The Macrosite for News, Analysis and Opinion about the Future of the Internet
Kim Davis

LulzSec Wise Guy Tweets to the Feds

Written by Kim Davis
3/7/2012 20 comments
DISCUSS     Email This

The hacker known as "The Real Sabu" is one of the members of the hacktivist group LulzSec who has been using Twitter to pump out prolific wisecracks and revolutionary messages. As far as anyone can tell, anyway, given the murky status of Twitter identities.

This week, it was revealed that he may have been tweeting to the feds, too. Singing like a bird, in fact. So much for honor among hackers.

Hector Xavier Monsegur, 28, who made New York's Lower East Side the base of his operations, was arrested last summer. Since then, reports say, he has been busy playing stool pigeon, passing information to the authorities that bore fruit this week with a series of arrests. Monsegur's assistance seems to have allowed the authorities to strike not only at LulzSec, but Anonymous and Anti-Sec, too. You can imagine how much trust and goodwill this will spread among the hacking community.

AntiSec/Anonymous has already retaliated, breaching subdomains of the Panda Security Website to post their own promotional videos along with email addresses and passwords for some Panda Security account holders. In a Pastebin post, they accused Panda of assisting law enforcement -- or "snitching." They also referred to the Monsegur situation:

Yeah yeah we know... Sabu snitched on us. As usually happens FBI menaced him to take his sons away. We undestand, but we were your family too... It's sad and we can't imagine how it feels having to look at the mirror each morning and see there the guy who shopped their friends to the police.

(Punctuation added.)

As far as we can tell, then, at least some hackers, probably involved in the Panda exploit, believe that Monsegur is an informant.

"The Real Sabu" continued to tweet anti-government, pro-hacking messages on his Twitter feed until Monday, when he closed with a message in German which may turn out to be his swan song: "Die Revolution sagt ich bin, ich war, ich werde sein." ("The revolution says I am, I was, I will be.") This paraphrases a comment published by the German socialist Rosa Luxemburg shortly before her arrest and death in police custody.

On Tuesday, court records were released showing Monsegur had pleaded guilty to hacking and financial fraud. Specifically, he had been involved in identifying vulnerabilities in third-party systems and either exploiting them himself or passing them to other hackers.

Is it possible, however, that Monsegur didn't flip his fellow hackers? Although it has been suggested that he denied being an informer in an Internet conversation with a Guardian journalist last year, the excerpts from that chat, published today, are actually quite ambiguous.

Assuming that Monsegur has been assisting the authorities, what are the implications for the loose underground federation that has claimed success in breaching a series of governmental, law enforcement, and enterprise Websites over the past year? The arrests, as the Panda Security exploit shows, are unlikely to bring down the curtain on Anonymous and LulzSec. Hackers, as Anonymous famously claims, "are legion."

The larger impact is likely to be on trust within the hacktivist networks. "The Real Sabu" was a high profile LulzSec member -- "one of the world's most-wanted hackers," as Reuters described him yesterday. Even in the shadowy corners of the "Darknet," hackers inevitably share some potentially identifying information. If a figure as central to operations as Monsegur cannot be trusted, who can?

The situation underlines the risks to individuals in working alongside anyone else in pursuit of hacking goals. The vulnerability at the heart of Anonymous-AntiSec-LulzSec turns out not to be technological, but very human.

Related posts:

— Kim Davis Follow me on TwitterVisit my LinkedIn pageFriend me on Facebook, Community Editor, Internet Evolution

Channel: Security
Tags: Government
DISCUSS     Email This
Current display:       newest comments first       display in chronological order
Page 1 of 2   Next >
Kim Davis
Thinkernetter
Tuesday March 13, 2012 12:20:22 PM
no ratings

Oh, you're right Mike.  Most of the hacking of law enforcement sites amounts to no more than publicity stunts, not serious cybercrime.  But embarrass people, and you make them hate you.

Mike Acker
Rank: Cyborg
Monday March 12, 2012 6:54:54 PM
no ratings

=" I think the FBI is just bound to go after hackers who keep embarrassing them by hacking their sites."

which represents what percentage of the total problem?

One of the reports I read indicated that HB\Gary was in the business of attempting to make root kits for the feds that would be undetectable.  How do you feel about that ?

One of my co-workers liked to chide me about my concern for wire-tapping,-- on cell phones, e\mail, web activity and the like, saying "I'm not doing anything interesting or illegal so I don't care if they read all my e\mail"

I reminded him: "while you may not be doing anything interesting or illegal what about the guys doing the wire tapping?"'

how do you feel about that?

Kim Davis
Thinkernetter
Monday March 12, 2012 5:25:17 PM
no ratings

While I sympathise with your "whack-a-mole" comment, Mike, I think the FBI is just bound to go after hackers who keep embarrassing them by hacking their sites.

Mike Acker
Rank: Cyborg
Saturday March 10, 2012 4:40:28 PM
no ratings

Kurt: You are right: software has been exempt from product liability law for years.

Schneier notes in his essay that liability will be necessary to get secure software, also that that liability ought to be limited in a sensible way

My thought on that is this: If your computer holds a Commercial Certification and then fails a software inventory audit the O/S OEM is responsible to reformat your disk, re-install the O/S and authorized software and to re-certify the computer, i.e. re-apply the software audit and create the commercial certification.

the last step of the commercial certification is a maintenance lock down which remains in effect until regular scheduled maintenance is required.  at that time the certification is revoked, the maintenance is applied and the software audit re-applied.  This would result in a maintenance lock-down followed by a new commercial certification.

the thorny problem that remains is what to do with executable documents.  if the customer moves an executable document to another area of the system or network and then that document is picked up with different privileges this can be trouble.  this is an issue that will have to be addressed.   one solution I think Google looked at for Chrome is to simply strip the executable code out of any document that is to be saved.  Rough, but it might be necessary: making portable documents executable was a mistake to begin with.

the real answer lies in re-examinining what the code in an executable document is permitted to do.  this won't be easy.

I think this is a  a good topic for IEv as I think "whither the Internet" hinges on the outcome.  There will be others who will attempt to remove all anonyminity in order to fix responsibility fpr all activity to the net.  But we must consider the further implications of this as it relates to the public dialog.  Valuable opinions often encounter violent opposition.

Hopefully some more of our IEv correspondents will chip in ont this topic.

Kurtkeys
IQ Crew
Saturday March 10, 2012 4:15:56 PM
no ratings

Mike,

Those are all valid points by some intelligent people. But they, just like you and I and every other user on the planet, all sign a end user license agrement that always states that the software is delivered as-is and is not gauranteed to work as advertised. And furthermore, the company granting the license holds no responsibility for any loss or damage that arises from use of the software. Even loss or damage from the use of the program as it was intended to function...

So, I assume those people are suggesting that licencing of software be fundamentally changed some how to make the license grantor responsible or liable for the damages incurred from using their software... To which I respond GOOD LLUCK.

 

pcharles
IQ Crew
Friday March 9, 2012 8:06:40 PM
no ratings

Ha. People always tend to be brave when they're NOT in a tight situation. Much like those hackers who claim they do it for passion and not truly for vengeance of some sort. If you put them in a scared straight scenario, I'm pretty sure they'd straighten out really quick.

Mike Acker
Rank: Cyborg
Friday March 9, 2012 7:07:09 PM
no ratings

consider the catch: 25 hackers.  and the cost : ?  the time and resources used ?

put this in perspective: there have been reports that something arond 70,000,000 new malware samples were identified in 2011 and 2012 shows no signs of slowing up

chasing these 'bad guys' is the world's most futile game of 'whack a mole' : you can never win at that

and in the end chasing hackers is really treating the symptoms of a problem rather than getting at the real cause

David Rice has it right on the money in his recent Geekonomics: The Real Cost of Insecure Software (paperback) by David Rice (Dec 9, 2007)

and I agree completely with Bruce Schneier on this

He said :

Right now consumers support the cost of unreliable software, Schneier said, adding that software vendors won't take security seriously until it's cheaper to do it than not to do it.

 

Liabilities are everything, because they change the economic incentives, Schneier said. Vendors shouldn't support all costs if something goes wrong because of their software, but they shouldn't get away without paying anything either, he said.

"If you waste your time a-talkin' to the people who don't listen to the things that you are saying, who do you think's gonna hear?" -- Kris Kristofferson\To Beat the Devil

Kim Davis
Thinkernetter
Friday March 9, 2012 4:49:41 PM
no ratings

Reports today suggest Monsegur was an eager and diligent informant, working all night on chats which the Feds could follow.  Doesn't say much for consistency of belief, does it?  I mean, you could imagine him doing the minimum necessary to get a plea deal, but he seems to have been an...over-achiever.

Kim Davis
Thinkernetter
Thursday March 8, 2012 2:30:52 PM
no ratings

And it reflects, I'm afraid, on the superificiality of the politics.  People with deep political commitments don't turn in their comrades so readily. 

The Dream Chaser
Rank: Cyborg
Thursday March 8, 2012 11:30:42 AM
no ratings

Oh legion right uh huh sure you are.  When you're facing the FBI in person and they are explaining you're looking at a 128 year term in the slammer then one becomes humanized pretty quickly and all the invincibility and loyalty goes right down the toilet.  Keep your pants up boyz and get used to showering with your new "room mates"  Good luck! 

Page 1 of 2   Next >
The ThinkerNet does not reflect the views of TechWeb. The ThinkerNet is an informal means of communication to members and visitors of the Internet Evolution site. Individual authors are chosen by Internet Evolution to blog. Neither Internet Evolution nor TechWeb assume responsibility for comments, claims, or opinions made by authors and ThinkerNet bloggers. They are no substitute for your own research and should not be relied upon for trading or any other purpose.
previous posts from Security Clan Editor's Blog
Kim Davis
Kim Davis   5/21/2013   13 comments
Extending existing US wiretap laws to give federal agencies easier backdoor access to Internet communications -- especially real-time P2P services like VoIP -- will give, not only aid and comfort, but also technical assistance, to the country's enemies. Not to mention cyberthieves.
Kim Davis
Kim Davis   5/15/2013   11 comments
When David E. Sanger of The New York Times broke the news that the United States was responsible for the Stuxnet malware exploit against Iran's nuclear program, Senator John McCain accused the administration of deliberately leaking the story to enhance President Obama's national security record.
Kim Davis
Kim Davis   5/8/2013   14 comments
The Gamma Group's business of supplying surveillance technology exclusively for use by government agencies may be legitimate. But not when it poses as the popular, free, open-source web browser Firefox.
Kim Davis
Kim Davis   5/1/2013   41 comments
If you were concerned about Twitter handing over your private data to the government, think again.
Kim Davis
Kim Davis   4/24/2013   18 comments
Yesterday's hack of the official Associated Press Twitter feed demonstrated the enormous risk attached to the platform's lazy, single factor approach to security.
5
of
Kim Davis
Aaron Swartz, RIP

1|14|13   |   2:36   |   6 comments


The Internet freedom activist, threatened with jail time, seems to have taken his own life last week.
Kim Davis
British Hacking Report Is 'Bonkers'

12|5|12   |   2:20   |   3 comments


Prime Minister David Cameron pledged to accept the hacking report’s recommendations unless they were “bonkers.” He’s rejecting the main one.
Mary E. Shacklett
Financial Services Policies Lag Tech Advances

12|4|12   |   2:18   |   6 comments


Regulations haven't kept up with advances in mobile devices and credit cards.
Wisdom of the Big Chair
FBI Turns Attention to Mobile Security

10|30|12   |   3:45   |   8 comments


The FBI recently issued a warning to smartphone users, highlighting two mobile malware applications: Loozfan, which steals personal information, and FinFisher, which is spyware that takes over a smartphone's functions.
Beau Brendler
Another Step Toward a Chinese Internet

7|2|12   |   1:44   |   3 comments


It wouldn't be the first time, but a group of Chinese engineers has proposed a means by which the Internet's root could be split, enabling secondary, independent networks that could be government-controlled. The Internet's root security committee is taking such proposals seriously.
Wisdom of the Big Chair
World War III Will Be Waged Online

6|26|12   |   3:23   |   7 comments


Recently, security software supplier Kaspersky identified Win32.Flame as malicious code that seems to have been developed, not by hackers, but by government agencies. Warring nations may set aside their bombs and wage their wars online.
Kim Davis
Assange's Day of Reckoning Approaches

5|31|12   |   2:48   |   21 comments


Whether it be sexual assault charges in Sweden or espionage charges in the United States, Julian Assange will one day have to face the music.
Mary E. Shacklett
Law Will Define Next-Gen Privacy

4|25|12   |   1:48   |   7 comments


The plan for unmanned police drones to patrol traffic and other city conditions in Seattle has sparked a new set of legal concerns about privacy. Law traditionally lags technology, but we can expect now to see a new round of activity in the courts as legal definitions begin to emerge on what "next-gen privacy" will look like.
Beau Brendler
Terrorism Expert Says US Gave Away Stuxnet Tech

4|4|12   |   3:29   |   9 comments


US counterterrorism expert Richard Clarke, who came to prominence with his prescient warnings before the 9/11 attacks, tells Smithsonian Magazine the US was responsible for the Stuxnet supersmart worm that attacked parts of nuclear reactors in Iran – and in the process, has given away one of the world's most sophisticated cyberweapons.
Wisdom of the Big Chair
Feds Provide Solution to Android's Security Problems

2|2|12   |   2:24   |   6 comments


Malware designed to infect Google Android smartphones has increased dramatically, and now the government is stepping in. The National Security Agency has developed SE Android, a system that tries to close up its security holes.
IETV: the thinkerNet on film
5
of
Kim Davis
Big-Data Can’t Always Sell Wine

5|21|13   |   2:23   |   3 comments


Whole Foods Global Wine Purchaser Doug Bell told me about some of the constraints on using analytics in the US wine market.
Paul J. Fleuranges
Digital Signage Keeps NYC Subway Straphangers on Track

5|6|13   |   3:51   |   No comments


New York's Metropolitan Transit Authority is conducting a pilot test of digital kiosks to guide subway users to where they want to go more efficiently and at lower cost.
Kim Davis
Fast Forward to the Future

4|23|13   |   2:29   |   20 comments


A look back at tech writing in the 90s makes us wonder where enterprise IT will be 20 years from now.
Mitch Wagner
Google Launches Its Most Depressing Service Yet

4|15|13   |   2:59   |   10 comments


Google's new Inactive Account Manager lets you control how Google disposes of your accounts when you die.
Second Shooter
Argument Over Top-Level Domains Is 'Stupid'

4|11|13   |   2:07   |   3 comments


The whole Amazon.reader debate is a double-stupid. It's stupid to think that there's any e-book buyer who doesn't know Amazon's URL, and it was stupider to let ICANN launch the whole free-form TLD initiative to start with.
Kim Davis
Ladies, Your Tablet Awaits

3|21|13   |   2:22   |   37 comments


ePad Femme is the world’s first tablet “made exclusively for women.”
Wisdom of the Big Chair
NFC Moves Into the Mainstream

3|20|13   |   2:16   |   No comments


While NFC's original goal was to enhance mobile commerce applications, it is finding its way into a number of other uses, which is creating both opportunity as well as challenges for IT departments.
Wisdom of the Big Chair
Integrating Security Into Your Cloud Contract

3|19|13   |   3:35   |   No comments


Enterprises would like to move to cloud computing but are hesitant because they are concerned about providers’ ability to secure company data. Here are some tips that help to ensure that if breaches occur, the business is not left holding the bag.
Brian Baron
How Edmunds.com Collects Customer Information

3|18|13   |   1:15   |   No comments


Edmunds separates customers into segments based on the info it collects on its site and from partners, and uses that to push out custom content, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
Brian Baron
How Edmunds.com Uses Analytics to Customize Site

3|14|13   |   0:47   |   No comments


The automotive website uses propensity modeling to target ads and customer registration forms, said Brian Baron, director of business analytics for Edmunds.com, at Predictive Analytics Innovation Summit.
an IBM information resource
sponsored content
big blue blog
an IBM information resource
sponsored content
Expert Integrated Systems: Changing the Experience & Economics of IT
In this e-book, we take an in-depth look at these expert integrated systems -- what they are, how they work, and how they have the potential to help CIOs achieve dramatic savings while restoring IT's role as business innovator.

READ THIS eBOOK
your weekly update of news, analysis, and
opinion from Internet Evolution - FREE!

REGISTER HERE
Wanted! Site Moderators
Internet Evolution is looking for a handful of readers to help moderate the message boards on our site – as well as engaging in high-IQ conversation with the industry mavens on our thinkerNet blogosphere. The job comes with various perks, bags of kudos, and GIANT bragging rights. Interested?

Please email: moderators@internetevolution.com
Internet Evolution – not for thickies
Keep Critical Data With a Knowledge Management System
Taimoor Zubair
Fortune 500 companies lose at least
$31.5 billion a year by failing to share knowledge. A Knowledge Management System (KMS) can help companies significantly reduce these costs.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
M2M: Rise of the Machines? Not Yet
David Weldon
In the 1970 science fiction thriller
Colossus: The Forbin Project, two giant supercomputers from the United States and Soviet Union secretly join forces to take control of the collective nuclear might of the two countries. In the film, the two machines discover each other's existence, communicate back-and-forth, share their collective data, and cut their human creators out of the process. It is the ultimate example of machine-to-machine communications, or M2M.

CLICK FOR MORE
Yahoo Needs to Break Tumblr in Order to Fix It
Joe Stanganelli
As
Mitch Wagner discussed today, Yahoo is acquiring Tumblr. The big Internet debate at the moment is whether Tumblr will be good or bad for Yahoo. Regardless of their stances on the future of Yahoo itself, many claim that Yahoo will somehow ruin Tumblr.

CLICK FOR MORE