Earlier quoted context omitted.
"No, if they just put UNKN on the most wanted list, then it wouldn't be doxing." I misread that as it either would be the thing to do or an alternative option and you were against putting names on a wanted list.
No, I was just trying to clarify that the "doxxing" part is not the "add $name to $list" but "tie $alias to $real-name".
German police name alleged leaders of GandCrab and REvil ransomware groups
61–70 of 175 posts
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#62Feels odd for an infosec blog to use 'doxxing' this way. Doxxing is generally considered to be unethical exposure of personal information. Identifying a criminal is ethical.
> Identifying a criminal is ethical. I agree that “doxxing” is being misused in TFA, but criminals have privacy rights like anyone else. Violating these rights requires specific justification, it’s not automatically ethical.
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#63Earlier quoted context omitted.
Running a ransomware gang is immoral. Catching someone running a ransomware gang is good. If publishing their name helps catch them, it's also good. Not sure where do you see the gap between legality and morality in this case
People often forget that Threat Actors (TA) are the ones keeping the infosec alive. They are doing a good job of scaring people into implementing actual security protocols and thereby improving everyone's security posture. The whole infosec would collapse without TAs, let's not forget that. They create jobs.
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#64Earlier quoted context omitted.
No, I was just trying to clarify that the "doxxing" part is not the "add $name to $list" but "tie $alias to $real-name".
Isn't this just the good old "aka"?
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#65Earlier quoted context omitted.
Certainly, criminals also have a right to privacy. However, the limited publication of personal data of criminals by law enforcement is generally a legally legitimate measure. Doxxing, on the other hand, is generally a process that violates the fundamental right to privacy.
> Doxxing, on the other hand, is generally a process that violates the fundamental right to privacy. It historically was used for this exact case: revealing someone hiding behind a pseudonym for purposes of law enforcement. The term dates back to the 90s, if not earlier. This isn't something Gen Z made up. It's a Gen X term. "Hack the gibson" era. Wargames era.
I might want to do violence upon you for some reason. Maybe I hate you. Maybe you're doing something that I don't like. If I'm lucky I can round up half a dozen buddies to help. But I don't have infinite resources and infinite reach, so my capability is rather laughable unless you live next door.
Buuuut, if I craft it just right, I can cause the state with it's practically infinite resources, infinite men with guns who kick in doors, etc, etc to choose to kick in your door and do violence upon you. (And the request usually looks a lot like doing their job for them "hey look over here there's this specific person doing this specific thing that you're supposed to go after", but that's beside the point.)
Same as how if I craft a request to a 3rd party server just right a few Kb of on my end can become dozens of Mb on yours.
The German police can't reach these guys. Hence why they're doxing them. They're hoping to structure things such that those who can reach them respond to the request (i.e. rounding up these guys will be a line item in some larger geopolitical context).
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#66Feels odd for an infosec blog to use 'doxxing' this way. Doxxing is generally considered to be unethical exposure of personal information. Identifying a criminal is ethical.
"Doxxing" is from the 90s and was used to describe a hacker unmasking another hacker so they could be arrested. That's almost exactly the same usage as here.
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#67Putting someone on a (most) wanted list is "doxing"? [Edit] "An international search is underway for Daniil Maksimovich SHCHUKIN on suspicion of numerous counts of gang-related and commercial extortion using ransomware to the detriment of commercial enterprises, public facilities, and institutions."
> Putting someone on a (most) wanted list is "doxing"? No, if they just put UNKN on the most wanted list, then it wouldn't be doxing. But then they also tie UNKN together with "Daniil Maksimovich Shchukin", and that's the doxxing, regardless or not if it's on a most wanted list.
This seems to be just issuing an arrest warrant.
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#68Earlier quoted context omitted.
"Doxxing" is from the 90s and was used to describe a hacker unmasking another hacker so they could be arrested. That's almost exactly the same usage as here.
I can't find it in the jargon file: http://catb.org/jargon/html/D.html
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#69Unless there's something not covered in the article, his current address, family members, phone, etc were not listed. That's not doxxing; that's "here's a guy were want to arrest."
Re: German police name alleged leaders of GandCrab and REvil ransomware groups
#70Putting someone on a (most) wanted list is "doxing"? [Edit] "An international search is underway for Daniil Maksimovich SHCHUKIN on suspicion of numerous counts of gang-related and commercial extortion using ransomware to the detriment of commercial enterprises, public facilities, and institutions."
> Putting someone on a (most) wanted list is "doxing"? No, if they just put UNKN on the most wanted list, then it wouldn't be doxing. But then they also tie UNKN together with "Daniil Maksimovich Shchukin", and that's the doxxing, regardless or not if it's on a most wanted list.