not the CEO, who is accountable when something like this breach happens? The CTO? The PM The DBA? Nobody? Maybe they’ll care developer who wrote the code or botched the configuration should be prosecuted? CEOs can justify their pay be being accountable for what their company does. The…

When a bridge fails, it is the professional engineer that signed off on that part. If you want someone to sign off on software or IT you will need to pay them quite a lot.

In my experience civil engineers get paid less than software developers of equivalent experience or responsibility.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#162
post #156

This is why you should not go to a therapist who uses electronic records. This will happen to you at some point.

Or: this is why you strictly regulate the storage of confidential/private/sensitive information. There were multiple failures here, but a single step could've prevented the entire hack: industry-standard encryption of the sensitive information.

If someone can access it remotely, a sophisticated bad actor can too.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#163

This is why you should not go to a therapist who uses electronic records. This will happen to you at some point.

i guess you should never use banks that use “electronics” either, right? just cash and paper records?

Your bank transactions reveal a lot less than your inner thoughts that you told someone in confidence.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#164
post #33

Do we really only catch the laziest hackers? The opsec is shocking.

>The opsec is shocking If you choose to blindly believe what the prosecution claims, sure.

This is worse than the SBF denial, do better, post a full on substack about how they didn't link you to a bitcoin address.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#165
post #99
post #21

Earlier quoted context omitted.

Thank you for providing an example that is exactly showing how messed up this is: > Der Vorsitzende Richter gab zu Protokoll, dass alleine die Tatsache, dass die Software ein Passwort für die Verbindung gesetzt habe, bedeute, dass ein Blick in die Rohdaten des Programms und eine anschließende Datenbankverbindung zu Modern Solution den Straftatbestand des Hackerparagrafen erfülle > The Judge gave to protocol that just…

Germany is the most contradicdory country I know of, and such a huge warning flag to anywhere else. For decades, half of children's education has been spent on hammering in "Never Again". Surely there are two huge lessons to learn there: 1. Do not judge the value of people based on their biological characteristics they were born with 2. "I was just following orders" is not an excuse, and one needs to instead do what…

> The rules are interpretable as it being illegal to access data with a publically available password using this password, so we're going to apply them, despite it being patently absurd.

I very much agree. I do think that this kind of ethical hacking should have a legal framework around it, to protect both sides during such an access. But this should be more on the basis of responsibly minimizing access to protected data as well as minimizing foreseeable damage.

For example - running a select on a database may show you private and protected data, but if this is done to validate a problem, fine. Start digging for data on specific persons? Touch something called "Pump Controls"? This would however require technologically competent judges, and those are rare.

As I said, a frustrating topic and it will become very interesting if a hostile state starts pushing on this.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#166

Earlier quoted context omitted.

Exactly, was it a burglary when your front door is open, lights on, spotlights on your wall safe, with the keys still inserted? The CEO should be in prison.

>Exactly, was it a burglary when your front door is open Legally speaking, yes in every place I've ever lived if all those things are the case it's still a burglary, although the cops may call the victim an idiot.

Also the insurance company doesn't pay out if they can prove you did not lock the doors.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#167

Earlier quoted context omitted.

Harsh punishment doesn't change anything. Criminals are just stupid, mentally ill or in the most sad cases kids. In my country they actually do put away people for life and yet we still have crime.

Some criminals are neither stupid nor mentally ill. I suspect this man is neither although he could be a psychopath.

Being a psychopath is a mental illness. And yes everyone who is a criminal is stupid- career criminals all spend years of their lives in jail and many of them get shot.

I will never forget that story about a big drug dealer who retired and was assassinated in Thailand by a few kids on a motorped.

Re: The 'untouchable hacker god' behind Finland's biggest crime

#168

Knowing the timeline of events and the nicknames attributed to him (ryanlol included), some interesting posts can be found. For example, in the period between the CEO starting communication (September 2020) and the clinic's public admission (October 2020) [1], ryanlol replied to a top comment (Oct 3, 2020): "If you’re a hospital or, say, a school district, 'never pay' is simply an unconscionable attitude" [2]. Isn't…

[dead]

Re: The 'untouchable hacker god' behind Finland's biggest crime

#169
post #33

Earlier quoted context omitted.

>The opsec is shocking If you choose to blindly believe what the prosecution claims, sure.

This is worse than the SBF denial, do better, post a full on substack about how they didn't link you to a bitcoin address.

A LLM chatbot trained to deliver and debate the denials might be more on trend?

Re: The 'untouchable hacker god' behind Finland's biggest crime

#170
post #154
post #95

Earlier quoted context omitted.

No, that did not actually happen.

What did happen, then?

Someone else leaked a copy of a shared throwaway VM used for hacks. Akin to https://www.thc.org/segfault/, but longer lived and potentially tens of people with access.

The leaked home folder data doesn't really tie that VM to anyone, which is natural given that it seems to have mostly been used to run headless hacking tools and inspect their output.

The idea that I'm linked to this VM comes from the ridiculous idea that lazy hackers would not share SSH key files in order to control access to groups of virtual machines. I.e. if a SSH key fingerprint is at one point tied to me, that key must also still belong to me even when used from a internet connection belonging to another person in another country with a similar track record as me.

In court we had long debates about whether or not hackers could actually be so lazy as to violate best practices by sharing private key material, the lower court rejected such an idea as incredible and found me guilty.

Post reply on HN