Página principal  |  Contacto  

Correo electrónico:

Contraseña:

Registrarse ahora!

¿Has olvidado tu contraseña?

PHALLABEN
 
Novedades
  Únete ahora
  Panel de mensajes 
  Galería de imágenes 
 Archivos y documentos 
 Encuestas y Test 
  Lista de Participantes
 Bi-scussioni, tri-scussioni ecc. 
 BIBLIOGRAFIA 
 
 
  Herramientas
 
General: The FBI stole an Instapaper server in an unrelated raid
Elegir otro panel de mensajes
Tema anterior  Tema siguiente
Respuesta  Mensaje 1 de 11 en el tema 
De: Merendina  (Mensaje original) Enviado: 13/07/2012 04:39

One of Instapaper’s five leased servers was hosted at DigitalOne, a Swiss hosting company leasing blade servers from a Virginia datacenter. Early Tuesday morning, the FBI raided the datacenter to seize servers used by another DigitalOne customer for fraudulent “scareware” distribution, according to the FBI’s press release, but they seemingly took a lot more servers that happened to be physically near the server(s) they were looking for.

There’s very little information on this, but The New York Times has the most complete coverage in Tuesday’s Bits post:

The F.B.I. seized Web servers in a raid on a data center early Tuesday, causing several Web sites, including those run by the New York publisher Curbed Network, to go offline. …

In an e-mail to one of its clients on Tuesday afternoon, DigitalOne’s chief executive, Sergej Ostroumow, said: “This problem is caused by the F.B.I., not our company. In the night F.B.I. has taken 3 enclosures with equipment plugged into them, possibly including your server — we cannot check it.”

Mr. Ostroumow said that the F.B.I. was only interested in one of the company’s clients but had taken servers used by “tens of clients.”

The LA Times also has good coverage:

“FBI was interested in one of our clients and in his servers, but they took besides target servers tens of not related servers of other customers,” [Ostroumow] said.

As far as I know, my single DigitalOne server was among those taken by the FBI (which I’m now calling “stolen” since I assume it was not included in the warrant). I’m assuming this because it became unreachable and stopped sending updates to my internal monitoring system at approximately the time that the FBI raided the datacenter, and has not come online again since then.

The server was used as a MySQL replication slave, handling read-only queries to speed up the site. Instapaper suffered no downtime as a result of its theft andno data has been lost, but site performance has been slower without it.

Instapaper’s main host, SoftLayer, responded quickly to an order I placed to replace this server there. It’s almost completely set up, and the site’s performance should be fully restored by tonight.

What the FBI stole from Instapaper

I didn’t own the hardware — I was leasing it from DigitalOne. So the FBI has only stolen my time and a partial month of hosting fees, not any physical property of mine. (The hardware was pretty expensive to DigitalOne, though: each of these servers probably costs $5,000–8,000.)

Possibly most importantly, though, the FBI is now presumably in possession of a complete copy of the Instapaper database as it stood on Tuesday morning, including the complete list of users and any non-deleted bookmarks. (“Archived” bookmarks are not deleted. “Deleted” bookmarks are hard-deleted out of the database immediately.)

Instapaper stores only salted SHA-1 hashes of passwords, so those are relatively safe. But email addresses are stored in the clear, as is the saved content of each bookmark saved by the bookmarklet.

The server also contained a complete copy of the Instapaper website codebase, but not the codebase of the iOS app.

Linked Facebook, Twitter, or Tumblr accounts only store their respective OAuth keys. Linked Evernote accounts only store the Evernote email-in address. Linked Pinboard accounts, however, store plaintext usernames and encrypted passwords, and the encryption keys are present in the website source code on the server.

So the FBI now has illegal possession of nearly all of Instapaper’s data and a moderate portion of its codebase, and as far as I know, this is completely out of my control.

Due to the police culture in the United States, especially at the federal level, I don’t expect to ever get an explanation for this, have the server or its data returned, or be reimbursed for the damage they have illegally caused.

UPDATE: Fortunately, I was wrong about one of those: The server has been returned. Please read.

I’m really not sure what to do about this. I’m speaking to my lawyer about it shortly, but as far as I know, there’s nothing I can reasonably do without spending more money, time, and stress than I can afford on a path that would likely lead nowhere productive.

DigitalOne’s response

DigitalOne hasn’t handled this well. Nobody from the company has contacted me at all since this began. The company’s website is still down, suggesting that they might not have any backups (or at least don’t care enough) to set up a temporary page elsewhere. I have no idea whether I’ll ever see the server again, whether I’ll be reimbursed for the remainder of the month that I’m not receiving the service I paid for, or whether I’ll be billed on July 1 for the next month of nonexisting service.

It’s also possible that miscommunication or a lack of communication from DigitalOne caused the FBI to be so imprecise in what they took. Nobody really knows except DigitalOne and the FBI, and neither are being particularly helpful.

Regardless, I’m not hosting any servers at DigitalOne in the future, and I’m not renewing this one (if that ever becomes possible).




Primer  Anterior  2 a 11 de 11  Siguiente   Último  
Respuesta  Mensaje 2 de 11 en el tema 
De: Merendina Enviado: 13/07/2012 04:55
Inquietante sempre più inquietante. 

Respuesta  Mensaje 3 de 11 en el tema 
De: emme Enviado: 13/07/2012 05:17
minchia! così lungo manco in italiano lo leggerei che dice? rincara la benzina? crolla la fiducia dei consumatori? berlusconi ha un sondaggio che lo vede in campo al posto di tiago silva?

Respuesta  Mensaje 4 de 11 en el tema 
De: Merendina Enviado: 13/07/2012 05:57
dice che, se lo vuoi leggere, te lo traduci sennò vola leggiadro verso altri lidi... 
la potenza della libertà individuale

Respuesta  Mensaje 5 de 11 en el tema 
De: Peterpan® Enviado: 13/07/2012 06:53
In sostanza dice che Franchino è stato scelto come nuovo addetto stampa dell'FBI. Poi, vabbe', in questi casi la fanno sempre lunga: una notizia che potrebbe durare una riga te la fanno di due pagine, un po' come gli articoli sportivi o quelli politici.

Respuesta  Mensaje 6 de 11 en el tema 
De: Peppe Gioacchin Enviado: 13/07/2012 07:12
Il sogno proibito dei capi dell' FBI, o della CIA o di qualche altro Cattivo Istituzionale (ma il KGB esiste ancora o è diventato una bocciofila?) credo sia un UNICO ENORME SERVER mondiale, contenente in base a leggi, regolamenti e trattati ogni e qualsivoglia dato, sensibile e non, di chiunque...
 
...per potere, in ogni momento, alla bisogna, farsi i cazzi di chiunque in vita sua si sia connesso almeno una volta!
 
Inquietante?  Ehm...  confesso che nun me ne po' frega' de meno....

Respuesta  Mensaje 7 de 11 en el tema 
De: Peterpan® Enviado: 13/07/2012 07:40
Ma guarda che in pratica già ci stiamo, in questa situazione. Anzi, non ricordo quale autore di thriller tecnologici affermava che i nostri PC vengono utilizzati a nostra insaputa per svolgere dei calcoli, ossia una parte di essi, che per un ente qualsiasi sarebbero troppo dispendiosi in termini di tempo: indi per cui ti entrano nel sistema e tu involontariamente dai loro una mano (gratis, tra l'altro).
Il problema comunque esiste e non esiste: i servigj segreti, quando ben bene hanno controllato per un periodo per es. Phalla, immagino (voglio sperare) dirigano la loro attenzione su qualche obiettivo più importante, che so, la com di Franchino (segretissime ricette per gli spaghetti cacio e pepe!)...


Respuesta  Mensaje 8 de 11 en el tema 
De: Peppe Gioacchin Enviado: 13/07/2012 07:53
andrà a finire come nelle Regie Questure Italiche, dove si accumulano fin TROPPI DATI (i dati degli inquilini...  o dei clienti degli alberghi) e poi ci si accorge che non ci sono i soldi per pagare quelli che dovrebbero fare i controlli...  quindi i controlli non si fanno

Respuesta  Mensaje 9 de 11 en el tema 
De: Peterpan® Enviado: 13/07/2012 07:59
Ma da fonti ben introdotte so che è in corso uno stretto monitoraggio degli autori di ricette cacio & pepe nelle loro varianti.

Respuesta  Mensaje 10 de 11 en el tema 
De: Merendina Enviado: 13/07/2012 08:04
Sai cos'è l'app iCloud? 
Io ho tutti i mezzi, quindi, se mi permetti mi inquieta, sto fatto 


Respuesta  Mensaje 11 de 11 en el tema 
De: Peppe Gioacchin Enviado: 13/07/2012 08:16
e tu Merendina archiviacisivi soltanto le ricette (per esempio: spaghetti cacio e pepe),  i dati sensibili e riservati archiviateceseli nel cerebro, che dovrebbe essere inaccessibile agli hacker della Spectre


Primer  Anterior  2 a 11 de 11  Siguiente   Último  
Tema anterior  Tema siguiente
 
©2025 - Gabitos - Todos los derechos reservados