HideMyAss defends role in LulzSec hack arrest
Anons vow to give ass-hiders a hiding
HideMyAss has defended its role in handing over evidence that resulted in the arrest of a suspected LulzSec member last week.
UK-based HideMyAss, which offers freebie web proxy and paid-for VPN services, said it handed over potentially incriminating data to the feds only in response to a court order. It had been aware that its service was being used by Anonymous/LulzSec members for some time before this without taking any action, as a blog post headed LulzSec fiasco by the firm explains.
Cody Andrew Kretsinger, 23, of Phoenix, Arizona allegedly used HideMyAss.com's web proxy service to hack into the systems of Sony Picture Entertainment as part of a hack that exposed the personal details of thousands of gamers. According to the court order, Kretsinger used SQL injection techniques that were run via HideMyAss's anonymising web proxy service to launch the high-profile attack.
It first came to our attention when leaked IRC chat logs were released, in these logs participants discussed about various VPN services they use, and it became apparent that some members were using our service. No action was taken, after all there was no evidence to suggest wrongdoing and nothing to identify which accounts with us they were using.
HideMyAss, which bills itself as a leading online privacy website, adds that it does not condone illegal activity, saying that similar services that do not co-operate with law enforcement are "more likely to have their entire VPN network monitored and tapped by law enforcement, thus affecting all legitimate customers". The service said it carries out session-logging, recording the time a customers logs onto and disconnects from the service as well as the IP addresses he or she connects to. It said it does not record the actual content of web traffic.
Twitter accounts affiliated with Anonymous were unsurprisingly vociferous in their criticism of HideMyAss's business practices and assistance of a federal investigation, dubbing the service SellMyAss, and arguing that HideMyAss users are less likely to trust it and more likely to look for alternatives.
"Question @HideMyAssCom: Was it worth to rat out one guy who allegedly hacked #PSN in exchange for all your business? You will find out soon," AnonymousIRC said.
HideMyAss, which was established in 1995, was set up as a way to bypass censorship on the web before moving on to offer commercial VPN services. It boasts of its recent role in allowing Arab Spring protesters to gain access to websites such as Twitter, which were blocked by the former Egyptian government of Hosni Mubarak. Privacy activists have accused HideMyAss of double standards over its handling of the Kretsinger case.
"The Hide My Ass VPN service is run by a bunch of hypocrites," said Jacob Appelbaum, a core member of the Tor project, in a Twitter update. "They support revolution and circumvention when it suits their business image."
In updates to its original blog posts, HideMyAss defended its stance on this point, arguing that it simply complies with UK law. It denied acting as a pawn at the behest of the Feds.
"We are not intimidated by the US government as some are claiming, we are simply complying with our countries legal system to avoid being potentially shut down and prosecuted ourselves.
"Regarding censorship bypassing, some have stated it is hypocritical for us to claim we do not allow illegal activity, and then claim our service is used in some countries to bypass censorship illegally. Again we follow UK law, there isn’t a law that prohibits the use of Egyptians gaining access to blocked websites such as Twitter, even if there is one in Egypt ... though there are certainly laws regarding the hacking of government and corporate systems," it concludes. ®
A policeman friend of mine...
...when I asked how hackers are stupid enough to get caught even though they know Internet traffic is not truly anonymous replied...
"Fingerprint technology has been publicly known for a hundred and thirty years, but some blokes still break into houses without wearing gloves."
That about says it all I think.
Euro data retention directive.
Anybody using a European service and expecting no logging, is just being wilfully ignorant of euro directive 2006/24/EC, or plain stupid.
Hackers should be interested in the law, even when they think they stand above it, it will affect them.
Or, more accurately --