Re: Swedish Police Swoop on Dan Egerstad

2007-11-17 Thread Fabian Keil
"Paul Ferguson" <[EMAIL PROTECTED]> wrote:

> Not good.

What's that?

> Via TheAge.com.au.

> The hack required little more than tools freely available on the
> internet, and Egerstad maintains he broke no laws.

I find it hard to believe that his "hack" didn't
violate any laws in Sweden and I also have my doubts
about the raid taking place in the way described in
this poorly-researched article.

Without more information I get the impression that
he broke Swedish law and is now facing the consequences.
Big deal.

Fabian


signature.asc
Description: PGP signature


Re: Swedish Police Swoop on Dan Egerstad

2007-11-14 Thread Christopher Layne
On Wed, Nov 14, 2007 at 08:41:48PM -0800, Christopher Layne wrote:
> > The Swedish hacker who perpetrated the so-called hack of the year has been
> > arrested in a dramatic raid on his apartment, during which he was taken in
> > for questioning and several of his computers confiscated.
> 
> Amusing of course how said embassies ignore caveat emptor.
> 
> -cl

"As Egerstad and I discussed the problem in August, we both came to the
conclusion that the embassy employees were likely not using Tor nor even knew
what Tor was. Instead, we suspected that the traffic he sniffed belonged to
someone who had hacked the accounts and was eavesdropping on them via the
Tor network. As the hacked data passed through Egerstad's Tor exit nodes,
he was able to read it as well."

I take back my comment. I will say this, as much as I will support any
technology that aids freedom and goes against eavesdropping - I do find
the constant nefarious activity out there today quite annoying. Not tor's
responsibility in the least - just a general gripe about the level of "crap"
flowing through the pipes these days.

-cl


Re: Swedish Police Swoop on Dan Egerstad

2007-11-14 Thread Christopher Layne

http://blog.wired.com/27bstroke6/2007/11/swedish-researc.html

On Thu, Nov 15, 2007 at 02:57:40AM +, Paul Ferguson wrote:
> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
> 
> Not good.
> 
> Via TheAge.com.au.
> 
> [snip]
> 
> The Swedish hacker who perpetrated the so-called hack of the year has been
> arrested in a dramatic raid on his apartment, during which he was taken in
> for questioning and several of his computers confiscated.

Amusing of course how said embassies ignore caveat emptor.

-cl


Swedish Police Swoop on Dan Egerstad

2007-11-14 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Not good.

Via TheAge.com.au.

[snip]

The Swedish hacker who perpetrated the so-called hack of the year has been
arrested in a dramatic raid on his apartment, during which he was taken in
for questioning and several of his computers confiscated.

Dan Egerstad, a security consultant, intercepted data carried over a global
communications network used by embassies around the world in August and
gained access to 1000 sensitive email accounts. They contained confidential
diplomatic memos and other sensitive government emails.

After informing the governments involved of their security failings and
receiving no response, Egerstad published 100 of the email accounts,
including login details and passwords, on his website for anyone curious
enough to have a look. The site, derangedsecurity.com, has since been taken
offline.

The hack required little more than tools freely available on the internet,
and Egerstad maintains he broke no laws. In fact, he is confident the email
accounts he gained access to were already compromised by other hackers, so
his efforts in fact prevented them from continuing their spying.

[snip]

More:
http://www.theage.com.au/news/security/hacker-of-year-arrest/2007/11/15/119
4766821481.html

Background:
http://www.infoworld.com/article/07/09/10/Security-researcher-intercepts-em
bassy-passwords_1.html
http://www.pcworld.com/article/id,136630-c,onlinesecurity/article.html
http://blog.wired.com/27bstroke6/2007/08/embassy-e-mail-.html

- - ferg


-BEGIN PGP SIGNATURE-
Version: PGP Desktop 9.6.3 (Build 3017)

wj8DBQFHO60aq1pz9mNUZTMRAnqMAKD/OG+oVoFOUfnmAVoXJHxgbNCLGwCfZLeu
AqffLgbQ4KvrDWx1RJ0RzLs=
=c5MK
-END PGP SIGNATURE-

--
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawg(at)netzero.net
 ferg's tech blog: http://fergdawg.blogspot.com/