Seems like the original author is only commenting on Reddit. It's surprising that this was posted to /r/Anarchism instead of a bigger subreddit like /r/tech or /r/politics. That makes me think that the original leaker was already involved in the /r/Anarchism community in some way.
Interesting comments from the author on the Reddit thread:
"""
Not just replying to you, but directed at everyone that'll say I should've leaked it to some organization and that it's 'irresponsible' to dump the raw data on everyone or something:
I'm unconvinced that news stories about government's surveillance capabilities are actually effective in fighting those systems of control. Listening to stories all day about how we're all being hacked and spied on just feels disempowering. When everyone can participate it's more empowering, more fun, and far more effective. Gamma deliberately avoided storing identifying information about their customers, the customers I've managed to identify so far are from looking at the metadata in the documents they sent finfisher support staff and other mistakes they made. The more eyes looking at it, they more we'll find. I want the researchers at citizen lab and elsewhere who have been researching finfisher attacks to use this data in whatever way it'll help them. I want whoever wants to try their hand at forensics to be able to look through it and find what they can about Gamma's customers. I want programmers, hackers, and reverse engineers to have access so they can analyze the software and take it apart. In enabling people with diverse talents to actively participate in the research, we can hopefully develop a better understanding of the tools, organizations, and methods of operation involved in these attacks so that those targeted can actually defend themselves, not just read headlines about how powerful the organizations targeting them are. I want everyone having access to the data, not just the headlines! Seed the torrent!
"""
"""What rechelon said about the EFF. They're reformist lawyers that do some good work, but are terrified of anything too radical or illegal. There's no way they'd touch this, they aren't wikileaks. In the unlikely event that I ended up on trial for this, EFF probably wouldn't even help with the legal defense. They help with some hacking related cases like weev's or DeCSS, because those cases were on the edge of the law and legal precedent was being set. The EFF does not defend computer hackers if it's not setting legal precedent and aligning with their reformist goals.
"""
It'll be very interesting to see how this aspect plays out. I expect "anarchist hacker" headlines before long.
I wonder if those passages are enough to perform style analysis. reddit doesn't let us search comments, but we know they're a member of /r/Anarchism. These parts seem identifying to me:
* Capital letters and proper punctuation. Investigating the source code shows that they one-space.
* Single quotes, not double quotes, around individual words.
* Repetition in triplets with a serial comma ("...more empowering, more fun, and far more...", "...programmers, hackers, and reverse engineers...".
* No semicolons, sparing use of exclamation points at the end of comments only.
* Always uses contractions.
With further analysis we could probably find regional dialects, average sentence length, rate of punctuation use, etc. Crawling /r/Anarchism with that criteria could identify them.
Pure guesses and speculation follow: the hacker probably posts comments on /r/Anarchism. With 50,000 subscribers, there may be about 5,000 commenters. Of those, perhaps 80% of them put one space after a period. So, with only that criteria, we've reduced the anonymity set to 4,000 people.
For what it's worth, I commend their efforts (and am seeding the hell out of the torrent) but think it was a serious mistake to make a post announcing it. They should have posted it on major sites anonymously, not pseudonymously. To post prose online risks being identified by stylometrics or things like time between key presses, etc. (Perhaps these could be defeated by copy and pasting to and from Google Translate.)
Or you could do like the post itself suggests: If you're going to try your hand at forensics, why not dig into that 40GB data dump, see what you can find out this Gamma/Finspy business.
Sure it's interesting to figure out who hacked/leaked all this data. But in the same sense, it's extremely counterproductive to do so, if you agree in any way that it is wrong what this company is doing, collecting and selling 0day malware kits.
(hmm, for some reason I missed your last paragraph, so the above doesn't really apply to you. however the point still stands for others / in general)
If someone is going to try this, be sceptical of the results. We do not know for sure they're a member of /r/Anarchism. If you run the analysis only on the members of that subreddit, you'll only get "the member that writes most like the leaker".
Sorry to burst the bubble but you can't rely on the result of this kind of analysis. Identifying people through their writing style isn't new, and you don't know they haven't already done a prior analysis and ensured their writing style doesn't identify them (or maybe matches to someone else on /r/anarchy).
Things that can be faked have every chance of being faked. Especially when it comes to hackers who need to cover their tracks daily.
I'm happy that he shares my exact point of view on this.
Apparently it's okay for anyone to just build up a suite of security penetrating software, call yourself a 'security company' and sell it on the open market. You will just get money thrown at you by governments and voila, there's your profit. Now just keep all the exploits you find private and rake in the millions. (100 clients in their database, times at least 1.5 million. You do the math)
The only thing we 'geeks' can do against this is tear this apart whenever it leaks, submit the relevant bugreports to the companies that are exploitable and hope for quick patches. It's an insane world we live in.
Footnote: I do not condone or promote hacking websites and then leaking data like this, but I have a strong feeling that this hacker just used SQLMap on their site (judging by the fact that there's no sql injection prevention at all in the code)
HBGary also got social-engineered with emails to an oversees sysadmin. At that point they already had used some relatively minor security exploit, then used the social-engineering to escalate privileges further.
(this is from vague memory, I may have gotten some details wrong here)
Then it seems very much that FinSpy uses GNU libGMP on its source code, right?
If that's the case, aren't they obligated by law and license to release the relevant source code of their system to the public under GNU v3 or GNU v2 licenses?
To further specify: The GPL states that the recipient of the software has a right to also get the source. The public is simply not a recipient of the software.
They only have to release that particular source code and any changes they have made. They aren't obligated to release anything related to or using that code. Essentially it just means they need to provide links to download either the original code if they haven't changed it or provide the source if they have altered it.
That's only if it's the LGPL and they modified the original library. If It's GPL licensed, then yes, if someone asks for the source code, they have to make it available.
Interesting comments from the author on the Reddit thread:
"""
Not just replying to you, but directed at everyone that'll say I should've leaked it to some organization and that it's 'irresponsible' to dump the raw data on everyone or something:
I'm unconvinced that news stories about government's surveillance capabilities are actually effective in fighting those systems of control. Listening to stories all day about how we're all being hacked and spied on just feels disempowering. When everyone can participate it's more empowering, more fun, and far more effective. Gamma deliberately avoided storing identifying information about their customers, the customers I've managed to identify so far are from looking at the metadata in the documents they sent finfisher support staff and other mistakes they made. The more eyes looking at it, they more we'll find. I want the researchers at citizen lab and elsewhere who have been researching finfisher attacks to use this data in whatever way it'll help them. I want whoever wants to try their hand at forensics to be able to look through it and find what they can about Gamma's customers. I want programmers, hackers, and reverse engineers to have access so they can analyze the software and take it apart. In enabling people with diverse talents to actively participate in the research, we can hopefully develop a better understanding of the tools, organizations, and methods of operation involved in these attacks so that those targeted can actually defend themselves, not just read headlines about how powerful the organizations targeting them are. I want everyone having access to the data, not just the headlines! Seed the torrent!
"""
"""What rechelon said about the EFF. They're reformist lawyers that do some good work, but are terrified of anything too radical or illegal. There's no way they'd touch this, they aren't wikileaks. In the unlikely event that I ended up on trial for this, EFF probably wouldn't even help with the legal defense. They help with some hacking related cases like weev's or DeCSS, because those cases were on the edge of the law and legal precedent was being set. The EFF does not defend computer hackers if it's not setting legal precedent and aligning with their reformist goals.
"""
It'll be very interesting to see how this aspect plays out. I expect "anarchist hacker" headlines before long.