21 ms·
Terrorist watchlist exposed via misconfigured Elasticsearch cluster
- scrps 5y ago>The researcher considers this data leak to be serious, considering watchlists can list people who are suspected of an illicit activity but not necessarily charged with any crime. "In the wrong hands, this list could be used to oppress, harass, or persecute people on the list and their families." I'd imagine being on a list that limits your personal freedom without being charged with a crime and convicted falls pretty squarely within the definition of being oppressed & persecuted before even considering any second order effects of the list being leaked.
- sschueller 5y agoThe list should be public or at least I should have the right find out if I am on that list.
- MeinBlutIstBlau 5y agoYou can request if youre on the tsa no fly list iirc.
- brokenmachine 5y agoWouldn't you find out if you tried to book a flight?
- MeinBlutIstBlau 5y agosorry...I mean TSA watch list. But yes you're right haha.
- imglorp 5y agoBook or board? The difference is you bought the tickets in one case and might not get the money back.
- GordonS 5y agoI wouldn't be at all surprised if they used asking if you are on the list as grounds to add you to the list.
- raxxorrax 5y agoIt is amazing what the hunt for terrorism has done to modern countries. They only look fearful and weak, exactly what professional terrorists always wanted them to be. Anyone who knows bureaucratic behavior knows that even in the absence of real terrorists, people will find their way onto lists like these. I hope the lists will leak to a wide audience. Find the cases that are wrong and sue those responsible behind the desks. This is the only way this can stop. The website is extremely horrible. Did use a dev browser without adblock. Grave mistake.
- tester756 5y agoWhy "misconfigured" Elastichsearch being reason appears this often?
- kieselguhr_kid 5y agoBy default, Elasticsearch is unsecured. If you manage your own ES cluster, you have to go through a few steps to secure it manually. Lots of people either don't know/don't care about this though, so they regularly expose their data to the whole internet.
- Saris 5y agoIt has no authentication by default, and it listens on all interfaces instead of just localhost by default. I used it for a while at home for a project, and setting up auth was quite a process, very difficult compared to most other databases.
- mienski 5y agoThink I've posted this before but my employer paid Elastic for the official training - and even that course included everything on how to set up, run and tune ES but applying any security was only covered in the advanced course that you had to pay another $x thousand dollars to attend. So even doing official Elastic training still leaves you with a nice footgun.
- rodgerd 5y agoYeah. "Not leaking data" is basically a pay-for way for Elastic to commercialise the tool. A pretty shitty way, I would say.
- criticaltinker 5y ago> [cybersecurity researcher Bob Diachenko] was able to find about 1.9 million records detailing individuals’ no-fly statuses, full names, citizenship, genders, passport numbers, and more. > “it seems plausible that the entire list was exposed”
- WrtCdEvrydy 5y agoI wonder if this will end up on haveibeenpwned? "The FBI leaked your name as a terrorist"
- tubbs 5y agoThat would be funny (I guess). At any rate, neither email addresses nor phone numbers were part of the leak.
- imglorp 5y agoI would like to know if any grumbling about the agencies on social media--like this post--has landed me on the watch list.
- gjsman-1000 5y agoThe freaking FBI leaked your info. Not a stupid private organization. The FBI. And also, because the FBI doesn't tell people they are watching them, there was absolutely nothing - no product, no service - you could have just not signed up for to avoid this leak. What next, the IRS?
- nullc 5y ago> What next, the IRS? Already happened: https://www.propublica.org/article/the-secret-irs-files-trove-of-never-before-seen-records-reveal-how-the-wealthiest-avoid-income-tax https://www.propublica.org/article/the-secret-irs-files-trov... They don't disclosed how many parties were included, but their description of their validation (they verified it against 60-some public figures who had separately disclosed their tax filings) suggests that it's probably a significant fraction of the US population.
- goodluckchuck 5y agoI wonder if we can even trust the CCP to not leak our party membership!?
- rdtsc 5y agoWonder if they did it on purpose. I can't figure out what the purpose might be - a whistleblower wanting to raise awareness about it and realizing they didn't want to have to relocate to Russia or say live an Ecuadorian embassy for years. Or, I can imagine, a rogue agent wanting to warn someone they are on the list without communicating with them privately, so there is no metadata linking them, and they "accidentally" leaked the whole list.
- cyberlurker 5y ago> “The terrorist watchlist is made up of people who are suspected of terrorism but who have not necessarily been charged with any crime,” Diachenko wrote. “In the wrong hands, this list could be used to oppress, harass, or persecute people on the list and their families. It could cause any number of personal and professional problems for innocent people whose names are included in the list.” I’m curious how many journalists are on the list. Now that we are pulling out of Afghanistan, we should reevaluate the other actions we took after 9/11. The patriot act deserves another look and possible edit.
- ashtonkem 5y agoGiven the history of the FBI deciding that journalists and activists are actually terrorists to be suppressed? Probably quite a few.
- flatiron 5y agoWouldn’t that be hard in practice though? Journalists typically have to travel for work so it would soon be apparent. And if they work for a big media outlet would be instantly litigated.
- ashtonkem 5y agoThis is the terrorism watch list, not the no fly list. Any of us could be on that list and it would take a while for us to know. The no fly list is much smaller, and far less ambiguous in its impact. You’re on that, you’ll find out the first time you try and fly.
- southerntofu 5y agoMost journalists working for big outlets are docile when asked politely not to publish on a certain topic (either by their boss, or by government agencies), and that's how they avoid problems. See for example Glenn Greenwald's choice to leave the Guardian in order to publish the Snowden papers. For the french-speaking among us (not sure you can find english subtitles), the documentary "Les nouveaux chiens de garde" (the new watchdogs) goes into detail, interviewing sociologists and journalists, about the ties between the mainstream capitalist media establishment and other circles of power (industry, political parties). About the no-fly list specifically, you should really check out https://en.wikipedia.org/wiki/No_Fly_List#Notable_cases https://en.wikipedia.org/wiki/No_Fly_List#Notable_cases . Some relevant quotes: > TSA refused to allow an Air France flight from Paris to Mexico to cross U.S. airspace because it was carrying Colombian journalist Hernando Calvo Ospina > On August 19, 2009, Air France flight AF-438 was not allowed to cross into U.S. airspace because of the presence on board of one Paul-Emile Dupret, a civil servant at the European Parliament for 18 years, who had written some articles criticizing the EU's policies toward Latin America because they are aligned too closely with those of the United States > A U.S. citizen, stranded in Colombia after being placed on the No Fly List as a result of having studied in Yemen > In October 2008, the Washington Post reported that Maryland State Police classified 53 nonviolent political activists as terrorists, and entered their names and personal information into state and federal databases Seems like it's not hard in practice for psychopaths in uniforms to abuse secretive powers given to them.
- Rd6n6 5y agoWikipedia says the no fly list only had 47k people on it. The terror watch list had about 1.9M though, so this must be the terror watch list. 1.9M people is a massive number of people > The No Fly List is different from the Terrorist Watch List, a much longer list of people said to be suspected of some involvement with terrorism. As of June 2016, the Terrorist Watch List is estimated to contain over 2,484,442 records, consisting of 1,877,133 individual identities. https://en.m.wikipedia.org/wiki/No_Fly_List https://en.m.wikipedia.org/wiki/No_Fly_List
- OJFord 5y agoThe submitted article does say watch list, it's just the title here that ~has~ had the error. (Editing it was fair enough IMO, at least to remove from 'and boy'...)
- tvirosi 5y agoOr the 47k no fly number is just a lie
- jedimastert 5y agoIt's pretty easy to check, but I'm guessing it's just far easier to get yourself on the watch list.
- mrits 5y agoMust be really annoying when your terrorist cousin comes over and uses your wifi on the holidays.
- deleted 5y ago[deleted]
- jedimastert 5y ago47k vs 1.9M, meaning it's apparently 40x easier to get on one than the other.
- 5y ago
- jl6 5y agoWould love to know how the FBI dealt with transliteration deduplication of non-Latin names, cf. the many spellings of Muammar Gaddafi. Although I guess they would just use whatever’s on the passport?
- oa335 5y agoThey didn’t. I know of several people with an extremely common name (Basically Muslim equivalent of “John Smith”) who were unable to fly or cross borders, even with the “Redress numbers” that they are supposed to give out in case of mistaken identity.
- jessaustin 5y agoThis reminds me of "interstate crosscheck", in which a "Tyrone E. Brown" voting in Pennsylvania was enough to kick a "Tyrone M. Brown" off the voting rolls in Kansas. https://www.gregpalast.com/interstate-crosscheck-on-the-verge-of-collapse/ https://www.gregpalast.com/interstate-crosscheck-on-the-verg...
- nurgasemetey 5y agoOut of curiosity, how can I search myself?
- nullc 5y agoLeaks are for intelligence operatives to act with plausibility deniability ("It was hackers!"). They are not for you to use to create accountability by discovering inappropriate inclusions and demanding answers.
- clipradiowallet 5y agoInquiring minds want to know
- deleted 5y ago[deleted]
- sergiomattei 5y agoYeah, I'm curious! I recall the NSA's XKeyscore was revealed to put Linux Journal readers in watch lists.
- krapp 5y ago>I recall the NSA's XKeyscore was revealed to put Linux Journal readers in watch lists. No, it didn't. See this comment by grkvlt[0] and another debunking here[1] [0]https://news.ycombinator.com/item?id=12070156 https://news.ycombinator.com/item?id=12070156 [1]https://blog.erratasec.com/2014/07/validating-xkeyscore-code.html https://blog.erratasec.com/2014/07/validating-xkeyscore-code...
- sergiomattei 5y agoThank you for the clarification! Did not know this.
- ClumsyPilot 5y agoAs expected, it is only a matter of time untill all the intensely private data collected by NSA and pals is leaked or stolen and used by criminals for fraud and extortion.
- vmoore 5y agoThis. Eventually all sensitive data becomes concentrated enough that it becomes leakable material
- deadalus 5y agoUsually by an insider.
- sneak 5y agoThe main databases the NSA has are far too large to be easily leaked. Even blueleaks was <1T (~300GB iirc) and many people had trouble downloading it. I am sure many IC databases are several hundreds or thousands of times larger even without indices. It's not like you could just throw up a 4000TB torrent for a 7z of all of the north american phone call metadata for last year.
- nonameiguess 5y agoWhen I worked on the main NRO ground processing station for electro-optical collections, we were generating double-digit petabytes daily, and that back in 2008. Don't even know what it's up to now. Not only is there no practical way for anyone other than maybe Google or CERN to download that much data, unlike the no-fly list, actual classified information isn't attached to any networks that can be accessed from outside of a secure facility. This means the only way to egress data is for an inside threat to copy it onto USB drives or possibly optical media, maybe steal hard drives. But there are pretty hard limits to what you can just bulk copy. It can't be much more than a person can hide in a bag.
- rsbrans 5y ago
- TekMol 5y agoWhat would happen if you put all these people together on an empty island?
- fouc 5y agowho is John Galt?
- aaomidi 5y agoThey would be super confused since there is really no checks on who gets put on this list.
- OneLeggedCat 5y agoYou'd have about 1.9 million people on an island, the vast majority of which are normal, average people.
- Ceezy 5y agoThese people are morons! They claimed to be crème de la crème and watch. Few years ago they wanted to force Apple to create a "secure backdoor". Hope we gonna get more details. Sorry for the rant
- ClumsyPilot 5y agoI wonder how many hacks happened purelu because of these backdoors
- gjsman-1000 5y agoJust an hour ago I was having a dialogue with someone on Hacker News saying we needed a national ID system after the T-Mobile hack. I said that the US Government should not be trusted to be any more secure than T-Mobile with such a system. I rest my case.
- creato 5y agoA national ID doesn't necessarily have data security implications any more than the current state-by-state DMV system does. The relevance of a national ID is (presumably) so that banks can check identity more reliably, i.e. making security breaches like the T-Mobile one irrelevant. It wouldn't matter if your SSN was public information.
- adolph 5y ago> check identity more reliably Most states in the current system seem to have a crude biometric identity verification of a photo plus point in time stats of height/weight/coloring, all of which is nominally protected/validated by counterfeit protection. How would a national ID be any different?
- nautilius 5y agoDo you have to have a 'crude state ID'? Is there any legal pressure to keep the data on it up-to-date? Are the standards for 'crude state IDs' identical between states or would you have to know the rules and regulations of 50 different jurisdictions?
- Joker_vD 5y agoYou know, I can understand why the Terrorist Watch List is secret ― but not why the No Fly list is. If there is a list that governmental agencies and/or commercial companies are obliged to check you're not on before providing you with their service, then surely such list must be public or at the very least, one should be able to easily inquire about whether he/she is on it or not. For a related example, Russian government maintains a list of banned Internet resources. The list is not public — at least in theory — but there is an official web site where you can input an URL or a domain name and it would response either with "no, it's not on the list", or with "yes, it's on the list, here's who ordered it and when".
- datavirtue 5y agoIt's not a secret, just need-to-know basis.
- outworlder 5y agopotato potato
- londons_explore 5y agoSurely the easy way to check if a name is on the list is to book a flight in that name. If the booking gets rejected, it's on the list. Repeat for every name you want to check, and make use of the airlines free cancellation policy so you don't actually have to spend money.
- dukeofdoom 5y agoSo basically a list of Trump supporters. Well known for their opposition to COVID measures, and claims of election fraud, and belief that Trump can be reinstated.
- c3534l 5y agoWhat makes you say its a list of Trump supporters?
- dukeofdoom 5y agoThey build a fence around the capital to protect against them. Since there's no way there are actual 1.9 million terrorists in the US. 1.9 million/326 million is about 1 person out of 200 on that list. In all likely hood, its just a list composed of people in opposition to government. Can't be many BLM protestors, and leftists, since government is flying their flags. Simple deductive reasoning will get you to that this list is mostly Trump supporters from his populist movement. Just read the latest Terrorism Threat bulletin from DHS. Then visit Gab.com, if you have any doubts on the overlap. Summary of Terrorism Threat to the U.S. Homeland https://www.dhs.gov/ntas/advisory/national-terrorism-advisory-system-bulletin-august-13-2021 https://www.dhs.gov/ntas/advisory/national-terrorism-advisor...
- tubbs 5y agoThe list seemingly not just citizens of the United States.
- datavirtue 5y agoAnother Q drop.
- deleted 5y ago[deleted]
- jjulius 5y agoYou could've distilled your answer to the question by simply saying, "Pure speculation based on a faulty assumption that only US citizens are on this list".
- sonicggg 5y agoWhere is this alleged list then? Very convenient that this guy is not disclosing a link to this supposed leak. I think someone wants notoriety.
- mygoodaccount 5y agoIt looks like it was "leaked", as in, publicly exposed server indexed by a few search engines. It's possible that this researcher was the only one to come across it, and reported it immediately. In which case it'll never see the light of day.
- serf 5y ago"The exposed server was taken down about three weeks later, on August 9, 2021. It's not clear why it took so long, and I don't know for sure whether any unauthorized parties accessed it." three weeks open on the internet; it seems unlikely that no other party accessed it.
- ransom1538 5y agoCan someone post the list?
- hughrr 5y agoAwaiting future headline “Secret CSAM hash list leaks online”. Keeping lists secret appears to be something the human race is really really bad at.
- grishka 5y agoIt's so secret it gets distributed to every compatible iOS device, right
- throwaway4688f 5y agoWhere is the torrent, dammit? Internet ain't what it used to be.
- alexfromapex 5y agoThe fact this wasn't protected by a VPN is amazing
- thepasswordis 5y agoSo this is definitely going to be used for character assassinations right?
- thepasswordis 5y agoSuggestion: Take the Facebook leak from earlier. Create hundreds of collections if 1.9M people. Release it to the dark web. Just flood then zone with noise. FBI can still keep their list (and know it’s legit), and peoples privacy will be ensured. Otherwise this is going to 100% get integrated into various social credit systems we have in the US.
- mygoodaccount 5y agoDid some perusing - can't find it anywhere you'd normally find these things. Let me know if anyone does!
- 1023bytes 5y agoPerhaps yet another unsecured MongoDB?
- tom7 5y agoIt leaked so hard that nobody outside of mainstream media saw it. You people are idiots.
- deleted 5y ago[deleted]
- tomc1985 5y agoElasticsearch is like the security breach gift that keeps on giving...
- kieselguhr_kid 5y agoI mean, the FBI should 1000000% know better than to expose their unsecured Elasticsearch cluster to the internet. While Elasticsearch should be more secure by default, I'd say the blame is much more on the agency.
- tomc1985 5y agoHas Elasticsearch done anything to fix its ridiculously bad lack of access control? People are fucking stupid, and expecting them not to fuck this up is a big ask. Too big, in fact. Secure by default or GTFO
- kieselguhr_kid 5y agoI think it's reasonable to expect the FBI to not expose this. I'm with you on Elasticsearch being too insecure but you're talking about secret government info. If they put that on the open internet that's a serious failure on their part and they'd have fucked it up with another tool if they weren't fucking it up with ES.
- clipradiowallet 5y agoElasticsearch has nothing to fix - the product does precisely what the config tells it to. Maintainers of various distros ES packages are largely responsible for any [mis]configuration there. If you'd like to read how you can secure ES, go do that: https://www.elastic.co/what-is/open-x-pack https://www.elastic.co/what-is/open-x-pack PS: x-pack is the piece that adds authorization/authentication to ES.
- altdataseller 5y agoYou can setup username and pass auth in newer versions of Elastic without paying for xpack (I think at version 6 or up?)
- outworlder 5y ago"Misconfigured Elasticsearch cluster" Doubly so. No passwords _and_ it was exposed. There's no real reason to ever directly expose a database to the internet for 0.0.0.0/0. Heck, there's no reason to expose to any routable address. Yeah sure zero trust or whatever. Still, why even risk it? Layers.
- atonse 5y agoThis is what I came here to ask. How did this server even have a public IP?
- Saris 5y ago>There's no real reason to ever directly expose a database to the internet for 0.0.0.0/0 And open the host firewall too, there were quite a few layers of absolute incompetence involved here!
- deleted 5y ago[deleted]
- r1ch 5y agoIt's amazing how many hacks and data breaches all come down to dangerous default settings. Elasticsearch defaulted to no security, anyone hitting the IP has full access to the cluster. MongoDB is another infamous example. Even today, one of my sites is being DDoSed by a bunch of 2007-era Ubiquiti network devices which use ubnt / ubnt as the root login and naturally got exposed to the internet. Bad defaults linger for a long time.
- southerntofu 5y agoAnd that's why some of us use firewalls, and/or avoid the Docker craze like hell.
- _moof 5y ago"In the wrong hands, this list could be used to oppress, harass, or persecute people on the list and their families." Teetering on the brink of an epiphany.
- dane-pgp 5y agoThe person who you're quoting is likely a "SelfAwarewolf": "A person who, when trying to criticize those who match a certain description, fails to realize that they have (in the process of criticizing others) revealed themselves to match the exact same description" https://neologisms.rice.edu/index.php?a=term&d=1&t=24708 https://neologisms.rice.edu/index.php?a=term&d=1&t=24708
- jessaustin 5y agoThere is no reason to think that Bob Diachenko is such a person. He didn't take part in the authoritarian project that generated these lists.
- kamray23 5y agoIndeed, he simply prevented the list's proliferation
- _moof 5y agoI probably should've added that as a parenthetical - those words weren't spoken by the people who made the list. And it's hard to tell how much of an implied wink is behind that quote. I know if I'd said it, I'd have done so with subtext.
- jessaustin 5y agoYou clearly communicated that meaning, but the reply to yours seems to overstate things in an unfair way.
- woodruffw 5y ago> Additionally, the researcher noticed some elusive fields such as "tag," "nomination type," and "selectee indicator," that weren't immediately understood by him. I'm not sure about the others, but "selectee indicator" might be whether the individual is on the Selectee list used for SSSS flagging[1]. [1]: https://en.wikipedia.org/wiki/Secondary_Security_Screening_Selection https://en.wikipedia.org/wiki/Secondary_Security_Screening_S...
- commandlinefan 5y agoAt least last time I looked at it, ElasticSearch is shockingly insecure by default (as are Mongo, Cassandra, Hadoop, and everything else that's popular in the relatively recent Java ecosystem).
- snarf21 5y agoYeah, this is the same as Wi-Fi routers all being admin/password. They finally started assigning them random pwds. Why isn't secure by default chosen?
- l0b0 5y agoThat's easy: perverse incentives. 1. Secure by default makes for a higher barrier to entry. It's human nature to want to keep barriers of entry low for your life's work. (I have similar thoughts around copyleft licenses being better for the users but hard to sell to the creators.) 2. Security is "available" to anyone savvy enough to clear all the hurdles to secure the system, so the creators feel justified to blame the user. 3. The product is developed with an assumption that something outside the product is supposed to provide security. For example, the Go.CD devs (excellent product otherwise) scoffed at the idea of improving their crappy password hashing (single round of SHA256 with no salt IIRC), instead suggesting that I should wrap the service in some other, safer authentication mechanism.
- Saris 5y agoIt's crazy how much stuff is just no auth and listens on all interfaces by default.
- MichaelMoser123 5y agoFor a system like ES there is encryption in transit and encryption at rest. https://docs.aws.amazon.com/elasticsearch-service/latest/developerguide/encryption-at-rest.html https://docs.aws.amazon.com/elasticsearch-service/latest/dev... amazon elastic search gives you the option of encrypting the data at rest (meaning it is encrypted by amazon ES when stored persistently) - they use KMS for key management, so it should have a per record symmetric key that is encrypted by master symmetric key. It's notable that the amazon fork has added this functionality, this does not seem to be part of elastic search proper (please correct me if I am wrong) Elastic search proper is only talking about encryption in transit https://www.elastic.co/what-is/elastic-stack-security?ultron=B-Stack-Trials-EMEA-Other-UK-Exact&gambit=Security-Elastic-Security&blade=adwords-s&hulk=cpc&Device=c&thor=elasticsearch%20encryption&gclid=CjwKCAjw3_KIBhA2EiwAaAAlii_hMSFyQZb8bikIOPqZV_vAakNhaFiM9D6JosZgt62eDBAyODFLvBoCXMYQAvD_BwE https://www.elastic.co/what-is/elastic-stack-security?ultron... Here they say that they don't have encryption at rest https://www.elastic.co/guide/en/cloud-enterprise/current/ece-securing-considerations.html https://www.elastic.co/guide/en/cloud-enterprise/current/ece... Now you can possibly encrypt the records at the application level, but that makes them unsearchable; however the ability to search the stuff is arguably the point of having it in elasticserarch.
- londons_explore 5y agoWith 1.9 million people,there must be plenty of people here whose data is in this list. Any of you care to comment?
- southerntofu 5y agoI have no clue if i'm on the list. However as an anarchist i believe there are chances i'm on there, because we anarchists are opposed to all forms of domination and exploitation, so there's a lot of people in power who are angry at us. The ancestor of Interpol, the first international conference gathering psychopaths from political police from across the planet in 1898, was famously a conference "for social defense against anarchists": https://en.wikipedia.org/wiki/International_Conference_of_Rome_for_the_Social_Defense_Against_Anarchists https://en.wikipedia.org/wiki/International_Conference_of_Ro... I have had many friends over the years go through prison and put on "terrorism" lists by the french secret service for their political activities. Government is tyranny. Governments only exist to serve the rich and powerful, and ensure nothing ever changes. If you're not convinced, you can look up FBI's "COINTELPRO", of which the current no-fly list program and terrorism-creation program (search for "How the FBI creates terrorists", plenty of documented cases) are just a continuation of COINTELPRO and other FBI/CIA programs designed to prevent the people from exerting their free will and right to organize.
- trident5000 5y agoOnce government agencies are given approval from congress they typically have very little oversight from that point on including from congress. Its why we get abusive behavior from so many of them. NSA: Prism DEA: Asset forfeiture FBI/CIA: Abusing fisa and using five eyes to spy domestically IRS: Political targeting etc etc etc
- giantg2 5y agoATF: Approving background checks on known traffickers and continuing to sell them guns even after there were concerns they couldn't track the weapons. (And ruby ridge, and waco... )
- throwaway0a5e 5y agoATF is the one of the few federal agencies that's simultaneously hated by both the right and the left. They bring crime to poor urban areas with their anti-gun trafficking operations and violate people's 2a rights left and right with their mundane administrative operations and enforcement thereof. Nobody who knows what they do likes them.
- giantg2 5y agoEven the FBI dislikes them. Both Waco and Ruby Ridge started as botched ATF operations that the FBI had to take over.
- int_19h 5y agoWhat really bugs me about these lists isn't just that they exist, but that there's continuous clamoring to expand the scope in which they are applied. For example: https://www.theatlantic.com/politics/archive/2015/12/no-fly-list-inverted-politics/419172/ https://www.theatlantic.com/politics/archive/2015/12/no-fly-... So, basically, politicians have found it to be a convenient tool to skirt due process concerns in general when pushing for their favorite agenda.
- southerntofu 5y agoDatabases of people are the exact opposite of human rights. IBM famously enabled the nazi holocaust to go faster/further because of their punch-card databases. Eastern Germany Stasi, and KGB/FBI scandals famously pushed for privacy regulations in pretend-free countries like France (Loi Informatique et Libertés, 1978). Anything that uniquely identify someone else (ID card, phone number, DNA) is a tool of tyrants to oppress their people.
- afrcnc 5y agoSource of this convoluted blog spam: https://www.linkedin.com/pulse/americas-secret-terrorist-watchlist-exposed-web-report-diachenko/ https://www.linkedin.com/pulse/americas-secret-terrorist-wat...
- voldacar 5y agoSo somebody found the terrorist watchlist and didn't upload it anywhere or start a torrent, but instead took some screenshots and gave vague descriptions of the data to journalists? I'd like my reality unmediated, please
- jimmaswell 5y agoMaybe they wanted to mitigate their risk of major prison time.
- SevenSigs 5y agoWhere can I get the list? This should definitely public (unless they just put random people on the list).
- southerntofu 5y agoIt should definitely be public, but it isn't. And just like any political repression database, it's filled with random people.
- smitty1e 5y agoAmong the basic concepts of American Civil Rights used to be Sixth Amendment right to confront accusers. Legal weenies may engage in mental gymnastics to rationalize the evil of no-fly lists. They deserve the receiving end of their perfidy.
- thephyber 5y agoI’m curious if anyone who is on the leaked list now has standing in court to litigate their status, whereas they could not prove their status/data before. One of my biggest complaints with national security programs is that they tend to argue that transparency (even to the voters and elected representatives whom these programs ostensibly protect) threatens the program. Sometimes when leaks happen, it gives the citizens a tool they didn’t previously have to challenge those programs.
- deleted 5y ago[deleted]
- hcduytWW 5y agoChristian Garreth is my name and i reside here in Los Angeles, i work as a dispatcher and got dropped down from work in regards to Covid-19 but before the incident i was able to save some funds hoping to invest someday into some good business that can really brings out good income, before I got dropped from my job due to covid-19 i came across a broker trading site which deal on cryptos and i signed up with the site and a representative called me, it was a female voice, she made me feel comfortable and i trusted the process so i decided to invest with $8500 in Bitcoin, after three months of loosing my job i decided to make a withdraw and i was ask to pay more then i did until i noticed i have paid $46,980 US Dollars which led me into debt and the worst of all was that the whole thing was a scam so i decided to look for a means to get my funds back. then i came across several hackers online about 4 of them who took my money and take advantage of my situation, i totally gave up and i lose my apartment along the process so i was squatting with a friend of mine who works at a grocery shop, it was my lucky day when i got referred by someone close to me to email wizardharry (@) programmer (.) net or WhatsApp him +1- (807) 808 - 6168, i did as instructed and when i explained everything to him, he only asked me for details and the cost of the services and it was very affordable and understood by me so i decided to give it a try, a try turns out to be something great and bigger than my expectation. today I'm a happy man and all my funds were recovered by him and my life changed for good. please don't fail to contact wizard harry for scam funds recovery.
- atok1 5y agoThis is the definition of authoritarian. We need to make this list public ASAP! If you have a copy, please do humanity a favour.
- readonthegoapp 5y agoI figure the FBI is using ES, with all its default insecurity and RCE features, as a honeypot.