Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The FBI used standard police techniques to infiltrate and eventually dismantle the those groups.

Seriously, how do we know the FBI's story isn't "parallel construction"? It always seemed to me that tracking down Anonymous would be easy if you had NSA-scale monitoring. I don't want to sound like paranoid guy, but maybe the FBI's stories about tracking down clues from chat logs are all made up.



I don't think it sounds paranoid. I think it's at least plausible.

I only recently learned about parallel construction: http://en.wikipedia.org/wiki/Parallel_construction

Basically, the NSA is suspected to cooperate with other arms of the government, such as the DEA. The NSA supposedly provides information about who is involved in what illegal activity. Apparently this information is provided illegally, without a warrant. So if the DEA gets info from the NSA, the DEA needs to make up a story about how they came to possess that info, since that info was collected illegally without a warrant. That's parallel construction.

I don't know whether NSA would bother with a target like Anonymous, but it's not outside the realm of realistic possibility.

The biggest question is, how did the FBI identify Sabu? He supposedly revealed himself by visiting the website 2600.com, and selling stolen credit cards on Facebook. But how did visiting that website reveal Sabu?

Actually, now that I think about it, the best explanation is probably the simplest: 2600.com probably runs forums, and Sabu probably posted to those forums from his home IP address like an idiot. So the FBI simply demanded his IP address from 2600.com.


Sabu had his identity compromised for a few reasons:

1) Old whois info with his real name on a domain (prvt.org) that he linked on IRC. He had long since changed it but someone looked it up.

2) Mistakenly logging into IRC without a VPN/Tor.

More: http://arstechnica.com/tech-policy/2012/03/doxed-how-sabu-wa...


I'll look for the article, but as I mentioned above, the way I understand it is that he logged into IRC without using TOR or a VPN one time and they got him.


> 2600.com probably runs forums, and Sabu probably posted to those forums from his home IP address like an idiot.

sounds very plausible :)


Because... doing it the other way isn't particularly hard, either?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: