4 ms·
My organization Fight for the Future was targeted by the same hacking-for-hire operation while working on net neutrality protections. It was really interesting
by holmesworcester 2y ago
My organization Fight for the Future was targeted by the same hacking-for-hire operation while working on net neutrality protections.
It was really interesting because at the time the conclusion of our security consultants was that the attack was just random commercially-motivated prospecting. Then the Citizen Lab Dark Basin report came out years later and it was clear they were after our internal comms, so they could milk a decade of emails for anything that looked bad when taken out of context. Yikes.
After the attack we put a 3 month retention limit on most emails and messages. I recommend this to anyone doing sensitive work! You miss the old emails sometimes but it's worth it.
I think it's possible we'll learn more soon about who hired our hackers, which is exciting! It was almost certainly a major American ISP, or the lobbying umbrella group they created. It's my optimistic read that blowback from this case has already eroded the practice of dirty tricks like these. More lobbyists and companies getting caught would strengthen the effect.
Since I left Fight for the Future I've been working on a Signal alternative that feels more like Slack, for teams facing similar threats. Hopefully something comes of that too!
- tmpz22 2y agoAny reason you can’t dump an air gapped archive and put it on a physical device in a deposit box? Best of both worlds should you truly need to access it. Or are depositions also a concern? Funny enough I just did a business law presentation on Comcast Corp v FCC (2010). Thanks for doing what you could for Net Neutrality
- holmesworcester 2y agoIt was a pleasure! We lost nominally in the end (except in California and outside the US) but we built enough awareness to give the ISPs a fear that blatant violations would rock the boat and lead to worse outcomes for them, like more state laws or tougher agency rules when Democrats regained power. I do regret not pushing harder for federal legislation though! On airgapped email archives, yes, the subpoena threat model is real too. That also happened to us because of some other dirty tricks by ISPs in the same campaign! Fake FCC submissions opposing net neutrality were being created with blatantly stolen user data; like, not people being tricked into singing a petition but just straight up identity theft. We documented all of this and pitched some state AGs on looking into it. New York did, which was awesome, but they ended up subpoenaing everyone including us! We were psyched about this overall of course since it was our idea, and they did end up finding out who did it which was awesome (Broadband for America, the umbrella lobbying group for the telcos) but it was a huge amount of work to comply with the subpoena. The retention limits reduced that burden. Another reason to have them! I would also say that, if you do create an airgapped archive and store it in an appropriately paranoid way, you are likely to never ever bother to dig it out of storage before the SSD melts into uselessness. You'll miss the ocassional old email but not enough to go digging for it.
- lukan 2y agoIf you really don't need old email, then don't bother, but for the chance that you do need them sometimes, but don't want to store everything in an internet connected place - it would be an option setting up a old laptop for this(maybe with Thunderbird), where you can remove the wifi chip for this air gapped use case. (In most older laptops they are easy to remove and not soldered on.) Then regulary exporting all the needed files, either just copy them with a USB stick and more secure would be burning CD-R's for each data transfer. And it likely helps having an exotic linux system on the laptop, so a windows USB worm won't replicate there if you use the pragmatic USB data transfer variant.
- michaelt 2y agoNah, the value of having access to 3-month-old e-mails is that they're indexed in gmail, so if someone asks how much we paid for that widget 18 months ago you can get the original quotes in an instant. Whereas if the data is in a bank vault, you ask the same question and the reply is "IDK, I think it was about $50-100?"
- holmesworcester 2y agoExactly.
- Teever 2y agoSurely there's a middle ground for these things. The value in old data isn't just in pulling up a single piece of information like a magician pulls a rabbit out of their hat, it's tremendously useful for looking back and seeing how an organization and its methodology has changed and how that information can be applied to future project.
- michaelt 2y agoI see it as less about pulling up a single piece of information and more that a tool that every employee uses a dozen times a day produces much more value than the same tool if it's used only by the big boss, and only once or twice a year as it's so inconvenient to use
- DaiPlusPlus 2y ago> After the attack we put a 3 month retention limit on most emails and messages. I recommend this to anyone doing sensitive work! You miss the old emails sometimes but it's worth it. How are pro-delete policies like these impacted by the discovery-process in law? Or even Sarbanes-Oxley?
- holmesworcester 2y agoGreat question. IANAL but my understanding is that outside of some specific regulatory requirements in specific industries you're free to put these policies in place as long as you do it before you have any expectation that you're going to be sued. That's another reason to bite the bullet and put these policies in place now: once you actually have a specific fear of being sued it's maybe too late, because at that point changes to your retention policy could be construed as interfering with the legal process. You can also have your policy exempt certain categories of documents (like financial records) and that's okay too as long as you're consistent about it.
- mmooss 2y ago> Yikes. That's a common response these days and while I empathize, I think it's wrong. The right response IMHO is, essentially, 'fuck them; they can't stop us'. A Soviet dissident (I don't recall the name atm) advised not talking about your arrest, torture, detention - the horrors, the fear, etc. That's what the oppressors want you to do, to spread fear and intimidation to all the people they didn't arrest; that's half the point of their actions - they don't have the resources to arrest everyone. If you don't talk about it, it's a forgotten moment of one small point in time and space. It's the echoes of it, of people repeating the story, that spread across orders of magnitude more time and space. Don't spread it around and you've disarmed your oppressors. Also, look at contemporary political movements: The overwhelmingly successful one is barely slowed by attacks, never expresses any fear or intimidation, is always on the offensive. The flailing one is regularly talking about its terror, despair, whether or not there is any hope at all, and quitting. There's a time and place to talk about your fears - privately, to your trusted confidants (and not to those who depend on you for leadership). Everyone has them; that's fine. Out in public is not the place; that's where you show that you can manage your fears and are resolute, undeterred, unshaken. Think of great leaders - Washington, Lincoln, Churchill, etc. - who ever said 'Yikes'? On social media, we all are leaders.
- soco 2y ago"We must take sides. Neutrality helps the oppressor, never the victim. Silence encourages the tormentor, never the tormented." - Elie Wiesel