The Case of Aaron Swartz

Aaron Swartz was 26 when he hung himself last Friday. He was a co-author of the RSS 1.0 specification at the young age of 14. He was also a cofounder of Reddit, from where he was later fired. Aaron dropped out of Stanford. He created web.py, a Python web framework.

Swartz broke into a network closet at MIT. He placed a computer in the closet to run scripts to download articles from JSTOR, which is a journal storage system. Swartz had downloaded almost 5 million articles. JSTOR did not pursue a case against Swartz.

The Massachusetts attorney picked up the case against Swartz. The trial was to start in the spring. Swartz was pleading not guilty. He was charged with wire and computer fraud under the Computer Fraud and Abuse Act. If found guilty, he could have served up to 35 years in jail. He also may have been liable for $1M in fines.

Swartz initially had access to JSTOR at MIT. Then they detected his massive downloads. At first, his IP address was blocked. He changed his IP address. Then his MAC address was banned. He changed his MAC address. Finally he got another laptop, broke into a network closet at MIT, and jacked into the network to download the files.

McAfee Surveillance

Previously I had heard about John McAfee going on the run from Belize police. That sounded a bit odd. He was allegedly a person of interest in the murder of his neighbor in Belize. This caused McAfee to go into hiding, claiming that the police were trying to silence him.

Recently I read that McAfee launched a surveillance campaign against police and government officials in Belize. He said that he got a bunch of new laptops. Then he installed some keyloggers on all the PCs. Finally he distributed the laptops free of charge to people of importance in Belize.

McAfee also hired a team of people to monitor the rogue laptops. He then allegedly recorded all kinds of wrongdoing from the subjects of his espionage. Perhaps that is why the law is gunning after him in Belize. If that is true, he better hope that they don't extradite him back to Belize. He might not last long in that scenario.

I do love the premise that McAfee used to put the laptops in the hands of high ranking Belize officials. Part of the draw was that the cost was free. The other vector he used was to have some hotties deliver the PCs to the dudes in charge. Smart. Apparently it worked.

Elcomsoft Forensic Disk Decryptor

I recently read an article about a product called Forensic Disk Decryptor from Elcomsoft. This thing can access Bitlocker, PGP, and TrueCrypt volumes. It does this by grabbing the keys required to decrypt the data. There are three main ways the software can grab the key: from RAM, a hibernation file, or through a FireWire attack.

Note that you need to use some other third party tools for some of these attacks. For exampl, you need to use a separate tool to get a RAM memory dump for the program to scan. Also you need some extra software to mount a Firewire attack.

The fun part of this is that once you get the key, this software will mount the encrypted volume as a drive letter in unencrypted format. It will also not modify the encrypted volume it is cracking. This is access without a trail. The software looks like it costs a couple hundred bucks. There has been some discussion about this release. Most of the talk hinges around the fact that they are really just mining the keys. Once you have those keys, accessing the encrypted data is really not much of a hack.

Bureau of Prisons

Recently I went to the bookstore to do a little Christmas shopping. In the corner of the magazine section I spotted a stack of 2600 magazines. Ahh I remember reading those diligently in the past. They have such a good feel to them. I bought a copy and am half way through the thing. I need to actively pace myself so I don't read it cover to cover in one sitting.

So far the most interesting article was on the Federal Bureau of Prisons. The author describes the hoops inmates need to jump through to get computer access. They need to pay for it. Pay for the time. Pay for each page printed. You cannot email anyone directly in prison. You must go through a proxy where your correspondence is monitored and approved on an email by email basis.

Of course the author described some of the details of the systems used to provide net access to prisoners. LOL. Looks like he found a few holes to avoid payment and/or censoring. He had better be careful. I think he gets released soon. No need to further delay his release for something small such as hacking the printer.

This perspective helps me realize how lucky we have it. I often grumble about having to change the printer paper or toner. Or I need to occasionally reboot the wireless router to get back on the Internet. If you are in prison, you got to do a lot to be able to get even restricted access to the net.

Bribing Cops in Central America

This weekend I read an insightful blog post by John McAffee. His post is a guide to travel. John lives in Belize, a country in Central America that borders on the Carribean. This is the same John McAffee that founded McAffee Associates, the antivirus company. Recently McAffee has been in the news as a person of interest in a murder. But let's get back to the travel guide.

Appanrently it is business as usual for the police to shake down travelers in Central America. And the use of bribes to get past these cops is also common practice. John has a bunch of tips to ensure you stay alive and stay out jail. One key point he makes is for you to stay in your vehicle at all times. That applies even if a cop tells you to get out of the vehicle.

Another theme John reiterates is to stay calm, smile, and negotiate. Cops may try and distract you to plant some drugs in your vehicle. Even that should not phase you. One somewhat radical recommendation from John is to smile, wave, and slowly drive away from the cops. Strangely enough, he says this works a lot of the time.

John calls the bribes "documentation". That is, the cops ask you for documentation. They are actually using that as a code for a small bribe so you can be on your way. I found it hilarious that John often uses some technical manual with a $20 bill stuffed in it as his official travel papers. He says most of these cops can't even read. But they know and appreciate the greenbacks.

You should go to John's blog and reading all the details and scenarios for yourself. This may come in handy if you find yourself on travel in a third world nation.

Hiding Email Transmissions

I just learned of an interesting way to send and receive emails with someone that makes the transmission almost impossible to detect. What you do is share the username and password to a Gmail account. Then you compose an email, but do not send it. That keeps the email in your drafts folder. The recipient then just logs in and checks out the latest draft message. They can then either edit that draft, or delete it and start a new draft. Sneaky huh?

I found out about this hack because General Petraeus of the US military used this technique to communicate with his mistriss. Sneaky devil. Terrorists have used this technique as well. Your email client never actually sends the email over the wire via email protocol. The message just sits on some server. The method is not foolproof. They figured out Petraeus' antics while investigating a crime. He was outed.

Rot-13 Job Posting

Today I spotted an apparent job posting over on Reddit. At first I thought the posting was written in a another language. Upon closer inspection, I figured they were just doing some encryption on the posting. The giveaway was the job title "Fravbe Fbsgjner Ratvarre". They put "Senior Software Engineer" in parentheses next to that job title.

The number of character in each word lined up. Then I saw that the letters E and then R were mapping to the same letters in the encrypted version. Wait. E went to R and R went to E. By golly, this is ROT-13 encryption, a very simple cipher.

The company is looking for what looks to be a junior developer (despite the title of senior software developer). They also want a PHP/Java/.NET hacker. That does not sound like me. Plus the salary is too low. However I found their ad pretty cool. Other Redditors were not as amused as me with the job posting encryption.