Stories
Slash Boxes
Comments

News for nerds, stuff that matters

Slashdot Log In

Log In

Create Account  |  Retrieve Password

Swede Hacks Embassy Account Information From Around the World

Posted by Zonk on Fri Aug 31, 2007 09:33 AM
from the around-the-world-in-an-address-book dept.
paulraps writes "A Swedish IT consultant has caused a stir in diplomatic circles after publishing a list of secret log-in details belonging to 100 embassies, public authorities and political parties around the world. Dan Egerstad said he wasn't trying to earn money, gain publicity or get a name for himself in hacking circles. Instead he claimed that publishing the list was easier than contacting the organizations individually — and that if he had handed it to the Swedish authorities then that would have been spying."
+ -
story

Related Stories

[+] Tor Used To Collect Embassy Email Passwords 99 comments
Several readers wrote in to inform us that Swedish security researcher Dan Egerstad has revealed how he collected 100 passwords from embassies and governments worldwide, without hacking into anything: he sniffed Tor exit routers. Both Ars and heise have writeups on Egerstad's blog post, but neither adds much to the original. It's not news that unencrypted traffic exits the Tor network unencrypted, but Egerstad correctly perceived, and called attention to, the lack of appreciation for this fact in organizations worldwide.
This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • by Paperghost (942699) on Friday August 31 2007, @09:35AM (#20424467)
    "Dan Egerstad said he wasn't trying to earn money, gain publicity or get a name for himself in hacking circles." ....whoops.
    • haha i was just thinking the same thing.. I don't understand how he can possibly say that and believe it at the same time. Likely he doesn't.
    • Re: (Score:3, Interesting)

      "...easier than handing it to them directly..." ???
      wtf, so it is easier to make a post and leave 100+ embassies open to the world or to send mails..
      I suppose there are ethics here that I am missing.. saying he was supposedly doing these people a "favor" by publishing this..

      I guess at least he didn't try to blackmail them.

  • by blind biker (1066130) on Friday August 31 2007, @09:38AM (#20424503) Journal
    Then why not publish the list anonymously?
    • If he DID publish the list anonymously, then the list could just as easily been dismissed (through political agreements) as completely inaccurate/wrong.
      • Re:Because.... (Score:5, Insightful)

        by kevin_conaway (585204) on Friday August 31 2007, @09:46AM (#20424669) Homepage

        If he DID publish the list anonymously, then the list could just as easily been dismissed (through political agreements) as completely inaccurate/wrong.

        I don't see how having a random strangers name attached to the list makes the data published any more or less accurate.

        • Re:Because.... (Score:4, Insightful)

          by Vellmont (569020) on Friday August 31 2007, @10:40AM (#20425449)

          I don't see how having a random strangers name attached to the list makes the data published any more or less accurate.

          It doesn't, obviously. Publishing anonymously makes it easier for governments to simply SAY the published information is inaccurate. Having someone that's standing behind that statement makes it more difficult to play that game. People don't tend to trust anonymous sources. Look no further than slashdot for evidence of that (where anonymous is different from a pseudonym).
    • Because then no one would search for his LinkedIn account [linkedin.com], thus upping his number of connections from a mere 8.

  • by SavvyPlayer (774432) on Friday August 31 2007, @09:40AM (#20424549)
    Anonymously giving the list to a local newspaper would have achieved the stated objective.
    • Re: (Score:3, Insightful)

      ...and also would've caused a LOT of trouble for both, him and the newspaper publishing it. Not everywhere on this planet journalists enjoy the right to keep their sources secret.
      • No editor would outright publish such a list. Of course the proper agencies would be contacted by the paper and a sensationalized story reprimanding the irresponsible gov agencies involved written during the course of the interaction.
        • Or the paper would have handed it to the correct government agency and that government agency would have been able to (mis)use the information (maybe only for a short time, but still).

          I think that this course of action, whilst not the best was probably taken to ensure that he wasn't seen as a spy, or a terrorist. Moreover I assume that once he had this information he had a hell of a time figuring out who he would be able to trust with it. If you don't know who to trust, don't want to start contacting the g
      • Journalists lack the forensic tools to track down anonymous submissions, especially those of competent security consultants. Sigh.
      • by QuickFox (311231) on Friday August 31 2007, @10:19AM (#20425171)

        Not everywhere on this planet journalists enjoy the right to keep their sources secret.
        Here in Sweden he would certainly be well protected. We have strong laws about these things. Not only in the direct relationship with the papers. For instance, a whistleblower in public employ is so well protected that his boss can't even make innocent comments during a break at the coffee table trying to guess who it might be. Any attempt to try to identify a whistleblower, no matter how innocent it might seem, would land the boss in trouble. And the papers of course guard this protection with great fervor, making lots of publicity when any attempt is made.
    • Yeah right. Newspapers get bogus crap from anonymous 'geniuses' all the time, who claim to have uncovered conspiracies or figured out the secrets of the universe. Another list of startling vulnerabilities in the world's embassies certainly would have gotten the attention of all the editors.
      • This info can be validated by anyone in 3 minutes. Sigh.
        • This info can be validated by anyone in 3 minutes. Sigh.

          First of all, No, it can't. Investigative journalists are trained to do only two things:

          1. Tell when someone's lying or when their story doesn't add up -- a kind of social engineering
          2. Follow the money

          They can't examine scientific claims or medical breakthroughs or stories about computer technologies. When they are forced to do this, they call a bunch of experts and see what their opinions are, which is basically employing skill #1.

          If you can validate this story in 3 minutes, you are a better than average

          • While one must appreciate another's effort to discuss, I have to abstain from a response until a valid analogue is supplied. Why can't an investigative journalist type a URL and enter a user name and pw when prompted given a few minutes?
            • If that's all that's required, I have to admit that that level of technical competence is widespread enough that any journalist could do it.
            • I re-read the article trying to figure out the point you can make. From what I gather, a Swedish 'hacker' -- probably just a computer user -- found a list of valid passwords for the embassies' email websites. It's not like this is a buffer overflow, backdoor, or lousy password policy. They simply didn't protect their passwords, AFAICan tell. So what exactly is the story, or the journalistic angle? "Web email system works as expected, even for Embassies" ? That you can log in, provided you know the userna
  • Good intentions? (Score:4, Insightful)

    by eln (21727) * on Friday August 31 2007, @09:41AM (#20424557) Homepage
    I'm not sure what he was thinking when he decided that publishing the list would be the best way to draw the attention of the affected parties. Sure, calling 100 different embassies can be kind of a hassle, but he could just send out an email with a bunch of BCCs. I would assume he has an email address for each of them.

    Maybe this guy just doesn't have the same sense of self preservation that I do, but in my work I tend to avoid doing things that have the potential to cause a major international incident.
    • Re: (Score:3, Funny)

      Sure, calling 100 different embassies can be kind of a hassle, but he could just send out an email with a bunch of BCCs.

      Yeah, you'd think that a guy who is so 1337 that he "accidentally" ran a cracker against 6 different embassies (it's 100 people, not embassies, despite what the submitter and Zonk wrote) wouldn't have trouble cc'ing them. My coworkers don't seem to have any trouble cc'ing a lot more people than that.

      • He did not run a cracker against anything at all.
        • Re: (Score:3, Interesting)

          Is there some article I'm missing, besides the Ars Technica story and the piece it links? There are things in the blurb that don't appear in either.

          At any rate, I'd be curious what this guy did that caused these passwords to "accidentally" fall out.

    • by Anonymous Coward on Friday August 31 2007, @10:17AM (#20425127)
      "he could just send out an email with a bunch of BCCs"

      Thats basically what he did. It doesn't sound like this list is very public. Its just making its way around the so-called "diplomatic" circles.

      Let's look at this from another angle. He quietly published this list, and probably notified all the affected embassies. Then, at least some of the embassies, and a few news outlets, verify the list. Then, at least some of the embassies change the passwords. Then, those news outlets are able to get comments from the embassies and the guy, and then, publish a story on it. All this happened before YOU found out about it.

      I say its a little early to fault the guy, since what he did is working just fine. Had he contacted each embassy individually, he would have had to convince each one over several emails or phone conversations. This way, he probably only had to talk to a few news outlets / embassies. Had he published the list in a local paper (i laughed out loud at this one) as another slasher suggested, the general public would probably have read copies of the emails in the affected accounts before the embassies ever knew there was a problem.
      • Did he discover them all instantaneously? Why not send a quick email to each one as they become available. He could even do some quick copy/pasting if necessary. Why give the full list to everyone instead of the pertinent parts to each? It seems difficult to believe that he found the time to find all of thesee but couldn't find the time to separate the information to give to each respective office.
  • The real truth (Score:5, Informative)

    by paulraps (1007407) on Friday August 31 2007, @09:51AM (#20424751)
    Here's a more detailed article [thelocal.se] on the subject, ending with a highly amusing quote from Dan Egerstad about his real reason for releasing the log-in info.
    • Re:The real truth (Score:5, Informative)

      by Rob T Firefly (844560) on Friday August 31 2007, @09:54AM (#20424817) Homepage Journal

      He said he had published the list because it would have been too time-consuming to contact all 100 organizations named. Had he handed the list to the Swedish Security Service (Säpo), he would have been guilty of spying. He claimed that by publishing the list he saved himself trouble.

      "This rescues me from the shit," he said.
      Well, I can see how that - huh???
      • Re: (Score:3, Insightful)

        He claimed that by publishing the list he saved himself trouble.

        Sure it does. Let's watch and learn... I'm not Sweedish, but I feel safe in speculating that even there, hacking someone's email and reading it is illegal.

        "I haven't logged in to anyone's account, but I can read their email," he said.

        Typical hacker, thinks the authorities are really interested fixing this sort of thing, if only they knew. I'll bet they did know, and now they're more pissed off than ever since their spy agencies can no longer

        • "hacking someone's email and reading it is illegal" is not quite accurate since its possible to request emails (and its often done too,) and every sys-admin who's administering email servers know that.

          Confidentiality of email does NOT exist. It might exist in some alternate universe but it doesn't exist on this planet.

          Thinking that it does gets people in deep do-doo (or even killed [depends who's doing the asking.])
          • Re: (Score:3, Informative)

            Confidentiality of email does NOT exist. It might exist in some alternate universe but it doesn't exist on this planet.

            This has nothing to do with the Confidentiality of email, and everything to do with accessing other people's email accounts without authorization.

      • He said he had published the list because it would have been too time-consuming to contact all 100 organizations named. Had he handed the list to the Swedish Security Service (Säpo), he would have been guilty of spying. He claimed that by publishing the list he saved himself trouble

        .

        "This rescues me from the shit," he said.
        Well, I can see how that - huh???

        The publicity makes disappearing in the night conspicuous. He's probably hoping that deters Governments from attempting to prosecute him for blackmail. If he mailed them individually they might indeed take it as a attempt to black mail them.

    • "This rescues me from the shit," he says. I think he is about to become very familiar with another quote: "Out of the frying pan into the fire".

      Now instead of the government accusing him of spying, he'll have a bunch of foreign governments pressuring his government to lock him up for spying. I don't think this guy really thought things through here.
    • Excuse me, but I think my English must not be up to par. I read the article you linked to, but what does "This rescues me from the shit" mean? I suppose it's an amusing quote, but it's gibberish. What is the shit? And why does he feel that he needs rescuing from said shit? It seems like a total non sequitur. Please explain this to me.
    • Re: (Score:3, Insightful)

      by Anonymous Coward
      I can't see the problem. He's not American. He's Swedish.

      The Swedes don't persecute their citizens. And they don't let other countries like the US persecute them either. So he's quite correct that he's safe.

      If this had happened in the US, you would be scared to do anything. What a country! This is what you can do if you're free, but you can't do it in the land of the free!

  • by gillbates (106458) on Friday August 31 2007, @09:53AM (#20424789) Homepage Journal

    In the local jail. Why else would anyone do something so boneheaded?

    Honestly, I can't think of any better way to get jailed than to embarrass and irritate the high-level diplomats of 100 countries.

    Yes, it was easier than turning the list over to authorities, or contacting each of the embassies. So what? It could easily be argued that he had a duty of confidentiality with his client that he failed to observe.

    Furthermore, he has actually made security worse by disclosing in this matter. Who knows how many embassies were already aware of the problem, and were in the process of tightening security? It is also likely that at least some of the embassies would have discovered the vulnerabilities independently of this consultant through internal audits, and would have fixed them silently.

    Now, while this guy has stirred up a hornet's nest, he hadn't really done anything to improve the security of these embassies. Sure, they have to fix it now, but they might have done it anyway.

    And what if the Swedes were aware of this and using this information for intel gathering? I don't think anyone is happy he did this.

    • ... It could easily be argued that he had a duty of confidentiality with his client that he failed to observe. ...

      Client? What client?

    • I can't think of any better way to get jailed than to embarrass and irritate the high-level diplomats of 100 countries.

      It's also a good way to see 100 countries over your lifetime. However Gary McKinnon [wikipedia.org] recommends leaving the US until last. That stop takes quite a long time.
      • Re: (Score:2, Interesting)

        Yes, they'll tighten up their security, but it is possible that they were going to do it silently, anyway.

        I mean, if you're going to do research in this area - that is, expend effort looking at security - it's really a cop out to claim that you can't be bothered to contact the embassies individually. You were neither required, nor asked, to evaluate their security. Instead, you take it upon yourself to expend the effort to do the research, and then claim that you can't expend the additional effort to

  • by Rob T Firefly (844560) on Friday August 31 2007, @09:58AM (#20424861) Homepage Journal
    Their security is borked.
  • by Opportunist (166417) on Friday August 31 2007, @10:02AM (#20424939)
    Honestly, should I dig up something like that, I will make it as public as possible, with as much of my name on it as possible as well.

    The reason is simple: When you're in the limelight, it doesn't go unnoticed when you suddenly "vanish". Post it anonymously and they will dig you up. Hand it to some journalist and the same will happen (just that one more person goes with you). You can't simply make someone disappear when he's in the center of attention. Unless you're Copperfield and want to vanish, but that's a different matter.
    • You may not "vanish" in the way you think, but when the activity is considered illegal (hacking other people's accounts is generally seen as illegal in most countries), a public outing like this will almost certainly not be taken the way you imply, and the indevidual will end up in jail.

      Remember that Brit that hacked Nasa? He's headed to Guantanamo.

    • Re: (Score:3, Insightful)

      You can't simply make someone disappear when he's in the center of attention.


      You can make them really and verifiably dead, however; perhaps under suspicious circumstances, but you can make it difficult to prove anything and discover or invent material to discredit anyone peddling "conspiracy theories" connecting you to it. Which, ultimately, acheives the same result as the whole disappearing thing.

  • Say he had contacted each embassy individually. Best case, a mid-level functionary would have fixed the one specific problem and not reported it.
    This way, media in the affected countries will be asking pointed questions, politicians will be asking questions in parliament, and many countries will improve their security policies at all their embassies worldwide, rather than just at the one with the known exposure.
    Why, though, do all recent articles seem to be click-throughs to other articles scant on details,
  • "A Svedeesh IT cunsooltunt hes coosed a stir in deeplumetic curcles effter poobleeshing a leest ooff secret lug-in deteeels belungeeng tu 100 imbesseees, poobleec oothureeties und puleeticel perties eruoond zee vurld. Dun Igersted seeed he-a vesn't tryeeng tu iern muney, geeen poobleecity oor get a neme-a fur heemselff in heckeeng curcles. Insteed he-a cleeemed thet poobleeshing zee leest ves ieseeer thun cuntecting zee oorguneezeshuns indeefidooelly -- und thet iff he-a hed hunded it tu zee Svedeesh oothur
  • I'm curious as to which security hole or human weakness he used. I see from his site [derangedsecurity.com] and Netcraft [netcraft.com] that a lot of sites were Windows Server 2003 or Windows 2000 running IIS, but there is also Apache on Linux.
    • by Anonymous Coward
      Just because

      "Dan Egerstad said he wasn't trying to earn money, gain publicity or get a name for himself in hacking circles..."

      and has the technical ability and the altruistic motives doesn't make it right. Yet if the powers that be (pick you favorite governmental agency) can do this at will, that doesn't make it wrong either.

    • by king-manic (409855) on Friday August 31 2007, @10:29AM (#20425295)

      Of the compromised account, ten belong to the Kazakh embassy in Russia. Around 40 belong to Uzbeki embassies and consulates around the world.
      So half of the 100 accounts belong to underdeveloped former Soviet republics. It seems unsurprising that many of their staff would be unfamiliar with computer systems and computer security.

      Kazakhstan is the greatest country in the world, all other countries are run by little girls. Kazakhstan is number one exporter of internet security, Other Central Asian countries have inferior internet security.

      High Five!
      • Around 40 belong to Uzbeki embassies and consulates around the world

        Assholes Uzbekistan.

        I get computer, Uzbekistan gets computer

        I get gmail, Uzbekistan get gmail

        I get access to naughty website with Pamela, Uzbekistan cannot afford!

        Great success!