Slashdot Mirror


Homeland Security Subpoenas Twitter For Data Breach Finder's Account (zdnet.com)

An anonymous reader shares a report: Homeland Security has served Twitter with a subpoena, demanding the account information of a data breach finder, credited with finding several large caches of exposed and leaking data. The New Zealand national, whose name isn't known but goes by the handle Flash Gordon, revealed the subpoena in a tweet last month. The pseudonymous data breach finder regularly tweets about leaked data, found on exposed and unprotected servers. Last year, he found a trove of almost a million patients' data leaking from a medical telemarketing firm. A recent find included an exposed cache of law enforcement data by ALERRT, a Texas State University-based organization, which trains police and civilians against active shooters. The database, secured in March but reported last week, revealed that several police departments were under-resourced and unable to respond to active shooter situations.

Homeland Security's export control agency, Immigration and Customs Enforcement (ICE), served the subpoena to Twitter on April 24, demanding information about the data breach finder's account. ICE demanded Twitter turn over his screen name, address, phone number -- and any other identifying information about the account, including credit cards on the account. The subpoena also demanded the account's IP address history, member lists, and any complaints filed against the Twitter account.

48 comments

  1. We'd all be better off by ArchieBunker · · Score: 0, Offtopic

    if Twitter just went away one day. It's a part of the culture at this point and collectively making everyone dumber.

    --
    Only the State obtains its revenue by coercion. - Murray Rothbard
    1. Re:We'd all be better off by Anonymous Coward · · Score: 0

      Found the dinosaur

    2. Re:We'd all be better off by Anonymous Coward · · Score: 2, Insightful

      Government secrets used to be leaked in newspapers; burn all newspapers!

    3. Re:We'd all be better off by Anonymous Coward · · Score: 0

      Found the dinosaur

      Found the one who obviously hasn't used Twitter. If you had, you sure as hell wouldn't be defending the notion that social media mouth-breathers bring value to it...

    4. Re:We'd all be better off by Anonymous Coward · · Score: 0

      Found the dinosaur

      Found the stupid jerkoff who has yet to understand that wasting time on bullshit like Twitter is something smart people don't do.

    5. Re:We'd all be better off by Anonymous Coward · · Score: 0

      subpoenas is a funny word
      like if you didnt know how to pronounce that how would you say it in conversation
      go ahead and sound it out

    6. Re:We'd all be better off by Anonymous Coward · · Score: 0

      Found the dinosaur

      Found the stupid jerkoff who has yet to understand that wasting time on bullshit like Twitter is something smart people don't do.

      Because arguing about Twitter on /. is sooo different and not a waste at all :-/

    7. Re:We'd all be better off by PopeRatzo · · Score: 4, Informative

      if Twitter just went away one day. It's a part of the culture at this point and collectively making everyone dumber.

      I feel the same way about the Department of Homeland Security.

      --
      You are welcome on my lawn.
    8. Re:We'd all be better off by Anonymous Coward · · Score: 0

      Wrong, I'm the dinosaur. No Twitter, no FaceBook, no Instagram, no SnapChat. I have a phone I call with or text as needed and an email account to share pictures with family and friends. Well, I do have a Reddit account and a Slashdot account so maybe more a Neanderthal and not a dinosaur. But close.

    9. Re:We'd all be better off by Anonymous Coward · · Score: 0

      I also have none of the above mentioned things, not because I'm a dinosaur but because I'm not stupid.

  2. Finder. Not breach creator. Finder. by Anonymous Coward · · Score: 2, Informative

    How dare you say the king is wearing no clothes!

  3. No fan of an HSA TLAs by TimMD909 · · Score: 5, Insightful

    The Homeland Security crowd seems as focused on security as the Ministry of Truth was about truth.

    1. Re:No fan of an HSA TLAs by 93+Escort+Wagon · · Score: 1

      Well, it is run by Ming the Merciless - and he’s show. a special interest in this particular case.

      --
      #DeleteChrome
    2. Re:No fan of an HSA TLAs by gweihir · · Score: 1

      Indeed. You know a society is in decline when keeping up appearances becomes far more important than solving problems.

      --
      Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
    3. Re: No fan of an HSA TLAs by Reverend+Green · · Score: 1

      Tacitus said it best:

      "The more corrupt the state, the more numerous the laws."

  4. Incompetence? by Maelwryth · · Score: 3, Insightful

    Someone should tell them what the wheel on the mouse does. It might save them having to use a lawyer every time they want some freely available info in a twitter feed....or they could just talk to him.

    --
    I reserve the write to mangle english.
  5. That's no boating accident by Anonymous Coward · · Score: 0

    The linked article has an image purportedly showing a "subpoena." That's no subpoena. It's a simple typewritten request that Twitter is free to ignore.

    1. Re:That's no boating accident by onepoint · · Score: 3, Informative

      While you might have thought you were Trolling, I went and looked and discovered something that I never knew existed and it's rather interesting ( at least to me who like's to learn about customs, shipping and laws

      what ICE issued was a
      Export Enforcement Supeana: WTF is what I said, then I learned, interesting tool they have https://www.law.cornell.edu/cf... that's the link to the Cornell legal explanation of it and where it sits in the law books.

      Now how it applies to Twitter, well that's up to a lawyer to explain to the readers of slashdot
      I understand how it applies to exports but this is confusing how it's being applied to Twitter.

      --
      if you see me, smile and say hello.
    2. Re:That's no boating accident by Anonymous Coward · · Score: 1

      it seems to me that they tried requiring provision of records without a subpoena and Twitter told them to go fly a kite -- so they went and got a subpoena (just applying the information in the link).

      In other words, it "applies to Twitter" because they "say so". Not being an export lawyer, my guess is that their argument goes that since Twitter operates internationally it is inherently doing export and import so it comes under their jurisdiction. And if you are exporting/importing then you have to maintain records as to what, by whom, for what purpose.

      So, more generally, just an attempt to end run around the legal system that Twitter rejected. Since their bluff was called, instead of folding, they are doubling down by following up with a subpoena. The relevance of export regulations seems tenuous at best, but that is their argument and they are sticking with it.

    3. Re:That's no boating accident by grep+-v+'.*'+* · · Score: 1

      but this is confusing how it's being applied to Twitter.

      It's being applied to Twitter by a very nice smiling man in a black hat, holding a large piece of legal-sized paper on Twitter behind which is a large gun, and saying, "Nice piece of internet real-estate you've got there, ..."

      It's the government. Once you finally manage to attract their attention and actually get them pissed, you've got Trouble with a Capital T.

      Good info, thanks for sharing it!

      --
      If the universe is someone's simulation -- does that mean the stars are just stuck pixels?
    4. Re:That's no boating accident by Anonymous Coward · · Score: 0

      "(b)Persons located outside of the United States."

      So can anyone clarify how this law applies to people outside of the United States?

  6. Is the subject correct? by houghi · · Score: 1

    I thought it was a judge who did the subpoena and not HLS? If so do not get angry at HLS for asking it but at the judge for goving it, if you think they should not have done that.

    I have been in situations where the police asked for data and I (and my cow orkers) refused to give it untill there was an order from a judge. The police is allowed to ask for it, yet we are not allowed to give it.

    The thing is atht these where cases we had no real issue giving the information, but if the defence found out how they got their proof, the case could easily be trown out.
    And I am talking about cases like fraud, blackmail, childporn, theft. Not about grandma downloading a Metallica song. (That reference tells you how old I already am) because those where never in court., In fact I remeber reading a letter where the courts said not to bother them with such cases as it would be hogging to much time and would be seen as a contempt of the court if they continued. (Unfortunately I have not kept the letter). Yes, they would still help if there was some sort of financial gain. i.e. a copy of a CD? No problem. Selling that copy? You are going to court.

    If the courts or a jury gave an OK to the sobpoena (and not rubberstamped it) I have no real issues. I must see what it is based on before any outrage.

    --
    Don't fight for your country, if your country does not fight for you.
    1. Re:Is the subject correct? by Anonymous Coward · · Score: 1

      I thought it was a judge who did the subpoena and not HLS? If so do not get angry at HLS for asking it but at the judge for goving it, if you think they should not have done that.

      A subpoena is supposed to be for producing testimony and other evidence in a case. Who would be the defendant in this case? Are they planning to bring some kind of charge against Flash Gordon? WTF? No wrongdoing on his part has been alleged. Surely they're not planning to prosecute the people who left the data accessible.

    2. Re:Is the subject correct? by Anonymous Coward · · Score: 0

      Apparently they're going after him for illegal data export. I'd assume making bug information available to the enemy.

      I'd bet they don't want him though. They want his sources. If they bring him in for questioning, they can threaten him with legal consequences unless he turns in his sources. Sure he might be getting all these leaks through original research, but I doubt HLS thinks so.

  7. If the finder by Grand+Facade · · Score: 1, Interesting

    is a US citizen will IRS also be putting his last 10 years under scrutiny?

    Isn't this akin to shooting the messenger?

    Or is the finder in the game and looking to get the feds to take down his competition?

    --
    Rick B.
    1. Re:If the finder by Anonymous Coward · · Score: 0

      Isn't this akin to shooting the messenger?

      Nah, if he was a real pain in the ass to those in power, he'd need to be hiding in an embassy / or powerful enemy country somewhere.

      This is a case of "woke the sleeping tiger". Which in the United States of Kissups, is a felony punishable by several years in prison, fines, and life ruining. But not death. Yet.

    2. Re:If the finder by HiThere · · Score: 1

      This seems clear evidence that if you find an official has made a mistake, you ensure that your notice of that is really anonymous. Possibly by selling it on the black market.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  8. The horse is already out by Nidi62 · · Score: 4, Insightful

    In a sane world, they would be finding them to give them a medal. If he could find those leaks, there's a good chance somebody else already had. And these days it seems the only way to get companies to acknowledge and fix leaks is to make them public, otherwise they get swept under the rug.

    On a side note, having a hard time seeing how this falls under the purview of ICE. And I'm sure the government will be going after the medical telemarketing firm for a breach of HIPAA

    --
    The only thing necessary for evil to triumph is for it to be pitted against a slightly greater evil
    1. Re:The horse is already out by Anonymous Coward · · Score: 1

      TFA says: Although ICE's public image is often viewed through a lens of detentions and deportations, a large part of the agency's work includes fighting national security threats and fighting transnational crime, including prosecuting those who violate export laws.

  9. Remember, this is publicly accessible data by Anonymous Coward · · Score: 5, Insightful

    They're going after someone who walks down the virtual street pointing out things that are publicly accessible without a single functional access control mechanism. This isn't a "hacker," it's a person that points at something on the digital street that anyone could find and access anyway. This person has committed no crimes whatsoever in doing this.

    1. Re:Remember, this is publicly accessible data by BlueStrat · · Score: 4, Insightful

      They're going after someone who walks down the virtual street pointing out things that are publicly accessible without a single functional access control mechanism. This isn't a "hacker," it's a person that points at something on the digital street that anyone could find and access anyway. This person has committed no crimes whatsoever in doing this.

      He committed the worst crime imaginable in the eyes of the US Government.

      He revealed the incompetence and ineffectiveness of a US Government security agency. To those in government, there are few crimes as onerous as revealing their incompetence and lawbreaking for all to see.

      It appears that the NSA and other US TLAs have been too busy with US domestic mass surveillance, data-farming, and domestic political shenanigans to bother with piddly things like securing national infrastructure and other mundane tasks they were created to perform. Very sad.

      Strat

      --
      Progressivism (aka US 'Liberalism'): Ideas so good they need a police/surveillance-state to enforce.
  10. interesting prioritization by jm007 · · Score: 2

    there's enough resources to track down someone pointing out DHS fuckups but not enough to set up a firewall or two to prevent the fuckups in the first place

    the fuckups allowing all that private data to leak out won't be held accountable as wrongdoers, just the person pointing it all out

    there's always more to the story than we're being told

  11. Blame both. Don't allow yourself to do bad things by raymorris · · Score: 2

    Your post was interesting, thanks.

    > do not get angry at HLS for asking it but at the judge for giving it, if you think they should not have done that.

    We don't know why they're asking, or what basis (evidence) they have to support the subpoena, but let's assume for a moment that there is a bad subpoena, that the subpoena shouldn't have been done. If so, I would definitely blame the people who decided to get a bad subpoena that they shouldn't have gotten. "The judge let us get away it" isn't an excuse for doing bad things.

    If a subpoena is not only bad but also illegal, the judge would ALSO be at fault for allowing an illegal subpoena. (Remember judges rule on what's legal, not on what they think is good).

    In fact I would go so far as to say a free country *requires* we hold ourselves to a higher standard than "it's fine to do anything, so long as a judge doesn't rule it illegal". If we as a society decide we'll all do whatever nasty things as long as the law lets us get away with it, then we'd need laws against everything that might be a problem. If the only limits we put on our behavior is the law, pretty soon we need laws to stop all kinds of things, totalitarianism is required. If instead we live based on trying to do the right thing, to be considerate of others and avoid causing problems for other people (law or not), then we don't need so many laws. We can have a functioning society that is much more free of we each use our freedom in ways that are respectful and considerate of others, we don't need laws telling us exactly what we can and can't do.

    > I thought it was a judge who did the subpoena and not HLS?

    In this instance the agency can issue a subpoena. If someone doesn't comply with the subpoena, they can ask a court to enforce it.

  12. target might be someone else by Anonymous Coward · · Score: 1

    You may be jumping to the conclusion that this guy is under investigation -- possible, but not necessarily. The person under investigation could be the person who possibly exposed this data to the internet intentionally. If you are selling an ICE agent database, your client is a probably a drug exporter in Mexico, and the Internet facilitates transfer. Flash Gordon could be subpoena'ed as a material witness. Surely it happens, every once in a while, that the US justice system is seeking a legitimate bad guys.

    1. Re:target might be someone else by HiThere · · Score: 1

      No, I'm jumping to the conclusion that the guy is being persecuted. They probably haven't yet decided what they're going to charge him with, but they'll come up with something. This isn't the way you contact someone to ask for their help, this is an attempt to bludgeon him with the law. Judging by what has thus far been said, the applicability of the law they're using is quite dubious, but if they can threaten Twitter enough, they can get the guy id'd. This is much more like coercion than asking for help.

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  13. Export Enforcement Subpoena??? by Anonymous Coward · · Score: 1

    The Twitter user is in New Zealand, correct? What exactly got exported that requires enforcement? Also, none of the information ICE is asking for is covered by ITAR, so the subpoena is unenforceable on its face.

    Twitter should just respond by ceasing to operate in the United States, which would have the added bonus effect of shutting up the Cheeto-in-Chief.

  14. Seek help please by Anonymous Coward · · Score: 0

    It is perhaps time to acknoweledge that you are possibly a paranoid delusional. Advocating/inciting murder is actually a crime and you might really someday become the subject of an investigation for doing it. You may conflate that LEO interest with your espousal of 9/11 theories...
    It is actually time to put away the phone or disconnect your keyboard and go talk to a physician you trust. Look up signs/symptoms of paranoia and honestly measure yourself and your beliefs against that criterion. You have nothing to lose if you are in fact ok and everything to gain if it does turn out you have a problem.

    1. Re: Seek help please by Anonymous Coward · · Score: 0

      He's an astroturfer employed on a black budget contract. The purpose of his inane posts is to make 911 "truthers" look like deranged nutjobs. Thereby discrediting skeptics of the obviously-false official 911 narrative.

  15. Shoot the messenger by gweihir · · Score: 1

    And you will not get any bad news anymore. Short-term this may be nice, long-term it is a disaster. Is this agency staffed by complete and utter morons?

    --
    Most ACs are not even worth the keystrokes to insult them. Be generically insulted by this and ignored otherwise.
  16. Take the pat down! by Anonymous Coward · · Score: 1

    walking in those big machines will give you cancer

  17. *sigh* by Anonymous Coward · · Score: 1

    There is probably a 30% chance this is legitimate (we want to talk to this person in case this was part of a planned leak) a 50% chance it is a scare tactic to prevent people from using free speech (if someone finds this information about LEOs they should tell us, not put it online), and a 20% chance it was reactionary chest thumping (how dare they make Law Enforcement Look bad!)

    I hate living in a world where it's impossible to tell the difference without being incredibly biased one way or the other.

    1. Re:*sigh* by HiThere · · Score: 1

      You are an anonymous poster on the internet presuming to speak for a government that lies more often than it tells the truth. Why should we believe you?

      --

      I think we've pushed this "anyone can grow up to be president" thing too far.
  18. Re: ICE Needs Your Help! 1-866-DHS-2-ICE by Anonymous Coward · · Score: 0

    Can I report creimer?

    He is a drain on society.

  19. They're a CAPTCHA: vipers by Anonymous Coward · · Score: 0

    Terrorist gang.

  20. Whose security is the DHS defending? by Bruce66423 · · Score: 1

    The security of the American state, or of the incompetents who make these mistakes? Does ANYONE vote for the first?

    1. Re: Whose security is the DHS defending? by Anonymous Coward · · Score: 0

      The incompetents themselves are certainly not concerned with the former, and by definition they are in charge.