Monday, July 11, 2011

Scriptkiddies Claim Fox News Twitter Account Hack

Scriptkiddies Claim Fox News Twitter Account Hack


Tuesday, July 05, 2011



Headlines

69dafe8b58066478aea48f3d0f384820

One of the Twitter accounts maintained by the Fox News organization was hijacked over the holiday weekend and used to post false messages claiming that President Barack Obama was assassinated.

The disturbing messages remained for several hours before being removed. The incident has been reported to the Secret Service and an investigation is underway.

The hack was claimed by a group calling themselves the "Scriptkiddies".

"We are looking to find information about corporations to assist with antisec [a concerted hacker attack on corporate and government security]. Fox News was selected because we figured their security would be just as much of a joke as their reporting," a purported member of the Scriptkiddies told Think Magazine.

A Fox News Twitter feed was hacked and used to publish false items that President Barack Obama had been killed.

Representatives of Fox News have requested Twitter present them with the details of the event and have asked to be provided with guidance on how to prevent further incidents.

"We will be requesting a detailed investigation from Twitter about how this occurred and measures to prevent future unauthorized access into FoxNews.com accounts," said Jeff Misenti, Fox News Digital's vice president and general manager.

Twitter representatives released the following statement regarding the Fox News account hijacking:

While Twitter does monitor accounts for brute-force login attempts and similar methods of attack, we're unable to anticipate compromises that take place due to offsite behavior.

Generally speaking, we suggest using an e-mail address associated with your domain or, if you do not have one, using two-factor authentication or being aware of best practices around password security in order to prevent attacks.

We've heard from Fox News that they have identified the offsite vector that led to the compromise, and would encourage follow-up with them about the details of how that compromise took place.

The Scriptkiddies claim to be loosely associated with the rogue movement Anonymous who previously gained attention for DDoS attacks against PayPal, Visa, MasterCard, PostFinance Bank, Amazon, Bank of America, the U.S. Chamber of Commerce website, and for having breached the systems of security consultants HBGary Federal.

"I would consider us to be close in relation [to Anonymous], two of the members of our group were members of Anonymous... I was a member of Anonymous. We hope to be working with them soon," the alleged hacking group member said.

Anonymous last week released the "OpNewBlood Super Secret Security Handbook" (pdf) in an effort to recruit more would-be hacktivist types to further the Internet anarchy cause.

The tutorial-style guide instructs users on multiple subjects, particularly how to set up secure Internet Relay Chat (IRC) access for group discussion participation.

The publication is more evidence that hacktivist groups like Anonymous and the now supposedly defunct LulzSec are shifting tactics by moving away from conducting offensive operations themselves, and instead may be seeking to educate and enable others take up the cause.

Recently we have also seen the emergence of the Anonymous-backed School4lulz, a resource for hi-tech hooligans to learn the finer art of hacking, cross-site scripting, SQL injections, botnet herding, doxing, and tools of the trade.

https://www.infosecisland.com/blogview/14971-Scriptkiddies-Claim-Fox-News-Twi...

Posted via email from Whistleblower

Innocence Blog: Friday Roundup: The Stories of Innocence Before and After Exoneration

Friday Roundup: The Stories of Innocence, Before and After Exoneration (7/8/2011)

innocenceproject.org | Jul 8th 2011 1:55 PM

Friday Roundup: The Stories of Innocence, Before and After Exoneration

Tavis Smiley sat down recently for a two-part PBS invterview with four men exonerated in Illinois after years in prison for crimes they didn’t commit.

A review by the Mid-Atlantic Innocence Project is exposing doubts about the police investigation of a Washington D.C. murder.

A Florida State Attorney recused himself after four new suspects were revealed in a case for which William Dillon was wrongfully convicted.

NPR reported this week on reforms in Dallas to make eyewitness identification procedures more reliable.

A Florida Today editorial calls on the state legislature to address reforms in eyewitness identification procedures.

A DNA mix-up caused by human error that led to a wrongful conviction of a Las Vegas man has prompted police to reanalyze more than 200 cases handled by a forensic scientist.

Two Canadian men who say they falsely confessed to a murder are seeking to overturn their convictions in Washington state with the help of the Idaho Innocence Project, an Innocence Network member.

Original Page: http://www.innocenceproject.org/Content/Friday_Roundup_The_Stories_of_Innocence_Before_and_After_Exoneration.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Innocence Blog: Supreme Court Ruling Means Lab Tech Should Testify

Supreme Court Ruling Means Lab Tech Should Testify (7/11/2011)

innocenceproject.org | Jul 11th 2011 5:16 PM

Supreme Court Ruling Means Lab Tech Should Testify

Last month, the U.S. Supreme Court ruled that the prosecution must call the actual lab analyst who performed the testing – or at least an analyst who was present during the testing – in criminal prosecutions.

Although this is a pretty clear requirement of the Constitution’s confrontation clause, , lab officials in New Mexico are worried that they will have to add up to 20 analysts to manage the work load, reported the Daily Times.

The Supreme Court’s finding stems from a 2005 drunk driving case where the public defender for the defense moved to exclude the testimony of the blood analyst since it wasn’t the analyst who performed the actual test.

The overburdened Scientific Laboratory Division is the only lab in the state and it has to be determined how it will handle the increased demands of analysts.

"The initial response is we are going to need more analysts, but if we don't have more, then we may be asking the analysts there to work more hours," said Elizabeth Trickey, general counsel for the state health department. "The implications could be very broad."

Read the full article.

Original Page: http://www.innocenceproject.org/Content/Supreme_Court_Ruling_Means_Lab_Tech_Should_Testify.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Innocence Blog: Reforms Pending In Connecticut

Reforms Pending In Connecticut

innocenceproject.org | Jun 15th 2011 5:16 PM

After a decade of attempts by Connecticut lawmakers to mandate the recording of interrogations, a bill is finally awaiting the governor’s signature, reports the Hartford Courant.

The bill, which cleared the Senate last week, requires police to make an electronic recording of every custodial interrogation on a felony case that is substantially accurate and not intentionally altered. If the bill is signed, any custodial interrogations that are not electronically recorded will be inadmissible in court.

Interrogations won’t be recorded until January 2014, to give law enforcement ample time to familiarize themselves with the procedure.

Recording interrogations can prevent disputes about how a suspect was treated, create a clear record of a suspect’s statements and increase public confidence in the criminal justice system. Recording interrogations can also deter officers from using illegal tactics to secure a confession.

In addition to mandatory recording of interrogations, the Connecticut legislature also passed a bill aiming to reduce wrongful convictions by creating an Eyewitness Identification Task Force to study issues surrounding eyewitness misidentification.

Read the full article.

Read the full text of the proposed bills: Interrogations / Identification

Read more about false confessions and the benefit of recording interrogations.


Tags: Connecticut, False Confessions, Eyewitness Identification

Original Page: http://www.innocenceproject.org/Content/3106.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

The Innocence Project - As More States Weigh Improving Lineups, New Innocence Project Report Shows Extent of the Problem and Effectiveness of Reform

As More States Weigh Improving Lineups, New Innocence Project Report Shows Extent of the Problem and Effectiveness of Reform

innocenceproject.org | Jun 15th 2011

75% of wrongful convictions overturned with DNA testing involve eyewitness misidentification; 17 states in last two years have considered reforms

(New York, NY; July 16, 2009) —A report released today by the Innocence Project shows that while eyewitness identification is among the most prevalent and persuasive evidence used in courtrooms, it is not error-proof and is the leading cause of wrongful convictions that have been overturned with DNA testing.

The report comes as 17 states have considered legislation in the last two years to improve lineups. So far, nine states have taken action to prevent eyewitness misidentification, and the Innocence Project said it will focus on implementing reforms over the next year in 10 states, including New York, Texas, Kentucky, New Mexico, Ohio, Michigan and Rhode Island.

Titled “Reevaluating Lineups: Why Witnesses Make Mistakes and How to Reduce the Chance of a Misidentification,” the report lays out the overview of eyewitness misidentification and problems with traditional eyewitness identification procedures. It explains how to minimize the possibility of misidentification and outlines criminal justice reforms that are proven to reduce inaccurate eyewitness identifications.

“There is a growing understanding nationwide that eyewitness identification is often unreliable, and that simple reforms can reduce misidentifications,” said Stephen Saloom, Policy Director at the Innocence Project, which is affiliated with Cardozo School of Law. “This reports shows the extent of the problem, explains why eyewitnesses sometimes identify the wrong person, and outlines how police practices can be improved to result in more reliable evidence. The consequences of not improving lineups are stark: Investigations get derailed early in the process, and true perpetrators of crime remain free to commit additional violent crimes while innocent people are incarcerated.”

A series of reforms that are proven to reduce misidentifications have been developed by leading social scientists, endorsed by criminal justice organizations and successfully implemented in the field. The reforms include: double-blind presentation (photos or lineup members are presented by an administrator who does not know who the suspect is); lineup composition (the non-suspects included in a lineup resemble the eyewitness’s description of the perpetrator and the suspect should not stand out); witness instructions (the person viewing a lineup is told that the perpetrator may not be in the lineup but the investigation will continue regardless); confidence statements (at the time of identification, the eyewitness provides a statement in her own words indicating a level of confidence in the identification); recording of identification procedures (the identification is videotaped entirely); and sequential presentation (lineup members are presented one-by-one instead of side-by-side; because research is ongoing on this reform, the Innocence Project recommends it as an optional addition to the reforms above).

“Several states, cities and towns have already adopted the reforms and found them to be cost-effective and easily implemented,” the report found. “The benefits are extensive and include reinforcing the integrity of reliable identifications as well as reducing the rate of misidentifications.”

States that have taken steps to improve eyewitness identification through legislation include: New Jersey and North Carolina, which mandate blind-sequential policies; Georgia, which has statewide training; West Virginia, which mandates the use of certain reforms proven to increase the accuracy of eyewitness identifications; Vermont, which established a task force to explore and recommend enhanced eyewitness identification protocols; Maryland and Wisconsin, which require all jurisdictions statewide to enact written policies regarding the use of eyewitness identification procedures; Connecticut, which directed its Advisory Commission on Wrongful Convictions to monitor and evaluate implementation of double-blind administration of lineup procedures; and Virginia, where the Crime Commission studied misidentification cases and recommended improvements to eyewitness identification procedures including training and sequential presentation.

Disappointingly, there are no consistent standards for identification procedures from state to state or even from one police department to the next. Many police departments don’t even have a written policy, which often leads to inconsistency within a single station.

“We know from social science research and real-world experience that these reforms work. We’re looking forward to working with police and policymakers in several key states over the next year to help them understand the need to improve lineups and the benefits of these reforms,” Saloom said. “Victims are denied justice, innocent defendants are sent to prison and the public’s safety is at risk when real perpetrators go undetected.”

The findings in “Reevaluating Lineups: Why Witnesses Make Mistakes and How to Reduce the Chance of a Misidentification,” released today, include:

• 240 people, serving an average of 12 years in prison, have been exonerated through DNA testing in the United States, and 75% of those wrongful convictions (179 individual cases as of this report) involved eyewitness misidentification.

• In 38% of the misidentification cases, multiple eyewitnesses misidentified the same innocent person.

• Over 250 witnesses misidentified innocent suspects.

• 53% percent of the misidentification cases (among those where race is known) involved cross-racial misidentifications.

• In 50% of the misidentifications cases, eyewitness testimony was the central evidence used against the defendant (without other corroborating evidence like confessions, forensic science or informant testimony).

• In 36% of the misidentification cases, the real perpetrator was identified through DNA evidence.

• In at least 48% of the misidentification cases where a real perpetrator was later identified though DNA testing, that perpetrator went on to commit (and was convicted of) additional violent crimes (rape, murder, attempted murder, etc.) after an innocent person was serving time in prison for his previous crime.

Read the executive summary here.

Download the full report here. (PDF)

Original Page: http://www.innocenceproject.org/Content/2079.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Eyewitness Identification: "Reevaluating Lineups: Why Witnesses Make Mistakes and How to Reduce the Chance of a Misidentification

Reevaluating Lineups: Why Witnesses Make Mistakes and How to Reduce the Chance of a Misidentification

innocenceproject.org

Executive Summary

Eyewitness identification is among the most prevalent and persuasive evidence used in courtrooms. Eyewitness testimony that directly implicates the defendant is compelling evidence in any trial, but it is not error-proof. Jurors may not realize that confident, trustworthy witnesses can be mistaken. A single witness’s identification can be enough to obtain a conviction.

Eyewitness identification also plays a key role in shaping investigations. In the immediate aftermath of a crime, an erroneous identification can derail police investigations by putting focus on an innocent person while the actual perpetrator is still on the streets. Once a witness identifies the suspect to police, whether or not that person actually committed the crime, investigators may stop looking for other suspects.

Over 175 people have been wrongfully convicted based, in part, on eyewitness misidentification and later proven innocent through DNA testing. The total number of wrongful convictions involving eyewitness misidentifications exceeds this figure, given the widespread use of eyewitness testimony and the limited number of cases in which DNA evidence is available for post-conviction testing.

Experts estimate that physical evidence that can be subjected to DNA testing exists in just 5-10% of all criminal cases.1 Even among that small fraction of cases, many will never have the benefit of DNA testing because the evidence has been lost or destroyed. DNA exonerations don’t just show a piece of the problem – they are a microcosm of the criminal justice system.

Decades of empirical, peer-reviewed social science research reaffirms what DNA exonerations have proven to be true: human memory is fallible. Memory is not fixed, it can be influenced and altered. After the crime and throughout the criminal investigation, the witness attempts to piece together what happened. His memory is evidence and must be handled as carefully as the crime scene itself to avoid forever altering it.

The Innocence Project identifies the common causes of wrongful convictions across DNA exoneration cases and has found eyewitness misidentification to be the leading cause.

Innocence Project research shows:

• Over 230 people, serving an average of 12 years in prison, have been exonerated through DNA testing in the United States, and 75% of those wrongful convictions (179 individual cases as of this writing) involved eyewitness misidentification.

• In 38% of the misidentification cases, multiple eyewitnesses misidentified the same innocent person.

• Over 250 witnesses misidentified innocent suspects.

• Fifty-three percent of the misidentification cases, where race is known, involved crossracial misidentifications.

• In 50% of the misidentification cases, eyewitness testimony was the central evidence used against the defendant (without other corroborating evidence like confessions, forensic science or informant testimony).

• In 36% of the misidentification cases, the real perpetrator was identified through DNA evidence.

• In at least 48% of the misidentification cases where a real perpetrator was later identified through DNA testing, that perpetrator went on to commit (and was convicted of) additional violent crimes (rape, murder, attempted murder, etc.), after an innocent person was serving time in prison for his previous crime.

Many of these misidentifications could have been prevented, many wrongful convictions averted, and many additional crimes avoided if police had used more reliable lineup procedures. In recognition of this, procedural reforms have been developed by leading eyewitness psychologists and successfully implemented by criminal justice professionals. These reforms have a strong scientific foundation and have been embraced by leading national justice organizations including the National Institute of Justice and the American Bar Association.They include:

• Double-blind presentation: photos or lineup members should be presented by an administrator who does not know who the suspect is.

• Lineup composition: “Fillers” (the non-suspects included in a lineup) should resemble the eyewitness’s description of the perpetrator and the suspect should not stand out. Also, a lineup should not contain more than one suspect.

• Witness instructions: The person viewing a lineup should be told that the perpetrator may not be in the lineup and that the investigation will continue regardless of whether an identification is made.

• Confidence statements: At the time of the identification, the eyewitness should provide a statement in her own words indicating her level of confidence in the identification.

• Recording: Identification procedures should be videotaped.

• Sequential presentation (optional): Lineup members are presented one-by-one (by a “blind” administrator) instead of side by side.

Several states, cities and towns have already adopted the reforms and found them to be cost-effective and easily implemented. The benefits are extensive and include reinforcing the integrity of reliable identifications as well as reducing the rate of misidentifications. Despite positive feedback from police departments where the reforms have been implemented and mounting evidence of the reforms’ effectiveness, the majority of jurisdictions have maintained the status quo. There are no consistent standards for identification procedures from state to state or even from one police department to the next. In fact, many police departments do not have written procedures for conducting identifications, so there is often inconsistency even within individual police departments. Now is the time for change. Misidentifications benefit no one: not the innocent defendants who face incarceration for crimes they didn’t commit, not the victims who are denied justice, not the police officers working to catch the real perpetrator, and not the public whose safety is jeopardized when real perpetrators remain at large.

This report provides a historical overview of how eyewitness misidentification came to be recognized as a leading cause of wrongful conviction, it examines the shortcomings of traditional eyewitness identification procedures, and it describes how simple improvements to procedures can alleviate the problem, with examples of cities and states across the country that have successfully implemented procedural reforms.

Download the full report here. (PDF)

Original Page: http://www.innocenceproject.org/Content/Reevaluating_Lineups_Why_Witnesses_Make_Mistakes_and_How_to_Reduce_the_Chance_of_a_Misidentification.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Confidential Informants, Questionable Convictions (7/6/2011)

Confidential Informants, Questionable Convictions (7/6/2011)

innocenceproject.org | Jul 6th 2011 5:54 PM

Confidential Informants, Questionable Convictions

An editorial in yesterday’s Newark Star-Ledger points to the murky role played by confidential informants in countless criminal cases across the state and the country. New Jersey has few rules governing the use of confidential informants in police investigations or in court. And while informants can help investigations, secret incentives like reduced sentences – or even cash – can lead to false testimony. At least 15 percent of the 272 wrongful convictions overturned through DNA testing to date involved informant testimony at the trial level.

A report released last month by the New Jersey ACLU calls on the New Jersey Attorney General to “issue specific, detailed and mandatory policies” governing use of informants by all law enforcement agencies in the state.
From the Star-Ledger editorial:

Each year, thousands of offenders provide all levels of law enforcement with information in order to save themselves. Sometimes, the information is reliable. Often, it’s not.

And while the ACLU report details how police can abuse informants, who often create fiction to get the deal they want or just to get cops off their backs, the real victims are the courts. Sometimes, innocent people get railroaded, and bad guys, because of shady witnesses, go free.


Read the full editorial.

Original Page: http://www.innocenceproject.org/Content/Confidential_Informants_Questionable_Convictions.php

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Bit of a phone phreak

Accused Pentagon Hacker's Online Life

by Kevin Poulse, theregister.co.uk
November 19th 2002 9:57 PM

Usenet posts show Gary McKinnon was a bit of a phone phreak, knew where to buy lock picks, and had an early interest in defense computers. A former employer says he was bored at work.

The British man accused of the most ambitious hack attacks against Defense Department computers in years was also a fine network administrator, according to a former co-worker.

A manager at the London-based telecom equipment seller Corporate Business Technology Ltd. recalls Gary McKinnon as a friendly -- if unremarkable -- presence at the company, where he provided IT support for an office of about 50 people. "He was personable, relatively happy around the office," says the manager, who declined to give his name. "You wouldn't have realized that he could do what he did."

McKinnon, now 36, worked for CBT for approximately ten months ending in late 1999, the company says. He left on good terms. "As I remember it, he decided to leave because he was bored working here," says the manager. "But at the time that he left, he didn't have any place to go to."

On Tuesday (Nov 12, 2002), U.S. officials in Virginia charged McKinnon with seven felony counts of computer fraud for allegedly penetrating 92 different systems belonging to the Army, Navy, Air Force, the Pentagon, and NASA, as well as six computers owned by private companies and organizations, in a year-long hacking spree that ended last March.

A related indictment unsealed the same day in New Jersey charges the Londoner with a September, 2001 attack against U.S. Navy systems at the Earle Naval Weapons Station that allegedly resulted in the network of 300 computers being shut down for a week.

The private computers listed in the Virginia indictment are mostly at traditional easy targets, like public libraries and universities, and may have been used as cut-outs to cover the hacker's tracks. Gregg Cannon, IT director at victim-company Tobin International in Texas, says federal investigators contacted and subpoenaed his company early this year after a test system outside the company firewall was compromised and used to attack government computers. "All the government would tell us is that it was overseas," says Cannon. "He didn't do any damage."

Diverse Interests

The U.S. is seeking McKinnon's extradition, which McKinnon is fighting in the U.K.

McKinnon's former co-worker said Wednesday that there was nothing about the network admin to hint at a future as a civilian infowarrior, "assuming it was him that did it."

A trail of Usenet messages posted by McKinnon in the late 1990's to public Internet newsgroups suggests McKinnon had an early interest in esoteric technological subjects.

Postings in 1997 to the U.K. phone hacking newsgroup alt.ph.uk show McKinnon, or someone with the same name, offering advice on purchasing lock picks in the U.K., tips on encrypting files, and hints on changing the electronic serial numbers in cellular telephones.

A flurry of less subversive posts in December, 1999 from an email address at Corporate Business Technologies have McKinnon advising colleagues in Windows-administration newsgroups on a variety of topics -- most of them security related.

One post from that period hints at an earlier start to McKinnon's interest in U.S. defense systems than the government has acknowledged. The message finds McKinnon advising someone on what brand of intrusion detection system to buy. He recommends ISS's RealSecure, because "The US Navy use[s] that and only that ..."

"[B]ut then," McKinnon adds without explanation, "they really need it."

© 2002 Security Focus. All rights reserved.

Original Page: http://www.theregister.co.uk/2002/11/19/accused_pentagon_hackers_online_life/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Thursday, July 7, 2011

Conversation "The Freak Show" LoL

Heather (@Lebonbon22)
7/7/11 6:50 PM
@ElyssaD @RockTique Is that the freak show?
Elyssa Durant (@ElyssaD)
7/7/11 6:50 PM
@RockTique I knew it wouldn't be long. Give him a swift where it counts.
Meredith Allison (@RockTique)
7/7/11 6:41 PM
@JDenigma @ElyssaD Oooh, so we meet!
Josh (@JDenigma)
7/7/11 4:35 PM
@ElyssaD lol & you also make up crap about me...why don't u tell her the whole story? ;-) u have me blocked yet troll my TL too @RockTique
Elyssa Durant (@ElyssaD)
7/7/11 12:56 PM
@RockTique @lebonbon22 I refollowed but if some troll Jdenigma bugs you just block him. He's relentless and pathetic. Sorry.
Meredith Allison (@RockTique)
7/7/11 12:52 PM
@Lebonbon22 Yep! I meant to ask if you too but I guess not. I tweeted her when I noticed & no reply. @ElyssaD ..WHY?! Something I said? Lol
Heather (@Lebonbon22)
7/7/11 9:16 AM
@RockTique she deleted u? Really?
Meredith Allison (@RockTique)
7/7/11 8:01 AM
So late!! (@ Starbucks) http://4sq.com/qynAUt

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Conversation

freethetweet (@freethetweet)
7/7/11 1:55 AM
@JDenigma no you've just rustled the right feather@silentsoeur @_cromcruach @snkscoyote @elyssad @mantis8585 @_deadreckoning_ @awesomejon37
Josh (@JDenigma)
7/7/11 1:52 AM
@silentsoeur @freethetweet @_cromcruach @snkscoyote @elyssad @mantis8585 @_deadreckoning_ @awesomejon37 I've created a storm here lol
liz a (@silentsoeur)
7/7/11 1:50 AM
@JDenigma @freethetweet @_cromcruach @snkscoyote @elyssad @mantis8585 @_deadreckoning_ holy shit I'm lost here and I read all the tweets :P
Josh (@JDenigma)
7/7/11 1:48 AM
@freethetweet @_CromCruach @silentsoeur @snkscoyote @elyssad @mantis8585 @_deadreckoning_ I never said you are lol
freethetweet (@freethetweet)
7/7/11 1:48 AM
@freethetweet @JDenigma @_CromCruach @silentsoeur @snkscoyote @elyssad if you think I am "elyssa", you are all fucking sorts of SAD.
freethetweet (@freethetweet)
7/7/11 1:46 AM
@JDenigma @_CromCruach @silentsoeur @snkscoyote @elyssad why keep contacting ppl u have bocked and hated upon? Makes no sense. (elyssa)
Josh (@JDenigma)
7/7/11 1:42 AM
@_CromCruach @freethetweet @silentsoeur @snkscoyote lol S.O.S. to @elyssad Hello Elyssa "cease and desist"
Donnchadh (@_CromCruach)
7/7/11 1:42 AM
@freethetweet @silentsoeur @jdenigma @snkscoyote informants? Me? Lmao you're drunker than all of us bahahahahahaha
freethetweet (@freethetweet)
7/7/11 1:38 AM
@freethetweet btw crom, u suck, they should "hire" informants better than you.@_CromCruach @silentsoeur @jdenigma @snkscoyote
freethetweet (@freethetweet)
7/7/11 1:35 AM
@_CromCruach just study the play book. @silentsoeur @jdenigma @snkscoyote @jessidarko @awesomejon37 @mantis8585
Donnchadh (@_CromCruach)
7/7/11 1:32 AM
@silentsoeur @freethetweet @jdenigma @snkscoyote @jessidarko @awesomejon37 @mantis8585 fall? Weebles wobble but never fall down!!!
liz a (@silentsoeur)
7/7/11 1:26 AM
@freethetweet @jdenigma @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585 we all fall down in the end then :(
freethetweet (@freethetweet)
7/7/11 1:25 AM
@JDenigma @silentsoeur @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585 we can play ring round the rosie till cows come home.
Josh (@JDenigma)
7/7/11 1:20 AM
@silentsoeur @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585 It's in good fun here snks ;-)
liz a (@silentsoeur)
7/7/11 1:19 AM
@JDenigma not workin but still amusing ;P @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585
Josh (@JDenigma)
7/7/11 1:17 AM
@silentsoeur Oh,you're baiting snks now I see ;-) @snkscoyote @_cromcruach @jessidarko @awesomejon37 @mantis8585
liz a (@silentsoeur)
7/7/11 1:16 AM
@jdenigma @snkscoyote ur raped & tortured &then proven innocent but its ok I got a badge @_cromcruach @jessidarko @awesomejon37 @mantis8585

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Monday, July 4, 2011

@JosephKBlack GET ON THIS ACCOUNT nyan-my-ass

Joe Black ✔ Genuine (@JosephKBlack)
7/3/11 9:28 PM
I HAVE NYANED FOR 9554.0 SECONDS! http://t.co/G1pdxGl via @nyannyancat

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

@JosephKBlack, 7/3/11 10:07 PM re: CIA.gov

Joe Black ✔ Genuine (@JosephKBlack)
7/3/11 10:07 PM
@xSSLZx You cant be this dumb? Im doing my job you fuck stick. cia.gov received my resume in '08 and brought me on as an Agency asset in '10

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

And the CIA got hacked in 11. So did Blackandbergsecurity.us 

Joe claims to be with Lulzsec. 

Get me the fuck out of here! NOW!

Posted via email from Whistleblower

@JosephKBlack, 7/4/11 1:36 PM

Joe Black ✔ Genuine (@JosephKBlack)
7/4/11 1:36 PM
Thank you for the Mentions, @not2fear @JosephDeSanko @c4i @ElyssaD @jadedsecurity @Abhaxas @Donotgiveintoev You're all ROCKSTARS! Much love

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

What the what???? 

Posted via email from Whistleblower

Conversation

✔mate (@xSSLZx)
7/4/11 5:50 AM
@itinsecurity @attritionorg @caks2257 @ElyssaD regardless @JosephKBlack is fucked http://t.co/ZUOfsyC http://t.co/HARXy7X
Anders Reed-Mohn (@itinsecurity)
7/4/11 3:26 AM
RT @attritionorg: and it seems @caks2257 is Greg Evans' sockpuppet of the day #LIGATT < And @ElyssaD is @JosephKBlack 's perhaps?

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Friday, July 1, 2011

Conversation #Exploitation

Tom (@d0rkh0rs3)
7/1/11 7:04 PM
@jadedsecurity @grostad @isdpodcast @ElyssaD Sounds like winning to me. Wait, #winning is so 2 months ago.
Jaded Security (@jadedsecurity)
7/1/11 7:00 PM
@d0rkh0rs3 @grostad @isdpodcast :) The @ElyssaD shirts will be here next week...
Tom (@d0rkh0rs3)
7/1/11 7:00 PM
@jadedsecurity @grostad @isdpodcast Awesome. Where's my shirt? ;)
Jaded Security (@jadedsecurity)
7/1/11 6:59 PM
@d0rkh0rs3 @grostad @isdpodcast LOL... i saw it.. I'm converting the 2 episodes so far..
Tom (@d0rkh0rs3)
7/1/11 6:58 PM
Hey @grostad, since you're always pimping the iTunes rating for @isdpodcast you should tell @jadedsecurity how to get on iTunes

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Saturday, June 25, 2011

UK Cyber Security Challenge renewal promises better prizes • The Register

UK Cyber Security Challenge renewal promises better prizes

by John Leyden, theregister.co.uk
April 20th 2011 11:14 AM

The UK's Cyber Security Challenge is promising a renewal of the competition, with more competitions on a broader range of topics and better prizes.

The Challenge, successfully run last year as a way of promoting interest in information security as a career and unearthing hidden pools of talent, is once again backed by the UK government.

Last year's exercises have involved one-off code-breaking puzzles as well as a more structured programme of network security exercises culminating in a grand final, which was won by Dan Summers, a postman from Wakefield.

This year's event will include exercises involving penetration testing, malware forensics, and network defence among a total of eight competitions, each testing a different cyber-security skill.

Competitions will run more frequently throughout the year and some will offer multiple opportunities to play, allowing more people the chance to participate. Winners in each of the eight categories will compete in a semi-final before the most accomplished performers face off in a masterclass grand final, due to be held in HP Labs, near Bristol.

The Government’s Office of Cyber Security and Information Assurance is giving £180k in sponsorship to help the scheme along. Organisations providing logistical and financial support for the scheme include PWC, Sophos, the SANS Institute, HP Labs, Cassidian and QinetiQ, the US Department of Defense’s Cyber Crime Center is also getting on board by running and promoting the digital forensics strand of the competition.

Organisers of the scheme are seeking further sponsors ahead of the opening of competition to schools and members of the general public in May.

More details on the renewal can be found on the official Cybersecurity challenge website here. ®

Original Page: http://www.theregister.co.uk/2011/04/20/cyber_security_challenge_reloaded/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

No waiting list for admin passwords

Lulz warns NHS of sick security

by John Oates, theregister.co.uk
June 10th 2011 8:45 AM

LulzSec, the security collective which claimed credit for hacking Sony, has taken to Twitter to warn the NHS that it stumbled across several admin passwords.

The Department of Health claimed the breach was nothing more serious than "a very small number of website administrators". It said no national systems were hit - given the slow progress of creating such national systems this might not be a surprise.

Lulz published an email sent to the NHS with the relevant passwords blacked out.

It said:

We're a somewhat known band of pirate-ninjas that go by LulzSec.

Some time ago, we were traversing the Internets for signs of enemy fleets.

While you aren't considered an enemy - your work is of course brilliant - we did stumble upon several of your admin passwords, which are as follows....

We mean you no harm and only want to help you fix your tech issues. Also, we hope that little girls feasts on the bones of many giving souls. All the best.

Lulz Security

And no, we don't have any idea what "little girls feasts" means either.

At least the breach is not quite as embarrassing as the recent failure by FBI partner Infraguard which was hacked this week.

Original Page: http://www.theregister.co.uk/2011/06/10/lulz_nhs_hack/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

8m health records go walkabout • The Register

8m health records go walkabout

by John Oates, theregister.co.uk
June 15th 2011 9:11 AM

A London health authority has admitted losing a laptop which contains 8.6 million health records.

The machine was lost three weeks ago, but has only just been reported missing to police and the Information Commissioner's Office.

We've asked North Central London health board why it needed to store 8.63 million health records on an unsecure laptop in the first place.

They sent us the following: "NHS North Central London is investigating the loss of a number of laptops. One of the machines was used for analysing health needs requiring access to elements of unnamed patient data. All the laptops were password protected and our policy is to manually delete the data from laptops after the records have been processed. NHS North Central London operates under strict data protection guidance and is taking the matter extremely seriously. We have started an investigation into the issues raised by the loss. We are liaising with the office of the Information Commissioner."

The machine was one of 20 lost from a storeroom at London Health Programmes - a research body based at NHS North Central London, reports. Eight of the 20 have been recovered, but the authority is still looking for the other 12.

The records contain no names but do include other identifying information like age, gender, postcode, medical history, hospital visits, HIV status and mental illnesses.

An ICO spokesperson said: “Any allegation that sensitive personal information has been compromised is concerning and we will now make enquiries to establish the full facts of this alleged data breach.”

A Department of Health spokesman later sent us this statement:

"All NHS organisations are legally required to comply with Data Protection legislation and are expected to take data loss extremely seriously, be open about incidents and about the action taken as a result.

"We have set clear standards for NHS organisations to adhere to on data handling, and have issued guidance that sets out the steps they must take to ensure records are kept secure and confidential.

"Local NHS organisations are responsible for implementing these data handling processes, including which staff need to have access to health records, and for compliance with Information Governance standards." ®

Original Page: http://www.theregister.co.uk/2011/06/15/eight_million_health_records/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

Daily Mail launches McKinnon campaign • The Register

Daily Mail launches McKinnon campaign

by John Leyden, theregister.co.uk
July 3rd 2009 2:17 PM

The Daily Mail has launched a high-profile campaign supporting Gary McKinnon's fight against extradition to the USA.

The red-baiting, Romany-hating paper criticises US authorities for treating a "naive hacker" interested in uncovering evidence of extraterrestrial life on poorly-secured Pentagon systems as a dangerous cyber-saboteur.

The paper also lambasts UK politicians for meekly going along with US demands in a front-page article. An associated online petition to the new Home Secretary, Alan Johnson, calls on him to use his discretion in order to block extradition proceedings against McKinnon, a recently diagnosed sufferer of Asperger's Syndrome.

Such a move would allow for McKinnon to be tried in the UK, avoiding the trauma of a US trial followed by the likelihood of an extended spell behind bars.

The wholehearted support of the influential daily paper is a major fillip to the McKinnon campaign, which has already attracted high-profile supporters including Pink Floyd's David Gilmour, London mayor Boris Johnson and former Beirut hostage Terry Waite.

Lord Carlile, the independent reviewer of anti-terror laws, and Oscar-winning actress Julie Christie have also voiced support for McKinnon's fight against extradition.

McKinnon admits taking advantage of weak password security to root around US military and NASA systems back in 2001 and 2002 but denies claims that he caused $700,000 in damage in the process. He was first arrested and questioned by UK cops in 2002, but it wasn't until 2005 that the US began extradition proceedings.

The long-running campaign against extradition included failed appeals to the House of Lords and the European Court of Human Rights last summer. These legal actions happened before McKinnon was diagnosed with Asperger's Syndrome.

McKinnon's last hope against avoiding extradition rests with two judges who are due to review the decision by UK prosecutors not to prosecute McKinnon in the UK during a hearing scheduled for Tuesday, 14 July. The same two judges - Lord Justice Stanley Burnton and Mr Justice Wilkie - heard arguments that the then Home Secretary Jacqui Smith was wrong to allow McKinnon's extradition to proceed following his diagnosis with a mild form of autism at an earlier hearing.

A decision on the first hearing was "reserved" pending consideration of the other judicial review. ®

Original Page: http://www.theregister.co.uk/2009/07/03/mail_mckinnon_campaign/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower

DEC 'hacker' questions McKinnon political bandwagon • The Register

DEC 'hacker' questions McKinnon political bandwagon

by John Leyden, theregister.co.uk
January 30th 2009 2:19 PM

Boris Johnson's outspoken defence of Gary McKinnon in his extradition fight has been criticised by a former security consultant, who complains he was denied such support when he himself was charged with hacking offences.

Daniel Cuthbert was convicted in October 2005 of breaking the Computer Misuse Act by "hacking" into a tsunami appeal website in December 2004, and fined £400 plus £600 in costs. He was subsequently forced to change career after the prosecution, which was widely seen by his peers as misguided. Cuthbert now wants to know why he wasn't shown any support from politicians of the kind lent to McKinnon by Johnson.

The London mayor wrote a barbed critique of attempts by US authorities to drag McKinnon over to the US to answer for charges of hacking into US military systems, rather than be tried in the UK for his admitted offences, in an opinion piece in The Daily Telegraph on Monday. Johnson argues that treating McKinnon as a "cyberterrorist" rather than a hacker with out-there beliefs is itself lunacy.

McKinnon is far from the first Brit to face high-profile computer charges, but the degree of political support he's received - a motion on his behalf was signed by 80 MPs, to say nothing of the lampooning of extradition proceedings by the London mayor - is unprecedented, and a tribute to the long-running campaign fought by McKinnon's lawyers and supporters.

Cuthbert's woes began when he made a donation through the DEC (Disasters Emergency Committee) site. After failing to get a confirmation email, he became suspicious and carried out two tests to check its security. These actions triggered a warning on the intrusion detection system behind the site, maintained by BT, who reported the matter to police. This ultimately led to Cuthbert's arrest, conviction and inability to continue his career as an IT security consultant.

After a spell in Thailand, Cuthbert is back in the UK and studying for an MA in documentary and photojournalism at the London College of Communication. Cuthbert - who has repeatedly spoken out against the extradition proceedings against McKinnon in the past - ruefully notes that he didn't enjoy the benefit of support from political figures, such as the London mayor.

"Whilst it would be lovely if Boris could talk about my conviction, the chance of that happening is slim," Cuthbert told El Reg.

Cuthbert criticised Johnson's argument that McKinnon ought to be given special consideration because of his motives.

"Gary committed a crime, end of story," Cuthbert said. "The issue has always been where he would be tried for that crime. In all honesty, the fact he was searching for UFOs doesn't make what he did right, he did break into computers and the intent was always to break in to find information. What Boris is saying is that he should be given special consideration, and I don't believe in that at all.

"I personally think he should be tried in the UK. The UK is wrong to bow down to the whims of the US, especially since the extradition treaty between the two countries is hardly fair and equal."

Cuthbert's sense of injustice is supported in a response to Johnson's original piece by Ira Winkler, president of the Internet Security Advisors Group and an ex-NSA officer who's become a cybercrime guru. Winkler argues that McKinnon caused real damage, so arguments that he was only rooting around systems looking for evidence of UFOs are neither here nor there. He goes on to say that Johnson would do better to look into cases of injusice closer to home, such as the Cuthbert case.

Why doesn't Johnson turn to the case of Daniel Cuthbert? In that case prosecuted in London, a real security expert and security community volunteer was prosecuted and convicted for what essentially amounted to typing "cd ..". The Cuthbert case demonstrates absurdity of at least one computer crime prosecution in London. Until Johnson speaks out on Cuthbert, he shouldn't have the gall to waste any time on a person who actually caused significant damage to a government system.

We've dropped the Mayor an email asking what position he might have on the Cuthbert case. We've received an automated reply confirming the safe delivery of this message and saying that, while busy, "the Mayor is committed to responding to all appropriate correspondence and everything is being done to reply to your query as quickly as possible". We await further correspondence with interest.

Meanwhile, a former US prosecutor involved at the start of the McKinnon prosecution has defended the US handling of the case. Scott Christie, an assistant US attorney in New Jersey in 2002 at the time McKinnon was first indicted in the case, criticised Johnson's critique as badly misinformed.

"[McKinnon] has created this cause celebre status in order to appeal to folks who will beat the drum on his behalf and they conveniently ignore the facts of the situation and the entire nature of his conduct," Christie said, Computerworld reports. Christie, who heads the IT group at attorneys McCarter & English LLP, added that Johnson's public support "lends some credence to the individuals who are painting McKinnon as a victim" rather than a criminal hacker. ®

Original Page: http://www.theregister.co.uk/2009/01/30/cuthbert_mckinnon/

Shared from Read It Later

Elyssa Durant, Ed.M. 

United States of America 

Forgive typos! iBLAME iPhone

Posted via email from Whistleblower