Slashdot Mirror


Swede Hacks Embassy Account Information From Around the World

paulraps writes "A Swedish IT consultant has caused a stir in diplomatic circles after publishing a list of secret log-in details belonging to 100 embassies, public authorities and political parties around the world. Dan Egerstad said he wasn't trying to earn money, gain publicity or get a name for himself in hacking circles. Instead he claimed that publishing the list was easier than contacting the organizations individually — and that if he had handed it to the Swedish authorities then that would have been spying."

25 of 92 comments (clear)

  1. When best intentions go wrong by Paperghost · · Score: 5, Funny

    "Dan Egerstad said he wasn't trying to earn money, gain publicity or get a name for himself in hacking circles." ....whoops.

    1. Re:When best intentions go wrong by joeldg · · Score: 2, Interesting

      "...easier than handing it to them directly..." ???
      wtf, so it is easier to make a post and leave 100+ embassies open to the world or to send mails..
      I suppose there are ethics here that I am missing.. saying he was supposedly doing these people a "favor" by publishing this..

      I guess at least he didn't try to blackmail them.

  2. Not after fame, eh? by blind+biker · · Score: 5, Insightful

    Then why not publish the list anonymously?

    --
    "The agriculture ministry is not in charge of Gundam" - Japanese ministry official.
    1. Re:Not after fame, eh? by morgan_greywolf · · Score: 2, Funny

      Because then no one would search for his LinkedIn account, thus upping his number of connections from a mere 8.

  3. Competent hacker, poor social engineer by SavvyPlayer · · Score: 4, Insightful

    Anonymously giving the list to a local newspaper would have achieved the stated objective.

    1. Re:Competent hacker, poor social engineer by Opportunist · · Score: 2, Insightful

      ...and also would've caused a LOT of trouble for both, him and the newspaper publishing it. Not everywhere on this planet journalists enjoy the right to keep their sources secret.

      --
      We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    2. Re:Competent hacker, poor social engineer by QuickFox · · Score: 3, Informative

      Not everywhere on this planet journalists enjoy the right to keep their sources secret. Here in Sweden he would certainly be well protected. We have strong laws about these things. Not only in the direct relationship with the papers. For instance, a whistleblower in public employ is so well protected that his boss can't even make innocent comments during a break at the coffee table trying to guess who it might be. Any attempt to try to identify a whistleblower, no matter how innocent it might seem, would land the boss in trouble. And the papers of course guard this protection with great fervor, making lots of publicity when any attempt is made.
      --
      Terrorists can't threaten a country's freedom and democracy. Only lawmakers and voters can do that.
  4. Good intentions? by eln · · Score: 3, Insightful

    I'm not sure what he was thinking when he decided that publishing the list would be the best way to draw the attention of the affected parties. Sure, calling 100 different embassies can be kind of a hassle, but he could just send out an email with a bunch of BCCs. I would assume he has an email address for each of them.

    Maybe this guy just doesn't have the same sense of self preservation that I do, but in my work I tend to avoid doing things that have the potential to cause a major international incident.

    1. Re:Good intentions? by Otter · · Score: 2, Funny
      Sure, calling 100 different embassies can be kind of a hassle, but he could just send out an email with a bunch of BCCs.

      Yeah, you'd think that a guy who is so 1337 that he "accidentally" ran a cracker against 6 different embassies (it's 100 people, not embassies, despite what the submitter and Zonk wrote) wouldn't have trouble cc'ing them. My coworkers don't seem to have any trouble cc'ing a lot more people than that.

    2. Re:Good intentions? by Otter · · Score: 2, Interesting
      Is there some article I'm missing, besides the Ars Technica story and the piece it links? There are things in the blurb that don't appear in either.

      At any rate, I'd be curious what this guy did that caused these passwords to "accidentally" fall out.

    3. Re:Good intentions? by Anonymous Coward · · Score: 5, Insightful

      "he could just send out an email with a bunch of BCCs"

      Thats basically what he did. It doesn't sound like this list is very public. Its just making its way around the so-called "diplomatic" circles.

      Let's look at this from another angle. He quietly published this list, and probably notified all the affected embassies. Then, at least some of the embassies, and a few news outlets, verify the list. Then, at least some of the embassies change the passwords. Then, those news outlets are able to get comments from the embassies and the guy, and then, publish a story on it. All this happened before YOU found out about it.

      I say its a little early to fault the guy, since what he did is working just fine. Had he contacted each embassy individually, he would have had to convince each one over several emails or phone conversations. This way, he probably only had to talk to a few news outlets / embassies. Had he published the list in a local paper (i laughed out loud at this one) as another slasher suggested, the general public would probably have read copies of the emails in the affected accounts before the embassies ever knew there was a problem.

  5. Because.... by erareno · · Score: 2, Insightful

    If he DID publish the list anonymously, then the list could just as easily been dismissed (through political agreements) as completely inaccurate/wrong.

    1. Re:Because.... by kevin_conaway · · Score: 5, Insightful

      If he DID publish the list anonymously, then the list could just as easily been dismissed (through political agreements) as completely inaccurate/wrong.

      I don't see how having a random strangers name attached to the list makes the data published any more or less accurate.

    2. Re:Because.... by Vellmont · · Score: 3, Insightful


      I don't see how having a random strangers name attached to the list makes the data published any more or less accurate.

      It doesn't, obviously. Publishing anonymously makes it easier for governments to simply SAY the published information is inaccurate. Having someone that's standing behind that statement makes it more difficult to play that game. People don't tend to trust anonymous sources. Look no further than slashdot for evidence of that (where anonymous is different from a pseudonym).

      --
      AccountKiller
  6. The real truth by paulraps · · Score: 5, Informative

    Here's a more detailed article on the subject, ending with a highly amusing quote from Dan Egerstad about his real reason for releasing the log-in info.

    1. Re:The real truth by Rob+T+Firefly · · Score: 4, Informative

      He said he had published the list because it would have been too time-consuming to contact all 100 organizations named. Had he handed the list to the Swedish Security Service (Säpo), he would have been guilty of spying. He claimed that by publishing the list he saved himself trouble.

      "This rescues me from the shit," he said. Well, I can see how that - huh???
    2. Re:The real truth by Anonymous Coward · · Score: 3, Insightful

      I can't see the problem. He's not American. He's Swedish.

      The Swedes don't persecute their citizens. And they don't let other countries like the US persecute them either. So he's quite correct that he's safe.

      If this had happened in the US, you would be scared to do anything. What a country! This is what you can do if you're free, but you can't do it in the land of the free!

    3. Re:The real truth by Frosty+Piss · · Score: 2, Insightful

      He claimed that by publishing the list he saved himself trouble.

      Sure it does. Let's watch and learn... I'm not Sweedish, but I feel safe in speculating that even there, hacking someone's email and reading it is illegal.

      "I haven't logged in to anyone's account, but I can read their email," he said.

      Typical hacker, thinks the authorities are really interested fixing this sort of thing, if only they knew. I'll bet they did know, and now they're more pissed off than ever since their spy agencies can no longer access these accounts.

      --
      If you want news from today, you have to come back tomorrow.
  7. He wants room and board by gillbates · · Score: 2, Interesting

    In the local jail. Why else would anyone do something so boneheaded?

    Honestly, I can't think of any better way to get jailed than to embarrass and irritate the high-level diplomats of 100 countries.

    Yes, it was easier than turning the list over to authorities, or contacting each of the embassies. So what? It could easily be argued that he had a duty of confidentiality with his client that he failed to observe.

    Furthermore, he has actually made security worse by disclosing in this matter. Who knows how many embassies were already aware of the problem, and were in the process of tightening security? It is also likely that at least some of the embassies would have discovered the vulnerabilities independently of this consultant through internal audits, and would have fixed them silently.

    Now, while this guy has stirred up a hornet's nest, he hadn't really done anything to improve the security of these embassies. Sure, they have to fix it now, but they might have done it anyway.

    And what if the Swedes were aware of this and using this information for intel gathering? I don't think anyone is happy he did this.

    --
    The society for a thought-free internet welcomes you.
  8. According to the Swedish Hacker by Rob+T+Firefly · · Score: 5, Funny

    Their security is borked.

  9. Safety of the limelight by Opportunist · · Score: 4, Interesting

    Honestly, should I dig up something like that, I will make it as public as possible, with as much of my name on it as possible as well.

    The reason is simple: When you're in the limelight, it doesn't go unnoticed when you suddenly "vanish". Post it anonymously and they will dig you up. Hand it to some journalist and the same will happen (just that one more person goes with you). You can't simply make someone disappear when he's in the center of attention. Unless you're Copperfield and want to vanish, but that's a different matter.

    --
    We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
    1. Re:Safety of the limelight by DragonWriter · · Score: 2, Insightful

      You can't simply make someone disappear when he's in the center of attention.


      You can make them really and verifiably dead, however; perhaps under suspicious circumstances, but you can make it difficult to prove anything and discover or invent material to discredit anyone peddling "conspiracy theories" connecting you to it. Which, ultimately, acheives the same result as the whole disappearing thing.

  10. There is Moral Argument Here... by Anonymous Coward · · Score: 2, Interesting

    Just because

    "Dan Egerstad said he wasn't trying to earn money, gain publicity or get a name for himself in hacking circles..."

    and has the technical ability and the altruistic motives doesn't make it right. Yet if the powers that be (pick you favorite governmental agency) can do this at will, that doesn't make it wrong either.

  11. Re:Cue Borat Joke Here by king-manic · · Score: 4, Funny

    Of the compromised account, ten belong to the Kazakh embassy in Russia. Around 40 belong to Uzbeki embassies and consulates around the world. So half of the 100 accounts belong to underdeveloped former Soviet republics. It seems unsurprising that many of their staff would be unfamiliar with computer systems and computer security.

    Kazakhstan is the greatest country in the world, all other countries are run by little girls. Kazakhstan is number one exporter of internet security, Other Central Asian countries have inferior internet security.

    High Five!
    --
    "There are more things in heaven and earth, Horatio, than are dreamt of in your philosophy."
  12. Re:Uh, email is open not private by Frosty+Piss · · Score: 2, Informative

    Confidentiality of email does NOT exist. It might exist in some alternate universe but it doesn't exist on this planet.

    This has nothing to do with the Confidentiality of email, and everything to do with accessing other people's email accounts without authorization.

    --
    If you want news from today, you have to come back tomorrow.