Live data from Hacker News

Who Hacked Ashley Madison?

krebsonsecurity.com

31–40 of 308 posts

Re: Who Hacked Ashley Madison?

#31
post #28

Can we also ask, HOW did they hack Ashley Madison?

http://digg.com/2015/ashley-madison-hack

Not a complete answer, but:

"MOTHERBOARD: How did you hack Avid Life Media? Was it hard?

The Impact Team: We worked hard to make fully undetectable attack, then got in and found nothing to bypass.

MOTHERBOARD: What was their security like?

The Impact Team: Bad. Nobody was watching. No security. Only thing was segmented network. You could use Pass1234 from the internet to VPN to root on all servers."

Re: Who Hacked Ashley Madison?

#32
post #19
post #15

So Krebs has no conclusive proof for anything? As he himself admits: > It is possible that Zu is instead a white hat security researcher or confidential informant Jeez, how about talking to the police and let them do their job, or at the very least censor the name. This is just a witch hunt.

Why do they need to censor an alias account for someone connected to the hack? There is no "Zu", the photos of Zu and his locations are copied from the internet.

For the same reason I don't go around and post an article how "watty" did $x. It doesn't matter if this is a pseudonym and what kind of avatar you use.

If watty might be implicated in something illegal I should go talk to the police and not publicly witch hunt your handle, no?

Re: Who Hacked Ashley Madison?

#34
post #2

I don't condone this hack, but morals/ethics aside for a moment: The one positive thing this hack has done is really give serious ammo to the battle for online privacy, because the demographic hit by this hack is the most politically & economically powerful demographic in the world....

I'd argue the opposite. The AM hack hasn't helped at all, since enough people view it as a just retribution due to it being about a pet moral value that is held dear, namely marital fidelity. And to others, it's all a big joke. The cheating cheaters (who likely never got the opportunity to cheat) have been named and shamed, and because of those asserting that it's acceptable to do this if it strokes their personal mo…

Yeah, well if you engage in a promise with someone that you're going to be in a monogamous relationship -- let's be real, that's what marriage is for the vast majority -- you're a prick if you attempt to break that commitment, and again, that's what being on AM is about.

Pretending otherwise is delusional, and having morals isn't a bad thing.

Is doxxing always unethical?

Re: Who Hacked Ashley Madison?

#35
post #26
post #2

I don't condone this hack, but morals/ethics aside for a moment: The one positive thing this hack has done is really give serious ammo to the battle for online privacy, because the demographic hit by this hack is the most politically & economically powerful demographic in the world....

What I find weirdest about the whole thing is the data wasn't sold back to Ashley Madison. The hacker(s) could have leaked 10 or 20 juicy names then probably cleared $10 million dollars or better. It would have been a bargain to Ashley Madison at that price.

The problem with digital data is that it can be replicated at no cost and with no trace, so there wouldn't be any way for Ashley Madison to ever be sure the leak was contained. They could pay $10MM for a copy of the data... and two months later it can anonymously show up on Tor. Not to mention the hackers would need to come forward to collect the $10MM, which might land them in a jail cell before they can collect.

Re: Who Hacked Ashley Madison?

#36

Earlier quoted context omitted.

This is going to have some long-lasting repercussions on the industry. I fully expect there to be a push in the legislature to require PCI-like compliance from anyone who takes "sensitive data". That would have very serious effects for the startup community.

I wish the push was more of a law that let users delete their data immediately and completely from a service with the click of a button.

Any architecture that facilitates this will lose massive amounts of customer data, full stop. Backups have to be in places where live systems can't touch them, or can append only. Backups have to be offline and immutable. If you can mutate a backup based on a user request, it's not a backup.

Offline backups are, however, pretty hard to steal (unless you're stealing the physical tapes).

So... immediately, maybe. Completely, no fucking way.

Re: Who Hacked Ashley Madison?

#37
post #2

I don't condone this hack, but morals/ethics aside for a moment: The one positive thing this hack has done is really give serious ammo to the battle for online privacy, because the demographic hit by this hack is the most politically & economically powerful demographic in the world....

I hadn't considered that, but it's an interesting point. That said, all the standard moralizing accompanying this is so gross.

What would you prefer, some amorphous undefinable moral relativism where everyone is somehow a good person, and we're all the same? Public shaming is a pretty decent prosocial incentive.

Re: Who Hacked Ashley Madison?

#38
post #27

Earlier quoted context omitted.

unclear if its a witch hunt or if Krebs wants to be on record with his reasoning in order to secure some of that $500K bounty if it turns out to be this guy? I've never figured out how they actually decide who gets what if they have to split that up.

He could have not posted the twitter handle but a hash instead? echo "The Twitter handle Brian Krebs anonymized in this blog post is..." | sha256sum There you go, you can prove it to anyone at any point in time.

Not familiar with Twitter, but if you can easily get all or most handles through their API or scraping then wouldn't it be easy to brute-force reverse the hash?

Edit: Maybe add a private salt?

Edit again: Oh, missed that "The Twitter handle Brian Krebs..." is effectively the private salt, nevermind.

Re: Who Hacked Ashley Madison?

#39
post #15

So Krebs has no conclusive proof for anything? As he himself admits: > It is possible that Zu is instead a white hat security researcher or confidential informant Jeez, how about talking to the police and let them do their job, or at the very least censor the name. This is just a witch hunt.

unclear if its a witch hunt or if Krebs wants to be on record with his reasoning in order to secure some of that $500K bounty if it turns out to be this guy? I've never figured out how they actually decide who gets what if they have to split that up.

I'm pretty sure Krebs is in the game for the publicity, not the reward money. The publicity and "staying relevant" as a security researcher has a lot more value than a nebulous reward that likely will never pay out.

Based on the typical wording when reward money is offered, I strongly suspect almost no reward money is ever paid out. It typically requires arrest and prosecution (often conviction) and there are plenty of opportunities for the lawyers to say "sorry, your tip did not qualify" even if someone is arrested and prosecuted.

I did not find a direct offer, but Wired has a quote[1] (most sources don't even provide a quote!):

“Today I can confirm that Avid Life Media is offering a $500,000 reward to anyone providing information that leads to the identification, arrest and prosecution of the person or persons responsible for the leak of the Ashley Madison database,” Evans said, according to the BBC.

[1] http://www.wired.com/2015/08/ashley-madison-offering-500k-re...

Update: Odd. The BBC link in the Wired story has quotes from "Bryce Evans of the Toronto police", but does not have the offer of a reward quote that Wired quotes. http://www.bbc.com/news/technology-34044506

Re: Who Hacked Ashley Madison?

#40
post #2

I don't condone this hack, but morals/ethics aside for a moment: The one positive thing this hack has done is really give serious ammo to the battle for online privacy, because the demographic hit by this hack is the most politically & economically powerful demographic in the world....

I'd argue the opposite. The AM hack hasn't helped at all, since enough people view it as a just retribution due to it being about a pet moral value that is held dear, namely marital fidelity. And to others, it's all a big joke. The cheating cheaters (who likely never got the opportunity to cheat) have been named and shamed, and because of those asserting that it's acceptable to do this if it strokes their personal mo…

The future is a future where no semblance of privacy exists.

In the year 3000:

"Truth about the ugliness of the human race will finally be revealed when every single detail about anyone's life is public knowledge available to all."

Post reply on HN