Hiding your identity from casual observers: trivial.
Hiding your identity from scrutiny by local law enforcement: straightforward.
Hiding your identity from scrutiny by federal agents: Tricky.
Hiding your identity from scrutiny by an international investigation after having pissed off several high octane intelligence agencies: impossible.
Not impossible in the strictest since, but highly improbable. Even Bin Laden went down and he had a lot more on his side than all of the members of lulz and anon combined.
Snitching. It really isn't that hard to remain anonymous, as you said. But if you're spending hundreds of hours working on Ops with a small team, you learn to trust them and you slip up and share personal information. When somebody slips up, the cops threaten to drop the hammer unless they give up the rest. A 17 year old kid isn't going to risk his whole life for somebody he's never even met, so he snitches.
LulzSec isn't anything new, this kind of hacking has been going on since the 80s - they've just taken a different approach with the media. And snitching is always how hacker groups fall.
This is essentially how all law enforcement investigations work, actually. Drugs, hacking, graffiti, white collar crime, whatever. Get a good snitch and you'll get the whole organization eventually.
Taking all the precautions necessary and doing it consistently while not talking/bragging about it to outside people requires a lot of discipline. Most of these guys do no really have it. It takes few rounds of arrests, trials etc for the core group of survivors to get actually paranoid smart enough.
I would imagine it is pretty hard to make no mistakes. He might have accidentally logged into his twitter account (or some other account known to be his) through the wrong browser, which allowed them to see his real IP address.
I don't think it's anything technical, just the same old tactics they use against any other criminal organization.
Catch a weak link, offer them a deal in exchange for information that leads to the conviction of someone higher up in the organization, repeat until you make it to the top.
Comments
I'm curious what led to all the arrests. It's not that hard to hide your identity if you truly want to be anonymous.
Hiding your identity from casual observers: trivial. Hiding your identity from scrutiny by local law enforcement: straightforward. Hiding your identity from scrutiny by federal agents: Tricky. Hiding your identity from scrutiny by an international investigation after having pissed off several high octane intelligence agencies: impossible.
Not impossible. Very burdensome and lonely, but not impossible.
Not impossible in the strictest since, but highly improbable. Even Bin Laden went down and he had a lot more on his side than all of the members of lulz and anon combined.
Snitching. It really isn't that hard to remain anonymous, as you said. But if you're spending hundreds of hours working on Ops with a small team, you learn to trust them and you slip up and share personal information. When somebody slips up, the cops threaten to drop the hammer unless they give up the rest. A 17 year old kid isn't going to risk his whole life for somebody he's never even met, so he snitches.
LulzSec isn't anything new, this kind of hacking has been going on since the 80s - they've just taken a different approach with the media. And snitching is always how hacker groups fall.
This is essentially how all law enforcement investigations work, actually. Drugs, hacking, graffiti, white collar crime, whatever. Get a good snitch and you'll get the whole organization eventually.
"Would you have sex for $5?" "No" Would you have sex for $500?" "Maybe" "Would you have sex for $5,000,000?" "Yes"
Everyone succumbs (snitches) with the right encouragement (threat)
Taking all the precautions necessary and doing it consistently while not talking/bragging about it to outside people requires a lot of discipline. Most of these guys do no really have it. It takes few rounds of arrests, trials etc for the core group of survivors to get actually paranoid smart enough.
I would imagine it is pretty hard to make no mistakes. He might have accidentally logged into his twitter account (or some other account known to be his) through the wrong browser, which allowed them to see his real IP address.
I don't think it's anything technical, just the same old tactics they use against any other criminal organization.
Catch a weak link, offer them a deal in exchange for information that leads to the conviction of someone higher up in the organization, repeat until you make it to the top.