Showing posts with label doxing. Show all posts
Showing posts with label doxing. Show all posts

Monday, August 15, 2016

Guccifer 2.0 Uses Doxing in a Curious Call for Curation

Guccifer 2.0 leaked a series of documents from the Democratic Congressional Campaign Committee (DCCC) on Friday, August 12, 2016.

Since the hacker's blog entry for the 12th was later censored by WordPress, the hyperlink above allows readers to view the original post via the Internet Archive Wayback Machine.

Of all the posts from Guccifer 2.0, this one is likely to seem the most schizophrenic to readers because it couples a callous exposure of private information (including unlisted phone numbers) with a respectable plea to journalists for help with curation.  

In his preamble to the hacked data, Guccifer 2.0 wantonly singles out a particular DCCC worker (Nirali Amin) as the source of various passwords that enabled him to access much of the leaked data.

It's certainly a failure on the institutional level for the DCCC to have kept "the user name and password the same" in so many cases, as Amin indicates in one email--but I'm not sure that many people would blame Amin herself for the oversight. And since Amin's specialization appears to be accounting (rather than cybersecurity), most people will be reluctant to fault her for responding by email to various emailed requests for passwords. (Should she have known better? We all know better on some level, but those of us who work at computer screens all day also know how customary it is to respond to requests for information without wondering who might be spying on our correspondence.)

Beyond singling Amin out for blame, however, the Guccifer 2.0 blog post goes on to provide readers with private phone numbers and unlisted email addresses for many Democrats serving in (or campaigning for) the House of Representatives.

Representative Nancy Pelosi, for example, complained of receiving "obscene and sick" messages on her private number after the blog post appeared. (Incidentally, that's about as close as any Democrats have come to confirming the authenticity of any documents leaked by Guccifer 2.0.)

In an article for Newsweek, Nicholas Loffredo explained why ordinary Americans (and not just those whose information was compromised) might question the integrity of the Guccifer 2.0 project:
[I]t's difficult to identify what public interest is served by sharing cellphone numbers and contact lists from within the DCCC, as Guccifer 2.0 did, or what truth is being uncovered by the release of a program from a political fundraiser. Despite Guccifer 2.0's gleeful tone, Friday's release is a minor footnote to the hack of the DNC, which showed committee officials arguably conspiring against former Democratic candidate Bernie Sanders and which lead to the resignation of DNC chair Debbie Wasserman Schultz
On the one hand, our political representatives are so difficult for ordinary citizens to contact that there is something to be said for releasing their private contact information. But on the other hand, they are still private citizens (at least part of the time), and those of us who seek to protect the Fourth Amendment should respect their right to privacy as much as anyone else's.

And this is precisely what makes the blog post from the 12th so tricky: Clearly Guccifer 2.0 is concerned, on some level, with releasing information in a responsible manner. After sharing lots of personal information and passwords, he ends his blog post with a curious request for assistance from journalists:
Dear journalists, you may send me a DM if you’re interested in exclusive materials from the DCCC, which I have plenty of.
That's a strange move for a completely reckless hacker to make. If bringing information to light is all Guccifer 2.0 cares about, then why does he need to bother with journalistic middlemen? Why didn't he just post all the hacked documents directly to his WordPress site?

In other words, why should a hacker who doesn't mind doxing Democratic Congresspeople suddenly show scruples about exposing their internal documentation willy-nilly? 

Depending on what one assumes about the identity of Guccifer 2.0, there are lots of different ways to answer that question. But if we assume for the moment that the hacker is who he says he is (a lone cyber warrior attempting to expose the failure of democracy in the U.S. to the entire world), then his decision is a predictable result of anxiety over document curation.

He seeks to expose all of the publicly sensitive information that warrants exposure, but he doesn't want to expose it without professional guidance. Unfortunately, professionals won't give him guidance until they realize that he should be taken seriously--so releasing the privately sensitive information must seem (from this perspective at least) like an efficient way of demonstrating the validity of the hack.

Concerns about how Julian Assange would curate information leaked to him by Chelsea Manning led to persistent problems in his working relationship with The New York Times and Der Spiegel back when journalistic hacktivism was first establishing itself as an important 21st-century phenomenon.

Edward Snowden's asylum in Russia is indisputably a product of his relationship with Assange and WikiLeaks, but many people forget that Snowden reached out to Laura Poitras and Glenn Greenwald--not Assange--for help in disseminating his information, in part because of his concerns about how his sensitive materials would be curated.

The tension between Greenwald's journalistic approach to curation and Assange's increasingly strident commitment to exposing pristine documents is perhaps best illustrated by this tweet from Snowden:

I don't believe Guccifer 2.0 is who he says he is, but if he is, then it makes sense for him to be somewhat bewildered by the same questions that led to disagreements between luminaries such as Snowden and Assange.

Guccifer 2.0 does not appear to have broken any laws by publishing the contact information in the DCCC leaks. According to Thomas Fox-Brewster of Forbes, the hacker's entry from the 12th was censored by WordPress because it violated the website's "policy on sharing private information"--not because of a specific federal statute that forbids the sharing of such data.

Fox-Brewster also reports that the Guccifer 2.0 Twitter account was temporarily suspended, but it's not clear what justification Twitter used for the suspension. In any case, the account has been restored as of this writing, and the hacker used it to promote a new batch of leaked documents made available today (August 15th):
Those documents have not been censored by WordPress, and they don't seem to warrant censorship.

Complex questions about curation and censorship are too difficult to be resolved in a single blog post, but if we assume that there is only one bad actor in this scenario (the Democratic Party as an institution), then the seemingly schizophrenic behavior of Guccifer 2.0, Twitter, and WordPress is easy to explain as an attempt to process confusion and anxiety about how information should be regulated when the government that was supposed to be in charge of regulating it can no longer be trusted to do its job.


Friday, June 17, 2016

Call Tony Podesta at (202) 393-1010 and Tell Him to Make His Brother Stop Talking about UFOs

In the second release of documents allegedly filched from the DNC, Guccifer 2.0 includes lists of various DNC donors along with some personal details.

Before plunging into the leaked documents, Guccifer 2.0 calls out Debbie Wasserman-Schultz for claiming that "no financial information or secret documents were stolen."

The hacker challenges this claim from Wasserman-Schultz by providing screenshots of Excel spreadsheets that contain "donors lists and their detailed personal information including email addresses and private cell phone numbers."

The screenshots certainly look authentic to my eye (though my eye isn't especially well-trained in detecting spreadsheet chicanery).

But I'm not sure the doxing is as thorough as Guccifer 2.0 suggests. The first entry in the first screenshot lists Ellen Tauscher as a donor whose phone number is (202) 234-4671. One way to check on whether that really is Tauscher's number is to throw it into Google. If you do so, you'll find that it comes up (along with Tauscher's name and address) in a whitepages entry.

The third screenshot for this new post by Guccifer 2.0 includes a highlighted entry for Tony Podesta (brother of the infamous John, who cannot stop yammering about the potential declassification of Area 51 files under a Hillary Clinton presidency). I googled the phone number associated with Tony and found it listed on the contact page of the Podesta Group's website (under the "Anything" category). When I googled the two email addresses, I found the first (tpodesta@gmail.com) plastered all over teh interwebz. The second email address listed (tpodesta@podesta.com) appears to be a predictable variation on podesta@podesta.com (which is listed on the bio page that the Podesta Group dedicates to Tony).

I haven't checked any other data "exposed" by these spreadsheets. Maybe some of it will turn out to be far more "secret" than the two entries I randomly decided to examine. (Random is the wrong word. I picked the Tauscher entry because it came first and the Podesta entry because it was highlighted and because I hoped it really would include Tony Podesta's private cell phone number so that I could tell him to punch his brother in the nose the next time he diverts attention from Clinton's message-less campaign by invoking UFOs).

So far, I'm not blown away by the secret info I've encountered, and I want to share one comment from a reader (Tyrone Russ) of the hacker's blog:
Holding back +1’ing anything like this until it’s confirmed. The Trump report appears to be just a dump of media reports about the Teflon Donald, with no authorship/masthead noting who created the report.
The spreadsheets? Again, no way to verify who created them. They’re way too generic to be any kind of smoking gun without corroborating metadata.
Not a Shill-bot, just being careful – the Kool-Aid can be strong, but can also be subtle.
EDIT: Going through all the doc’s linked, they all have the concerns I stated. No confirmation, no email headers, no metadata. It’s smelling a little fishy. Just because you want something to be true, doesn’t necessarily make it true.
Like Russ, I just want my fellow Sanders supporters to take a few deep breaths before they go hog wild with this Guccufer 2.0 stuff. Yes, it confirms a lot of what we already know about collusion between Clinton and the DNC. But the problem is that if we make too big a deal out of that supposed confirmation and the info turns out to be doctored or in any way inauthentic, the Hillaryans will simply point to the Guccifer 2.0 story as proof that there was never any collusion.

Let's not go overboard.