Live data from Hacker News

German police name alleged leaders of GandCrab and REvil ransomware groups

krebsonsecurity.com

61–70 of 175 posts

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#61

Earlier quoted context omitted.

"No, if they just put UNKN on the most wanted list, then it wouldn't be doxing." I misread that as it either would be the thing to do or an alternative option and you were against putting names on a wanted list.

No, I was just trying to clarify that the "doxxing" part is not the "add $name to $list" but "tie $alias to $real-name".

Isn't this just the good old "aka"?

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#62
post #29
post #8

Feels odd for an infosec blog to use 'doxxing' this way. Doxxing is generally considered to be unethical exposure of personal information. Identifying a criminal is ethical.

> Identifying a criminal is ethical. I agree that “doxxing” is being misused in TFA, but criminals have privacy rights like anyone else. Violating these rights requires specific justification, it’s not automatically ethical.

I mean doxxing is totally incorrect. Let's say for example there was a person on film near a crime scene, even though the police know they weren't directly involved there is no violation of privacy in the US if the police post their picture and ask for them to come forward. Or even later find out their name and look for them publically.

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#63
post #59
post #46

Earlier quoted context omitted.

Running a ransomware gang is immoral. Catching someone running a ransomware gang is good. If publishing their name helps catch them, it's also good. Not sure where do you see the gap between legality and morality in this case

People often forget that Threat Actors (TA) are the ones keeping the infosec alive. They are doing a good job of scaring people into implementing actual security protocols and thereby improving everyone's security posture. The whole infosec would collapse without TAs, let's not forget that. They create jobs.

That's right. They also create jobs for police though, and now German police is doing theirs

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#64

Earlier quoted context omitted.

No, I was just trying to clarify that the "doxxing" part is not the "add $name to $list" but "tie $alias to $real-name".

Isn't this just the good old "aka"?

Like in " William H. Bonney aka The Kid"? Doxing in the 19th century by the government it seems.

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#65
post #50

Earlier quoted context omitted.

Certainly, criminals also have a right to privacy. However, the limited publication of personal data of criminals by law enforcement is generally a legally legitimate measure. Doxxing, on the other hand, is generally a process that violates the fundamental right to privacy.

> Doxxing, on the other hand, is generally a process that violates the fundamental right to privacy. It historically was used for this exact case: revealing someone hiding behind a pseudonym for purposes of law enforcement. The term dates back to the 90s, if not earlier. This isn't something Gen Z made up. It's a Gen X term. "Hack the gibson" era. Wargames era.

Doxxing is basically a DDOS reflection attack but for real violence, or threat thereof, instead of 1s and 0s.

I might want to do violence upon you for some reason. Maybe I hate you. Maybe you're doing something that I don't like. If I'm lucky I can round up half a dozen buddies to help. But I don't have infinite resources and infinite reach, so my capability is rather laughable unless you live next door.

Buuuut, if I craft it just right, I can cause the state with it's practically infinite resources, infinite men with guns who kick in doors, etc, etc to choose to kick in your door and do violence upon you. (And the request usually looks a lot like doing their job for them "hey look over here there's this specific person doing this specific thing that you're supposed to go after", but that's beside the point.)

Same as how if I craft a request to a 3rd party server just right a few Kb of on my end can become dozens of Mb on yours.

The German police can't reach these guys. Hence why they're doxing them. They're hoping to structure things such that those who can reach them respond to the request (i.e. rounding up these guys will be a line item in some larger geopolitical context).

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#66
post #49
post #8

Feels odd for an infosec blog to use 'doxxing' this way. Doxxing is generally considered to be unethical exposure of personal information. Identifying a criminal is ethical.

"Doxxing" is from the 90s and was used to describe a hacker unmasking another hacker so they could be arrested. That's almost exactly the same usage as here.

I can't find it in the jargon file: http://catb.org/jargon/html/D.html

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#67

Putting someone on a (most) wanted list is "doxing"? [Edit] "An international search is underway for Daniil Maksimovich SHCHUKIN on suspicion of numerous counts of gang-related and commercial extortion using ransomware to the detriment of commercial enterprises, public facilities, and institutions."

> Putting someone on a (most) wanted list is "doxing"? No, if they just put UNKN on the most wanted list, then it wouldn't be doxing. But then they also tie UNKN together with "Daniil Maksimovich Shchukin", and that's the doxxing, regardless or not if it's on a most wanted list.

Back in the day, being doxed meant having your real name, address, phone number, email, etc. posted online for anyone to do what they would.

This seems to be just issuing an arrest warrant.

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#68
post #66
post #49

Earlier quoted context omitted.

"Doxxing" is from the 90s and was used to describe a hacker unmasking another hacker so they could be arrested. That's almost exactly the same usage as here.

I can't find it in the jargon file: http://catb.org/jargon/html/D.html

It comes from leetspeak. Identity documents -> docs -> dox

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#69
How is "this is the name of the formerly anonymous extortionist" doxxing?

Unless there's something not covered in the article, his current address, family members, phone, etc were not listed. That's not doxxing; that's "here's a guy were want to arrest."

Re: German police name alleged leaders of GandCrab and REvil ransomware groups

#70

Putting someone on a (most) wanted list is "doxing"? [Edit] "An international search is underway for Daniil Maksimovich SHCHUKIN on suspicion of numerous counts of gang-related and commercial extortion using ransomware to the detriment of commercial enterprises, public facilities, and institutions."

> Putting someone on a (most) wanted list is "doxing"? No, if they just put UNKN on the most wanted list, then it wouldn't be doxing. But then they also tie UNKN together with "Daniil Maksimovich Shchukin", and that's the doxxing, regardless or not if it's on a most wanted list.

Uh, you think they should just put "UNKN" on the wanted list instead of the person they believe is UNKN? That's not very helpful...
Post reply on HN