
Doxer, die sich als Polizisten ausgeben, bringen große Technologiefirmen dazu, die privaten Daten anderer zu teilen | Eine gefälschte E-Mail-Adresse und ein leicht zu fälschendes Dokument reichen aus, damit große Technologieunternehmen Ihre persönlichsten Daten preisgeben
https://www.wired.com/story/doxers-posing-as-cops-are-tricking-big-tech-firms-into-sharing-peoples-private-data/

8 Kommentare
Issues of note:
>When a privacy specialist at the legal response operations center of Charter Communications received an emergency data request via email on September 4 from Officer Jason Corse of the Jacksonville Sheriff’s Office, it took her just minutes to respond, with the name, home address, phone numbers, and email address of the “target.”
>
>But the email had not in fact come from Corse or anyone else at the Jacksonville Sheriff’s Office. It was sent by a member of a hacking group that provides doxing-as-a-service to customers willing to pay for highly sensitive personal data held by tech companies in the United States.
>
>“This took all of 20 minutes,” Exempt, a member of the group that carried out the ploy, told WIRED. He claims that his group has been successful in extracting similar information from virtually every major US tech company, including Apple and Amazon, as well as more fringe platforms like video-sharing site Rumble, which is popular with far-right influencers.
>
>…
>
>In the US, federal, state, and local law enforcement agencies who need to find out the identity of the owner of a social media account, or details about a specific phone, send the relevant company a subpoena or warrant requesting the information.
>
>All major companies operating in the US have departments and specific staff assigned to dealing with these requests, which are typically sent via email. The companies, once they review the subpoena and see it has come from what looks like a law enforcement agency, typically comply with the requests, sometimes taking additional verification steps such as phoning the officer involved to confirm they did indeed send the request.
>
>But officers can also make emergency data requests, or EDRs, in cases involving a threat of imminent harm or death. These requests typically bypass any additional verification steps by the companies who are under pressure to fulfil the request as quickly as possible.
>
>…
>
>The problem partly stems from the fact that there are around 18,000 individual law enforcement agencies in the US alone, all of which use their own email naming conventions and domain registrations, including .us, .net, .org, .gov, and .com.
>
>The hackers typically use one of two ways to trick companies into making them believe the emails being sent are coming from real law enforcement agencies. In some cases, they use authentic law enforcement email accounts that they have compromised via social engineering or using credentials stolen in previous hacks. Other times, they create convincing fake domains that closely mimic legitimate police departments.
>
>…
>
>“The core issue isn’t companies being careless, it’s that traditional communications channels, like email, weren’t built for the level of identity verification, context evaluation, and real-time decisioning that modern investigations and legal compliance require,” says Matt Donahue, a former FBI agent who left the agency in 2020. Soon after, Donahue founded Kodex, a company that works with companies to build secure online portals law enforcement can use to make data requests.
>
>While technologies like Kodex provide a much safer alternative to email, over 80 percent of the companies listed on the SEARCH database still accept emergency data requests via emails, according to one review conducted by Kodex,
>
>But even those who only use Kodex are not in the clear. Exempt claims that they were able to make requests through Kodex for a period of time, using compromised law enforcement email accounts. However, because of Kodex’s enhanced safety features, including whitelisting specific devices from which requests can be made, Exempt and his group have now lost access to the system.
>
>The hacker claims, however, that they are now working to regain access via another avenue.
>
>“We are in talks with a deputy from a large sheriff’s office … who we got paid to dox [and] who is now interested in either renting his Kodex account to us or he may submit the requests for us on his side,” says Exempt. “This is in [the] very early stages of talks. He would want a percentage of the money we make and his dox removed on a well-known doxing site.”
>
>…
>
>While the hackers are taking advantage of the weakness in email security, they are also taking advantage of companies’ desire to help law enforcement save lives.
>
>“Public-private sector coordination is an incredibly complex and nuanced space that could very well be the difference between a kid being found in a trunk, or not,” says Donahue. “Lawful government data requests sit at the very unique intersection of data privacy, public safety, security, legal compliance, and civil rights, so anyone suggesting these requests are carelessly responded to in minutes has little to no understanding of the subject matter.“
These are concerning circumstances here that appear to have no straightforward solutions. Part of the issue here is the proliferation of law enforcement agencies (18,000!) across the nation and at all levels of government. That there are no standards for domains or for information security or anything else makes this a difficult issue to address effectively.
> traditional communications channels, like email, weren’t built for the level of identity verification, context evaluation, and real-time decisioning that modern investigations and legal compliance require
Companies are collecting more PII than ever before, while our communication channels are still so easily exploited.
I don’t think we’re handling this World Wide Web thing properly.
The AI is time, and sign, to stop using the **dead internet** for social interactions. All we do is tracked. Meta has one of the biggest datacenters in the world, while having also the biggest AI server-centers, while their AI is not even widely used, they train bots using our data, chats etc. and then can use it to even worse things.
OpenAI can not be trusted at all, no to mention DeepSeek. Gemini has tons of data too, all of them.
Before AI they at least tried to keep the data under seal. Now all they want is even more data to train that technology, and they lost its brakes. DRAM situation just straight says they don’t give a fuck, they do anything in their force to reach that ill imagination of intelligent machine. Look, OpenAI bought out raw wafers to stop competition. The wafers can not be used by anyone, it is corpo war at purest form. Because it is the most important piece of that puzzle. Memory, to keep even more compressed data available for these calculations that are no longer controlled.
The worse is that they will never reach their target, cuz it is all statistics, combinatorial calculations and mathematics, without positive and negative reactions of human body. We can feel and decide on many levels due to events that shaped us, and created these negative and positive memories. We escape the bad ones, and try to continue the good ones, even if these are bad things from psychological side (like addictions) and vice versa.
So the more the machines are trained, they become more wrong, cuz they are designed to be mathematically correct.
Warrant.
Demand one.
Call to verify it. Using the public numbers. Not any number on the potentially fake doc.
So really, the only thing it requires is a fraudulent but official-looking domain name or spoofed address, and you could announce yourself as Immigrations & Customs Enforcement Digital Anti-Terror Administration, ICE DATA. And then you could persuade some schmuck that such-and-such is suspected of harboring, aiding, and abetting an invasion by narcotic illegals blah blah blah.
Christ alive, human gullibility is the first and weakest line of defense in every security system I swear to God
And they will face 0 consequences when they do.
When terms of service says they’ll share information with law enforcement only upon request, they actually meant this.
It’s almost like there’re consequences to lionizing law enforcement to the point that we’re conditioned to think they can do no wrong and that civil liberty protections are just „red tape“ that holds up the cops and stops them from catching the „bad guys“.