<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Cognitive Dissidents</title>
	<atom:link href="http://blog.cognitivedissidents.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.cognitivedissidents.com</link>
	<description>Joshua Corman&#039;s Security Blog    [opinions may not reflect my employer&#039;s or other affiliations&#039;]</description>
	<lastBuildDate>Fri, 11 May 2012 17:46:06 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.cognitivedissidents.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/99e3b598a63129a37ffb25af28b7551b?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Cognitive Dissidents</title>
		<link>http://blog.cognitivedissidents.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.cognitivedissidents.com/osd.xml" title="Cognitive Dissidents" />
	<atom:link rel='hub' href='http://blog.cognitivedissidents.com/?pushpress=hub'/>
		<item>
		<title>“Building a Better Anonymous” Series: Part 6</title>
		<link>http://blog.cognitivedissidents.com/2012/05/11/building-a-better-anonymous-series-part-6/</link>
		<comments>http://blog.cognitivedissidents.com/2012/05/11/building-a-better-anonymous-series-part-6/#comments</comments>
		<pubDate>Fri, 11 May 2012 13:29:32 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Anonymous]]></category>

		<guid isPermaLink="false">http://blog.cognitivedissidents.com/?p=304</guid>
		<description><![CDATA[Building a Better Anonymous – Details By Josh Corman &#38; Brian Martin 2012 If you are new to this series, please begin with Part 0 and the index. NOTE: We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=304&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<table border="0" align="&quot;“center””">
<tbody>
<tr>
<td>
<p><div id="attachment_306" class="wp-caption alignnone" style="width: 268px"><a href="http://cognitivedissidents.files.wordpress.com/2012/05/joker_fawkes-small.jpg"><img class=" wp-image-306  " title="joker_fawkes-small" src="http://cognitivedissidents.files.wordpress.com/2012/05/joker_fawkes-small.jpg?w=258&h=405" alt="Guy Fawkes Joker (Artwork by Mar - sudux.com)" width="258" height="405" /></a><p class="wp-caption-text">Guy Fawkes Joker (Artwork by Mar &#8211; sudux.com)</p></div></td>
<td>
<p><div id="attachment_305" class="wp-caption alignnone" style="width: 268px"><a href="http://cognitivedissidents.files.wordpress.com/2012/05/anonymous_batman.jpg"><img class=" wp-image-305  " title="anonymous_batman" src="http://cognitivedissidents.files.wordpress.com/2012/05/anonymous_batman.jpg?w=258&h=405" alt="Guy Fawkes Batman (Artwork by Mar - sudux.com)" width="258" height="405" /></a><p class="wp-caption-text">Guy Fawkes Batman (Artwork by Mar &#8211; sudux.com)</p></div></td>
</tr>
</tbody>
</table>
<h2>Building a Better Anonymous – Details</h2>
<h3>By Josh Corman &amp; Brian Martin</h3>
<h3>2012</h3>
<p>If you are new to this series, please begin with <a title="“Building a Better Anonymous” Series: Part 0" href="http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/" target="_blank">Part 0</a> and the index.</p>
<p><strong>NOTE:</strong> We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. Please comment toward improving/clarifying the content.</p>
<h3>Building Upon the Foundation</h3>
<p>Previously, <a title="“Building a Better Anonymous” Philosophy" href="http://blog.cognitivedissidents.com/2012/04/12/building-a-better-anonymous-series-part-5/" target="_blank">we outlined a method for creating a new foundation</a> for Anonymous or similar groups. The proposed foundation is based on defining explicit goals, a code of conduct, and streamlining the process. Here we further flesh out “streamlining”. A key element to &#8220;building a better&#8221; Anonymous is that of a defined path of conflict escalation. Until Anonymous, or any other activist group, adopts that principle we&#8217;re stuck with a relatively chaotic group of actors that frequently negatively impact government, business, and society – often without even meeting their own goals. In this article, we will focus on a few of the group&#8217;s key areas for improvement, and detail why it is critical for them to change. As with many causes, it is inevitable that perceived unjust laws will eventually be broken to achieve a stated goal &#8211; a matter of &#8216;when&#8217;, not &#8216;if. A better and more impactful group would see this as a last resort – and then only when justified by its just first principles.</p>
<p>As it stands, the group Anonymous has demonstrated they are a force to be reckoned with, or least respected. Whether that respect is based on fear or admiration simply doesn&#8217;t matter right now, although respect should ultimately be earned. It is also clear that, for better or worse, the group is not going to disappear any time soon. While law enforcement and corporations struggle to come up with plans for dealing with them, Anonymous will continue on, evolving as needed.</p>
<p>One thing society cannot do is ignore the group. Ignoring their activity, even in mainstream or social media coverage, will not make them go away. Insulting or dismissing the group will only provoke some of them. Thus, the logical route is to not only talk about the group, but to do so in a constructive manner. This may be counterintuitive to some professionals, especially ones that maintain any positive attention is a &#8220;BAD THING®©™&#8221;. That thinking is archaic and <a title="Optimism Bias" href="http://en.wikipedia.org/wiki/Optimism_bias" target="_blank">dangerous</a>.</p>
<p>Having discussions about making a perceived adversary better or more difficult to deal with may initially seem unreasonable. In reality, those discussions are equally beneficial to the persons that must deal with the adversary. Anticipatory and proactive thinking leads to creating defenses and solutions before problems become unmanageable. In this case, a discussion on improving Anonymous not only helps to prepare, but hopefully serves to influence Anonymous members to achieve their goals in a manner that creates less collateral damage. That is a win for all sides of the equation.</p>
<p>For Anonymous, this article should appeal to their rational self-interests. Improving their methodology and philosophy will help them improve their batting average, so to speak. Rather than &#8216;striking out&#8217; so often in the eyes of the public, more operations and activities will appeal to more people and have more lasting effect. Operations that can be accomplished without breaking the law and/or with minimal collateral damage will help deflect/reduce law enforcement attention. Further, an improved group will help to quell infighting and potentially increase the quantity and quality of the recruiting base.</p>
<p>Finally, if the last paragraphs did not appeal to a rational side, let us warn the rest of you. This type of thinking is not new. Anonymous, and the next group similar to them, are always thinking of ways to improve. It is human nature, and it cannot be avoided. In short, this article and the rationale behind it is a reality, you must deal with it. If you’re still not sure you want a “better” Anonymous, would you prefer a worse one?</p>
<h3>Collateral</h3>
<p>One of the most damning weaknesses of Anonymous is the disparity between their intended targets and actual victims. When striking out at an entity that has wronged the public, it is critical that the attack affect them, and only them. This is probably the single biggest mistake Anonymous continues to make, and it increasingly hurts their cause and lessens public support each time it occurs. Rather than being supported for what they do, they are branded as criminals and terrorists, instead of the Robin Hoods many members see themselves as. Time after time, Anonymous ends up hurting the public as much or more than their intended target, when leaking user and customer data. While this shows a level of insecurity in their target, the end result is that the average citizen is hurt. For the user who just had their personal information leaked, that is what they will remember; not the purpose of the &#8216;Op&#8217; or what the target did wrong.</p>
<p>Looking at recent news, the list of Anonymous activities that resulted in the disclosure of user / customer information is depressing. These include <a href="http://www.sott.net/articles/show/241456-US-Hacker-Group-Anonymous-Claims-it-Broke-into-Alabama-Government-Websites-Stole-Personal-Info" target="_blank">attacks against law enforcement</a> that also disclosed citizen information in an amnesty program for outstanding municipal offense warrants, a protest against Bay Area Rapid Transport (BART) that also <a href="http://news.cnet.com/8301-1023_3-20092221-93/anonymous-defaces-bart-site-leaks-user-data/" target="_blank">leaked MyBART.org customer data</a>, dumping information of <a href="http://www.cyberwarnews.info/2012/02/19/la-business-connect-hacked-exposed-data-leaked-and-taken-offline-by-anonymous/" target="_blank">LABusinessConnect.com members</a>, as well as posting the e-mail addresses and passwords of <a href="http://writerspace.com/" target="_blank">Writerspace members</a>. These are not government employees, military soldiers, or law enforcement. These are regular people caught up in Anonymous&#8217; war on anything that strikes their mood. Often times, Anonymous will compromise a site, view the data, and only afterwards come up with a justification for their actions (e.g., LABusinessConnect.com lead them to find information on an &#8216;adult staffing&#8217; firm).</p>
<p>Moving forward, a better group must remove the collateral damage from their operations. If a site is compromised and (if) data must be leaked to prove a point, do it in a fashion that only hurts the intended target. For example, dump the technical information on the system and the first 50 user/customer records, but redact the information to protect them. Leak enough information for a journalist to be able to validate the operation, but not enough to make the users victim of identity theft or harassment. This will force the company or agency&#8217;s hand in improving security and force them to follow data breach laws, while still ultimately achieving your goal. Even this point assumes that such a breach is even necessary or the most impactful way to achieve your objectives.</p>
<h3>OpSec: Social Media Cuts Both Ways</h3>
<p>Social media is perhaps the most powerful weapon in Anonymous&#8217; arsenal. It gives them access to millions of people for real-time updates on activity and propaganda. In some cases, social media is used to organize and coordinate operations. In almost every case, it is then used to disseminate information about the target and the reasons for the activity. Without these platforms, Anonymous would be completely at the mercy of journalists who dug for information and opted to write about them.</p>
<p>In the digital world, where anonymity is crucial to daily operation, social media platforms like Twitter, Facebook, or Tumblr are also a recipe for disaster. These &#8220;free&#8221; services operate because &#8220;If you are not paying for it, you&#8217;re not the customer; you&#8217;re the product being sold&#8221; (<a href="http://www.metafilter.com/95152/Userdriven-discontent#3256046" target="_blank">source</a>). Aggregated data on social media users is a powerful tool in the hands of advertisers and law enforcement. For every Facebook post, for every Tweet, for every word choice or manner of typing… a better social profile can be built on those participating. These profiles are the first line of investigating who is behind an online identity. With the <a title="Mugshots" href="http://cognitivedissidents.files.wordpress.com/2012/02/anonymous_mugshots-small.jpg" target="_blank">arrests of several alleged Anonymous members</a> over the last year, and <a href="http://www.wired.com/threatlevel/2012/02/anonymous-arrested-interpol/" target="_blank">increasingly larger busts</a> <a href="http://news.cnet.com/8301-30685_3-20070818-264/turkey-arrests-32-after-anonymous-web-attacks/" target="_blank">happening since</a>, it is safe to say that many involved are not practicing good Operational Security (OpSec).</p>
<p>Good OpSec not only involves a wide variety of technical precautions like using proxies and public WiFi, but also involves being extremely careful in what details are included. Seemingly innocuous comments can quickly be turned against a person, especially when considered in the bigger picture. The time of day, mention of weather, connectivity, ISP outages, and other social remarks can be used in conjunction with image meta data, IP addresses, and software choices to narrow down suspects. Once a person is in custody, those same details can help confirm or eliminate them as a suspect. For Anonymous to keep going strong, they must better understand not only OpSec, but how law enforcement works, and what information is made available. As we recently saw, it only takes a <a href="http://www.foxnews.com/scitech/2012/03/06/exclusive-unmasking-worlds-most-wanted-hacker/" target="_blank">single slip up in OpSec to lead to a bust</a>, sometimes as innocuous as <a href="http://nibletz.com/2012/04/member-of-anonymous-arrested-thanks-to-a-picture-of-his-girlfriend/" target="_blank">using a single image</a>.</p>
<p>More important to established members maintaining their own operational security, is that they teach prospective members the same. For example, in 2010, <a href="http://www.theregister.co.uk/2010/05/25/second_scientology_ddoser_jailed/" target="_blank">Brian Mettenbrink was jailed for a year</a> and ordered to pay $20,000 in compensation to the Church of Scientology for his part in Operation Chanology. Later, in the <a href="http://wearelegionthedocumentary.com/" target="_blank">We Are Legion</a> documentary, Mettenbrink explains how he naively downloaded a tool for denial of service attacks, put in an IP, and hit &#8216;attack&#8217;, as instructed by Anonymous. He was not told what the tool did, that he could be easily tracked, or that it had serious repercussions. He is one of many that some see as Anonymous&#8217; <a title="Cannon Fodder" href="http://en.wikipedia.org/wiki/Cannon_fodder" target="_blank">cannon fodder</a>. While some Anon members have tried to help newcomers (e.g., Op Newblood), it is too little and often too late.</p>
<p>Regardless of how good an operative is, they can still succumb to failed OpSec and other elements of social human behavior. The best operatives and groups have been busted or infiltrated, so the goal is to raise the bar for would-be adversaries. Anonymity may have <em>benefits</em> to those who wish to work outside of law, but/and maintaining said anonymity is hard (very hard) and comes with <em>costs</em>. Paying these costs is especially a shame when transgressions were either unnecessary or of lower impact than intended.</p>
<h3>Open Model and Infiltration</h3>
<p>The open model of Anonymous, based on loose collaboration, is a great strength. At the same time, it is also a potentially crippling weakness. Like most things, there are trade-offs. With no real bar for membership, anyone can approach the group through a variety of channels and claim to be a supporter. This creates a perfect avenue for infiltration due to the lack of vetting process. There are at least three distinct times this has been used against Anonymous, whether successful or not.</p>
<p>The most notable occurrence was that of Aaron Barr, ex-CEO of HBGary Federal, who told the media that he had analyzed Anonymous IRC channels along with social media to figure out some of the leaders. Barr began publicizing the information without revealing exact names, leading to an article in the Financial Times. The story of what happened after, and the downfall of Barr, has been <a href="http://www.wired.com/threatlevel/2011/02/anonymous/all/1" target="_blank">well covered</a>, but it reminds us that very basic infiltration led to the reconnaissance.</p>
<p>A second incident, not directly aimed at Anonymous but undoubtedly affecting some members, was <a href="http://gawker.com/5850054" target="_blank">Tom Ryan and Occupy Wall Street (OWS)</a>. Ryan joined a mail list created for the organization and coordination of OWS efforts. With that information, he received a considerable amount of details about protesters, leaders, and more. Ryan leaked those emails to blogger Andrew Breitbart, who subsequently used them in an attempt to brand OWS participants as anarchists. Email is notoriously insecure, both in transit and as a target for hackers to access. Operating a mail list where anyone can join is almost guaranteed to ensure the information is shared with others beyond the list.</p>
<p>The most recent incident led to suspected Anonymous members getting arrested. Police arrested 25 people across four countries in an Interpol coordinated bust of people alleged to have been involved in attacks against Colombian and Chilean web sites. Shortly after the arrests, members of Anonymous in Spain posted a blog saying that the busts were a result of being infiltrated. The blog said that due to &#8220;carelessness&#8221; and &#8220;[giving] personal details to spies and people who were not members&#8221;, the police were able to determine the identity of many members. According to Anonymous, those busted were also all members of an Anonymous site (anonworld.info) created for discussing activities. This does not even begin to address the threat of so-called &#8220;trusted&#8221; members, such as a <em>de facto</em> leader and spokesperson named Sabu, who became an <a title="Sabu LulzSec" href="http://www.foxnews.com/scitech/2012/03/06/exclusive-unmasking-worlds-most-wanted-hacker/" target="_blank">FBI informant for a year after getting busted</a>.</p>
<p>Contrary to the idea of Anonymous, one way to <span style="text-decoration:underline;">help</span> avoid infiltration in the future is to have established and trusted relationships with other members. This should be organized in a decentralized manner where any one member does not know details beyond a few other members. All of this goes back to maintaining good OpSec in order to provide as much protection for those involved as possible. While many anons cherish the open and flat, low barrier to entry, these benefits come too with an upper bound of effectiveness and being prone to infiltration. This doesn’t even touch upon the imposters and <a title="“Building a Better Anonymous” Series: Part 4 - False Flags" href="http://blog.cognitivedissidents.com/2012/03/08/building-a-better-anonymous-series-part-4/" target="_blank">false flags we mentioned in Part 4</a> – nor speak to outside players attempting to steer and manipulate the pack toward their own selfish ends.</p>
<h3>Disinformation; Friend or Foe</h3>
<p>The art of disinformation is versatile. It can tie into proper OpSec, in that providing intentionally misleading or incorrect information can help protect you. Peppering a Twitter feed with subtle, but purposefully crafted &#8216;facts&#8217; about the poster can re-frame and begin to throw off social profilers. Co-opting unsuspecting people to wear the Guy Fawkes mask or replace their Twitter avatar with an Anonymous-themed image can add confusion by giving a wide range of additional targets your adversary must take interest in. Clever campaigns designed to give the illusion that your most outspoken critics are secret members of the group are just the start of how disinformation can become a weapon.</p>
<p>On the other hand, disinformation at the wrong time can completely undermine your efforts and call into question the small bits of integrity you rely on. For example, the <a href="http://www.guardian.co.uk/media/2012/feb/27/wikileaks-publishes-stratfor-emails-anonymous" target="_blank">recent publishing of over five million emails taken from Stratfor</a> was immediately called into question when news of the Stratfor CEO resignation <a href="http://www.forbes.com/sites/andygreenberg/2012/02/27/leak-check-stratfors-ceo-hasnt-resigned-after-wikileaks-release/" target="_blank">was quickly denied by the company</a>. The leaked email claiming the CEO was resigning was likely disinformation, but the question is from whom? If it came from Anonymous, then they undermine their own credibility in what may be an attempt to force the CEO to resign. If it came from Stratfor, then this is a perfect example of how disinformation can be used against Anonymous.</p>
<p>In <a title="“Building a Better Anonymous” Series: Part 5" href="http://blog.cognitivedissidents.com/2012/04/12/building-a-better-anonymous-series-part-5/" target="_blank">part 5</a>, we discuss a new framework for Anonymous or subsequent groups. One of the core strengths of the proposed model is to help a group set forth a statement of principles, code of conduct and operational parameters. With these defined in advance, disinformation used against the group is more easily challenged and refuted. Combating False Flags may become one of the biggest issues Anonymous faces moving forward.</p>
<h3>Ready &#8211; Fire &#8211; Aim!</h3>
<p>The &#8220;hacktivist&#8221; phenomenon of &#8216;belated justification&#8217; is not exclusive to Anonymous. For many years, a wide range of hackers have scoured the Internet looking for vulnerable systems. In many cases, they scan hundreds of thousands of systems looking for a handful of easily exploited vulnerabilities. As they find vulnerable systems, their personal agenda takes over. For some, they immediately look to see if there is a web server running in order to deface the web page. For others, they immediately look to see if there is a trove of sensitive information for personal gain or public disclosure.</p>
<p>Only after that do the hackers justify their actions. If it happens to be a government server, the justification of &#8220;anti-government&#8221; comes easy. In other cases, it may be a stretch, as a mom-and-pop business finds themselves victim to a &#8220;lesson in security&#8221;. These high-level explanations are examples of popular &#8220;go-to&#8221; justifications for criminal activity. Without vetted incident data it is hard to qualify how often this happens, but based on one author&#8217;s personal experience researching and communicating with hackers, this is certainly a prevalent theme over the last 12 years.</p>
<p>Anonymous must consider their targets, and then act. By calling out a company or government body in advance of an attack, it removes any doubt that attacks are <em><a title="&quot;ex post facto” on wikipedia" href="http://en.wikipedia.org/wiki/Ex_post_facto" target="_blank">ex post facto</a> </em>justified or lucky. If there is concern that such announcements may make subsequent attacks more difficult, there are a variety of methods to establish a target was called out in advance, without publication. Sending a letter to a journalist organization that does not typically cover Anonymous related news, or PGP signing a message with a shared key to establish a time/datestamp are both effective without tipping your hand. Over time, this practice has the added benefit of giving legitimacy to the group&#8217;s ability to selectively target and carry out threats of hacktivism. Such a history could conceivably be used to encourage a target organization to “change their evil ways”, in order to avoid an attack that they are sure will succeed.</p>
<h3>“Mercy is for the Weak”</h3>
<div class="wp-caption aligncenter" style="width: 416px"><img class=" " title="Cobra Kai - No Mercy (source mrftw photobucket)" src="http://i83.photobucket.com/albums/j318/mrftw/CobraKai-01.jpg" alt="Cobra Kai - No Mercy (source mrftw photobucket)" width="406" height="675" /><p class="wp-caption-text">Cobra Kai &#8211; No Mercy (source mrftw photobucket)</p></div>
<p>It is not a requirement that anonymous rules with fear and a refusal to forgive. The package deal of these choices may ultimately prove to be self-defeating. Regardless, they clearly have been using fear. Unless Anonymous is falling victim to a case of rhetoric, then those that they oppose are the enemy. As <a title="Karate Kid Cobra Kai" href="http://www.imdb.com/title/tt0087538/quotes?qt0449947" target="_blank">our favorite 80&#8242;s bad guy teaches us</a>, &#8220;an enemy deserves no mercy&#8221;. Anonymous has done a decent job keeping this credo, but it bears repeating. Many will think that disclosing customer records or defacing a web page sends a clear message, or that more prolonged ops definitively state their position. True, perhaps, but <a title="datalossdb" href="http://www.metricscenter.net/index.php/datalossdb.html" target="_blank">preliminary evidence suggests companies quickly recover from breaches</a>, financially speaking. Other than a short term &#8216;win&#8217; in the form of a media black eye, Anonymous needs to keep the pressure on to make their point. Pressure in this case, is still adhering to our previously stated &#8220;defined path of conflict escalation&#8221;, where it does not necessarily mean illegal activity. Lasting changing is more “campaign” than “op”, more strategy than tactic, and will by necessity require the group does “fewer things, better”. Such pressure can be achieved in at least two ways.</p>
<p>First, a given operation against a target should not be thought of with a defined start and end. If a corporation or government agency is doing &#8216;wrong&#8217;, you can be assured they are doing that same &#8216;wrong&#8217; for the long haul. Taking a lump along with their time in the press will pass, and many entities already rely on this fact. Instead, just as the heat seems to die down, Anonymous could hit them again, but harder and longer. Winning a war means a <strong>decisive victory in the eyes of your enemy</strong>. Your enemy must know with certainty that you will be there to punish them day in and day out. Only then, will they consider changing their &#8216;evil&#8217; ways.</p>
<p>Second, the fear of retaliation can be a strong weapon. Anonymous already has an ample history of retaliation, such as their <a href="http://www.huffingtonpost.co.uk/2012/03/01/anonymous-hacks-interpol-_n_1312544.html" target="_blank">attacks on Interpol</a>, <a href="http://www.huffingtonpost.com/2012/02/03/anonymous-boston-police-occupy-wall-street_n_1252718.html" target="_blank">defacement of the Boston Police web site</a>, and <a href="http://www.cbsnews.com/8301-501465_162-57362764-501465/megaupload-anonymous-hacker-retaliation-nobody-wins/" target="_blank">DDoS attacks related to the MegaUpload takedown</a>. Anonymous can benefit from a better public presence regarding this history, along with the promise that more retaliation hacks will occur if organizations do &#8216;wrong&#8217;. Law enforcement won&#8217;t give Anonymous a pass, but they may eventually begin to choose their takedowns carefully, and reconsider the subsequent press frenzy that follows. Corporations that are prone to support <a title="SOPA" href="http://en.wikipedia.org/wiki/Stop_Online_Piracy_Act" target="_blank">ridiculous legislation</a> may begin to reconsider their endorsement of controversial politics. Today, some pockets within Anonymous already <a title="Anonymous Analytics" href="http://www.v3.co.uk/v3-uk/news/2163744/financial-services-firms-fear-shamed-anonymous" target="_blank">enjoy this reputation in some industries</a>.</p>
<h3>Building in Reality</h3>
<p>Along the lines of maintaining good OpSec, Anonymous needs to tap into one of their greatest strengths; numbers. A handful of members doing the heavy lifting with thousands of glorified cheerleaders isn&#8217;t an effective use of support. Strength comes from quality; not just quantity. Tapping into the idea of <a title="#OpNewblood Super Secret Security Handbook" href="http://serpentsembrace.wordpress.com/2011/04/23/the-opnewblood-super-secret-security-handbook/" target="_blank">Operation NewBlood</a> (an operation designed to train new members how to better secure/anonymize their activities), educating members on how to better help achieve goals is crucial. Rather than see the large number of prospective members as cannon fodder, help turn them into members that can contribute more effectively. This is a model successfully used for decades in hacking crews &#8211; where mentoring would both teach you your skills and your code of conduct. As one example, this idea could be leveraged to use hundreds or thousands of people to do remote reconnaissance of a company in such a way that any one person is not breaking a law. Using the combined results, operations can be planned better, attacks can be more precise, and the chance of collateral damage minimized.</p>
<p>Along with training Anonymous members in the ideas of hacktivism, the older members must look at their organization like any other. New users unfamiliar with technology are more likely to blindly install software without considering the risk to themselves, their systems, or their fellow members. In recent months, Anonymous members <a href="http://www.symantec.com/connect/blogs/anonymous-supporters-tricked-installing-zeus-trojan" target="_blank">have been tricked into installing trojans</a> on <a href="http://www.eweek.com/c/a/Security/AnonOps-Says-New-OS-is-Fake-Wrapped-in-Trojans-455613/" target="_blank">more than one occasion</a>. The lack of authoritative information sources for the groups may protect some members, but open the door for a greater number of members to be targeted. These members risk punishment from third parties or law enforcement, and ultimately will end up disillusioned with Anonymous.</p>
<h3>Trailing Thoughts</h3>
<p>These are just examples of issues that Anonymous will grapple with and attempt to manage over time. Looking to improve the effectiveness of any group is a good thing, but mileage will vary by group, sub-group, and operation. If done correctly, the end result will leave the group with all of its strengths, and fewer weaknesses. Most importantly, such changes will do a lot to win the hearts and minds of the public, force targets to take the group more seriously, and ultimately affect more positive change.</p>
<p>Your turn… What would <strong>you</strong> do to make such a future group or offshoot more effective and consequential?</p>
<div id="attachment_308" class="wp-caption aligncenter" style="width: 510px"><a href="http://cognitivedissidents.files.wordpress.com/2012/05/lulzsec-stronger-animated.gif"><img class="size-full wp-image-308" title="lulzsec-stronger-animated" src="http://cognitivedissidents.files.wordpress.com/2012/05/lulzsec-stronger-animated.gif?w=614" alt="Stronger? (Artwork by Mar - sudux.com)"   /></a><p class="wp-caption-text">Stronger? (Artwork by Mar &#8211; sudux.com)</p></div>
<p>Copyright 2012 by Josh Corman and Brian Martin. Permission is granted to quote, reprint or redistribute provided the text is not altered, appropriate credit is given and a link to the original copy is included. Custom graphics courtesy of Mar - <a title="http://sudux.com/" href="http://sudux.com/" target="_blank">sudux.com</a>.</p>
<p>Should you feel generous, please donate a couple of bucks on our behalf to any 501(c)(3) non-profit that benefits animals or computer security.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/304/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/304/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/304/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=304&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2012/05/11/building-a-better-anonymous-series-part-6/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2012/05/joker_fawkes-small.jpg" medium="image">
			<media:title type="html">joker_fawkes-small</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2012/05/anonymous_batman.jpg" medium="image">
			<media:title type="html">anonymous_batman</media:title>
		</media:content>

		<media:content url="http://i83.photobucket.com/albums/j318/mrftw/CobraKai-01.jpg" medium="image">
			<media:title type="html">Cobra Kai - No Mercy (source mrftw photobucket)</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2012/05/lulzsec-stronger-animated.gif" medium="image">
			<media:title type="html">lulzsec-stronger-animated</media:title>
		</media:content>
	</item>
		<item>
		<title>“Building a Better Anonymous” Series: Part 5</title>
		<link>http://blog.cognitivedissidents.com/2012/04/12/building-a-better-anonymous-series-part-5/</link>
		<comments>http://blog.cognitivedissidents.com/2012/04/12/building-a-better-anonymous-series-part-5/#comments</comments>
		<pubDate>Fri, 13 Apr 2012 03:25:19 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Anonymous]]></category>

		<guid isPermaLink="false">http://blog.cognitivedissidents.com/?p=291</guid>
		<description><![CDATA[Building a Better Anonymous &#8211; Philosophy By Josh Corman &#38; Brian Martin 2012 If you are new to this series, please begin with Part 0 and the index. NOTE: We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=291&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_292" class="wp-caption aligncenter" style="width: 355px"><a href="http://cognitivedissidents.files.wordpress.com/2012/04/anonymous-thinker.jpg"><img class="size-full wp-image-292" title="A contemplative Anon (Artwork by Mar - sudux.com)" src="http://cognitivedissidents.files.wordpress.com/2012/04/anonymous-thinker.jpg?w=614" alt="A contemplative Anon (Artwork by Mar - sudux.com)"   /></a><p class="wp-caption-text">A contemplative Anon (Artwork by Mar - sudux.com)</p></div>
<h2>Building a Better Anonymous &#8211; Philosophy</h2>
<h3>By Josh Corman &amp; Brian Martin</h3>
<h3>2012</h3>
<p>If you are new to this series, please begin with <a title="“Building a Better Anonymous” Series: Part 0" href="http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/" target="_blank">Part 0</a> and the index.</p>
<p><strong>NOTE:</strong> We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. Please comment toward improving/clarifying the content.</p>
<h3>Acknowledgements</h3>
<p>Today, Anonymous is both an identity / meme and a &#8220;group&#8221; / organizational construct (albeit amorphous and decentralized). The focus below is not to enhance or augment the identity / meme, but rather the latter. Adopting such enhancements will involve trade-offs &#8211; as everything does. The authors believe many of the current Anons (or would-be-anons) yearn for a larger impact, a better batting average, and to mitigate several complications inherent in the current approach (some of which were explored in <a title="“Building a Better Anonymous” Series: Part 4" href="http://blog.cognitivedissidents.com/2012/03/08/building-a-better-anonymous-series-part-4/" target="_blank">Part 4</a>).</p>
<p>When we define a &#8220;better anonymous&#8221; we realize that this may apply to as few as <strong><span style="text-decoration:underline;">zero</span></strong> of its current participants. It is entirely possible that such an instantiation could emerge in ten years or with people currently unwilling to join the existing ranks. If it helps the reader, picture this &#8220;better Anonymous&#8221; under a different name, taking place five years from now, and sharing no members with current manifestations. While we do believe these refinements and enhancements can and would be of benefit to today&#8217;s manifestation(s) of Anonymous, this is immaterial to the following points.</p>
<p>Since no one &#8220;owns&#8221; Anonymous, and since its ranks are so diverse in ideology and motivational structures, it is best to judge the following ideas on their own merits &#8211; rather than expressing personal preference (positive or negative) for what the increasingly ill-fitting &#8220;they&#8221; would or wouldn&#8217;t like. Some of them will agree &#8211; some will be indifferent &#8211; and some will find these concepts detestable.</p>
<p>For these reasons (and others), we also expect the possibility of plural groups over time &#8211; with plural charters. Put another way, this installment may be less about building a replacement for Anonymous, but rather &#8211; &#8220;building better Anonymi&#8221; &#8211; especially where ideological and topical schisms reveal themselves.</p>
<h3>Laying a New Foundation</h3>
<p>In <em>Leviathan</em>, the philosopher <a href="http://en.wikipedia.org/wiki/Thomas_Hobbes" target="_blank">Thomas Hobbes</a> described the state of nature as a state of war. Paraphrasing slightly:</p>
<blockquote><p>The state of nature is a state of war&#8230; &#8220;and the life of man, solitary, poor, nasty, brutish, and short&#8221;.</p></blockquote>
<p>In contrast, <a href="http://en.wikipedia.org/wiki/John_Locke" target="_blank">John Locke</a> considered the state of nature to be a state of inconvenience and inefficiency. Where they agreed is that out of rational selfish-interest, people must form social contracts to escape the limits of the state of nature.</p>
<p>To date, Anonymous has enjoyed its more chaotic lack of structure, openness, low barrier to entry, and other features. The downside of this has been an upper bounds of effectiveness, a lower batting average, a muddied focus, &#8220;brand damage&#8221;, arrests &#8211; and even catalyzing escalation with law enforcement, legislators, and other forces of &#8220;control&#8221;. As we&#8217;ve said, if not careful, Anonymous could help cause the very things they fear/oppose.</p>
<p>The authors believe that the current state is either untenable or of limited impact in the long run. To this we offer the following &#8220;three steps&#8221; as a straw man of &#8220;organized chaos&#8221; for consideration and dialectic, or debate. We argue that such an approach would, on the whole, improve the impact and mitigate several current challenges.</p>
<ol>
<li>Statement of belief, values, objectives, and first principles &#8211; i.e. WHY you have come together</li>
<li>Code of conduct and operational parameters &#8211; i.e. HOW you conduct your pursuit of your common goals</li>
<li>A plan for streamlining success, increasing potency, and mitigating risks &#8211; i.e. WHAT will make you more successful</li>
</ol>
<p>We will outline these three below for those who see themselves as &#8220;<a href="http://en.wikipedia.org/wiki/Alignment_%28Dungeons_%26_Dragons%29#Chaotic_Good" target="_blank">Chaotic Good</a>&#8221; &#8211; as a sample use case. We will then directly link how such a system would mitigate several of today&#8217;s Anonymous challenges identified in <a title="“Building a Better Anonymous” Series: Part 4" href="http://blog.cognitivedissidents.com/2012/03/08/building-a-better-anonymous-series-part-4/" target="_blank">Part 4</a>.</p>
<h4>#1: Statement of beliefs, values, objectives, and first principles (WHY)</h4>
<p>To repeat, a mentor once told me:</p>
<blockquote><p>&#8220;If you believe something, you should write it down. The more important the belief, the more critical it is that you are precise and clear in its articulation.&#8221;</p></blockquote>
<p>Core to any meaningful group or endeavor is your purpose. <strong><span style="text-decoration:underline;">Why</span></strong> have you come together? What are your beliefs? What are your values? What do you hope to change? What are your essential &#8220;first principles&#8221;?</p>
<p>For Martin Luther, it was nailing his <a href="http://en.wikipedia.org/wiki/The_Ninety-Five_Theses" target="_blank">95 Theses</a> to the Castle Church &#8211; sparking the Protestant Reformation to separate from what he saw as an increasingly corrupt Catholic Church. For Martin Luther King, Jr., this was the vision expressed in &#8220;<a href="http://en.wikipedia.org/wiki/I_Have_a_Dream" target="_blank">I have a dream</a>&#8220;.</p>
<p>It is a common purpose that binds movements together. <em>Ad hoc</em> bonds can be weaker bonds, but bonds formed in shared values and shared beliefs are not as easily broken. Commitment to shared purpose and objectives can serve to strengthen the resolve, staying power, and impact of those involved.</p>
<p>Historically, Anonymous has been ambiguous about what it stands for. Sure, there have been some more dominant themes but&#8230; too many of them. This has lead to a sort of <a href="http://en.wikipedia.org/wiki/Trans-cultural_diffusion" target="_blank">stimulus diffusion</a> in which ideas have been passed between people, but without the blueprint or foundation. Such diffusion can lead to an idea being refined and improved upon, or misunderstood and re-built as a hideous form of the original.</p>
<p>When everything is important, nothing is. Zen wisdom tells us, &#8220;He who chases two rabbits catches neither&#8221;. To reach critical mass, perhaps Anonymous needs a period of &#8220;valuable ambiguity&#8221;. To overcome its current limitations, smaller splinters may need to rally around fewer objectives, better. These splinters may not be instead of the &#8220;general population&#8221; of Anonymous, but for greater impact with less collateral damage and backlash; it may prove to be a logical necessity. For some, this personal recognition has already come. Such splinter groups may also serve another purpose; by focusing on more specific goals, the personal desires and reasons for involvement of each member are more likely to be met.</p>
<p>Here are <em>some</em> lines that a &#8220;Chaotic Good&#8221; group who cared about free speech and anti-censorship <strong>might</strong> hold:</p>
<ul>
<li>We believe in free speech for all.</li>
<li>We reject attempts to control or limit free speech online.</li>
<li>We aim to be a watchdog for the citizens of the net; to identify, expose, and rally resistance to legislation and special interests, which threaten these rights.</li>
<li>We believe free speech applies to everyone &#8211; especially when we do not agree with it.</li>
<li>When governments take access from their people, we will help to re-supply them with alternative access and vehicles to these basic rights.</li>
</ul>
<p>Benefits of writing down <strong><span style="text-decoration:underline;">why</span></strong> your group exists are numerous. First, you will attract more like-valued, and potentially more talented members. These beliefs will be the foundation of any brand to the rest of the world. It will give the group focus in the short term, and as time moves on it will give you the backbone to resist mission drift and spreading yourselves too thin. It is also your primary defense against the brand damage of <a href="http://en.wikipedia.org/wiki/False_flag" target="_blank">False Flag</a> operations done in your name. Further, such segmentation can insulate the group from any harm done by less aligned (and maybe less noble) members of the currently shared melting pot, general population of &#8220;Anonymous&#8221;.</p>
<p>When choosing your foundational beliefs and values, choose wisely.</p>
<h4>#2: Code of conduct and operational parameters (HOW)</h4>
<p>A &#8220;code&#8221; is not new to groups. For example, there is the <a href="http://en.wikipedia.org/wiki/Bushido_Code" target="_blank">bushido code</a> way of samurai, honor among thieves, the pirate code (more what you&#8217;d call &#8220;guidelines&#8221; than actual rules)&#8230; and countless others that dominate both history and popular culture.</p>
<p>The hitman/cleaner in &#8220;<a href="http://www.imdb.com/title/tt0110413/" target="_blank">Léon: The Professional</a>&#8221; had a rule; &#8220;No women. No kids.&#8221;</p>
<p>In <a href="http://www.imdb.com/title/tt0137523/" target="_blank">Fight Club</a>: &#8220;The 1st rule of Fight Club is, do not talk about Fight Club&#8221;.</p>
<p>In <a href="http://www.imdb.com/title/tt0293662/" target="_blank">The Transporter</a>, &#8220;Rule #3: Never open the package.&#8221;</p>
<p>A code of conduct and explicit statement of operational parameters has benefits. Building upon the prior foundation of your statement of beliefs, your defined &#8220;<strong><span style="text-decoration:underline;">how</span></strong>&#8221; will both attract like valued participants &#8211; and repel the opposite. Such statements will help to win the court of public opinion, both in establishing your &#8220;brand&#8221; and in defending it from pretenders and False Flags. Infiltrators would be more constrained to these narrower methods and False Flags would look anomalous in contrast.</p>
<p>A &#8220;code of conduct&#8221; actually has precedent within Anonymous. In fact, this may have been the origin of donning the Guy Fawkes mask. During the <a href="http://en.wikipedia.org/wiki/Project_Chanology" target="_blank">Project Chanology</a> planning to take to the streets against the Church of Scientology, a <a href="http://www.youtube.com/watch?v=-063clxiB8I" target="_blank">video was posted outlining the code of conduct</a>. Rule <a href="http://www.youtube.com/watch?feature=player_detailpage&amp;v=-063clxiB8I#t=205s" target="_blank">#17</a> was to cover your face to protect your identity. It just so happened that the <a href="http://en.wikipedia.org/wiki/Guy_Fawkes_mask" target="_blank">visage from V for Vendetta</a> was available and &#8220;top of mind&#8221;. Here are <em>some</em> lines that a &#8220;Chaotic Good&#8221; group who cared about free speech and anti-censorship might hold:</p>
<ul>
<li>In all actions, we must take great care to prevent collateral damage &#8211; or to hurt innocents.</li>
<li>In our pursuit to promote free speech, it is critical that we do not impinge upon the free speech of others &#8211; even when we disagree with them.</li>
<li>We will conduct our operations within the bounds of the law, leveraging <a title="Freedom of Information Act" href="http://en.wikipedia.org/wiki/Freedom_of_Information_Act_(United_States)" target="_blank">FOIA</a> and open source information.</li>
<li>Much like <a href="http://en.wikipedia.org/wiki/Rosa_Parks#Her_refusal_to_move" target="_blank">Rosa Parks did as a last resort</a>, and in rare cases, where transgression is required and righteous, it must be supported by our statement of beliefs and part of a pre-defined path of escalation.</li>
<li>We will NEVER {INSERT SCENARIO HERE}.</li>
</ul>
<p>For readers that have played MMORPGs such as World of Warcraft, you may recall the frequent statement from Blizzard Entertainment; <em>&#8220;No Blizzard employee will EVER ask you for your password.&#8221;</em> Note the utility of such an explicit, absolute statement. By making it, gamers can immediately spot imposters. Therefore, such statements can serve to mitigate some of the risk of False Flag operations and unsanctioned, brand damaging attacks done &#8220;in the name&#8221; of the more principled group.</p>
<p>One of the first examples of defining a code of conduct in &#8220;Hacktivism&#8221; activities can be found in a paper presented to Yale Law School by 0xblood Ruffin of the Cult of the Dead Cow (cDc) entitled &#8220;<a href="http://cultdeadcow.com/cDc_files/cDc-0384.html" target="_blank">Hacktivism, From Here to There</a>&#8220;; in which he states:</p>
<blockquote><p>I began to formulate some hard and fast rules for hacktivist tactics. First, no Web defacements. If groups or individuals are lawfully entitled to publish content on the Web, any violation of their right to distribute information is an abridgement of their First Amendment [freedom of expression] rights. The same goes for Denial of Service (DoS) attacks.</p></blockquote>
<p>While groups like the <a href="http://en.wikipedia.org/wiki/Electronic_Disturbance_Theater" target="_blank">Electronic Disturbance Theatre</a> (EDT) disagree about DoS, they simply wouldn&#8217;t join 0xblood or <a href="http://www.hacktivismo.com/" target="_blank">Hacktivismo</a> due to a difference in ideology. Maintaining a code and mission statement may be, at times, prohibitive to gaining wide support, but honesty and integrity are important, even to an organization who must resort to criminal acts to achieve their goals at times.</p>
<h4>#3: A plan for streamlining success, increasing potency, and mitigating risks (WHAT)</h4>
<p>What will be the difference makers and secrets to greater impact? Here we will consider a few. For example, it is often smarter to do fewer things, better. Will your actions make you look like a BadAss or a DumbAss? How you are viewed in the court of public opinion can be a major success factor. Knowing what your want and stand for is critical, but remember: A goal without a plan is called a wish.</p>
<h5>Less is More</h5>
<p>As we&#8217;ve suggested, it is ideal to do fewer things better. Would you rather have a superficial impact on ten fronts, or a meaningful impact on one front? The very things that &#8220;need fixing&#8221; are almost by definition &#8220;non-trivial&#8221;. If something is worth doing, it is worth doing well. If there are more ills to right, this simply may require more teams. Focusing on fewer fronts also allows more time and attention to be spent on each front. This would benefit operations that publish or leak information for example; rather than dumping gigabytes of information, time could be spent to pull out key pieces of interest.</p>
<h5>Unlocking Your Inner BadAss</h5>
<p>Another important factor is your potency and prowess. What&#8217;s more impressive to onlookers and adversaries, a fool shooting wildly &#8211; missing all targets? Or a sniper who makes every single bullet count; &#8220;One Shot. One Kill&#8221;. When a swordsman first takes up his blade, they may flail wildly and wastefully, but a master is more deliberate and deadly &#8211; with each stroke delivering the full impact of its intention. The true master may seldom need to draw his sword. While 2011 saw many Anonymous operations, there were several misses and/or mis-steps. Imagine instead a more potent group who seldom (if ever) misses and rejects more ops, for a better op &#8211; one that hits its targets without collateral damage. A pyro-maniac will torch everything &#8211; a pyro-technician will design and execute a targeted and effective &#8220;<a href="http://en.wikipedia.org/wiki/Controlled_burn" target="_blank">controlled burn</a>&#8220;. An amateur will amputate, but the skilled surgeon will remove the tumor with precision.</p>
<h5>Measure Twice, Cut Once</h5>
<p>Toward that end, a more potent group would do more strategizing and prep-work. When you&#8217;re taught carpentry or wood-working, most of us are equipped with the wisdom of &#8220;measure twice, cut once&#8221;. Preparation helps to avoid mistakes. Fewer mistakes conserves limited resources and helps to promote / preserve a more BadAss image to your supporters and adversaries. During the StratFor hacks in December of 2011, many criticized the &#8220;steal $1 million to give to charities&#8221; aspect of the operation &#8211; as disingenuous or naïve. Those charities did not get to keep the money, nor was that ever a possibility. Such visible/perceived mis-steps only hurt the groups brand in the court of public opinion &#8211; and are avoidable with better planning on fewer operations. For other operations, why risk arrest and incarceration to steal information that was readily obtained through a FOIA request?</p>
<h5>Finger on the Pulse</h5>
<p>Finally, the &#8220;court of public opinion&#8221; <span style="text-decoration:underline;">matters</span>. In studying the myriad of Anonymous and LulzSec operations throughout 2011, one could watch a volatile ascension and decline of support for Anonymous depending upon how noble (or ignoble) an operation was. The good will formed from lawful enablement of Occupy Wall Street could be undone by an unnecessary or overly aggressive illegal operation from different ranks in the same week. One could almost plot public support like a stock ticker &#8211; or a presidential/job approval rating. While some may &#8220;not care&#8221;, the savvy will not only pay close attention to the &#8220;pH level&#8221; or &#8220;barometer&#8221; of public opinion, but will also seek to assure their brand and accuracy of media coverage and narrative are an asset (versus a liability). Further, gauging public perception allows you to respond, make adjustments, and improve future ops.</p>
<p>This is <strong>not</strong> to say popular opinion should rule the day. In our Defcon 19 Q&amp;A after the panel, it was revealed to us that the press failed to understand or cover the more restrained / responsible hacks. Rather than investing the time to better explain their motives and decisions, Anonymous instead opted for louder and noisier ones, which a sensationalist press responded to. The sad, yet accurate, catch phrase of modern media holds; &#8220;If it bleeds, it leads&#8221;. Knowing this is the case, investment in getting the public perception and media involvement more &#8220;on point&#8221; will be a key factor in a group&#8217;s ultimate success. Perception is reality.</p>
<h3>Conclusion and Validation</h3>
<p>Building a better Anonymous must be done from the ground up, with a solid foundation to set the direction and tone of the group. Perhaps the best way to validate this idea and such a foundation is to consider it in the context of <a title="“Building a Better Anonymous” Series: Part 4" href="http://blog.cognitivedissidents.com/2012/03/08/building-a-better-anonymous-series-part-4/" target="_blank">Part 4: Failing in Practice (aka Pyrrhic Practices)</a>. All four failures we outline would have benefited substantially had their been a well-defined foundation. The case of doing &#8220;more wrong than right&#8221; during opBART could have been avoided had Anonymous stuck to principles and followed a code of conduct. OpDarknet, which saw a single chaotic actor hurt the operation and brand, could have been easily disavowed as not following a published code of conduct. Texas Takedown Thursday could have enjoyed great success, albeit slower, through a series of legal FOIA requests and strategic leaks of information if hacking was deemed necessary. OpSatiagraha would have been streamlined and a more potent operation if only the significant emails were released and highlighted. Another benefit to all of this is that there is less time wasted creating public announcements taking credit for, or denying, operations. They will be much more evident from their actions.</p>
<p>Coincidentally, as we worked on this article, <a href="http://news.softpedia.com/news/MalSec-Introduce-Themselves-After-Hacking-Raiffeisen-Bank-and-Others-264349.shtml" target="_blank">news broke</a> about a new splinter group of Anonymous, called &#8220;Malicious Security&#8221; (MalSec). This news came with the group <a href="http://www.youtube.com/watch?v=Fu_8qD8BrWQ" target="_blank">releasing a video</a> that introduced the group and outlined their objectives. MalSec firmly states they believe in free speech, and stresses that any defacement would add text to a web site, but they would not delete content, to support this idea. Many may disagree with their activity of breaking into web servers, but in setting this foundation for the group, they are in a position to maintain their principles while disavowing anyone that attempts to tarnish their brand. This is basically the same thing that happened with LulzSec; they weren&#8217;t happy with Anonymous, split off for 50 days, formed a new charter, and operated under it.</p>
<p>We expect the above to be debated and discussed, but we also believe something along these lines will come as a logical necessity. If you could make a better Anonymous, <strong>an ominous anonymous</strong> perhaps, what would <strong><span style="text-decoration:underline;">you</span></strong> build?</p>
<p>Copyright 2012 by Josh Corman and Brian Martin. Permission is granted to quote, reprint or redistribute provided the text is not altered, appropriate credit is given and a link to the original copy is included. Custom graphics courtesy of Mar - <a title="http://sudux.com/" href="http://sudux.com/" target="_blank">sudux.com</a>.</p>
<p>Should you feel generous, please donate a couple of bucks on our behalf to any 501(c)(3) non-profit that benefits animals or computer security.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/291/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/291/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/291/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/291/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/291/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/291/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/291/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/291/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/291/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/291/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/291/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/291/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/291/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/291/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=291&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2012/04/12/building-a-better-anonymous-series-part-5/feed/</wfw:commentRss>
		<slash:comments>11</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2012/04/anonymous-thinker.jpg" medium="image">
			<media:title type="html">A contemplative Anon (Artwork by Mar - sudux.com)</media:title>
		</media:content>
	</item>
		<item>
		<title>“Building a Better Anonymous” Series: Part 4</title>
		<link>http://blog.cognitivedissidents.com/2012/03/08/building-a-better-anonymous-series-part-4/</link>
		<comments>http://blog.cognitivedissidents.com/2012/03/08/building-a-better-anonymous-series-part-4/#comments</comments>
		<pubDate>Fri, 09 Mar 2012 03:53:17 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Anonymous]]></category>

		<guid isPermaLink="false">http://blog.cognitivedissidents.com/?p=261</guid>
		<description><![CDATA[Part 4: How Anonymous Has Failed in Theory &#38; Practice By Josh Corman &#38; Brian Martin 2012 If you are new to this series, please begin with Part 0 and the index. NOTE: We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=261&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_262" class="wp-caption aligncenter" style="width: 624px"><a href="http://cognitivedissidents.files.wordpress.com/2012/03/fffuuu_failed.jpg"><img class="size-full wp-image-262" title="fffuuu_failed - (Artwork by Mar - sudux.com)" src="http://cognitivedissidents.files.wordpress.com/2012/03/fffuuu_failed.jpg?w=614&h=462" alt="fffuuu_failed - (Artwork by Mar - sudux.com)" width="614" height="462" /></a><p class="wp-caption-text">fffuuu_failed - (Artwork by Mar - sudux.com)</p></div>
<h2>Part 4: How Anonymous Has Failed in Theory &amp; Practice</h2>
<h3>By Josh Corman &amp; Brian Martin</h3>
<h3>2012</h3>
<p>If you are new to this series, please begin with <a title="“Building a Better Anonymous” Series: Part 0" href="http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/" target="_blank">Part 0</a> and the index.</p>
<p><strong>NOTE:</strong> We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. Please comment toward improving/clarifying the content.</p>
<p>While this post in the series gets more critical than prior ones, the post to follow (Part 5) serves as its companion on potential ideas for mitigating some of the issues identified below. We expect (and hope for) comments and discussion on the content below – and expect much of it will be addressed further in Part 5.  Also note that this post was written prior to <a title="LULZSEC ARRESTS EXCLUSIVE" href="http://www.foxnews.com/scitech/2012/03/06/exclusive-unmasking-worlds-most-wanted-hacker/" target="_blank">the arrests of alleged LulzSec</a> members earlier this week. We will not dive into the details or recent press coverage in this installment. While some of the content below is relevant to these developments, it was written independent of them and with a bigger picture in mind.</p>
<p>Before addressing how Anonymous has &#8220;failed in theory&#8221;, it must be stressed that Anonymous is not an organization known for its internal consistency. There is no charter that lays out their theories and goals, so we must make our best guesses as to their nature. Their lack of stated beliefs is dual-edged and (in fact) one of their weaknesses and stumbling blocks &#8211; but we will explore this more in Part 5.</p>
<h3>Failed in Theory: An Unmanageable Brand</h3>
<p>Anonymous is not a simple group. It is more a group of groups. It is a brand or franchise which can be used or abused by anyone – and has been. The uncoordinated actions of one pocket can dilute, confuse, and/or adversely impact the overall brand and public opinion of Anonymous. These impacts can come by accident, but also via deliberate actions of imposters of various types. Since the court of public opinion is a major factor for the brand long term, this will increasingly be problematic.</p>
<h3>Failed in Theory: Imposters are Legion</h3>
<p>Since anyone can claim to be Anonymous, many imposters will. One CISO in the DC area claimed, “Anonymous is God’s gift to the Chinese” – asserting that the phenomenon allowed for easy scapegoating and <a title="False Flag" href="http://en.wikipedia.org/wiki/False_Flag" target="_blank">“False Flag”</a> operations which masked and served as distraction to straight up espionage. Other imposters from organized crime, law enforcement, and foreign agencies have been suspected and spotted as well. Beyond doing operations “in the name of” Anonymous, infiltration into their operations is also something that regular participants will have to expect as reality. The inability to trust others you are collaborating with is exhausting and eventually untenable for the average human. This state of war/inconvenience is why rationally self-interested people tend to form social contracts like those described by <a title="Hobbes" href="http://en.wikipedia.org/wiki/Hobbes" target="_blank">Hobbes</a> and <a title="Locke" href="http://en.wikipedia.org/wiki/John_Locke" target="_blank">Locke</a> respectively.</p>
<h3>Failed in Theory: Unclear/Inconsistent Ideology</h3>
<p>A mentor once told me:</p>
<blockquote><p>“If you believe something, you should write it down. The more important the belief, the more critical it is that you are precise and clear in its articulation.”</p></blockquote>
<p>To this we add:</p>
<blockquote><p>“At some point, if you can’t state your principles, you may not have any.”</p></blockquote>
<p>While some semi-consistent themes emerge, so do diametrically opposed actions. As time progresses, we sense that one reason no formal principles, code of conduct, or statements of belief have surfaced could be from fear that they know they will not all agree. Such tactical ambiguity may be beneficial in the short run, but can also come at the cost of greater impact and effectiveness. Can anyone state their top 3 beliefs? If we asked five members of Anonymous, would we get the same list? Maybe it is time to render these more explicit.</p>
<h3>Failed in Theory: V’s Ideas Do Not Bleed&#8230; (but see above)</h3>
<p>Anonymous&#8217; iconography of Guy Fawkes draws immediate comparisons to the movie &#8216;V for Vendetta&#8217;. At the start of the movie, Evey (played by Natalie Portman), does a voice over:</p>
<blockquote><p>Remember, remember, the Fifth of November, the Gunpowder Treason and Plot. I know of no reason why the Gunpowder Treason should ever be forgot&#8230; But what of the man? I know his name was Guy Fawkes and I know, in 1605, he attempted to blow up the Houses of Parliament. But who was he really? What was he like? We are told to remember the idea, not the man, because a man can fail. He can be caught, he can be killed and forgotten, but 400 years later, an idea can still change the world. I&#8217;ve witnessed first hand the power of ideas, I&#8217;ve seen people kill in the name of them, and die defending them&#8230; but you cannot kiss an idea, cannot touch it, or hold it&#8230; ideas do not bleed, they do not feel pain, they do not love&#8230;</p></blockquote>
<p>While Anonymous does not directly quote this, many commentators and some who affiliate with the group will frequently use phrasing from it. There is a certain amount of romance in the notion that &#8220;ideas do not bleed&#8221;, and that Anonymous&#8217; ideas and goals are like that. The decentralized group centered around common goals with a commonly accepted icon, the Guy Fawkes mask, further reinforces this kinship with &#8216;V for Vendetta&#8217;. However, there is a stark difference between the historical Fawkes or &#8216;V&#8217;, and Anonymous. Anonymous does not have one goal, nor do they have a list of goals clearly defined. While the group may embrace the notion that &#8220;ideas do not bleed&#8221;, the scattered and diverse membership and objectives will unfortunately lend to movements that are quickly lost in the noise, and to history.</p>
<p>The group&#8217;s own diversity and wildly varying causes will likely be the most significant contributor to their own ideas bleeding away, and eventually dying. As time passes, Anonymous will take on an increasing number of operations (ops). Some of their ops will resonate with larger numbers of the public, and some ops will remain mostly in the dark, rarely spoken about. The success of a high profile operation that appears to be a major win for Anonymous, may also be the same thing that effectively kills a half dozen smaller goals; some of which never left the planning stage as the group&#8217;s momentum carried them along the path of the higher profile op.</p>
<h3>Failed in Theory: Winning the Battle, Not the War</h3>
<p>As a group, or as individuals, Anonymous lacks long term vision. Only being able to focus on the here and now may be a side effect of the group&#8217;s nature, with members coming and going while limited resources are put entirely into the operation of the moment. Fighting one battle at a time, and not necessarily the most strategically sound battle, is not a recipe for winning a war. Small groups picking their battles is akin to guerrilla warfare. While problematic to an enemy with superior numbers and resources, such a tactic can be time consuming and very taxing on the smaller force. Without an end goal, without a defined way to &#8216;win the war&#8217;, Anonymous is left with a never-ending string of diverse battles and very few veterans to lead the troops. Big corporation (e.g., Visa), big money (e.g., Bank of America), and big religion (e.g., Scientology) have superior resources and deal with swings in performance and income as a matter of business. In short, they are used to the end result of an Anonymous operation. Some of these entities likely have a section of their disaster recovery policy that deals with protests. Even big crime (e.g., Zeta Cartel) will not be affected by a group such as Anonymous. After years of fighting a multi-million dollar war against law enforcement, they are well prepared for such an adversary.</p>
<p>The second problem Anonymous faces is that of commitment. While many core members of Anonymous are dedicated to the cause, a significant percentage of the group is made up of people that see themselves as casually involved. When your force is only half in the fight, your enemy has a significant advantage. The organizations that Anonymous fights are dedicated to their business, their bottom line. Showing up for a few hours on a weekend at a protest is great, but doesn&#8217;t send a message of being committed to the fight. This may give rise to hope in your opponent who sees waiting as a viable tactic. If your enemy is going to pack up and go home after weeks or months, you can focus on outlasting them, not beating them swiftly and surely.</p>
<p>The third issue we see, is that Anonymous sends mixed messages without realizing it. This is certainly a minor point, but most assuredly undercuts the message being delivered. For example, Anonymous has some level of involvement in the Occupy Wall Street (#OWS) movement. Activists in this fight write messages, communicate, and deliver manifestos complaining that corporations &#8220;have sold our privacy as a commodity&#8221;. They do this by delivering the message on Twitter and Facebook, two huge corporations that have undermined privacy in the most sinister of ways. Further, Anonymous has adopted the Guy Fawkes mask as one of their icons and wear the mask at protests and events. In doing so, they seem to forget that the rights to the image of Guy Fawkes is owned by Time Warner, parent company of Warner Brothers. Every time an Anonymous member buys a Fawkes mask, they <a title="Money made from Guy Fawkes Mask Sales" href="http://www.nytimes.com/2011/08/29/technology/masked-anonymous-protesters-aid-time-warners-profits.html" target="_blank"><strong>contribute a tiny sum of money to a big corporation</strong></a>.</p>
<p>While minor, these points are not lost on the media and the companies they are fighting. Though Anonymous&#8217; actions may go a long way to win the <a href="http://en.wikipedia.org/wiki/Hearts_and_Minds_%28Vietnam%29" target="_blank"><strong>hearts and minds</strong></a> of some, the group also feeds their enemy by giving them weapons that can be used to undermine the group&#8217;s message.</p>
<h3>Failed in Theory: Brand Management Examples</h3>
<p>As we have mentioned several times, Anonymous is a nebulous group with no central leadership and no member roster. This is both a strength and weakness of the model. In the spirit of &#8220;building a better Anonymous&#8221;, we will focus on the weaknesses first, as they must be understood before they can be improved on.</p>
<p>With no list of members or official method for joining, any random person with a computer, Guy Fawkes mask, or fleeting desire can claim membership. This allows a single chaotic actor to commit an action that goes against Anonymous&#8217; stated goals yet still claim to be part of the group. This in turn forces the group to issue a formal denial or denounce the actions of a person that is not part of the group, further reminding the world that their group makeup is questionable at best. If a rogue actor leaks a particularly sensitive database under Anonymous&#8217; name, they have the ability to seriously hurt the public opinion of Anonymous. While the group may dismiss this, carrying public favor is an incredibly valuable tool in fighting perceived evil.</p>
<p>To counter this problem, Anonymous must figure out a channel for declaring projects, public action, or protests. The group already does this in many cases, but not consistently. If a goal or action is announced, even if it is not carried out, it helps confirm the legitimacy should an act be carried out. In the case of LulzSec, a splinter group of Anonymous, they maintained a Twitter feed that acted as their official channel to announce or deny involvement in activity. Falling back on &#8220;Did we Tweet it? No? Then not us!&#8221; became a simple and reliable method for journalists and bloggers to determine their involvement, should they be bothered to fact check.</p>
<p><a href="http://cognitivedissidents.files.wordpress.com/2012/03/anonymous_waffle.jpg"><img class="aligncenter size-full wp-image-263" title="anonymous_waffle" src="http://cognitivedissidents.files.wordpress.com/2012/03/anonymous_waffle.jpg?w=614" alt=""   /></a></p>
<p>In our previous article, <a title="“Building a Better Anonymous” Series: Part 2" href="http://blog.cognitivedissidents.com/2011/12/29/building-a-better-anonymous-series-part-2/" target="_blank"><strong>Fact vs. Fiction</strong></a> we highlighted a recent example that clearly illustrates the weakness in an open model. The <a title="Stratfor attacks" href="http://news.yahoo.com/anonymous-hackers-target-us-security-think-tank-190846242.html" target="_blank"><strong>recent attack on Stratfor</strong></a> by Anonymous, as credited on <a title="Defaced Stratfor" href="http://zone-h.org/mirror/id/16416728" target="_blank"><strong>the defaced Statfor web page</strong></a> quickly gave way to an <a title="Stratfor Credit?" href="http://pastebin.com/8yrwyNkt" target="_blank"><strong>&#8220;Emergency Christmas Anonymous Press Release&#8221;</strong></a> in which Anonymous claimed they were not responsible. Not even a day later, <a title="Straft For Credit? Yes/No?" href="http://pastebin.com/q5kXd7Fd" target="_blank"><strong>another release appeared</strong></a> once again taking credit as Anonymous. This will continue to be a problem for Anonymous in the future, and likely be used as a method to undermine the Anonymous brand.</p>
<p>To date, it appears that a handful of independent would-be do-gooders have been the only ones to undermine Anonymous in such a fashion. Anonymous simply isn&#8217;t prepared to deal with an adversary that uses this against the group intentionally, especially in bigger and more public ways.</p>
<h3>First Rule of Anonymous; Stay anonymous</h3>
<p>The second rule of Anonymous; stay anonymous. This amusing reference to <a title="Fight Club" href="http://en.wikipedia.org/wiki/Fight_Club" target="_blank"><strong>Fight Club</strong></a> may seem a joke of sorts, but in reality it is an object lesson in how Anonymous is failing. Our preliminary count at the time of this posting shows the number of arrests or &#8220;busted&#8221; (search/seizure) is around 175 &#8211; including the <a title="25 Interpol arrests" href="http://news.yahoo.com/interpol-says-suspected-anonymous-hackers-arrested-232447517.html" target="_blank">25 interpol arrests</a> last week and the <a title="Alleged LulzSec Arrests" href="http://www.foxnews.com/scitech/2012/03/06/exclusive-unmasking-worlds-most-wanted-hacker/" target="_blank">LulzSec arrests</a> this week. The fundamental purpose of anonymity and presenting a uniform singular image is to strip away personal identity when committing an act of disobedience. Violating anonymity, whether it is at the hands of an Anonymous member, or through the diligent work of law enforcement, gives their enemy a win. Lapses in operational security (OpSec) are not just a matter of &#8220;leaking an IP address or name&#8221;, it may have a more serious impact such as being arrested or facing retaliation from a rival entity.</p>
<p>Some members of Anonymous dismiss these busts as inconsequential, stating &#8220;they weren&#8217;t really a member&#8221;. In some cases, when a high profile pseudonym is busted (e.g., Topiary), there are <a title="Sabu denied it was Topiary" href="https://twitter.com/#!/anonymousabu/status/86536978560065536" target="_blank"><strong>replies from the group</strong></a> saying &#8220;that wasn&#8217;t the real Topiary&#8221;. Such claims may be the truth, or disinformation. Eventually, claims that the police &#8220;got the wrong guy&#8221; become disingenuous as they simply can&#8217;t be wrong all the time. Either way, Anonymous appears to miss the more important point; each bust, no matter if legitimate, works against the group in several ways.</p>
<p>First and perhaps most importantly, every time law enforcement (LE) busts a member of Anonymous, public perception is swayed. The bust is always covered in the media, and the resulting press tells the public that law enforcement won a victory that day. This is LE&#8217;s attempt to win the &#8216;hearts and minds&#8217; in the never-ending battle for public opinion. Second, if LE continually busts members, it may severely impact Anonymous&#8217; recruiting efforts. Potential members or contributors that see a long string of arrests may reconsider becoming involved. Third, statistics are on LE&#8217;s side. For each person busted, there is a chance that they may seek a more lenient sentence and do so by <a title="Turning States Evidence" href="http://en.wikipedia.org/wiki/Turn_state%27s_evidence" target="_blank"><strong>turning state&#8217;s evidence</strong></a>. Even worse, they may become an informant who helps to infiltrate the group and report subsequent activity to law enforcement. NOTE: Much of this seems to have transitioned from theory to practice as of this week’s LulzSec / FBI activity.</p>
<h2>Failing in Practice (aka <a title="Pyrrhic Victory" href="http://en.wikipedia.org/wiki/Pyrrhic_victory" target="_blank">Pyrrhic</a> Practices)</h2>
<p>This criticism of the theory behind Anonymous is not simply academic. The failure in theory has led to failures in action, as illustrated in the following examples. Note that as is often the case, the public does not have all the details of a given incident. We can only make these observations based on what we know.</p>
<h3>OpBART &#8211; More Wrong than Right</h3>
<p>In August, 2011, there was a flurry of news regarding Anonymous protesting the Bay Area Rapid Transport (BART) administration. This lead to a wide variety of drama as BART jammed cellular telephone signals at some of the stations, leading to cries of censorship and concerns for safety (e.g., inability to dial 9-1-1). Anonymous <a title="opBART" href="http://youranonnews.tumblr.com/post/8894155866/this-is-just-a-brief-release-to-clarify-for-the" target="_blank"><strong>called for several types of attacks</strong></a> as well as <a href="http://blog.operationreality.org/2011/08/14/anonymous-sunday-fun-bart-defaced-and-user-data-leaked/" target="_blank"><strong>defaced the mybart.org site</strong></a> as well as leak user data from the site. There are several issues with this operation that question if Anonymous is really helping and/or getting their message out there.</p>
<p>First, there is relatively little coverage of <span style="text-decoration:underline;">why</span> the protests were originally called for. More mainstream media such as <a title="Bay of Rage" href="http://www.thetechherald.com/articles/Anonymous-leaks-BART-data-prepares-for-a-Bay-of-Rage" target="_blank"><strong>the Tech Herald</strong></a> wrote one piece on opBART, but did not cover the history. Non-mainstream sites like <a href="http://knowyourmeme.com/memes/events/operation-bart" target="_blank"><strong>KnowYourMeme</strong></a> are about the only ones who give a concise and clear explanation of what prompted the protest (the shooting of a homeless man by two BART officers months earlier). Listening to Anonymous&#8217; own <a href="http://www.youtube.com/watch?v=MlsLmDOhQ5Y" target="_blank"><strong>two</strong></a> <a href="http://www.youtube.com/watch?v=lG0C4lhE6bg" target="_blank"><strong>videos</strong></a> don&#8217;t give background. The <a title="opBART Collateral Damage ?" href="http://www.examiner.com/anonymous-in-national/anonymous-punishes-bart-defaces-website-leaks-user-data" target="_blank"><strong>leaking of mybart.org user emails, passwords, addresses, and phone numbers</strong></a> certainly doesn&#8217;t punish BART, rather it punishes their customers; the average citizens Anonymous claims to fight for. Between the lost message and collateral damage, Anonymous seams to undermine the overall message.</p>
<h3>OpDarknet &#8211; A Question of Ethics</h3>
<p>In what appeared to be a <a href="http://arstechnica.com/business/news/2011/10/anonymous-takes-down-darknet-child-porn-site-on-tor-network.ars" target="_blank"><strong>significant win for Anonymous</strong></a>, news broke about the group shutting down part of &#8216;Darknet&#8217;, a shadowy technical network dedicated to sharing child pornography among other things. This event, <a href="http://pastebin.com/SCdpTr2d" target="_blank"><strong>announced via pastebin</strong></a>, certainly <a href="http://www.informationweek.com/news/security/attacks/231901499" target="_blank"><strong>garnered more attention</strong></a>, reaching the mainstream including CNN and Fox News. With child pornography, it is seemingly the universal immoral act that everyone is against. After Anonymous took out &#8216;Lolita City&#8217; and &#8216;Hard Candy&#8217;, two sites dedicated to child pornography, a third site was compromised and declared to have the same material. In reality, OpDarknet called Anonymous&#8217; own ethics into question as much as their victims.</p>
<p>Shortly after the news broke, a blogger named &#8216;Justice Duck&#8217; <a href="http://the-duck-pond-blog.blogspot.com/2011/08/lulzsec-lie.html" target="_blank"><strong>wrote a piece that presents compelling evidence</strong></a> that the third site brought down by Anonymous was not actually a child pornography site at all. Based on the blogger&#8217;s research, it appears that the only person who likely had virtual child porn was a member of Anonymous. In addition, with the release of the densetsu.com site&#8217;s user list, Anonymous advocated the harrassment of what appear to be legitimate users (including many females) that are likely innocent of any allegations related to such pornography. The site&#8217;s members that signed up because of their interest in <a href="http://en.wikipedia.org/wiki/Hentai" target="_blank"><strong>Hentai</strong></a> were in turn branded &#8216;child porn traders&#8217; and paedophiles. While some may argue that Hentai is &#8216;virtual child porngraphy&#8217;, remember that law enforcement and <a href="http://www.amazon.com/s/ref=nb_sb_noss?url=search-alias%3Daps&amp;field-keywords=hentai&amp;x=0&amp;y=0" target="_blank"><strong>retailers disagree</strong></a>.</p>
<p>There are enough bad actors committing heinous crimes out there, that Anonymous should never have to resort to the same criminal and unethical behavior as their targets do. Further, vigilante takedowns may complicate/undermine justice. If systems were compromised, is any evidence against true criminals contaminated and therefore inadmissible? What is to stop the attackers from planting false accounts to smear enemies? Given this subject matter, suspects are especially “guilty until forever” in the court of public opinion.</p>
<h3>Texas Takedown Thursday (#ttt) &#8211; Crime vs. Bureaucracy</h3>
<p>Anonymous has been in a half-year war against law enforcement, <a href="http://www.scmagazine.com/anonymous-targets-law-enforcement-in-latest-data-leak/article/214961/" target="_blank"><strong>targeting their systems and releasing sensitive data</strong></a>. In an operation titled <a href="http://www.examiner.com/anonymous-in-national/anonymous-stomps-cops-texas-takedown-thursday" target="_blank"><strong>Texas Takedown Thursday</strong></a>, Anonymous released <a href="http://pastebin.com/4NG4jCLy" target="_blank"><strong>extensive emails and details</strong></a> from TexasPoliceChiefs.org. Some of the emails released exposed a variety of problems within law enforcement including abuse of government resources, racist and sexist messages, and pornography. Such an exposure is likely good for the citizens who pay the salary of law enforcement via tax dollars. On the other hand, criminal trespass into a computer system to leak the emails may not be as effective as other legitimate avenues.</p>
<p>In a <a href="http://www.star-telegram.com/2011/09/06/3341563/police-e-mails-were-vulnerable.html" target="_blank"><strong>Star-Telegram article about the incident</strong></a>, Saginaw Police Chief Roger Macon made the observation that &#8220;[Anonymous] could have had &#8230; a whole lot more [e-mails] just by sending a public information request.&#8221; Some of the emails leaked that were marked &#8216;Law Enforcement Sensitive&#8217; may not be covered under such requests, but a surprising amount of information is available from all levels of government offices if you know how to ask correctly. After figuring out the procedures which vary on a nearly per-office basis, it becomes pretty straight forward.</p>
<p>If Anonymous is truly intent on opening government records, a coordinated series of <a title="FOIA" href="http://en.wikipedia.org/wiki/Freedom_of_Information_Act_%28United_States%29" target="_blank"><strong>Freedom Of Information Act</strong></a> (FOIA) requests would be interesting and potentially compelling. To date, Anonymous does not appear to have considered this route, instead relying on computer intrusion to obtain documents. A completely separate, but more relevant issue to the law enforcement leaks, is that Anonymous is leaking data that puts police officers and their informants at risk. You may not agree with some police activity, but to put them at increased risk of violence or attack does not help anyone, especially the citizens they are supposed to protect. It also damages the Anonymous brand in the court of public opinion. This is not because breaking <em>any</em> law will be judged. Rather what may be judged is breaking laws unnecessarily or breaking “unjust” laws without the aforementioned, articulated ideology to support the “unjust” claim.</p>
<h3>OpSatiagraha &#8211; Separating the Wheat from the Chaff</h3>
<p>The last year has seen Anonymous leak a considerable amount of data from the victims of their hacking. The leaking of user databases and thousands of emails is becoming a routine part of their hacktivism methodology. The downside to such data dumps, is that the amount of information is overwhelming to a majority of would-be readers. As <a href="https://www.infosecisland.com/blogview/15869-Anonymous-Conspiracies-That-Never-Materialize.html" target="_blank"><strong>Scot Terban writes</strong></a>, the material is often interesting, but &#8220;it&#8217;s certainly not earth shattering.&#8221; Hundreds of megs (or gigs) of data with no context or analysis, puts the burden on journalists to scour the information looking for the juicy bits. Anonymous will go so far as to imply a conspiracy or overstate the scope of the data being released, only to leave readers underwhelmed when the data is finally made public.</p>
<p>When faced with thousands of routine email correspondences, finding the handful of gems becomes the more valuable service. This is something that <a title="WikiLeaks on WikiPedia" href="http://en.wikipedia.org/wiki/WikiLeaks" target="_blank"><strong>Wikileaks</strong></a> has had to contend with over the years. Rather than rely on journalists or hope that a member of Anonymous will pick out the material of interest, Anonymous needs to focus on analysis as much as providing the data dumps. For all we know, they could have leaked earth-shattering information a year ago, and it was simply lost in the noise. Without methodical analysis of each data dump, we may never know.</p>
<p>While these failures in theory and in practice are not exhaustive, we now have a basis for discussing some ways one could “build a better Anonymous” in Part 5 of this series.</p>
<p>Which failures, weaknesses, or challenges would you add? Please comment below.</p>
<p>Copyright 2011-2012 by Josh Corman and Brian Martin. Permission is granted to quote, reprint or redistribute provided the text is not altered, appropriate credit is given and a link to the original copy is included. Custom graphic courtesy of Mar &#8211; <a title="sudux.com" href="http://sudux.com/" target="_blank"><strong>sudux.com</strong></a>.</p>
<p>Should you feel generous, please donate a couple of bucks on our behalf to any 501(c)(3) non-profit that benefits animals or computer security.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/261/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/261/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/261/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=261&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2012/03/08/building-a-better-anonymous-series-part-4/feed/</wfw:commentRss>
		<slash:comments>8</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2012/03/fffuuu_failed.jpg" medium="image">
			<media:title type="html">fffuuu_failed - (Artwork by Mar - sudux.com)</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2012/03/anonymous_waffle.jpg" medium="image">
			<media:title type="html">anonymous_waffle</media:title>
		</media:content>
	</item>
		<item>
		<title>RSA 2012 Preamble</title>
		<link>http://blog.cognitivedissidents.com/2012/02/15/rsa-2012-preamble/</link>
		<comments>http://blog.cognitivedissidents.com/2012/02/15/rsa-2012-preamble/#comments</comments>
		<pubDate>Wed, 15 Feb 2012 18:40:43 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Conferences]]></category>

		<guid isPermaLink="false">http://blog.cognitivedissidents.com/?p=248</guid>
		<description><![CDATA[RSA 2012 is close upon us (Feb 27th &#8211; Mar 2nd) &#8211; for better or worse. Love it or hate it, RSA is the single largest security conference of the year &#8211; and if the security industry has a rhythm and a cadence, then it is the RSA Conference sets it. Though I sometimes quip [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=248&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="wp-caption aligncenter" style="width: 562px"><a href="http://www.rsaconference.com/images/headers/rsa-final-registration-secondary-hero-225px-v0-4-1.jpg"><img class=" " title="RSA 2012" src="http://www.rsaconference.com/images/headers/rsa-final-registration-secondary-hero-225px-v0-4-1.jpg" alt="RSA 2012" width="552" height="180" /></a><p class="wp-caption-text">RSA 2012</p></div>
<p><a title="RSA 2012 Site" href="http://www.rsaconference.com/events/2012/usa/index.htm" target="_blank">RSA 2012</a> is close upon us (Feb 27th &#8211; Mar 2nd) &#8211; for better or worse.</p>
<p>Love it or hate it, RSA is the single largest security conference of the year &#8211; and if the security industry has a rhythm and a cadence, then it is the RSA Conference sets it.</p>
<p>Though I sometimes quip that:</p>
<blockquote><p>RSA is mandatory punishment</p></blockquote>
<p>or</p>
<blockquote><p>Every year at RSA I want to quit security</p></blockquote>
<p>&#8230;there is no denying the importance of the event on framing the upcoming year&#8217;s buzz words, topics, trends, etc.</p>
<p>Below are:</p>
<ul>
<li>a few quick thoughts on how to make the most of the conference week</li>
<li>a few topics/times I&#8217;ll be speaking in case you&#8217;d like to catch me</li>
</ul>
<h2>People Value:</h2>
<p>The best parts of the RSA conference aren&#8217;t the actual conference. Be sure you embrace the Hallway-Con, the Bar-Con, the Lobby-Con, and nearby eateries&#8230; <em><strong>People</strong></em> are what drive the progress of our industry more than any vendor or sponsored keynote. We are blessed with some very creative minds and dynamic personalities. Network as ferociously as you can. My best collaborators have been born from happenstance chats in some hallway or lobby.</p>
<h2>Non-RSA Venue:</h2>
<p>Some of the best talks and debates are at adjacent events to RSA. <a title="BSides Home" href="http://www.securitybsides.com/w/page/12194156/FrontPage" target="_blank">BSides</a> and <a title="BSidesSF" href="http://www.securitybsides.com/w/page/35868077/BSidesSanFrancisco" target="_blank">BSidesSF</a> has become a force (despite its growing pains). I get a ton of value out of the <a title="ACG Security Conference" href="http://WWW.AMERICASGC.COM/news-events/index.asp?id=41" target="_blank">AGC Security Conference</a> (America&#8217;s Growth Capital) which brings great content to a high octane audience of the investment community, the founders of innovative start-ups, and potential acquirers. <a title="Mini-Metricon 6.5" href="http://www.securitymetrics.org/content/Wiki.jsp?page=Metricon6.5" target="_blank">Mini-MetriCon 6.5</a> continues to push the rock up the hill to drive us from faith based security to evidence based models. There are a myriad of other events and working groups which converge that week. While many are closed or filled up by now, do some digging &#8211; as they are well worth it.</p>
<h2>The Exhibit Floor:</h2>
<p>While the exhibit floor is a bit of a <strong>Bizarre Bazaar</strong> (Hat Tip to <a title="Neil Gaiman Home Page" href="http://www.neilgaiman.com/" target="_blank">Neil Gaiman</a>), you must try to walk the floor. Embrace the horror. Treat it as a Tour de Force of what matters and what doesn&#8217;t. Of who is a source of SIGNAL and who is a source of NOISE. In fact, develop a <em>justified, righteous indignation</em> against hyperbole, <a title="FUDsec BLOG" href="http://fudsec.com/" target="_blank">FUD</a>, and vendor B.S. Vendors do this because they can, because we let them, and because there are seldom consequences for doing so. Provide the feedback loop that alters that equation for them.</p>
<p>Last year I walked the floor with <a title="Paul Roberts Twitter Page" href="https://twitter.com/#!/paulfroberts" target="_blank">Paul Roberts</a> and we gave this a try. We knew just about ever vendor, who had the goods, who was full of [insert your favorite here], etc. We saw <em>maybe</em> a dozen vendors making credible claims about emerging security challenges and offering valuable products/services in response. We asked each vendor who was thumping APT to define it &#8211; with nearly none of them even close to real substance. Asking for specifics will quickly reveal the snake-oil from the substance. We even quipped a safe rule of thumb (at least last year):</p>
<blockquote><p>The frequency of the phrase &#8220;APT&#8221; by a vendor is inversely proportional to their actual expertise or comprehension of it</p></blockquote>
<p>Put the vendors to the test. Ask for specifics. Maybe take some dramamine 1st.</p>
<h2><strong>My Speaking Slots:</strong></h2>
<p><em>Monday, February 27, 12:30 PM &#8211; RSA - Room 302</em></p>
<p style="padding-left:30px;"><strong>PROF-001 &#8211; Stress and Burnout in the Information Security Community</strong></p>
<p style="padding-left:30px;"><a title="Jack Daniel Twitter" href="https://twitter.com/#!/jack_daniel" target="_blank">Jack Daniel</a>, <a title="Stacy Thayer Twitter" href="https://twitter.com/#!/stacythayer" target="_blank">Stacy Thayer</a>,  <a title="Gal Shpantzer Twitter" href="https://twitter.com/#!/Shpantzer" target="_blank">Gal Shpantzer</a>, <a title="Martin McKeay Twitter" href="https://twitter.com/#!/mckeay" target="_blank">Martin McKeay</a>, Joshua Corman (and <strong><a href="https://twitter.com/#!/kcyerrid" rel="nofollow">@kcyerrid</a> shhh!</strong>)</p>
<p style="padding-left:30px;">We&#8217;ve done real <a title="Read about our Survey... or HURRY and take it" href="http://blog.uncommonsensesecurity.com/2012/01/infosec-career-attitudes-survey.html" target="_blank">survey work</a> with proven non-security-models and this is an important topic. We did a less formal version at BSidesLV 2011 with great feedback, validating the need for this.</p>
<p><em>Monday, February 27, 3:00 PM - AGC&#8217;s Security Conference - Main Stage at </em>Westin Market St</p>
<p style="padding-left:30px;"><strong>PM Keynote: Apocalypse Now: Adapting to Espionage and Chaotic Actors</strong></p>
<p style="padding-left:30px;">Joshua Corman</p>
<p style="padding-left:30px;">I&#8217;m excited to confront the VC and Investment community to actually rise to substantive changes in the space &#8211; versus repackaging old &#8220;kit&#8221; into the latest compliance or FUD buzzwords. This industry used to innovate, and it is time to again. What&#8217;s really cool about this, is my keynote is followed by two child panels: one on adapting to Espionage developments &#8211; one on implications of Chaotic Actors. With the money and the innovators in the room, confronting these topics, perhaps we can catalyze some action.</p>
<p><em>Tuesday, February 28, 1:10 PM &#8211; RSA - Room 305</em></p>
<p style="padding-left:30px;"><strong>CLD-106 &#8211; Security is Dead. Long Live Rugged DevOps: IT at Ludicrous Speed</strong></p>
<p style="padding-left:30px;"><a title="Gene Kim Twitter" href="https://twitter.com/#!/RealGeneKim" target="_blank">Gene Kim</a> &amp; Joshua Corman</p>
<p style="padding-left:30px;">Gene and I have been collaborating for a little over a year and a half on this topic. I&#8217;m most excited about this one. **BONUS POINTS if you can name the movie reference in the title</p>
<p style="padding-left:30px;">Here is a <a title="RSA Podcast CLD-106 Security is Dead. Long Live Rugged DevOps: IT at Ludicrous Speed" href="http://365.rsaconference.com/community/connect/blog/2012/02/21/rsac2012-podcast-cld-106-security-is-dead-long-live-rugged-devops-it-at-ludicrous-speed" target="_blank">short podcast teaser</a> we did with RSA</p>
<p><em>Wednesday, February 29, 9:30 AM &#8211; RSA - Room 309</em></p>
<p style="padding-left:30px;"><strong>GRC-202 &#8211; Adversary ROI: Why Spend $40B Developing It, When You Can Steal It for $1M?</strong></p>
<p style="padding-left:30px;">Joshua Corman &amp; <a title="David Etue Twitter" href="https://twitter.com/#!/djetue" target="_blank">David Etue</a></p>
<p style="padding-left:30px;">David and I have been working this idea for several years. After last year&#8217;s pantheon of adversaries and pervasive failures became clearer, more practitioners may be ready for this concept. <a title="Intro to HDMoore’s Law" href="http://blog.cognitivedissidents.com/2011/11/01/intro-to-hdmoores-law/" target="_blank">HDMoore&#8217;s Law</a> will be discussed.</p>
<p style="padding-left:30px;">Here is a <a title="RSA Podcast on GRC-202: Adversary ROI: Why Spend $40B Developing It, When You Can Steal It for $1M?" href="http://365.rsaconference.com/community/connect/blog/2012/01/18/rsac2012-podcast-grc-202-adversary-roi-why-spend-40b-developing-it-when-you-can-steal-it-for-1m" target="_blank">short podcast teaser</a> we did with RSA</p>
<p>If you need/want to reach me while there, hit me on twitter: <a title="Josh Corman Twitter" href="https://twitter.com/#!/joshcorman" target="_blank">@joshcorman</a></p>
<p>RSA is what you make of it&#8230;</p>
<ul>
<li>What are you expecting?</li>
<li>What are you dreading?</li>
<li>Which people/talks are you eager to see?</li>
</ul>
<p style="padding-left:30px;">
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/248/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/248/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/248/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=248&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2012/02/15/rsa-2012-preamble/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://www.rsaconference.com/images/headers/rsa-final-registration-secondary-hero-225px-v0-4-1.jpg" medium="image">
			<media:title type="html">RSA 2012</media:title>
		</media:content>
	</item>
		<item>
		<title>“Building a Better Anonymous” Series: Part 3</title>
		<link>http://blog.cognitivedissidents.com/2012/02/13/building-a-better-anonymous-series-part-3/</link>
		<comments>http://blog.cognitivedissidents.com/2012/02/13/building-a-better-anonymous-series-part-3/#comments</comments>
		<pubDate>Tue, 14 Feb 2012 00:37:21 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Anonymous]]></category>

		<guid isPermaLink="false">http://blog.cognitivedissidents.com/?p=231</guid>
		<description><![CDATA[Part 3: How We All Got it All Wrong By Josh Corman &#38; Brian Martin 2011 If you are new to this series, please begin with Part 0 and the index. NOTE: We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=231&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_236" class="wp-caption aligncenter" style="width: 624px"><a href="http://cognitivedissidents.files.wordpress.com/2012/02/anonymous_good_and_evil.jpg"><img class="size-full wp-image-236" title="Anonymous Good and Evil (Artwork by Mar - sudux.com)" src="http://cognitivedissidents.files.wordpress.com/2012/02/anonymous_good_and_evil.jpg?w=614&h=423" alt="Anonymous Good and Evil (Artwork by Mar - sudux.com)" width="614" height="423" /></a><p class="wp-caption-text">Anonymous Good and Evil (Artwork by Mar - sudux.com)</p></div>
<h2>Part 3: How We All Got it All Wrong</h2>
<h3>By Josh Corman &amp; Brian Martin</h3>
<h3>2011</h3>
<p>If you are new to this series, please begin with <a title="“Building a Better Anonymous” Series: Part 0" href="http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/" target="_blank">Part 0</a> and the index.</p>
<p><strong>NOTE:</strong> We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. Please comment toward improving/clarifying the content.</p>
<p>Like many, early on we carried a cognitive dissonance about Anonymous. Is this a good thing? Or a bad thing? Many people seemed to approve of the attacks against Scientology &#8211; or Anonymous&#8217; apparent passion for transparency and their crusade against corruption. Helping oppressed people in Tunisia and Egypt? Absolutely, people see that as a force for good. Others operations however, were a bit more disconcerting for the onlookers. Leaking personal details of law enforcement, their families, and confidential informants did not sit well with many.</p>
<p>Riding on the back of <a title="“Building a Better Anonymous” Series: Part 2" href="http://blog.cognitivedissidents.com/2011/12/29/building-a-better-anonymous-series-part-2/" target="_blank">Part 2: Fact vs Fiction</a>, there are some additional points to make. When we explored fact and fiction, many of the points were based on a lack of understanding. In this article, we discuss how we collectively &#8220;got it wrong&#8221;. This moves beyond misconceptions born out of poor reporting or conflicting information, and into the realm of our simple lack of understanding. Further, it highlights that as a society, we seem to be unable to learn from our history. As <a href="http://en.wikiquote.org/wiki/George_Santayana" target="_blank">George Santayana</a> famously said in The Life of Reason,</p>
<blockquote><p>&#8220;Those who cannot learn from history are doomed to repeat it.&#8221;</p></blockquote>
<h3>Everything Old is New Again</h3>
<p>Regarding this article, the concept of speculating and proposing a &#8220;better&#8221;, more efficient, and more serious adversary is old. Government sponsored think-tanks and the U.S. military have been doing this for decades. With regard to Anonymous, the idea of the group is also not new. All of their diverse traits seen in a single group, even if nebulous, may be new to most people. However, many in information security or law enforcement have been exposed to most of these traits before. The concept of Hacktivism has been going on for well over a decade, primarily through groups defacing web pages with political messages.</p>
<p>Disregarding the apparent disconnect between a &#8220;computer-based group&#8221;, as Anonymous is often considered, and more traditional groups, the traits of Anonymous become more prominent. Compare some of the actions of <a href="http://en.wikipedia.org/wiki/People_for_the_Ethical_Treatment_of_Animals" target="_blank">PETA</a>, <a href="http://en.wikipedia.org/wiki/Black_hand" target="_blank">the Black Hand</a>, <a href="http://en.wikipedia.org/wiki/Kkk" target="_blank">Ku Klux Klan</a>, <a href="http://en.wikipedia.org/wiki/Weather_underground" target="_blank">Weather Underground</a>, or <a href="http://en.wikipedia.org/wiki/Earth_first" target="_blank">Earth First</a> to some of the actions of Anonymous. Despite their goals being diverse, and each group having their share of radical members, there are many parallels to be drawn.</p>
<p>While they have far less in common than a broad swath of their members or observers would think, their common traits are certainly there. Each group is frustrated about their <em>raison d&#8217;etre</em>. Each group believes in presenting a unified front outwardly while embracing diversity and resilience internally. Despite being a heterogeneous group sociologically, Anonymous does a good job putting forth a homogeneous image (arguably propaganda) through the use of iconography and central messages.</p>
<h3>Being Dismissive is a Disservice</h3>
<p>Over the last year, many media outlets, pundits, and security professionals have given commentary on Anonymous and LulzSec. In many cases, the tone of the commentary has been negative, with the commentator essentially dismissing the groups&#8217; actions. In some cases, it has been a general dismissive &#8220;the group is not effecting change&#8221; line. In other cases, pundits outright deride LulzSec as having no advanced hacking skills and only attacking the &#8220;low hanging fruit&#8221;. While most, if not all, of their hacking exploits have been easy to find and exploit, these pundits are missing the bigger picture.</p>
<p>First, LulzSec didn&#8217;t <strong><span style="text-decoration:underline;">need</span></strong> more sophisticated exploits to compromise these organizations. An attacker is only as sophisticated as they are required to be; when companies don&#8217;t make it a challenge for attackers, there is no reason to use more advanced attacks. If large companies and law enforcement are protecting such valuable information, why are their own security programs not catching the low hanging fruit?</p>
<p>Second, what if the high profile compromises using basic exploits are just a noisy cover hiding the real activity? The concept of misdirection when hacking has been around for over twenty years. It is dangerous to assume that we know the whole picture when we are only seeing what makes the front page. There are two aspects to this idea: LulzSec could be using some of these attacks as a method of distracting onlookers from their real goals, or third parties unaffiliated with LulzSec and Anonymous may be using their brand for misdirection. For example, a disgruntled employee could launch a denial of service attack against his employer and embed a message such as <em>&#8220;We are legion&#8221;</em> in it, giving the impression the attacks are the work of Anonymous.</p>
<p>&#8220;Pretenders&#8221; also came up during the Q&amp;A following our <a title="DEFCON 19 Anonymous Whoever Fights Monsters Panel" href="http://www.defcon.org/html/defcon-19/dc-19-speakers.html#Roberts" target="_blank">DEFCON 19 panel</a>. Several in-room members of Anonymous claimed the two large Sony breaches of credit cards were &#8220;not us&#8221; but rather &#8220;the Russians&#8221; &#8211; as many suspected. Regardless, many have been dismissive of the group or the impact of an attack &#8211; until they&#8217;ve been on the receiving end.</p>
<h3>The Media&#8217;s Field Day</h3>
<p>To say the media has collectively had a field day with coverage of Anonymous is certainly an understatement. The group&#8217;s diverse actions, ranging from in-person protests or virtual sit-ins (DDoS attacks) to leaking information from hacked corporations, provides a gold mine of drama-rich news. The lack of a central authority or official channel for public statements from Anonymous helps the media run wild, and Anonymous must play a game of catch-up when trying to hold the media accountable. The perception that Anonymous is new and a game changer has led many media outlets to go to press without finding a qualified person to speak on the matter. Simply grabbing the nearest mouthpiece, that frequently has a personal or corporate agenda, does not help the media, Anonymous, or the public.</p>
<p>When LulzSec splintered off from Anonymous, the more revealing story was not the material results of their hacking; rather, it was the sad commentary on infosec-centric and mainstream news coverage alike. After 50 days of hacking into a wide variety of sites, accompanied by a high profile predominantly Twitter-based media presence, the pressure added up. With the looming threat of law enforcement catching up to them, LulzSec <a href="http://pastebin.com/1znEGmHa" target="_blank">announced their retirement</a> on Pastebin and broadcast it via Twitter. While the announcement was deemed inevitable, many <a href="https://www.infosecisland.com/blogview/14781-Rumors-of-LuzSecs-Demise-are-Greatly-Exaggerated.html" target="_blank">figured we hadn&#8217;t heard the last from them</a>, and they were right. Some in the mainstream media <a href="http://www.guardian.co.uk/technology/blog/2011/jun/27/lulzsec-disband-hacking-why" target="_blank">announced it and gave commentary on why it was inevitable and certain</a>.</p>
<p>One of the most noticeable traits of media coverage during the 50 days LulzSec was active, was the lack of truly critical press. Publications and authors that have been more vocal and firm in the past seemed to pull their blows when covering the hacking activity of LulzSec. Since the group was executing a wide variety of attacks, and supporters of the group were carrying out DDoS attacks against detractors, it appeared that journalists were scared to be overly critical. Paul Carr <a href="http://techcrunch.com/2011/06/26/the-lion-that-squeaked/" target="_blank">wrote for TechCrunch</a> saying &#8220;Please Hacker Don&#8217;t Hurt Us: The Media&#8217;s Coverage Of LulzSec Has Been Cowardly and Pathetic&#8221;. It should be noted the irony that this article came <span style="text-decoration:underline;">a day after LulzSec posted their retirement message</span>. Worse, the timing of the article and criticality suggests that Carr, like many others, felt that the group was truly done and their &#8220;vandalism spree&#8221; was finished. Similarly, Bill Brenner <a href="http://blogs.csoonline.com/1570/whatever_lulzsec" target="_blank">wrote an article for CSO Online</a> called &#8220;Whatever, LulzSec&#8221;, two days after the retirement message. The timing of these articles suggest the authors feared potential retaliation from LulzSec should their message be construed negatively. Provoking these groups may seem undesirable, but it would also prove an interesting point; if Anonymous or LulzSec retaliate over poor press, they may be considered the tyrants they so oppose.</p>
<h3>Arresting Anonymous Won&#8217;t Help</h3>
<p>The pursuit of Anonymous is just as futile as it is necessary. Thinking of the group in terms of traditional crime simply doesn&#8217;t hold up. This group is not four people that have been knocking over banks, where bringing even one of the four to justice may stop further robberies. For each Anonymous member busted, another will take his or her place, maybe two. That said, law enforcement cannot let the group go unchallenged. Public and corporate pressure to put a stop to their activity is stronger than ever. With a nebulous group that has new recruits ready to step in for fallen comrades, it could be a never ending battle. With a seemingly endless supply of new recruits, all with a strong belief in the movement, a few dozen arrests won&#8217;t put a dent in the organization.</p>
<p>Some have suggested the only way to truly stop these groups is to capitulate, and meet their demands, which is as much a pipe dream. With a diverse set of demands, that are often not well defined, or more of a general principle such as &#8220;maintain secure networks&#8221;, meeting them is often not possible. If you take away the reason someone is protesting, they will generally stop. Locking them up or pushing back rarely leads to a real solution. As Natalie Portman&#8217;s voice over in &#8216;V for Vendetta&#8217; said,</p>
<blockquote><p>&#8220;We are told to remember the idea, not the man, because a man can fail. He can be caught, he can be killed and forgotten, but 400 years later, an idea can still change the world.&#8221;</p>
<div align="center">
<div id="attachment_234" class="wp-caption aligncenter" style="width: 410px"><a href="http://cognitivedissidents.files.wordpress.com/2012/02/anonymous_mugshots-small.jpg"><img class="size-full wp-image-234" title="Anonymous_Alleged_mugshots-small" src="http://cognitivedissidents.files.wordpress.com/2012/02/anonymous_mugshots-small.jpg?w=614" alt="Anonymous Alleged Mugshots"   /></a><p class="wp-caption-text">Anonymous Alleged Mugshots</p></div>
<p>(Source of mugshots: <a href="http://media.talkingpointsmemo.com/slideshow/anonymous-mugshots-unmasked" target="_blank">talkingpointsmemo.com</a>)</p>
</div>
</blockquote>
<p>Even with dozens of arrests in several countries, there is no indication that Anonymous is dissuaded.</p>
<h3>Occam&#8217;s Razor Cuts Deep</h3>
<p>Like most current topics, a prevailing trend in media coverage of Anonymous is heavily based on making assumptions. A news organization may receive one or two pieces of information about a situation or scandal, then fill in the blanks with their best guesses. We&#8217;ve become accustomed to news coverage that consists of a commentator standing by repeating the same fact over and over, interjected with their guess of additional facts. Moving beyond the simple (e.g., &#8220;the politician is greedy&#8221;), commentators will speculate wildly about state of mind or other actors that may or may not be involved. We, the viewers, are the cause of this. As a society, we are willing to forgo logic and simplicity in favor of drama and intrigue.</p>
<p>For Anonymous, a group largely grounded in the Internet as a medium and meeting place, the theory of <a href="http://en.wikipedia.org/wiki/Occams_razor" target="_blank">Occam&#8217;s razor</a> is largely applicable. Combine with that the <a href="http://en.wikipedia.org/wiki/Online_disinhibition_effect" target="_blank">Online Disinhibition Effect</a>, and it becomes obvious that many are acting out <em>because they can</em>. More interesting is the notion that the casual members and new recruits, viewed as &#8216;cannon fodder&#8217; by some, are the ones acting out the most. Further, they feel safer with a layer of anonymity and perceived protection that they do not enjoy in real-world protests or activity. In some cases, it is simply a matter of the participant not fully understanding technology and how it relates to anonymity. They feel that being virtual protects them, without understanding the exposure of a disclosed IP address that has not been masked with effective technology (e.g., <a href="https://www.torproject.org/" target="_blank">TOR</a>, proxies).</p>
<p>On the flip side, many members of Anonymous are proving that the Online Disinhibition Effect only goes so far. With members helping in Internet activism before proceeding to a local protest to square off with those they are protesting, anti-protestors, and law enforcement, one has to accept that not all members act differently simply because of perceived Internet anonymity. As this happens, media outlets are guilty of varying degrees of projection, assigning traits and beliefs to persons that have made no definitive actions of the sort.</p>
<p>In challenging the integrity or morals of someone that hides behind a mask or computer, many of us fail to realize that dissociative anonymity may also be helping our society. The protection provided by that anonymity may be leading people to find the strength or freedom to say things they wouldn&#8217;t otherwise. At DEFCON 19, one member of our panel began the session wearing a mask. When we asked the audience if he should remove it, a majority said &#8220;no&#8221; (with a noted selection bias). This lends to the idea that many sympathizers don&#8217;t want Anonymous unmasked, perhaps as a way of supporting or agreeing with a majority of their actions; or simply out of fear of repercussions. Like most tools, anonymity can be used for good or evil.</p>
<p>Those seeking anonymity may include people effectively <a href="http://en.wikipedia.org/wiki/Whistleblower" target="_blank">whistleblowing</a>, arguably a valuable public service that puts them at risk for the greater good of society. Further, asynchronous communications may be fueling people to embrace speaking out. The ability to voice opinions or share information on message boards, via e-mail, or on web sites, without immediate backlash or punishment is a powerful motivator for opening up and sharing.</p>
<p>There are many factors that contribute to the actions and mindset of a person affiliating themselves with Anonymous, LulzSec, or any group tangentially related to Anonymous. Despite all of the speculation and possibilities enumerated in this article, Occam reminds us that a group such as LulzSec may truly be doing it all &#8220;<a href="http://knowyourmeme.com/memes/i-did-it-for-the-lulz" target="_blank">for the lulz</a>&#8220;. Every time the media or an analyst takes a guess or makes a suspect claim about Anonymous&#8217; motivations, it is important to go back to a more simple explanation and give it serious consideration.</p>
<p>Copyright 2011 by Josh Corman and Brian Martin. Permission is granted to quote, reprint or redistribute provided the text is not altered, appropriate credit is given and a link to the original copy is included. Custom graphic courtesy of Mar - <a href="http://sudux.com/" target="_blank">sudux.com</a>.</p>
<p>Should you feel generous, please donate a couple of bucks on our behalf to any 501(c)(3) non-profit that benefits animals or computer security.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/231/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/231/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/231/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=231&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2012/02/13/building-a-better-anonymous-series-part-3/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2012/02/anonymous_good_and_evil.jpg" medium="image">
			<media:title type="html">Anonymous Good and Evil (Artwork by Mar - sudux.com)</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2012/02/anonymous_mugshots-small.jpg" medium="image">
			<media:title type="html">Anonymous_Alleged_mugshots-small</media:title>
		</media:content>
	</item>
		<item>
		<title>Nomination for Most Educational Blog</title>
		<link>http://blog.cognitivedissidents.com/2012/01/23/nomination-for-most-educational-blog/</link>
		<comments>http://blog.cognitivedissidents.com/2012/01/23/nomination-for-most-educational-blog/#comments</comments>
		<pubDate>Mon, 23 Jan 2012 22:32:18 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.cognitivedissidents.com/?p=224</guid>
		<description><![CDATA[It&#8217;s an honor just to be nominated. A few weeks ago, the nominations for the 2012 Social Security Bloggers Awards came out. Given how spanky new this blog was, I was shocked to see it receive a nomination for &#8220;Most Educational Security Blog&#8220;. This is a tough category and a humbling one. I almost took [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=224&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div class="wp-caption aligncenter" style="width: 409px"><a href="2012 Social Security Bloggers Awards"><img title="2012_SocialSecurityBloggersAwards" src="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201676012f2de970b-pi" alt="2012 Social Security Bloggers Awards" width="399" height="246" /></a><p class="wp-caption-text">2012 Social Security Bloggers Awards to take place at RSA</p></div>
<blockquote><p>It&#8217;s an honor just to be nominated.</p></blockquote>
<p>A few weeks ago, the nominations for the <a title="2012 Social Security Bloggers Awards Nominees" href="http://www.ashimmy.com/2012/01/and-the-nominees-are.html" target="_blank">2012 Social Security Bloggers Awards</a> came out.</p>
<p>Given how spanky new this blog was, I was shocked to see it receive a nomination for &#8220;<strong>Most Educational Security Blog</strong>&#8220;. This is a tough category and a humbling one. I almost took it as a suggestion/challenge to rise than any other meaning. I do really try to add <em>signal</em> and researched backed concepts (versus simply adding <em>noise</em>) &#8211; so I feel great that at least a few noticed that. I also want point out that Brian Martin (aka Jericho <a title="Jerisho Twitter Page" href="https://twitter.com/#%21/attritionorg" target="_blank">@attritionorg</a>) has co-authored the &#8220;<a title="“Building a Better Anonymous” Series: Part 0" href="http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/" target="_blank">Building a Better Anonymous series</a>&#8221; &#8211; and therefore is also part implicated/reponsible.</p>
<p>Regardless, I am honored to have &#8220;Cognitive Dissidents&#8221; included among some excellent resources (pasted below):</p>
<p style="padding-left:30px;"><strong><span style="font-size:small;">The Most Educational Security Blog:</span></strong></p>
<p style="padding-left:30px;">Cognitive Dissidents <a href="http://blog.cognitivedissidents.com/">http://blog.cognitivedissidents.com/</a></p>
<p style="padding-left:30px;">Tao Security <a href="http://taosecurity.blogspot.com/">http://taosecurity.blogspot.com/</a></p>
<p style="padding-left:30px;">F-Secure blog <a href="http://www.f-secure.com/weblog/">http://www.f-secure.com/weblog/</a></p>
<p style="padding-left:30px;">The New School Security Blog <a href="http://newschoolsecurity.com/">http://newschoolsecurity.com/</a></p>
<p style="padding-left:30px;">AppSecInc Blog <a href="http://blog.appsecinc.com/">http://blog.appsecinc.com/</a></p>
<p style="padding-left:30px;">Evil Bytes/John Sawyer <a href="http://www.darkreading.com/blog/archives/evil-bytes/index.html">http://www.darkreading.com/blog/archives/evil-bytes/index.html</a></p>
<p>All of those are excellent resources. I&#8217;d probably vote for The New School Security Blog. Each offer something different, so I&#8217;d highly encourage you to try them each.</p>
<p>There are many great nominees for various categories of BLOGs and Podcasts. If you haven&#8217;t taken a look, I&#8217;d encourage you <a title="And The Nominees Are . . ." href="http://www.ashimmy.com/2012/01/and-the-nominees-are.html" target="_blank">to do so</a>. There are also some glaring omissions from some of the nominees, so feel free to suggest write-ins or ask more about the nomination process.</p>
<p>E.g. Best Security Podcast  was missing <a title="Ricky Business Weekly" href="http://risky.biz/netcasts/risky-business" target="_blank">Risky Business</a> and the <a title="Social-Engineer.org Monthly Podcast" href="http://www.social-engineer.org/podcast/" target="_blank">Social-Engineer.org</a> podcasts &#8211; the former being the best source of weekly security news and the latter being one of the most structured and educational in its monthly format.</p>
<p>Like the SAG (Screen Actors Guild) awards, these are voted upon by other bloggers. You need a security blog to vote. If you have one, and have not voted yet, please do so before it closes. Here&#8217;s a <a title="VOTE - Social Security Blogger Awards 2012" href="https://www.surveymonkey.com/s/2012securityblogger" target="_blank">convenient link to the voting form</a>.</p>
<p>Like many of you, I feel a bit conflicted about these kinds of things. Sure there is a bit of echo chamber and digerati and cult-of-personality stuff with any of these awards. That said, there are some truly excellent researchers and bloggers who devote a ton of their personal time to helping advance this space. This is a small, easy way to acknowledge their contributions.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/224/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/224/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/224/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=224&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2012/01/23/nomination-for-most-educational-blog/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://www.stillsecureafteralltheseyears.com/.a/6a00d83451e4d369e201676012f2de970b-pi" medium="image">
			<media:title type="html">2012_SocialSecurityBloggersAwards</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;Building a Better Anonymous&#8221; Series: Part 2</title>
		<link>http://blog.cognitivedissidents.com/2011/12/29/building-a-better-anonymous-series-part-2/</link>
		<comments>http://blog.cognitivedissidents.com/2011/12/29/building-a-better-anonymous-series-part-2/#comments</comments>
		<pubDate>Thu, 29 Dec 2011 15:55:04 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Anonymous]]></category>

		<guid isPermaLink="false">http://blog.cognitivedissidents.com/?p=207</guid>
		<description><![CDATA[Part 2: Fact vs. Fiction By Josh Corman &#38; Brian Martin 2011 If you are new to this series, please begin with Part 0 and the index. You may also recognize the above ink blot from a short post in November (which has several comments worth reading). NOTE: We will post each installment here for the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=207&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_208" class="wp-caption aligncenter" style="width: 510px"><a href="http://cognitivedissidents.files.wordpress.com/2011/12/anonymous_rorschach.jpg"><img class="size-full wp-image-208" title="anonymous_rorschach" src="http://cognitivedissidents.files.wordpress.com/2011/12/anonymous_rorschach.jpg?w=614" alt="Telling Fact from Fiction since we see what we WANT to in Anonymous - (Artwork by Mar - sudux.com)"   /></a><p class="wp-caption-text">Fact vs. Fiction? we see what we WANT to in Anonymous - (Artwork by Mar - sudux.com)</p></div>
<h2>Part 2: Fact vs. Fiction</h2>
<h3>By Josh Corman &amp; Brian Martin</h3>
<h3>2011</h3>
<p>If you are new to this series, please begin with <a title="“Building a Better Anonymous” Series: Part 0" href="http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/" target="_blank">Part 0</a> and the index. You may also recognize the above ink blot from a short post in November (which has several <a title="An Anonymous Ink Blot Rorschach" href="http://blog.cognitivedissidents.com/2011/11/11/an-anonymous-ink-blot-rorschach/" target="_blank">comments worth reading</a>).</p>
<p><strong>NOTE:</strong> We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. Please comment toward improving/clarifying the content.</p>
<p>The story of Anonymous is interesting. Some of the activities and exploits of the &#8220;group&#8221; are surely entertaining. As such, the media tends to run wild and loose with fact, injecting a healthy dose of fiction along the way. With as much truth as fiction in the news, it makes it difficult to understand and accurately portray such a group. It skews our perception of Anonymous&#8217; activities and goals. Reporting with a lack of information or perspective is often just as big a disservice as reporting inaccurate information.</p>
<p>After our DEFCON 19 Panel &#8220;Whoever Fights Monsters&#8230;&#8221;, we had several intense discussions with many attendees and even some self-identifying members of Anonymous. While there were many take-aways, our biggest was that one of the reasons our collective narrative is so far off base is due to a bit of a Rorschach effect. We see in Anonymous, what we want to see. We project. Our narrative says more about us than it does about them. Just because we may want them to be &#8220;demonstrating insecurity in order to catalyze better security&#8221;, doesn&#8217;t mean that&#8217;s what is driving them. In fact, there isn&#8217;t even one singular, monolithic motivation or cause &#8211; and that is one of the next points.</p>
<p>With that, we examine some of the myths and fiction surrounding Anonymous. Anonymous is surrounded in contradictions and represents a paradox. Exploring the paradox is part of the dialogue, as contradictions are inherent in the subject matter.</p>
<h3>Fact or Fiction: Leadership and a Defined Group</h3>
<p>Anonymous is a loose collective with no membership roster, not a monolithic group. One could say it is an &#8220;idea&#8221;, but even that is incorrect, as it is a collective of ideas. Without structure, without a roster, without leadership, how can a collection of people even be called a group, let alone affect change? Despite that they call themselves a group, and by definition they are one. They assemble under the banner and ideal of Anonymous. What exactly that is, is hard to nail down. The idea of such a nebulous group that can usually work together to achieve a goal is a foreign concept to most people. For law enforcement, who is already struggling to break away from the mindset that digital criminal organizations are like the Mafia, Anonymous represents an entirely new paradigm.</p>
<p>To add even more confusion, Anonymous may have equally undefined sub-groups; people who associate with Anonymous, but only to participate in a specific cause or action. These pockets have different backgrounds, different motivations, and different levels of involvement. When people seem surprised that Anonymous did this or that &#8211; that it may be &#8220;out of character for them&#8221; &#8211; this is often due to the fact that they assign a singular, cohesive persona and timeline to one group &#8211; when reality is more of a morphing plurality of parties and interests. Commentary from the group mentions a hive mind, or <a href="http://en.wikipedia.org/wiki/Collective_consciousness" target="_blank">collective consciousness</a> in psychology. Using IRC and Twitter, the group gathers like-minded individuals for operations and they effectively become a cell of the group.</p>
<p>Take for example the <a href="http://news.yahoo.com/anonymous-hackers-target-use-security-think-tank-190846242.html" target="_blank">recent attack on Stratfor</a> by Anonymous. The initial news reports credited the attack to Anonymous, as the hack <a href="http://zone-h.org/mirror/id/16416728">and defacement of the Stratfor web page</a> was signed Anonymous. Shortly after, <a href="http://pastebin.com/8yrwyNkt">an &#8220;Emergency Christmas Anonymous Press Release&#8221;</a> was released claiming the attack was <strong>not</strong> the work of Anonymous. A day after that, <a href="http://pastebin.com/q5kXd7Fd">another release appeared</a> once again taking credit as Anonymous. This back-and-forth credit game perfectly punctuates the problem with such a decentralized group.</p>
<p>Anonymous is less of a cohesive singular personality than it is a brand or a franchise &#8211; which can be borrowed by anyone &#8211; and it has been. <a href="http://pastebin.com/4vprKdXH" target="_blank">&#8220;Anonymous is not Unanimous&#8221;</a>. This introduces complications for the group, when anyone can claim involvement and then tarnish the brand. This can be used by a bored person or a more organized subversive group that seeks to undermine Anonymous.</p>
<div id="attachment_209" class="wp-caption aligncenter" style="width: 410px"><a href="http://www.geekosystem.com/hacker-family-tree/"><img class="size-full wp-image-209" title="anonymous_family_tree-small" src="http://cognitivedissidents.files.wordpress.com/2011/12/anonymous_family_tree-small.jpg?w=614" alt="Family Tree courtesy of Eric Limer - click for his full piece"   /></a><p class="wp-caption-text">Family Tree courtesy of Eric Limer - click for his full piece</p></div>
<p>More importantly, there has been at least one splinter group, LulzSec, that formed from Anonymous. A month after splintering, LulzSec and Anonymous announced that they &#8220;made up&#8221; so to speak, and fully support each other. With multiple groups operating and focusing on different goals, while still not having a defined roster, the question of membership becomes more important. This becomes evident when a journalist must qualify an interview in the headline: <a href="http://blogs.datadoctors.com/index.cfm/2011/6/24/Our-Exclusive-Interview-with-a-Member-of-LulzSec" target="_blank">Our &#8216;Possible&#8217; Interview with a Member of LulzSec</a>. The first part of the article further articulates the confusion:</p>
<blockquote><p>DataDoctors First question: How do we know that this is really a LulzSec account and not a wanna be fan?</p>
<p>Lulzsec: We do not represent the twitter voice of LulzSec. We are the original founders.</p></blockquote>
<p>Further updates to the article indicate LulzSec denied this person is legit, while the interviewee insists they are part of a splinter group of LulzSec. Regardless, the one thing that is abundantly clear is that leadership appears to be in short supply. Despite that, there is some sense of leadership, as hundreds, if not thousands, of members can mobilize to achieve the same goal. Temporary thought leaders can emerge on designated IRC channels. Anyone can take up this title by being in channel and making an argument that people want to follow.</p>
<h3>Fact or Fiction: Hacktivism is New</h3>
<p>Digital or <a href="http://en.wikipedia.org/wiki/Internet_activism" target="_blank">Internet activism</a> is the use of technology to facilitate a group of people to more effectively communicate over large distance in order to effect some form of change. When one of the methods used to this end is hacking (generally accepted as committing some form of computer crime), the term &#8220;<a href="http://en.wikipedia.org/wiki/Hacktivism" target="_blank">hacktivism</a>&#8221; is used. Anonymous has used hacking as a vehicle to expose private information they felt should be public.</p>
<p>Hacktivism predates Anonymous by a decade a more. Perhaps the first documented instance comes from 1989, when a <a href="http://en.wikipedia.org/wiki/WANK_%28computer_worm%29" target="_blank">malicious worm called &#8220;WANK&#8221;</a> was used to protest nuclear weapons. According to <a href="http://en.wikipedia.org/wiki/Hacktivism#Notable_hacktivist_events" target="_blank">Wikipedia&#8217;s timeline of hacktivism</a>, the first <a href="http://en.wikipedia.org/wiki/Intervasion_of_the_UK" target="_blank">incident of hacktivism</a> not involving self-replicating software was the &#8220;Intervasion of the UK orchestrated by a group called the Zippies on Guy Fawkes Day&#8221;. While unrelated to the group Anonymous, the coincidence of it occurring on Guy Fawkes Day is certainly interesting.</p>
<p>Not all hacktivism involves illegal activity. The legitimate use of technology to gain access to information from diverse sources and piecing it together can often appear to be the result of hacking. Using <a href="http://en.wikipedia.org/wiki/Open-source_intelligence" target="_blank">open-source intelligence (OSINT)</a> to piece together details, it is possible expose a wide range of information that may not have been thought of as public, despite being available to anyone that looked for it. This activity historically took the form of &#8220;doxing&#8221; (document dropping), an old practice of exposing detailed personal information about an individual such as name, phone number, address, or relative names. Primarily used as a threat or indirect attack, exposing a person conducting illegal hacking in such a way can assist law enforcement in apprehending the person. However, by publishing information on people in sensitive positions (e.g., law enforcement that may be undercover) or persons wishing to stay out of the spotlight (e.g., political donors), &#8220;doxing&#8221; can be used by activists in a similar manner.</p>
<h3>Fact or Fiction: A Force for Good</h3>
<p>A fundamental trait of many original Anonymous is their desire to do good. The group&#8217;s actions are born out of a sense of righting wrongs and combatting injustice. There is an ethical delimna when achieving goals in pursuit of good require breaking the law, but it is one the group sees as a necessary evil. Despite good intentions, some of the group&#8217;s activities are certainly questionable, while others are clearly misguided and do more harm than good.</p>
<p>In early December, 2011, Anonymous <a href="http://www.theregister.co.uk/2011/12/02/oprobinhood_who_pays/" target="_blank">drew criticism for &#8220;OpRobinHood&#8221;</a>, an operation intended to steal from the rich and give to the poor. This idea was great in theory, but many suspected it would end up hurting the common people, not banks or big corporations. This was put to the test when <a href="http://thedrum.co.uk/news/2011/12/28/anonymous-hackers-act-robin-hood-unauthorised-donations" target="_blank">credit cards pilfered from the Stratfor hack</a> were used to donate to several charities. Instead of helping charities, the <a href="http://www.huffingtonpost.com/2011/12/28/anonymous-stratfor-hack-c_n_1172926.html" target="_blank">fraudulent transactions are being returned</a>. Not only did the money not end up helping the charities, the misguided attempt to help ended up causing them administrative overhead in trying to make things right. Worse, at least one charity <a href="https://twitter.com/#!/aidg/status/151350204929556480" target="_blank">said they are charged $35 for each fraudulent transaction</a> and pleaded with Anonymous not to make any more donations. The full story and operation have yet to play out, but early signs show that things are more complex and more cleanly &#8216;good&#8217; in practice, than in theory.</p>
<p>Ultimately, in attempting to help the poor and needy, Anonymous has hurt both charities and common people. The credit cards taken from Stratfor were not corporate cards tied to faceless businesses. They were mostly personal credit cards of average citizens, including <a href="http://www.huffingtonpost.com/2011/12/25/anonymous-stratfor-hack-hackers-hacking_n_1169268.html" target="_blank">some that had to close their accounts and did not have the money donated</a>. The banks will likely not absorb the cost of the fraudulent transactions. Rather, they will pass the costs around to merchants in the form of additional fees. This may in turn lead to an increased cost of service as merchants pass the costs down. In the end, Anonymous may have robbed from the poor, not the rich.</p>
<h3>Fact or Fiction: Anonymous and LulzSec Make you Vulnerable</h3>
<p>The classic phrase, &#8220;don&#8217;t shoot the messenger&#8221; must be remembered. While it takes a criminal to break into your system and cause some form of mischief, that person <strong><span style="text-decoration:underline;">did not make your system vulnerable</span></strong>. They merely exploited the vulnerabilities that were already present. Either through manufacturer defect or misconfiguration, the system has weaknesses before the hacker attackers. The private information that is being exposed by groups such as Anonymous and LulzSec was being stored on systems with inadequate protection.</p>
<p>Members of LulzSec have claimed their activity was based on showing that <a href="http://answers.yahoo.com/question/index?qid=1006050209041" target="_blank">the emperor has no clothes</a>. Subsequently, LulzSec believes they have revived the <a href="http://en.wikipedia.org/wiki/Antisec_Movement" target="_blank">Antisec Movement</a>, focusing on general insecurity, where the original movement was based primarily on exposing problems with security companies and professionals. Others following in the footsteps of LulzSec fomented the Antisec Movement by attacking not only security companies, but any other company they found to be vulnerable.</p>
<h3>Fact or Fiction: Anonymous and LulzSec are a Terrorist Organization</h3>
<p>Until recently, most media outlets and victims of Anonymous&#8217; actions have labeled them a nuisance or criminals. With the <a href="http://latimesblogs.latimes.com/technology/2011/06/azdps.html" target="_blank">publishing of the Arizona Department of Public Safety confidential documents</a>, Jimmy Chavez, president of the Arizona Highway Patrol Association, went one step farther by labeling them a terrorist organization:</p>
<blockquote><p>&#8220;They don&#8217;t need any additional pressure on them from a &#8212; let&#8217;s just call it what it is &#8212; a terrorist organization.&#8221; &#8212; Jimmy Chavez</p></blockquote>
<p>Noted privacy researcher and advocate <a href="http://www.pogowasright.org/?page_id=5661" target="_blank">Dissent</a> <a href="http://twitter.com/PogoWasRight/statuses/84446410862379008" target="_blank">once commented</a>, &#8220;It was a Class C misdemeanor when an AZ state employee revealed PII that endangered others, but when @LulzSec did it, it&#8217;s &#8216;terrorism?&#8217;&#8221; Chavez&#8217; labeling either group a &#8220;terrorist organization&#8221; is disingenuous and self-serving at best, as Anonymous / LulzSec&#8217;s activity certainly don&#8217;t fit the <a href="http://en.wikipedia.org/wiki/Terrorism" target="_blank">definition of terrorism</a>. Increasingly aggressive acts against policy makers and law enforcement will certainly invite the term &#8216;terrorist&#8217;, even if it is misapplied. In addition, given the diverse nature of the group, many members or people that identify with Anonymous have morals that would preclude them from staying involved if they thought they were close enough to even be mistaken for &#8220;terrorism&#8221;. Further, such a brand would work to counter their objectives and movement.</p>
<h3>Fact or Fiction: They Are Not Moral</h3>
<p>Cries that Anonymous is not legitimate in the activism movement because of a supposed lack of morals are shortsighted. It simply does not matter if you feel they are moral or not. Their activities are not about <strong>your</strong> morals or values. Ethics are a secondary thought at best; if Anonymous feels that a specific action will have the desired result, they act based on their perception of the greater good. It is clear that to many involved, <em>the ends justify the means</em>. In other cases, for some members of Anonymous, the real-world consequences for their digital activity may not be fully realized.</p>
<p>As previously covered, the notion that such a group adheres to any one set of beliefs, morals or code of ethics is wrong. With a large, nebulous, diverse group such as Anonymous, we must also consider that decisions are unlikely to be made according to any one person&#8217;s sense of morality (more on this later), making it difficult to ascribe an ethical standard to the group as a whole. There are simply too many factors at play and too many individuals affiliated with the group to ascribe a binary value of &#8220;yes&#8221; or &#8220;no&#8221; to the question of Anonymous&#8217; morals.</p>
<h3>Fact or Fiction: The Concept of &#8220;Organized Chaos&#8221; is Absurd</h3>
<p>As people try to wrap their head around the concept of such a fundamentally different group, conclusions are reached that seem contradictory. The idea that a group or idea can be &#8220;organized chaos&#8221; appears to be an oxymoron, yet it certainly applies. The loose structure, lack of central leadership, diverse objectives, and wide range of tools at their disposal speak to this. They are certainly organized, as demonstrated by the <a href="http://articles.sfgate.com/2011-08-22/news/29913744_1_sony-s-playstation-network-supporters-civic-center-station" target="_blank">BART protests</a>. They are also most assuredly chaotic, practicing a form of <a href="http://en.wikipedia.org/wiki/Civil_disorder" target="_blank">civil disorder</a> that borders on general chaos.</p>
<p>The concept that organization and logic can be found in chaotic situations has been studied and falls under the category of a <a href="http://en.wikipedia.org/wiki/Complex_adaptive_system" target="_blank">complex adaptive system</a>. Both <a href="http://www.amazon.com/exec/obidos/ISBN=0716727250/insekurityorgA/" target="_blank">Murray Gell-Mann</a> and <a href="http://www.public.asu.edu/~kdooley/papers/iebm.PDF" target="_blank">Kevin Dooley</a> write about the topic as it applies to a variety of systems, including socially. Dooley writes:</p>
<blockquote><p>Contingency theory states that an organization structures itself and behaves in a particular manner as an attempt to fit with its environment. Thus organizations are more or less complex as a reaction to environmental complexity. An organization&#8217;s environment may be complex because it is turbulent, hostile, diverse, technologically complex, or restrictive. An organization may also be complex as a result of the complexity of its underlying technological core.</p></blockquote>
<p>Applying this to Anonymous is fitting and revealing.</p>
<h3>Fact or Fiction: They Believe in Anonymity</h3>
<p>As their name suggests, the group certainly cherishes their own anonymity. With some of their actions crossing moral and legal lines, anonymity becomes a protective blanket to keep them running afoul of the law. However, there is a flip side; many affiliated with Anonymous do not believe in the anonymity of the people they expose. This can be seen in their <a href="http://www.californiabeat.org/2011/08/17/anonymous-hackers-attack-bart-police-leak-list-of-officers-contact-information" target="_blank">leaking of BART police information</a>, <a href="http://www.theatlanticwire.com/national/2011/07/anonymous-leaks-90000-military-emails/39822/" target="_blank">leaking Booz Allen email and logins</a>, and <a href="http://datalossdb.org/incidents/3926" target="_blank">Arizona law enforcement information leak</a> that included officer and confidential informant information. During our feisty DEFCON Q&amp;A, David Etue posed this to the Anons participating in the exchange:</p>
<blockquote><p>&#8220;There is something paradoxical about a group that promotes transparency, but isn&#8217;t transparent themselves; and believes in anonymity, but negatively impacts the anonymity of others. How do you resolve your values and operations?&#8221; &#8212; David Etue</p></blockquote>
<p>This is further exacerbated when Anonymous claims to fight for the people, yet performs actions that directly hurt the common person. Leaking databases full of consumer information surely teaches a company a lesson in security, but does so in a manner that yields a high amount of collateral damage. Leaking the personal information about police officers and their family makes a point, but does not fight corruption or the relatively small number of &#8220;bad apples&#8221; in police departments. This not only belies a cognitive dissonance, but may also hint at the presence of less noble/righteous participants &#8211; and even psychopathy within the group.</p>
<h3>Fact or Fiction: Anonymous Supports Free Speech &amp; Civil Liberty</h3>
<p>On the surface, this is most assuredly true. Looking deeper, there appears to be a lack of understanding of causality that could drastically impact both free speech and civil liberties. Legislators have a history of introducing <a href="http://www.efa.org.au/Issues/Privacy/cybercrimeact.html" target="_blank">new laws as part of a knee-jerk reaction</a> to a high profile negative incident. If Anonymous continues to break the law to achieve their goals, they risk legislators replying the only way they know how; more legislation. In doing so, the risk of sweeping laws being enacted that are poorly considered is high. This could lead to new laws that limit free speech, suspend or restrict civil liberty, and take away freedoms we currently enjoy. As one of the authors remarked at DEFCON and elsewhere,</p>
<blockquote><p>When threatened&#8230; powerful, uninformed people make powerfully uninformed decisions.</p></blockquote>
<p>If Anonymous continues in the same fashion as they have for years, what will the group say when a &#8220;Cyber Patriot Act&#8221; modeled after the <a href="http://en.wikipedia.org/wiki/USA_PATRIOT_Act" target="_blank">Patriot Act</a> or &#8220;Cyber <a href="http://en.wikipedia.org/wiki/McCarthyism" target="_blank">Neo-McCarthyism</a>&#8221; is enacted as a direct result of their actions?</p>
<h3>Fact or Fiction: Disinformation Cuts Both Ways</h3>
<p>With such a radical shift from a classic activist group, the level of inaccurate or misleading information is immense. The disinformation we see about Anonymous and their actions come from a variety of sources, including the media, analysts, law enforcement, chaotic actors (that may or may not associate with the group) and Anonymous themselves.</p>
<p>Law enforcement and media are consistently contributing to a campaign of disinformation, often times without realizing it. As we see more frequent articles announcing the &#8220;bust of # members of Anonymous&#8221;, it gives the perception that law enforcement is making steady progress fighting the group. In addition, it is easy to read into such articles and believe that they are &#8220;key&#8221; or &#8220;core&#8221; members of the group. In reality, they may be casual members, sympathizers or completely unaffiliated with the group. Regardless of their affiliation, once the announcement is made, they are branded as such and the world is rarely exposed to a correction or follow-up with details. The articles that claim &#8220;Topiary of LulzSec busted&#8221; or &#8220;Commander X taken down&#8221; also call into question the ratio of persons to handles. What if multiple people assume the same name, just as they assume one name as a group?</p>
<p>There are an increasing number of people that consider themselves ex-Anonymous. For a variety of reasons, they no longer identify themselves as part of the group. For example, &#8220;SparkyBlaze&#8221; quit the group leaving a <a href="http://pastebin.com/WYJS303d" target="_blank">missive behind</a> focusing on Anonymous removing innocent peoples&#8217; right to stay anonymous themselves. In a few cases, the persons will stay involved to some degree. For example, Gregg Housh no longer identifies with the group, but calls himself an observer of the group as he maintains <a href="http://chanologytimeline.com/" target="_blank">a timeline related to Anonymous</a>. Another person that is involved, but from a slightly removed stance, is <a href="https://twitter.com/#!/St4rFox" target="_blank">St4rFox</a> (Twitter feed now gone), who has talked about his involvement in running a site to <a href="http://anonnews.org/?a=item&amp;i=661&amp;p=press" target="_blank">train would-be Anonymous members</a> on hacktivism and hacking, titled Operation NewBlood. Both of these individuals call to question if they are part of the group as a fringe element, members of the group that are attempting to manage public perception, or simply acting as sources of information and disinformation as is convenient.</p>
<p>With dozens of Twitter feeds likely operated by twice as many people, the level of accuracy and trustworthiness of the information being broadcast by Anonymous is questionable. With so many sources of noise about the group, for example <a href="https://twitter.com/#!/JosephKBlack" target="_blank">Joseph Black and his creating confusion with wild claims</a>, it becomes hard to find the signal. Finally, there are an unknown number of actors that are influencing, or attempting to influence, perception of the group such as a supposed Federal Bureau of Investigation (FBI) psychological profile of Anonymous that was later <a href="http://nakedsecurity.sophos.com/2011/09/16/fake-fbi-anonymous-psychological-profile/" target="_blank">determined to be fake</a>. Additionally, private citizens, some with an <a href="http://arstechnica.com/tech-policy/news/2011/02/how-one-security-firm-tracked-anonymousand-paid-a-heavy-price.ars" target="_blank">apparent motive to profit</a>, have been <a href="http://www.dailymail.co.uk/news/article-2049899/Thomas-Ryan-Meet-whiz-snitched-Occupy-Wall-Street-protesters.html" target="_blank">attempting to infiltrate their ranks</a>.</p>
<h3>Anonymous: A Visit from Rorschach</h3>
<p>This isn&#8217;t a case of fact versus fiction, this is a simple truth about human nature and perception. We project our own desires, fears and love on others, and Anonymous is no different. Anonymous is a real Rorschach test, helping us discover what we see in the group day to day. Yes, day to day because perception changes quickly, and what we see in the group can change just as quickly. Early on, one author of this article saw Anonymous as &#8220;light gray hats demonstrating insecurity to catalyze security&#8221;. Over time, that opinion changed as more activity occurred and Anonymous matured.</p>
<p>Many sympathetic to Anonymous see them as a group of Robin Hoods, hitting the rich and powerful in the name of the oppressed people. Some analysts see them more as the Joker, a purely chaotic actor that wants to see the world burn. Others romanticize the group, seeing the greater good they hope to accomplish, falling in love with the anti-hero &#8216;V&#8217;. This projection and perception says more about us than it does about Anonymous. In short, <a href="http://blog.cognitivedissidents.com/2011/11/11/an-anonymous-ink-blot-rorschach/" target="_blank">we see what we want to see</a> in the group.</p>
<p>In the next installment: &#8220;How We Got It All Wrong&#8221;.</p>
<p>&nbsp;</p>
<p>Copyright 2011 by Josh Corman and Brian Martin. Permission is granted to quote, reprint or redistribute provided the text is not altered, appropriate credit is given and a link to the original copy is included. Custom graphic courtesy of Mar - <a href="http://sudux.com/" target="_blank">sudux.com</a>.</p>
<p>Should you feel generous, please donate a couple of bucks on our behalf to any 501(c)(3) non-profit that benefits animals or computer security.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/207/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/207/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/207/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=207&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2011/12/29/building-a-better-anonymous-series-part-2/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/anonymous_rorschach.jpg" medium="image">
			<media:title type="html">anonymous_rorschach</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/anonymous_family_tree-small.jpg" medium="image">
			<media:title type="html">anonymous_family_tree-small</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;Building a Better Anonymous&#8221; Series: Part 1</title>
		<link>http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-1/</link>
		<comments>http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-1/#comments</comments>
		<pubDate>Wed, 21 Dec 2011 01:25:37 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Anonymous]]></category>

		<guid isPermaLink="false">http://blog.cognitivedissidents.com/?p=128</guid>
		<description><![CDATA[Part 1: Introduction &#38; Approach By Josh Corman &#38; Brian Martin 2011 If you are new to this series, please begin with Part 0 and the index. NOTE: We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=128&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_131" class="wp-caption aligncenter" style="width: 510px"><a href="http://cognitivedissidents.files.wordpress.com/2011/12/anonymous_soap.jpg"><img class="size-full wp-image-131" title="anonymous_soap" src="http://cognitivedissidents.files.wordpress.com/2011/12/anonymous_soap.jpg?w=614" alt="Expect Anonymous Fight Club Soap (Artwork by Mar - sudux.com)"   /></a><p class="wp-caption-text">Expect Anonymous Fight Club Soap (Artwork by Mar - sudux.com)</p></div>
<h2>Part 1: Introduction &amp; Approach</h2>
<h3>By Josh Corman &amp; Brian Martin</h3>
<h3>2011</h3>
<p>If you are new to this series, please begin with <a title="“Building a Better Anonymous” Series: Part 0" href="http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/" target="_blank">Part 0</a> and the index.</p>
<p><strong>NOTE:</strong> We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. Please comment toward improving/clarifying the content.</p>
<h3><span style="text-decoration:underline;">Why Write This &amp; Operating Parameters</span></h3>
<p>As we sit here to write this in October and November of 2011, we&#8217;d like to render a few things explicit. As objective observers, we&#8217;ve seen the rise of Anonymous and other chaotic actors as both intriguing and &#8220;of consequence&#8221;. We&#8217;ve also seen very little in the way of what we&#8217;d call &#8220;insight&#8221; or &#8220;understanding&#8221; toward the evolution of the &#8220;group(s)&#8221;. Those who are publicly speaking don&#8217;t seem to &#8220;get it&#8221;. Those who seem to have insight are frequently unwilling (and in many cases afraid) to speak.</p>
<p>So with natural curiosity, we have attempted to ask questions, engage in dialectic, apply logic and analysis, and see if other willing minds can&#8217;t nudge the conversation forward in useful and non-confrontational ways for the benefit of all. As the group(s) continue to morph and evolve &#8211; and as our comprehension (hopefully) improves, this will clearly re-cast the content of what you will read throughout these articles. We will attempt to capture thought at this time &#8211; and when necessary, we may adjust/augment/update against this point-in-time content.</p>
<p>Operating parameters of this series:</p>
<ul>
<li>We are not now, nor have we ever been, members of Anonymous</li>
<li>We have not joined any IRC rooms affiliated with Anonymous</li>
<li>We are not seeking to &#8220;break&#8221; any story, but rather to logically analyze events as they unfold and to anticipate likely future scenarios and developments</li>
<li>We are not seeking to identify or investigate individuals, but rather to understand broader attitudes and motivations</li>
<li>By writing this article, we are not endorsing or denouncing Anonymous</li>
</ul>
<h3></h3>
<h3><span style="text-decoration:underline;">Anonymous Background</span></h3>
<p>Unstructured and nebulous, a group called <a title="Wikipedia Anonymous" href="http://en.wikipedia.org/wiki/Anonymous_(group)" target="_blank">Anonymous</a>, born in the trenches of virtual trolling, has become a household name based on a reputation of civil disobedience and digital activism. They are a wildly diverse and unpredictable group, one that takes up arms to fight a varied collection of causes, while having no stated charter or organizational chart. Despite these seemingly limiting traits, Anonymous has flourished and become a force to be feared or respected, but not reasoned with.</p>
<p>Many people believe they know the history &#8211; but &#8220;which one?&#8221; The <a href="http://resources.infosecinstitute.com/a-history-of-anonymous/" target="_blank">history of Anonymous</a> is just as murky as trying to define them. The very brief history we present below could be thought of as a commonly accepted history. However, a <a href="http://www.socialtextjournal.org/blog/2011/09/is-it-a-crime-the-transgressive-politics-of-hacking-in-anonymous.php" target="_blank">similar history</a> claims the background is more wrong than right. Gregg Housh, a former Anonymous member who now observes the group, has put together a <a href="http://chanologytimeline.com/" target="_blank">considerably more thorough &#8220;chanology timeline&#8221;</a> that attempts to chronicle all events related to Anonymous.</p>
<p>Formed in 2003, Anonymous was born out of a community / forum known as &#8220;4chan&#8221;, with a subset message board called &#8220;/b/&#8221;. Gawker wrote <a href="http://gawker.com/346385/what-the-hell-are-4chan-ed-something-awful-and-b" target="_blank">a concise summary of these boards and other 4chan affiliated projects</a>, to better explain the origin of today&#8217;s Anonymous. Widely perceived as putting their attention and power toward a greater good only in the last three years, Gawker notes that <a href="http://gawker.com/5629066/4chan-is-turning-into-internet-good-guys" target="_blank">previous pranks may have begun to show their &#8216;good&#8217; side</a> much earlier. Based on the concept of an anonymous community that became a shared collective identity, the Anonymous name gained international attention in 2008 for <a href="http://en.wikipedia.org/wiki/Project_Chanology" target="_blank">Project Chanology</a>, a coordinated fight against the <a href="http://en.wikipedia.org/wiki/Church_of_Scientology" target="_blank">Church of Scientology</a>. Years before Project Chanology, <a href="http://en.wikipedia.org/wiki/Anonymous_(group)#Activities_during_2006-07" target="_blank">between 2006 and 2007</a>, Anonymous demonstrated that they were heading down a path of righteousness with several high profile activities. In <a href="http://en.wikipedia.org/wiki/Anonymous_(group)#Activities_during_2009" target="_blank">subsequent years</a>, the group <a href="http://en.wikipedia.org/wiki/Anonymous_(group)#Activities_during_2010" target="_blank">continued activities that garnered mainstream media</a> <a href="http://en.wikipedia.org/wiki/Anonymous_(group)#Activities_during_2011" target="_blank">that demonstrated the concept of digital activism</a>, sometimes based on illegal hacking activity.</p>
<p>Anonymous activities in 2011 have helped them become a household name, covered by all types of media and gaining increased attention from law enforcement and pundits. Security firm and government contractor <a href="http://hbgaryfederal.com/" target="_blank">HBGary Federal</a> angered Anonymous after claims that they were working with the FBI to unmask key Anonymous members, <a href="http://arstechnica.com/tech-policy/news/2011/02/anonymous-to-security-firm-working-with-fbi-youve-angered-the-hive.ars" target="_blank">resulting in more than 60,000 private e-mails of CEO Aaron Barr and other employees being published</a>. In response to <a href="http://www.redmondpie.com/geohot-sued-by-sony-over-ps3-jailbreak/" target="_blank">Sony suing Geohot (aka George Hotz)</a>, Anonymous launched a Distributed Denial of Service (DDoS) against the corporate giant, resulting in <a href="http://arstechnica.com/tech-policy/news/2011/05/anonymous-sony-is-incompetent-and-we-dont-steal-credit-cards.ars" target="_blank">Sony blaming them for subsequent attacks</a> they had no declared part in, <a title="sony_aka_sownage" href="http://attrition.org/security/rants/sony_aka_sownage.html" target="_blank">which were numerous</a>. Banking giant Bank of America dealt with Anonymous when they <a href="http://www.huffingtonpost.com/2011/03/14/bank-of-america-anonymous-leak-mortgage_n_835220.html" target="_blank">released internal mails that claimed to prove corruption and fraud</a>. <a href="http://en.wikipedia.org/wiki/Operation_AntiSec" target="_blank">&#8220;Operation Anti-sec&#8221; was (re)born</a>, with the <a href="http://en.wikipedia.org/wiki/LulzSec" target="_blank">Anonymous splinter group LulzSec</a> teaming back up with their parent group to protest a list of government transgressions by breaking into numerous sites ranging from the <a href="http://www.azdps.gov/" target="_blank">Arizona Department of Public Safety</a> to <a href="http://www.thetimes.co.uk/tto/news/" target="_blank">The Times</a> to the <a href="https://twitter.com/#!/foxnews" target="_blank">Fox News Twitter Account</a>. One of the most recent attacks after our DEFCON 19 panel was launched against the <a href="http://www.bart.gov/" target="_blank">Bay Area Rapid Transit (BART)</a> after the <a href="http://www.sfexaminer.com/local/bay-area/2011/06/mehserle-protests-oakland" target="_blank">death of BART passenger Oscar Grant</a>, leading to BART customer information being exposed and increased calls for protests. These activities, and more, have resulted in the group being perceived as more dangerous as well as more effective.</p>
<h3><span style="text-decoration:underline;">Understanding Anonymous</span></h3>
<p>It is not easy to claim understanding of a group so diverse as Anonymous. At best, one can attempt to understand some of the fundamental principles and ideas that motivate some, but not all, members. There are several articles that attempt to display this understanding, written from a variety of perspectives (and possibly involvement). For example, Adrian Crenshaw wrote &#8220;<a href="http://www.irongeek.com/i.php?page=security/understanding-anonymous" target="_blank">Crude, Inconsistent Threat: Understanding Anonymous</a>&#8220;, in which he discusses the motivation and organization of the group. Josh Corman, co-author of this article &#8220;<a href="http://www.csoonline.com/article/682511/the-rise-of-the-chaotic-actor-understanding-anonymous-and-ourselves" target="_blank"> has previously written about the topic</a>&#8220;. Cole Stryker has even authored a book on the topic, titled &#8220;<a href="http://www.amazon.com/exec/obidos/ISBN=1590207106/insekurityorgA/" target="_blank">Epic Win for Anonymous: How 4chan&#8217;s Army Conquered the Web</a>&#8220;. One thing should remain clear; no one person will ever fully understand Anonymous beyond the broad influences.</p>
<p>Throughout their history, Anonymous has exposed weakness and vulnerabilities in a wide variety of social and technical systems. In doing so, the group has been demonized unfairly by a wide range of people including the media and law enforcement. One fundamental truth that seems to escape many observers is that the vulnerabilities were already there. Anonymous just brought them to the public&#8217;s attention. In crying for the heads of Anonymous, we are effectively shooting the messenger bearing bad news. Gene Spafford, from the Center for Education and Research in Information Assurance and Security (CERIAS), <a href="http://www.cerias.purdue.edu/site/blog/post/bullies_pirates_and_lulz/" target="_blank">summarized the underlying issue that is absolutely critical</a> for everyone to understand:</p>
<blockquote><p>&#8220;First, if a largely uncoordinated group could penetrate the systems and expose all this information, then so could a much more focused, well-financed, and malevolent group &#8211; and it would not likely result in postings picked up by the media. Attacks by narcotics cartels, organized crime, terrorists and intelligence agencies are obvious threats; we can only assume that some have already succeeded but not been recognized or publicized.&#8221; &#8212; <a title="Spaf's Twitter page" href="http://twitter.com/#!/TheRealSpaf" target="_blank">Gene Spafford</a></p></blockquote>
<h3><span style="text-decoration:underline;">Anonymous Zeitgeist in Popular Media</span></h3>
<p>For those who wish to avoid the laborious task of trying to define a chaotic and disparate group, there are several pop culture leanings that <strong>may</strong> help paint the group in a very broad stroke. These media references are based on Anonymous&#8217; actions and the authors&#8217; interpretation of their activity and writings.</p>
<div id="attachment_136" class="wp-caption aligncenter" style="width: 310px"><a href="http://cognitivedissidents.files.wordpress.com/2011/12/vforvendetta1.gif"><img class="wp-image-136 " title="VforVendetta" src="http://cognitivedissidents.files.wordpress.com/2011/12/vforvendetta1.gif?w=300&h=300" alt="V for Vendetta by Alan Moore" width="300" height="300" /></a><p class="wp-caption-text">V for Vendetta by Alan Moore</p></div>
<p>Due to the adoption of the <a href="http://en.wikipedia.org/wiki/Guy_Fawkes" target="_blank">Guy Fawkes</a> mask as a symbol of the group, perhaps the most popular pop culture reference would be Alan Moore&#8217;s <a href="http://www.imdb.com/title/tt0434409/" target="_blank">V for Vendetta</a>. Toward the end of the movie, the protagonist V outfits thousands of citizens in a black cloaks and Fawkes masks to create an anonymous army of sympathizers fed up with the totalitarian government. This scene is perhaps the ultimate symbolism for the group as we know it; an army of oppressed citizens finally fed up with an abusive regime that has stripped them of privacy, civil liberty and ultimately power.</p>
<div id="attachment_135" class="wp-caption aligncenter" style="width: 172px"><a href="http://cognitivedissidents.files.wordpress.com/2011/12/fightclub.jpg"><img class="wp-image-135 " title="Fight Club by Chuck Palahniuk" src="http://cognitivedissidents.files.wordpress.com/2011/12/fightclub.jpg?w=162&h=240" alt="Fight Club by Chuck Palahniuk" width="162" height="240" /></a><p class="wp-caption-text">Fight Club by Chuck Palahniuk</p></div>
<p>Chuck Palahniuk&#8217;s <a href="http://www.amazon.com/exec/obidos/ISBN=0393327345/insekurityorgA/" target="_blank">Fight Club</a> touches on broad leanings of Anonymous members. The idea of a near cult-like group engaging in diverse projects under the names &#8216;Project Mischief&#8217; and &#8216;Project Mayhem&#8217; certainly draws parallels to Anonymous. Members of the group determine their own level of involvement, a strong theme of Anonymous. Ultimately, tapping into the latent frustration of members, eloquently summarized by Tyler Durden (Brad Pitt) in the movie adaptation:</p>
<blockquote><p>Man, I see in Fight Club the strongest and smartest men who have ever lived. I see all this potential, and I see it squandered. Goddammit, an entire generation pumping gas, waiting tables, slaves with white collars. Advertising has us chasing cars and clothes, working jobs we hate so we can buy shit we don&#8217;t need. We&#8217;re the middle children of history, man; no purpose or place. We have no Great War, no Great Depression. Our Great War is a spiritual war. Our Great Depression is our lives. We&#8217;ve all been raised by television to believe that one day we&#8217;d all be millionaires and movie gods and rock stars. But we won&#8217;t; and we&#8217;re slowly learning that fact. And we&#8217;re very, very pissed off.</p></blockquote>
<div id="attachment_137" class="wp-caption aligncenter" style="width: 203px"><a href="http://cognitivedissidents.files.wordpress.com/2011/12/watchmen.jpg"><img class="size-medium wp-image-137" title="Watchmen" src="http://cognitivedissidents.files.wordpress.com/2011/12/watchmen.jpg?w=193&h=300" alt="Watchmen by Alan Moore" width="193" height="300" /></a><p class="wp-caption-text">Watchmen by Alan Moore</p></div>
<p>Another Alan Moore graphic novel, <a href="http://www.amazon.com/exec/obidos/ISBN=0930289234/insekurityorgA/" target="_blank">The Watchmen</a>, highlights several aspects of the Anonymous collective; post-modern anti-heroes willing to do evil things to avoid a greater evil, a cast of characters confront and challenge both morality and alignment, redefining the popular concept of heroes embodying good. One of the running themes throughout the novel is the idea of &#8220;who watches the watchmen?&#8221;</p>
<div id="attachment_138" class="wp-caption aligncenter" style="width: 211px"><a href="http://cognitivedissidents.files.wordpress.com/2011/12/dark_knight.jpg"><img class="size-full wp-image-138" title="Dark_Knight" src="http://cognitivedissidents.files.wordpress.com/2011/12/dark_knight.jpg?w=614" alt="The Dark Knight"   /></a><p class="wp-caption-text">The Dark Knight</p></div>
<p><a href="http://www.amazon.com/exec/obidos/ASIN/B001GZ6QC4/insekurityorgA/" target="_blank">The Dark Knight</a> introduces people to a purely chaotic evil actor, The Joker, who the butler Alfred draws an allegory to. He tells Bruce Wayne of a bandit he helped chase in a forest who was throwing away the jewels he stole, saying &#8220;Some men aren&#8217;t looking for anything logical &#8230; [they] just want to see the world burn.&#8221; Wayne asks how he was ultimately caught. Alfred replies, &#8220;We burned the forest down.&#8221; A simple solution, but one that is easily argued as worse than the bandit&#8217;s actions. Opposite of the chaotic evil Joker is Batman, a chaotic good hero that demonstrates a steady scale of escalation to fight evil, just as Anonymous appears to do often times. At the same time, Anonymous likely has a handful of <a title="Chaotic Actors Corman 3x3 Alignment Chart" href="http://www.csoonline.com/images/editorial/illustrations/AlignmentChart_451_2of2_GoodVsEvil_LawfulVsChaotic.jpg" target="_blank">chaotic evil</a> actors involved, even if they don&#8217;t realize it yet.</p>
<div id="attachment_139" class="wp-caption aligncenter" style="width: 235px"><a href="http://cognitivedissidents.files.wordpress.com/2011/12/ghostintheshell_standalonecomplex_laughingman.jpg"><img class="size-full wp-image-139" title="GhostInTheShell_StandAloneComplex_LaughingMan" src="http://cognitivedissidents.files.wordpress.com/2011/12/ghostintheshell_standalonecomplex_laughingman.jpg?w=614" alt="Ghost In The Shell: Stand Alone Complex The Laughing Man"   /></a><p class="wp-caption-text">Ghost In The Shell: Stand Alone Complex The Laughing Man</p></div>
<p>There are several other notable media that draws parallels to Anonymous to some degree or another. <a href="http://www.amazon.com/exec/obidos/ASIN/B000HIVQAS/insekurityorgA/" target="_blank">Ghost in The Shell &#8211; Stand Alone Complex</a> is eerily prophetic about these concepts, with a villain named Laughing Man that is essentially a collective of infectiously contagious meme copycats of an original that may not even exist.<a href="http://www.imdb.com/title/tt0133189/" target="_blank">SLC Punk</a> showcases the fleeting catharsis, contradictions, inconvenience, and ultimate emptiness experienced by a few young anarchists.</p>
<div id="attachment_140" class="wp-caption aligncenter" style="width: 174px"><a href="http://cognitivedissidents.files.wordpress.com/2011/12/slc_punk.jpg"><img class="size-medium wp-image-140" title="SLC_Punk" src="http://cognitivedissidents.files.wordpress.com/2011/12/slc_punk.jpg?w=164&h=300" alt="SLC Punk!" width="164" height="300" /></a><p class="wp-caption-text">SLC Punk!</p></div>
<p>With the group constantly changing and adapting, losing followers as often as they gain new interest from the disenfranchised, understanding will come in small waves and require reexamination every step of the way.</p>
<p>Copyright 2011 by Josh Corman and Brian Martin. Permission is granted to quote, reprint or redistribute provided the text is not altered, appropriate credit is given and a link to the original copy is included. Custom graphic courtesy of Mar - <a href="http://sudux.com/" target="_blank">sudux.com</a>.</p>
<p>Should you feel generous, please donate a couple of bucks on our behalf to any 501(c)(3) non-profit that benefits animals or computer security.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/128/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/128/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/128/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=128&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-1/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/anonymous_soap.jpg" medium="image">
			<media:title type="html">anonymous_soap</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/vforvendetta1.gif" medium="image">
			<media:title type="html">VforVendetta</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/fightclub.jpg?w=202" medium="image">
			<media:title type="html">Fight Club by Chuck Palahniuk</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/watchmen.jpg?w=193" medium="image">
			<media:title type="html">Watchmen</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/dark_knight.jpg" medium="image">
			<media:title type="html">Dark_Knight</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/ghostintheshell_standalonecomplex_laughingman.jpg" medium="image">
			<media:title type="html">GhostInTheShell_StandAloneComplex_LaughingMan</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/slc_punk.jpg?w=164" medium="image">
			<media:title type="html">SLC_Punk</media:title>
		</media:content>
	</item>
		<item>
		<title>&#8220;Building a Better Anonymous&#8221; Series: Part 0</title>
		<link>http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/</link>
		<comments>http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/#comments</comments>
		<pubDate>Tue, 20 Dec 2011 23:35:21 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Anonymous]]></category>

		<guid isPermaLink="false">http://blog.cognitivedissidents.com/?p=113</guid>
		<description><![CDATA[By Josh Corman &#38; Brian Martin 2011 This multi-part article, with original artwork by Mar, is a follow-up to a one hour panel discussion at DEFCON 19 titled &#8220;&#8216;Whoever Fights Monsters&#8230;&#8217; Confronting Aaron Barr, Anonymous and Ourselves&#8221; moderated by Paul Roberts, discussed by Josh Corman, Brian Martin and Scot Terban. The views of the authors are not meant [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=113&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_114" class="wp-caption aligncenter" style="width: 610px"><a href="http://cognitivedissidents.files.wordpress.com/2011/12/better_anonymous.jpg"><img class="size-full wp-image-114" title="a_better_anonymous" src="http://cognitivedissidents.files.wordpress.com/2011/12/better_anonymous.jpg?w=614" alt="A Better Anonymous - (Artwork by Mar - sudux.com)"   /></a><p class="wp-caption-text">A Better Anonymous &#8211; (Artwork by Mar &#8211; sudux.com)</p></div>
<h3>By Josh Corman &amp; Brian Martin</h3>
<h3>2011</h3>
<p>This multi-part article, with original artwork by <a href="http://sudux.com/" target="_blank">Mar</a>, is a follow-up to a one hour panel discussion at <a href="http://www.defcon.org/" target="_blank">DEFCON 19</a> titled &#8220;&#8216;Whoever Fights Monsters&#8230;&#8217; Confronting Aaron Barr, Anonymous and Ourselves&#8221; moderated by Paul Roberts, discussed by Josh Corman, Brian Martin and Scot Terban. The views of the authors are not meant to be a criticism of Anonymous, nor are they meant to be encouragement for future criminal activity. It is an inevitable fact that Anonymous, or similar groups, will become bigger, stronger, and more effective. Discussions on how to build a more potent digital hacktivism group (illegal hacking to achieve a political goal) have occurred for over a decade. This article will not attempt to introduce groundbreaking new ideas, but rather will summarize many existing ideas and subject them to analysis from two security practitioners on two sides of this issue. If anything, this will serve more as a &#8216;Lessons Learned&#8217; with the aim of broadening the reader&#8217;s understanding of the topic, while demonstrating that the &#8220;problem&#8221; is not going away; the &#8220;problem&#8221; is evolving and growing.</p>
<p>When we say &#8220;building a better Anonymous&#8221;, we seek to explore the ideas of making such a group truly better. That means better for all parties involved; the group, end users, citizens and law enforcement. &#8220;Better&#8221; does not mean more criminal acts in the name of the greater good, it means a more efficient organization that can achieve the same (or better) results with less collateral damage. We envision a group with <a href="http://en.wikipedia.org/wiki/Goal_setting" target="_blank">better defined goals</a>, <a href="https://www.infosecisland.com/blogview/10617-Anonymous-Movement-is-Fueled-by-Cowardice.html" target="_blank">more accountability</a>, <a href="http://www.zdnet.com.au/mcdonalds-web-site-hacked-by-fluffy-bunny-120205255.htm" target="_blank">a healthy dose of humor</a> and the <a href="http://iceage.wikia.com/wiki/Scrat#Personality" target="_blank">legendary resolve</a> of the sabertooth squirrel. Of course, the chaotic nature of a group such as Anonymous means that any hopes of improvement will likely come in the form of small numbers of members guiding the rest toward these goals.</p>
<p><strong>NOTE:</strong> We will post each installment here for the security industry to garner feedback for about one week prior to posting to Forbes.com and a more mainstream and business readership. Please comment toward improving/clarifying the content.</p>
<p>Below you will find an index for the series (links will be added as published):</p>
<h3>1) <a title="“Building a Better Anonymous” Series: Part 1" href="http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-1/">Introduction &amp; Approach</a></h3>
<p style="padding-left:30px;">A brief introduction to this article series and Anonymous.</p>
<h3>2) <a title="“Building a Better Anonymous” Series: Part 2" href="http://cognitivedissidents.wordpress.com/2011/12/29/building-a-better-anonymous-series-part-2/">Fact vs Fiction</a></h3>
<p style="padding-left:30px;">Figuring out the fact versus fiction of Anonymous.</p>
<h3>3) <a title="“Building a Better Anonymous” Series: Part 3" href="http://blog.cognitivedissidents.com/2012/02/13/building-a-better-anonymous-series-part-3/">How We Got it All Wrong</a></h3>
<p style="padding-left:30px;">How the media and professionals got it wrong.</p>
<h3>4) <a title="“Building a Better Anonymous” Series: Part 4" href="http://blog.cognitivedissidents.com/2012/03/08/building-a-better-anonymous-series-part-4/">How Anonymous Has Failed in Theory &amp; Practice</a></h3>
<p style="padding-left:30px;">Anonymous, as they are today, and various shortcomings.</p>
<h3>5) <a title="“Building a Better Anonymous” Series: Part 5" href="http://blog.cognitivedissidents.com/2012/04/12/building-a-better-anonymous-series-part-5/">Building a Better Anonymous &#8211; Philosophy</a></h3>
<p style="padding-left:30px;">A foundation/framework for improving on the Anonymous blueprint.</p>
<h3>6) <a title="“Building a Better Anonymous” Series: Part 6" href="http://blog.cognitivedissidents.com/2012/05/11/building-a-better-anonymous-series-part-6/">Building a Better Anonymous &#8211; Details</a></h3>
<p style="padding-left:30px;">Extending the new foundation for improving on the Anonymous blueprint.</p>
<h3>7) Abstract Ideas</h3>
<p style="padding-left:30px;">Other considerations relevant to this topic.</p>
<h3>8) Conclusion</h3>
<p style="padding-left:30px;">What have we learned, and what we hoped to teach.</p>
<p>Copyright 2011 by Josh Corman and Brian Martin. Permission is granted to quote, reprint or redistribute provided the text is not altered, appropriate credit is given and a link to the original copy is included. Custom graphic courtesy of Mar - <a href="http://sudux.com/" target="_blank">sudux.com</a>.</p>
<p>Should you feel generous, please donate a couple of bucks on our behalf to any 501(c)(3) non-profit that benefits animals or computer security.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/113/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/113/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/113/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=113&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2011/12/20/building-a-better-anonymous-series-part-0/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/12/better_anonymous.jpg" medium="image">
			<media:title type="html">a_better_anonymous</media:title>
		</media:content>
	</item>
		<item>
		<title>An Anonymous Ink Blot Rorschach</title>
		<link>http://blog.cognitivedissidents.com/2011/11/11/an-anonymous-ink-blot-rorschach/</link>
		<comments>http://blog.cognitivedissidents.com/2011/11/11/an-anonymous-ink-blot-rorschach/#comments</comments>
		<pubDate>Fri, 11 Nov 2011 19:39:32 +0000</pubDate>
		<dc:creator>joshcorman</dc:creator>
				<category><![CDATA[Anonymous]]></category>

		<guid isPermaLink="false">http://cognitivedissidents.wordpress.com/?p=94</guid>
		<description><![CDATA[I have a &#8220;simple&#8221;, non-rhetorical question for you: When you look at Anonymous, what do you see? Context: Jericho (@attritionorg) and I have been working on a BLOG series about Anonymous, as a follow-on to our DEFCON19 Panel called &#8220;Whoever Fights Monsters: Confronting Aaron Barr, Anonymous and Ourselves&#8221;. We&#8217;re pretty close to posting the 1st of [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=94&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<div id="attachment_96" class="wp-caption alignnone" style="width: 510px"><a href="http://cognitivedissidents.files.wordpress.com/2011/11/anonymous_rorschach.jpg"><img class="size-full wp-image-96  " title="Anonymous Rorschach (by MAR @ sudux.com) - http://cognitivedissidents.wordpress.com" src="http://cognitivedissidents.files.wordpress.com/2011/11/anonymous_rorschach.jpg?w=614" alt="Anonymous Rorschach Ink Blot (Artwork by Mar - sudux.com) - http://cognitivedissidents.wordpress.com"   /></a><p class="wp-caption-text">We see in Anonymous what we WANT to see (Anonymous Rorschach) - (Artwork by Mar - sudux.com)</p></div>
<p>I have a &#8220;simple&#8221;, non-rhetorical question for you:</p>
<blockquote><p>When you look at Anonymous, what do <strong>you</strong> see?</p></blockquote>
<p><strong>Context:</strong></p>
<p>Jericho (<a title="Jerisho Twitter Page" href="https://twitter.com/#!/attritionorg" target="_blank">@attritionorg</a>) and I have been working on a BLOG series about Anonymous, as a follow-on to our DEFCON19 Panel called <a title="DEFCON 19 Abstract for our Anonymous Panel" href="http://www.defcon.org/html/defcon-19/dc-19-speakers.html#Roberts" target="_blank">&#8220;Whoever Fights Monsters: Confronting Aaron Barr, Anonymous and Ourselves&#8221;</a>. We&#8217;re pretty close to posting the 1st of these (possibly next week).</p>
<p>It dawned on me as we researched that <strong>one</strong> of the &#8220;distortion fields&#8221; surrounding &#8220;understanding Anonymous&#8221; is that we see in them what we WANT to see &#8211; like we do with a <a title="Rorschach Ink Blot Test on Wikipedia" href="http://en.wikipedia.org/wiki/Rorschach_test" target="_blank">Rorschach</a> ink blot test. We project. Our narrative says more about <strong><em>us</em></strong>, than it does about <strong><em>them</em></strong>. This is the double-edged sword that sometimes comes with symbols and iconography.</p>
<p>For those who didn&#8217;t immediately recognize the <a title="Wikipedia on Friedrich Nietzsche" href="http://en.wikipedia.org/wiki/Friedrich_Nietzsche" target="_blank">Friedrich Nietzsche</a> reference in that DEFCON title, it comes from this:</p>
<blockquote><p>Whoever fights monsters should see to it that in the process he does not become a monster. And if you gaze long enough into an abyss, the abyss will gaze back into you.</p></blockquote>
<p>As a teaser to our series &#8211; and as I finalize my slides for <a title="Joshua Corman: Adapting to the Age of Anonymous : SOURCE Barcelona" href="http://www.sourceconference.com/barcelona/schedule.asp#JCorman" target="_blank">my Anonymous talk</a> for next Thursday at <a title="SOURCE Barcelona Schedule" href="http://www.sourceconference.com/barcelona/schedule.asp" target="_blank">SOURCE Barcelona</a>, I thought I&#8217;d throw this <strong>Non-Rhetorical Question</strong> out to each of you&#8230;</p>
<p><strong>When you look at Anonymous, what do you see?</strong></p>
<p>As succinctly as you can &#8211; either within the Comment field or with a BLOG post/response of your own&#8230; please add your take on Anonymous (initially, today, going forward, all of the above&#8230;)</p>
<p>I hope to share some of the more interesting responses during my talk in Barcelona.</p>
<p>Remember&#8230; as you gaze into the Anonymous Abyss&#8230; it too gazes back into you.</p>
<p><strong>Artwork Note:</strong></p>
<p>This Rorschach and several other BEAUTIFUL pieces of orignal artwork come from -MAR- at <a title="MAR did our original Artwork  find her at sudux.com" href="http://sudux.com" target="_blank">sudux.com</a> &#8211; just amazing.</p>
<div id="attachment_97" class="wp-caption alignnone" style="width: 510px"><a href="http://cognitivedissidents.files.wordpress.com/2011/11/anonymous_rorschach1.jpg"><img class="size-full wp-image-97  " title="Anonymous Rorschach (by MAR @ sudux.com) - http://cognitivedissidents.wordpress.com" src="http://cognitivedissidents.files.wordpress.com/2011/11/anonymous_rorschach1.jpg?w=614" alt="Anonymous Rorschach Ink Blot (Artwork by Mar - sudux.com) - http://cognitivedissidents.wordpress.com"   /></a><p class="wp-caption-text">We see in Anonymous what we WANT to see... what do you see? (Artwork by Mar - sudux.com)</p></div>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/cognitivedissidents.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/cognitivedissidents.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/cognitivedissidents.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/cognitivedissidents.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/cognitivedissidents.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/cognitivedissidents.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/cognitivedissidents.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/cognitivedissidents.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/cognitivedissidents.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/cognitivedissidents.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/cognitivedissidents.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/cognitivedissidents.wordpress.com/94/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/cognitivedissidents.wordpress.com/94/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/cognitivedissidents.wordpress.com/94/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.cognitivedissidents.com&#038;blog=9852010&#038;post=94&#038;subd=cognitivedissidents&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.cognitivedissidents.com/2011/11/11/an-anonymous-ink-blot-rorschach/feed/</wfw:commentRss>
		<slash:comments>19</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/c8d70c435559e5d352c4b40c0d8a75ec?s=96&#38;d=identicon&#38;r=G" medium="image">
			<media:title type="html">joshcorman</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/11/anonymous_rorschach.jpg" medium="image">
			<media:title type="html">Anonymous Rorschach (by MAR @ sudux.com) - http://cognitivedissidents.wordpress.com</media:title>
		</media:content>

		<media:content url="http://cognitivedissidents.files.wordpress.com/2011/11/anonymous_rorschach1.jpg" medium="image">
			<media:title type="html">Anonymous Rorschach (by MAR @ sudux.com) - http://cognitivedissidents.wordpress.com</media:title>
		</media:content>
	</item>
	</channel>
</rss>
