Earlier quoted context omitted.
Doxxing? Hardly. Looking at the Twitter thread, he did far less than a lazy casual fan of a TV star would do on an average Google/Facebook search. > Doesn't seem quite as sensational once you know the backstory. Though your summary was sensationalised by the addition of the term doxxing (usually negative connotations there), whether you meant it to be or not. It is all about how the spin is put on it. An innocuous si…
First definition of "dox" that came up for me on google: > search for and publish private or identifying information about (a particular individual) on the Internet, typically with malicious intent. Sounds appropriate, doesn't it? If you still disagree, here's a thought experiment: If someone were searching and posting that info about you, or anyone else reading this very thread, wouldn't we call that doxxing?
DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet
31–40 of 90 posts
Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet
#32Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet
#33I can't even anymore. If this story is anywhere near true -- and I have no reason to believe it is not -- then what the hell do we as citizens DO about it? How can we put an end to ridiculous infringements on rights and wasteful use of resources? It certainly starts with voting for representatives that won't allow thus, but damn. There aren't a lot of good choices out there. And even if there are, how do we fix the i…
> what the hell do we do More like what can we do, which is essentially nothing besides begging elected officials to do something about it (spoiler: they won't). Alternative is court cases, but those take a lot of time and money, and rulings won't necessarily have the reach you want even if they're in your favor.
Try making it clear to candidates that you would not support such behaviour in an elected official, and that if their interests are aligned with such causes you will not vote for them.
Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet
#34I used to tell my son that there will always be work for computer security specialists and that he should go for that. This makes me wonder about my advice.
I guess that if you work for a company you're probably not looking at anyone's website that's not explicitly paying you/your company and under some contract.
Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet
#35So a security researcher who was angry about getting raided and hit with a CFAA accusation after an unauthorized access of private medical data started doxxing the FBI agent responsible on Twitter. And in response the FBI is requesting information about the Twitter users that were part of the conversation. Doesn't seem quite as sensational once you know the backstory. The author is right that the charges aren't the s…
So if you get @ed in a Twitter thread that meets the bar of irritating DOJ, it's totally reasonable for them to subpoena the times of day you use your Twitter account? I guess that fits with throwing legal charges at people that laugh at you.
The subpoena against the comment poster is questionable, but targeting people who were named in the Tweet is ridiculous. In particular, Dissent Doe never engaged with the thread in any way, but was only named in the exchange.
If you can spawn an invasive data request against someone just by including their handle in a tweet, that's a shocking overreach or a misunderstanding of the communication system.
Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet
#36I used to tell my son that there will always be work for computer security specialists and that he should go for that. This makes me wonder about my advice.
I assume that if you're freelance you're at more risk of finding yourself on the receiving end of a CFAA violation. What I wonder is that if security researchers who work for domestic companies face the same degree of scrutiny that these freelance researchers do. I guess that if you work for a company you're probably not looking at anyone's website that's not explicitly paying you/your company and under some contract…
Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet
#37So a security researcher who was angry about getting raided and hit with a CFAA accusation after an unauthorized access of private medical data started doxxing the FBI agent responsible on Twitter. And in response the FBI is requesting information about the Twitter users that were part of the conversation. Doesn't seem quite as sensational once you know the backstory. The author is right that the charges aren't the s…
"unauthorized access" is bs. It was a public ftp server and he notified the owners. It's like telling your neighbor his door is open.
I think it's more like your neighbors door being open and you going in side and seeing that the refrigerator is open. Therefore proving that you trespassed on private property. Not legal. Of course in most cases you wouldn't be prosecuted for that I would imagine unless you tramped around the house.
Article says:
"he'd come across an FTP server operated by another dental software company, Patterson Dental, which makes "Eaglesoft," a dental practice management software product. Shafer had discovered an openly available anonymous FTP server with patient data"
In order to determine it had patient data he would have to see the patient data not just connect to the server at the root level and then exit. So at the very least (in theory) he would have cd'd a few directories and perhaps downloaded a few files or noted the directory structure and names. That is entering and looking around.
Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet
#38So a security researcher who was angry about getting raided and hit with a CFAA accusation after an unauthorized access of private medical data started doxxing the FBI agent responsible on Twitter. And in response the FBI is requesting information about the Twitter users that were part of the conversation. Doesn't seem quite as sensational once you know the backstory. The author is right that the charges aren't the s…
Doxxing? Hardly. Looking at the Twitter thread, he did far less than a lazy casual fan of a TV star would do on an average Google/Facebook search. > Doesn't seem quite as sensational once you know the backstory. Though your summary was sensationalised by the addition of the term doxxing (usually negative connotations there), whether you meant it to be or not. It is all about how the spin is put on it. An innocuous si…
I'm sure they'd say they take any 'threats' against their agents seriously, even seemingly benign ones. It's possible most of this stuff is automated anyway, so they can do deep searches with all identifiers into their NSA-fueled databases on anyone talking about FBI agents on social media.
Re: DOJ Subpoenas Twitter About Five Users Over a Smiley Emoji Tweet
#39One of the subpoenas was about PopeHat, who of course is public, and he wrote about it on his blog. Why demand twitter unmask a public account?
Link to said popehat blog article, https://www.popehat.com/2017/10/24/in-which-my-identity-is-s... Speculated reasoning in the comments on the article was that it then gives an admissible account of who owns the twitter name. Otherwise the assertions about who owns it are inadmissable hearsay. That said it's still really weird that the accounts were subpeonaed EDIT: fixed link. Just noticed it went to an old article.…