Live data from Hacker News

Hackers selling hacked police emails to request user data from TikTok, Facebook

404media.co

31–40 of 53 posts

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#31
post #13

Earlier quoted context omitted.

You'll be horrified to learn exactly how much business is conducted through unsecured fax machines.

For some absurd reason fax is often seen by bureaucracies in some countries as “more secure” than email.

Isn’t it though? You can attack email systems, network operators, and end users in a myriad of ways remotely from anywhere in the world. How can you compromise a traditional fax? Eavesdropping the PSTN itself? Physical access to one of the machines? Stealing the printed document?

Network fax systems are more convenient to use than traditional, but still more secure than email because they’ve been designed to be so.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#32
post #24

The emails should just be made public anyway. They are public servants, yes? "To serve and to protect."

It’s about fraudulent data requests using hacked email accounts from government bodies all around the world. What emails are you referring to that should be made public?

Well if they have nothing to hide then what's the issue, officer?

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#34
post #16

Earlier quoted context omitted.

I don't think most law enforcement agencies have any second factor to authenticate themselves online. And it's not the social media companies that suffer but their users whose privacy is being violated.

Don't you think it's within the social media companies interest to respond to as few subpeonas as possible i.e. only genuine ones from authorities? but maybe you're right and this problem won't be solved because the person being harmed has no power and the institution in power sees no harm

Why do you believe they would?, it's definitely not demonstrated here.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#35
post #13

Earlier quoted context omitted.

You'll be horrified to learn exactly how much business is conducted through unsecured fax machines.

For some absurd reason fax is often seen by bureaucracies in some countries as “more secure” than email.

How's that absurd? If you have 0 experienced security folks on staff/consulting, and no one willing to listen to them, then a fax is almost certainly more secure in practice.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#36

Ok if these social media giants are authenticating LEOs by origin email only, without benefit of GPG, or secure token, or whatever, then they are stuck on stupid, and deserve any hacking they get. Ouch.

Email actually has very well thought out authentication mechanisms such that its not unreasonable to expect a domain is not spoofed, and it came from the server it says it came from but if some baddies have logged into your server and sending messages as you, then DKIM can't save you so say social media companies want a higher standard of proof that emails are coming from a particular institution, what mechanisms are…

Never buillding a back door for LEOs sounds like a reasonable option.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#37
post #29

Earlier quoted context omitted.

Don't you think it's within the social media companies interest to respond to as few subpeonas as possible i.e. only genuine ones from authorities? but maybe you're right and this problem won't be solved because the person being harmed has no power and the institution in power sees no harm

Obviously they're going to try to verify law enforcement requests. It's a tradeoff.

"Try" == "it's a .gov email - looks good!"

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#38

Earlier quoted context omitted.

For some absurd reason fax is often seen by bureaucracies in some countries as “more secure” than email.

How's that absurd? If you have 0 experienced security folks on staff/consulting, and no one willing to listen to them, then a fax is almost certainly more secure in practice.

One of those countries is the US. Fax is unencrypted analog. If practice, tgis is ver certainly not secure. It's only "more secure" in the sense that unauthorized access to it counts as wiretapping, whereas the feds carved a loophole allowing them to read private emails without going afoul our anti-wiretapping laws. That you don't see the absurdity means our educational system is also doing what feds built it to do.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#39
post #31

Earlier quoted context omitted.

For some absurd reason fax is often seen by bureaucracies in some countries as “more secure” than email.

Isn’t it though? You can attack email systems, network operators, and end users in a myriad of ways remotely from anywhere in the world. How can you compromise a traditional fax? Eavesdropping the PSTN itself? Physical access to one of the machines? Stealing the printed document? Network fax systems are more convenient to use than traditional, but still more secure than email because they’ve been designed to be so.

Analog. Unencrypted. Your intent to misinform appears evident.

Re: Hackers selling hacked police emails to request user data from TikTok, Facebook

#40
post #24

Earlier quoted context omitted.

It’s about fraudulent data requests using hacked email accounts from government bodies all around the world. What emails are you referring to that should be made public?

Well if they have nothing to hide then what's the issue, officer?

I’m not arguing against your point, it just appears completely irrelevant to the article under discussion, so I asked for clarification instead of just assuming you didn’t read the article.
Post reply on HN