8 ms·
This affidavit is a laugh riot so far. Guy has a background in infosec, an holds a CISSP cert, among others. The FBI sends him crypto and what does he do?! (1)
by MarchKilroy89 4y ago
This affidavit is a laugh riot so far. Guy has a background in infosec, an holds a CISSP cert, among others. The FBI sends him crypto and what does he do?!
(1) immediately opens a KYC custodial account
(2) xfers the crypto there
(3) converts it to USD and sends it to his KYC bank in Colorado.
You can't make this stuff up. Also I love how (ostensibly either proton or tutanota) is referred to "Foreign Email Provider". They should buy ForeignEmailProvider.com and make it another email domain for their users. I would love hackerman69420@foreignemailprovider.com
- vdfs 4y ago4 minutes later, someone registered that domain
- MarchKilroy89 4y agoWasn't me! But I expect my hackerman handle when you get your infra set up, anonymous registrant! :p
- arthurcolle 4y agoThey should just redirect ForeignEmailDomain to whatever the real foreign email domain was lmao. What is it, Tutanota? ProtonMail? FastMail? Lmao
- kevin_thibedeau 4y agoYou should grab Hackerman31337 first. That will be worth something.
- lamontcg 4y agoi call dibs on zerocool@foreignemailprovider.com
- wswope 4y agoDon’t mind me; just checking for any automated scripts that are watching for unregistered domains mentioned on here: SmallPPDomainRegisterBot.com
- runnerup 4y agohow would you differentiate a script from a troll?
- bergenty 4y agoWhat’s the difference in this case?
- wswope 4y agoSmallPP-HN-Troll.com Troll the troll into trolling themselves?
- jjoonathan 4y agoA mystery for the ages.
- 93po 4y agoThis domain does in fact point to a potato shaped like genitalia. Either someone had $10 to spare for a laugh or the bot does exist
- rsj_hn 4y agoBrilliant! Also try "ShadyForeignEmailProvider.com"
- fsckboy 4y agothat's taken, I suggest NotShadyForeignEmailProvider.com
- jrockway 4y agoOne of my deep background worries is how many criminals aren't caught because they don't make amateur mistakes. You always read these indictments and the perpetrator served themselves up on a silver platter. But what about all of those unsolved crimes that might simply be unsolvable!
- bowmessage 4y agoThis is FUD, but don't discount the fact that the 'easy' path to catching this criminal could be fabricated in order to hide the real, more intense, methods used by the authorities to uncover Jareh.
- jjtheblunt 4y agoTo your point, he worked for the NSA for 3 weeks, only 3 weeks! So some such system detected him as a threat and he left in under a month of employment? That's wild.
- wjnc 4y agoWell this takes the testing of compliance with regulations to a new level though. And here I am, doing my daily and weekly chores with HoxHunt and two other Q&A websites on our compliance procedures. And these aren't intellectual questions or anything - rote memorization is what they are striving for. I wish they would just send me crypto and be done with it.
- jjtheblunt 4y agoFiat would be more useful!
- adultSwim 4y agoIn the jargon, this is called "parallel construction".
- loxias 4y agoI don't think it's FUD at all. Evidence laundering is well documented and has judicial approval by the Roberts court...
- mzs 4y agoAnd he worked at NSA for under a month.
- jmkni 4y agoThis is interesting, I wonder if he quit or got fired. Bit of a red flag to work for the NSA and quit after a few weeks lol
- deleted 4y ago[deleted]
- jiveturkey 4y agoI'm guessing he fell for some internal honeypot, and that led to his immediate termination and subsequent monitoring. Then he also transmitted the honeydocs and the rest. Sure they traced the crypto but that's not how they got him.
- notch656a 4y agoOnly explanation I can think of is dude planned to leave the country shortly and figured he'd be gone by the time he got caught so there was no point in covering it up. Also based on the value the crypto was Monero (and he use Kraken, which is only big US exchange that converts XMR/USD pair), so he probably didn't realize even though it is difficult to directly trace where it came via the blockchain the exact unique amount deposited on KYC exchange fucked him. A naive Monero user would probably think "impossible to find where monero came or went from, so I'm safe" not realizing they're leaking out the side-channel by depositing a unique amount on a centralized exchange.
- cypherpunks01 4y ago"His resume also states that he has specialized training with federal law enforcement related to digital forensics and incident response, dark web investigations..." Lol, I suppose he's guilty of lying on his resume too!
- queuebert 4y agoAs opposed to the domestic email providers that willingly hand over private info when they ask politely?
- throwoutway 4y agoMost CISSPs I interview can’t tell me the difference between the two most common types of encryption
- walrus01 4y agosaw a CISSP who didn't know the difference between a SHA256 checksum and SHA1 or even how to hash a file using openssl
- throwoutway 4y agoI would expect that. But the lack of knowing the definitions is embarrassing
- Something1234 4y agoDoes anyone have a tutorial on using the openssl cli? It seems to barf on some inputs if it's not exactly perfect or you miss a step in the stack overflow answer. Honestly I would expect some to be more familiar with the hashXsum tools.
- deleted 4y ago[deleted]
- computerfriend 4y agoI'm relatively deep in this stuff. If you asked my how to use the openssl CLI for anything other than X.509 and s_client I would fail your interview.
- est31 4y agoYeah openssl CLI is so incomprehensible. And some parameters have to be configured using .conf files, ewww. The C API is hardly any better. When I read the RFCs behind the stuff to write what I needed in Rust, suddenly it dawned on me: wow this stuff isn't nearly as complicated and horrible as openssl's interface makes it seem like.
- walrus01 4y ago
- yieldcrv 4y ago> on or about August 24, 2022, the OCE deposited approximately 0.64053413 units of the requested cryptocurrency, worth approximately $99.90 USD Monero was worth $154 on August 24th, is a privacy crypto and .64 of that would be $99
- deleted 4y ago[deleted]
- belter 4y agoThe NSA has 32,000 employees. Not everybody there is a Ramanujan...