48 ms·
Fraternal Order of Police Data Dump
- mangeletti 11y agoI was JUST solicited by phone on the day before yesterday, by our local FOP in Jupiter, FL. Let me tell you how that went (I'll call the caller Albert, to avoid using his real name): Albert: Hi, <my full name>. This is Albert from the Jupiter Police Department... Me: Hi (...shit, did I cut somebody off and they called the cops?). Albert: [nothing for 3 seconds while I ruminate in my paranoia] Albert: Don't worry, there's nothing wrong. I'm calling about officers in need. I'm from the Fraternal Order of Police... Each year we... yata yata... we help officers that have been injured on the job and officers whose families are in need... can you help us out? Me: [how does this guy know my mobile phone number and full name, anyway] Me: Possibly. ... some back and forth - him trying to convince me that the only amount that can be accepted is $285. Me having patience, thinking about how, despite all the police brutality reports out there, etc., there are also a lot of public servants in need that are now doubly screwed by all the bad press, as a result of the few that do bad things, also how the Jupiter Police Department has always been really great compared to anywhere else I've lived... basically, I'm sympathizing with the officers, rather than wondering what this FOP organization is, and why they're being allowed to say they're calling FROM the Jupiter Police Department. Me: Ok, I'll donate $90. ... quick discussion about check / payable to, etc... Albert: Ok, I've got you at <my address>. Is that correct? Me: [what, does the police department give him the address from my license?] Me: Yes. Albert: Ok, I'll have our guy come pick up the check tomorrow. The call basically ends there, but I'm left with this uncomfortable "well, that guy seemed like a hustler to me" feeling. I do a quick search, pull up their website, and immediately find that they offer legal services, etc. Instantly, I'm thinking, "wait, I was just bamboozled into donating to a fund that is probably used for lobbying / bargaining, and for protecting police that are charged with murdering innocent people! I was donating to help officers directly in need!". I called back and cancelled the donation. Organizations like this are, sadly, basically large gangs, and they only serve to ruin the establishments they "serve" by adding unnatural protections that lead to corruption and abuse. Note: My full name is on my profile page. I only mask it here, in case this comment was, for some reason, copy/paste quoted on NYT or something ridiculous.
- LordKano 11y agoThey stopped calling me years ago. The caller went through his spiel and asked if I'd like to make a $100 donation. I politely informed him that I would not. He tried again at $50. I declined and again for $20. He said something along the lines of if I can't afford a larger donation, anything would help. I explained to him that I had the money. $100 isn't the problem. I was unwilling to donate money to the FOP. He laughed, told me that he understood and we wished each other a good day as the call ended. They haven't called me back since.
- uremog 11y agoDid you ever figure out how they know your address?
- mangeletti 11y agoNo, but I did register a business in FL last year, so it could very well have been that.
- ryanlol 11y agoWhile I wouldn't put abusing police records past them, it seems more likely that they just purchased some telemarketing DBs from data brokers.
- fiatmoney 11y agoScammers will also impersonate as fundraisers for the local PD. Really, never give money in response to an unauthenticated phone call.
- pavel_lishin 11y ago> Don't bother with legal threats or trying to get UK law enforcement to seek revenge. This is me playing nice. If you want to go nuclear with me, feel free to do so, but trust me when I say you might want to think long and hard before you do. > I'm not known for bluffing, and I know many more of your secrets. About 18TB all in all actually, all unpublished yet. I wonder what's in the unpublished docs, and why they're remaining unpublished.
- draw_down 11y agoThat's quite the provocation, certainly. But (at least in America) the cops aren't known for bluffing either.
- numbsafari 11y ago> I wonder what's in the unpublished docs, and why they're remaining unpublished. Probably something damning/valuable/devastating. Probably so that whoever this is has something of value to further prove authenticity and to hold as leverage against retaliation (hence the OP words you quoted).
- pc86 11y agoBut what's the alternative? They either release everything eventually, and the leverage is lost, or they don't, and damning/valuable/devastating information about corruption or whatever else is there does the public zero good, or it's somehow destroyed and we get the worst of both. Dribbling the data out slowly is the best move from a PR standpoint but dangerous if you hold on to the worst of the worst info.
- granos 11y agoThey are trying to extort money. They are always trying to extort money. Look at all these nasty things I released about you. I wonder what else is in this large trove of files that I can slowly leak over a few years to keep you in the news. Maybe if somebody sent me some money....
- geobmx540 11y agoI need more popcorn for this
- travjones 11y agoWow. This is going to be interesting... The page even includes the key to decrypt the encrypted fields in the dump. Is pg_crypto that easy to crack, or is it more likely the key was stored somewhere in plaintext (e.g., email, pdf, etc.)?
- ascendantlogic 11y agoOne would assume the key was simply pilfered as well vs the crypto being cracked, but that's just a gut reaction. Human opsec is almost universally worse than any crypto, even ones that have already been broken.
- travjones 11y agoThat's what I suspected. Thanks.
- infogulch 11y agoThe key is "Nipper47". Only 8 characters in the standard "short english-ish word starting with a capital letter followed by a couple numbers"-pattern. I'd say it's less that pg_crypto is easy to crack, and more that the key is trivially insecure and easy to brute-force. But sibling is probably right that it was just sitting there.
- _asdf_asdf 11y ago8 chars, including numeric, uppercase and lowercase... With sufficient GPU resources (being in possession of a working rig, cloud-based or standalone and air-gapped, all powered-up and running operable software) and talent (experience, and familiarity with an existing framework and an established code base), I'm thinking one person could brute force that, in the privacy of their own home, in a trivial amount of time.
- infogulch 11y ago> one person could brute force that, in the privacy of their own home, in a trivial amount of time. Yes. And that's assuming your pattern (26+26+10)^8 ~ 2e14, but the basic character pattern here is 26 * 26^5 * 10^2 ~ 3e10, almost 10000 times weaker. This is an extremely common pattern, most passwords don't follow a uniform distribution of those "numeric, uppercase and lowercase" characters.
- colinbartlett 11y agoIs there any background here or are there any summaries of what is contained in the documents?
- rfrank 11y agoDon't have any background, but from what I've seen so far (a small handful of the tons of docs) it's collective bargaining agreements between various police unions and the cities they operate in. Haven't seen one more recent than 2012.
- samstave 11y agoSearch for "stingray" and "body cameras" in all docs please.
- cmurf 11y agodrone money drugs swimming pool lawsuit lawyer illegal destroy ruin idiot river tax fbi atf cia nsa irs Lots of words to search for.
- samstave 11y agoSure, But currently Stingray and Body Cameras are the two biggest contentious technology issues with police at the moment. Police in Chicago were caught destroying cameras and mics to avoid audio recording and reporting. Stingrays are seemingly getting reported weekly. So, I think they are a good focus. But - make a word cloud and see whats largest.
- ihsw 11y agoWe should expect the FBI to become involved if there is any credence to this, and the domain name thecthulhu.com (Namecheap with WhoisGuard) should be taken down shortly. Heads will roll, that much is certain. Does anyone have a file listing for this? Is it just a PGDATA dump, or are there more interesting things?
- omginternets 11y ago>Does anyone have a file listing for this? Is it just a PGDATA dump, or are there more interesting things? I see a lot of text files (docx, doc, rtf, txt), and two DB dumps. Not sure how/where to start looking. Opening files at random yields things like collective bargaining agreements and legal briefs. Any suggestions for munging through all of this?
- encoderer 11y agoThere should be tools for crowdsourcing this sort of thing. It's only going to become more common. Does such a tool already exist? Something to help split up a corpus so people can collaborate on it.
- mutagen 11y agoYes, there are tools exploring a couple different approaches. It's a tough problem if you want solid results, verification to avoid forged documents inserted alongside authentic ones, building tools to facilitate finding the important stuff in all the minutia of day to day exchanges. Some stuff isn't easily fully crowdsourced because the domain knowledge to find the smoking gun among the jargon of a particular field. A good tool will at least let the average citizen distill information into a form an expert can quickly digest large numbers of documents though. Here's a linkdump: https://www.documentcloud.org/home https://www.documentcloud.org/home https://civic.mit.edu/blog/shidash/effective-approaches-and-experiments-in-leak-processing https://civic.mit.edu/blog/shidash/effective-approaches-and-... https://github.com/crowdata/crowdata https://github.com/crowdata/crowdata http://towcenter.org/research/guide-to-crowdsourcing/ http://towcenter.org/research/guide-to-crowdsourcing/ https://en.wikipedia.org/wiki/List_of_crowdsourcing_projects https://en.wikipedia.org/wiki/List_of_crowdsourcing_projects (too broad, search page for roots of terms like 'transcribe' or 'document' or the like.
- godzillabrennus 11y agoSecurity is just an illusion.
- SixSigma 11y ago"We will make it more secure" no, you will make it less insecure.
- Kristine1975 11y agoEvery year a huge leak. 2015 it was HackingTeam, 2016 it seems to be the FOP.
- jimrandomh 11y agoIMPORTANT: This is a collection of files from an anonymous hacker including file formats such as docx that are known for carrying malware. Safe handling means opening them only on a virtual machine with nothing of value inside it and no access to your internal network. You have been warned.
- ryanlol 11y agoOh come on, we might as well start posting this warning every time someone links to any files on HN. In fact, websites are known for carrying malware. Especially considering that at the point where you have the docs you have already opened the torrent, and torrent clients are known for being super secure
- exhilaration 11y agoI think it's worth reminding people that there's a huge difference between harmless text files and MS Office documents that can carry all kinds of malware.
- ryanlol 11y agoDo we need a bot that posts the warning every time someone links to a .doc/.pdf/.whatever? And in any case, I'd be significantly more worried about the .torrent file...
- brazzledazzle 11y agoI don't think there's any harm in a warning for binary files distributed by someone who presumably broke the law to get them.
- mindslight 11y agoNor any harm in a warning for binary files created by people willing to break the law to protect their conspiracies.
- ryanlol 11y ago
- ryanlol 11y agoHaven't dled the dump yet, but if it contains credentials some of them will probably work at https://email.fop.net/postfixadmin/users/login.php https://email.fop.net/postfixadmin/users/login.php cve-2012-0811 yo Clearly it's no wonder that these guys got hacked. See also: https://news.ycombinator.com/item?id=10990193 https://news.ycombinator.com/item?id=10990193 http://fop.net/servlet/util/util.jsp?cmd=id;uname+-a;cat+/etc/shadow&html=true&pass=secret http://fop.net/servlet/util/util.jsp?cmd=id;uname+-a;cat+/et... uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm),6(disk),10(wheel) Linux data.fop.net 2.6.18-407.el5 #1 SMP Wed Nov 11 08:12:41 EST 2015 x86_64 x86_64 x86_64 GNU/Linux root:$1$04KmnGtM$V0naSp94MiVAQUpoBH.fI1:16828:0:99999:7::: thanks to user thisisthepolice for the above ;) Edit: I sure hope it wasn't someone from here that turned the server off. That's, like, several felonies.
- sarciszewski 11y agoThat's illegal. EDIT: In case the OP gets rm'd: https://archive.is/fyHfC https://archive.is/fyHfC https://web.archive.org/web/20160128190623/https://news.ycombinator.com/item?id=10989900 https://web.archive.org/web/20160128190623/https://news.ycom... http://www.webcitation.org/6escqonB6 http://www.webcitation.org/6escqonB6
- ryanlol 11y agoYeah possibly, but this SHOULD be illegal: http://www.fop.net/servlet/listing/news_article?user_id=-1&nocache=1765055&XSL=xsl_pages/members/member_news_listing.xsl http://www.fop.net/servlet/listing/news_article?user_id=-1&n... Note the convenient "Admin Tools" button :)
- sarciszewski 11y agoWow what the fuck. Who programmed their website?
- ryanlol 11y agoA time traveller. (Just to clarify, from the past.)
- malchow 11y agoSpeaking as a taxpayer, it does not seem to me at all clear why collective bargaining agreements between public servants and city governments should be able to be private documents at all. We pay the bills, after all.
- eplanit 11y agoI agree. Collective bargaining for public workers is overall absurd, IMHO. It injects a layer (the union) between the voters/citizens and the public employees. We don't get to elect/control the union or see their dealings? BS!
- sbarre 11y agoEhh I think there is definitely a value in allowing a large group of employees to collectively negotiate as one entity with their employer (if only to ensure parity of resources & skills at the negotiating table) but the results should definitely be public (for public service employees).
- pc86 11y agoThe most commonly cited issue with this line of reasoning is that the root reason for private sector unions (massive power disparity between employers and employees) simply don't exist in the public sphere. Public sector employees often vote for or against their current bosses directly.
- hackuser 11y ago> Public sector employees often vote for or against their current bosses directly. That's a very weak bargaining position: Give us what we want or our members, a small minority of the electorate, won't vote for you in two years. Why should they be weaker than other unions?
- snomad 11y agoIt isn't just the vote of the membership. It is the dollars of the organization. In California, the California Teachers Union and SEIU are regularly 2 of the top 3 campaign spenders.
- tyingq 11y agoBookmarking this for future entertainment. I hope he got a dump of their emails...that's probably where most of the interesting stuff is.
- tyingq 11y agoIf it's helpful, here's a good overview of why I'm experiencing Schadenfreude over this: http://www.theatlantic.com/politics/archive/2014/12/how-police-unions-keep-abusive-cops-on-the-street/383258/ http://www.theatlantic.com/politics/archive/2014/12/how-poli...
- sbarre 11y agoUgh I got about half way through that article and had to close the browser because it made me so angry.
- geographomics 11y agoSeems rather impolite to be leaking all this data. Where's the benefit?
- nitrogen 11y agoI think this is a fair question. From other comments it sounds like there are union agreements that may not have been available before, and it can be argued that the public should know what their governments have contracted with police unions. Another item mentioned in other comments is what looks like a forum database dump, so people could find out what the police say about various subjects when they expect nobody to hear.
- deleted 11y ago[deleted]
- sarciszewski 11y agoIn case the main story goes down, here are several mirrors: https://web.archive.org/web/20160128183444/https://fop.thecthulhu.com/ https://web.archive.org/web/20160128183444/https://fop.thect... http://www.webcitation.org/6esai2UHY http://www.webcitation.org/6esai2UHY https://archive.is/https://fop.thecthulhu.com/ https://archive.is/https://fop.thecthulhu.com/
- apo 11y agoAnyone care to give a summary of what the data dump contains?
- raus22 11y agoYeah, is there a TL;DR version of this?
- dmix 11y agoI haven't downloaded it yet but it seems to be email and server(?) dumps from the FOP website. FOP = Fraternal Order of Police https://en.wikipedia.org/wiki/Fraternal_Order_of_Police https://en.wikipedia.org/wiki/Fraternal_Order_of_Police Additionally, the hacker made a Q/A-style blog post which will answer your questions: https://www.thecthulhu.com/fraternal-order-of-police-data-dump/ https://www.thecthulhu.com/fraternal-order-of-police-data-du...
- anigbrowl 11y agoThanks for this! I hate the FOP with a passion - it's a RICO as far as I'm concerned and I look forward to the day when its leaders are rotting in jail cells.
- deleted 11y ago[deleted]
- 5ilv3r 11y agoAh, so that's where they hid all that undisclosed evidence! Thanks, Ed!
- chippy 11y agoTen days ago he was in custody and released by the UK police (and Intelligence folks) https://www.thecthulhu.com/insurance-release/ https://www.thecthulhu.com/insurance-release/ Why? Possibly due to his release of his "insurance" dump - a dump containing unknown stuff. Why release this bigger archive after then? No idea but I'm not touching either with any type of stick!
- pjc50 11y agoDo we have any third-party reports on what happened there?
- Dan_JiuJitsu 11y agoWithout espousing an opinion one way or the other, I think the point that is most striking to me is the relatively civilized manner we're all discussing a contentious topic. Hat's off to hackernews readers for navigating tough issues with class!
- tiredofhtebs 11y agoThis planet will be pulverized by an asteroid before this 18TB is released in plain text for the entire world to freely peruse. The entire hacker/anonymous phenomenon is a complete fraud run by western intelligence/police agencies with the corporate media’s cooperation.
- tiredofhtebs 11y agoThis planet will be pulverized by an asteroid before this 18TB is released in plain text for the entire world to freely peruse. The entire hacker/anonymous phenomenon is a complete fraud run by western intelligence/police agencies with the corporate media’s cooperation.