11 ms·
LulzSec's 'Topiary' arrested
- koenigdavidmj 15y agoArticle does not say why they think that he is Topiary.
- ipsin 15y agoAccording to: http://www.guardian.co.uk/technology/2011/jul/27/lulzsec-hacking-suspect-topiary-arrested http://www.guardian.co.uk/technology/2011/jul/27/lulzsec-hac... The source is the Metropolitan Police Service of London, a.k.a. Scotland Yard.
- alanfalcon 15y agoEvery time I read a story like this, I picture the opening sequence from "Hackers". I wonder if that isn't one of the most realistic portrayals (of anything) in that movie?
- Hominem 15y agoI was busted in much the same way in the early 90s in NYC. Yes, it was the only realistic part of the movie. It is a bit frightening to be woken up by a man pointing a shotgun in your face when you are 13. IIRC, there was a well known NYC hacker who was getting ready for school, and was in the shower, when the SS burst in and the scene was loosely based on him.
- alexgartrell 15y agoAny way we could get you to share more of your story?
- Hominem 15y agoNot much to say. It was part of operation sundevil. I was never arrested or indicted and eventually got all my equipment back. I'm not sure if it is SOP, or the Secret Service thought they were dealing with violent criminals. But they knocked down the front door with one of those rams you see on TV , ran room to room "securing" everything. Once they realized they were dealing with a scared 13 year old they seemed more embarassed than anything. In addition to the local cops, and the Secret Service, there was a postal inspector involved, that guy was kind of a dick, he kept sneering and telling me stuff like "you are going down buddy", even at that young age I figured he didn't get out of the office much. The Secret Service spent post of their time bullshitting and telling me stories of various trips abroad with the president. Some of the nerds bagging up all my equipment would sometimes come in and peer at me, asking me minor questions like "Why do you have so many batteries" until they were reminded that I was a minor and they did not have parental permission to ask me questions. I waited for years for the other shoe to drop, and be indicted, but I never was. I still have all the equipment, still tagged, and even have some disks they put in the drives labeled "SS transport disk"
- meatsock 15y ago"I'm not sure if it is SOP, or the Secret Service thought they were dealing with violent criminals" seems possible the bulk of them had first learned about hackers at the same time they learned about the raid -- perhaps from someone who exaggerated the average size of a hacker's fangs. in any event it doesn't seem likely that in preparation for sundevil they'd have consulted with anyone that would have urged a relaxed and moderated view of what was at that time an unexplored frontier of law enforcement.
- Hominem 15y agoRight, from the sheer scope of the raids I'm sure they thought they were dealing with some sort of syndicate, probably professional criminals branching out. They were absolutely dumbfounded, they didn't know whether to slap the cuffs on me or give me milk and cookies.
- yalue 15y agoI find it hard to believe that European kids care that much about the CIA or Arizona's immigration laws. Yet many of these alleged LulzSec arrests seem to be in Europe.
- schrototo 15y agoI think every wannabe-hacker wants to "hack" the CIA and Arizona's racist laws have been covered extensively on comedy programs like The Daily Show which I'd imagine are popular with anti-authoritarian internet-savvy youths worldwide.
- ellyagg 15y agoOf course, if it were really about their problems with "racist" immigration laws, many countries in Europe have stronger and more strictly enforced immigration policies.
- xyzzyz 15y agoThese are only excuses to show off their "skills". Everyone loathes script-kiddies, and they know the only way for them not to be considered script-kiddies (which they are in fact) is make everyone believe that their motivation is different than fame and feeling of power.
- pnathan 15y agoI'm personally a bit curious as to why it's only been European (only UK perhaps?) people. I'd think the FBI would in on it too.
- redthrowaway 15y agoThey will be. This latest round of arrests by the FBI were made based on the PayPal attacks, which were ages ago. LulzSec didn't even start going until months later, and the attacks that would have really pissed off the FBI happened just recently. The FBI is big and slow, but they'll get around to it if they have any evidence of members in the US.
- 15y ago
- jgrahamc 15y agoThe other day his Twitter feed was cleaned up and a single tweet remained: http://twitter.com/#!/atopiary/status/94225773896015872 http://twitter.com/#!/atopiary/status/94225773896015872 reading "You cannot arrest an idea". I guess he saw this coming.
- citricsquid 15y agohttp://topsy.com/twitter/atopiary http://topsy.com/twitter/atopiary Archive
- Aloisius 15y agoYou may not be able to arrest an idea, but you sure can give its owner more jail time for destroying evidence. What was he thinking?
- fragsworth 15y agoI don't think anyone can claim the evidence was destroyed. All of their posts have been archived in many places.
- psone 15y agoOne may still be charged with obstruction of justice if there is a definite attempt to make unavailable evidence needed for a case, even if the unavailability is temporary until a suitable mirror can be found. It's such a broad definition for a criminal charge to have, and in this case I really think they would consider it.
- Confusion 15y agoDon't be silly. If a murderer burns the clothes in which he perpetrated the murder, he's not 'destroying evidence' in addition to being a murderer. Something must first have been determined to be evidence, before destroying becomes a criminal act. Neither are you obstructing justice by hiding evidence.
- zgorgonola 15y agoInteresting that this arrest follows just a week after a series of other arrests in USA/UK/NL regarding LulzSec and Anonymous: http://nakedsecurity.sophos.com/2011/07/20/arrests-lulzsec-anonymous-hacker-suspects/ http://nakedsecurity.sophos.com/2011/07/20/arrests-lulzsec-a... Not a good time to be a hacktivist
- colinplamondon 15y agoHacktivists? These guys are breaking into private companies and stealing property. They're criminals.
- ryusage 15y agoActivists tend to break laws, no?
- ChuckMcM 15y agoGenerally it does seem to be a common attribute. Some activists are also idealists, which is to say they have a view of the world that is idealized based on their principles which is a distortion of reality to a lesser or greater extent. Living as I do in the San Francisco bay area, I encounter all forms of activists from people living in trees on college campuses (illegally) to folks who provide services to undocumented workers, to folks who expose security flaws on web sites. Of the ones with whom I've been able to talk briefly about their goals, all of them did not grasp that the results of activism are later perceived through the dialog of what the people that 'win' write. (sort of a variation on the winners write the history)
- dailyrorschach 15y agoOne of the critical measures though is that most activists openly do so. Someone up-thread mentions that MLK was a criminal, and he was. As was Ghandi, and others. But they said here I am, here is what I am doing, and why I am breaking this law. And for civil disobedience to be effective, here's the kicker, they welcomed and expected the punishment. The idea that we would arrest another human being for sitting at a lunch counter, etc, is designed to provoke outrage at the unjust situation. The Crito is an excellent place to start in examining I suppose the philosophical roots of civil disobedience: http://en.wikipedia.org/wiki/Crito http://en.wikipedia.org/wiki/Crito
- grahammather 15y agoI'm on the edge of my seat following all this AntiSec/AntiAntiSec drama: The original AntiAntiSec crusader: http://th3j35t3r.wordpress.com http://th3j35t3r.wordpress.com has picked up some helpers: http://lulzsecexposed.blogspot.com/ http://lulzsecexposed.blogspot.com/
- dmbass 15y agoSo the A-Team dox were a bunch of rubbish? (or perhaps that was already confirmed and I missed it). http://pastebin.com/iVujX4TR http://pastebin.com/iVujX4TR
- lwat 15y agoYea that was Aaron Barr's attempt at 'exposing' anonymous after losing his job in disgrace.
- pyre 15y agoIf this report is right, then those d0x were BS: ########################################################################### ########################################################################### ooooooooooooo o8o 8' 888 `8 `"' 888 .ooooo. oo.ooooo. oooo .oooo. oooo d8b oooo ooo 888 d88' `88b 888' `88b `888 `P )88b `888""8P `88. .8' 888 888 888 888 888 888 .oP"888 888 `88..8' 888 888 888 888 888 888 d8( 888 888 `888' o888o `Y8bod8P' 888bod8P' o888o `Y888""8o d888b .8' 888 .o..P' o888o `Y8P' ########################################################################### ########################################################################### Now we have Topiary. Probably the lamest one of the bunch. He doesn't actually do anything except give interviews. There are plenty of logs of him all over the internet being a complete idiot. His "d0x" are all over the internet also. He tries to deny it but there are logs of him bitching about being d0x'ed int he #hq logs that Laurelai leaked. Name: Daniel Ackerman Sandberg Location: Sweden
- mdisraeli 15y agoIt's not unreasonable to suspect that a user in the Shetlands Isles might have had a POP in Sweden, or use of a connection in Sweden to host a remote box with a better connection than available to them normally.
- chippy 15y agoI am very curious as to the methods of how they caught him. Anyone care to guess, or know?
- dlss 15y agoWell, since no one else is wading in here's what look like the usual suspects to me: - obvious digital connection (forgot to use tor / ipredator / hacked vpn) - timing attacks (keeping normal waking hours for his home country, using a vpn instead of tor) - word frequency attacks (since he wrote a lot of press releases, his word choices may have been cross correlated with a personal blog) - bragging to a friend - getting flagged after showing up at a political/high-suspicion meet up (which might be enough to allow for a timing attack) - voice analysis from interviews he did w/o a voice transformer being matched to other audio - opsec blunders (loose lips when talking to press / on IRC / wherever anon talks) Anyone else have any guesses?
- nikcub 15y agoif I were tasked with catching these guys, I would: * setup numerous honeypot open proxies and tor gateways * work with journalists to have all emails and communications forwarded * isolate ddos clients and reverse-engineer command and control. surprisingly many of these trojans are poorly written and have security holes themselves * setup numerous fake twitter profiles and provoking them into responses - things like posting images, replying, etc. * setup fake hacker groups. stage defacements etc. in order to get in touch with them * I would write a system that tracks and stores every bit of communication they make and plot out their social communication graphs and when they are talking, who to, etc. * ask ISP's or proxy providers to grep for traffic patterns. * get user-agent info from twitter, or provoke them into visiting a link, and possibly load malware. no browser is really safe in a targetted attack * word/speech tracing. this is why 1337 5p34k was invented, so you can not be traced via your vocab/grammar/spelling/phrases etc. it doesn't take a large sample to start narrowing it down probably more - haven't really thought about it, but when i did see that they started using twitter I gave them 3-4 months, tops.
- 15y ago
- driverdan 15y agoI'm curious what led to all the arrests. It's not that hard to hide your identity if you truly want to be anonymous.
- fragsworth 15y agoI would imagine it is pretty hard to make no mistakes. He might have accidentally logged into his twitter account (or some other account known to be his) through the wrong browser, which allowed them to see his real IP address.
- tlear 15y agoTaking all the precautions necessary and doing it consistently while not talking/bragging about it to outside people requires a lot of discipline. Most of these guys do no really have it. It takes few rounds of arrests, trials etc for the core group of survivors to get actually paranoid smart enough.
- knieveltech 15y agoHiding your identity from casual observers: trivial. Hiding your identity from scrutiny by local law enforcement: straightforward. Hiding your identity from scrutiny by federal agents: Tricky. Hiding your identity from scrutiny by an international investigation after having pissed off several high octane intelligence agencies: impossible.
- 3pt14159 15y agoNot impossible. Very burdensome and lonely, but not impossible.
- 27182818284 15y agoNot impossible in the strictest since, but highly improbable. Even Bin Laden went down and he had a lot more on his side than all of the members of lulz and anon combined.
- rajpaul 15y ago
- sausagefeet 15y agoFor computer crime do they have to be able to draw a direct line from the act to the person's computer? Also, does a persons computer legally mean they committed the crime? What I'm getting at is, could a group like LulzSec guarantee lighter sentences for themselves if a line could be drawn from the crime to the group but you couldn't determine who actually hit the keyboard?
- starwed 15y agoIn the US, they could be charged with "Conspiracy to commit <crime>". >One important feature of a conspiracy charge is that it relieves prosecutors of the need to prove the particular roles of conspirators. If two persons plot to kill another (and this can be proven), and the victim is indeed killed as a result of the actions of either conspirator, it is not necessary to prove with specificity which of the conspirators actually pulled the trigger.[1] I'd assume English law has something equivalent -- it's a really old problem, and involving computers won't change the principles involved. [1] http://en.wikipedia.org/wiki/Conspiracy_%28crime%29#Conspiracy_in_the_United_States http://en.wikipedia.org/wiki/Conspiracy_%28crime%29#Conspira...
- deleted 15y ago[deleted]
- _delirium 15y agoGiven the close proximity of this case to the News Corp phone-hacking case, any bets on whether similar conspiracy-to-hack charges will be brought against all the people who were involved in that one? Not putting large odds on it; I'd bet that if anybody goes to jail for it, it'll only be a person or two who can be shown to have actually personally done the break-in.
- _delirium 15y agoExcellent. This means the problem is solved and we don't have to secure any of our systems, because he was a one-in-a-billion case that nobody could replicate. (Surely nobody is currently doing the same things with less fanfare.)
- commandar 15y agoSo we shouldn't arrest people when they commit a crime because others are committing the same crime? Or because they're doing it in a high-profile manner? I'm not sure what your point is here.
- 18pfsmt 15y agoI think his point is that by doing this we are simply treating the symptom (breach in security), and not the cause (unsound security measures). It appears to me as "security theater" in every sense that I understand the phrase.
- atomicdog 15y agoAlthough, of course, the police aren't the ones who would be patching up the security vulnerabilities anyway. So arresting unethical hackers and securing systems aren't mutually exclusive. What a country!
- electromagnetic 15y ago> It is dangerous to be right in matters on which the established authorities are wrong. ~Voltaire Our governments have no comprehension or understanding of the prospects or implications that the internet has on modern civilization. When an individual can take down an organizations method of operation (mastercard/visa/paypal), it isn't the individuals fault (regardless of their actions) it is the organizations fault. You don't blame someone for stealing from a bank when they pile gold bullion in the entrance without a guard in sight. You blame the bank because that's fucking stupid. Being able to dDOS mastercard isn't the individuals fault, it's mastercards. I've never heard of someone dDOSing Google, why? Because Google only makes money when people access it and their system can support insane amounts of instantaneous traffic. It's a simple fact that sooner or later mastercard/visa would have been taken down by a normal traffic spike. Is it the users fault when mastercard gets dDOS'd by a few million people placing midnight orders on Black Friday? Seriously, look at the world rationally. If I can spend $5 on a padlock, it's my fault when someone steals my $500 BBQ from my back yard. Someone committed a crime, yes, but I'm going to be buying a padlock like I should have in the first place. Why didn't mastercard/visa/paypal/sony/sony/sony/(sony x 27 fucking times) front the goddamn cash so they wouldn't lose hundreds of thousands.
- r0s 15y agoIt always grates on my nerves when someone that young, seventeen, is referred to as a "man". I suppose teenagers enjoy more freedom in Europe, maybe it's more appropriate there.
- deleted 15y ago[deleted]
- adw 15y agoScots law: age of consent (and age you can enlist) is 16, drivers license is 17, drinking and voting is 18. And this is Scotland, so the age of criminal responsibility is 12. (Until recently, it was eight: http://news.bbc.co.uk/1/hi/scotland/7916561.stm http://news.bbc.co.uk/1/hi/scotland/7916561.stm).
- cwiese95 15y agoI found it interesting how he deleted all of his twitter updates with the exception of "You cannot arrest an idea"
- chuchurocka 15y agoI think that at least a few other people have access to the account. To bad there isn't an api to see when the tweets were deleted.
- xctually 15y agoHA! You cannot arrest an idea!
- mckoss 15y agohttp://www.quip-art.com/3RP http://www.quip-art.com/3RP
- jared314 15y agoThey always shoot the messenger.
- JacobIrwin 15y agoThe top minds behind Lulzsec are worth more to federal authorities ALIVE - when (or if) they are caught. By alive, I mean: not in a prison cell. Frank Abagnale Jr. comes to mind.
- tmp43522 15y agoNo they're not that good, if the arrests are correct then they're actually pretty bad. For the little value that they are worth, they're worth far more as an example to be made for others.
- Tsagadai 15y agoActually, arresting them is next to worthless. Does the oodles of cash spent each year pursuing, prosecuting, jailing, fining, policing and enforcing vandalism cases result in decreased vandalism? Boredom is a social problem, no amount of enforcement will reduce bored kids desire to break stuff. If anything, drawing attention to Anonymous only attracts more people to it.
- srl 15y agoI doubt it. The people who are worth catching for the sake of their minds ... don't get caught. At least not nearly as easily as this group.
- Volscio 15y agoI was surprised there was someone in the Shetland Islands?