Live data from Hacker News

RaidForums gets raided, alleged admin arrested

krebsonsecurity.com

91–100 of 197 posts

Re: RaidForums gets raided, alleged admin arrested

#91
post #41
post #20

Earlier quoted context omitted.

Actually, you're spot on. They started doing these style of splash pages a few years after hacking groups did.

I'd make a guess that they simply just hired those people (semi-voluntarily)

Quite a few former cyber criminals are on probation with three letter orgs…

Re: RaidForums gets raided, alleged admin arrested

#92
post #72
post #3

Earlier quoted context omitted.

Not to mention the following paragraph: >“In an attempt to retrieve his items, Coelho called the lead FBI case agent on or around August 2, 2018, and used the email address unrivalled@pm.me to email the agent,” the government’s affidavit states. Investigators found this same address was used to register rf.ws and raid.lol, which Omnipotent announced on the forum would serve as alternative domain names for RaidForums…

>These people tend not to be the brightest. Well, for those that are bright, you don't hear anything at all. So it's hard to characterize all of them. I hear something similar on shows like Dateline about how not-bright the murderers are. Yet only about half of homicides are solved in the US every year.

You only need to be slightly more intelligent than the people trying to track you in order to not get caught. I heard and read enough true crime stories to noticed that successful serial killers and incompetent law enforcement tend to go hand-in-hand.

Re: RaidForums gets raided, alleged admin arrested

#93
post #43
post #34

Earlier quoted context omitted.

I am always surprised at how often people who know each other randomly run into each other in an airport. I mean, what are the odds? I only had it happen once, but it was nuts. A guy from my previous company I ran into randomly in Frankfurt while I was on my way to India. He lives in California, I live in Chicago. We were on the same flight to Bangalore . Our trips had nothing to do with each other, other than we bot…

Hub-and-spoke routing + "it's not a small world, it's a small social class/industry/demographic/what-have-you" + the tendency for industries to cluster geographically. And what are the odds people meet in the first place? Those exact same factors are what make folks run into each other again later. It would actually be weird if you never ran into people you know. >…Bangalore. Our trips had nothing to do with each oth…

Yep, and throw in that humans are just bad at estimating statistics.

Like the birthday paradox: If there are just 23 people in a room, then there's a 50% probability that two people share the same birthday.

Re: RaidForums gets raided, alleged admin arrested

#94

What are the legal implications of having registered on this forum once with a personal email account but not having ever engaged in any transaction or downloading any leaked data, just lurking a few threads of nothing interesting at most. Asking for a friend, of course...

Hard to say, but rest assured that countless "white hat" infosec companies have also signed up and probably purchased stolen databases in furtherance of their own business activities.

Re: RaidForums gets raided, alleged admin arrested

#95
post #92
post #72

Earlier quoted context omitted.

>These people tend not to be the brightest. Well, for those that are bright, you don't hear anything at all. So it's hard to characterize all of them. I hear something similar on shows like Dateline about how not-bright the murderers are. Yet only about half of homicides are solved in the US every year.

You only need to be slightly more intelligent than the people trying to track you in order to not get caught. I heard and read enough true crime stories to noticed that successful serial killers and incompetent law enforcement tend to go hand-in-hand.

I would guess that things like search history, email records, cell phone records and security cameras are a huge crutch for police these days. So avoiding those things probably gets you most of the way there.

Re: RaidForums gets raided, alleged admin arrested

#96
post #11

Earlier quoted context omitted.

I imagine a lot of people think that just because they've used a WHOIS anonymization service through their registrar, domain registration isn't traceable back to their account. On the contrary, registrars make this incredibly straightforward for law enforcement to do: for instance, see https://www.godaddy.com/legal/agreements/subpoena-policy . It's a remarkably silly way to get busted.

Some context for those that do not know. I believe some time ago raidforums.com was transferred from NameCheap to Cloudflare registrar (pre-seizure) and it was under data redaction with an address in the territory of Cyprus in Whois data. Some sort of attempt at P.O box or shell company voodoo is my guess. With Cloudflare registrar I would not be surprised if they were a cooperating party in this case.

https://www.namecheap.com/legal/general/court-order-and-subp...

https://www.cloudflare.com/media/pdf/transparency-report.pdf - and https://developers.cloudflare.com/registrar/why-choose-cloud... indicates Cloudflare retains "the registrant email on file for that domain."

WHOIS redaction is extremely useful for shielding personal information from non-governmental entities! But US government entities have full access to any data the registrar has on file, regardless of whether they provide redaction services.

Re: RaidForums gets raided, alleged admin arrested

#98
post #95
post #92

Earlier quoted context omitted.

You only need to be slightly more intelligent than the people trying to track you in order to not get caught. I heard and read enough true crime stories to noticed that successful serial killers and incompetent law enforcement tend to go hand-in-hand.

I would guess that things like search history, email records, cell phone records and security cameras are a huge crutch for police these days. So avoiding those things probably gets you most of the way there.

License plates, CCTV, purchase records, public transport etc.

There are so many ways in which you could be tracked that the safe assumption is that you won't be able to avoid it.

Re: RaidForums gets raided, alleged admin arrested

#99

Amazing how the perp started the website at 14 and gradually turned it into the top data leaks site in the world. To be able to build a multi million dollar illegal marketplace and not get caught for 7 years was quite an achievement in itself. Alas you just have to slip once and the party's over.

not really. unless it involves contraband, terrorism, or kid porn, the feds will not care that much. they will get to it eventually but it is not a top priority. Also they need many years to built an airtight case.

Re: RaidForums gets raided, alleged admin arrested

#100
post #26

Earlier quoted context omitted.

What he was doing might very well have been legal had he just avoided payment information and stuck to stolen databases containing emails, phone numbers, passwords. That was the bulk of the trade on raidforums anyway. But yeah, definitely not the sharpest knife in the drawer.

> might very well have been legal had he just avoided payment information and stuck to stolen databases containing emails, phone numbers, passwords I suspect that you are wrong about this. https://en.wikipedia.org/wiki/Accessory_(legal_term) "Count 1: Conspiracy to Commit Access Device Fraud (18 U.S.C. §§ 1029(b)(2)and 3559(g)(1)) Count 2: Access Device Fraud — Using or Trafficking in an Unauthorized Access Device (1…

Also important to keep in mind he ( most likely ) wasn’t aware of US law. Not sure how Portugal classifies businesses such as these, but we know how e.g. Russia differs in this regard.
Post reply on HN