Contents of Leaked HBGary Emails Reveal Wrongdoing
chargersfan420 writes "Ars Technica has sifted through the contents of the HBGary emails leaked last week in the attack by Anonymous and posted an interesting story about some of the things they were up to (which include rootkit development, selling rootkits to the private sector, and an entire list of 0-day exploits in a variety of OSes and other software, among a variety of other devious plans). Today they are reporting a democratic push for a congressional investigation of HBGary Federal."
a democratic push for a congressional investigation of HBGary Federal
You're going to dig for info on their union-busting, but you're going to be very embarrassed if you find out that the Obama administration was in bed with these scumbags on some other sleazy project(s) that come up too. They were working for the banks, but some of these firms were (or at least had been) working for the government too. Might want to check with the White House before you start digging too deep.
SJW: Someone who has run out of real oppression, and has to fake it.
eventually anonymous would become a V for vendetta mask behind which vigilantes would do things that needed to be done, like this. Where are the people who were foaming at the mouth against Anonymous just a few weeks ago huh ? Here is anonymous justice, packed up and ready to go. The justice which was in no way delivered by the normal means you were speaking about that people should follow.
of course good guys, indifferent guys, and bad guys will do things by hiding behind such a mask. but, that doesnt make the presence of that mask, something bad.
Read radical news here
1) Don't use Windows
2) Don't use Facebook
I am very small, utmostly microscopic.
So they were clearly and intentionally on the more shady end of ethical boundaries. They aren't a security firm, they're crackers for hire.
how is babby formed?
I suspect that what was meant was that there is a Democratic push (by big D Democrats) to investigate HBGary. I haven't heard of any sit-ins over the issue, at least as yet.
i told you that, going after anonymous would cause more hardcore circles, which are in constant rebellion to anything that is establishment, to take up the cause of the anonymous.
Anyone spending a few years in the early stages of internet, in which those underground circles were not so underground like today, would be able to know and tell the same. Its the rebel net culture. That underground is multitudes over the level of what the private lackey corps or govts. can afford to hire or educate. They are of a sort that grows/breeds on its own.
Despite their roads have diverged with most of us the early netizens like me, i indeed learned to develop a deep respect for their kind. For, even if they do a lot of shady stuff, they do have a very strong attachment to some principles. and that's something to be respected.
Anyway. see, what they have done. good luck to govt and their lackeys in finding who did it. they may even be inside hbgary itself. you'll never know. once a rebel, always a rebel.
Read radical news here
Talk about rats leaving a sinking ship...
ELOI, ELOI, LAMA SABACHTHANI!?
Hairy Back Gary, that guy that lives in your mother's basement. The one she calls your uncle.
Tiger Blooded Bi-Winning Machine
http://nakedsecurity.sophos.com/2011/02/16/lessons-to-learn-from-the-hbgary-federal-hack/
..... blah blah and stole proprietary and 'confidential' information which was STOLEN by us by using ROOTKITS and VIRUSES and 0 DAY EXPLOITS from private citizens' computers ....."
....
down below.
http://sophosnews.files.wordpress.com/2011/02/hbgary-rsa-sign.jpg?w=640
"A group of AGGRESSIVE hackers known as 'Anonymous' illegally broke into blah blah
corporate lack of shame. you produce rootkits, viruses, 0 day exploits, malware to spy on people, steal their confidential, legally private information to SELL them, and then you dub that information 'proprietary' information belonging to you
i wonder what will they say in their defense in front of senate committee. what's more, i wonder what will the senate committee say to them, in regard to their dealings with this filthy outfit.
whats the slogan of hbgary anyway ? "hey - we produce viruses, rootkits, 0 day exploits and malware to steal your private information to sell to corporations and government !!!" ?
Read radical news here
Quis custodiet ipsos custodes?
Where money and power is concerned there is no freedom and nothing is sacred; except money and power.
Did you ever wake up in the morning, with a Zombie Woof behind your eyes? -- FZ
Or not so amazing...
I note the comment from The Wild Norseman:
http://it.slashdot.org/comments.pl?sid=2017860&cid=35350670
No brain, no pain.
HBGary has also DMCA'd a security blogger over a post about "Malware DNA" as well.
This is the same blogger HBGary called 'nutty but smart' (I paraphrase) in their emails and then cited to his work as 'a good idea'
See: http://conanthedestroyer.net/2011/02/15/wherez-it-at-hbgary-response/
I thought it stood for "Huge Balls" Gary. As in, that guy must have some huge fucking balls doing what he did.
- None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
The problem I have with this is that I think its just noobs selling shit to boobs.The more this story develops I become more and more uncertain that HBGary had te technical know how to make working root kits, and 0-days for multiple OS's. I betcha these guys would just sit waiting for bugtraq to update and hurriedly package it, that i do believe they are capable of. Some of the things that were apparently willing to sell or selling require superior technical understanding, and if the twats at HBG had that, they wouldn't be so chock full of epic loss right now
sig loading.......
Karma: a concept for people who want to believe in justice but don't want a daddy-figure meting it out. Sorry, but no. There is no such force as karma, unless we make it. If we want justice, we shouldn't wait for a holy sky father or invisible morality scale to create it, we need to do it ourselves.
- None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
http://en.wikipedia.org/wiki/The_Yes_Men
The Yes Men often deploy a satirical approach: they pose as a powerful entity (typically a corporate or government representative or executive) and make ridiculous and shocking comments that caricature the ideological position of the organisation or person. Furthermore, they acknowledge the idea that many corporate or government entities manipulate their ideology using spin; in response, the Yes Men use this power of spin to their own advantage, and use media outlets to disseminate their personal interpretation of the situation. A sense of humor and shock value is usually employed to make these issues more palatable to the general public and to call greater media attention to stories of interest.[1] Some of these outrageous ideas include the possibility to sell one's vote or that the poor should consume recycled human waste. On most occasions, little to no shock or outrage is publicly evoked in response to their prank.
On occasion, the Yes Men's phony spokesperson will make announcements that represent fictitious scenarios for the anti-globalization movement or opponents of corporate crime. The result often heed false news reports which cover the demise of the World Trade Organization, or Dow Chemical paying compensation to the victims of the Bhopal disaster, which the Yes Men intend to provide publicity for problems concerning these organizations. One of the effects of apologizing and promising support on behalf of an organization is that the organization is then later forced to re-acknowledge the event in question and retract all of the proposed good will. This served to further publicize the negative event of the organization and sets-up the organization to look bad for taking back any support The Yes Men offered under the name of their organization.
--
There are people who attack corporations in this way, and are not investigated by the Democrats on anything like a regular basis.
Are they gonna be investigated too?
I have left slashdot and am now on Soylent News. FUCK YOU DICE.
I think that what he meant was, the result was what some might term "karmatically appropriate" (even if we don't properly understand a true meaning of karma). Here's how:
- Many people see Anonymous as posing a threat of illegal stuff. (or Stuff we don't like, depending on who you ask.)
- HBGary Federal positions themselves as someone who can identify who Anonymous are, so that we can punish them for illegal stuff.
- Anonymous retaliates, and exposes all of HBGary Federal's communications.
- Apparently, HBGary Federal was engaging in shady stuff, and we'd never have known had they not targeted Anonymous.
Did anything illegal happen? The letter suggests that forgery, wire fraud, and computer fraud might have taken place and that Congress should investigate the ways that private contractors turn their military contracting experience on private targets.
(quoting Ars.) It's most interesting that the questionably-legal things that they were pursuing would likely never have been known, had they not attempted to "bring down" Anonymous. The company was probably small enough that a whistleblower would be unlikely to be involved, and they were generally under Anonymous' radar until they pissed them off.
It's fascinating: most of us dislike the idea of vigilante justice. However, in this case, it was directly responsible for uncovering something which might be wrongdoing (hence the call for an investigation). Wow.
You mean all that social activism shit? I'd rather play CS than worry about some groups vendetta. Life's too short
"He who lives in glass house should not throw stones"
ok it's not attributed to him, but is attributed (in various slightly differing forms) to a wide variety of people, including Ben Franklin. Nothing quite as entertaining to see someone tasked with bending laws get bent over BY the laws, from their own pen.
I work for the Department of Redundancy Department.
Capitalization is important. Consider the sentence:
i helped my uncle jack off a horse
"I'd rather be a lightning rod than a seismometer." -Ken Kesey
I assume it stands for (Greg) Hoglund (something or someone with an initial "B") Gary. This is the third time I would post the same tirade, just google for "Greg Hoglund".
Emotions! In your brain!
That''s an insult to his testicles; I am sure they are significantly smarter than he is.
I bet you their bosses at the NSA are already calling senators suggesting how Inconvenient it would be if Certain Things came to light and the whole matter will go poof inside of a week.
So why is Anonymous the good guys for hacking banks and the government is the bad guys for hacking...well the bad guys!?
Who is surprised at how unprofessional and childish some of these emails are? Forget about the questionable activities, I have never worked at a job where these emails would be considered acceptable communications, even internally.
"In America, first you get the sugar, then you get the power, then you get the women..." -H. Simpson
"Climategate"? You mean the made-up controversy by oil company shills?
Really? It doesn't have anything to do with justice? You DO realize that there are several eastern religions that talk about karma, and that while it isn't the same in all of them, most conceptions of karma can be boiled down to "you reap what you sow." How is that not justice?
It still stems from the misconception that the self is separate from the universe. Being separate, the self is an uncaused cause. We all understand how cause and effect work, if that were all karma were, there would not be a separate word for it, it would just be "causation." No, karma springs from the idea that the self is a separate uncaused cause, and therefore, there needs to be some spiritual method of restoring balance caused by the unbalancing actions of the separate self. That method is karma.
The most common conception of karma is in relation to reincarnation, that how you act in this life determines what you are reincarnated as. That is a form of wishing after justice. The next most common conception is of a kind of universal enforcement of "you reap what you sew," which posits that if you do bad things, bad things will happen to you. As we can see that bad things do not always happen to bad people, that leads right back into believing in reincarnation, karma will ensure those bad people are punished, if not in this lifetime, then the next. That is the sense the OP was using it in.
If you take the self out of the picture, then all the concept of karma is saying is that bad things are bad, while good things are nice. Bad things lead to hurt, while good things lead to happiness. As there is no "self" in this discussion, it doesn't matter who perpetrates the action and who receives the bad feelings. I kick you in the nuts, you feel nut-pain, THAT is real karma. And also not how the OP was using the term at all.
Are we done with school yet, or would you like another lesson?
- None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
Thu big sky turtle, what lives in the sky, gets flea bites when people do wrong and will occasionally shake, causing untowed damage to the world it carries on the backs of elephants.
I drank what? -- Socrates
Anonymous just might be the invisible morality scale. I'd say they're either lawful evil or chaotically good. I don't know my D&D well enough to apply it. Means, Ends, that whole moebius strip.
Although he was trolling hard, in a way "what is it to us who HBGary is in the scheme of things if it allows a total conflation abuse by the govt to say "look, Anonymous hacked sensitive federal companies! They must be stopped!"
Insert TV Trope here.
My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine
The Lady of the Lake, her arm clad in the purest shimmering samite held aloft Excalibur from the bosom of the water, signifying by divine providence that I, Arthur, was to carry Excalibur.
Hail Eris, full of mischief...
E pluribus sanguinem
You mean all that social activism shit? I'd rather play CS than worry about some groups vendetta.
"You may not be interested in politics, but, sooner or later, politics will be interested in you." -- Vladimir Lenin
Life's too short
Exactly! Too short to waste it on Slug.
Yes. What's the connection? That's the question.
We are aware that HBGary did something to piss off Anonymous - which in fact tells us precisely nothing.
A little context would be nice.
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
I'd say Anonymous is chaotic neutral: sometimes good, sometimes evil, never lawful.
- None can love freedom heartily, but good men; the rest love not freedom, but license. -- John Milton
I found this, which was nicely informative:
http://dagblog.com/reader-blogs/hb-gary-federal-anonymous-and-wikileaks-8912
The short of it is that there is evidence that they were soliciting "cyber attacks" as a service, which is a complete departure from what Security Firms up to this point do (protect from said attacks, etc). Defensive to offensive.
For large sets, this will be our guide even unto death, for the LORD will work for each type of data it is applied to...
If you still believe climategate was anything other than a political beat up then you haven't even bothered to do your own investigation.
And did you exchange a walk on part in the war for a lead role in a cage? - Pink Floyd.
Anonymous is more like a Far Plane aberration, if you interpret their morality as a group and not just as a large number of people doing their own thing and cooperating or anonymously with each other randomly as their interests or whims align. Kind of like the "Wild Hunt"
Emotions! In your brain!
They weren't even under investigation until the break in.
That kind of reminds me of something else I heard somewhere before...
the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff
"You may not be interested in politics, but, sooner or later, politics will be interested in you." -- Vladimir Lenin
Isn't that the point of Soviet Communism?
the existence of personna management software makes you wonder about the useage of facebook and other social media in the revolutions in Tunisia, Egypt and Libya doesn't it...
Donald 'Duck' Dunn: We had a band powerful enough to turn goat piss into gasoline.
Chaotic Neutral is my guess. Rare case of *actual* chaotic neutral.
They troll a lot of innocent people/entities, but also troll a lot of horrible people/entities.
Folks,
This is US and EU. Businesses (DMCA, IPR, RIAA...) prove institutions' civil-rights exceed the individual rights of any citizen to any protection from attack, exploitation, legal threat. Themis is just another business committed to impacting "The USA Constitution," US, and EU people (nothing new).
Remember it is safer to accept than reject your masters. The politicians in the USA know that fact; So, never expect them to do anything about their betters.
Business is the government of governance. Parliaments, congresses, ministers, presidents... are the loyal servants of global-corporate elitist/plutocrats. IOW: National Governments are a propaganda façade for the dogma-swilling public.
Industry/banking... C*Os legally destroyed the economies, our governments provided corporate-welfare bailouts, many of "The People" lost everything, and some token-crooks went to jail. US and EU folks are really very fucked-up legally and economically. We lose our houses, retirements... and the C*Os, politicians... that committed the crimes get welfare (C*Os) or reelected (corporate loyal lobbyist).
CIOs/Politicians seldom to never go to jail for breaking laws or for fucking US or EU folks.
Unaccountable leaders are masters, and unrepresented people are slaves. How do US and EU fare?
thats quite well said actually. depending on the social composition of internet, anonymous will keep its identity and formation, because it comprises of voluntary, unattached groups having an attachment only to a principle ; "Anonymous"
Read radical news here
Once again, the DoJ is found to be involved in shady dealings involving software to track and correlate people.
http://www.wired.com/wired/archive/1.01/inslaw.html
The linked article mentions alleged wrongdoing by HBGary only very briefly - just one paragraph near the end. It also isn't immediately clear whether or not any of the actions this paragraph alleges would actually be illegal under US law. (For reference, the paragraph in question starts "When asked to investigate pro-union websites".)
The main focus of the article is on the sort of technology HBGary was developing. (Personally, I'm particularly intrigued by the use of direct access ports in attack technology, because this is a vulnerability I've been complaining about for years. Nobody I discussed it with would admit it was a security risk worth caring about.)
I still maintain that these jackwagons will just sell book and movie rights because of this amd make millions.
So. Hacking and computer security in the end made them rich. Not in the manner they intended... but I am sure they don't care.
I am very small, utmostly microscopic.
OK, so you've heard the term "chain of custody". You're not thinking this through like an investigator, though. Congress can subpoena the original records and establish that chain. They can even subpoena people who received the emails, and ISP who may have stored them on a server somewhere.
If you mod me down, I shall become more powerful than you could possibly imagine.
I'd say Chaotic Neutral with Evil tendencies. The heart of Anonymous is chaos: no visible structure, no weak points, just lots of individuals that occasionally cooperate. They are a source of punishment much more than reward, but the targets that they punish are usually violators of some sort of ethical boundary (I'd say Neutral with occasional Good depending on target, but every DM has their own definition of alignment anyhow). The "for the lulz" motivation for many members is very selfish, and selfishness is squarely on the path towards Evil (personal gratification without regard to the expense/effects on others).
One of the few appropriate examples of Chaotic Neutral. Most attempts (even the 2nd edition Player's Guide, IIRC) end up depicting the alignment as Chaotic Stupid. Maybe it's an indication that Law/Chaos applies to a community rather than an individual. In any case, it's certainly better that Wizards of the Coast's latest alignment interpretation, where the bad guys are either Evil or Really Evil.
http://www.bradblog.com/?p=8351
"I can't imagine how things could get any worse!" (some guy) "That could just be failure of imaginatioÂn on your p
As Thursday's show continued, I received confirmation that I, personally, along with members of my family, had been highlighted in Themis' proposed hit job, as ThinkProgress followed up with a second story, based on several other emails from HBGary's CEO Aaron Barr. The email focused on me included names, personal information, home addresses, etc. of myself, family members and a number of other members of VR. Naturally, I reported on the then-confirmed news in the second hour of that night's Malloy Show.
From page 5 of the Ars Technica article:
When asked to investigate pro-union websites and WikiLeaks, Barr turned immediately to his social media toolkit and was ready to deploy personas, Facebook scraping, link analysis, and fake websites; he also suggested computer attacks on WikiLeaks infrastructure and pressure be brought upon journalists like Glenn Greenwald.
His compatriots at Palantir and Berico showed, in their many e-mails, few if any qualms about turning their national security techniques upon private dissenting voices. Barr's ideas showed up in Palantir-branded PowerPoints and Berico-branded "scope of work" documents. "Reconnaissance cells" were proposed, network attacks were acceptable, "target dossiers" on "adversaries" would be compiled, and "complex information campaigns" involving fake personas were on the table.
Critics like Glenn Greenwald contend that this nexus of private and public security power is a dangerous mix. "The real issue highlighted by this episode is just how lawless and unrestrained is the unified axis of government and corporate power," he wrote last week.
Especially (though by no means only) in the worlds of the Surveillance and National Security State, the powers of the state have become largely privatized. There is very little separation between government power and corporate power. Those who wield the latter intrinsically wield the former.
The revolving door between the highest levels of government and corporate offices rotates so fast and continuously that it has basically flown off its track and no longer provides even the minimal barrier it once did. It's not merely that corporate power is unrestrained; it's worse than that: corporations actively exploit the power of the state to further entrench and enhance their power.
Even if you don't share this view, the e-mails provide a fascinating glimpse into the origins of government-controlled malware. Given the number of rootkits apparently being developed for government use, one wonders just how many machines around the globe could respond to orders from the US military. Or the Chinese military. Or the Russian military.
While hackers get most of the attention for their rootkits and botnets and malware, state actors use the same tools to play a different game—the Great Game—and it could be coming soon to a computer near you.
"I can't imagine how things could get any worse!" (some guy) "That could just be failure of imaginatioÂn on your p
Aaron Barr just failed upward. Nepotism is one thing, but once I saw that W had failed upward all the way to the Presidency with Supreme Court jurists as his accomplices, I re-examined a lot of assumptions about ethics and competency in high places in this country.
"I can't imagine how things could get any worse!" (some guy) "That could just be failure of imaginatioÂn on your p
And all of them will be labeled Terrorist Organizations in a heart beat. And the majority of American Mouthbreathers will believe it in the same tick of time.
will never let a committee question HB Gary or any other corrupt company for that matter. Thanks, all-knowing, wise US voters.
What is the most interesting to me, is how there was no direct damage done by Anonymous. They hacked into the servers, grabbed information, and published it. They did deface a web site to prove they'd been in, but that was minimal and easily fixed. They didn't destroy equipment or attack his family.
What they did was get in, grab the information, and publish it. Then they let the information stand on its own as to what it reveals about HBGary. This is the transparency corporations and governments should offer and which Wikileaks has been trying to offer. I really like where this is going.
If he explores all forms and substances Straight homeward to their symbol-essences; He shall not die.
I dunno, I see Anonymous as Chaotic Good, but with a problem much like a chess computer calculating a tricky move. What "is good to do" may be provisionally true, as a "fight censorship / fight the man / fight the corps" kind of thing. Per the other thread if more than one side is morally wrong, it becomes a mess to evaluate your own decision. HBGary would have been one more faceless semi-competent little gov agent of dubious morals. We wring our hands when the gov doesevil stuff, because "don't you know who they are? They're the Governaut, bitch!". But when citizens do it, look at the paid anonymous turfers trying to poison the discussion.
(What's a political astroturfer called? They're selling mercs, not merch.)
But yes, only Chaotic Good, because then they miscalc something and drift off into the lulz and lose the storybook ending for something messier.
Also Anonymous has a big weakness. Gov is trying to deliberatly apply the logical fallacy that "there is only one Anonymous and they must be stopped by draconian measures."
My first Journal Entry ever, in 8 years! http://slashdot.org/journal/365947/aphelion-scifi-fantasy-horror-poetry-webzine