56
Bootstrapping Your Hacktivist Community Kiwicon 6 2012 Liz Henry @lizhenry Wednesday, May 1, 13

Tracking trollers

Embed Size (px)

DESCRIPTION

 

Citation preview

Page 1: Tracking trollers

Bootstrapping Your Hacktivist Community

Kiwicon 6 2012Liz Henry @lizhenry

Wednesday, May 1, 13

Page 2: Tracking trollers

I will now tell you how to make a hacktivist

community

Wednesday, May 1, 13

Page 3: Tracking trollers

HAHAHAHA

Wednesday, May 1, 13

Page 4: Tracking trollers

What is “hacktivism”?

• Legal or lower risk hacking:

• Reporting, citizen journalism (maybe)

• Outing people for something

• Protest, petition, policy, law changes

• Civil disobedience (maybe)

Wednesday, May 1, 13

Page 5: Tracking trollers

Wednesday, May 1, 13

Page 6: Tracking trollers

Sometimes“hacktivism”looks like this

Wednesday, May 1, 13

Page 7: Tracking trollers

And “community”?

• For community, you need trust

Wednesday, May 1, 13

Page 8: Tracking trollers

Trust is nice

Wednesday, May 1, 13

Page 9: Tracking trollers

Lower Risk “hacktivism”

• Publicity. Use all possible social capital.

• Get consent, protect privacy, personal security, personal data if possible.

• Rhizomatic spread. Don’t wait for the boss.

• Action plan. Group chat. Collectively edit some documents. Needs list. Schedule.

• Report on what is effective. Ask for more.

Wednesday, May 1, 13

Page 10: Tracking trollers

Emergency power!

• Hurricane Sandy

• Existing communities, social capital among disabled people online

• Incredibly fast mobilization, public call, in-person help from friends of friends of friends, nearly random strangers

Wednesday, May 1, 13

Page 11: Tracking trollers

Higher risk

• Reporting or citizen journalism (maybe)

• Infiltration, espionage

• Leaking military or other secret info

• Messing with governments, huge corporations, organized crime

Wednesday, May 1, 13

Page 12: Tracking trollers

Who will you piss off?

• Professional reputation/status?

• Stalkers or other hostile individuals?

• Intellectual property, legal, hacking laws

• Repressive government, military?

• Mexican drug cartel? Russian mafia?

• In short, what are you risking?

Wednesday, May 1, 13

Page 13: Tracking trollers

Example: Editing the Zetas

• What’s the threat level if you want to edit some Wikipedia pages about Mexican drug cartels?

• Where are you?

• Not-Mexico: Make persona, use Tor + VPN

• Mexico or near: Maybe that’s not enough

Wednesday, May 1, 13

Page 14: Tracking trollers

Nuevo Laredo carspotting

• Chat rooms to report on dangerous stuff

• Green Chevy at corner of 9th and Main every afternoon

• Roadblock on the west road out of downtown

Wednesday, May 1, 13

Page 15: Tracking trollers

sms blogging

• blog from burner phones

• vojo.co has all-phone setup

Wednesday, May 1, 13

Page 16: Tracking trollers

Risks, maybe

• Someone shoulder surfs you in a cafe and shoots you in the head later

• Keylogging, insecure connection

• Site you’re on is run by gangsters. Oops!

• Or is on phpBB or something scarier

• (narcomensajes, torture, murder)

Wednesday, May 1, 13

Page 17: Tracking trollers

Consider Risk

• Are you’re risking your freedom?

• Or your life

• Or other people’s lives

• Make sure it’s what you want to risk

• For a good reason!

Wednesday, May 1, 13

Page 18: Tracking trollers

There are good reasons

Wednesday, May 1, 13

Page 19: Tracking trollers

Why?

• What are your reasons and goals

• Publicity? (Then stick to lower risk)

• Personal studliness? (Don’t!)

• Expose truth?

• Freedom fighter?

Wednesday, May 1, 13

Page 20: Tracking trollers

How to make a hacker community

Wednesday, May 1, 13

Page 21: Tracking trollers

Don’t!

Wednesday, May 1, 13

Page 22: Tracking trollers

Or, first...

• At least pause

• Ethics of encouraging others to do high risk things on some crappy Windows machine with LOIC or whatever. Yeah.

• Learn security, anonymity, privacy

• Put them into practice

• Practice!

Wednesday, May 1, 13

Page 23: Tracking trollers

Before y’all do this. . .

Wednesday, May 1, 13

Page 24: Tracking trollers

Totally pause

Wednesday, May 1, 13

Page 25: Tracking trollers

Wednesday, May 1, 13

Page 26: Tracking trollers

Feminist Hackers

• Bunch of women hackers talking

• Why is there a “false accusers” wiki run by MRAs, but no “rapists” wiki run by rape survivors? Unfair and wrong!

• OMG Haxxors!

• Retaliation (identity/safety/DDoS)

• Defamation, legal threats

Wednesday, May 1, 13

Page 27: Tracking trollers

Wednesday, May 1, 13

Page 28: Tracking trollers

Pick your cool haxxor names!

• We thought of some great ones

• Most of them were totally contaminated

• Anyway, they sounded like roller derby names

• And we were telling them to each other, which was dumb, but we realized that about 2 minutes in

Wednesday, May 1, 13

Page 29: Tracking trollers

• So I can never secretly be “Louise Boat”. This makes me very sad.

Wednesday, May 1, 13

Page 30: Tracking trollers

Test for leaks

Wednesday, May 1, 13

Page 31: Tracking trollers

Testing each other

• We looked at what info we were leaking by accident, and what we knew or could deduce or find about each other.

• Some of us were better at it than others.Wednesday, May 1, 13

Page 32: Tracking trollers

We found a lot of leaks

Wednesday, May 1, 13

Page 33: Tracking trollers

Some hackers are more equal than others

• We all had some practice, because we are all women talking in public and thus, present more attack surface

• Various factors made some of us more vulnerable than others: queer, trans, people of color, homeless, have kids, domestic violence survivors...

• Those factors often encourage more practice in privacy, anonymity, pseudonymity

Wednesday, May 1, 13

Page 34: Tracking trollers

Check your privilege

• If you’re hacking in a high risk way you’re risking everyone around you.

• The others in your “hacktivist community” may be at risk merely by being associated with you

• Protect your contacts

Wednesday, May 1, 13

Page 35: Tracking trollers

Learn to attack

Wednesday, May 1, 13

Page 36: Tracking trollers

Learn to spy

Wednesday, May 1, 13

Page 37: Tracking trollers

Be a trickster

Wednesday, May 1, 13

Page 38: Tracking trollers

Be Paranoid

Wednesday, May 1, 13

Page 39: Tracking trollers

Trust no one

Wednesday, May 1, 13

Page 40: Tracking trollers

Make personas within personas

Wednesday, May 1, 13

Page 41: Tracking trollers

Don’t contaminate your personas

Wednesday, May 1, 13

Page 42: Tracking trollers

Don’t boast

Wednesday, May 1, 13

Page 43: Tracking trollers

Ops checklist

• Safer computer, software (encrypt)

• Physical security (for your computer!)

• Safer connection (Tor, then VPN?)

• Persona management.

• Shut your pie hole!

Wednesday, May 1, 13

Page 44: Tracking trollers

More leak vectors to consider

• Location, time, time zone. Avoid patterns!

• Password hygiene

• Paying for stuff

• clicking links someone sends... (don’t)

• Panopticlick (browser fingerprinting)

• Tor, then VPN(s)

Wednesday, May 1, 13

Page 45: Tracking trollers

Study security, privacy, anonymity guides

• EFF guide

• Internews, CPJ guides

• TOR, crypto.is

• Study together

• That’s still not good enough

Wednesday, May 1, 13

Page 46: Tracking trollers

You must be flawless

Wednesday, May 1, 13

Page 47: Tracking trollers

Consciousness Raising

• Bootstrapping new hackers is hard.

• Consider your personal identity and what attack surface you present.

• This will take some discussion and thought.

• You will get a community that is capable of hacking something for some reason someday. Maybe in a crisis.

• It’s political consciousness raising

Wednesday, May 1, 13

Page 48: Tracking trollers

That isn’t very glamorous

Wednesday, May 1, 13

Page 49: Tracking trollers

But neither is jail

Wednesday, May 1, 13

Page 50: Tracking trollers

Or the Ecuadorian Embassy

Wednesday, May 1, 13

Page 51: Tracking trollers

Medium risk hacking• There’s still things to do that probably

aren’t super super super risky...

Wednesday, May 1, 13

Page 52: Tracking trollers

SRS Business

• Hollaback. Cell phone pics of street harassment.

• Public callouts of public bad behavior, whether pseudonymous or real name

• Twitter hashtags, mockery

• ShitRedditSays started reporting on public misogyny. “Outing” and “doxxing” of violentacrez ... ie “googling” and “his beer buddy told on him”.

Wednesday, May 1, 13

Page 53: Tracking trollers

FERT was born

• Feminist Emergency Response Team!

Wednesday, May 1, 13

Page 54: Tracking trollers

Lower risk high risk hacker activity

• Neighbor in domestic violence crisis, we found her husband in her Yahoo email and her phone

• Ex-pat Syrian journalist getting death threats. Looked at email headers, IP and told her it was not obviously a local threat or a threat from within Syria

• Palestinian activist convinced site was hacked by Israeli govt. Were able to show them it was just a spambot, php/sql injection

• Advised feminist blogger undergoing 4chan raidWednesday, May 1, 13

Page 55: Tracking trollers

“Stay Safe” (or not)

Wednesday, May 1, 13

Page 56: Tracking trollers

Create possibilities

Wednesday, May 1, 13