Government Spyware Vendor Left Customer, Victim Data Online for Everyone To See (vice.com)
The Germany-based spyware startup Wolf Intelligence exposed its own data, including surveillance target's information, passports scans of its founder and family, and recordings of meetings. From a report: A startup that claims to sell surveillance and hacking technologies to governments around the world left nearly all its data -- including information taken from infected targets and victims -- exposed online, according to a security firm who found the data. Wolf Intelligence, a Germany-based spyware company that made headlines for sending a bodyguard to Mauritania and prompting an international incident after the local government detained the bodyguard as collateral for a deal went wrong, left a trove of its own data exposed online. The leak exposed 20 gigabytes of data, including recordings of meetings with customers, a scan of a passport belonging to the company's founder, and scans of the founder's credit cards, and surveillance targets' data, according to researchers.
Security researchers from CSIS Security discovered the data on an unprotected command and control server and a public Google Drive folder. The researchers showed screenshots of the leaked data during a talk at the Virus Bulletin conference in Montreal, which Motherboard attended. "This is a very stupid story in the sense that you would think that a company actually selling surveillance tools like this would know more about operational security," CSIS co-founder Peter Kruse told Motherboard in an interview. "They exposed themselves -- literally everything was available publicly on the internet."
Security researchers from CSIS Security discovered the data on an unprotected command and control server and a public Google Drive folder. The researchers showed screenshots of the leaked data during a talk at the Virus Bulletin conference in Montreal, which Motherboard attended. "This is a very stupid story in the sense that you would think that a company actually selling surveillance tools like this would know more about operational security," CSIS co-founder Peter Kruse told Motherboard in an interview. "They exposed themselves -- literally everything was available publicly on the internet."
VENDOR?! They openly admit to their existence now?! How exactly are the targets compromised? Backdoors in Windows? Hardware backdoors? AND they left this info lying around in public?! WTF?!
Whatever happened to basic competency in your core skillset?
I've lost respect for people who use "easy" cloud services.
They were just taking 'transparency' and 'full disclosure' to its logical conclusion.
This was no accident.
Keep dragging those evil fuckers hiding in the dark corners of our governments into the light of exposure! They cant do their evil without us technical peons. We peons can change the world for good.
But your sister enjoys my lignite
They were just demonstrating their software on themselves! Look at how well it works!
Doesn't sound very intelligent to me.
(disclaimer, I only RTFS)
General Relativity: Space-time tells matter where to go; Matter tells space-time what shape to be.
taking corporate transparency a little too far.
Sig Follows: "Suppose you were an idiot. And suppose you were a member of Congress. But I repeat myself." -- Mark Twain
https://www.youtube.com/watch?v=YQBFx-4ZltA
What more does anyone need to say?
#facepalm
File under 'M' for 'Manic ranting'
This is the kind of company you want to make deals with concerning spying on your voters? If they can't even keep their own crap secure, do you think they will keep your shady deals with them from public eyes? From the eyes of the people you want to spy on that you on the other hand also want to vote for you?
Yeah. Smart move. Then again, we didn't exactly expect you to know anything about IT anyway, considering your track record.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
.... and many heads were shaken.