Attacked By Anonymous, HBGary Pulls Out of RSA
itwbennett writes "HBGary Federal cancelled a talk the company's CEO Aaron Barr was planning to give at the BSides San Francisco conference on his investigation of WikiLeaks. 'I was receiving death threats,' Barr said in an interview Tuesday. 'There was lots of talk that was being made of in the Anonymous IRC channels of harassing us at our booth and sending people to heckle [HBGary speakers at the conference].' The company has also decided to pull its booth from the RSA Conference floor after it was vandalized on Sunday, said Jim Butterworth, HBGary's vice president of services. 'We... came back the next morning and it was very apparent that the group responsible for the activities in the news had decided to make another statement,' he said."
Ars has a really good summary of the attack that used really run-of-the-mill stuff from social engineering via e-mail to an SQL injection of HBGary's CMS using this URL: http://www.hbgaryfederal.com/pages.php?pageNav=2&page=27
My work here is dung.
Tell lies about Wikileaks? That's War
Want to mess with Anonymous? That's War
It's an all-out war between the forces of good and evil that has never stopped and will never stop. The price of freedom? Constant vigilance.
"You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
Vandalized booth = a sign that says "Anon...In it 4 The LuLz..." http://yfrog.com/gzbvtllj I was expecting the booth to have been burned to the ground or something.
Let sleeping Agent Smiths lie. Even if they don't have cool matrix moves, there are a lot of them, they are functionally identical for most e-combat related purposes, and of course, they have a record of pulling this kind of stuff off.
Some_Group: Hey guys, let's attack Anonymous! It'll make us rich if we can hack them, an our security can stop their counterattack, right?
Anonymous: No it can't. I'm putting all your embarrassing/incriminating email messages onto the net.
Some_Group: FFFFFFFFFFFFFFFFFFFFUUUUU-
I'm not sure why they were concerned. These guys are confident when they're behind a laptop, not when they're face-to-face at a booth. There's no way they'd have done anything in person.
For supposed 'security experts' they do seem pretty weak.
Also I suspect this might well be a publicity stunt to get more attention.
So, let's take a look at this:
Option 1: Members or associates of a loose-knit group of hackers who are likely subjects of federal interest after illegally penetrating and utterly humiliating a private-sector spook shop decide that it would be a great idea to show up, in person, at an event with some amount of security likely to be in the vicinity, just to heckle somebody they have already pwned good and hard. They think that this is a good idea because showing up in crowded areas and making a disturbance is an excellent way to remain anonymous.
Option 2: Aaron Barr and the rest of the losers at HBGary really don't want to show their faces at RSA, after having been ruthlessly punked by a bunch of amateurs; but decide to cry about "security threats" in an attempt to look less than totally pathetic.
Y'know, I don't think that this is a terribly difficult decision...
Backing down from your beliefs due to threats and attacks will only breed more attacks and threats. While I'm not necessary against Anon, their acts are that of terrorism in this case, and unfortunately, those tactics work.
Protesting is one thing but wanton destruction of property is another. Death threats are well over the top.
These are not things responsible protests groups do in a situation like this. Next time, keep it to rhetoric and, if you are willing to be !Anonymous, picketing in person.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
Anonymous is just the first of many future darknets that will be nearly impossible to destroy. You might take out a ringleader or two, but 4 others would stand up to take their place if they felt that it was unjust. And in the end, it's death by a thousand harmless cuts, or in this case, 1,000 users that don't like something running the their Ion cannons under central control. In this case, this dude is using social networking like facebook to figure out who are hackers. I doubt they have many connections to other hackers on facebook or twitter. It's most likely random unrelated acquaintances, so I think the guy's research is flawed anyway.
The best example of what one of these organized systems could do is a story by Bruce Sterling called Maneki Neko. It is what happens when people get organized but maintain some level of anonymity. We are not to this level yet, but I suspect it right around the corner. It will do strictly good at first, but eventually it will ruin someone's life. Just as Anonymous has ruined some people's lives, they've done a little good for some, like a great birthday. It doesn't justify the destruction, but it's bored kids on the internet, so what are you going to do?
The news media will make a big deal about future 'attacks', but some will be harmless kids having fun. But if you start to push that everyone involved in these groups must be destroyed, those people who are marginally involved will suddenly get VERY involved in your destruction. So be careful.
Gonzo Granzeau
"Nothing the god of biomechanics wouldn't let you into heaven for.." -Roy Batty
Anonymous good?
Is making death threats because you do not like someone is going to say at a conference good? Is heckling and yelling them down good? Funny but I have seen those actions in old news reels from the 30s and from old news stories from the 60s. The folks using those tactics where the ones in the brown shirts and the white sheets.
I don't think MLK or Gandhi ever made any death threats to people or hecked them when they presented papers at conferences. I could be wrong but I am pretty sure about that.
Since when is when someone says something you do agree with you make death threats been a sign of being good?
Anonymous is a gang of bullies. People often see bullies and thugs as heroes if they themselves do not ones being bullied. There are people that think the KKK are a bunch of brave freedom fighters.
Anonymous is no differn't right down to hiding their faces. And their fans do not like they people they are abusing.
Anonymous are those peoples brave Knights in white sheets.
See my blog http://ilovecookes.blogspot.com/ for light hearted technical information.
Anonymous is trying to suppress information using death threats. That makes them no better than many governments and worse than the U.S. government.
I wonder what people would say if members of Anonymous were on the receiving end of death threats. Some how I bet it would be "Look! They are evil fascists!1!!!1!". Well, as soon as Anonymous used death threats, they became an oppressive, authoritarian group using terroristic tactics.
So what about the US Gov vs WL? You know, where they said that they had to kidnap (arrest) all the people and try them for treason (when not a USA citizen) and that Julian Asange should be executed are things that responsible governments don't do in situations like this.
How about Saddam? They actually killed him. Not just threatened. Killed. For torturing people and killing civilians. Later, the USA is torturing at abu graib and killing civilians in Iraq.
The gall of a company who just got caught planning a massive campaign of harassment and dirty tricks whining about people potentially harassing them is amazing.
Protesting is one thing but wanton destruction of property is another
Do you want to see how much property was "destroyed"? Look here
That's it, what they call "vandalism" was a piece of paper with something written. If someone could prove they are "Anonymous" they would have grounds to sue HBGary for libel.
So Anonymous is kind of like Earth First folks. Loosely organized, with sociopathic tendencies.
Except instead of burning down construction sites and SUVs, they crash websites and break into systems.
They both apparently make death threats.
When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
I can't comment on what kind of snobs HBGary folks are, but the actions of Anonymous seem quite hypocritical to me in general. So "Anonymous" fights for wikileaks, which is expressly set up for the purpose of sharing secrets and revealing things. Then I read about how someone tried to expose who various members of Anonymous were, after which Anonymous got all upset and attacked him for doing the very things that wikileaks does, which they work to support. Seems like they value secrecy above everything else, kind of like the people that feel the most threatened by wikileaks. Ironic.
I just have this feeling that there are folks out there cheering for the bad guys here just because Barr is a jerk
My impression from all this is that HBGary were incompetent and as a Government contractor, they should be investigated for fraud. Selling their services as a Government security firm only to be broken into with SQL injections and rainbow tables?!?
Plah- ease!
bleh and bleh.
we are not excusing ourselves as people, and not doing anything that the current law would shun as criminal, but those people whom you speak about are doing all the inexcusable criminal acts as government contractors, and getting away with it. this ranges from torture to censorship.
no. there is a certain point of assness at which things can be excused.
Read radical news here
What happened when Assange started releasing diplomatic cables? Oh, that's right: he received public death threats from US officials. What happens when an individual starts complaining about a corporation, or about scientology? Oh, that's right: they get bullied by a team of lawyers that cost more per hour than the individual makes in a month.
I don't support making death threats or using baser harassment to get a point across, but the only thing newsworthy about the tactics of Anonymous is that now it's regular citizens making the threats and engaging in bullying tactics instead of governments and corporations. If governments and corporations only respect the law when they aren't the ones in power anymore, fuck'em.
You are still in Fox mode, trying to see the conspiracy behind events because your mind cannot grasp that shit just happens.
Anonymous has no organization, it cannot by its very nature. Some people who HAVE grouped together have used the name for themselves BUT by that they have seized to become Anonymous.
Is it really that hard to grasp? Just because you know the identity of ONE A. Nonymous author doesn't mean that every other book written under that name is linked to it in anyway. Anonymous, the concept to give a mystic to the random actions of people that sometimes seem to work together and groups calling themselves anonymous are NOT the same thing.
MMO Quests are like orgasms:
You may solo them, I prefer them in a group.
me knowing what my government is doing with my money : good.
...............
anyone trying to prevent me from knowing what my government is doing with my money, for ANY reason : evil
anyone helping me know what my government is doing : good.
anyone defending those who are helping me know what my government is doing : good.
at our time and age, with the point our societal corruption has hit, unfortunately things are as black & white as this.
and talking about fascism and lack of freedom - dont worry. fascists already have taken over your country long ago - you are just being repressed willingly, living only in proportion to your material wealth, while the rich has cornered the economy before you and controlling you through their bigger wealth, and you think that as freedom. you have nothing to fear - you are already willingly participating in what you fear.
Read radical news here
...is wrong with editors here?
Having a sign put on your booth is not being 'attacked', you goddamn fucktards. Nor is it a 'threat'. I know the article claims that,but it's clearly insane nonsense.
What the fuck is wrong with you, CmdrTaco? Why are you repeating lies?
And what is wrong with the people who here repeat the 'vandalism' claim without actually look at what was done? Laying a poster on top of someone else's table is not even legally vandalism, and that's a crime with a pretty low bar.
Perhaps, you know, we shouldn't be repeating claims that HGBGray makes, an organization that has been demonstrated they will lie about people they are paid to lie about.
If corporations are people, aren't stockholders guilty of slavery?
Allegedly Attacked By Anonymous, HBGary Pulls Out of RSA
Fixed that for you.
Mess with the bull..... You wanted it now you have it. If you don't have the courage of your own convictions (Which these guys don't) then shut your mouth.
Hi. You're going to call off your rigorous investigation. You're going to publicly state that there is no underground group. Or... these guys are going to take your balls. They're going to send one to the New York Times, one to the LA Times press-release style. Look, the people you are after are the people you depend on. We cook your meals, we haul your trash, we connect your calls, we drive your ambulances. We guard you while you sleep. Do not... fuck with us.
But because he was ashamed. Think about going to hold a security talk, pretending to be an expert, while your company has just been rooted by the powers you claim to dominate.
This is just spin. He didn't do the presentation out of shame.
I never thought my heroes would be fat kids with Cheeto fingers
Wikileaks, as you mentioned, works to reveal secrets. As a part of that work they also have to keep some secrets however, for example about their sources.
This is not the great paradox you make it out to be.
There is a difference between trying to reveal crimes/unethical behavior/corrupt and all that stuff, and to reveal personal information just out of spite or to harm someone. Not all secrets are bad, but those that are must be exposed.
Actually I'd like to call upon my betters at math, because I'm getting the sense that there are relations to set theory, game theory, etc. Places to look:
How do you know someone is in Anonymous? *How do you prove you are not?*
My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine
Toss em in jail and forget about em. See how "anonymous" they are when they are all sitting in PMITA prison.
Apparently, with today's abysmal science (or even critical thinking) teaching, it's quite common to sell magic beans to teh gubbemint.
Why should the cybersecurity market be any different?
http://en.wikipedia.org/wiki/ADE_651
http://en.wikipedia.org/wiki/GT200
http://en.wikipedia.org/wiki/Quadro_Tracker
http://en.wikipedia.org/wiki/Sniffex
http://en.wikipedia.org/wiki/Alpha_6
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
All of them tools. Both sides. The attackers are terrorists. The parallels to Islam and Islamic terrorists are striking. In /. you have Islam as a whole and you have Islamic terrorists in the attackers. You may champion the terrorists now but you do not control them so be careful of what you wish.
Facts take all of the premium out of arm waving - T. Reynolds
Barr is a fool. Don't poke the bear .. especially if the bear is smarter and more legit than you.
Mess with the best, die like the rest!
I can't wait for the security video to be released and show a Guy Fawkes mask placing that sign.
I don't really see too much wrong with what Anonymous did...
HBGary (regardless if they are assholes) hit them first by "hacking" and threatening to release personal information (for money) about various members. Anonymous hit back. HBGary were trying to bully them and I can't stand bullies.
They're being manipulated, used as useful idiots.
Hoodoos. (they)Thought the matrix was full of mambos 'n' shit. Wanna know something, Moll?
What?
They're right.
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
Doesn't anyone think anonymous should get an anonymous medal of freedom for exposing a now obviously fraudulent company and potentially saving some taxpayer funds. It's not like any of those other bozos that got it yesterday deserved it any more than the people who exposed this potential fraud.
the Democratic Process - if the mob is organized enough to change the law to reflect its beliefs.
I will not be pushed, filed, stamped, indexed, briefed, debriefed or numbered. My life is my own.
The difference is that HBGary tried to dox random people. They dug up some names they believed to be "members" of Anonymous and then tried to gain the FBI's attention which they knew were on a crusade against Anonymous. And considering previous cases chances are the life of the people named by HBGary would have become quite miserable. BTW: Anonymous does not care much about consistency or reputation or what slashdotters might think of them.
On se Internetz nobody noes your German.
http://en.wikipedia.org/wiki/Transportation_Security_Administration
Given this guy's 'tude and behavior, I'm gonna need real proof of said threats before I believe them. Anything less is just a Kabuki dance to drum up even more raids by the Federales.
3. The government and their handmaidens no longer believes in, or acts according to, the Rule of Law.
Anonymous should have called themselves"I'm Spartacus"... maybe then these old farts would understand what's going on.
It's amazing how dangerous thumb tacks and sharpie markers are.
Actually I'd like to call upon my betters at math, because I'm getting the sense that there are relations to set theory, game theory, etc. Places to look: How do you know someone is in Anonymous? *How do you prove you are not?*
You dont
but you are
That is the nature of anonymous
it is everyone and no one
Crassus simply had all of them crucified along the road back to Rome.
If I'd seen the lulz image before posting I would've laughed the vandalism charge right out of the court of public opinion instead of using it as an example of something that's not okay to do.
However, assuming the death threats were real they were way over the top.
Making fun of someone's idiotic actions with the intent of deservedly killing their reputation, that's what rhetoric is for.
Actually threatening someone's physical well-being, NOT okay in a case like this.
Oh, as for the remark about the British and 200 years ago: If your government is so corrupt that it's unjust and the normal means of petitioning and peaceful protest don't work, then holding a revolution may be the morally okay or even required thing to do. That's what happened in the mid/late 1770s in America and a recently in Cairo.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
By the same logic, Assange is being hippocritical by not jumping on a plane to sweden/USA.
Organisation doesn't necessarily mean top-down organisation.
Anonymous is definitely organised, but along anarchist lines rather than a traditional hierarchy.
Don't worry, you'll get it eventually ;-)
Anonymous are the bored teenagers, twenty-somethings, and misanthropes of the Internet. They aren't "responsible protesters", individuals just do whatever they like because they feel like it. The core ideal of the "movement" is "do it for the lulz".
Which is why most events associated with "Anonymous" is full of racism, homophobia, child porn, etc. "Anonymous" will do pretty much anything to get a laugh. Telling them to act responsible will just cause some of them to go and act even more irresponsibly to annoy you.
========
CINC, 4th Penguin Legion
Seriously, what about their competitors exhibiting at the show. Have one of your salesman make the sign up and slip on their booth and make them look like fools once again, might as well kick them while their down. Seems like the people with both motive and opportunity. Plus the consequences of being caught are pretty low, if someone saw your guy placing the sign he just says "so what, it was a joke, I didn't make a threat, we are just joking around with a competitor". And he is right, the sign is in no way a threat.
It was the threat of embarrassment that kept them away from the conference.
If you're with Anonymous, you only regain your identity upon death or capture.
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
So now they are vandalizing actual property. This guy is still a dick, Anonymous has now ceased to be a cyber-terrorist organization and turned into a real life one.
Go Anonymous!!! Now if only you were all armed and we could find out who REALLY shot JFK (from the front, and not through a tree from behind with an antiquated rifle).
This is democracy in action. I hope we can someday eliminate the corporate slavery our corrupt politicians and media have inflicted on this country.
I hold very few opinions. I hold information based on observation and fact. If you wish to disagree, please use facts.
SQL injections and rainbow tables
unfortunately the truth of this statement will be entirely missed by the greater public.
The greater public probably think SQL injections and rainbow tables are some bizarre gay fetish activity.
Is that why the Wikipedia entry on "SQL Injection" is blank as of right now? It says last modified on 15 February 2011. Hmm. The page just looks blank in Firefox—View Source shows the text. I brought up IE, and the text is all there. Except...was SQL injection really "First discovered by hippies from Las Cruces, New Mexico."?
This is all very interesting, of course. Competitive urination between somebody I don't know and an unknown number of people I don't know. I don't dare say more than that; who knows what Anonymous would do to me if I did?
Dr. Vomact's true name is Hilda Bergenbanger, she lives at 1055 Matheson Road, Columbus Georgia. Call her at 706-433-6969 for a really good time at a very modest cost.
Great men are almost always bad men--Lord Acton's Corollary
That is what is the cause of the whole Anonymous thing IMNSHO. If these kids had been instilled with the belt from time to time I doubt we would be talking about them.
desu desu desu desu
Who the hell is HBGary, why should I care, and what did he do to "piss off" "anonymous?"
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...