687 ms·
LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census
- deleted 15y ago[deleted]
- ElliotH 15y agoGiven LulzSec seems to post their hacks on twitter, that there's no way of validating who posted the PasteBin item and that the Office of National Statistics hasn't reported the loss, its probably best to wait and see something a little more convincing.
- ZeroMinx 15y agoI haven't seen "Census" mentioned in their twitter feed (yet), so as far as I know the only source is a bit of anonymous text on pastebin. Anyone could put that there.
- 46Bit 15y agoThey are mentioning something they've got though, in similar language to the pastebin. I think it unlikely they'd have managed to acquire the full census, but I think it's probably quite possible they've got ones submitted online.
- m4tt 15y agoI wrote the article and have been trying to trace the authenticity of the release. I am still waiting to hear back from the Office of National Statistics, which at the time were unaware of who LulzSec even were. I contacted them a little over two hours ago, I haven't received a response, yet.
- ErrantX 15y agoKnowing a little of the internals of ONS... It may take them a while to figure out what a "computer" is and how it might be "hacked". You could be waiting some time :) ahem.
- m4tt 15y agoJust got off the phone to them. Issuing a statement very soon. Will update both the article and on HN.
- m4tt 15y agoIn related news, the "Mastermind" behind LulzSec has been arrested: http://thenextweb.com/industry/2011/06/21/suspected-lulzsec-mastermind-arrested/ http://thenextweb.com/industry/2011/06/21/suspected-lulzsec-...
- Peroni 15y agoLooks like Sophos are instigating PR damage control already: https://twitter.com/#!/gcluley/status/83121318723194880 https://twitter.com/#!/gcluley/status/83121318723194880
- deleted 15y ago[deleted]
- mikle 15y agoIt also has the Bethesda and US senate links in the end, making this look more like copy-paste of an older release. This is inconclusive though since the real LulzSec might copy paste from an older release to get all the ascii art.
- crocowhile 15y agoYes, also the phone number is wrong. That number doesn't work anymore.
- nitrogen 15y agoI've wondered how many individuals and groups out there post things in the name of other security groups to distract attention from (or direct it toward) themselves. Maybe everyone should start signing their releases with a private key.
- JonnieCache 15y agoGoodbye plausible deniability...
- gazrogers 15y agohttp://twitter.com/#!/c4marcus/status/83135821351370752 http://twitter.com/#!/c4marcus/status/83135821351370752
- m4tt 15y agoFull statement: We are aware of the suggestion that census data has been accessed. We are working with our security advisers and contractors to establish whether there is any substance to this. The 2011 Census places the highest priority on maintaining the security of personal data. At this stage we have noevidence to suggest that any such compromise has occurred.
- justincormack 15y agoThis was the first census where you could submit details online. I wonder if it was these records? Would be surprised if they had even finished scanning the paper ones yet, but the UK governments security record is not good. They contracted it to Lockheed Martin, who also do the US census, so presumably reused the software?
- crocowhile 15y agoLM was penetrated few days before census day. Maybe the left some back doors? http://www.ibtimes.com/articles/154078/20110529/lockheed-martin-cyber-attack.htm http://www.ibtimes.com/articles/154078/20110529/lockheed-mar...
- BrianLy 15y agoIn all likelihood it was probably compromised through some other means than the software. I'm sure the software got a lot of attention in terms of security but surrounding systems were neglected.
- Simon_M 15y agoI wonder if they are using the same (undocumented) exploit for each of these attacks. I am certainly no expert in this field, but I would have thought discovering new exploits and security holes would take time, yet these guys are hitting several major sites a week.
- mike-cardwell 15y agoFrom what I understand, their main tool is simple SQL injection. Most websites seem to have at least one XSS or SQL injection hole. Nearly all have CSRF flaws.
- wisty 15y agoStill, census data should not be accessible from a public facing web site. That's just amateur hour. You should really assume that anything with a POST form is vulnerable.
- drstrangevibes 15y agowell its got to go in somehow, perhaps a facade that exposes only preparedstatements procs could have prevented this, but equally perhaps they exploited the facade, the transport mechanism to the facade, the db driver..... who knows, what is known is that theres a path, however narrow
- wisty 15y agoNo, they should have processed the data on a secure network, then burnt CDs with the final results. That's how Australia treats important (Top Secret classified) data. I don't know how classified our census is, it should be treated with a bit of respect.
- mike-cardwell 15y agoAgreed. Any submitted data should have been immediately encrypted with a public key who's companion private key was stored offline. It should have then been immediately transferred to a secondary box which was setup with a single function of accepting and storing the data. Ie a box which you can't query over the network for data. As soon as the census closed, the relevant boxes should have been taken offline. The data moved to a "secure" location, and the original boxes wiped and destroyed. Considering the data that was being collected, I don't think this is overkill.
- antihero 15y agoIf this is true then I am suing Lockheed Martin under the Data Protection Act.
- estel 15y agoThere's jurisdiction for that?
- eftpotrm 15y agoIf their servers have been compromised to leak the data, should be. They ran the survey and UK and European data protection law makes data leaks the responsibility of the data holder.
- sunchild 15y agoThey were one of the first companies to admit that the RSA SecurID exploit compromised them over the past months, too. Link to story: http://www.networkworld.com/news/2011/052611-lockheed-martin-outage.html http://www.networkworld.com/news/2011/052611-lockheed-martin...
- beck5 15y agoYes, they will probably be the information controller under the DPA and have to be extreamlly careful that our data is safe. Even keeping a copy in a non EU country is very hard.
- davweb 15y agoUS companies can store data from EU countries if they comply with the "Safe Harbour" principles. Organisations can self-certify and as yet no company has been challenged as failing to meet the guidelines. http://en.wikipedia.org/wiki/Safe_Harbor_Principles http://en.wikipedia.org/wiki/Safe_Harbor_Principles
- StrawberryFrog 15y agoWhy would jurisdiction enter into someone in the UK suing the company that processed the UK census data? Thier data. I don't know if antihero is in the UK, but if they aren't, people in the UK should do it instead. I am disturbed that my data could leak like this.
- Peroni 15y agoIf true, this will be a massive coup and regardless of how they obtained the records, LulzSec will get all of the significant negative attention they so badly crave. I submitted my census info via the online form and given the amount of detail I included I would be terrified if that info was leaked.
- shubble 15y agoImagining that the release is true, this will do strange things for pay bargaining. Imagine if you could look up your colleagues before asking for a rise? On the other hand, I don't recall anything really horrific on that form. Enough data to steal my identity and take out a mortgage in my name, yes. Enough to embarrass me? no...
- Peroni 15y agoThere may not be anything in there to embarass me but there is unequivocally enough in there for someone to steal my identity and ruin a credit rating I've been working extremely hard to build over the last three years.
- mariuskempe 15y agoWhat info from the census would enable someone to steal an identity? From the looks of it there's only DoB and address in terms of personal info...
- crocowhile 15y agoI don't like where this is going.
- beseku 15y agoWhats worrying about the apparent proliferation of security breaches like this is that as the attacks get more sophisticated, so do the prevention methods. This could get to the point whereby the skill level required to protect an application or server goes way higher than the skill level of many developers. The result being that independent development is impossible as you would need to hire ever more expensive security consultants for anything that stores data.
- gaius 15y agoIn my experience the expense of a security consultant is rarely correlated with their skill level.
- Joakal 15y agoBut aren't they using pretty old exploits, SQL injections and DDoS?
- noobiscus 15y ago"This could get to the point whereby the skill level required to protect an application or server goes way higher than the skill level of many developers." We reached that point quite a while ago. What we are seeing now is the result of that point being reached, without anyone realising at the time.
- crocowhile 15y agoI was thinking more in terms of reactions. Governments rarely admit their own faults and weaknesses. They will react claiming computer terrorists must be stopped now and that more control on the Internet is needed to protect everybody.
- cageface 15y agoMore likely that common development tools and frameworks will become much more intrinsically security conscious.
- pedrokost 15y agoWith the amount of hacking that is flooding the news recently, I would like to learn about database security. What are some good books/tutorials/videos on how to make databases more secure?
- estel 15y agoThe Web Application Hacker's Handbook is most widely cited in a more general sense. I'm reading it myself at the moment - http://www.amazon.com/Web-Application-Hackers-Handbook-Discovering/dp/0470170778 http://www.amazon.com/Web-Application-Hackers-Handbook-Disco...
- Joakal 15y agoSQL injections seem to be the prominent exploit by them. Not in any order of popularity: 1. Brute-force (or not) cracking of weak or default usernames/passwords 2. Privilege escalation 3. Exploiting unused and unnecessary database services and functionality 4. Targeting unpatched database vulnerabilities 5. SQL injection 6. Stolen backup (unencrypted) tapes http://mobile.darkreading.com/9289/show/8506121498da7d8ae48394480223d1f2&t=68d089bd0a4d2a12101720a1a53d9e9a http://mobile.darkreading.com/9289/show/8506121498da7d8ae483...
- tomp 15y agoI believe that most databases are secure, especially the open source ones. What you should be careful about is the things surrounding the database: the .php files (or whatever) that read/write the database, and the system it is running on. Basic security practice for the web: NEVER trust user input: check and recheck all the GET/POST variables, check that numbers are numbers, that strings are correct strings (they have no funny characters, such as " or ; (for databases) or <>"&' (for HTML) or . (for paths)). Check all input into the databases (to prevent SQL injections) and all output for to the user (for XSS). Basic security practice for sysadmins: Use up-to-date OS and software. Use strong passwords. Almost never run root. Make remote access hard. This seems easy, and for the most part, it is. It's just so many things that people forget to check for them all.
- ern 15y ago
- retube 15y agoThey're going to piss a lot of people off if they do this. Like every single UK citizen. Exposing security flaws and embarrassing govt is one thing, but to put un-redacted personal data online is quite another.
- drstrangevibes 15y agoer... I dont think they care, its for the Lulz.... apparently :-\
- paradoja 15y agoIf you read the article or the pastebin: We’re keeping them under lock and key though… so don’t worry about your privacy (…until we finish re-formatting them for release) So, given they really arer LulzSec, they are hinting that they won't publish the data un-redacted.
- redthrowaway 15y agoOr they're just literally formatting it for organization and readability. They've released damaging info before on innocent users.
- mike-cardwell 15y agoI filled in the UK census online, but I can't actually remember what compulsory data was requested. Is there a copy of it somewhere?
- xedarius 15y agohttp://www.ons.gov.uk/census/2011-census/2011-census-questionnaire-content/index.html http://www.ons.gov.uk/census/2011-census/2011-census-questio...
- rwmj 15y agoIf this is true (and it seems it's probably not) then the people to get angry with are the UK government and their contractors Lockheed-Martin. WTF are we using a US-based company for anyway?
- patrickod 15y agoSo what's the worst possible outcome here in terms of the UK government's reactions? Fast-tracked arcane legislation to make security tools illegal like they are in .de ? Broadening the terms of hacking and increasing the legal penalties? If LulzSec aren't trolling the world and they do indeed have these records I would imagine there is going to be one hell of a shitstorm in the coming weeks.
- crocowhile 15y agoIt would be just another excuse to get the Internet ID implemented. MAFIAA has been pushing for Internet ID since years now and a number of politicians are in favour. Must admit that every time I read about the latest Lulsec activity I cannot help but think that MAFIAA is behind all this.
- mike-cardwell 15y agoI'd say the opposite will happen. The government will not be able to set up anything which requires a massive secure database for quite a few years. Every time they claim they can set up a secure database, the 2011 census leak will be brought up.
- tomp 15y agoIf they will implement the Internet ID in the same way as they implement their current security (assuming the leak is real), then there is no need to worry...
- gaius 15y agoI don't think so, this is the government that wants to pass the Freedom Bill: http://freedom.libdems.org.uk/ http://freedom.libdems.org.uk/
- JonnieCache 15y agoHilariously, that url returns "403 forbidden." Google doesn't seem to return anything on that domain. Here's the text of the freedom bill: http://www.libdems.org.uk/siteFiles/resources/PDF/The_Freedom_Bill.pdf http://www.libdems.org.uk/siteFiles/resources/PDF/The_Freedo... Seems pretty nice. I dread to think what they'll have to trade the tories for it though.
- drtse4 15y ago"Biggest" only for the media coverage this could get, i would not be surprised if they had exploited a common vulnerability. At least when we are discussing about publicly accessible sites, "security-illiterate" is the perfect definition for these government agencies (and the external companies that realize the sites they need). Will this kind of things make the general public at least a bit more security conscious?
- mike-cardwell 15y agoThere'll be some interesting mashups if this is true.
- deleted 15y ago[deleted]
- arn 15y agoof interest [edit, arrest link below]: http://twitter.com/#!/channel4news/status/83129762142363649 http://twitter.com/#!/channel4news/status/83129762142363649 19-year-old suspected of being mastermind behind computer hacking group LulzSec arrested in Wickford, Essex. #c4news
- JackWebbHeller 15y agoJust noticed that a moment ago. As of now no reports on the Channel 4 News website (http://www.channel4.com/news/ http://www.channel4.com/news/) but I'm keeping my eye on it...
- ZeroMinx 15y agoIt's on the Met Police site - http://content.met.police.uk/News/eCrime-unit-arrest-man/1260269113895/1257246745756 http://content.met.police.uk/News/eCrime-unit-arrest-man/126...
- JonnieCache 15y ago"The PCeU was assisted by officers from Essex Police and have been working in co-operation with the FBI."
- deleted 15y ago[deleted]
- JackWebbHeller 15y agoScotland Yard press release: They have confirmed his arrest. http://content.met.police.uk/News/eCrime-unit-arrest-man/1260269113895/1257246745756 http://content.met.police.uk/News/eCrime-unit-arrest-man/126...
- click170 15y agoThis whole escalating security situation has me thinking that IT security is heading down the same path as the War On Drugs. I wonder if ten or twenty years from now we'll see petitions to legalize hacking tools after we see a resurgence in security breaches following the criminalization of "hacking tools"...
- iamichi 15y agoWhat pissed me off was that it is a legal requirement to complete the census (http://en.wikipedia.org/wiki/United_Kingdom_Census_2011#Operation http://en.wikipedia.org/wiki/United_Kingdom_Census_2011#Oper...), so everyones personal details are in the database, which if stollen is a identify thief's dream load.
- binarymax 15y agoSo, after I was strongarmed into filling out the damn thing, now all my identity data is in the wild. I will be joining in a suit of Lockheed if this is true.
- arethuza 15y agoThere is already a guide on how to take a case under the Data Protection Act: http://www.ico.gov.uk/upload/documents/library/data_protection/practical_application/taking_a_case_to_court.pdf http://www.ico.gov.uk/upload/documents/library/data_protecti...
- khafra 15y agoI'm leaning toward "hoax." Lulzsec has been reasonably competent writers so far, and the bizarre placement of "blissfully" makes that either incompetent or some kind of steganography. That, added to the lack of tweet, makes me doubt. Of course, it could still be some anon who actually does have the census data, and considers himself lulzsec-affiliated.
- mjhall 15y agoThe writing style does seem different, sentences in this release aren't terminated in some cases, whereas those from officially corroborated releases always are.
- Fjolle 15y agoAlso according to their twitter the number listed in the pastebin has been suspended, and they have a new one (not in the pastebin).
- StavrosK 15y agoWhy can't anyone bother to sign their press releases, it's not like it's the 60s.
- MiguelHudnandez 15y agoPlausible deniability? (assuming you meant to cryptographically sign the press releases.)
- StavrosK 15y agoHmm, good point.
- Andrew_Quentin 15y agoSuch a shame. Anonymous had a lot of support for their attacks on Mastercard et. al. People, not just the programmers demographic, were seeing them as civil disobedience through the internet and hailing them for taking a right cause, namely against dirty, probably unconstitutional, certainly unethical attacks on wikileaks by numerous powerful groups. What's more, anonymous was seen as more powerful than such groups on the internet arena. It was felt that such powerful groups would thus think twice and know that they are against probably smarter people, perhaps even their own employees. Alas, like actual physical protests, they did not manage to change much. Wikileaks has almost been forgotten now. Julian has gone quite. The organisation itself seems to have become divided and disorganised. They possibly are buying time. But the power that be has shown us that they have the resources, are willing to play, publicly, dirty tricks, and can even withstand a public opinion quite strongly against them. Julian has been given some outstanding honour in journalism. He might even win the Peace prize for what some say was the effect of wikileaks on bringing about the Arab Spring. That may show that there are many powerful avenues to resist and/or push back the power that be. All of that is being undermined for no apparent reason whatever. Although Lulzec might be trying to send a signal to the power that be. We are stronger. We are smarter. You need to know that before thinking again about doing dirty tricks. They don't seem to be able or willing to choose their targets well to send such a message. Showing that you can for example steal the census data in order to increase the security of organisations which deal with our data is like a man showing that he can steal a car by so breaking into the car and stealing it. We can all commit crimes. We choose not to for very good reasons. Some things can not be fortified and turned into castles. And even castles can be brought down. So the ultimate effect is that anonymous is painted with the same brush. As petty criminals bringing havoc into the streets of the neighbourhood by breaking car windows to show us that they can so break car windows. For now, anonymous still has the upper moral ground. That is for now. By for now I mean for the next few days or weeks. The report for example that a member of lulzsec has been arrested who has connections with anonymous helps tremendously in blurring the lines between anonymous and lulsec. The blurring means nothing more nor less than the excuse and the swaying of the public opinion that the power that be needs to go after anonymous and send a clear signal. You may be smarter but we have more resources and more avenues and the consequences you face are much greater. The biggest signal that the power that be may send however is that they are able to control the public opinion by playing tricks. I think we all remember how last year we were talking about how the power that be is going to deal with wikileaks. The conversations that were had here on hackernews are probably still accessible through searching. Killing him seemed to be the most mentioned option, but quickly refuted by others. Now, it may be a strong statement to make seeing as I have no evidence whatever, but the information that did come out in regards to the two women, the fact that Assange is still here in Britain almost a year after, that he is actually free, suggests that tainting him with rape accusations was their choice. As we are seeing, it seems to have worked. Equally, I do not know who lulzecs is. They have no motive, no reason, to do what they are doing. They are intelligent. Thus I doubt they would risk years in prison to just show that they can break a car. People do not tend to do things for no reason, especially if there are great consequences. There is no laughter to be had of say having access to a lot of information of sonny users. Nor is there any lulz in having say the information of the census. I therefore think that there is a probability that Matercard, Visa, Bank of America et al got quite pissed off from anonymous' attacks, but unable to do anything because of the strong public support that anonymous had, thought creatively and went for the blurring of the lines between common thief's and civil disobedience. That is one possibility. Probably the more likely possibility. Sophos for example seems to be salivating every time lulzsecs does something. The other option, that they are kids, being stupid, like most teenagers at time, confused, rebellious, is a possibility but unlikely. They probably know full well, that gaining such a high profile while not having any public support or even having the public against them means that they will crash down painfully to the bottom and remain there for years and years. I'll finally finish this quite long comment by stating that if lulzsec is anything else than affiliated or corrupted, then they should know that they are tainting ideals with petty crimes.
- acron0 15y agoHead of the hydra and all that.... https://twitter.com/#!/LulzSec/status/83164092998758400 https://twitter.com/#!/LulzSec/status/83164092998758400
- thomasknowles 15y agoApparently it's fake: http://twitter.com/#!/LulzSec/status/83168314527981568 http://twitter.com/#!/LulzSec/status/83168314527981568 reply
- someone13 15y agoAccording to their Twitter, they haven't hacked the Census. Seems like someone was spreading false information... See: https://twitter.com/#!/LulzSec/status/83168314527981568 https://twitter.com/#!/LulzSec/status/83168314527981568 https://twitter.com/#!/LulzSec/status/83167715799470080 https://twitter.com/#!/LulzSec/status/83167715799470080 EDIT: Those tweets were deleted. Here's the official word: "Just saw the pastebin of the UK census hack. That wasn't us - don't believe fake LulzSec releases unless we put out a tweet first." https://twitter.com/#!/LulzSec/status/83172089711964161 https://twitter.com/#!/LulzSec/status/83172089711964161
- pavel_lishin 15y agoI wonder how long it will take before someone compromises their Twitter account.
- joejohnson 15y agoWhen you post a tweet, how much information does twitter have about you? An IP adress, what platform you use, etc. I'm just curious, because Lulzsec posts frequently and I wonder if law enforcement could subpoena twitter in attempts to catch these people.
- aparadja 15y agoI'm sure they aren't connecting to twitter directly.
- qF 15y agoDuring the 'hunt' for Wikileaks the U.S. has subpoenaed Twitter for info about supposed supporters.[1] In the case of Lulzsec this will have very little use though, as they use VPN's to hide their IP [2]. [1] http://www.wired.com/threatlevel/2011/01/twitter/ http://www.wired.com/threatlevel/2011/01/twitter/ [2] http://lulzsecexposed.blogspot.com/2011/06/scared-puppies.html http://lulzsecexposed.blogspot.com/2011/06/scared-puppies.ht...
- trotsky 15y ago
- evolution 15y agoLulzSec just confirmed this being rumor on their twitter account http://twitter.com/#!/LulzSec/status/83167715799470080 http://twitter.com/#!/LulzSec/status/83167715799470080
- BasDirks 15y agoLulzSec The Lulz Boat Oh well, just because we want to waste government and local authority investigation time: we hacked every website in the world. Enjoy! 11 minutes ago LulzSec The Lulz Boat I'm not seeing "we hacked the UK census" on our twitter feed or website... why does the media believe we hacked the UK census? #confusion 13 minutes ago LulzSec The Lulz Boat Not sure we claimed to hack the UK census or where that rumour started, but we assume it's because people are stupider than you and I.
- deleted 15y ago[deleted]
- cabalamat 15y agoAnyone can claim to have the census data; I won't believe this until they release it.
- InclinedPlane 15y agoIt appears that LulzSec isn't directly responsible for this. Although, since they called for the hacking of every government agency in the world with their "anti-sec" call to arms it's a bit disengeneous for them to rock back on their heels in shock and confusion.