Live data from Hacker News

Is This The Girl That Hacked HBGary?

blogs.forbes.com

91–100 of 135 posts

Re: Is This The Girl That Hacked HBGary?

#91
post #40

Using the quotes from the article, however too few words to analyze properly, so inconclusive, but still... From http://www.hackerfactor.com/GenderGuesser.php Genre: Informal Female = 171 Male = 182 Difference = 11; 51.55% Verdict: Weak MALE Weak emphasis could indicate European. From http://bookblog.net/gender/analysis.php Female Score: 94 Male Score: 133 The Gender Genie thinks the author of this passage is: male!

I'm female last time I checked, and a paste from my blog makes gender guesser thinks I'm weak male and gender genie says I'm male. Doesn't mean anything, but worth noting.

Grepped this, which ars technica claims is a real chat log. She says just under 200 words on this log, and it comes up as weak male again on Gender Guesser and male on Gender Genie. Her username of `k is removed for the analysis. http://pastebin.com/x69Akp5L

Here's the article where Ars Technica links to that pastebin http://arstechnica.com/tech-policy/news/2011/02/how-one-secu...

Re: Is This The Girl That Hacked HBGary?

#92
post #40

Using the quotes from the article, however too few words to analyze properly, so inconclusive, but still... From http://www.hackerfactor.com/GenderGuesser.php Genre: Informal Female = 171 Male = 182 Difference = 11; 51.55% Verdict: Weak MALE Weak emphasis could indicate European. From http://bookblog.net/gender/analysis.php Female Score: 94 Male Score: 133 The Gender Genie thinks the author of this passage is: male!

I ran the first answer from this interview with Barbara Liskov (famous MIT computer science professor) through the gender guesser: http://news.cnet.com/8301-1001_3-10217055-92.html

Genre: Formal Female = 509 Male = 971 Difference = 462; 65.6% Verdict: MALE

Computing represents a pretty specialized topic, and most of the sample data with computing-related discussion will be from men. It would be pretty tough for any simple Bayesian analysis to account for this.

Re: Is This The Girl That Hacked HBGary?

#93
post #47
post #8

This could very likely be a carefully (and cleverly constructed) identity. This girl might not exist; but because we all really really want a 16 year old girl to be the hacker the discrepancies are glossed over (the art of a good lie is not giving too much detail and letting other people's imagination fill the gaps). On the other hand the personality strikes me strongly as female, so if it is an facade it is a very w…

When I had a lot more time, I would go into Yahoo chat and basically phish for pedophiles usernames/passwords. I can tell you that a "hehe" after anything will set the hook. I could on average phish about an account a minute and I was never figured out. I only fell out of character once to warn an 18 year old kid, that talking to 14 year old girls sexually online wasn't the best use of his time. He freaked out and th…

Finding one in Yahoo! Chat in the 90s wasn't very hard it was tough trying to find someone, anyone to chat with who wasn't a pedophile, those chatrooms were insane! ...and the webcams too!

Re: Is This The Girl That Hacked HBGary?

#94
post #91
post #40

Using the quotes from the article, however too few words to analyze properly, so inconclusive, but still... From http://www.hackerfactor.com/GenderGuesser.php Genre: Informal Female = 171 Male = 182 Difference = 11; 51.55% Verdict: Weak MALE Weak emphasis could indicate European. From http://bookblog.net/gender/analysis.php Female Score: 94 Male Score: 133 The Gender Genie thinks the author of this passage is: male!

I'm female last time I checked, and a paste from my blog makes gender guesser thinks I'm weak male and gender genie says I'm male. Doesn't mean anything, but worth noting. Grepped this, which ars technica claims is a real chat log. She says just under 200 words on this log, and it comes up as weak male again on Gender Guesser and male on Gender Genie. Her username of `k is removed for the analysis. http://pastebin.co…

I ran a bunch of short stories through it too and it gave me plenty of weak male for female authors.

Re: Is This The Girl That Hacked HBGary?

#95
post #93
post #47

Earlier quoted context omitted.

When I had a lot more time, I would go into Yahoo chat and basically phish for pedophiles usernames/passwords. I can tell you that a "hehe" after anything will set the hook. I could on average phish about an account a minute and I was never figured out. I only fell out of character once to warn an 18 year old kid, that talking to 14 year old girls sexually online wasn't the best use of his time. He freaked out and th…

Finding one in Yahoo! Chat in the 90s wasn't very hard it was tough trying to find someone, anyone to chat with who wasn't a pedophile, those chatrooms were insane! ...and the webcams too!

For the record, I believe this would have been between 2000 and 2004ish.

Re: Is This The Girl That Hacked HBGary?

#96
This is Anonymous we're talking about. Isn't "16 year old girl" a well-known colloquialism on 4chan, normally used to convey the stereotype of a middle-aged, balding geek still living in his parent's basement who likes to use fake online personas? Forbes got trolled in a monumental fashion.

Re: Is This The Girl That Hacked HBGary?

#97
post #58

Earlier quoted context omitted.

This is where TrueCrypt comes in. If you are being extorted to reveal a password, you supply one that loads a "clean" OS/filesystem.

I've never understood this. Wouldn't a competent security professional know of the existence of TrueCrypt, who would then ask a competent psychologist to determine if you were withholding information (I sure as hell wouldn't be able to keep a straight face), who would then ask a competent interrogator to get the real password from you? I don't even think plausible deniability would hold in court -- claiming that a la…

Sure it's plausible. The suggested _secure_ way of wiping a harddrive is to override it with random data (since a typical delete simply drops an entry from a table, making data retrieval trivial (in the current context)).

What I don't understand is that in a context of a court (and this group of competent professionals), password disclosure _should_ be considered self-incrimination (although there was at least one case in the UK where a judge came up with some loophole reasoning around that). Disclosure of multiple passwords ("we didn't like what we found, do you have any other passwords?") would certainly be obtained under great duress.

Re: Is This The Girl That Hacked HBGary?

#98
post #8

This could very likely be a carefully (and cleverly constructed) identity. This girl might not exist; but because we all really really want a 16 year old girl to be the hacker the discrepancies are glossed over (the art of a good lie is not giving too much detail and letting other people's imagination fill the gaps). On the other hand the personality strikes me strongly as female, so if it is an facade it is a very w…

I've hung out in the anonops irc quite a bit, and `k certainly comes across as female. I hadn't linked her to the Kayla > YOU spam before, but that was almost 3 years ago, now. If it is a constructed identity, then it's been carefully cultivated.

It is an awesome story, though. Regardless of whether it's true or not, it's effective at both rallying the neckbeards and shaming opponents. It's funny to see how much deference is paid to her on IRC, although I only started going there after news of the HBGary incident broke, so she already had quite a lot of cred.

`k may or may not be a 16 year old girl, but it's a hell of a troll if she isn't. I'm not aware of many anons who could pull something like that off for so long. There were a few back in the day who had managed to become trusted enough at anontalk to get promoted to wiseguys, but that took a couple months, not a couple years. For that reason, as well as her general demeanor, I'm inclined to believe her.

Re: Is This The Girl That Hacked HBGary?

#99
post #58

Earlier quoted context omitted.

This is where TrueCrypt comes in. If you are being extorted to reveal a password, you supply one that loads a "clean" OS/filesystem.

I've never understood this. Wouldn't a competent security professional know of the existence of TrueCrypt, who would then ask a competent psychologist to determine if you were withholding information (I sure as hell wouldn't be able to keep a straight face), who would then ask a competent interrogator to get the real password from you? I don't even think plausible deniability would hold in court -- claiming that a la…

A large part of the design of Truecrypt is that nobody CAN prove there's an alternate partition. Or, you can decrypt your secondary alternate partition under duress to reveal your real hidden one. Maybe put some token warez on it or something.

To make sure that you can't distinguish free space from encrypted noise, you have to write random noise everywhere as part of the filesystem creation process.

The one thing Truecrypt is vulnerable to is that you can note what parts changed -- say they raid your house twice and image it between when you used it. Then they'll know that free space isn't really free.

Re: Is This The Girl That Hacked HBGary?

#100

My bs meter was high for a number of reasons. This paragraph was the most notable: "Meanwhile she refuses to be chained to her computer, limiting herself to a few hours a night online. She rarely visits online forums "they’re boring"and a few days a week takes a course in college to further her goal of being a teacher. She lives in an English-speaking country not the U.K.but won’t say more about it" So the previous p…

> Add in the admission she deletes all her emails and wipes all her drives clean? Really? Does this person memorize every line of code she uses then?

I agree that the persona is bullshit and that 'she' is a probably a mid-to-late 20s male but...

Where does it say that she/he deletes wipes all her drives clean? It only says that (s)he wipes her web accounts. From reading the article, (s)he keeps her personal files/documents on a MicroSD card; quite a smart and disposable solution really.

Perhaps the personal files are encrypted also? It's interesting to imagine what other steps you could take to protect your privacy, it probably wouldn't be too difficult to do alternating sharding at the bits and bytes level over SSH with off-site storage (Half on MicroSD, half off-site), does any tool do something similar currently? You could even put a self-destruct timer on the offsite storage (if last_login > 5 days ago: format hard drive with 40-pass erase) or maybe a kill-switch containing sensitive informatoin (ala Wikileaks).

Post reply on HN