10 ms·
Doxing the hero who stopped WannaCry was irresponsible and dumb
- custos 9y agoYeah, let's tell everyone everything about someone who partially foiled an organized crime operation. What could possibly go wrong?
- jlebrech 9y agothey came to the wrong conclusion that someone who bought a kill switch domain, would have been one of the hackers. when it fact the kill switch was firewall check (look for 502 rather than 404) and the person who bought the domain kill switched it for everyone. Sucky journalism strikes again.
- gadders 9y agoI saw that at the weekend. The guy did a good thing and obviously didn't want his name out there. It was a pretty shitty thing to do.
- mr_spothawk 9y agomaybe it's some sort of "parallel construction" payback motive
- krona 9y agoThere is a newspaper claiming he's now working with GCHQ. I doubt such information is true, but given what happened to Gareth Williams in similar circumstances, I'd suggest it's egregiously irresponsible for a newspaper to even suggest it given everyone now knows who he is.
- proaralyst 9y agoFor those curious as I was: https://en.wikipedia.org/wiki/Death_of_Gareth_Williams https://en.wikipedia.org/wiki/Death_of_Gareth_Williams
- poooogles 9y agoNever knew about the claims around the SVR, at the time it seemed way to convenient to be what the investigation claimed. And SIS/GCHQ wonder why they have such a hard time recruiting staff.
- Ntrails 9y agoI'm not sure this has any impact on the ability of the services to recruit staff, compared to things like compensation, or having to fill in "permission to socialise" forms... I don't think anyone much thought it was anything but an extremely suspicious death. In many ways matching almost too perfectly the imaginary world of Spies we like to watch/read about.
- sillysaurus3 9y agohttps://www.reddit.com/r/todayilearned/comments/6990kh/til_in_2010_an_mi6_spy_was_found_dead_his_naked/dh4r4vo/ https://www.reddit.com/r/todayilearned/comments/6990kh/til_i... -- It's definitely weird, but there's a reason (https://www.theguardian.com/world/2012/apr/25/mi6-gareth-williams-bed https://www.theguardian.com/world/2012/apr/25/mi6-gareth-wil...) that they considered this as a real possibility: > But his former landlady, Jennifer Elliot, told the inquest that three years before his death, she and her husband had heard Williams call for help at 1.30am from the annex flat he was renting from them in Cheltenham, where he worked at GCHQ. > They let themselves in with the spare key and found the codes expert lying on his back on the bed, in boxer shorts, with his hands tied to the bed posts with material so tight it had cut his wrists. > In a statement read to the inquest, Elliot said she and her husband had both been in shock. Her husband asked Williams: "What the bloody hell are you doing?" Williams told them: "I just wanted to see if could get myself free." > The statement added that he did not appear sexually aroused, and was "very embarrassed, panicky and apologetic." > The couple, who never spoke to anyone about the incident, said they concluded it was "sexual rather than escapology".
- tenryuu 9y agoI've had my shit doxxed by the media before, but fortunate enough they were kind enough to redact information on request. It was a very quick turn-around
- 1337biz 9y agoStory?
- tenryuu 9y agoJust a simple internet website prank that went viral with fake news. Was about three years ago now
- SideburnsOfDoom 9y agoI'd be extremely surprised if the Daily Mail did that.
- tudorconstantin 9y agoIf some journalists were able to find his identity, he can safely assume that the people behind wannacry are also able to do it. Maybe he'll take some measures to protect himslef more now. I would've liked to see the journalists find the hackers behind this. That would've been an achievement indeed.
- tonmoy 9y agoI would have liked to see a story from the journalists on how easy it was for them to find the guy and then they had responsibility alerted the person on those points w/o revealing his name (you know like what security researchers do)
- ConceptJunkie 9y agoSo you expect journalists to be something other than whores? Good luck with that.
- sctb 9y agoPlease comment civilly and substantively on Hacker News or not at all. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- tripzilch 9y agoA "slang" term for a perfectly legal profession (where I'm from) used in a derivative but substantive manner--it's obviously short for the phrase "attention whore" (which is really the main reason why you shouldn't have moderated this remark) and this type of journalist is doing it just for the attention to make money, which is relevant because it sheds light on their motivation behind their questionable actions. The phrase couldn't be more on-point, actually. Which leaves the "civil" part. Because he said "whore" instead of "prostitute". Certainly from now on, you'll be moderating people for using the ugly word "hacker" instead of "security consultant/researcher", right? It really (still) has the same bad name among people not well-acquainted with the biz. And no, it doesn't matter that some people chose to wear the "hacker" title with pride, because guess what? So do most whores. To add substantively to the discussion myself, here's an open question. I'm having a real hard time coming up with a phrase two words or less, that communicates this aspect of journalism as accurately as "attention whoring". How would you say it?
- golergka 9y agoI respect the intent of the article, but I feel that the author completely misjudges the intentions and perspective of the mainstream journalists and their readership. It looks more like a culture clash than malice. > MalwareTech doesn’t give out his name on his Twitter page or blog. There are no headshots. It’s obvious that he just wants to be left alone to get on with what he enjoys – hacking shit, and figuring out how stuff works. For a modern mainstream internet user, who sees that everybody goes with their real names and photo (except trolls), it's not obvious. > stalking other people’s Twitter and Instagram accounts How can reading information that people have voluntarily posted online for everyone to see can be called "stalking"? > The weird emphasis about his fondness for pizza, and how he works from a small bedroom in his parents’ place? That shows they don’t actually respect him, or what he’s accomplished. To me, it shows just that they were interested to paint a picture of a human being instead of just a username. I feel that HN audience is very used to talking to someone whom they know just by a nickname, with no personal details or information - but for the general public, the concept of "anonymous hacker" is not associated with anything good. > Why do I need to know his age, and that he enjoys pizza? Why do I need to know his name, or know what he looks like? Does anyone care that he enjoys surfing? It adds nothing to the story. Look at any NYT or Guardian longread about a complicated issue that touches a lot of people - instead of analyzing statistics (as I personally would prefer), they always include an individual story or two, with unrelated personal details, to make the reader feel "connected". Only logical to assume that, while to me, and probably, to HN reader, this is just irritating and distracting, that's what "general public" wants to read about.
- aphexbr 9y ago"for the general public, the concept of "anonymous hacker" is not associated with anything good" An association that's largely created by these tabloids in the first place. "that's what "general public" wants to read about" Maybe, but if that's what's required, they should be requesting an interview with him and only reveal what he agrees to reveal. If he wishes to, that could lead to a more insightful look at a man and his motivations rather than random paragraphs about pizza and surfing. If he chose not to reveal anything, a responsible journalist would accept that and understand that the man has reasons for wishing to stay anonymous. Not dig into his information and publish it anyway, leading to both him and his friends being needlessly harassed for preventing crimes. At the very least, this could lead to future would-be Samaritans from deploying fixes or publicly detailing their methods. At least they manages to increase their clicks with some facts rather than just making things up, I suppose.
- OwlsParliament 9y agoThe Telegraph, The Sun and the Daily Mail are utter shitstains.
- FluffyTheWalrus 9y agoGot to love the news! They just love throwing anyone under the bus..
- pferde 9y agoWell, it's been an adage for many years - names sell newspapers... I mean, clicks and ad views.
- beedogs 9y agoThis was mostly Murdoch's rags, which, unfortunately, many folks can't distinguish from actual newspapers.
- gadders 9y agoIt was the Sun, the Telegraph and the Daily Mail. Only on of those belongs to Murdoch.
- soundwave106 9y agoA better way to put it would be to say all of the UK tabloid papers (the Mirror was also mentioned in the article). Tabloid journalism doesn't exactly have a stellar history of responsibility. Unfortunately this sells for some reason.
- kingosticks 9y agoIs the Telegraph really a tabloid? It's hardly on the same scale as the others presented here (and in the article).
- soundwave106 9y agoThe Telegraph is a broadsheet, yes. However, I've seen some rumblings on the Internet that it used to be high quality journalism, but lately it had been going more downmarket of late. This is "Internet opinion" of course, so I'm not sure what the real truth is. That being said, if they are engaging in tabloid-style stunts like this these day, this would sort of confirm what I've read.
- Dolores12 9y agoThey failed to find creators of wanacry, so they found the guy that didn't hide and made him look like he did something bad.
- cpncrunch 9y agoNo, they presented him as a hero, because that's what he is, and that's what people want to hear about.
- Dolores12 9y agoDid you happen to read his tweets?
- cpncrunch 9y agoYes, just did. Did you read the articles? Certainly sounds like they're calling him a hero: http://www.telegraph.co.uk/news/2017/05/14/revealed-22-year-old-expert-saved-world-ransomware-virus-lives/ http://www.telegraph.co.uk/news/2017/05/14/revealed-22-year-...
- neogodless 9y agoThey may not use the term "doxxed" lightly, but they also don't provide a definition for it. I have no idea what it means. I guess it means "give credit by providing the name." Maybe?
- arundelo 9y agohttps://en.wikipedia.org/wiki/Doxing https://en.wikipedia.org/wiki/Doxing
- neogodless 9y agoAh - while it's technically slang, it is defined in the dictionary - https://www.merriam-webster.com/dictionary/dox https://www.merriam-webster.com/dictionary/dox My bad!
- sillysaurus3 9y agodox = reveal identity. Nothing more complicated.
- neogodless 9y agoThanks - I deserve a dig for not googling it. It's a pet peeve to see acronyms that aren't defined, but this is apparently a "common" word that I just happened to be oblivious to!
- lmkg 9y agoIt publicly releasing the IRL identity (name, address, etc) of the person behind an anonymous online identity. The term applies more to places like reddit/twitter/4chan than to someone's own blog, but it's generally considered a form of harassment because it's an invasion of privacy.
- neogodless 9y agoAh! I didn't realize it was an English dictionary word. I really thought it was an "inner circle" term that needed defined for the layperson. My mistake.
- stuffedBelly 9y agoIt’s obvious that he just wants to be left alone to get on with what he enjoys – hacking shit, and figuring out how stuff works No, he wants to be left alone because it endangers his life to reveal his identity. Jesus, do people seriously expect someone that's done heroic deeds like this to jump out and scream "I am Batman"???
- stagger87 9y agoThe author talks about this further down in the article.
- zitterbewegung 9y agoThe Media likes to have gripping headlines that create celebrities . Presenting a person as a Hero is a tried and true way to do this. Once you do that to a person the hazards of being a celebrity pop up . Doxxing from media and anonymous , people digging up dirt on you etc... it is an unfortunate situation and it's ruined many people's lives .
- urbanj 9y agoOK, let's doxx the journalists.
- throwaway_ques 9y agoWhat does "dug through a ton of OSINT" mean? Also can anyone point me to resources on preventing doxing while hosting a website? I want a checklist of things that can possibly leak my identity. For example: - Some basic stuff is use whoisguard and don't reuse any existing hosting / cloud infrastructure or even google analytics accounts - But for new accounts, does using real credit card information matter? I am not sure how easily a company will give that information up. For example how hard is it to social engineer or get a court order/subpoena for it? - Even then you can still be fingerprinted by ip, browser agent, hardware if you ever even log in with the same computer. For example HN certainly knows who my alts are just by checking request logs ip. - What about sharing similar coding style / code base? Or even just speech/writing patterns? Is NLP sufficiently advanced to fingerprint you by that yet? Are some of these too paranoid? I really think there's no way to fully prevent doxing for anyone sufficiently motivated. What's actually good enough in practice?
- m0tive 9y agohttps://en.wikipedia.org/wiki/Open-source_intelligence https://en.wikipedia.org/wiki/Open-source_intelligence
- MichaelGG 9y agoUse Tails or Whonix. Buy Bitcoin with cash via mail on Localbitcoins.com. Depending on your level of paranoia, don't use bills directly withdrawn from the bank/ATM.[1] Be careful to not get fingerprints/hair/traceable writing on the envelope. What I've done is ask someone at the store (buy a card/envelop at CVS or something) to write the address for you. With BTC-via-mail, the only thing you leak is a rough physical location. Running the coins through Monero or something should blind things and render all this moot, but hey just in case? With anonymized currency, then you're free to start signing up for stuff. If a site doesn't accept Bitcoin, use Localbitcoins.com to buy a prepaid debit card (Visa/Mastercard). If a site insists on a phone number for confirmation, use a darknet market to buy a pre-made Google Voice account. You can't access it over Tor or it'll get blocked, so use darknet markets to rent a Windows client box ($10-20 a month) so you have a "clean" IP and Google won't block you. Then it's a matter of not giving away your info. You should adopt an entire persona when you're doing anything related to your site. Come up with a backstory (name, location, etc.). Ideally, none of this would matter: You're over Tor and using an entirely separate system for everything related to the site. But from the indictments I've read, it seems like a lot of first steps in finding someone's ID are just going off small hints. The way they write, mentioning the weather, etc. I would assume it to be very effective to fake these things. (For instance, notice a flood in a part of the country. Stay offline during the flood. When you get back on, write a small note that you had to be away due to flooding.) None of this will protect you from an adversary that can correlate your home-connected-to-Tor times with site-gets-updated-times. But it'll stop people without that access, even if they're willing to fake a subpoena/warrant/etc. to your registrar/hosting provider (easier than you'd think). And hell, it doesn't always take a legal order to get those details; social engineering can do it just fine. The Whonix wiki goes into lots of details on all this: https://www.whonix.org/wiki/DoNot https://www.whonix.org/wiki/DoNot 1: I asked Wells Fargo and they claimed they don't keep track of serial numbers and have no way to do so, but it seems so trivial I wouldn't believe it.
- nl 9y agoWhile perhaps (probably?) all the criticism of the papers is justified I'd note that the subject of the doxing doesn't seem very concerned about it at all.
- ianai 9y agoI hope instead of focusing on the doxing, people focus on employing and protecting him from threats. You can't count on keeping a secret forever.
- cpncrunch 9y ago>To the hacks at The Telegraph, MalwareTech will always be some sad basement-dwelling hacker nerd. No, actually. They're showing that he fits into the archetypical British bedroom hacker/programmer genius, which is very highly respected in the UK, and produced the likes of Matthew Smith, David Braben, etc. It looks like the author of this article wasn't around in the 80s, so perhaps he's not familiar with this history. edit I fit into this category myself, and I'm not offended at all.
- powera 9y agoDespite all the claims of "major cyber-attack", what I see here was a virus that infected the entire British NHS, but otherwise had very little impact.
- asveikau 9y agoI agree with this article, but though I am no expert in this topic I do wonder how much the wannacry perpetrators would actually go after this guy. Consider: 1. The fact that it was disabled so trivially was ultimately their own fault. 2. As we have seen, it was easy enough for them to change the logic to remove the web request on the nonexistent domain and start spreading again. 3. Retaliation would not be without cost and risk. Acting on #2 instead is a less costly, less risky action.
- YeGoblynQueenne 9y ago>> The Telegraph talks a little bit about how he’s self-taught, and how he stopped WannaCry by figuring out it had a kill-switch. The reasearcher's blog (posted on HN earlier) said that although originally he thought it was a kill switch he now thinks it was just a clumsy attempt at detecting whether the worm was runnign inside a sandbox. Apparently, worms will often do that sort of thing- call out to an unregistered domain to check whether they get a response indicating that they're not really connected to the internet. Except the ones that do it right call out to some random domains and this one had it hard-coded (either because the creator of the worm was a numpty or because they forgot it) (and therefore, a numpty). So it probably wasn't a kill-switch in the sense of a failsafe, as it was reported in the press.
- Vera527 9y agoThis whole thing is not adding up. You would think that MalwareTech being the great "ethical hacker" that he is, that he would at least have information hidden and his identity hidden, but a simple DDOX was able to expose his identity. This does not add up. If you're part of the community,you would know better to protect your identity,unless you intend it to be exposed. Take me for example. I dare anyone to find anything about me. I dare you to even find my real IP address. This whole thing with WannaCry and MalwareTech seems like a publicity stunt. It is as if it all had been planned for, from the beginning. What if MalwareTech is the one responsible for WannaCry? He sure is, but it is hard to draw such conclusion, until you look at his Twitter account and his willingness to talk to the public, and his nonchalant attitude about being known in the public as the person who stopped a huge cyber attack. Anyone in his place would be freaking the fuck out,because anyone in the community knows not to mess with a hacker, let alone stop a cyber attack of presumably several hackers. MalwareTech is not scared,because there is no one behind the attack besides himself, and the whole thing is a publicity stunt. It's a hoax. He probably wants a job in California or somewhere in the US working with an antivirus company with a high salary. To that I say that he was clever in doing so.
- deleted 9y ago[deleted]
- pvaldes 9y agoIf we think about it, this is not much different than shouting publicly the name of a journalist infiltrated in a drug cartel. Terrible. Journalists should know better the game and what is at stake here.
- retrogradeorbit 9y ago"no good deed goes unpunished"