[00:00.250 --> 00:01.810] Hello, everyone. [00:02.490 --> 00:03.650] I'm Micah Lee. [00:04.670 --> 00:06.790] I'm a hacker, a journalist. [00:07.170 --> 00:11.530] Up until a few months ago, I was the director of information security at The Intercept. [00:12.210 --> 00:16.270] And today I'm going to be talking about analyzing hacked and leaked data. [00:17.170 --> 00:28.850] So in late 2012, while I was working as a technologist at EFF, I got an anonymous encrypted email asking if I could help teach some journalists how to use PGP. [00:28.850 --> 00:30.330] And so I did. [00:30.590 --> 00:37.370] And I later learned that I was talking to Edward Snowden while he was leaking secret NSA documents to journalists. [00:37.690 --> 00:41.690] And so I've been doing investigative journalism ever since then. [00:42.370 --> 00:45.790] I worked at The Intercept for 10 years. [00:46.730 --> 00:48.610] But a few months ago, I got laid off. [00:49.830 --> 00:54.610] And now I'm an independent consultant and I'm actually like way too overemployed right now. [00:54.610 --> 01:05.330] I'm spending my time writing lots of code, doing some information security work for some very interesting people, including for Citizen Lab at the University of Toronto. [01:06.170 --> 01:20.690] And I'm also working on making some software called Semifemoral, which is an app that lets you delete all of your user generated content from across the Internet right when all the tech platforms are trying to sell all your data to AI companies. [01:22.130 --> 01:33.530] But back when I was working at The Intercept, I spent many years reporting on the Snowden documents, like digging through that archive and analyzing it and writing articles about it. [01:33.530 --> 01:38.210] And so since then, I've also analyzed many other hacked and leaked data sets, too. [01:38.470 --> 01:42.110] And now I've written a book to teach everyone else how to do it. [01:42.790 --> 01:45.430] And so that's what I'm going to be talking about. [01:45.630 --> 01:52.230] But before I tell you about the book, let me tell you about a few recent data leaks that you probably haven't heard of. [01:53.270 --> 01:59.590] So last month, the Kansas City Police was hacked by a ransomware gang called Black Suit. [01:59.890 --> 02:03.530] This is a Fox 4 Kansas City article about it. [02:03.690 --> 02:12.410] And according to this article, it says it would appear that the majority of the files held by the police and fire departments in Kansas City, Kansas have been compromised. [02:14.410 --> 02:31.610] And so after a bit of digging, I found Black Suit's Tor Onion service, which is, you know, all of the ransomware groups pretty much have an onion site like this where they publish data that they leak from companies and cities and stuff that don't pay their ransom. [02:32.070 --> 02:33.550] There's linked to the actual data. [02:35.550 --> 02:38.630] So I really didn't spend very much time on this data set. [02:38.630 --> 02:40.310] But I briefly clicked around. [02:40.390 --> 02:48.550] I found a folder called Investigative Bureau with 2024 FBI detective training in it, and it looked interesting. [02:48.750 --> 02:50.590] It looked like there were some interesting files in there. [02:52.230 --> 02:56.190] So this is from a file called VehicleTelematics.pdf. [02:56.610 --> 03:07.370] It has the FBI logo in the top right and the logo for a group within the FBI called CAST, which I figured out is Cellular Analysis Survey Team in the top left. [03:07.370 --> 03:22.890] So modern cars are basically smartphones, and this appears to be a flowchart explaining how FBI agents send subpoenas and search warrants to cell phone carriers like AT&T and T-Mobile and Verizon to get information about a target vehicle. [03:22.890 --> 03:25.950] So I'll talk about the groups in a second. [03:26.110 --> 03:39.190] But if the FBI is targeting a car within Group A, first they'll submit a subpoena to AT&T with a VIN, which is the unique identifier of a car, in order to get the MC, which is the unique identifier of a SIM card. [03:39.190 --> 03:50.030] And then if AT&T hands it over, they then send a search warrant to AT&T to get the actual data about the car. [03:50.270 --> 03:53.250] And this was also part of this PDF. [03:53.550 --> 03:55.010] These are the different types of cars. [03:55.010 --> 03:59.030] So there's Group A, Group B, and Group C. [03:59.210 --> 04:05.190] So if the FBI is investigating a target with a 2021 Tesla, then they're in Group B. [04:05.350 --> 04:12.630] And so that would mean that they would submit a subpoena to the manufacturer. [04:12.750 --> 04:17.370] So in this case, Tesla, they would contact Tesla, submit a subpoena with a VIN asking for the MC. [04:17.370 --> 04:20.470] And then once they get the MC, they would submit a search warrant to AT&T. [04:20.710 --> 04:24.730] So anyway, this is just like a thing that I happened to find that happened to look interesting. [04:25.610 --> 04:28.190] This was also another really interesting document in this dataset. [04:29.570 --> 04:35.450] This is from a 306-page PDF called 2023CastFieldResourceGuide.pdf. [04:35.890 --> 04:37.310] And here's a screenshot from it. [04:37.390 --> 04:39.610] And each of these boxes is like a section of the PDF. [04:39.910 --> 04:44.370] So naturally, I immediately went to the pages with the Apple and Google logos. [04:46.210 --> 04:53.810] So there was a lot of interesting stuff about how the FBI can get data from Apple and Google, specifically like about phones. [04:53.810 --> 05:00.290] But the most interesting to me was the Google location history parts of this PDF. [05:01.790 --> 05:11.130] So the document made it very clear that users need to have enable location history turned on on their phone for Google to be collecting this. [05:11.130 --> 05:17.190] And that if, you know, they turn it off and they delete their location history from Google, the FBI no longer can access it. [05:17.590 --> 05:20.270] And that, you know, the FBI needs a search warrant to get it. [05:20.410 --> 05:25.030] But I'm sure a lot of Android users have location history turned on. [05:26.530 --> 05:29.790] And it has a whole thing explaining how geofence warrants work. [05:29.950 --> 05:33.850] So this is an example where they draw a box around a specific area. [05:34.570 --> 05:40.910] And they specify a 12 hour timeframe between January 25th, 2017, 10 p.m. [05:41.050 --> 05:42.670] And the next morning, 10 a.m. [05:44.210 --> 05:50.010] And Google identified 140 accounts with location history in that geographic area during that time. [05:50.010 --> 06:01.550] So basically, if you have Google location history turned on, there's a chance that Google is handing over your location to the FBI because you happen to be physically or temporarily close to something that they're investigating. [06:02.410 --> 06:06.150] So anyway, there's much more in this Kansas City police data set. [06:06.330 --> 06:07.510] I barely looked at it. [06:07.570 --> 06:09.030] I only spent like maybe an hour. [06:09.570 --> 06:11.390] No one has published these documents. [06:11.610 --> 06:12.790] No one has reported on this yet. [06:12.790 --> 06:14.870] And I don't think anybody knows about it. [06:14.950 --> 06:15.770] You're the first to see it. [06:16.490 --> 06:18.590] I just found this like a few days ago. [06:19.290 --> 06:22.930] And so briefly, here's one more data set that you probably haven't heard of. [06:23.670 --> 06:32.330] A few months ago, a friend sent me a message on Signal about a data breach from the Post Millennial, which is a Canadian conservative news website. [06:32.330 --> 06:35.610] It publishes a lot of conspiracies and disinformation. [06:36.030 --> 06:37.170] It had been hacked. [06:37.190 --> 06:40.710] And this is the post on breach forums about it. [06:42.070 --> 06:46.050] So according to the breach forums post, the website was defaced with this message. [06:46.670 --> 06:49.950] Andy Ngo is a well-known far right extremist. [06:50.350 --> 06:52.790] And he's the editor at large of the Post Millennial. [06:53.110 --> 06:56.250] And so the website was replaced with this fake message from Andy Ngo. [06:56.670 --> 06:58.930] Coming out as a trans woman, Angelina Ngo. [06:59.370 --> 07:02.330] And so he's notorious for his anti-trans hate. [07:02.510 --> 07:04.390] So they're obviously trolling him. [07:04.890 --> 07:08.870] But anyway, a friend, my friend that sent me this, sent me a copy of all of the data. [07:08.870 --> 07:11.150] And I started to take a look at it. [07:12.950 --> 07:18.330] The data, it was a 1.7 gigabyte file called the postmillennial.com.7z. [07:18.850 --> 07:21.430] I extracted it and looked inside. [07:21.430 --> 07:29.270] And I used a command line tool called DU for disk usage to see that after it's extracted, it's 7.3 gigabytes when uncompressed. [07:29.830 --> 07:32.870] There are a few JSON files and there's a folder called dbs. [07:33.870 --> 07:41.170] So the dbs folder has a bunch of folders inside it ranging from a few bytes to a few gigabytes each. [07:42.210 --> 07:45.450] So I decided to start looking at the users.json folder. [07:46.050 --> 07:47.990] I opened it up in Visual Studio Code. [07:48.270 --> 07:53.370] Each line is an object representing a different user who had an account on the postmillennial website. [07:53.370 --> 07:55.730] So the file has about 40,000 lines. [07:57.590 --> 08:03.110] I copied and pasted one of the lines into a new tab and then formatted it so it's making it easier to read. [08:03.290 --> 08:06.250] And the first thing that I noticed is the passwords are all in plain text. [08:07.190 --> 08:11.050] This user's password is angry mom of three kids with a Z. [08:14.430 --> 08:20.290] And there's also, you know, potentially phone numbers, gender, addresses and other information. [08:21.490 --> 08:23.410] But for this user, they're all set to null. [08:23.650 --> 08:26.010] And there's a subscription field that's also null here. [08:27.690 --> 08:34.870] Most of the users had the subscription field set to null, but 1,679 of them had a JSON object in that field. [08:35.010 --> 08:37.470] And so here's an example of one of the subscription things. [08:37.670 --> 08:45.750] And so in this example, this person signed up for the VIP supporter yearly plan and donated 100 Canadian dollars a year using Stripe. [08:45.750 --> 08:52.510] So, you know, just with this data, I could potentially write a little script to figure out how much revenue the Postmillennial makes from its subscribers. [08:54.430 --> 09:01.270] So after manually poking around, I started writing some Python code to analyze users.json some more. [09:01.830 --> 09:03.670] And here are some of the things that I discovered. [09:03.910 --> 09:05.470] So there's about 40,000 users. [09:06.290 --> 09:07.850] There's 3.6 years of data. [09:07.850 --> 09:14.950] And what's interesting is the, like, most recent timestamp in the data stamp was from July 24th, 2022. [09:15.710 --> 09:28.130] And one of the first things I do when I see a data set is look for what the most recent timestamp on the files are or, you know, the timestamp in spreadsheets or whatever, because that's probably the day that the hack happened, because that's like the end of the data. [09:31.050 --> 09:33.950] And 31,000 phone numbers, only 50 addresses. [09:34.110 --> 09:40.810] What was kind of weird is 75% of the users were created in the last week of October 2021. [09:40.810 --> 09:41.990] And I had no idea why. [09:42.990 --> 09:52.330] I recently gave a talk at B-Sides Vancouver, and I showed them this surge of new subscriber data on the Postmillennial and said I had no idea what it was about. [09:52.330 --> 10:03.390] And someone came up to me and said that they think that likely it was related to the right-wing backlash to Canada formally admitting to and apologizing for genocide against Indigenous people. [10:03.570 --> 10:07.210] Like, it was happening, like, a few months before that, and it was big in the media cycle. [10:08.730 --> 10:16.070] And this was after an unmarked mass grave with hundreds of children's bodies was found at a residential school for Indigenous children. [10:16.070 --> 10:24.430] And so there was, like, a lot of right-wing people in Canada were, like, very upset that the government was apologizing for genocide. [10:24.930 --> 10:28.730] And maybe that would cause the massive new accounts. [10:30.090 --> 10:35.770] Anyway, I started looking at email address domains that contain the word police and the end in .gov. [10:37.230 --> 10:48.850] So here are users with police in their email address domain names, and there are 449 users of the Postmillennial from .gov email addresses. [10:49.170 --> 10:57.050] And, of course, just the fact that somebody has an account on this doesn't mean anything other than they're interested in what this fake news website is publishing. [10:57.050 --> 10:59.550] But it is potentially an interesting data point. [11:01.790 --> 11:04.050] And then I started looking in the db's folders. [11:04.790 --> 11:09.630] And, honestly, it's just, like, a huge mess of unorganized spreadsheets. [11:10.050 --> 11:15.450] For example, the writes-donor-file spreadsheets, each about 16 megabytes. [11:16.010 --> 11:21.250] Together, they contain, like, personal information, private information, about 100,000 people. [11:21.250 --> 11:27.330] Including names, email addresses, mailing addresses, a column called ideological tag. [11:27.830 --> 11:31.470] And I actually, like, did some analysis on the ideological tag. [11:31.690 --> 11:37.130] 86% are conservative, 13% Republican, and then a very small number libertarian. [11:37.350 --> 11:37.790] And that's it. [11:39.290 --> 11:44.870] And so just to understand the scale of the data, I wrote a Python script that opens every CSV file. [11:45.070 --> 11:49.110] And then identifies email addresses and counts how many unique email addresses there were. [11:49.110 --> 11:51.510] And there were over 20 million unique email addresses. [11:52.150 --> 11:54.850] Just in this data set that, like, no one's ever heard of. [11:56.210 --> 12:00.610] And so, yeah, I spent about an hour looking at that Kansas City police data. [12:00.870 --> 12:03.170] I spent about two hours looking at the post-millennial data. [12:03.610 --> 12:04.870] That's as far as I got. [12:05.370 --> 12:13.750] I'm not really sure what revelations there are in either of these that will be worth publishing, beyond the, like, the fact of the, you know, that these things were hacked. [12:13.750 --> 12:19.510] Although I do think that some of those FBI documents that I, like, found right away are definitely pretty interesting. [12:20.330 --> 12:24.650] But I bet that I'm the only journalist who has even looked at it, or even knows that this stuff exists. [12:24.990 --> 12:30.750] And a big reason is because journalists and researchers just don't have the skills to look through data sets like this. [12:31.390 --> 12:34.370] They happen, like, every single day, constantly. [12:34.550 --> 12:40.270] In fact, actually, earlier today, I heard of a data set and started looking at it, and I'm going to talk about it a little bit later. [12:40.610 --> 12:42.270] But anyway, I'm hoping to change that. [12:42.490 --> 12:46.770] And that's, you know, basically why I wrote this book. [12:47.570 --> 12:53.130] So I spent about two years writing a book about how to analyze hacked and leaked data like this. [12:53.350 --> 12:55.770] It was published in January by No Starch Press. [12:56.310 --> 12:58.610] The book is incredibly hands-on. [12:58.870 --> 13:04.470] It uses real data sets as examples and has you download them and analyze them as you read it. [13:05.050 --> 13:06.830] It's designed for total newbies. [13:07.030 --> 13:12.270] It gets pretty technical, but it doesn't assume any prior experience or skills at all. [13:13.150 --> 13:16.250] All you need is a laptop, an Internet connection, and some disk space. [13:17.050 --> 13:18.910] It's a cross-platform book also. [13:19.130 --> 13:26.890] It includes detailed instructions on how to do everything in Linux, macOS, and even in Windows, using the Windows subsystem for Linux. [13:28.290 --> 13:29.790] And briefly, here's what's in it. [13:30.450 --> 13:40.790] So I started talking about things like digital security and source protection and ethics and document redaction and where you can find data sets and download them. [13:41.390 --> 13:50.450] And then I move on to a deep dive into things like using the terminal, how to make data sets searchable for keywords and stuff, how to work with email dumps in different formats. [13:50.810 --> 13:57.210] And then I go into Python programming and it's actually like a whole... there's like two chapters on like you've never done any programming before. [13:57.490 --> 13:58.850] Here's how you like start. [13:59.110 --> 14:01.370] And then you start actually working with data sets in it. [14:01.370 --> 14:08.850] And I spend a lot of time working with structured data, especially CSV files, JSON files, and SQL databases. [14:09.410 --> 14:11.550] And then finally, I have a few case studies. [14:13.350 --> 14:19.550] So I've released this book under a Creative Commons license also in order to remove any barriers to access. [14:19.830 --> 14:24.490] And so you can go and start reading the whole thing online right now at hacksandleaks.com. [14:25.570 --> 14:30.210] But of course, I think a physical copy is a lot nicer and I brought a bunch of copies of the book with me. [14:30.650 --> 14:38.650] And so over in the vendor area, I'll be signing books tomorrow and Sunday, probably if I still have books. [14:42.210 --> 14:48.450] So before you start working with hacked and leaked data, it's important to start with a baseline of digital security. [14:49.670 --> 14:53.130] So the first part of the book is the least technical, but it's still critically important. [14:54.410 --> 14:58.930] So the book has like homework assignments throughout it that you like follow along. [14:59.090 --> 15:10.850] And so some of those assignments include starting to use a password manager, making sure your hard disk is encrypted, making sure you know how to encrypt a USB hard disk because there's a lot of data that you need to be storing. [15:11.650 --> 15:15.190] And then also other things like you can't trust everything that you read online. [15:15.190 --> 15:17.570] And so this also includes hacked and leaked data. [15:17.690 --> 15:21.690] So it shows some techniques on how you can verify that the data is authentic. [15:24.870 --> 15:39.730] And then it goes into how to acquire data sets, both public data sets that anyone can download from the Internet and private data sets that, you know, confidential sources send directly to you and how you can go about setting yourself up for accepting submissions of data. [15:40.230 --> 15:43.090] And all the data sets that you work with throughout the book, they're all public. [15:43.930 --> 15:46.750] You can download them all from distributed denial of secrets. [15:47.710 --> 15:54.930] And so, yeah, like everything in the book, when you follow along with the book, you download several data sets as you're reading the chapters and then work with them. [15:56.410 --> 16:01.030] So distributed denial of secrets or DDoS secrets, it's a U.S. [16:01.130 --> 16:02.530] nonprofit founded in 2018. [16:03.050 --> 16:06.650] And if you're not familiar with them, they're here. [16:06.830 --> 16:09.990] There was a DDoS secrets adjacent talk earlier. [16:10.310 --> 16:14.210] And on Sunday, you should definitely check out the future of leaks. [16:14.370 --> 16:16.310] What's next for the online library of hacked data? [16:16.750 --> 16:19.310] It's in this room at 11 on Sunday. [16:19.770 --> 16:23.230] They're basically the public library of hacked and leaked data sets. [16:23.830 --> 16:25.750] I've been working with them for several years. [16:25.990 --> 16:29.470] I've reported on tons of data sets that DDoS secrets has published. [16:29.470 --> 16:32.370] Their website is DDoSsecrets.com. [16:32.590 --> 16:42.390] And one of the first homework assignments that you do after you encrypt your hard drive is download a copy of the Blue Leaks data set from DDoS secrets onto your encrypted hard drive. [16:44.170 --> 16:57.210] So in the summer of 2020, in the middle of the Black Lives Matter uprising that was sparked when a cop murdered George Floyd, someone hacked hundreds of law enforcement websites in the U.S. [16:57.210 --> 17:00.510] Most of them belonged to law enforcement fusion centers. [17:00.890 --> 17:04.630] And they leaked 270 gigabytes of data to DDoS secrets. [17:05.270 --> 17:06.650] So this is Blue Leaks. [17:06.870 --> 17:08.930] It's a very large and complicated data set. [17:09.390 --> 17:18.350] And I use this data set throughout the book as an example data set to basically teach data analysis skills. [17:18.350 --> 17:26.390] And also tonight at 8 o'clock after this talk, I'm giving a workshop specifically about this data set. [17:26.570 --> 17:28.990] So check that out if you're interested. [17:29.390 --> 17:34.670] I'm very excited about the idea of giving a room full of hackers hundreds of gigabytes of hacked police documents. [17:37.130 --> 17:40.570] So not everyone was as happy about Blue Leaks as I was. [17:42.490 --> 17:51.010] After DDoS secrets published it, German authorities at the request of the FBI seized a DDoS secret server that contained all of its public data sets. [17:51.290 --> 17:55.090] But it didn't actually work to suppress Blue Leaks at all because everyone was just using the BitTorrent. [17:56.190 --> 18:01.930] And then also in 2020, Reddit and Twitter both started censoring DDoS secrets. [18:02.470 --> 18:11.350] Twitter permanently suspended the DDoS secrets account and it started preventing anyone from posting or even direct messaging links to DDoSsecrets.com. [18:12.730 --> 18:20.830] So I briefly had hope that when Elon Musk took over Twitter, he might restore the DDoS secrets account and stop censoring links to it. [18:21.130 --> 18:22.550] That didn't happen. [18:23.650 --> 18:25.770] DDoS secrets is still blocked by X today. [18:26.130 --> 18:26.990] It's been four years. [18:27.590 --> 18:30.470] And go ahead and try tweeting a link to DDoSsecrets.com. [18:30.730 --> 18:31.550] See what happens. [18:34.810 --> 18:42.030] So while I'm talking about DDoS secrets getting censored, last year, this is one of the datasets that DDoS secrets published. [18:42.190 --> 18:43.270] It's from... [18:43.950 --> 18:45.210] Last year they published this. [18:45.990 --> 18:46.470] Raskamnadzor. [18:46.650 --> 18:52.130] And so this is a Russian government agency in charge of monitoring, controlling and censoring mass media in Russia. [18:52.130 --> 18:58.310] And this was actually the second leak from Raskamnadzor that DDoSsecrets had published. [18:59.770 --> 19:06.050] Here's a court document from this dataset about Raskamnadzor censoring DDoSsecrets itself. [19:06.330 --> 19:13.990] So this PDF was attached to an email and it shows a request to add DDoSsecrets.com to Russia's domain name censorship list. [19:17.100 --> 19:22.360] The technical part of the book starts with teaching how to use the command line interface. [19:22.880 --> 19:27.600] It teaches basic things like navigating the file system, running commands, using sudo. [19:28.140 --> 19:31.700] And then it moves to some techniques to quickly analyze datasets. [19:33.300 --> 19:39.420] So, for example, when you first download Blueleaks, you have a folder with 167 zip files in it. [19:39.640 --> 19:43.620] You could right click on each zip file one at a time to extract them. [19:43.760 --> 19:48.580] But this shows you how to do it all at once with, you know, a for loop in Bash. [19:50.240 --> 19:54.980] And then after you unzip them all, you have hundreds of folders, many of them full of thousands of files. [19:55.920 --> 20:03.660] And you learn how to use commands like DU to measure the disk space of different folders, which I was doing earlier with a post-millennial dataset. [20:04.020 --> 20:06.720] And how to use sort to sort the output. [20:06.720 --> 20:12.460] So you can do things like see which folders have the most data, which folders have the least data and things like that. [20:12.560 --> 20:18.040] So there's all sorts of like really powerful command line things where you can really quickly assess a dataset. [20:18.540 --> 20:27.700] And it shows you how to make lists of file names and how to use grep to search that list of file names for keywords, which is a really useful thing when you first get a dataset. [20:29.920 --> 20:32.720] Or you can use grep to search other text files. [20:33.440 --> 20:37.040] So grep is a great useful tool for searching text. [20:37.920 --> 20:38.960] So you can search file names. [20:39.060 --> 20:43.520] It's great for searching other types of text files like CSVs and JSON files. [20:44.040 --> 20:50.220] But you can't really use grep to search a lot of other types of data, including PDFs or office documents or even emails. [20:51.520 --> 20:55.400] Email is plain text, but it's often mime encoded. [20:56.320 --> 20:58.880] And it often uses base64 encoding. [20:59.220 --> 21:01.780] So you can't grep that stuff. [21:01.920 --> 21:04.960] You have to actually parse the emails in order to search them. [21:05.240 --> 21:10.860] So if you want to search the contents of all of these different types files, you can use software called Alice. [21:14.240 --> 21:23.280] So Alice is open-source investigative investigation software developed by OCCRP, which is the Organized Crime and Corruption Reporting Project. [21:23.940 --> 21:25.920] It's designed for investigative journalism. [21:26.180 --> 21:31.780] And OCCRP runs a big public server full of a bunch of datasets that you can look at at data.occrp.org. [21:31.780 --> 21:35.820] But you can also use Aleph to index datasets and search them yourself. [21:36.240 --> 21:40.460] And it does all sorts of stuff like entity extraction and it OCRs your documents. [21:40.700 --> 21:44.960] So if they're like scanned documents, you can search them and you can cross-reference multiple datasets. [21:46.360 --> 21:51.240] And you can run Aleph locally on your laptop if you want using Docker containers. [21:51.240 --> 21:56.440] And so here's a screenshot from the book of using Aleph. [21:56.560 --> 22:07.040] And in this case, I indexed BlueLeaks data, like a piece of BlueLeaks from IcefishX, which is a partnership between law enforcement agencies in Minnesota, North Dakota, and South Dakota. [22:07.320 --> 22:14.460] And this shows a unclassified law enforcement sensitive document from a few days after George Floyd's murder in Minneapolis. [22:15.200 --> 22:18.480] And it warns of increased threats against police by protesters. [22:21.600 --> 22:25.800] So email dumps are a very common form of leaked data. [22:26.240 --> 22:29.540] So one of the chapters is called reading other people's email. [22:29.940 --> 22:40.000] It goes over the email message format and email protocols and specifically common file formats that email dumps come in. [22:40.000 --> 22:48.420] So this is EML files, which are just individual email messages, MBOX files and PST Outlook files. [22:49.840 --> 22:58.220] So you'll learn how to convert email dumps into different formats and into specifically a format that makes it easy to import into Thunderbird so you can analyze them. [22:58.960 --> 23:03.820] And there's a really good Thunderbird add-on called Import-Export-Tools-NG. [23:04.240 --> 23:09.220] And so in this example, this is a screenshot from the Nauru Police Force dataset. [23:10.220 --> 23:20.660] Nauru is a tiny island in the Pacific Ocean that hosts abuse-ridden offshore detention centers that the Australian government uses to hold immigrants and asylum seekers. [23:21.100 --> 23:36.720] So this screenshot shows an email from the president of Nauru telling Nauru's police chief to not respond to an Australian journalist who asked questions about two Nauru men who allegedly attacked a refugee worker, possibly ran him over with a car and stole his motorbike. [23:38.080 --> 23:45.520] And actually, you can just search for the president of Nauru's email, and you can see all sorts of email, all of his correspondence with the police. [23:47.860 --> 23:51.720] There are some other tools you can use for analyzing email dumps. [23:51.720 --> 23:53.600] So Aleph is one of them. [23:54.040 --> 23:57.740] And for PST files, you can use Microsoft Outlook directly. [23:58.040 --> 24:08.560] So this is a screenshot of Outlook where I imported a 48 gigabyte PST file leaked from the largest state-owned media company in Russia called VGTRK. [24:09.100 --> 24:17.560] And this is one of the dozens of Russian organizations that was hacked right after they invaded Ukraine, and the data was all leaked to DDoS secrets. [24:17.840 --> 24:26.900] And in this screenshot, I used Outlook, and I basically used Google Translate to figure out what the Cyrillic spelling of Tucker Carlson is. [24:26.900 --> 24:28.420] And I searched for it. [24:29.140 --> 24:33.160] And so the subject of this email is Tucker Carlson's think. [24:33.400 --> 24:39.400] And the body has a translated quote where Tucker Carlson is saying that Ukraine isn't an independent country. [24:39.520 --> 24:41.100] It's controlled by the Democrats. [24:41.360 --> 24:43.780] And then some conspiracy stuff about Hunter Biden. [24:46.910 --> 24:53.050] The book also includes a small, very old email dump from the Heritage Foundation. [24:53.630 --> 25:07.510] This is a conservative think tank that is behind Project 2025, which is this 920-page detailed plan for the upcoming Trump administration to turn the United States into a fascist bureaucracy. [25:08.050 --> 25:18.630] But back in 2015, someone noticed that the Heritage Foundation had accidentally left a file called backup.pst on an S3 bucket. [25:18.930 --> 25:20.550] And they tweeted a link to it. [25:21.470 --> 25:25.290] And so it was an old backup of one of the employees' email. [25:25.690 --> 25:27.870] And the latest email is in here for 2009. [25:27.870 --> 25:29.110] So this is really old. [25:29.330 --> 25:31.130] And it was actually his personal email. [25:32.050 --> 25:36.270] He worked on the major gifts team, but he had a bunch of work email in there. [25:36.270 --> 25:40.310] And so in this screenshot, it's the folder called Social Issues. [25:40.370 --> 25:46.690] And it's just full of a bunch of homophobic and bigoted stuff that he emailed from his work email to his personal email. [25:49.030 --> 25:59.530] And actually, earlier today, while I was sitting at the table signing books, I learned that Heritage Foundation had just recently gotten hacked, like three days ago. [26:07.800 --> 26:13.560] So they have a publication called The Daily Signal, and it was hacked by SiegeSec. [26:13.860 --> 26:19.560] And so just before this talk, I downloaded the data and took a quick look. [26:22.380 --> 26:25.540] And the data is basically like a zip file. [26:25.940 --> 26:30.140] I uncompressed it, and it's an SQL file, and it's a MySQL database. [26:30.580 --> 26:32.640] And actually, let me show you... [26:39.460 --> 26:40.820] Here's the MySQL database. [26:42.400 --> 26:44.500] And here's the user's table. [26:44.860 --> 26:46.480] Here's their password hashes. [26:47.100 --> 26:50.860] Some of these people say, like, apparently there may be representatives in Congress. [26:51.520 --> 26:52.080] I don't know. [26:52.180 --> 26:53.360] I haven't really looked through this. [26:53.520 --> 26:54.640] But anyway, it just happened. [26:55.240 --> 26:57.140] And I just was looking at it earlier today. [27:00.940 --> 27:02.600] Okay, back to the talk. [27:12.380 --> 27:14.320] Yeah, I don't know what's going to be in there. [27:14.560 --> 27:17.300] I'll spend a little bit more time, but it really is mostly just a public website. [27:17.300 --> 27:25.700] So there might not be much more interesting than, you know, their, like, password hashes and email addresses and stuff. [27:28.540 --> 27:33.440] Okay, so tools like Aleph and Thunderbird only work for some data sets. [27:34.000 --> 27:37.980] For a lot of data sets, the only way to make sense of them is to write custom code. [27:38.200 --> 27:41.540] And so this is true for the post-millennial data set that I showed at the beginning. [27:42.240 --> 27:48.920] And so the book includes, like, a crash course in Python programming for total beginners. [27:49.280 --> 27:57.140] And it especially focuses on how to, like, write code to traverse the file system and how to work with data structures using dictionaries and lists. [27:58.600 --> 28:01.920] So here's a quick example of some Python data analysis. [28:01.920 --> 28:08.380] The day after Russia invaded Ukraine, a ransomware group called Conti published this statement. [28:08.920 --> 28:14.760] Conti is known for extorting hundreds of millions of dollars from companies around the world, especially healthcare companies. [28:15.360 --> 28:27.600] After Russia attacked Ukraine, a Ukrainian security researcher hacked Conti and dumped 30 gigabytes of internal documents from the ransomware group online, including chat logs. [28:28.660 --> 28:33.020] So the chat logs were from a rocket chat server, and they were in JSON format. [28:33.280 --> 28:38.260] So here's an example of a single message posted in Conti's chat room on the day of the invasion. [28:38.740 --> 28:44.600] It translates to, Some American senators suggest blocking Pornhub in Russia, in addition to social networks. [28:44.880 --> 28:55.240] And this is right when the U.S. and Europe started imposing economic sanctions on Russia, and then Russia started blocking access to Facebook and Twitter in the country. [28:55.440 --> 29:01.140] And there were rumors that Pornhub will block access to Russia, to Russian users, but Pornhub never actually did. [29:01.140 --> 29:04.440] And the next messages after this in the chat are, That's it. [29:04.520 --> 29:04.900] We're done. [29:05.160 --> 29:07.260] And then they will take away our last joys. [29:13.450 --> 29:17.070] So here's an excerpt of some of the code from the Python chapter. [29:18.810 --> 29:26.670] The code at the top imports the chat logs from JSON into a large data structure made of dictionaries and lists. [29:26.670 --> 29:30.650] And then the code at the bottom is a for loop. [29:30.650 --> 29:36.670] And it basically just like loops through the messages and prints them out in a way more easy to read format. [29:36.910 --> 29:42.190] And in fact, you could actually select those and copy and paste them into like a machine translation thing. [29:42.370 --> 29:46.150] So that you can translate them because if you don't speak Russian, you could still tell what's going on. [29:47.370 --> 29:51.770] And here is my reporting for the intercept on the Conti chat logs. [29:52.370 --> 30:00.550] So this book teaches you how to take incomprehensible data and make it possible for you to read it and to understand it and to report on it like this. [30:03.110 --> 30:10.150] Another common format that data leaks come in is spreadsheets and in particular CSV files. [30:10.810 --> 30:19.810] So it's important to learn how to investigate data and CSV files and how to write Python codes that works with CSV files and how to also sometimes make your own CSV files. [30:20.710 --> 30:23.970] So here's a quick example of something that I found in a CSV file. [30:24.230 --> 30:28.450] I gripped... because CSV files are plain text files, so you can gripped them. [30:28.530 --> 30:35.330] I gripped the contents of the BlueLeaks folder, NICREC for the word Antifa. [30:35.810 --> 30:39.110] So NICREC is the Northern California Regional Intelligence Center. [30:39.490 --> 30:41.930] It's like my local fusion center. [30:41.930 --> 30:49.530] And I found this file or this line in SARS.csv, which is Suspicious Activity Reports. [30:49.810 --> 30:51.670] That's what the SARS stands for. [30:51.990 --> 31:01.750] And those are basically rumors or leads posted to law enforcement fusion centers about things that may or may not be illegal. [31:01.750 --> 31:02.530] It's very big. [31:03.970 --> 31:09.090] But here are the relevant fields from that one row that I found to make it easier to read. [31:09.810 --> 31:18.150] A lot of the homework actually involves loading CSV files and then looping through rows of data and displaying them in a way that's easier to read. [31:18.310 --> 31:23.290] Because a lot of times that's like half the problem is you just can't really read like a wall of text. [31:24.570 --> 31:33.190] So this row shows that someone from the Marin County District Attorney's Office, which is just north of San Francisco, submitted this SAR at 2.20 p.m. [31:33.370 --> 31:34.630] on June 5th, 2020. [31:35.010 --> 31:38.930] They set the category to radicalization slash extremism. [31:39.250 --> 31:45.970] And the summary says that they received the attached letter from a lawyer who was contacted by a University of Oregon student. [31:45.970 --> 31:54.070] And the student, quote, appears to be a member of the Antifa group and is assisting in planning protesting efforts in the Bay Area, despite living in Oregon. [31:54.690 --> 31:58.350] The CSV also makes a reference to an uploaded file called letter.pdf. [32:01.250 --> 32:03.070] So I opened that file. [32:03.170 --> 32:07.130] The actual file name was the, like, 277.pdf file. [32:07.310 --> 32:08.510] But I opened that file. [32:09.050 --> 32:10.590] Here's the scan letter from the lawyer. [32:11.170 --> 32:12.290] Written in all caps. [32:12.930 --> 32:21.250] Please see the attached solicitation I received from an Antifa terrorist wanting my help to bail her and her friends out of jail if arrested for rioting. [32:21.250 --> 32:25.970] He says he's staying anonymous because he's worried about getting a bar complaint filed against him. [32:26.150 --> 32:27.910] And he ends the letter, happy hunting. [32:30.290 --> 32:35.930] And then here's the actual letter from the student in Oregon. [32:36.270 --> 32:37.430] It's very polite. [32:37.430 --> 32:45.570] And she just says that she's compiling a list of lawyers and law firms that will be willing to represent pro bono Black Lives Matter protesters if they got arrested. [32:45.570 --> 32:54.350] Um, so this letter triggered this lawyer so much that he mailed it anonymously to a district attorney's office. [32:54.410 --> 33:01.630] And then the district attorney's office uploaded it as a suspicious activity report into the Northern California Police Intelligence Agency. [33:02.010 --> 33:07.030] Um, so I never would have found this if I wasn't, like, looking deep in the CSVs. [33:07.030 --> 33:11.670] If I was just, like, clicking around and opening the, like, PDFs and Word documents and stuff. [33:11.670 --> 33:22.450] Um, so back in 2020, when I was investigating blue leaks a lot, I discovered that the bulk of the interesting information actually is hidden in these thousands of CSV files. [33:23.110 --> 33:37.050] Um, so after, like, looking at the, the data set, which actually includes the source code of the hacked websites and stuff, I figured out that the hacker originally, um, exported all of these CSV files from, uh, a SQL database. [33:37.630 --> 33:43.530] Um, so, uh, that basically just means that all of these CSV files are just tables and they all have relationships. [33:43.870 --> 33:51.910] And so I built a custom web application called Blue Leaks Explorer that makes it much easier to explore the relationships between these and also to, like, display data. [33:52.030 --> 33:57.550] Like, this is a bunch of HTML in a cell in a CSV and there's no way that you can see what that says. [33:57.710 --> 33:59.310] But when you look at it like this, you could read it. [33:59.310 --> 34:04.650] Um, so I released Blue Leaks Explorer, uh, as open-source along with the book. [34:04.770 --> 34:10.430] So anyone that has a copy of Blue Leaks can, um, use it to start looking through the Blue Leaks data. [34:10.750 --> 34:14.390] And this is actually what the workshop that I'm giving tonight at eight o'clock is about. [34:14.550 --> 34:23.830] It's, uh, uh, getting you set up on the, on Blue Leaks Explorer and getting you to start being able to, like, research your own local police, um, like, on your laptop tonight. [34:23.830 --> 34:33.610] Um, so this screenshot is a bulk email that Nick Rick sent to thousands of local cops advertising a class about how to gather evidence from phones. [34:36.250 --> 34:40.390] So another common, uh, format that Leaks data comes in is JSON. [34:40.970 --> 34:48.010] I spent a chapter going deep into JSON and the example dataset that I used is, uh, related to the January 6th insurrection. [34:49.950 --> 34:55.150] So on January 6th, 2021, um, anti-democracy activists stormed the U.S. [34:55.270 --> 34:59.510] Capitol building, uh, to try to keep Donald Trump into power after he lost the election. [34:59.810 --> 35:08.610] And using their phones, they took photos and video, um, often including GPS coordinates in the metadata, and posted them online in real time. [35:08.930 --> 35:13.710] Uh, many of them posted videos to Parler, which is the far-right social network. [35:16.920 --> 35:22.420] Uh, after the attack, Parler, uh, refused to moderate content that incited violence. [35:22.660 --> 35:25.780] And so Apple and Google both banned it from their app stores. [35:26.040 --> 35:30.520] And AWS announced that it would kick Parler off of its service too in a few days. [35:30.840 --> 35:38.140] But before that happened, um, an archivist named Donk Envy downloaded 32 terabytes of videos from Parler. [35:38.360 --> 35:40.160] Over a million videos. [35:40.380 --> 35:43.700] And 32 terabytes is just, like, it's a lot of data. [35:43.700 --> 35:46.400] It's really, like, like, my hard drive in here is one terabyte. [35:47.100 --> 35:48.080] And, uh, yeah. [35:48.700 --> 35:53.760] So, uh, Donk worked with DDoS secrets to make all of the Parler videos public. [35:54.600 --> 36:00.880] Um, yeah, 32 terabytes is way too much data for anyone to individually download to their computer. [36:01.400 --> 36:07.980] Um, and so, uh, Donk used a command line program called EXIF tool to extract metadata from each video. [36:07.980 --> 36:12.500] And included, um, a file with all of the metadata as just part of the dataset. [36:12.820 --> 36:17.640] So this screenshot shows a folder, um, with over a million JSON files in it. [36:17.740 --> 36:21.020] And each one of these files is pretty small, but it's metadata for a different video. [36:21.240 --> 36:24.400] But together, it's two gigabytes of small JSON files. [36:25.120 --> 36:32.460] Um, and, oh, the ironic thing is that, uh, AWS was kicking Parler off. [36:33.120 --> 36:42.600] And, um, Donk Envy downloaded all of these videos from Parler, or from an AWS bucket, and then just uploaded them to, like, a different AWS bucket. [36:45.780 --> 36:48.140] Um, so here's metadata from one of the videos. [36:48.140 --> 36:55.320] Um, so as you can see, this, uh, has a January 6th timestamp and has GPS coordinates. [36:55.820 --> 37:00.540] And if you, like, copy and paste that into Google Maps, you can see that that's in Washington, D.C. [37:02.720 --> 37:06.780] And here is an example of one of the Python scripts that you would write if you follow along. [37:07.360 --> 37:18.780] Um, this is a script that loops through all one million pieces of video metadata from Parler, looking for videos that were filmed on January 6th and that have GPS coordinates in Washington, D.C. [37:19.180 --> 37:25.860] And then it saves a file in a format that can be loaded into Google Earth to visualize, uh, the Parler videos. [37:26.080 --> 37:33.320] And so if you've never written code before, it slowly, slowly, like, walks you through the process of how to, you know, write this script specifically. [37:33.400 --> 37:38.320] But, um, you know, you can use it to write your own scripts with looking at your own datasets. [37:39.140 --> 37:42.800] Um, and so here is Google Earth, a Google Earth map of the data. [37:43.120 --> 37:47.120] And so, as you can see, Trump supporters were deep inside the Capitol building. [37:47.520 --> 37:54.680] And, uh, a lot of these videos from the Parler dataset were used as evidence against Trump in his second impeachment inquiry. [37:57.850 --> 38:04.630] So another common format that leaked and hacked data comes in is SQL databases, or SQL, uh, pronounced SQL. [38:05.070 --> 38:12.170] Um, so the chapter about SQL, uh, uses a hack of data from a hosting company called Epic, as an example. [38:12.170 --> 38:19.210] Um, Epic is a company, uh, formerly run by, uh, a Christian nationalist. [38:19.710 --> 38:24.190] Um, it was recently acquired by some shadowy shell company now. [38:24.370 --> 38:30.470] Um, and it provides domain registration and hosting services to hate groups and other far-right extremists. [38:31.150 --> 38:35.390] So, for example, um, Epic hosts the domain Oathkeepers.org. [38:35.730 --> 38:41.450] Uh, if you look up the WHOIS data for Oathkeepers.org, you'll see that it's hidden behind Epic's domain privacy service. [38:42.630 --> 38:49.750] Um, but if you have the Epic data and you're on the right SQL query, you can find the real contact information of the person who owns the domain. [38:49.750 --> 38:58.730] Um, and, um, in this case, the administrator of this domain is someone named Edward Durfee, who lives in New Jersey and runs a company called Ejam Systems. [38:59.290 --> 39:10.650] Um, and, uh, if you look at a totally separate leak of Oathkeepers email, you can see that Edward Durfee basically worked as the Oathkeepers, uh, IT support person, and he signed his emails like that. [39:10.650 --> 39:20.130] Um, and yeah, so the Epic data has domain registration info for a lot of extremist websites, including, uh, sites run by neo-Nazis. [39:20.310 --> 39:28.990] It has information about Jim Watkins, who, um, runs 8kun, formerly 8chan, um, who is most likely one of the people behind QAnon. [39:29.590 --> 39:31.610] Um, yeah, it's an interesting data set. [39:32.050 --> 39:36.630] Uh, and then finally, I described some detailed case studies at the end of the book. [39:36.630 --> 39:41.730] I won't go into a lot of detail about this, but here's a brief description of, um, one of them. [39:42.970 --> 39:51.430] In September 2021, I was contacted by an anonymous source who said they were dropping some docs on Cadence Health, the horse-paced peddlers. [39:52.230 --> 39:54.750] Um, and they were hilariously easy to hack. [39:54.930 --> 39:59.730] And at the time, I had no idea what Cadence Health was or who anyone involved in the story was. [39:59.730 --> 40:03.310] I just had these two compressed files taking up about 100 megabytes of space. [40:04.270 --> 40:06.530] Um, and a few weeks later, I published my story. [40:06.710 --> 40:19.030] And I found out that an anti-vax group called America's Frontline Doctors was raking in millions of dollars convincing people the vaccines are harmful and selling them fake COVID medicine instead. [40:19.030 --> 40:28.430] So basically, I discovered that over a two-month period, they charged people at least $6.7 million just on $90 phone consultations. [40:28.710 --> 40:40.690] And they made the same amount of... and if they have made the same amount of money, um, on average during the months that I don't have data, but that I know they were doing this, then the patients may have paid an additional $18 million more just for, [40:40.710 --> 40:42.510] like, having, like, fake doctor's appointments. [40:42.510 --> 40:53.310] Um, and then over a nine-month period, patients paid, uh, $8.7 million on ivermectin and hydroxychloroquine and, like, fake, fake COVID medicine like that. [40:53.310 --> 41:01.570] Um, my reporting led to a congressional investigation into the group and also the health, the telehealth companies that they worked with. [41:02.010 --> 41:07.630] Um, but America's Frontline Doctors basically stonewalled and refused to cooperate with the data requests. [41:07.870 --> 41:11.570] And then Republicans took the house and they shut down the committee, so nothing really happened. [41:11.790 --> 41:15.730] Um, but, but still, it was, it was cool that they started an investigation. [41:16.210 --> 41:23.830] Um, and then also Simone Gold, the founder of America's Frontline Doctor, um, she, uh, is also a January 6th insurrectionist. [41:24.130 --> 41:35.710] And, uh, while she was serving a two-month prison sentence, um, other people at America's Frontline Doctors tried to take over the organization, and there was, like, this, like, nasty, like, lawsuit and stuff. [41:35.970 --> 41:45.630] Um, a lawyer named Joey Gibson did an internal audit, and he was, like, the America's Frontline Doctors lawyer, did an internal audit of how she had been spending the money, the group's money. [41:46.050 --> 41:57.290] Um, and, uh, uh, and then also, like, in addition to all of this, you know, profit that they made by scamming people, basically, they also received at least 10 million dollars in donations. [41:57.850 --> 42:01.170] Um, and, oh, I, I only have two minutes. [42:01.190 --> 42:05.050] I'm gonna jump through this, but basically, this is an insane story, you should look into it. [42:07.310 --> 42:19.450] Um, so, uh, and then the final case study is, um, about neo-Nazi chat logs collected by anti-fascist infiltrators in, uh, 2017. [42:20.150 --> 42:34.010] Um, so, in August 2017, uh, hundreds of white supremacists spent a weekend in Charlottesville, Virginia, for the United of the Right rally, and they, they came from groups like, uh, Vanguard America, League of the South, the Ku Klux Klan. [42:34.790 --> 42:42.090] One neo-Nazi drove his car into a crowd of anti-fascist counter-protesters, uh, killing Heather Heyer and injuring 19 other people. [42:42.550 --> 42:44.990] Um, Trump said there were very fine people on both sides. [42:46.270 --> 42:57.930] Um, so, uh, a non-profit, uh, news collective called Unicorn Riot obtained chat logs from Discord servers that were used to organize the violence in Charlottesville. [42:58.470 --> 43:06.490] Um, and they also obtained chat logs from a lot of other Discord servers that, like, the far-right was using, um, and militia groups and all sorts of stuff. [43:06.750 --> 43:09.270] Um, all of these were infiltrated by anti-fascists. [43:09.950 --> 43:19.250] Journalists at Unicorn Riot sent me copies of the chat logs in JSON, and, like with Louis Explorer, I made, um, a custom web app for analyzing all this stuff. [43:19.930 --> 43:22.750] Um, and here's an article that I wrote. [43:22.930 --> 43:37.070] Uh, I was gonna keep on reporting on the chat logs after writing this article, but I found it way too upsetting, and there's a little part of the book that actually talks about mental health while doing extremism research, and so instead of continuing to read the thoughts of the worst people in the [43:37.070 --> 43:40.190] world, I, uh, wrote a bunch of code so other people could do that. [43:40.710 --> 43:49.130] Um, so I shared my code with Unicorn Riot, and, uh, they took over development of it eventually, and turned it into a public website called Discord Leaks. [43:49.670 --> 43:53.950] Um, today it has hundreds of thousands of messages from dozens of fascist chat rooms. [43:54.450 --> 43:57.210] Um, it's an important tool used by extremism researchers. [43:57.770 --> 44:06.410] Um, and then survivors of violence in Charlottesville actually sued the organizers of the Unite the Right, trying to bankrupt the American fascist movement, and they basically succeeded. [44:07.190 --> 44:07.870] Sort of. [44:08.050 --> 44:16.070] I mean, the American fascist movement has expanded since then, and includes, like, some other richest people in the world, and maybe Trump's gonna be president again soon. [44:16.270 --> 44:17.030] So, so we'll see. [44:17.170 --> 44:22.630] But, um, uh, lawyers used Discord Leaks to gather evidence for their initial, uh, lawsuit. [44:22.630 --> 44:38.430] And, um, the Unite the Right organizers were ordered to pay $25 million in damages, and the lawyers said, while our team eventually subpoenaed the full servers from Discord itself, these initial leaks provided crucial early information that made the speed and breadth of the initial complaint [44:38.430 --> 44:38.870] possible. [44:39.410 --> 44:48.010] Um, and the Charlottesville chat server, um, included people talking about hitting counter-protesters with cars, and then claiming it was self-defense, which is exactly what happened. [44:48.010 --> 44:50.670] Um, so anyways, that's it. [44:50.990 --> 44:53.930] And, uh, on that happy note, I'm done, I guess. [45:02.120 --> 45:03.380] Thanks a lot, Micah. [45:03.620 --> 45:07.760] And while people line up to ask questions, we might have time for two or three. [45:08.080 --> 45:09.760] I'll have one question from the chat. [45:09.920 --> 45:14.620] Uh, you mentioned a Thunderbird plugin to navigate emails from leaked datasets. [45:15.080 --> 45:19.640] But many emails do things like phone home with red receipts or tracking pixels. [45:19.640 --> 45:21.520] Uh, does the plugin manage that? [45:21.680 --> 45:24.080] Or is it better to just view it in a network app VM? [45:24.720 --> 45:30.700] Um, so the plugin is just for importing, uh, the emails into Thunderbird. [45:31.020 --> 45:37.880] But then beyond that, like, you should, um, by default, the default setting in Thunderbird is to turn off remote content. [45:38.100 --> 45:39.380] And so you should keep that off. [45:39.480 --> 45:42.800] And then that should stop any of the emails from phoning home. [45:42.900 --> 45:47.400] But it definitely doesn't hurt to use a VPN or to run this stuff in a VM as well. [45:49.640 --> 45:58.280] I actually... I really like to talk, and I... I don't remember if I learned it from you or from where, but I actually looked at that XF data from the January 6th event. [45:58.560 --> 46:07.520] But what I did is I focused on the pictures that were taken prior to Trump's giving his speech at noon to 1 p.m. [46:07.520 --> 46:15.740] And the interesting thing was there were photographs taken from within the Korndorf area prior to his speech. [46:15.880 --> 46:21.680] So then I downloaded those videos, and they actually included the gates being opened and people coming in. [46:21.820 --> 46:23.020] So it was very interesting. [46:23.500 --> 46:24.180] Yeah, yeah, yeah. [46:24.260 --> 46:31.700] I actually... I think I might have watched that one video where it's, like, the police, like, just seem to be pulling the gates away to let all of the protesters in. [46:31.820 --> 46:32.420] And it's like, why? [46:33.100 --> 46:33.920] What's going on here? [46:34.220 --> 46:36.560] Yeah, so it was... So it's interesting where the data takes you. [46:36.740 --> 46:37.220] Thank you. [46:38.500 --> 46:40.740] Hey, I appreciated your talk. [46:41.220 --> 46:45.620] We do a lot of kind of threat intelligence, kind of similar stuff, scraping data. [46:46.380 --> 46:50.520] Have you ever come across synthetic data yet in your kind of exploration? [46:50.740 --> 46:51.440] Synthetic data? [46:51.680 --> 46:59.580] Like, mass produced by LLMs or, say, like, we find, you know, virtual hard drive images being stored, like VDIs being stored on S3 buckets. [46:59.820 --> 47:06.660] And so when we open those up and reach out to those companies, sometimes they, A, don't know they've been hacked is the most obvious one. [47:07.080 --> 47:15.920] But, B, we're running into, from some of our consultants, that there's some synthetic data essentially out there with these LLMs. [47:17.420 --> 47:31.420] I mean, I haven't really, like, with LLMs, I do know that there is definitely, there are some instances of data sets where, like, specific records have been deleted and then the whole data set's published. [47:31.420 --> 47:41.620] Like, I think WikiLeaks published a Syrian data set that just didn't include this one email about a big money transfer between Syria and Russia. [47:41.980 --> 47:43.660] That's kind of a synthetic. [47:43.660 --> 47:44.440] Yeah, it's kind of synthetic. [47:44.960 --> 47:45.560] I don't know. [47:45.580 --> 47:50.600] I haven't really seen a lot of that myself, but I'm sure that, like, I don't know, it's only a quarter of the way through the century. [47:50.740 --> 47:51.440] We have plenty of time. [47:51.660 --> 47:51.840] Right, right. [47:51.940 --> 47:52.240] Thank you. [47:54.200 --> 47:57.320] I guess I have a question that's a little related. [47:57.320 --> 48:06.820] Are there any, like, concerns about or strategies for validating or authenticating these kinds of data sets? [48:06.880 --> 48:15.000] Because in principle, like, a big dump of emails could contain or just be entirely fake emails, right? [48:15.000 --> 48:15.280] Yeah. [48:15.620 --> 48:21.200] So there's actually... there is a whole part of the book about how to authenticate data sets. [48:21.400 --> 48:24.160] And specifically for emails, it's not always possible. [48:24.340 --> 48:31.940] But with some email servers, you could actually cryptographically confirm that they're real, because emails oftentimes have DKIM headers. [48:32.240 --> 48:41.320] And so you could actually, like, verify that the email server actually signed this email at the time that it was sent, which is cool. [48:42.400 --> 48:46.060] But yeah, it's pretty much verifying it is always, like, a case-by-case basis. [48:46.060 --> 48:52.100] But when you're reporting on stuff, you always have to make sure that you've verified at least everything that's going to be included in your report. [48:52.220 --> 48:55.640] And so, like, a good example is the America's Frontline Doctors data. [48:56.040 --> 48:58.500] I have patient records from hundreds of thousands of people. [48:58.780 --> 49:02.420] I didn't know if it was real or fake, but I had their email addresses. [49:02.420 --> 49:05.340] And so I took a different data set, GAB. [49:05.860 --> 49:08.020] GAB is, like, this very social network. [49:08.200 --> 49:09.640] And they had been hacked, too. [49:09.720 --> 49:11.100] And I had a bunch of email addresses from there. [49:11.240 --> 49:16.640] I compared the two lists of email addresses, and I found hundreds of GAB users that were also American Frontline Doctors patients. [49:16.900 --> 49:22.540] I went and started looking through their GAB profiles and saw some of them talking about, you know, oh, my ivermectin finally came. [49:22.760 --> 49:25.360] And so that's how I was, like, pretty solid that this was real. [49:26.080 --> 49:26.680] Thank you. [49:27.920 --> 49:31.840] We're out of time, but can people come find you at your booth to ask further questions? [49:31.840 --> 49:33.560] Yes, you could talk to me more at my booth. [49:34.040 --> 49:37.440] I'm signing books, and you can come to the workshop. [49:38.580 --> 49:39.200] Okay, great. [49:39.360 --> 49:40.200] Final round of applause.