Live data from Hacker News

Lulzsec fiasco - from HideMyAss VPN provider

blog.hidemyass.com

51–60 of 62 posts

Re: Lulzsec fiasco - from HideMyAss VPN provider

#51
post #21

It's quite ironic how he says "Our VPN service and VPN services in general are not designed to be used to commit illegal activity", and then "there are many other legitimate uses such as the ability to unblock GEO-restricted websites." Hello, why do you think most of those sites are geo-restricted? Because of copyright laws . Circumventing those blocks in most cases means you're breaking those laws -- at the very min…

Hello, why do you think most of those sites are geo-restricted? Because of copyright laws. Circumventing those blocks in most cases means you're breaking those laws -- at the very minimum, you're breaking contractual obligations that you and the service are supposed to obey under penalty, and at worst you're committing fraud by claiming you come from a different country.

Using a different IP address is, in absolutely no way, a mechanism for claiming that you come from a different country.

If I live on the Canadian border, and get my internet access via long-range wireless from the US, am I committing "fraud" by presenting a "US" IP address?

Re: Lulzsec fiasco - from HideMyAss VPN provider

#52
post #51
post #21

It's quite ironic how he says "Our VPN service and VPN services in general are not designed to be used to commit illegal activity", and then "there are many other legitimate uses such as the ability to unblock GEO-restricted websites." Hello, why do you think most of those sites are geo-restricted? Because of copyright laws . Circumventing those blocks in most cases means you're breaking those laws -- at the very min…

Hello, why do you think most of those sites are geo-restricted? Because of copyright laws. Circumventing those blocks in most cases means you're breaking those laws -- at the very minimum, you're breaking contractual obligations that you and the service are supposed to obey under penalty, and at worst you're committing fraud by claiming you come from a different country. Using a different IP address is, in absolutely…

If it can be proved, above reasonable doubt, that you're using that IP on purpose, with the only aim to bypass such geographical restrictions on content distribution against the will of content owners... well, it'll be a tough day in court.

Note that I'm not saying that IP == actual physical person or GeoIP == actual physical location. A lawyer would have to prove that you were using that computer, with that specific IP, on that date-time, and you were accessing that content in full knowledge of the fact that only US-based consumers were allowed to do that... Which is very difficult, but not impossible. Laws are always interpreted, at the end of the day.

Re: Lulzsec fiasco - from HideMyAss VPN provider

#54
post #52
post #51

Earlier quoted context omitted.

Hello, why do you think most of those sites are geo-restricted? Because of copyright laws. Circumventing those blocks in most cases means you're breaking those laws -- at the very minimum, you're breaking contractual obligations that you and the service are supposed to obey under penalty, and at worst you're committing fraud by claiming you come from a different country. Using a different IP address is, in absolutely…

If it can be proved, above reasonable doubt, that you're using that IP on purpose, with the only aim to bypass such geographical restrictions on content distribution against the will of content owners... well, it'll be a tough day in court. Note that I'm not saying that IP == actual physical person or GeoIP == actual physical location. A lawyer would have to prove that you were using that computer, with that specific…

Then they'd have to show that spoofing your country was actually illegal, as opposed to just against their policies. Don't fall into the trap of equating terms of service with laws.

Re: Lulzsec fiasco - from HideMyAss VPN provider

#55
post #53

Why don't these guys hack from a virtual machine, in starbucks, then delete the virtual machine, then never visit the same coffee shop again? how would they get traced from doing that?

MAC address, store security tapes, cell phone geo tracking data.

I mean, you're right, face in a huge crowd is potentially more security than hidden really well, but it's not perfect either.

Re: Lulzsec fiasco - from HideMyAss VPN provider

#57
post #25

Earlier quoted context omitted.

No-one serious minds that a business complies with correctly formed legal requests. (And it's tricky for people in the UK facing the might of US law.) What's annoying is the disconnect between saying "We help you avoid censorship" and "we comply with correctly formed law enforcement documents".

He has US based servers - perhaps it was "give us your logs, or we take your servers" (speculation). I just figured I know the guy more than the people here - or at least, used to and from what I could tell he was a good guy who tried to to do the right thing. That's all I can say.

It's a bit like Hushmail. Compare their new advice to customers about how Hushmail will comply with law enforcement; to the point of creating new malicious Java software and pushing that out secretly to the 'target' / 'victim' to compromise their communication.

Hushmail states all this clearly, allowing new customers to make an informed choice.

Re: Lulzsec fiasco - from HideMyAss VPN provider

#58
post #53

Why don't these guys hack from a virtual machine, in starbucks, then delete the virtual machine, then never visit the same coffee shop again? how would they get traced from doing that?

MAC address, store security tapes, cell phone geo tracking data. I mean, you're right, face in a huge crowd is potentially more security than hidden really well, but it's not perfect either.

MAC addresses are easily changed. You don't have to be in a store, or even near it, to use its wifi. And you don't have to bring your cell. Or you could use a throwaway prepaid.

Long story short, no competent hacker would get caught using hidemyass, and the Feds are once again putting on a dog and pony show.

Re: Lulzsec fiasco - from HideMyAss VPN provider

#59
post #53

Why don't these guys hack from a virtual machine, in starbucks, then delete the virtual machine, then never visit the same coffee shop again? how would they get traced from doing that?

I wouldn't do that. It would pin the attacker down from 'anywhere in the world' to 'he lives somewhere near this Starbucks'.

Re: Lulzsec fiasco - from HideMyAss VPN provider

#60
I was always curious as to what they were doing to hide their identities. I read the logs, and I am a bit disappointed that the extent of their methods of hiding themselves were so narrow - involving only VPN providers.

The old way of doing this was to own a series of boxes around the world and setup your own SOCKS server, ssh forwards etc. You use boxes that are being used internally at small companies for email or web hosting, meaning that there aren't any admins on there looking for weird traffic patterns.

You setup a group of servers like that, and chain them together. Symlink all logs to null, and make sure the first box you jump onto is the most unsuspecting (and one that you have most control over).

With a group that I was a member of 10+ years ago we would abandon boxes that had a sysadmin that seemed like he knew what he/she was doing (looking at history logs) or boxes that had a lot of user activity on them but not a lot of resources (it only takes one user to wonder why the net connection is slow for the exploit and you to be found ). The best best were to scan for old ftpd's running on old kernels.

These were boxes that had been bought and setup for something like email or a small webpage and then forgotten about (usually setup by external IT). You patch the exploit so nobody else can get it, install a backdoor, and not do anything noticeable. We had access to such boxes for years and as far as I know we were never noticed by anybody.

VPN providers are constantly monitoring for abuse, and when they get a law enforcement notice they will comply. It is only a matter of time before you get caught if you are using them. I would suspect that law enforcement found out which VPN providers were being used some months ago, and set up honeypots at each one waiting for members of anonymous to reconnect.

Post reply on HN