On Thursday, the FBI arrested two suspected hackers who allegedly participated in Anonymous and LulzSec attacks. One of them, Cody Kretsinger, faces 15 years in prison for allegedly helping break into the Sony Pictures website with an SQL injection and publishing user data. As we described on Thursday, the indictment against Kretsinger says he used what's called a proxy server to hide his identity while carrying out the attack. But on Friday it emerged that the site he allegedly used to disguise his identity cooperated with police working to track him down. That's got some in the online privacy community very nervous.
The federal indictment against Kretsinger charges that he used a proxy server site called Hidemyass.com to disguise his Internet protocol address. Very basically, a proxy server works as an intermediary stop for a signal between one computer and another. By transmitting data through the proxy, a hacker can hide his or her ISP from the target. But since the proxy server gets between the machines on either end of that exchange, it is in a position to know details about the hacker. And if somebody investigating a hacking job gets access to that server, it can reveal their identity. That's apparently what happened in the investigation into Kretsinger. The details of that search haven't been made public yet, but a post on Hidemyass's blog says the company cooperated with police investigating the LulzSec actions.
Normal businesses do indeed regularly obey court orders. But something doing business as Hidemyass.com might not be thought to be a normal business. The service claims that "the world-wide-web should be world-wide and not censored in anyway," after which it goes on to highlight its popularity among protesters in Egypt when the government blocked access to Twitter. As the group Privacy International noted on its blog, that sets them up as "supra-legal arbiters of morality" who can choose to cooperate with some government requests and not others. Sony and the federal government see LulzSec hackers as criminal miscreants, but LulzSec sees itself as a revolutionary group.