Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Privacy

110,000 Affected by Epik Breach - Including Those Who Trusted Epik to Hide Their Identity (washingtonpost.com) 112

Epik's massive data breach is already affecting lives. Today the Washington Post describes a real estate agent in Pompano Beach who urged buyers on Facebook to move to "the most beautiful State." His name and personal details "were found on invoices suggesting he had once paid for websites with names such as racisminc.com, whitesencyclopedia.com, christiansagainstisrael.com and theholocaustisfake.com". The real estate brokerage where he worked then dropped him as an agent. The brokerage's owner told the Post they didn't "want to be involved with anyone with thoughts or motives like that."

"Some users appear to have relied on Epik to lead a double life," the Post reports, "with several revelations so far involving people with innocuous day jobs who were purportedly purveyors of hate online." (Alternate URL here.) Epik, based outside Seattle, said in a data-breach notice filed with Maine's attorney general this week that 110,000 people had been affected nationwide by having their financial account and credit card numbers, passwords and security codes exposed.... Heidi Beirich, a veteran researcher of hate and extremism, said she is used to spending weeks or months doing "the detective work" trying to decipher who is behind a single extremist domain. The Epik data set, she said, "is like somebody has just handed you all the detective work — the names, the people behind the accounts..."

Many website owners who trusted Epik to keep their identities hidden were exposed, but some who took additional precautions, such as paying in bitcoin and using fake names, remain anonymous....

Aubrey "Kirtaner" Cottle, a security researcher and co-founder of Anonymous, declined to share information about the hack's origins but said it was fueled by hackers' frustrations over Epik serving as a refuge for far-right extremists. "Everyone is tired of hate," Cottle said. "There hasn't been enough pushback, and these far-right players, they play dirty. Nothing is out of bounds for them. And now ... the tide is turning, and there's a swell moving back in their direction."

Earlier in the week, the Post reported: Since the hack, Epik's security protocols have been the target of ridicule among researchers, who've marveled at the site's apparent failure to take basic security precautions, such as routine encryption that could have protected data about its customers from becoming public... The hack even exposed the personal records from Anonymize, a privacy service Epik offered to customers wanting to conceal their identity.
This discussion has been archived. No new comments can be posted.

110,000 Affected by Epik Breach - Including Those Who Trusted Epik to Hide Their Identity

Comments Filter:
  • by Anonymous Coward

    One link is paywalled and the alternate site is banned by my ISP for spreading misinformation.

    • If your ISP "bans" and blocks/filters the Seattle Times, maybe you should get a real ISP instead of using a right wing nutjob job?

    • One link is paywalled and the alternate site is banned by my ISP for spreading misinformation.

      Your ISP blocks sites? You in China?

    • Banned by your isp? Lol it works for me, and Iâ(TM)m in communist China.

      Did you have a little too much to think?

  • This is a juicy dump! I'm going to write some software to sign these very fine people up for as many LGBTQ+, climate change, and justice reform newsletters as possible. I know the founder of the Proud Boys takes pride in sticking dildos up his ass for fun, so I suspect some of them will welcome the flood of newsletters.

    Let it be known the right is absolute fucking trash at IT, amongst other things....
    • This dump is a pretty funny situation. I guess if you are going to do some racist and creepy stuff, don't expect to hide behind a thin curtain of anonymity.
      • Anonymity ultimately never works and is for amateurs. They could have made some effort by retraining for a career in racism. There is no lull in demand for academics in race-related fields or for diversity and inclusion consultants.

        Having to flip your racism on its head is an adjustment worth making. No more hiding in the shadows. You can be as racist as you like while getting book deals, TV appearances, and being paid to teach children to be racist.

        Although it may be too late for these people, I'd suggest

    • Let it be known the right is absolute fucking trash at IT, amongst other things....

      I wouldn't use this breach as an anecdote towards that conclusion. From TFA:

      A huge proportion of the 1.8 million domains shown in the breached data appear ordinary, with Web addresses for people interested in real estate, home improvement, vegan cooking, various types of spirituality — as well as the occasional domain devoted to pornography, gaming and cryptocurrency.

      It sounds more like a typical registrar that is neutral towards whatever content their customers intend on hosting. That is inevitably going to make them popular for anybody who is intending on hosting content that is banned by other registrars.

    • Let it be known the right is absolute fucking trash Enough said. Antifa will be visiting soon.

  • by sdinfoserv ( 1793266 ) on Saturday September 25, 2021 @06:30PM (#61832311)
    What an epik failure. Sorry, couldnt resist.
  • by Digital Avatar ( 752673 ) on Saturday September 25, 2021 @06:34PM (#61832315) Journal

    Kirtaner's the founder of 420chan. He has fuck-all to do with "Anonymous"... unless you count the times posters to 420chan called up Hal Turner's racist radio show to harass him (which admittedly was hilarious if you were there). Of course, Kirtaner would know all about hatred since 420chan served as a haven for the Invasions forum that targeted other webforums for harassment, and of course also hosted its own loli forum (until his webhost made him take it down).

    TL;DR People in glass houses shouldn't throw stones.

  • Come on people, it's not that hard.

    Use a security focussed sdlc framework.
    Patch , patch and patch some more.
    Encrypt everything.
    Scan, scan and pentest some more.
    Get your Identity and Access Model right.
    Backup, backup and backup some more.
    Get a good security awareness/training program in place.
    Whitelist.

    Get back to the basics and 90% of your problems go away.

    Shit.

  • WHOIS data (Score:5, Insightful)

    by wellard1981 ( 699843 ) on Saturday September 25, 2021 @07:42PM (#61832397)
    This leak also contained e-mail addresses of people who have never done business with them, I know because I'm one of them. I stupidly downloaded the data because I was alerted by Firefox Monitor that my e-mail address was included in the breach. Upon inspection, it was WHOIS data from 2012 and 2014. So before people start going vigilante, know that there are personal details within the dump that have never done business with them. Until this point, I didn't know Epik existed.
    • This leak also contained e-mail addresses of people who have never done business with them, I know because I'm one of them.

      Can confirm. "Have I been Pwned" notified me that I was in the Epik breach, but I have not done any business with them. My email address is not in any whois data though.

    • Honest question here; If you've never done business with them, how is it your e-mail address is in their WHOIS data?

      The only way I can figure is if Epik bought out some other registrar that you did do business with, or there was someone fraudulently using your e-mail for their domain registration.
      =Smidge=

      • Or they had a whois crawler. Which they did.

        They crawled all expiring domains for marketing purposes, and potentially to scoop them up for auction if they thought that it was a good domain.

    • This leak also contained e-mail addresses of people who have never done business with them, I know because I'm one of them. I stupidly downloaded the data because I was alerted by Firefox Monitor that my e-mail address was included in the breach. Upon inspection, it was WHOIS data from 2012 and 2014. So before people start going vigilante, know that there are personal details within the dump that have never done business with them. Until this point, I didn't know Epik existed.

      Sorry, that's not how vigilantism works. You don't get to just turn it off.

      If you ever ranted against "far right hate" (while denying that far left hate even existed), and if you ever want to just have the mob roll over people with no due process, well, there are some chickens at your door who are home to roost.

    • This leak also contained e-mail addresses of people who have never done business with them, I know because I'm one of them.

      Same here.

      Until this point, I didn't know Epik existed.

      And again, same here. I've no idea why they had any of my info.

  • by aerogems ( 339274 ) on Saturday September 25, 2021 @07:44PM (#61832401)

    I mean... on the one hand, I have little to no sympathy for racists, jingoists, chauvinists, and the other types of "characters" you tend to find on the fringes of the right. Many of them spend their time targeting and terrorizing other groups, so the tables being turned on them now is a kind of poetic justice. At the same time, however, I believe very strongly in a person's right to hold beliefs that I don't agree with. Just because I do not agree with something a person has to say doesn't mean they shouldn't have a right to say it.

    A bunch of "good old boys" want to sit around, have a couple beers, and bitch about the government, fine. I'm sure they refuse to cash any social security checks, take their own trash to the dump, put their kids into private schools, don't drive on publicly funded roads, have their own portable generator that they use for all electricity, aren't connected to the city sewage, or any of the other "socialist" things government does all on principle. However, when they start targeting specific groups of people, that's where I draw the line personally.

    I understand it's a slippery slope argument, but once you start saying this speech is acceptable and that speech isn't, it's the first step towards authoritarianism. You need to make damn sure you have thought things through before acting.

    • by burtosis ( 1124179 ) on Saturday September 25, 2021 @08:00PM (#61832413)

      Just because I do not agree with something a person has to say doesn't mean they shouldn't have a right to say it.

      The difference is needing to hide behind an anonymous account to be free from civilian accountability, these people did have a legal right to say what they did. More or less the first amendment provides protection from governmental retribution unless very specific well established conditions are met but the first amendment is a double edged sword - other people have it too and including those who run companies and can use that to do things like refuse to associate with them. Because we don’t force public association my government mandate they are free to not buy things or demand a company fire someone (within existing legal framework) or any number of things and companies just follow the bottom line of profit, it’s not personal. If you actually wanted freedom to speak your mind without being interfered with the only party that can is the government - it’s an argument for a socialized government backed social media alternative with constitutional rights baked in from the start.

      • > Because we don’t force public association my government mandate

        That's not true actually. We force both companies and individuals to associate with those they may prefer not to by government mandate routinely.

        • > Because we don’t force public association my government mandate

          That's not true actually. We force both companies and individuals to associate with those they may prefer not to by government mandate routinely.

          This is only true for groups like protected classes and is based in equal rights not forced association and it’s only with some existing practices. For example if you run a business you cannot deny employment or patronage based on race due to equal rights, but the government does not force anyone to associate with any particular race - it is the act of being associated with a business that opens one up to not trampling over the constitutional rights of others based on historical discrimination. Some

          • Everything you said is in agreement with what I said so I'm not sure what you are arguing.

            • Because you framed it as forced association, when it’s basis is not.
              • What the basis is has nothing to do with whether or not it is forced association. It is forced association. It may be for a good reason or have some benefit, but that doesn't change the fact that it is forced association.

                • False. That’s like a city banning all motorized vehicles from sidewalks and framing it as the city banned the use of electric bikes. Yes, you can’t ride them on sidewalks, but you can on the street and elsewhere and to frame it that way is misleading at best.
                  • Um, no, your example has nothing in common with the argument at hand. I'm sorry, you lack rationality and logic and so further argument is pointless.

    • This whole situation just makes me think, "play stupid games, win stupid prizes."
    • by AmiMoJo ( 196126 )

      Many of them have already committed crimes, so the data will be used to investigate prior activities. It's also very useful for identifying links between groups that claim to be unrelated. That kind of "terror cell" isolation is very common with the far right, so they can disavow each other's behaviour and switch between identities as they get banned from mainstream platforms.

      It's also quite useful for identifying all the false flag ops and attempts to incite violence. Might help exonerate some people.

    • At the same time, however, I believe very strongly in a person's right to hold beliefs that I don't agree with.

      If true, then I congratulate you. You are rare as hen's teeth these days.

      • It's not that difficult once you realize it doesn't mean you have to like what they say, or agree with it, just accept they have a right to say it. Otherwise, how can I ever expect anyone to support my right to say something that someone else may not like or agree with?

    • Slippery slope is a heavily misunderstood fallacy. You can take any number of steps towards "authoritarianism" and not automatically get there; each step is an argument of it's own. The fallacy is over simplifying and equating many steps to a few big steps or a SLOPE where a tiny step just slides automatically into the extreme distant position.

      1st step implies a progression but it can be the only step. Protection by extreme position doesn't work as people historically can move extreme distances in their p

    • I only want out of social security what I put into it. I wish they would just let me manage that money myself. Instead they have to use my payroll taxes to keep the government solvent on any given day. I pay taxes for garbage collection, water, and sewer. I also pay gasoline tax that funds the roads. It isn't free. Watch what happens when you don't pay. I don't think socialism means what you think it means. And, yes, I send my kid to private school and can go off-grid if needs be with solar, batteries
  • by mysidia ( 191772 )

    There really ought to be some laws making it criminal with recoverable backpay and forced-rehire for an employer to rely upon information released as a result of an illegal act by someone else to make a decision such as this (Dismissing an employee after reading illegally-obtained information that contain something you think is negative, which you assume
    says something about their personal beliefs)..:

    The real estate brokerage where he worked then dropped him as an agent. The brokerage's owner told

      • Yeah. They'll cancel you while collecting a chunk of your paycheck and telling you they're standing up for you as they kick your ass to the curb, should the union leadership discover you hold opinions they don't like. Monopolies can do that. The duopoly of big labor and big business isn't much better.

        • Unions should be seen as a stopgap, we ought to be able to do better. Government should be making sure that all workers have reasonable rights in their workplace, not just ones that join a club and pay dues, and we need to demand representatives that will address that need.

          • The right to collective bargaining and freedom of association in the workplace, as Platonic ideals, should be able to ensure the desired result in an adversarial system like ours. The problem inevitably occurs when the laws are structured to favor or require a monopoly on labor representation by a single (big and politically connected) organization calling itself a "labor union."

            Ideally, union monopolies would be broken up and the union shop would be prohibited. But that diminishes the rent-seeking behavior

          • > Government should be making sure that all workers have reasonable rights in their workplace,

            Expecting government to do that is optimistic. Workers don't usually employ lobbyists.

        • to see somebody living in this day and age, owning a PC or at least a mobile phone and therefore having the means to do so, so completely oblivious to the fact that he owes that to Unions.

          I mean I guess it's possible you come from old money....
          • No, I come from a line of middle middle class white collar types going back as many generations as we collectively remember. Most of that was in the Soviet Union where the policies put in place to elevate the working man elevated nearly everyone to an equal level of poverty and the last few decades of it were here. In all cases, affiliation with a labor union has been involuntary wherever it has occurred.

    • Isn't this, in a way, a form of "social safety net"? Wouldn't that, then, be a form of socialism? I thought the sort of people who said hateful, bigoted things under cover of anonymity typically hated socialism.
      • by mysidia ( 191772 )

        Isn't this, in a way, a form of "social safety net"? Wouldn't that, then, be a form of socialism?

        No.. just a rejection of employers exploiting lawbreaking conduct.

        I thought the sort of people who said hateful, bigoted things under cover of anonymity typically hated socialism.

        There's no specific ideology for people who said something bigoted.

        There's also really nothing proving the registrant of the domains espouses to hate or bigotry -- there are people who just publish websites with a purpose of driving tra

    • Which is why lots of us create fake accounts using name in the who is, or elected senators, past and present, mayors etc. Creates a lot of mis-understandings. In fact there are campaign workers on the other side, working hard to discredit the incumbent. Thjanks to poor os and email designs, even genuine IP addresses can be inserted to add veracity to a complete set up. Or you outsource the dirty work to Russia/Cn.
  • The only reason they ask for all those personal data information is because of the payment. The solution is to use something like Bitcoin where you can stay anonymous and payment is done anyway.
    • And you think anonymity will foster a better overall dialog, an improved society, less hatemongering, less weaponized misinformation?

    • Anonymity through blockchain-recorded transactions is about the stupidest stupid you can find.

      Shave your neckbeard. Read a white paper for once in your life.

  • I think it would be fun to filter, then do a cluster analysis on the topics and people. Use NLTK to analyze the text and use that as a feature set.
  • Owning a website, and supporting the views behind the website are different, and even if you support disgusting / horrible views, if you don't bring violence for those views, then it should be off limits.
  • I got a Firefox message last week that my data had been found in a breach, and the message indicated that it was the Epik breach.

    The thing is, I have no idea how or why it was in there to begin with- I've never had an account with Epik, and never used them for hosting or did any business with them at all as far as I know.

    So I have no idea how my data or identity could have been involved. But there it is, apparently.

  • I'm sorry, but I just can't be the only one. Doesn't anyone else think the idea of a "Whites' Encyclopedia" could actually be an absolutely hilarious comedic idea?

    e.g. Could I look up dancing on it?

Keep up the good work! But please don't ask me to help.

Working...