XMR is accepted at based.win/ for those who shop with excellent OPSEC
@tuckvison Жыл бұрын
hey man I'm sorry but crypto makes you look kinda gullible and not actually educated about technology -- it makes it so incredibly difficult to continue respecting your opinions on technology as "informed" so I'm starting to lose my reason to keep checking this channel. I don't think it's possible to simultaneously understand blockchain technology and also have faith that crypto can ever be useful or ethical.
@SgtPiper Жыл бұрын
Can you please make it so i can use the website with the LibreJs Extension
@zanez7953 Жыл бұрын
@@tuckvison Money isn't ethical. Money is just a tool.
@johnarnold893 Жыл бұрын
@@tuckvison Teaching people to avoid getting caught by the FBI should be a criminal offense too.
@rj7250a Жыл бұрын
@@johnarnold893 Ok glowie.
@boody8844 Жыл бұрын
This is probably the funniest / dumbest opsec mistake I have ever seen
@moncef2466 Жыл бұрын
The Silkroad one is even sillier in my opinion
@fort809 Жыл бұрын
@@moncef2466 Ross’s situation was funny, but this was just absolutely retarded
@TwistedMe13 Жыл бұрын
Ulbricht will probably take the corrosive exploding cake on multiple counts for Amazingly ABYSMAL OPSEC for all time to come: kzbin.info/www/bejne/m4KVgI2BntmFrcU Why (FOR HEAVEN'S SAKE WHY?), when the FBI comes to your doorstep demanding to know why you were sent several forged IDs do you think it a good idea to hawk your illicit goods website?
@thehonkening1 Жыл бұрын
SWIM is competely innocent, here is his email. Again this is totally NOT ME.
@connoisseurofcookies2047 Жыл бұрын
Back in... 2015. He was 12/13 lol
@___gg421 Жыл бұрын
This really helps my imposter syndrome. If Pom can hack the fbi but fuck up this hard I can do anything.
@jjjj-x9g Жыл бұрын
He probably wanted to get caught or got too cocky. He's said in the past that the FBI can easily get him if they wanted to.
@TrevoltIV Жыл бұрын
@@jjjj-x9g He knows he's young and the example has already been made with this stuff, so he won't get much time if any at all, probably probation. But he also knows he will get fame from this and maybe even turn it into a legal revenue source. I don't think it's unlikely he wanted to be caught, but it's 50/50
@johnarnold893 Жыл бұрын
@@TrevoltIV Best thing the prosecutor could do is as for 10 years at hard labour. No different than robbing a bank.
@TrevoltIV Жыл бұрын
@@johnarnold893 prosecutor can lower charges and do better. I know because it happened to me. Although his case is federal so it’s a bit harder
@levelup2014 Жыл бұрын
@@TrevoltIV lol what did you do mr hackerman
@Joerje Жыл бұрын
Massive skill issue
@MentalOutlaw Жыл бұрын
ikr, firstname_lastname_DOB@gmail.com gonna go register a hackerman account with that LOL
@nuip7936 Жыл бұрын
@@MentalOutlaw imagine
@justspltoon Жыл бұрын
Bros just bad
@helicocktor Жыл бұрын
@@MentalOutlaw this is literally a copy of the top comment on your last video on this a week ago... don't encourage reposters smh This is where the fun begins :)
@highcaliberkaos7758 Жыл бұрын
GG; and not good game lol
@qmac9966 Жыл бұрын
They not even gonna turn him into a informant because his OPSEC is so bad 💀
@MRJMXHD Жыл бұрын
Lmaooo
@MentalOutlaw Жыл бұрын
this, maybe he can plea his sentence down by snitching, but he ain't getting a job with the feds after
@KangMinseok Жыл бұрын
@@MentalOutlaw someone this young hacking an FBI email server is still impressive. He can hack a Chinese government mail server, OPSEC is something they can provide him with. What I'm trying to say: The three-letter agencies don't hire people based on how well they can run away, but based on how much damage they can do.
@bsame Жыл бұрын
You honestly think the people that caught him have better opsec?
@long-hair-dont-care88. Жыл бұрын
@@MentalOutlaw you ever seen with your own eye's the opsec of government employees lol he's good.
@ThunderLiege Жыл бұрын
Funny to think that I probably had better OPSEC than Pom as a 12 year old deciding to make an email for Roblox without my personal info in it.
@pedrovitor8909 Жыл бұрын
Lol i laughed hard at this
@sa1t938 Жыл бұрын
to be fair, pom was ~12 or 13 at the time he DMd his email
@bsame Жыл бұрын
@@sa1t938 no he wasnt
@martini380 Жыл бұрын
@@sa1t938 The breach took place in 2017, so he was like 14-15+
@saamdotexe Жыл бұрын
@@martini380 The conversation is from Nov 2020 though
@24680kong Жыл бұрын
I always wonder how much of the "bad opsec" we see in court documents is real, versus just what they submit to the court to secure an arrest warrant. If they use a backdoor or an exploit, they can more easily identify perpetrators, but they won't want to have to reveal the exploit in court. So once they've identified the person, they can monitor them until they can find some smaller crime to execute the initial warrant.
@cybercrime_ Жыл бұрын
They do
@alternateperson6600 Жыл бұрын
I could fathom that happening; though it'd be unnecessary in this case since the FBI didn't really need any exploits to identify the dude - as they'd found his personal email within the RF leaks.
@Guna89420 Жыл бұрын
Kind of like how abc agencies would use stingray to gather info illegally, but they know they cant use it, so they use the information they gather illegally to catch them doing something lesser which they in turn use to get "legal" access to the info they rrady obtained illegally. I believe there was a case a while back where the accussed knew that they were 100% secure in their communications and the only way the agency could have the data they had was through illegal interception. So the case was dismissed. But they never stopped doing such illegal activites. Anyone in a position of authority should have constant surveilance and total transparency around their actions. As there is far to much makebolence and corruption in gov agencies and law enforcement. These perpetrators who think they are above the law will not be able to hife their secrets forever. Their minds are sick with power. There are truly good people out there but those in power try and rstionalize their actions by thinking, everyone else would do it too. But thats far from the case. They are afraid of letting anyone with morals into the mix. They make sure they take them to their after parties or private islands and test newcomers depravity. All while filming them to make sure they are implicated if they ever step out of line. Its a big group and we aint in it. I wouldn't ever want to be in it either. They don't see others the same as a normal person. They look at us as cattle. So if you think the gov will help you or feed us in times of desperation than we are hopelessly fooled. Weakened just like China wants us to be. As we were sold out as a resource a long time ago. I look at the debt clock for canada and i sure as hell have never had that much debt. Shit, my reparations of 5$ every other year hasn't had inflation accounted for in its inception. Over 100 years ago that was the price. Canada has defaulted on the payments they owe constantly. Canada was also a 99 year lease. The lease is not only up but was voided when the gov began to take control of our freedoms and try exterminate my peoples cultures by genocide and attacks on our longhouse ceremonies by the RCMP in the 50s and 60s. Then the residential schools and tearing children from their families. This wasn't all that long ago either. Rap1ng and mutilating children for their own sick n twisted desires, those are the supposed "men of god" that so many worship. Many were shipped over seas as tortutre toys for a certain famous family. Im sure we can all guess who. There is much truth to be told. Its up to us good like minded people, those with true love in our hearts to come together as the rainbow nation and prevail against those who oppress others for their own gain. Instead of all working together to lift eachother up. We can lift all of humanity to new heights of advancement where all can prosper and still maintain a 7 generation guarantee. Which means we take care of our mother earth and her resources so that 7 generations down the line mother earth will still be bountiful and all nations able to thrive together. At the rate and state that these "world leaders" have us in now-a-days, we will be lucky to make it 3 more generations before all is poisoned beyond repair. 😢 I have faith that us people with strong morals and love in our hearts and mind can prevail. But we are going to need help from each other. Let us come together and reach our potential!!!
@dafoex Жыл бұрын
I think some of the Snowden revelations talk about exactly this, with some cases being dropped entirely because they didn't have any evidence that didn't reveal the existence of rogue cell towers.
@run3676 Жыл бұрын
Those techniques are pretty sophisticated, quite rare or even non-existent. Dude was a kid who ran a forum... That's overkill and nobody's going to risk burning that for nothing.
@MillywiggZ Жыл бұрын
This is the e-mail equivalent of going to a store, buying something you’re embarrassed about then saying; “… errr. This is for my… friend.”
@Criticalmaze Жыл бұрын
10:12 How else are you supposed to avoid this? You get a static ip adress assigned to you by ur isp. What does he mean by same ip adress in the vpn?
@km077 Жыл бұрын
No, no: "a friend", that way they will never know it's YOUR friend and therefore cannot link them to you directly. Using "a friend's friend" is usually an overkill, but provides the best Op-Sec on the planet and further. Even MiB could not have found me since '97. Trust me, bro.
@ShowtimeAtWaco5 ай бұрын
@@Criticalmaze He is saying if you connect to a VPN, then log into some l33t hackerman forum, then use the same VPN connection to access personal accounts connected to your true identity then you’re making it stupidly easy to get caught
@nyekomimi Жыл бұрын
Can we at least agree that his hacker nickname was unironically, positively adorable
@zrIywcN8XJdHaY13K3tx Жыл бұрын
yeah, like a japanese sh
@netherworldfiend5 ай бұрын
yeah I mean he was literally named after a Sanrio character xD
@Crumb Жыл бұрын
Just goes to show when you get involved with online crime you're playing for keeps. Everyone thinks they're the perfect one, infallible, Michael Jordan's of the internet. But everyone is capable of making elementary OPSEC errors, that leave permanent consequences. It just takes one mistake for the glowies to get you. He honestly had one of the shortest affidavits I've read, usually they've collected a lot more information. Probably partly due to a rushed case though. Not surprised, was just a kid after all.
@kahok5ownage Жыл бұрын
Holy shit? It’s the legend Crumb!
@GFunkEra1992 Жыл бұрын
????
@fort809 Жыл бұрын
yeah everyone is capable of making a stupid opsec mistake, but signing into raid forums with his personal Gmail genuinely makes me wonder if Pom was lobotomized
@Vanlifecrisis Жыл бұрын
I dunno, if i was running some forums like that id better turn into edward snowden quick af.
@_wayward_494 Жыл бұрын
@@fort809 seriously can you even call that a stupid mistake at that point? Beyond regarded
@hmngghh Жыл бұрын
.... i don't even know what he was thinking, how did he type what he typed out and think "hm yes, totally believable, I somehow pulled out an email with a full name and DOB that doesn't appear in the data breach, but I somehow found it, someway, while knowing it was in the breach. Foolproof plan."
@ravindur3825 Жыл бұрын
keep in mind he is only 20 years old, he also believed putting "living in tokyo" in his bio tricked people
@hmngghh Жыл бұрын
@@ravindur3825 20 year olds should know way better than that, imo
@ravindur3825 Жыл бұрын
@@hmngghh yeah, tbh thats true. especially for him... i mean he "hacked" the FBI lmfao
@cheedozer7391 Жыл бұрын
Smoking that PomPom pack 🌬️ I'm glad he was so dumb.
@lukasgelu1834 Жыл бұрын
@@ravindur3825 Age is no excuse for making such a bad mistake.
@sharpieman2035 Жыл бұрын
3:21 Lmao that’s hilarious, one of the dumbest “asking for a friend” instances out there
@featheroml Жыл бұрын
Even though I’m not fits Gerald in any way shape or form, here is a email that wasn’t in the database!!
@mrkiky Жыл бұрын
My name is definitely not Fitzpatrick and no way in hell is my first name Conor heheh.
@Tophatjones358 Жыл бұрын
I thought this wasn’t real when I first saw it… like what the hell was this dude thinking?? I’m sure the first rule of hacking is to remain anonymous. Ouch, big time!
@featheroml Жыл бұрын
@@Tophatjones358 it literally is! 😂 if criminals actually used their brain they wouldn’t have been caught so easily. Sending your email WITH YOUR FULL NAME is so bad
@zilaz Жыл бұрын
@@featheroml its not real, the feds found him with some other surveillance they cant / dont want to disclose publicly, but to arrest him they set him up with stealinf his credentials etc.
@unnamed1479 Жыл бұрын
Mind boggling how poor this kids OpSec was. How long was he running breached for again? I wonder if they even give him a deal to work with the feds considering how many blunders he made. Also, while I'm at it finally commenting on one of your videos, I want to thank you for putting out consistently high quality content for as long as you have. Without your videos, I wouldn't have found my love for Linux, and would still be using Microsoft Winblows
@typicalmountainbiker Жыл бұрын
Pompompurin created Breached Forums around a year ago. People flocked to the site because he had been around on Raid Forums for years with a stellar reputation. I have no idea how they didn't catch him sooner. Even among cybercriminals that has to be one of the worst blunders I've ever seen.
@ReXoRofc Жыл бұрын
And he sacrificed... HIS FREEDOM!!!
@Guna89420 Жыл бұрын
@@UCp6Q6LE7IYCO yw mr FBI agent. We've reverse triangulated your home. 😉
@JJFX- Жыл бұрын
@@typicalmountainbiker I'm sure they could have but the feds collect everything they can to ensure cases are essentially bulletproof. It also gives them time to monitor related activities. Imagine the feds realizing, "Oh wow this kid doesn't have a clue what he's doing... should we go get him?" "Nah, let's see what else he'll lead us to.".
@bsame Жыл бұрын
Simp
@shodanargie1574 Жыл бұрын
He really tried the "asking for a friend"
@halcyonacoustic7366 Жыл бұрын
The original "in minecraft"
@whothoughthandleswereagoodidea Жыл бұрын
These court documents are really good at showing you how to do better opsec, and also proves (to me at least) that you're basically never gonna win.
@kenosabi Жыл бұрын
Yeah honestly if the gov wants to give it to you they will. If your deemed "important enough" your on borrowed time.
@TruthDoesNotExist Жыл бұрын
not true, the government obviosly doesn't talk about it much but there are many smart criminals that the government can't catch. they just get the low hanging fruit like this idiot
@klaykid117 Жыл бұрын
Very unfortunate to hear about the victim's suicide where he crashed his car off the road, then dragged himself 3 miles into the woods and shot himself three times in the back of his head and a bear or Something must have taken the gun and the casings
@louisazraels7072 Жыл бұрын
@@kenosabi well yeah, it's a combination of good opsec and low profile. If this guy had decent obsec they probably wouldnt have bothered, he didnt do anything too subversive
@beverly9486 Жыл бұрын
The hacker community might have to make a “10 OPSEC commandments” 😂
@DrilonLaCosta Жыл бұрын
There are plenty of them on dread 😂
@username---------- Жыл бұрын
Dual Core - Hack Commandments yw
@beverly9486 Жыл бұрын
@@username---------- 🤝
@BoleDaPole2 ай бұрын
What are the 10 Hack Commandments?
@madezra64 Жыл бұрын
I would argue 80% of all 'hackers' aka script kiddies, have mostly bad to no OPSEC. It takes a lot of effort and awareness to continuously live two entirely separate lives. It's also extremely easy to get complacent with these things. Without any warning or obvious signs to get your attention once you've fucked up, you start to feel affirmed that your blunder will just fade off into the ether. "Oh well, data retention sucks for a lot of companies, that shits probably long gone by now...". Proper OPSEC is a livelihood, a lifestyle, a way of life. You don't just practice good OPSEC, you fucking LIVE good OPSEC. You separate your public life from your OPSEC life 100% top to bottom with no compromises. If you slip up, it's time to go scorched earth and deactivate for a long time. It's very draining to switch back and forth. Laziness is OPSEC's worst enemy.
@luszczi Жыл бұрын
You would all probably do something equally stupid just this once when at your laziest / least attentive. Staying vigilant at all times is not easy.
@sharpieman2035 Жыл бұрын
Oh I 100% would. But that’s why I’m not out here becoming a notorious cybercriminal. If you’re going to do that type of thing, maybe you should know that you need to be that type of vigilant beforehand.
@jjjj-x9g Жыл бұрын
No.
@kemosabe1313 Жыл бұрын
I dont even use my real name/number nor my real address (I use the abandoned house at the end of the street) for grubhub deliveries
@walterclements2228 Жыл бұрын
That's why you don't create an online persona if you're a cybercriminal, you're basically grouping all the stuff you've done, and when you make a mistake (because you will make a mistake) they will charge you for everything because you've already made the glowies' work for them
@eezyville1704 Жыл бұрын
The safest thing you can have is a split personality
@lekhakaananta5864 Жыл бұрын
The key here is that Pompom didn't expect the private message to become non-private in his threat model. The chances are extremely low that the person he was directly talking to would try to ID him based on a hunch that conorfitzpatrick was his actual email. I'd wager that if he knew that other people would have eyes on that message he wouldn't be so lazy. He didn't expect the authorities to hack his forum and read all the records, which is the real mistake.
@mrkiky Жыл бұрын
Yea the other guy aka the owner of RaidForums who was an even bigger moron.
@Mayhzon Жыл бұрын
There is some poetic justice in this. He hacked the FBI / FEDs and they hacked him back. Moments like these make me realize the world really does run on equivalent exchange rules often enough. You get what you give.
@qunas101 Жыл бұрын
He still linked his hacker identity to a real email account, even if it's private messages, who knows who is sitting on the other end
@lekhakaananta5864 Жыл бұрын
@@qunas101 It's definitely a risk, but then again everything has a risk and/or cost. I still think that practically speaking, if we assume the message was never leaked, this would be in the realm of reasonable opsec. All security is a trade-off between security and convenience. He probably thought that the risk wasn't high enough to justify using more time and effort to find another email or ask his question in a different way. After all, he had a reason to talk about the email in the first place; he was trying to evaluate the quality of the data, which probably had significant monetary value to him.
@twotimer222 Жыл бұрын
I see what you’re saying, it makes Pom seem a bit less stupid to me. Still, any relevant person on that site should’ve instinctively known in their head “Never ever post my real name or real email on this site under any circumstance”
@decayedargon6765 Жыл бұрын
Apparently, the hacker's password was 'password.' Who knew they were taking security tips from a '123456' kind of person?
@PD_CĪPHĒR Жыл бұрын
"thats the code on my luggage"
@hallowseve58015 ай бұрын
How do we know about that?
@fluffypinkpandas Жыл бұрын
sometimes when you think you are at the top you begin to assume there is nowhere else to go but down. Thats when you get cocky and start acting a few levels below yourself. Almost wondering if deep down, you SHOULD get caught.
@yuke... Жыл бұрын
corny
@bsame Жыл бұрын
this reads like a bad haiku
@rollerskdude Жыл бұрын
Very true to real life unfortunately. I've experienced this first hand.
@MindZye Жыл бұрын
I always looked at "have I been pwned" as being something where I can enter my info, and expect it to be pwned shortly after.
@Kaz-qz2oq Жыл бұрын
If only he'd watched a channel called "Mental Outlaw" featuring videos about how to become anonymous on the internet
@jayl3840 Жыл бұрын
or "The Hated One" channel.. that guy is also top notch for this kind of content
@UseSomeSense Жыл бұрын
The real reason he got caught cause he committed a crime, criminals often get overconfident after getting away, as a result they start making mistakes. This is how most criminals get caught, besides the nowadays undercover agents are a trend, like there's one undercover cop in every city acting like a common civilian.
@cherubin7th Жыл бұрын
Love how pompom tried to use the strategy of hiding in the light, by using his real email and saying it is someone's email he found. It did fail though.
@madezra64 Жыл бұрын
Would've worked if he just PGP encrypted his messages lmao! Still absurdly retarded though.
@keylowmike85 Жыл бұрын
I really had to fight the urge from saying "he got caught because he wasn't careful" when reading the title. However, as I keep watching the video I kept thinking "I'll take The Most Reckless Hacker for 500, Alex!" JEEZ
@Margen67 Жыл бұрын
Penguins need HUGS
@rdqsr Жыл бұрын
Between pirates and hackermen, I can't tell who has worst opsec. I still remember when KAT got taken down because the admin was logging into his account via the same IP he used for Facebook and iTunes.
@incremental_failure Жыл бұрын
Proper pirates don't deal with torrents and the opsec is much better.
@afinelad3673 Жыл бұрын
@@incremental_failure >don't deal with torrents What? What do they use?
@ominous_Hash Жыл бұрын
@@afinelad3673 they live in third world countries where they can't worry about piracy
@kemosabe1313 Жыл бұрын
@@afinelad3673 the retail employee who smokes behind the store
@fishimun7138 Жыл бұрын
@@afinelad3673 chests laden with booty
@SagaEf Жыл бұрын
_"so my friend has this girl he likes"_
@therealcouchpotato9560 Жыл бұрын
The PomPomPurin saga has been my favorite anime in a long time.
@Elijah_Lopez Жыл бұрын
This guy really did the asking for my friend meme. I'm glad the FBI can actually perform these investigations. This was a really informative video. Learned a lot more about OpSec. Good reminder that using a VPN all the time to have two different identities is a weakness.
@mistermorphescarnoe2898 Жыл бұрын
And yet... we still are unable to capture the elusive hacker known as 4chan !
@Mayhzon Жыл бұрын
Are we? I'm sure the strategy they drive with 4chan is just more cost-efficient. Have the place fully diluted with BBC (not the media company) and c(d)uck pron posts. Also 4chan is interesting because it represents a sort of hive mind that has weaponization potential. I'm pretty sure they could have shut it down a long time ago. They don't because it's a hot bed for social engineering and experimentation. They also take some inspiration from it for spreadability of messaging. I have recently seen a lot of advertizement following imageboard meme schematics.
@mistermorphescarnoe2898 Жыл бұрын
@@Mayhzon Yes, I meant the original statement in pure jest, since a lot of coverage on them has been taking a stance against them that seems more serious than they actually are, 4chan when compared to RAID or Breach are nowhere near as damaging (to someone's privacy, security, etc) but they pretty much consist of radical members of society who aren't necessarily the best hackers, but have been proven to be relentless when they want to.
@fabianweber69378 ай бұрын
When can we finally sleep in peace again 😔
@planetjanet3845 Жыл бұрын
If only he had known grep has trouble with unreadable characters. He should have run the file through strings first.
@mskiptr Жыл бұрын
Why would there be some invisible characters within an email address?
@planetjanet3845 Жыл бұрын
@@mskiptr within the text file
@mskiptr Жыл бұрын
@@planetjanet3845 yeah, but if you're grepping for part of an email address, it will be in a continuous chunk of that file, right?
@mskiptr Жыл бұрын
@@planetjanet3845 So, I did the following experiment: for i in {0..255} printf \\$(printf '%03o' $i) >>file.txt echo -n FoobarBaz >>file.txt for i in {0..255} printf \\$(printf '%03o' $i) >>file.txt grep -i bar file.txt grep: file.txt: binary file matches So even when the text you're looking for surrounded by all possible ASCII characters, grep still works. I won't claim it does every single time, but I still don't see any reason why it shouldn't.
@planetjanet3845 Жыл бұрын
@@mskiptr I just know from experience, grep won't be able to find text I know to be present in a file unless I run it through strings first. I'm not sure what makes it give up, whether it's a certain quantity of unreadable characters or only certain specific characters.
@rothn2 Жыл бұрын
Hackers get decision fatigue like everyone else it seems
@Mayhzon Жыл бұрын
@Andai "Hello sir. It has come to our attention that you have been a very naughty boy online. We have thus planned your next butt whooping session. Kind Regards Your local law enforcement institution"
@machenka Жыл бұрын
It would be interesting to hear your take on how he should have acted in order to minimize the risk of being caught. Of course he shouldn’t have used his own email as an example in the first place but apart from that a walkthrough of each opsec error linked to what he should have done, eg. using different IP’s, Tor etc, would be quite interesting imho. Great video as always! 👍
@jayl3840 Жыл бұрын
well for starters he should have gone and bought a buner phone with cash from something like craigslist and then used burner SIM cards to activate ..but the key is to never take the burner phone home nor have it by your personal phone at all.. this will give you 2 seperate identities that would be very hard to link if done right
@drifter402 Жыл бұрын
So it's impossible thanks
@Dafty2k Жыл бұрын
@@jayl3840 yeah but the phone isnt that important here tho 🤷♂🤷♂
@j-elly. Жыл бұрын
As an average racercar jonnie, even I was AMAZED that my boy did this. That's a pretty bad mess up.
@rideroftheforce5245 Жыл бұрын
Whenever somebody on Breached would scam somebody Pom would often post the scammers IP address, which always made me suspicious of Breached OPSEC. It meant that he kept some kind of log, and turns out to have been true.
@rars0n Жыл бұрын
I've never understood why people wouldn't take advantage of the anonymity of email and NOT use personally identifying information RIGHT IN THE USERNAME. These kids have probably never even heard of Kevin Mitnick.
@JackieJKENVtuber Жыл бұрын
I know I asked about this on the comments of the last video but please make a video about what isn't bad opsec; is it possible to have a life and still have good opsec? How can you keep your personal and "work" life separate when you don't live alone (i.e. live with relatives or are married)? Who can you trust (if at all, since in an investigation folk can be easily manipulated into saying something that can be useful to the glowies)? You mentioned creating faraday cages with aluminium foil, but what if someone finds out you do that? Are they not a security vulnerability? Please check my comment on your last video, it's a lot more complete in what I am really asking
@smthng Жыл бұрын
check out the OpSec Bible for 2022 (or sth like that), it's another video of his that basically covers everything you asked for, and then some. Search on his channel and I think you'll find it. :)
@mrkiky Жыл бұрын
If you don't even have your own place, I think you can forget about navigating the "seven seas" 😂
@Crazy--Clown Жыл бұрын
Why don't you watch Darknet OPSEC Bible 20022 Edition........... You might learn something
@Mayhzon Жыл бұрын
Good opsec would be keeping everything separate and reducing vectors for attack. You have one machine you use for accessing ordinary life. Another machine everything else. This second machine should run a custom linux build tailor-made for your usage by handpicking the things you need. It should not use Intel chipset technology (all three, Intel hardware, Windows and Apple software are compromised by the American Hegemony). Furthermore, everything to your second persona has to use separate e-mail accounts, connect through VPNs from off-continental influence zones and use as little of your personal data as humanly possible. No checking reallife stuff with this second setup or vice versa. Mix-ups straight forbidden. This way you reduce attack vectors. As with everything, 100% security does not exist and never will. This communication technology we all use was granted us by the higher powers and thus they came up with it and know how to control it. So it's a matter of Risk + Effort vs Reward + Priority. If what you do is low value, nobody will bother checking your stuff or bother putting together a court case. If you are of high prolific criminal activity like Pompom, dumb enough to piss off papa government on purpose (hacking their agencies, constantly disparaging their efforts somehow) or are of geopolitical significance, no amount of security will be enough to save your sorry hide from the eventual consequences indefinitely.
@SR-ti6jj Жыл бұрын
These are my favorite kind of videos you make. Great "what not to do" guides
@tux8664 Жыл бұрын
Please do a video on RESTRICT act. It needs to be known, and everybody just thinks of it as "the bill that bans tiktok"
@fisiek_ Жыл бұрын
Im not even a criminal but have better opsec than pom
@no-name1.612 Жыл бұрын
"Im not even a criminal" sounds like what a criminal would say
@aboyaser5608 Жыл бұрын
@no-name 1.6 You might've even caught Bahamut himself!
@ts7901 Жыл бұрын
@@aboyaser5608 The FBI are already on that one dw
@yuanjv Жыл бұрын
my opsec is as bad as pom but im not crimal lol
@fisiek_ Жыл бұрын
@@no-name1.612 I would never ever commit b&nking fr&ud, wtf yt filtered my comment
@superdanyal2009 Жыл бұрын
Poms opsec is probably on par with Ross and most other extremely dumbass mistakes people make in cyber security, it's entirely attributed to ego, especiallly black hats. Infosec and opsec go hand in hand. As someone in cyber security (the blue team) I like baiting pentesters, black hats, asking my friends to hack me lol etc (as counter intuitive as it sounds it really helps people understand computers not just for pentesters but for me analysing vulnrabilities software or hardware, it helps us both improve, but this is extremely hilarious for so many reasons to me. When I saw him trolling "vinny" and beefing with cyber security experts (looool) it was only a matter of time before he got caught, that's not how you act if your doing something illegal, in summary, he was an idiot. Regardless, it's extremely hard to have good opsec in any 14 eyes, if 1. you live there 2. target the people associated within them, even if you didn't and commited enough big of a cyber crime uncle sam will kidnap you out of Iran, they don't care
@kemosabe1313 Жыл бұрын
Vinny from vinesauce?
@MarioGoatse Жыл бұрын
How so? Ross Ulbricht was only connected to his real name through a single slip up years before Silk Road was popular where he made a forum post “advertising” the site. The FBI found the very first mention of it online, and that lead to his arrest. This is 20x the amount of information leaked in a very short amount of time, with multiple different forms of ID.
@superdanyal2009 Жыл бұрын
@@MarioGoatse Ross legit went on the clearnet promoting the site silkroad (extremely conspicuously even that would be an understatement) which is what got him on the alphabet boys radar to begin with, using his real name on an email, what makes his opsec possibly even worse is that they were able to estabilish a very concrete link to the point even aristotle would've walked out the courtroom.
@MarioGoatse Жыл бұрын
@@superdanyal2009 He made a single forum post way before a site like Silk Road was even considered possible to be successful. It was a massive shot in the dark, so I can understand a young guy that isn’t a hacker so doesn’t have the best OPSEC yet, making a forum post to ask if anyone knew anything about “this new website”. Compared to this dude who should have already been on extremely high alert due to being a hacker and having been a former user of raidforums that had been taken over by the authorities. There’s a bit of a difference between the two as Ross could not have predicted that Silk Road would have been as popular as it was, whilst Fitzpatrick was actively hacking sites and wasn’t even using a VPN. Ross messed up once early on. Fitzpatrick messed up consistently and continuously. That’s the point I was trying to make.
@twotimer222 Жыл бұрын
@@superdanyal2009In ross’ defense, he literally made the first Bitcoin darknet market in history, he had no idea how big it would become or how much attention it would attract from the feds, there was no precedent for him to learn from. in the beginning he probably saw it as an obscure secret drug market for geeks and thought the boomer feds might not even catch onto it. Plus he didn’t advertise Silk Road with his real name email in the post, he used the username altoid which they linked to another post that had his real name email. His opsec was bad but Pom’s was just ridiculously bad, especially with the 100x extra knowledge of opsec you’d expect a cybercriminal to have compared to back then
@valdimer11 Жыл бұрын
We always have this romanticized idea in our heads that hackers are these brilliant computer geniuses that can never be caught and if they do it's like you said, the FBI must've had to dedicated a mountain of resources and time to finding this super evasive, super smart hacker. But no....more often than not...not at all. It's interesting as well because as you sift through the evidence you see pompom become a little better at what he is doing but his old mistakes are basically a permanent footprint.
@LucasCunhaRocha Жыл бұрын
just like Al Capone, it is always easier to get criminals on the small/dumb stuff than the big stuff.
@CoasterMan13Official Жыл бұрын
In these trying times, yacht rock provides an escape from all that.
@andrerenault Жыл бұрын
SAIIIIIILIN’ TAKES ME AWAAAAAAY
@lv1543 Жыл бұрын
I love yacht rock on sirusxm
@TylerDurden-up8hz Жыл бұрын
He is a cyber criminal not a hacker, it's not the same
@logans3365 Жыл бұрын
Was wondering how someone seemingly so skilled could get caught by the feds, he might as well just sent them a formal email admitting to his crimes
@xtremememestv1717 Жыл бұрын
If I had to guess, bro had an off day. If you doing shit like this tho, you can’t afford an off day
@GrimMetropolis Жыл бұрын
This kid is pretty good at customer service. Good on em. Hope he finds a passion in business
@SearedBite Жыл бұрын
let's be real, if they had some kind of back door they're not going to just say "we found it from a back door" they would make a fake story like this
@jayl3840 Жыл бұрын
nah they would just redadact how they did it or say they used special techniques or something like that .. this was flt out just lazy and bad OPSEC
@Mayhzon Жыл бұрын
@@jayl3840 Yep. They would take the chance to brag a little. After all they already have agents on the Joe Rogan podcast doing so. "Look at this amazing power we wield and what we can do with it." They must have been pretty disappointed in how they caught up to this Pompom guy. Easy pickings, didn't even have to start up any of their high profile software tools.
@0xKilty Жыл бұрын
It makes you think how people like this don't get caught sooner
@jjjj-x9g Жыл бұрын
Because the feds monitor them after finding out to stack up evidence. It's not like they raid them a day or even a week after figuring their real info out.
@kahok5ownage Жыл бұрын
I’m sure the FBI has to build a case, and also a hub for this activity really routes traffic to an east to monitor place for the fbi. I’m sure they let this stay up strategically.
@jjjj-x9g Жыл бұрын
@@kahok5ownage I just said that
@tzardnickolasthelitromanov Жыл бұрын
It's a combination of both incompetence (in some cases) and Strategical waiting in other cases, as feds will never pro-actively get (or stop) the offender during a crime (or even a series/multiples of them). They'll wait till a stack of crimes have been committed before they then bust ya.
@bsame Жыл бұрын
its all a psyops
@tedbear631 Жыл бұрын
I think this would make for a good spin off video on best practices for OPSEC not for hackers but just for Privacy advocates and people sick of Google and Apple and Big Brother spying on you 24/7. I think this would be interesting and make for a cool video!
@Vanlifecrisis Жыл бұрын
When this new law passes, just attempting to have privacy will be punishable with 20 years.
@jayl3840 Жыл бұрын
Ahh yes the RESTRICT ACT - that shit is terrifying
@ManskiTheRed Жыл бұрын
We need an Intro to Opsec course lol. Teach all the youngsters what they need to do
@SR-ti6jj Жыл бұрын
Most intelligent Windows user right here. Spends a paragraph explaining how he's confident that the grep command indeed works. Good stuff lol
@dafoex Жыл бұрын
Baph and Pom's opsec seem to be worlds apart, so whatever comes to replace BreachForums will likely be much harder to take down
@bogdanraczkowski7994 Жыл бұрын
Man do I love the bad OPSEC videos. I'm no expert but they are funny as hell.
@kulled Жыл бұрын
its funny because the first video i ever saw from you was the one explaining how tor users got deanonymized because of bad opsec
@NotFeelingBlauw Жыл бұрын
Bro. I love pompompurin (the Sanrio character) to the point I have a tattoo of him. I also work in cybersecurity. Finding out about Pompompurin is one of the wildest crossovers to me
@Sentient.A.I. Жыл бұрын
I am glad i never went to any of these forums. Who would of figured the opsec on a hacker site is less than kindergarten level. Damn i got a separate computer and vpn just for watching movies i don't even do hackerman type activities anymore and haven't in 20+ years
@solumyt Жыл бұрын
This did make me laugh, but thinking about the digital footprint I left on the internet as a teenager is pretty concerned... am I permanently screwed?
@traxx75 Жыл бұрын
Damn...laziness I can get, not everyone wants to bother with using five different email addresses, multiple phones, VPN and all that. But come on man, you were the leader of THE biggest hacker forum on the internet...at this point I think the guy had just no self-preservance, given that he admitted everything to the cops as well XD
@LucasCunhaRocha Жыл бұрын
the worst part is that he was using Apple shit, he was asking to get caught.
@traxx75 Жыл бұрын
@@LucasCunhaRocha Should have used Tails OS...XD
@kevynfernandezdelarosa1225 Жыл бұрын
FBI really said: "this you?"
@fireworm91 Жыл бұрын
People gets comfortable... It's same with tools... once you're not scared of getting hurt... you're getting screwed
@krewetko Жыл бұрын
Well,PomPomPurin is 20-yers old (today is 2023) He reveals his email on forum at 2020 (17 y. old) What are you waiting from a teenager ? of course he did so idiotic mistakes,many of them,because of lack of experience and knowledge on his dangerous way on the dark side of internet that requires paranoiac caution
@ForestOfSleep Жыл бұрын
I have no words. If you're doing illegal shit, don't get lazy.
@popcornto6032 Жыл бұрын
It seems that it's inevitable that a hacker would be caught, because when learning or doing "beginner hits", of course his OPSEC wouldn't be perfect, so even if he became very good in due time, he would still leave behind him a trail of mistakes from when he was less experienced? What am I overlooking? I'm a Windows peasant so I don't know anything, so tell me.
@pleonexia4772 Жыл бұрын
You're right. That's why it's important to keep making new and separate sandboxed accounts
@popcornto6032 Жыл бұрын
@@pleonexia4772 what are new sandboxed accounts?
@roastyou666 Жыл бұрын
@@popcornto6032basically the rule is to never create a trace by always using a throwaway account or preferably never appearing (unless you need to make transactions, which is very risky)
@halcyonacoustic7366 Жыл бұрын
@popcornto : sandboxed means isolated and separate. It makes it a lot harder to screw up by accident.
@popcornto6032 Жыл бұрын
@@halcyonacoustic7366 how does a separate account make it more difficult to screw up? Or do you mean a new seperate account for everything regularly such that old mistakes can't be linked to new ones?
@skii_mask_ Жыл бұрын
omg he really tried the "asking for a friend" strat.
@Spolt_main Жыл бұрын
I have a better separation of daily life and my ph activity than this guy does in his felonious hackerman activities.
@Tubeytime Жыл бұрын
I recently sent an email full of nsfw subreddit links to a customer support email for a company that sells security cameras (instead of myself). Followed up with "Sorry! Wrong address!" then started rapidly deleting contacts to prevent autofill from screwing me over again.
@Spolt_main Жыл бұрын
@@Tubeytime I accidentally clicked cast one time. Swear to god the worst idea anyone has ever had.
@herrwoland3500 Жыл бұрын
First I was like "15mins? ain't nobody has time for that" and here I am grinning throughout the whole video not even feeling the time. Great job, thanks for the video!
@carroton Жыл бұрын
high iq opsec moment
@user-se3sq3ek1r6 ай бұрын
Reminds me of how most car accidents happen close to home because people let their guard down after getting used to driving the same path everyday.
@supernovaw39 Жыл бұрын
When I started using a VPN I at first had a bit of a guilty feeling accessing Google, KZbin, etc from the VPN's IP for having established a theoretical connection between my identity and other things I look at on the internet. But I'm not wanted by the FBI for having ran illegal websites or anything, but damn, to have such a shitty OpSec, all while having so many glowing enemies AND living in the United States? You'd expect more from a hacker this famous. Like at least routing everything through TOR and having a separate device or at least a VM that is only for his anonymous activities.
@stvpls Жыл бұрын
to me he deserves his jail sentence like all the hackers on his forum that steal people's data
@BB-nn9en Жыл бұрын
I got a question. How is this different than MS or google scanning your emails, stealing your password, and then unencrypting your files with it? I never authorized them to steal my passwords or unencrypt my documents with them. Are they selling passwords too? Seems no different than what they were doing on the forums.
@rejvaik00 Жыл бұрын
Goes to show that pom pom won't be useful to the FBI at all 🤣
@thehonkening1 Жыл бұрын
11:50 lmaoo, great summary. Never backdoored CPUs. Always just the low hanging fruit 😂
@ismbks5 ай бұрын
let's be honest good opsec is very hard, you need schizo awareness to never make a single mistake
@nekosh1ru Жыл бұрын
you should cover the new restrict act, its hilarious
@nogr3369 Жыл бұрын
Crazy how much data they were able to get to trace back to him
@deordered. Жыл бұрын
There are a lot of developed tools by the glowies that we have no idea about
@EricLopushansky Жыл бұрын
@@deordered. This doesn't even use them lol.
@deordered. Жыл бұрын
@@EricLopushansky lol
@MRJMXHD Жыл бұрын
When the feds come for you, they usually have unbreakable proof 😭
@leftyonthenet Жыл бұрын
They say we need cops, and yet we have criminals doing shit like this.
@sideeggunnecessary Жыл бұрын
Oh so you think the fbi deserves it's security? B-b-bootlicker 🤡
@MarioGoatse Жыл бұрын
What kind of backwards logic is that?? It was the cops (Feds) who worked out what this criminal was doing, so maybe you do need the cops if you want to arrest people like him. Your logic would make sense if it wasn’t the police that found out all this information.
@araa5184 Жыл бұрын
This has the same feeling as the "I am asking for a friend" sentence 😂
@0xCAFEF00D Жыл бұрын
10:50 Of course this isn't good, it allows for additional connections once suspicions are raised. But practically any VPN user can be accused of sharing an IP with a hacker over a single day. Likely there's a couple gmail logins that fit this exact profile. Not saying this is safe, but if this alone would bring him down the US has kinda fucked up laws. They'll jail innocents.
@ginichimaru001 Жыл бұрын
VPN doesn't even keep you safe if you think about it, its gotta be preloaded the moment you open a device up to the Internet or else the download becomes associated with your iP and you permanently end up on some kind of list for just having a vpn on your device.
@aaronnikels5706 Жыл бұрын
That’s what I’m saying. The fact that both logins share the same IP doesn’t mean shit if the IP belongs to a VPN server. I mean it’s circumstantial evidence at best
@Herr4dler Жыл бұрын
Damn... I did not expect Trent Reznor to have such a bad OpSec. It was a terrible lie.
@JabbaTiure Жыл бұрын
Pompompurin gave himself what is called a Philadelphia Footlong.
@Jorn-sy6ho2 ай бұрын
Such good content! Very educational ❤
@deforged Жыл бұрын
5:20 no. it's not an "uncommon thing" to try to search for yourself in data breached. what IS fairly uncommon among anyone that has a "little bit of CyBeR SeCuRiTy knowledge" is to use their own *actual* name in any online identities they create.
@armmelon327 Жыл бұрын
Tbh most of us created these emails when we werent knowledgeable on online security.
@deforged Жыл бұрын
@@armmelon327 that's one of the things you do once you learn about online security - you completely sever you previous identity from any further activity going further. meaning that any accounts with the older/tracible one is burned.
@jonathanclark3337 Жыл бұрын
Don't you just love how if corporate profits are threatened the FBI is all over it but if 1000s of people get scammed they do nothing.
@nathanielmarshall9895 Жыл бұрын
In all fairness, the database breaches do affect thousands of people as well. Individuals that get scammed often are high profile targets or people who blindly click on links and/or use vulnerable software or fall for the usual scams. I'm more upset with mega corporations still having databases breached and my online passwords showing up in them.
@regarded9702 Жыл бұрын
He really thought he was smart. "I won't provide my personal details but here is someone else's I have that definitely isn't me." It must be devastating for that to be the reason it all comes crashing down.
@halcyonacoustic7366 Жыл бұрын
That detail helped them a lot, but ultimately, it wasn't necessary to catch him. The ip email account mixing was just as bad.
@specthegod Жыл бұрын
Please make more Good OPSEC videos! If "hackers" lack having them then awareness about it is vital for all... like that epic OPSEC Bible 2022 video you made... not for criminal activities but any average joe who does not want a 3lettered private part up in his privacy... and again PLEASE message me MO, I need to get a hold of you and there doesnt seem to be a way.
@fruitbleedjuice Жыл бұрын
lmao drain gang always shows up in the funniest places
@1val Жыл бұрын
fr
@BatkoNashBandera7745 ай бұрын
I don't comprehend how electric signals via wire -> ie internet
@understatements Жыл бұрын
imagine trolling the fbi and having a terrible opsec, funniest shit rip bozo
@useodyseeorbitchute9450 Жыл бұрын
I'd generally consider trolling your local security agency as bad idea. If someone could not resist the temptation, he should at least be annoying for security agency from different a continent.
@weirdsciencetv49997 ай бұрын
Hackers that don’t even know how to use TOR. Pretty low bar to be a considered a hacker these days
@fordprefect8235 Жыл бұрын
1:36 PomPomPurin confirmed as drainer
@alexanderSydneyOz Жыл бұрын
11:48 Question. Where the Google and Zoom accounts were both accessed from the same IP address, that was the VPN IP address. Surely, that IP address would be used by many different people, right? Which is the whole point of a VPN. So how could any inference be drawn from that? I assume I am missing something.
@aaronnikels5706 Жыл бұрын
Yeah I really don’t know what Mental Outlaw is on about for that point. Plenty of OPSEC mistakes were made by Pom, but I hardly think the incident of a VPN gateway IP being used for two separate accounts at different times constitutes as evidence to link one to the other. They could very well be different users
@e-maxwell Жыл бұрын
>Wintoddler >iToddler He was asking for it
@elite3221 Жыл бұрын
Is debloated windows that bad? I debloated mine so what's wrong with it? For Iphone it's obvious not going to bother asking
@Ginfidel Жыл бұрын
@@elite3221 There's nothing wrong with Windows once you tear the spyware out of it. MO and a portion of his fanbase are just hardcore FOSS supremacists and like to shit on proprietary software, as if source code is some kind of holy grail and reverse engineering doesn't exist. Don't get me wrong, FOSS is king on principal, but I'm not gonna put myself into a box for it.
@TheLakeJake3 Жыл бұрын
New sub, enjoying the content, cheers good sir!
@overcheats4518 Жыл бұрын
RIP PomPomPurin. never forget all they need is you making one little mistake, and all you need to do is never make a single mistake xD
@Iron_Condorr Жыл бұрын
Hey man, you are one of my favorite content creator's 💙 👌 thx
@salpertia Жыл бұрын
Rule 1 if you plan on being hackerman Keep that star rating low
@SeiryuNanago Жыл бұрын
I would expect people who make a business out of exploiting stolen private information to better protect their information. But perhaps I have a poor understanding of tech skills.
@lilliilllil2424 Жыл бұрын
His next name will be: Puri-Puri-Prisoner
@NotSure2020 Жыл бұрын
this pompomeranian reminds me of that Master of Disaster kid from Hackers.