56 ms·
Tampa teen accused of being ‘mastermind’ behind Twitter hack
- montenegrohugo 6y agoIf this turns out to be true, then we can conclude two things: 1. It's incredible that the security of Twitter allows for a solitary 17-year old to gain full access to (any) account. 2. This also explains why the profit of the hack was 'only' ~$100k. Many speculated about how incredibly valuable such a hack could be and how much more a group could have profited from this hack. Using it for two hours of bitcoin scamming seemed very amateurish. I suppose this explains it.
- happytoexplain 6y agoFrankly, I don't take "a teenager did it" as an extra mark against hacked systems any more. It's the details that matter - the difference between one teenager and multiple adults being able to hack something is not large unless the context is government hacking.
- lima 6y agoMaybe in terms of raw skills, but adults are likely to have more experience, better judgement and better opsec.
- dagmx 6y agoNot to mention likely have better access to hardware and other resources
- cle 6y agoThis works against them in many ways. They're also more likely to say "that wouldn't work", and to be otherwise biased by their prior experience.
- jayrice257 6y agoBut having no experience also can work against you in giant ways like leading to dead ends and hurdles you don't know how to overcome. Overall there's not a good argument that it's a better position for an individual to be in for success.
- tornato7 6y agoYes, a teenager, especially one stuck at home and not going to school, might just spend weeks and weeks poking around to see what he can hack, and is much less afraid of the consequences
- YinglingLight 6y agoWhat does the hack provide? Credible deniability for all VIPs involved for all DM's they've ever made. "I was hacked back in July 2020!"
- hentrep 6y agoMy initial thought was that the bitcoin move was a red herring. DMs associated with the compromised accounts could be very well worth much more than $100k.
- letier 6y agohttps://twitter.com/twittersupport/status/1286088135525318656 https://twitter.com/twittersupport/status/128608813552531865... https://www.theguardian.com/technology/2020/jul/23/twitter-hackers-accessed-dms-of-up-to-36-accounts https://www.theguardian.com/technology/2020/jul/23/twitter-h... "We believe that for up to 36 of the 130 targeted accounts, the attackers accessed the DM inbox, including 1 elected official in the Netherlands." You might be on to something.
- nonsapreiche1 6y agonever underestimate the intelligence of a teenager!
- pcunite 6y agoImagine what a russian could do.
- Ericson2314 6y agonyt 2025: Chinese-russian teenager gets donald trump elected in every single country using birth certificate 2fa
- logicslave 6y agoThat you nancy pelosi?
- chasd00 6y agoNever overestimate the intelligence of teenager either. I say this as a former teenager
- unishark 6y agoHow are we supposed to get an exact estimate of their intelligence then?
- ggggtez 6y agoThe Krebs article says that prior to the bitcoin hack, they were selling accounts such as @6 for $2000. They probably had a rapidly shrinking window and the bitcoin scam was the last ditch effort before whatever admin account they hijacked got discovered.
- imgabe 6y agoPeople did say things like you could have made a fortune shorting stock by tweeting something insane from Elon Musks account. I don't buy that as necessarily better than a Bitcoin account. Stock transactions are heavily regulated and monitored. You'd leave a pretty large paper trail of any stock manipulation you hoped to profit from. Of course Bitcoin is highly traceable as well, so maybe the lesson is hacking into high-profile Twitter accounts just isn't as profitable as you'd hope?
- woutr_be 6y agoIf they knew up front they would be doing this, they could’ve shorted Tesla in smaller positions, over multiple accounts. There’s tons of people shorting Tesla, would it really be traceable to any of those?
- vkou 6y agoYes, because the SEC isn't stupid, and would trawl through the data, until they found: * A set of freshly opened accounts. * That only shorted a single stock. * Right before a major hack. * That cashed out all at once. * That never traded again. And then they'd start calling the owners of those accounts, and asking questions. Most of those accounts would be legitimate traders, but that's fine - there's not that many accounts that satisfy four of those five criteria. A few sql queries can narrow it down to the point that basic detective work can solve the rest. The problem with playing stupid games on the stock market is that there's a very clear paper trail that will link you, as a human being, to the money that you're hoping to make. At least with bitcoin, you can theoretically isolate yourself from the source of the funds, through tumblers, transferring money in and out of shady exchanges, etc. This is also exactly how the SEC catches insider-traders. By analyzing the flow of trades, and following up on suspicious ones. If the first and only trade you've ever done in your life is a $200,000 short[1] on your employer twenty minutes before a disastrous earnings, you might soon be talking to a very nicely dressed man who would love to get another conviction under his belt. [1] If you think you're playing 34-d chess, and have done a bunch of other options trades surrounding it, to disguise it, you're just as likely to piss away all of your money before you even get a chance to insider-trade. That's the beauty of options - they will part a fool from their money before they can spit.
- 2OEH8eoCRo0 6y agoWasn't social engineering involved? It could simply be a numbers game. Twitter is no doubt probed daily by attackers and one managed to get through.
- syshum 6y agoI would add 3. People need to stop using "Trust <<insert large company>> instead of self hosting because they have teams of security "experts" and will have far better security than you ever could on your own"
- ehsankia 6y agoWasn't there one more person involve (Kirk#5270) who apparently did most of the work and let these kids do the work? Sounds like a MafiaBoy situation, where more experienced hackers did the work and let younger script kiddies take the fall for it.
- dyslexit 6y agoIt's implied that the 17 year old is kirk
- dehrmann 6y ago> 1. It's incredible that the security of Twitter allows for a solitary 17-year old to gain full access to (any) account. Someone else spoke to him being a teenager as not especially relevant, and I agree; it dismisses teenagers somewhat. You're also falling for a selection bias. Twitter is a big target and likely stops attacks like this daily. This is just the one that got through, and probably more because of luck than skill.
- peroporque 6y ago...and 3) if a teen can do it, then so can every intelligence service in the world. Just that they would probably stay quiet for years and years and gather data of "interesting" people.
- m90 6y agoMeta: this link is not accessible from within the EU.
- maxton 6y agoYou can probably read the article via the outline version: https://outline.com/https://www.wfla.com/news/hillsborough-county/tampa-teen-accused-of-being-mastermind-behind-twitter-hack-that-targeted-high-profile-accounts/ https://outline.com/https://www.wfla.com/news/hillsborough-c...
- m90 6y agoThanks, didn't know outline worked around such issues.
- rapnie 6y agoBlocked with "Our European visitors are important to us" Edit: http://archive.is/caOFK http://archive.is/caOFK
- macinjosh 6y agoplay stupid games (GDPR), win stupid prizes (geoblocks). welcome to earth.
- AlexandrB 6y agoplay stupid games (non-consensual tracking), win stupid prizes (GDPR). welcome to earth.
- closeparen 6y agoWhy would a local TV station in a random US city bend over backwards for Europeans?
- strictnein 6y agoI've been wondering about that for a while. Two possibilities (although there are obviously other possibilities): 1. I think a lot of news media was given bad legal advice about GDPR 2. They're all members of the AP and the AP required this of their members since they also work in the EU
- totetsu 6y agoFlorida Man masterminds twitter attack.
- bluedevil2k 6y agoMan = kid. He's only 17. I'm not a lawyer, but I thought it was illegal to put the names of minors in public for committing crimes.
- NoNotTheDuo 6y agoThey've updated the article in the last 5 minutes. The original article I read said something like "we're not releasing his name because he's under 18 years old" and now his name is fully out there. Crazy.
- 27182818284 6y agoWell apropos the grand-parent comment using "Florida Man" We hear about "Florida Man" more often because, yeah, maybe there is a lot more partying in Florida, but also because Florida has some of the most open public record laws. I've read that unlike other places where you have to bother the police for reports, in Florida you can get yourself added to a daily email blast of reports.
- fernandotakai 6y agothe verge is reporting that he's being tried as an adult, so maybe that's the reasoning. https://www.theverge.com/2020/7/31/21349920/twitter-hack-arrest-florida-teen-fbi-irs-secret-service https://www.theverge.com/2020/7/31/21349920/twitter-hack-arr... >He’s being charged as an adult, and the press conference made clear that law enforcement is considering how bad consequences of the hack could have been — not just the $100,000-plus in bitcoin that the teen is alleged to have scammed out of unsuspecting Twitter users.
- knolax 6y agoCan't even buy a cigarette but he's being charged as an adult. The court system needs reform.
- bluedevil2k 6y ago> the scheme reaped more than $100,000 in Bitcoin in just one day That's actually...pretty disappointing. I would have guessed into the 7 digits just based on how many Americans, and people in general, love a get-rich-quick-scheme.
- gkoberger 6y agoSummary for Europeans who are blocked from this site: A Tampa teenager, 17-year-old Graham Clark, is in jail, accused of being the “mastermind” behind a hack on the social media website Twitter that caused limited access to the site and high-profile accounts. The state attorney's office says the scheme to defraud “stole the identities of prominent people” and “posted messages in their names directing victims to send Bitcoin” to accounts that were associated with the Tampa teen. According to the state attorney, the scheme reaped more than $100,000 in Bitcoin in just one day. (The rest of the article just rehashes the attack.)
- Rebelgecko 6y agoIt will be interesting to learn more as the case proceeds. Was he not using tor? I'm actually not super surprised that they've arrested a teenager. Considering the thoroughness of the hack, just using it to scam a few bitcoins seemed a bit blasé. Imagine the shitshow he could've started by tweeting as Trump
- grezql 6y agoTrump is a "protected" account in twitters internal system. Even Twitter employees cant access such protected accounts.
- eunos 6y agoBut Biden's account wasn't? Quite peculiar considering the upcoming election.
- jacquesm 6y agoNot all of them can, but some of them can. For instance the people that could reset that 'protected' status. It certainly won't be the tooth fairy doing that, a Twitter employee is much more likely.
- danso 6y agoIt's weird that Musk's didn't have elevated privileges. Trump's account getting hacked has obviously greater potential harm, but Musk's (non-hacked) tweets had demonstrably major financial and legal impact. And if you read the replies to his tweets, you can see they are constantly getting spammed by bitcoin-hawking accounts (even hacked verified accounts) impersonating Musk's display name and avatar. If Musk didn't get elevated privileges, then who else besides Trump would have them? Or are the protections for Trump just the same emergency bespoke fix that they implemented when his account was previously deleted?
- ziddoap 6y agoI was under the (apparently false?) assumption that under-18s couldn't be named. The alleged mastermind here is 17, yet is named and pictured. Interestingly, when I first checked this out ~8 minutes ago, they stated that they would not name the alleged mastermind due to the fact he was under 18. In the update ~4 minutes ago, they have removed that section and named him.
- henryfjordan 6y agoFlorida has some of the most permissive laws about mugshots and criminal info. The reason for the "Florida Man" meme is not that people in Florida are more weird than anywhere else, just that it's easier to find the mugshots online.
- Jestar342 6y agoI always thought this was for precisely the oppposite - i.e. that news headlines (edit: I mean whole articles) were more often "A Florida Man has been arrested" because they were not allowed/didn't have the names.
- henryfjordan 6y agoI think using the term "Florida Man" is a meme now and probably carries more weight than using the accused's actual name. From the wikipedia article: > Miami New Times claimed that freedom of information laws in Florida make it easier for journalists to obtain information about arrests from the police than in other states and that this is responsible for the large number of news articles https://en.wikipedia.org/wiki/Florida_Man https://en.wikipedia.org/wiki/Florida_Man
- Jestar342 6y agoI understand now, the headline reads "Florida Man arrested" and then the article will have "Bob Bobbinson was arrested today for ..."
- J5892 6y ago
- foobaw 6y agoWonder when we'll get details on how he was actually able to do this - like how he got access to the internal tools, how did he succeed in social engineering, etc
- _jjkk 6y agoThey did provide a little detail so far [1]. > Hackers called a “small number” of employees in a phone spearphishing scheme, Twitter tweeted from its support account... The hackers were able to access some internal tools from the initial targeted employees and then learned specifically who had access to account support controls and targeted them next. One likely scenario is they got access to the lower level employee's Slack account or similar and used it to impersonate and successfully find/phish the employee with the access. [1]: https://www.washingtonpost.com/technology/2020/07/30/twitter-hack-phone-attack/ https://www.washingtonpost.com/technology/2020/07/30/twitter...
- ipunchghosts 6y agoI find this hard to believe.
- almost_usual 6y agoIt doesn’t fit the narrative a lot of people expect or want to believe but it’s probably true.
- korethr 6y agoInteresting to see that he's being charged in Florida, instead of federally. I mean yes, normally, when one commits a crime in a particular area, they're charged in that area. But my understanding is that once stuff crosses state lines, it becomes a federal issue, and this is part of why its usually the FBI that comes knocking.
- hughw 6y agoI would think federal charges will follow.
- ja27 6y agoAnything involving a computer connected to the internet (even firewalled or rarely connected) is considered to be a "protected computer" since it is involved in interstate commerce or communication and thus open to federal charges under 1030 (a).
- korethr 6y agoExactly. Thus why I am somewhat surprised to see that he's being charged in Florida. By the letter of the law, this is an issue for the feds to handle. Edit: Another post on HN[1] covers the federal charges. So, it sounds like this kid is being charged by both the state and the feds. I don't envy him. 1. https://news.ycombinator.com/item?id=24012968 https://news.ycombinator.com/item?id=24012968
- m3kw9 6y agoHope he’s not charged as an adult. I’m not getting the reasoning behind it.
- fataliss 6y ago"Florida (young) man" - the saga continues!
- amrrs 6y agoNo where in the article it mentions how did they nail him or how did he do. With Twitter saying that this entire process was done by social engineering some employee and then gaining system access of others by monitoring the process - this seems to have been done by someone with Corporate process understanding and hard to believe it could be a 18 yold.
- ceejayoz 6y agoSocial engineering is well within the capabilities of many 18 year olds, and plenty of them will have experience with corporate-style processes at school.
- devenblake 6y agoIt's doubtful that he actually did it. Probably just a teen groomed by a cracking group; the group gets away with the deed by leaving a paper trail pointing to the teen (that will get a reduced prison sentence) and the teen gets PR which will inevitably lead to a well-paying job.
- bdamm 6y agoI'm with you on this, he's probably a fall guy who's "caught" because he "confessed" or something like that. Two reasons for this; one, Twitter isn't exactly the kind of joint you stroll into and take over, it's not really an amateur operation and people are attacking it all the time. Second, coordinating all this work is not a simple one-person job. The timing of the attack suggests lots of coordination, practice, or both. Could one kid do it? Maybe, but highly improbable. And if it turns out this kid did do it, the CIA is going to find a way to own his ass basically forever.
- jacquesm 6y agoIf you are not 100% perfect in your opsec as a wannabe hacker you will get caught. It takes just one small slip-up.
- pier25 6y ago
- cellis 6y agoI actually think this kid has a bright future. My prediction: 1 year jail time, 5-10years probation. Will get hired as a security consultant.
- Romanulus 6y agoUnless he's ordered to stay away from computers for that time.
- dlhavema 6y agoAnd then he'll join up with Acid Burn to take down some skateboarding CEO...
- fortran77 6y agoI wouldn't hire him. It's not like he _programmed_ his way in. And he didn't just post tweets saying "Twitter's security is bad." He actively tried to scam people. So he wasn't trying to accomplish anything good.
- almost_usual 6y agoProgramming is a waste of time if you don’t need a program.
- Biganon 6y agoTrue, but what tech company would benefit from the social engineering skills of a young man with dubious morality? If at least he had proven to be the new Mitnick, but he hasn't.
- deleted 6y ago[deleted]
- pengaru 6y agoIt may make sense if you consider it more as a marketing hire. Such a person at least has potential for future interviews and talks one could leverage for increasing company visibility.
- jacquesm 6y agoThat didn't require a mastermind. Twitter crew were lucky this ended the way that it did. It could have been much worse.
- slackwill 6y agoZero Cool man.
- slackwill 6y agoZero_Cool man
- jermier 6y agoProbably could have earned a lot more from his exploits if he went the formal route and directly confronted Twitter. But then who even knows if Twitter are a good 'first responder' when it comes to high-profile exploits of their system. There was a recent post about some researcher who exposed flaws in Tor's architecture (which allowed third parties to detect Tor traffic easily) and Tor's staff didn't respond; so she published the finding without going through the proper channels, both embarrassing Tor staff, and simultaneously strengthening the Tor network. The 'I'm going to publish this sploit because you didn't respond' is a good tactic and I want to see more people do it. It's just unfortunate that the various channels like HackerOne[0] or wherever the skiddies flock to these days are not utilized thoroughly. [0] https://www.hackerone.com/ https://www.hackerone.com/
- gruez 6y agodoes hackerone cover social engineering exploits? I doubt it.
- MattGaiser 6y agoThey should. You should get $200 if you can get an employee's password.
- dane-pgp 6y agoI'm wondering what the objection is against this. There might be a conflict of interest in allowing an employee to share a bounty with a friend by giving the friend their password, but the rules of the bounty (and the employment contract) should be able to prevent that scenario. In theory, any sensitive operation (such as changing the email address of a verified account) could be made to require approval from a second (randomly chosen) employee, and that second employee should see a log of recent actions taken by the first employee. An attacker may still manage to avoid raising suspicion for the first few targets, though.
- thaumasiotes 6y ago> You should get $200 if you can get an employee's password. That's never going to fly; all Twitter bounties are multiples of $140.
- sergiotapia 6y agoIf only he would have done it for the lulz he would be badass. By asking for bitcoin he became a tool scammer.
- MattGaiser 6y agoGiven how many of these attacks have been social engineering ones, companies might benefit from having bug bounties for employees who get fooled. Yes, this will initially be very expensive as there will be thousands of payouts, but eventually the employees will learn. Offer $200 if you can get an employee's password.
- HumblyTossed 6y ago> The day after the hack, White House officials were concerned about President Donald Trump’s Twitter account, which he uses daily to push out news and other information. They assured the public that his account has extra protections. Really? Like what? And why? Are they afraid someone will start posting stuff that is actually TRUE?
- ideals 6y ago(If this is actually the person behind the attacks) Yes he may serve jail time for this, but he did get to read DMs of some of these people, and has had enough time to copy those contents to be read later. That's still valuable knowledge, he should leverage this to get people interested in those details to fund his legal defense in return for providing the contents of the DMs. Or is that illegal?
- tptacek 6y agoYes, that would be pretty illegal.
- idlewords 6y agoBut then he can do it again to pay for the second legal defense
- deleted 6y ago[deleted]
- akerl_ 6y agoThis is just as viable as selling stolen diamonds to fund your defense for robbing a jewelry store. It turns out that the legal system is already set up to make “selling illegally obtained material” also illegal, and to take notice of people doing so in order to fund their ongoing operations.
- GlTChWhISKY 6y agoMy thoughts go to the fact they were able to hunt someone down based on their bitcoin address. Either they got help, this kid was already being watched or it just speaks to the DOJs data collection to all citizens.
- ahmedalsudani 6y agoThe kid probably did not practice good OpSec. A single slip is all you need when you attack is so high-profile.
- stimpson_j_cat 6y agoThey don't say they were able to hunt someone down based on their bitcoin address
- p4bl0 6y agoThis is all I can see on this page : This site is currently unavailable to visitors from the European Economic Area while we work to ensure your data is protected in accordance with applicable EU laws. It should not be this complicated to respect laws that just enforce minimal good practices. A replacement link should be found for this story. Wfla dot com is clearly shit.
- thelean12 6y agowlfa is a super local US news station. Why would they put any effort at all to be compliant in Europe? Hell, they could be currently compliant and it still wouldn't be worth the effort to figure that out.
- detaro 6y agoMultiple people already have posted alternative links in the comments. Use those, and note that this kind of complaint is off-topic according to the site rules.
- soared 6y agoOr... like 2% of their readers are from Europe and the publisher is likely struggling for revenue so they’ve opted to focus on other things?
- cheez 6y agoI do the same thing on my business site.
- ColanR 6y ago> It should not be this complicated to respect laws that just enforce minimal good practices. It's not necessarily the compliance that's the issue, it can also be figuring out how to comply. IANAL, and I can't guarantee to myself that I can implement a site with policies that comply correctly. Better to just geoblock, because it's not necessarily worth the lawyer fees.
- sunilkumarc 6y agoOn a different note, online presence is becoming very important and with remote work culture gaining traction, having a good online presence has become a must have asset. I bought a course on building Twitter audience and been able to improve my following significantly from past 2 months. Twitter link: https://twitter.com/sunilc_ https://twitter.com/sunilc_ If you're looking to increase your social presence too, here's the course that I found very useful: https://gumroad.com/a/238777459/PBkrO https://gumroad.com/a/238777459/PBkrO
- pojntfx 6y ago"Our European visitors are important to us. This site is currently unavailable to visitors from the European Economic Area while we work to ensure your data is protected in accordance with applicable EU laws." nice
- kube-system 6y ago[cost of compliance] > [revenue from EU visitors]
- georgiecasey 6y agoAnd I don't blame the site at all. Another stupid rule from the EU preventing me from reading articles.
- giomasce 6y agoThe rule is not preventing anything. The website is redirecting your requests on a static page.
- Akronymus 6y agohttps://outline.com/ https://outline.com/ You may find this site helpful
- incomplete 6y agohttps://archive.is https://archive.is another option
- segfaultbuserr 6y agohttps://web.archive.org https://web.archive.org
- twhb 6y agoA man has a hotdog stand that he never cleans. One day, a health inspector comes by and tells him that unless he cleans his grill every day, he can’t keep selling hotdogs. The man shouts “I’ve never cleaned the grill in my life! It’s impossible, nobody does it! And who’s going to pay for the cleaner and the five minutes every day, me? No, I’ll just go sell my hotdogs somewhere else.” And he leaves. Later a regular comes by, sees the missing hotdog stand, hears it happened as a result of the health inspector’s visit, sees that other people are now eating the man’s hotdogs while he can’t, and thinks “Man I’m hungry. Screw health inspectors.” Taking care of people can be a thankless job. Here are a dozen healthier options: https://duckduckgo.com/?q=graham+clark&t=osx&iar=news&ia=news https://duckduckgo.com/?q=graham+clark&t=osx&iar=news&ia=new...
- bawolff 6y agoI'm not really surprised. * the attacker (allegedly) bragged to the press * the attack only involved phising and social engineering. (Its a bit unclear, but that's what it looks like) Bragging to the press is a definite sign of someone doing it for the lulz. Criminals know better than to brag about their crimes publicly, that is how you get caught. Bragging definitely fits into the sterotypical motivation for most teenage hackers. Social engineering is a skill, but its also a skill that a smart teenager is likely to have. Its not a super high sophistication attack. Its not a spy movie attack where people are breaking into offices, coercing employees, finding 0-days in the webserver etc. Its an attack that a dedicated teen could teach themselves and pull off themselves, no special resources needed.
- tantalor 6y ago> Its not... coercing employees How do you know? Coercion is a type of social engineering.
- bawolff 6y agoAll i know is that nobody has yet to claim that. I suspect he would be charged with something related to that if he did, but you're right we dont know the details of what he did precisely.
- js2 6y agoWhen I was a teen I made long distance phone calls using calling card numbers that were not my own, obtained through a war dialer. I'm pretty sure I never would've gone as far as this kid did, but who knows. I hope this doesn't ruin his life.
- psanford 6y agoKevin Mitnick seems to be doing just fine now.
- hentrep 6y agoOff topic, but the linked WFLA video highlights how factual reporting takes a backseat to an insidious "breaking news", headlines-first approach. Twice we hear Mr. Buinno misstate the Twitter attack as occurring "a few months ago" before being corrected by his colleague after the second instance. I realize this is a trivial criticism, but it makes one question their general preparation and fact-checking processes. Is it too much to expect alignment on the basic details of a story before broadcasting it to hundreds of thousands of people?
- dariusj18 6y ago> The two other suspects were identified as 22-year-old Nima Fazeli, a.k.a. “Rolex,” of Orlando and 19-year-old Mason Sheppard, a.k.a. “Chaewon,” of the United Kingdom.
- asutekku 6y agoThe third person has been identified in an Ars Technica article [1]. 1. https://arstechnica.com/tech-policy/2020/07/florida-teen-arrested-charged-with-being-mastermind-of-twitter-hack/ https://arstechnica.com/tech-policy/2020/07/florida-teen-arr...
- Pfhreak 6y agoWe protect juveniles for a reason. It seems reasonable to make an effort not to spread their identities around on social media (even if they are reported by press sites.)
- latchkey 6y agoExcept for the part that it is Florida and they release all this stuff... which is what brought on the whole Florida Man meme. https://www.wfla.com/news/hillsborough-county/tampa-teen-accused-of-being-mastermind-behind-twitter-hack-that-targeted-high-profile-accounts/ https://www.wfla.com/news/hillsborough-county/tampa-teen-acc...
- boogies 6y agoLegal ≠ ethical
- par 6y ago> Today’s announcement proves that cybercriminals can no longer hide behind perceived global anonymity Anyone know what the loose end was that got these guys busted?
- koolba 6y agoIf they were dumb enough to waste such a high value target on a small scale bitcoin scam then I wouldn’t be surprised if they were dumb enough to perform the malicious actions from their home IP address.
- SV_BubbleTime 6y agoDidn’t the hack need internal access? VPN maybe?
- function_seven 6y agoSure, but if they connected to the VPN from their own IP, then that's not going to hide anything.
- ehsankia 6y agoReally seems like a modern day MafiaBoy.
- focus2020 6y ago
- Taek 6y agoHitting a 17yo with 30 felony charges feels a bit steep to me. Also should any repercussions be considered against Twitter that a 17yo was able to gain access to the private messages of potentially some of the most important individuals in the world? If a 17yo could do it, I'm sure a nation state could do it.
- tedunangst 6y agoPrevious settlement regarding twitter security: https://www.ftc.gov/news-events/press-releases/2011/03/ftc-accepts-final-settlement-twitter-failure-safeguard-personal-0 https://www.ftc.gov/news-events/press-releases/2011/03/ftc-a...
- ponker 6y agoWhat does the 17yo have to do with it? Would it be different for an 18yo?
- dboreham 6y agoAs a society we generally make some allowance for a perpetrator's mental capacity. One aspect to that is we generally accept that teenage brains are not quite the same as adults.
- zenta 6y agoConversely, would it be different for a 16yo? What about 15yo? Or 12yo?
- wil421 6y agoI believe most states will charge a 17yo as and adult. Not sure what the feds would do.
- paulpauper 6y agoi could see this possibly be challenged by courts , possibly up to the supreme court
- dig1 6y ago"Someone has to go to prison, Ben" - quoting Harvey Keitel from National Treasure movie (1:50) [1] [1] https://www.youtube.com/watch?v=co4EsnwAM1Q https://www.youtube.com/watch?v=co4EsnwAM1Q
- cryptoz 6y agoFor all its flaws, I love that movie. Based (loosely) on the Beale ciphers, a real-life combination of cryptography, myth, and scams (probably) https://en.wikipedia.org/wiki/Beale_ciphers https://en.wikipedia.org/wiki/Beale_ciphers
- VonBlue 6y agoHold on... how could they have de-anonymized the blockchain transactions? That seems.. false
- tomc1985 6y agoWhy not? People link their wallets to other wallets and financial services with reporting requirements all the time. Bitcoin isn't anonymous
- Rebelgecko 6y agoAll transactions are public on the Bitcoin blockchain. I haven't followed the wallets, but it's possible that they tried to cash out on an exchange and got caught. Or they were initially found via other means and a search of their computers found the corresponding wallet.dat files.
- techntoke 6y agoWhich would likely be encrypted
- banana_giraffe 6y agoYeah, they used Coinbase, and Coinbase is of course willing to respond to warrants.
- Aaronstotle 6y agoBitcoin is a public blockchain, there are various blockchain analytic firms such as Elliptic/Chainalysis that offer bitcoin tracing services. Bitcoin is not private nor anonymous, the rise of blockchain surveillance is why privacy coins like Monero are gaining in popularity. That being said, I'm sure it wasn't solely BTC transactions, these guys seemed to have very poor op-sec for performing such a big hack.
- cyral 6y agohttps://www.justice.gov/usao-ndca/press-release/file/1300126/download https://www.justice.gov/usao-ndca/press-release/file/1300126... It’s detailed here, very interesting read
- dredmorbius 6y agoNumerous sources covering this: At NYTimes, from another submission: https://www.nytimes.com/2020/07/31/technology/twitter-hack-arrest.html https://www.nytimes.com/2020/07/31/technology/twitter-hack-a... Reuters: https://www.reuters.com/article/us-twitter-cyber/florida-teenager-charged-with-hacking-twitter-accounts-of-obama-musk-among-others-idUSKCN24W2W3 https://www.reuters.com/article/us-twitter-cyber/florida-tee...
- mzs 6y agoalso the DOJ release and complaints: https://news.ycombinator.com/item?id=24012968 https://news.ycombinator.com/item?id=24012968
- donarb 6y agoThe story has been updated, three people have now been charged, the teen, a man from Orlando and a man from the UK. https://www.theverge.com/2020/7/31/21349920/twitter-hack-arrest-florida-teen-fbi-irs-secret-service https://www.theverge.com/2020/7/31/21349920/twitter-hack-arr...
- pier25 6y ago> Originally, “Kirk” claimed to be a Twitter employee, according to a Discord chat log So these guys were able to get into Twitter but they chatted freely on Discord without considering everything would be recorded? And then they make one of the most public hacks in recent history without considering someone would go through all the logs with all the noise they made?
- ggggtez 6y agoThere is a reason you don't see this type of attack more often, and it's not because it's difficult to do. It's because social engineering attacks are noisy as heck. Within 30 minutes of them posting these tweets, you can bet the FBI was already on the line with Twitter's security team. The fact that they chose to do this attack at all demonstrates how amateur they were.
- lomoeffect 6y ago> Sheppard had used a personal driver’s license to verify himself with the Binance and Coinbase cryptocurrency exchanges, and his accounts were found to have sent and received some of the scammed bitcoin. Didn't even layer the Bitcoin through an anonymiser like Monero and extra Bitcoin wallets. Just sent and received BTC directly to an account linked with photo ID on multiple exchanges. Incredible really!
- pier25 6y agoIt's like robbing a bank and then making sure everyone knows you put the money in your personal bank account. If you spend 5 minutes reading about anonymizing Bitcoins you'll find plenty of ways to do it (tumblers, etc). How can you do a hack that will certainly get you in jail for several years and not even research the most basic techniques to protect yourself? It just doesn't make sense.
- alexander1100 6y agoI personally lost $6000 dollars, is there any way I could prove that I was a victim and get my crypto back?
- daseiner1 6y agoI don’t mean to be rude, but I have to ask - what were you thinking?
- creato 6y agoYou sent $6k in bitcoin to Elon Musk because you thought he'd give you $12k back? Assuming this isn't a joke, consider that $6k a lesson to not be such a gullible mark.
- deleted 6y ago[deleted]
- SahAssar 6y agoIf you want legal recourse and refunds why would you use a currency that explicitly does not allow for those? Seriously, if you want the protections of the legal system, then use currency controlled by the legal system.
- shuntress 6y agoBitcoin is actually explicitly designed to enable recourse and refunds. Every single transaction is permanently and immutable tied to a verifiable identity. Through common practice, these identities are treated as disposable and therefor generally ignored. But stating that the currency is explicitly designed to disallow accountability is not an accurate representation of reality. -- Edit to add a practical example for clarification because this is being downvoted. If the FBI conducts an effective warranted search + seizure of a mob safehouse, seizes a large safe, opens it up, and finds either: A) Gold bricks or B) Bitcoin wallet private keys In case (A), they can maybe correlate records, reports, statements, and other evidence to possibly determine the rightful owner of the gold or goods laundered for gold. In case (B), they can check the BTC ledger against fraud reports that contain bitcoin wallet public keys, then publish a public statement asking people to prove they own any matching public keys -- because bitcoin, by it's fundamental nature, is more accountable in a way that enables recourse and refunds.
- alexander1100 6y agoIs there any way I could prove that I was a victim of this crime?
- shadowgovt 6y agoI'd start your legwork here with a phone call to your nearest FBI field office. Make sure you have the paper trail showing from your end you sent crypto to the perpetrators, and ask what the next step would be for claiming your defrauded property. It may also be worth consulting with a lawyer to see what your legal recourse might be here. Fair warning: there may be no next step. I have no idea if the US government even considers cryptocurrency "property" in any legally-meaningful sense.
- paulpauper 6y agoif you have the private key, sign the wallet. if you used an exchange, there are probably records
- varenc 6y ago> "Washington DC Field Office Cyber Crimes Unit analyzed the blockchain and de-anonymized bitcoin transactions allowing for the identification of two different hackers"
- zionic 6y agoShould have used Monero lol
- Shared404 6y agoGot to love government knowledge of tech. This is the set of people that legislators listen to. I think we may be screwed.
- shadowgovt 6y agoI'm not sure what your criticism of the quote means here. The biggest weakness of BTC for criminal enterprise is the fact that every transaction must be logged to a global public ledger. The hard part is aligning the public keys with private keys, but if you have enough additional information (such as, say, the private keys' owners sitting in a prison cell and the private keys themselves flayed out of their unencrypted hard drives), it's trivial to prove the money flowed from one user to another. The quote seems accurate.
- Shared404 6y agoI know the quote was accurate. I thought it was common knowledge that bitcoin is not anonymous, therefore making "de-anonymized the bitcoin transactions" a bit of an overstatement.
- shadowgovt 6y agoAh, now I follow. I assume they intended "de-anonymized" to mean "tied the public keys to identifiable human beings IRL."
- 6y ago
- robotcookies 6y agoWasn't there inside help? I read several articles saying that there was. Any of those insiders charged? Twitter is in a bind. If there was no inside help, that says their security is pretty lax. If there was inside help, why have they not identified or named them.
- shadowgovt 6y agoUnless there's additional info I didn't see, the "inside help" theory came from the fact that they had images of the internal dashboards. That doesn't necessarily indicate voluntary inside help (they may have found a hole in Twitter's internet / intranet firewall, or they may have spear-phished a service team member's credentials).
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- dshep 6y agoTrying to paint this 17-year old kid as a criminal mastermind strikes me as rather gross. I can see it as a kid doing it to see if he could, and using an obviously meme-worthy fake post that got out of hand. I think everyone has done some dumb things at this age without thinking about the consequences. If that is the case here, I hope this doesn't ruin the guys life.
- justchilly 6y agoWould that apply to criminals of all ages, based on their intelligence / mental maturity? Plenty of incarcerated 18+ adults with less brainpower than this guy were deemed responsible for their actions.
- webkike 6y agoI think there are some arguments here to be made about the development of the prefrontal cortex. You may not be as “intelligent” as someone who is 17, but if you’re over the age of 25 your decision making capabilities are likely much much better. There’s a lot of evidence to support this. I will present my own anecdotal evidence because hacker news loves that stuff. I acutely felt my decision making improve a few months before I turned twenty five. It hit me like a wave, and reflecting on my past decisions felt like looking at the actions of a completely different person. If I were in different, more difficult positions when I was younger, it is unlikely that my decisions would be as rationally thought out as they would be now.
- chrononaut 6y ago> I acutely felt my decision making improve a few months before I turned twenty five. It hit me like a wave, and reflecting on my past decisions felt like looking at the actions of a completely different person. I don't know if this actually exists, but I experienced something similar: Starting at around 17 I decided to ask myself at every birthday whether I thought I was more mature as a person than the year before, which I think relates to proper and holistic decision making. I kept saying "yes" to this question until I was 24.
- 6y ago
- deleted 6y ago[deleted]
- qppo 6y agoThey should have just scammed old people with spoofed phone numbers, then the government would never have caught them.
- throw_m239339 6y agoWell their biggest mistake was to live in US and be US citizens. Most of the people operating high scale phone scams live abroad, India, Africa, South East Asia... Don't do that though, don't scam people.
- amrrs 6y ago> Washington DC Field Office Cyber Crimes Unit analyzed the blockchain and de-anonymized bitcoin transactions allowing for the identification of two different hackers. Anyone with Bitcoin Transaction knowledge, what's this de-anonymization of Bitcoins transaction? >Today’s announcement proves that cybercriminals can no longer hide behind perceived global anonymity,” said Thomas Edwards, Special Agent in Charge, U.S. Secret Service, San Francisco Field Office. This reads like an Ad copy of a company that's against perceived anonymity.
- dragonwriter 6y ago> Anyone with Bitcoin Transaction knowledge, what's this de-anonymization of Bitcoins transaction? Since Bitcoin is not anonymous but pseudonymous, it can be as simple as finding one or more transactions that link a wallet to a real identity (such as one tied to purchase of physical goods with an identified recipient and shipping information) and from there tieing every other transactions from.that wallet to the same identity. I would guess in practice it often involves more steps of connection. > This reads like an Ad copy of a company that's against perceived anonymity. The DoJ isn't a company, but it is very much against perceived lack of accountability, which is one of the reasons people choose systems that offer perceived anonymity.
- dumbfoundded 6y agoBitcoin is anonymous until you tie it to something that requires a real identity. For most people, it's probably tied to an exchange that has their real identity, credit card info, and maybe bank account info. What they should've done is generate a new wallet with no previous transactions and just used that to buy things.
- ggggtez 6y agoImagine a 17 year old robs a bank and steal 100k from the savings accounts of random people. Or a 17 year old steals a couple of cars from random people off the street... The crime is not breaking into Twitter. The crime is theft. Twitter didn't steal that money, this guy did. Let's not pretend the internet is a magical land without consequences.
- paulpauper 6y agotechnically he did not take the money but rather ppl gave it to him under a false pretense. It is close enough but one can imagine a jury being harder one someone who stole vs exploited his victim's greed and gullibility.
- ehsankia 6y agoIn the US, scams are still "conspiracy to commit money laundering", which is what the kid was charged with. Also wire fraud.
- Taek 6y ago> Imagine a 17 year old robs a bank and steal 100k from the savings accounts of random people. I think that's a great comparison. But it's not an armed robbery, it's a break-and-enter where no property gets destroyed. How many felonies does the robber get after being caught? I don't actually know but I'm guessing 1-3? Certainly stealing $100k is a deserving felony. But 30 felonies seems a bit steep.
- user5994461 6y agoThe guys have a very long history of scams, with $700 000 seized before this twitter thing it seems. That money is very much destroyed for the people whom it was stolen from.
- ChrisLomont 6y agoIt depends on how many laws with felony consequences each broke. If a robber hacks a computer (a felony), impersonates law enforcement (a felony), uses that to commit fraud (a felony), then transfers stolen money across state lines (a felony), then tries to launder it (a felony)..... You can see how such things can stack up.
- spir 6y agoIf the "mastermind" is a 17 year old, Jack should intervene to save his life from being ruined.
- sna1l 6y agoFrom the Verge[1] article it seems like there was someone else providing access to the accounts? So was it social engineering or not? > Intriguingly, Sheppard and Fazeli may just be middlemen for the scam — “an unknown individual” with the handle “Kirk#5270” is believed to be the one who got access to Twitter’s internal systems. It’s not clear if the Tampa teen is Kirk#5270, though it sounds like that’s possible. The Sheppard complaint is dated July 22nd, and the Tampa teen wasn’t arrested until today. Originally, “Kirk” claimed to be a Twitter employee, according to a Discord chat log: [1]: https://www.theverge.com/2020/7/31/21349920/twitter-hack-arrest-florida-teen-fbi-irs-secret-service https://www.theverge.com/2020/7/31/21349920/twitter-hack-arr...
- MiroF 6y agoWhat I heard was that one of the hackers managed to get access to Twitter's internal Slack, and that hacker was the one posing as having a Twitter employee friend. Don't know if that's true though.
- ehsankia 6y agoDamn, did these kids really get MafiaBoy'd?
- junar 6y agoIt seems like "Kirk" is believed to be some other individual. From the complaint against Sheppard: > On July 21, 2020, federal agents executed a search warrant authorized by U.S. Magistrate Judge Alex G. Tse at a residence in the Northern District of California. Among the occupants of the home was a juvenile (“Juvenile 1”). ““Juvenile 1” was believed to be a Discord user identified in chats as an individual who assisted “Kirk#5270” and “Chaewon” in selling access to Twitter accounts. Upon execution of the search warrant, “Juvenile 1” agreed to be interviewed. “Juvenile 1” admitted to law enforcement agents that he/she was the Discord user who was identified in chats as assisting “Kirk#5270” and that he/she participated in the sale of illegal Twitter access. “Juvenile 1” admitted that he/she worked with “Chaewon” to sell Twitter account access. According to “Juvenile 1,” his/her knowledge of “Chaewon” was that “Chaewon” lived in the United Kingdom and “Juvenile 1” knew “Chaewon” by the name “Mason.” According to “Juvenile 1,” he/she and “Chaewon” had discussed turning themselves in to law enforcement after the Twitter hack became publicly known. https://www.justice.gov/usao-ndca/press-release/file/1300126/download https://www.justice.gov/usao-ndca/press-release/file/1300126...
- stevievee 6y agoThe announcement video is quite intense and feels odd for some reason. Maybe it's the aspect ratio or cold intro - not sure. https://youtu.be/z80K3-q3Kqg https://youtu.be/z80K3-q3Kqg
- mkoryak 6y agoThey could have trimmed the first few seconds of that video. I would also like to see a loop of the first 4.5 seconds.
- ehsankia 6y agoNot sure anyone else watches this show, but this video gives me strong Homecoming[0] vibes. [0] https://en.wikipedia.org/wiki/Homecoming_(TV_series) https://en.wikipedia.org/wiki/Homecoming_(TV_series)
- indigochill 6y agoI have an unrealistic idea (more of a thought experiment) that companies should face equal culpability to criminal hackers in attacks. After all, technically the way the hackers use systems /is/ authorized in a sense, even if the method of obtaining authorization is unconventional. Maybe this would get companies to pay more attention to securing their systems. From a certain perspective, Twitter is an accomplice to fraud by providing the platform and the access to the fraudsters (although I'm fuzzy on whether knowledge of one's aiding of a crime is necessary for an entity to be legally considered an accomplice - probably is). And yes, the charge count is insane but the US loves holding a bit of life-ruining theater when they catch hackers threatening commercial interests. e.g. Aaron Swartz's conviction: https://en.wikipedia.org/wiki/Aaron_Swartz#Arrest_and_prosecution https://en.wikipedia.org/wiki/Aaron_Swartz#Arrest_and_prosec...
- paulpauper 6y agoaccomplice means they knowingly aided in the fraud or profited from it. Being caught off guard is not a crime. The culpability is the reputation damage from being hacked.
- tantalor 6y ago>Being caught off guard is not a crime It can be. Twitter could be found criminally negligent if they knew the risk of this type of attack (or it was obvious) but chose to ignore it.
- SparkyMcUnicorn 6y agoI'm not sure I would call this "authorized in a sense" since social engineering, in order to gain access to an internal tool, was the method. Social engineering most often involves impersonation, so the person getting access was not really the intended party.
- ChrisLomont 6y agoShould we make homeowners equally criminally liable when burglars break in? Certainly if the homeowner had been less lax or obtained more security, that burglary could have been prevented.
- jmount 6y agoI don't have examples, but it seems to me you really hear a lot of teens pulling off successful social engineering attacks, even back to the days of phone-hacking. I guess that is evidence that some teens develop a fairly comprehensive understanding of social interaction.
- StandardFuture 6y agoA kid who spends this much time at a computer thinking about how to break into Twitter has a good grasp of social interactions? Or, maybe Twitter just had some obvious loopholes that even a not super social-aware hacker could find and use? I think it is better to assume that in these situations it is more incompetence from the platform than "super-genius" from the hacker that allows for things like this to happen (regardless of what Twitter needs to say for PR or the media needs to imply for clicks).
- ggggtez 6y ago>White House officials were concerned about President Donald Trump’s Twitter account, which he uses daily to push out news and other information. They assured the public that his account has extra protections. I had suspected that they had added special protections on his account after the (2017?) incident where an employee temporarily deactivated his account (and got fired for it). I guess this confirms it.
- aerovistae 6y agoIt's sad to me how the authorities are bragging about how quickly they caught them and how effective they are at solving this type of crime. The truth is, the vast majority of these crimes go unpursued. They handled this quickly because it was so prominent, but if this happened to an everyday individual, the police wouldn't even bother. I don't see this as much of a triumph. It never should have happened in the first place, and the consequences could have been utterly dire if it hadn't just been teenagers running a Bitcoin scam. This isn't a victory for nation-state security, it's an utter failure, and no policy changes have been made to prevent it happening again. So what we have is a world in which our leadership is vulnerable to hackers, as are the rest of us, but only attacks against the rich and famous have actual consequences. It's the worst of all worlds.
- bmitc 6y agoIt's also just another case where those not in power who attacked those in power are swiftly and promptly dealt with versus those in power perpetuating the same attacks go free. I would rather see them gloat over putting people with real power and influence with their attacks in jail versus bragging about locking up teenagers and people in their early twenties. There's a quote in the article, "There is a false belief within the criminal hacker community that attacks like the Twitter hack can be perpetrated anonymously and without consequence", which just reiterates this perception of the justice system being "hard" on crime. Yet it conveniently ignores being soft on crime if you're rich or in power.
- apengwin 6y agoI don't think they're bragging. They're trying to dissuade the next attacker.
- Kaveren 6y agoi was assured by the cybersecurity experts of hacker news that REALLY this was all a mastermind ploy to steal and sell twitter DMs. who would they sell them to? doesn't matter! what information of actual value is sent through twitter DMs? doesn't matter! we did it, hacker news.
- perl4ever 6y agoAnybody ever seen one of these? http://www.vintagecalculators.com/html/invicta.html http://www.vintagecalculators.com/html/invicta.html
- tazedsoul 6y agoI’d imagine the FBI has more than just the link to these individuals via their drivers licenses being used for verification. Surely, these drivers licenses may have been used fraudulently by a hacker who wishes not to be found out so embarrassingly?
- bilbopotter 6y agoObviously what they did is wrong but the kid is 17. To me this is a prime example of where a short sentence or community service should be used. Don't ruin his life - he could be a useful employee for a tech company.
- Waterluvian 6y agoAmerican justice is rarely about rehabilitating the perpetrator. It’s about ensanguinating the bloodthirsty and making the fearful feel safe.
- TeeMassive 6y agoAnd enriching the private prisons owners, who then lobby both parties for harsher sentences and this is why the US, a free democracy, has the highest incarceration rate in the World.
- kingbirdy 6y agoPrivate prisons represent only ~8% of the US state & federal prison population[0]. Private prisons, while bad, are a distraction from the larger issues of policing and incarceration in the US and aren't the reason why we have so many people locked up. Almost half of all federally incarcerated people in the US are there for drug-related offenses[1] thanks to the "War on Drugs", that's where you want to be focusing your efforts on change. [0]: https://www.sentencingproject.org/publications/private-prisons-united-states/#:~:text=Private%20prisons%20in%20the%20United%20States%20incarcerated%20121%2C718%20people%20in,in%202012%20with%20137%2C220%20people https://www.sentencingproject.org/publications/private-priso.... [1]: https://www.bop.gov/about/statistics/statistics_inmate_offenses.jsp https://www.bop.gov/about/statistics/statistics_inmate_offen...
- bmitc 6y agoWhile that percentage is low, it doesn't tell the whole story. Private prisons are certainly a major symptom of the problem with our prisons. The U.S. has the largest private prison population in the world, and you'll note from your own link that the private prison population from 2000 to 2019 increased by 39%. Also, for federal prisons, the percentage of inmates in private prisons is 19.1%. These are definitely problems and discussing them also helps discuss the big issues such as why in the hell we're incarcerating so many people. https://www.sentencingproject.org/publications/capitalizing-on-mass-incarceration-u-s-growth-in-private-prisons/ https://www.sentencingproject.org/publications/capitalizing-...
- amiga_500 6y ago2 more convictions than the great financial crash!
- quarteredgallon 6y agoYeah no surprise there. The second Discord logs of the scam being planned started circulating around Twitter I knew it'd be a matter of weeks before these guys were caught. Absolutely unreal that one of them was dumb enough to not only post chatlog screenshots on Twitter with their usernames uncensored, but to use something like Discord to plan this in the first place. Since the crimes were financially-motivated all of them get upgraded to felonies. I have sympathy for people who get fucked by the US' dumb CJ system, but uh... touching a Presidential candidate's Twitter account was whose idea, exactly? What did they expect would happen? I have a hard time believing the "for the lulz" defense some people are making for these people when the whole thing was clearly financially motivated.
- StandardFuture 6y agoThe only reason he got caught was because he used his access to attempt a BTC scam. The likelihood that more sophisticated individuals and organizations have access to Twitter (and probably various other tech companies), and understand the importance of not letting your access be discovered, is probably far far higher than we realize. Should we just assume all data held by Twitter and various other tech companies is compromised (by multiple different actors)? Twitter seems to be wording things to make the attack seem out-of-this-world sophisticated, but I just have serious doubts about that.
- dkersten 6y ago> Our European visitors are important to us. > This site is currently unavailable to visitors from the European Economic Area So we're not important to them then? Gotcha! Block us, fine, whatever, but don't give us this BS about being important to you then.
- supergirl 6y agomany years in prison for what this kid probably thought is a prank. while twitter will likely get no punishment for having so little security that even a child can hack them.
- kgermino 6y ago> Although the case against the teen was also investigated by the FBI and the U.S. Department of Justice, the Hillsborough State Attorney’s Office is prosecuting Clark because Florida law allows minors to be charged as adults in financial fraud cases such as this when appropriate. The FBI and the Department of Justice will continue to partner with the office throughout the prosecution. Wow. It isn’t news, but what a terrible reflection of the US approach to criminal justice.
- TwoBit 6y agoWhat do you believe is terrible?
- ChicagoDave 6y agoWe really need to focus on rehabilitation instead of incarceration across the board.
- svartkanin 6y agoSo what will happen to the guy in the United Kingdom? Will he be extradited to the US?
- dang 6y agoSee also https://www.justice.gov/usao-ndca/pr/three-individuals-charged-alleged-roles-twitter-hack https://www.justice.gov/usao-ndca/pr/three-individuals-charg... (via https://news.ycombinator.com/item?id=24012968 https://news.ycombinator.com/item?id=24012968, but we merged the threads) Also: don't miss that this thread has multiple pages of comments. That's what the "More" link at the bottom of the page points to. Or you can click here for page 2: https://news.ycombinator.com/item?id=24011939&p=2 https://news.ycombinator.com/item?id=24011939&p=2
- hourislate 6y agoWhat's the big deal, he stole some bit coin and embarrassed Jack. Wall Street Insiders steal billions everyday from Joe6pack with the Governments help and they get to laugh about over a drink after work. Now we can spend millions in tax payer money incarcerating him.... He should get a reward for exposing how shitty Twatter is. Besides the NSA is reading every txt you send and listening to every call you make. They know where you are 24/7 and what you bought for lunch. No one is punishing them..... It's all theater for the masses I suppose....we caught the bad guys.....LOL...
- dumbfoundded 6y agohttps://www.youtube.com/watch?v=NtUfNtgawNY https://www.youtube.com/watch?v=NtUfNtgawNY
- deleted 6y ago[deleted]
- martinesko36 6y agoStrongly agree and I don’t know why you get downvoted...
- rglover 6y agoIf this is true let this kid go and fire the people at Twitter who he duped.
- mmmmmk 6y agoWhere's Kirk?
- syspec 6y ago> According to federal agents, Sheppard was found out partly because he used a personal driver’s license to verify himself with the Binance and Coinbase cryptocurrency exchanges, and his accounts were found to have sent and received some of the scammed bitcoin. Fazeli also used a driver’s license to verify with Coinbase, where accounts controlled by “Rolex” allegedly received payments in exchange for stolen Twitter usernames. That is such a simple mistake to make, wow.
- catsarebetter 6y agoWhat a waste of talent
- nicyl 6y agoI’m very uncomfortable about the fact a very young person (only 17 years old) has had his identity released like this... where was this boys fair trial first? Regardless if he was behind the hack or not, this is not the way forward to a decent society.
- nathan_f77 6y agoI hope they will provide some more details about how they got caught. If this person can hack Twitter and they know about Bitcoin, then I'd be very surprised if they didn't take some basic steps to hide their tracks. E.g. Tor, VPN, cafe wifi, etc. I heard that some social engineering was involved, so maybe they called someone and their phone number was traced. I would be interested to know if they forgot about one small detail. I think the FBI / NSA probably has full visibility into the Tor network and can easily deanonymise any users. Or it could be like the Harvard bomb hoax in 2013 [1]. (They used Tor, but they were also the only person using Tor at the time.) [1] https://www.theverge.com/2013/12/18/5224130/fbi-agents-tracked-harvard-bomb-threats-across-tor https://www.theverge.com/2013/12/18/5224130/fbi-agents-track...
- unionpivo 6y agoI wonder if Kerbs will apologize for doxing the wrong guy
- forgotmypw17 6y ago\/\The Conscience of a Hacker/\/ by +++The Mentor+++ Written on January 8, 1986 =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= Another one got caught today, it's all over the papers. "Teenager Arrested in Computer Crime Scandal", "Hacker Arrested after Bank Tampering"... Damn kids. They're all alike.
- aquarin 6y ago"This site is currently unavailable to visitors from the European Economic Area ..."
- deleted 6y ago[deleted]
- nicyl 6y agoI’m very uncomfortable about the fact a very young person (only 17 years old) has had his identity released like this... where was his fair trial first? Regardless if he was behind the hack or not, this is not the way forward to a decent society.
- antihero 6y agoRight, how are we going to try and prevent the British dude extradited?
- nicyl 6y agoThe moderation of my comment has completely stumped me. Is HN some sort of cliquey community or something?!
- luord 6y agoWhenever I read news like these, I just think that this is such a waste of talent (assuming Twitter's security isn't analogous to Swiss cheese). This kid could have gone into ethical hacking and general security. Now not only he's getting thrown in prison (over something he probably wasn't even convinced he could do, if the subpart attempt at capitalizing on it is any indication) for years, he's lost any potential career on the field.