Live data from Hacker News

LulzSec Exposed

seclists.org

71–80 of 82 posts

Re: LulzSec Exposed

#71

haha I think they pissed of the wrong people hacking FBI affiliates:p Check this email, it's the USA looking to hack Libya's oil infrastructure: http://pastebin.com/Jf406RVs I didn't know war got that advanced:)

In some public NATO reports, they said that during the Kosovo thing, NATO hackers took out specific Serbian radar installations to cover for the strike planes. I guess the Serbians didn't get the memo about putting critical infrastructure on a routable network...

Re: LulzSec Exposed

#72
post #17

So they got exposed because they were acting like a bunch of children and taking no precautions? Man, if people who don't know what they're doing are this successful, imagine what it means about people who are. And how any laws we make about computer security are just security theater.

Indeed!

That's one thing a lot of non-experts don't appreciate about these sorts of attacks. They are not terribly sophisticated, nor are they terribly malicious. This is why I put so much blame on Sony and Gizmodo, because they're not being attacked by some elite team of super hackers with an elaborate plot to destroy the company. Rather, they're being attacked by bored teens who are using crude techniques that no public facing website should be vulnerable to in 2011 and they are just dumping what data they gain access to on the internet. Compared to the sort of mischief a talented and dedicated hacker could achieve this is nothing.

Re: LulzSec Exposed

#74

Earlier quoted context omitted.

When you talk about IT security with people with real secrets (governments), they talk about LulzSec-types being the "lowest risk" category of attackers. The mid-risk category are the real professionals; they leave no trace, you never hear about them, you never know they were on your system, they just take your data and sell it. The highest-risk category is true information warfare, targeted attacks by other governme…

To be honest, if your opponent has a couple of million dollars or more to spend on hacking you, and you aren't willing to expend several multiples of that on defence, you should probably give up on the convenience of having your secret data on the internet and just have it encrypted on HDDs surrounded by handpicked armed guards who owe you a blood debt. Computers and especially networks are just fundamentally insecur…

check this out: http://www.ted.com/talks/david_bismark_e_voting_without_frau...

Re: LulzSec Exposed

#75
post #74

Earlier quoted context omitted.

To be honest, if your opponent has a couple of million dollars or more to spend on hacking you, and you aren't willing to expend several multiples of that on defence, you should probably give up on the convenience of having your secret data on the internet and just have it encrypted on HDDs surrounded by handpicked armed guards who owe you a blood debt. Computers and especially networks are just fundamentally insecur…

check this out: http://www.ted.com/talks/david_bismark_e_voting_without_frau...

I'll see your 7 minutes of TED and raise you 60 minutes of Google TechTalks!

http://www.youtube.com/watch?v=_GjmRwfkRXY

Electronic and Internet Voting (The Threat of Internet Voting in Public Elections)

It goes into all sorts of electoral fraud, the finer points of designing elections from a hacker perspective, the diebold hacks, and that awful rails app that those students (?) wrote in the hopes of using it in some US local elections a while back.

In brief, that system isn't safe because someone can obtain your reciept and therefore your voting rights from you by coercion/incentives. Votes should never be verifiable, because then they can be bought. Vote reciepts would be pretty valuable...

Re: LulzSec Exposed

#76

Are you serious? Hackers using windows? :'(

Almost: script kiddies using Windows. It helps the script distributors, by making it easier to target the script kiddies with embedded botnet software :)

Re: LulzSec Exposed

#77
post #74

Earlier quoted context omitted.

check this out: http://www.ted.com/talks/david_bismark_e_voting_without_frau...

I'll see your 7 minutes of TED and raise you 60 minutes of Google TechTalks! http://www.youtube.com/watch?v=_GjmRwfkRXY Electronic and Internet Voting (The Threat of Internet Voting in Public Elections) It goes into all sorts of electoral fraud, the finer points of designing elections from a hacker perspective, the diebold hacks, and that awful rails app that those students (?) wrote in the hopes of using it in some…

>Votes should never be verifiable, because then they can be bought

It's nearly legal to buy votes anyway, but they just call it advertising.

Re: LulzSec Exposed

#78
post #74

Earlier quoted context omitted.

check this out: http://www.ted.com/talks/david_bismark_e_voting_without_frau...

I'll see your 7 minutes of TED and raise you 60 minutes of Google TechTalks! http://www.youtube.com/watch?v=_GjmRwfkRXY Electronic and Internet Voting (The Threat of Internet Voting in Public Elections) It goes into all sorts of electoral fraud, the finer points of designing elections from a hacker perspective, the diebold hacks, and that awful rails app that those students (?) wrote in the hopes of using it in some…

They are already verifiable. You provide the seller with an absentee ballot, he or she fills it out, and then you exchange the completed ballot for the beer/cash/delicious pie.

Re: LulzSec Exposed

#79

Earlier quoted context omitted.

I'll see your 7 minutes of TED and raise you 60 minutes of Google TechTalks! http://www.youtube.com/watch?v=_GjmRwfkRXY Electronic and Internet Voting (The Threat of Internet Voting in Public Elections) It goes into all sorts of electoral fraud, the finer points of designing elections from a hacker perspective, the diebold hacks, and that awful rails app that those students (?) wrote in the hopes of using it in some…

They are already verifiable. You provide the seller with an absentee ballot, he or she fills it out, and then you exchange the completed ballot for the beer/cash/delicious pie.

True, but a crucial difference is that the cryptvoting allows verification after the fact, while absentee ballots must be verified in the window between the ballots being sent out and polling day.

Re: LulzSec Exposed

#80
post #30

They seem to be still tweeting new cracks. Wonder how long it'll take them to realize that they're being arrested by the FBI. (edit: seriously, though, something seems just a bit off here.)

The kid that got busted by the FBI was not actually a lulzsec member, he was just hanging around the lulzsec public IRC channels.

Lulzsec response here: http://pastebin.com/yut4P6qN

Post reply on HN