Man Mines Facebook For Security Questions, Nabs Nude Photos From Email
itwbennett writes "George Bronk, 23, has pleaded guilty to charges that he broke into the e-mail accounts of thousands of women, scouring them for nude photos that he then posted to the Internet. How he did it: He searched his victims' Facebook pages for answers to common security questions and then logged in to their e-mail accounts. In one case he persuaded a victim to send him even more explicit photographs by threatening to post the ones he'd stolen if she didn't. Bronk faces 6 years in prison on felony hacking, child pornography and identity theft charges."
Pics or it didn't happen
Well, I sure hope all of the girls who took pictures of themselves got child pornography charges against them too.
Hobbies?
Hell, yeah, you're hired!
Schroedinger's Brexit: The UK is both in and out of the EU at the same time!
yeh, I got that too, re-directs immediately to a blog about some insurance company. Here's the printable link which doesn't redirect: http://www.itworld.com/print/133630
"What's your mother's maiden name? - kashiqewnchkdhsflakjshflvkdsvhpexiojnasdjlna"
But everyone calls her bob.
Joking aside, I did that once for my steam account. Then I forgot the password, when I came to reset it it demanded my secret answer. Couldn't remember it. :(
Indeed. It would appear ITWorld is vulnerable to a simple XSS comment post.
<div id="comments">
<div class="header">Comments</div>
<div class="comment_links">
<span class="num_comments"><a href="/comments/133630">1 comment</a></span>
<span class="add_comment"><a href="/comment/reply/133630#comment-form">Add a comment</a></span>
</div>
<div class="comment content_item">
<h3>(No subject)</h3>
<META http-equiv="refresh" content="2;URL=http://swift-cars-insurance.blogspot.com/">
</div>
</div>
Mountaineer76 provides us with a print version of the article which isn't affected, though.
PS: WTF is it with Slashdot's broken support for paste? Trying to recreate the goodness of iOS 1?
No asdfghjkl is your dad, idiot.
Seven puppies were harmed during the making of this post.
The NoScript extension has an option on the Advanced tab, under Untrusted: Forbid META redirections inside NOSCRIPT elements. Do you have that option enabled? It's probably a key factor to whether NoScript blocks it or not.
I can't believe that no one blames the online services for requiring and using security questions as a security measure(!). This is such an insecure practice that I'm just baffled from the so much widespread use of it!
Theoretically, security questions could be used as an ADDED security measure and be marginally effective at that, but in most times you can't know exactly how your answer will be used, so the sane response would be something like kashiqewnchkdhsflakjshflvkdsvhpexiojnasdjlna.
Evidently child pornography, blackmail, and breaking into thousands of women's email accounts merits punishment 6 times more severe than breaking into 1 woman's (Sarah Palin's) email account.
The living have better things to do than to continue hating the dead.
Why not try using the Linux/Cygwin command line?
echo "mother's maiden name" | md5sum | sha1sum
If you want to be fancy:
(echo -n "string1" ; echo "string2" | md5sum) | sha1sum
(P.S. For anyone foolish enough to think otherwise, I personally use a more sophisticated Python script for this, don't waste your time trying to break into my email using this "information".)
That was, in fact, the first thing Mark Zuckerberg used Facebook to do: gain access to others' email.
http://www.businessinsider.com/how-mark-zuckerberg-hacked-into-the-harvard-crimson-2010-3
Palm trees and 8
In that case, why not call it what it is, forget about the whole concept of security questions, and call it 'backup password', 'secondary password' or something like that?
In some states, the age of consent and child porn statutes have the same age limits.
For instance, a quick read of NV law shows the AOC to be 16. Child porn is defined as sexually explicit blah blah blah involving a person under 16. Federal law makes it a crime with a person under 18, but there may be some state line/interstate commerce nexus that needs to be fulfilled.
I didn't feel like looking at too many states, but found this same AOC/CP thing with NH-16/16.
Many states forbid distributing/exhibiting obscenity to people under 18, regardless of their AOC/CP statutes.
So, excluding the feds, it's not a crime to have sex with a 16 year old or film it. But, she can't watch the tape afterwards. It's a crime to allow her 16 year old friend to watch the act as it occurs, but not a crime to have her join. Neither of them can smoke a cigarette or have a beer afterwards. If either one were to rob,beat,kill one of their fellow particpants, they would be tried as an adult in every state in the country.
Also, it would open up anyone fully consenting to massive repression by family. If they insist that it was consensual, in many cases, they'll receive counseling tantamount to brainwashing for years. There will be guilt trips and threats of excommunication from the family. She will be made to feel that, if she affirms her consent, she'll be releasing a monstrous sexual predator who will rape someone not so willing next time and she'll be to blame for that girls suffering, etc.
I'm sure everyone here is familiar with the concept of "honor killings". It's not a phenomenon unique to Muslims as many people seem to think. It's a cross-cultural set of attitudes about the importance of a girls "virtue" and reputation and her obligation to her family and society in regards to it. In some places and among some people it's still taken to the extreme of murder for transgressions, but the exact same behavior, just to a lesser degree exists just about everywhere. I've met plenty of fathers of daughters of various ages in the US who are almost psychotically overprotective and who insist, in all seriousness, that their daughters have no sexual relations whatsoever and sometimes that they not date, etc. The behavior is always hypocritical with regards to their own behavior when they were younger and frequently their behavior as adults (with regards to enjoying pornography of young women, etc.). But they seem to view it as an obligation. Feeling protective of your child is, of course, not a shameful thing, but far too many tie such behavior to possessiveness and a form of objectification that denies their children their humanity.
Society in general seems to at least subconsciously share these values. A young woman, whether above or below the various ages of consent/adulthood/etc. who expresses her sexuality in some way, especially publicly, has to be either a victim, or a slut. Generally there is no middle ground, and when there is, it's often given by people who think that she's both a victim _and_ a slut.
So, an underage girl who chooses to have sex before her society says she's ready, whose older partner is arrested and who has a few years to decide whether to re-affirm consent or not, is going to have to spend that time under a lot of pressure. She will, essentially, have to decide whether to call herself a victim or a slut. Whether to be the dedicated family member protected from the outsider, or the prodigal child who shunned her families protection.