9 ms·
Interview with the Guy Who Tried to Frame Me for Heroin Possession
- yardie 7y agoI wonder how much of his personal information was gleaned from "respectable" American companies like Lexis-Nexis, Equifax, and Transperian? I'm sure they gave everything and medical history for the price of a few coins. I have no respect for companies that don't respect my privacy. And I make it a habit of giving them as much useless, inaccurate information as possible.
- chisleu 7y agoWho do you mean by "his"? Also, Krebs is a hell of a guy.
- srbby 7y agoA hell of a guy who doxes people he doesn't like on Twitter.
- Craighead 7y agoA statement devoid of context intended for shock value is better off not said.
- srbby 7y agoI was expecting people on this website to be sufficiently skilled with computers as to being able to use google dot com
- mieseratte 7y agoWhat shock-value do you speak of? Cursory Googling[0][1] reveals that Mr. Krebs is quite possibly not above reproach. Is there something else that needs to be said about the situation? [0] - https://hacked.wtf/2019/04/26/dear-brian-krebs-no-more-doxxing-as-a-result-of-a-disagreement-please/ https://hacked.wtf/2019/04/26/dear-brian-krebs-no-more-doxxi... [1] - https://www.itwire.com/security/86867-infosec-researchers-slam-ex-wapo-man-krebs-over-doxxing.html https://www.itwire.com/security/86867-infosec-researchers-sl...
- jchw 7y agoThis is a bad hill to die on. There are two sides to that story.
- deleted 7y ago[deleted]
- yardie 7y ago> Vovnenko first came onto my radar after his alter ego Fly published a blog entry that led with an image of my bloodied, severed head and included my credit report, copies of identification documents, pictures of our front door, information about family members, and so on.
- kerkeslager 7y ago> And I make it a habit of giving them as much useless, inaccurate information as possible. How do you do this? (Specifically, with the companies you mentioned.)
- oyebenny 7y agoI would like to know this as well.
- ryanlol 7y agoEasy, you just lie when people ask. Apply for store loyalty cards and similar with fake information to get that associated with your data broker profiles. You could also open phone lines with fake information, ISP accounts and so on. A good investigator with expensive access will still be able to track you down, but automatically exploiting your data will be much more difficult if it's a mess.
- kerkeslager 7y agoWe're not talking about just any data brokers though, the parent comment mentioned credit bureaus specifically. I'm not a lawyer, but if you're applying for a line of credit with false information, I'm pretty sure that's a crime. If you're not applying for a line of credit, I don't think credit bureaus such as Equifax or "Transperian" (which I assume is a portmanteau of TransUnion and Experian) will base anything on that data, since it's so obviously easy to manipulate.
- ryanlol 7y ago>I'm not a lawyer, but if you're applying for a line of credit with false information, I'm pretty sure that's a crime. I'm definitely not a lawyer, but unless your intent is to defraud I wouldn't be so sure about that. I also don't see how you'd ever end up getting prosecuted for this unless you really piss someone off, in which case I guess you could get prosecuted for just about anything. In any case, whether or not this is legal seems utterly irrelevant. >If you're not applying for a line of credit, I don't think credit bureaus such as Equifax or "Transperian" (which I assume is a portmanteau of TransUnion and Experian) will base anything on that data, since it's so obviously easy to manipulate. You would be wrong. That'd be an awful way to maintain up-to-date address data on people. Besides, the first company named was "Lexis-Nexis".
- ryanlol 7y agoWell, they were specifically posting a branded Accurint report for Krebs in the lampeduza (IIRC) thread.
- staticautomatic 7y agoThose vendors' reports cost $10-$20 and contain no medical records.
- Breza 7y agoI'm currently working on a batch of information requests about myself to different data brokers and alternative credit reporting firms. I send a copy of my drivers license and a recent utility bill and they send me my records for free. It's shocking what I found the last time I did this.
- deogeo 7y agoDig up the personal information of their owners, board members, and major shareholders, and publish or sell it - an eye for an eye.
- brodsky 7y agoI'm not sure it's possible to "give" inaccurate information to Equifax.
- creditReport1 7y agoI work at one of the big 3 credit bureaus so thought I’d chime in - It is entirely possible to report inaccurate information to the bureaus. Although more often than not it’s on accident, not malicious. Additionally bureaus collect a lot of information from other sources. Some public some private. It’s possible for these datasets to be error prone themselves. There are however official procedures for disputing/correcting errors in reporting and in my experience they do a pretty good job of validating everything (as that’s literally the business they’re in)
- yardie 7y agoOur son (10 yo) had a delinquent medical bill for reasons we don't understand. The creditor can't tell us who sent the bill because we aren't the named party and I'll be damned if I put him on the phone with them, because he is a minor. So, we're at an impasse and no one can tell us anything. Someone managed to get his name and address and did not realize he was a minor. Brilliant system you have!
- dekhn 7y agohire a lawyer and write a letter. You're not at an impasse. You can have this cleared, if they don't have evidence and you write a letter, they have to shut it down.
- yardie 7y agoI'll do no such thing. Someone else made a mistake and therefore I have to pay a lawyer to fix it? It's not a legitimate debt, but it goes to show how anyone can put anything in anyone's file and these information brokers will suck it up and pass it around without even the most basic sanity checks. The FCRA was a good start but an American GDPR would be better.
- darkwater 7y agoOuch, Poggioreale is not a nice place to be in.
- cpach 7y agoWhy?
- darkwater 7y agoBeside living side by side with people from the camorra ("camorristi"). This is a letter to an italian newspaper about living in Poggioreale (in italian) https://www.corriere.it/cronache/13_luglio_28/detenuto-poggioreale-lettera-sulle-carceri_735836e4-f760-11e2-a852-8fa32bcbd2fe.shtml https://www.corriere.it/cronache/13_luglio_28/detenuto-poggi...
- deleted 7y ago[deleted]
- coldcode 7y agoIt's interesting that the "hacker" himself was caught via hackery. When I worked on anti-cheating stuff for a game company, I was able to stop the seller of the cheat because their cheat had been stolen and resold so they had to put anti cheating tech in their cheating tech and it opened a hole I was able to exploit to detect them.
- cloverich 7y agoWould you consider writing this up? Sounds fascinating.
- metalliqaz 7y agosounds more like they had to put anti-piracy tech in their cheating tech
- reificator 7y agoImagine you're selling a tool that lets players win every game. Then imagine someone else starts selling another tool. Anyone who buys that other tool is now able to beat the players you promised a win to, AND they're not giving you any money for it. This damages your reputation, which in an underground market is probably your most valuable resource. So not only are they not paying you, but they're robbing you of future sales by damaging your rep. Wouldn't you put in something to prevent users of your newest cheat from being cheated themselves?
- newnewpdro 7y agoNo different from Google blocking "spam" while simultaneously targeting and delivering ads...
- TazeTSchnitzel 7y agoSuggests something about honour among thieves.
- burtonator 7y agoLive by the sword, die by the sword. I low how they cheat steal and are upset when other people cheat and steal.
- spoovy 7y agoWhy on earth would you marry someone you don't trust??
- mirimir 7y agoDamn. It does seem that stupid mistakes took him down. Revealing too much about himself on his forum. I mean, if he'd been careful, compromise of that forum would have revealed nothing about him. And for Dog's sake, using the same password on low- and high-security accounts! Of course, the real story could be hidden through parallel construction. But on it's face, this does support the argument that it's stupid mistakes that take people down. Krebs' blog is full of them. Edit: And just to be clear, I'm not even suggesting support for that Ukrainian dickhead. It's just that criminal takedowns are well reported, and so provide cautionary lessons for the rest of us.
- xoa 7y ago>Damn. It does seem that stupid mistakes took him down. One possibility on the "cautionary lessons for the rest of us" front is a classic bit of wisdom about asymmetric adversarial situations: the other party only needs to get lucky once. There is a fundamental challenge of scale and time for any entity or individual that tries to run something dealing with persistent antagonists over long time periods, it just plain becomes hard to keep track of it all without further infrastructure systems in place. And its also hard for any single human to stay in the zone persistently, we're not really wired that way, hence the need for non-human support structures. And that in turn is the same challenge for any business dealing with significant organic growth, criminal or not, it's the classic "that TOTALLY TEMPORARY one-off excel spreadsheet someone made 15 years ago now runs hundreds of millions of dollars" issue. It's hard to know ahead what will be important and sticky or not, even if experience helps. And it's hard to decide how to allocate limited resources too. Infrastructure you build helps you scale properly in the future, but it doesn't do anything for you right now, you might not even know you could need it. And overbuilding upfront might mean there is no tomorrow to worry about anyway. It's a tough nut, though fortunately it's one area that is probably worse on the black side of things since there is less room for recovery from mistakes. Maybe it's one of the structural forces that can help encourage law abiding behavior, legit companies can mess up badly but still potentially recover if there is enough meat to them, whereas a total opsec break for criminals can mean the end of the enterprise.
- mirimir 7y ago
- celim307 7y agoSo this guy picked OP completely at random? I wonder why he was initially targeted
- yellowarchangel 7y agoThe most important and missing information at the start of the article is _why_ the OP had their information posted on the forum, why they were getting sent this package.
- dotancohen 7y agoOP is a very well known security researcher. Here is his self-bio: https://krebsonsecurity.com/about/ https://krebsonsecurity.com/about/
- sedachv 7y agoHere is a link to the original interview, since neither Krebs nor the people that made the translation seem to believe in citing their sources: https://krober.biz/?p=3200#more-3200 https://krober.biz/?p=3200#more-3200
- JetSpiegel 7y agohttps://krebsonsecurity.com/wp-content/uploads/2019/09/Interview-with-Mukha-aka-Fly-1.pdf https://krebsonsecurity.com/wp-content/uploads/2019/09/Inter... Here's the translated PDF. Either the original Russian was hacked up already, or this translation is very iffy.
- kspacewalk2 7y agoThe original is full of barely comprehensible jargon, obscure code-speak, intentional spelling mistakes, etc.
- Haga 7y agoThe scary part is that you have to be this active to prevent false charges.