Quitting or rebranding is the question I find myself asking.
Or to put my high school poetics into plain English:
They will want to blend in with the Anonymous masses, until they deem it safe to once again to craft new identities for themselves.
81–90 of 97 posts
Quitting or rebranding is the question I find myself asking.
Or to put my high school poetics into plain English:
They will want to blend in with the Anonymous masses, until they deem it safe to once again to craft new identities for themselves.
Earlier quoted context omitted.
Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…
You're assuming they're safe because their technology stack is safe, but there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Cops work like hackers in the sense that both groups attack vulnerabilities. The vulnerabilities here are clear: these guys have big mouths and they're overconfident. They'll talk to somebody someday, and when that happe…
Would be interesting to hear some of them.
Earlier quoted context omitted.
Hm, are you sure? I have a couple accounts there (and they are appearing in the dump) and they are not simply md5(password). Of course they were long, random passwords and I don't play this game anymore, but I'm curious. Where did you read that?
I didn't read it anywhere. I downloaded the database and checked all my friends against a known password database. They're plain md5(password).
Earlier quoted context omitted.
Pretty simple really, at least in the UK. Just get someone to make an allegation against them (underage porn, etc), and their computers get seized. If the police just happen to discover a ton of other things they're really involved in whilst analysing them, there you go. If encrypted, under UK law you have to divulge the keys or go to jail, so you're guaranteed to get them some jail time.
Just get someone to make an allegation against them (underage porn, etc), and their computers get seized. Is that legal in the UK? Because in the US it'd be unconstitutional.
Earlier quoted context omitted.
I'd have to agree. Even now I think that with time they will all be outed - if they've not already. Some of these 'raids' have just been too daring to expect to get away with forever.
Really though, if all of your traffic is going through TOR to a vpn in eastern europe, the chances of being tracked down are slim to nil. Sure, there are theoretical weaknesses in TOR, but you'd need to control quite a few exit nodes to even begin to have a chance of pinpointing the endpoints. Combine that with a compromised wifi as a last resort (which you erase the logs of regularly), and you're pretty damned safe.…
Earlier quoted context omitted.
Ahhh, didn't know they went onto hacked machines. So - some people should be getting some knocks on their door soon?
Yup, you use a compromised Windows machine or Linux server in a third world country as a proxy. When you're done, you wipe the disk.
Earlier quoted context omitted.
You're assuming they're safe because their technology stack is safe, but there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Cops work like hackers in the sense that both groups attack vulnerabilities. The vulnerabilities here are clear: these guys have big mouths and they're overconfident. They'll talk to somebody someday, and when that happe…
> there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Would be interesting to hear some of them.
This might involve (erroneously) shared contacts. Shared VoIP numbers. Shared MAC addresses, or shared IP addresses. Shared passwords. IRC channels or web sites.
Even what times you are active, what words and what phrases you use, and your browser strings can provide clues.
A group within (IIRC) Lebanon was reportedly identified a while back because of an opsec error; one of the folks involved in the group used a "restricted" cellular phone to call his girlfriend, and that broke open the identities.
The German Ultra encryption system was targeted and was sometimes vulnerable due to opsec errors. Opening such as key reuse, or sending duplicate messages, can provide openings that allowed decryption.
This area is related to the classic "covert channels" discussions within information security; on the expected information leakage, and around how a "defender" wants to keep leakage at a minimum, and how an "attacker" is looking for clues and errors.
This is also a corollary to the classic difficulties with maintaining server security; leave one sufficiently egregious opening in your security, and you can be toast.
Earlier quoted context omitted.
That's also what strikes me in this story. Anyone can explain this?
After thinking about it for a few moments, I would guess that they largely sell books and research papers and suchlike on subjects that are of interest to those in member militaries, but aren't of sufficient general interest to make it to Amazon or otherwise. EDIT : or, I could've spent a single moment to read the contents of the aforementioned link.
Earlier quoted context omitted.
Yup, you use a compromised Windows machine or Linux server in a third world country as a proxy. When you're done, you wipe the disk.
3rd world country only? You mean nothing else outside your own country works? tsk tsk.
Earlier quoted context omitted.
You're assuming they're safe because their technology stack is safe, but there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Cops work like hackers in the sense that both groups attack vulnerabilities. The vulnerabilities here are clear: these guys have big mouths and they're overconfident. They'll talk to somebody someday, and when that happe…
> there are about 20 ways that law enforcement could possibly track these guys down that don't require particularly l33t skillz. Would be interesting to hear some of them.