19 year old arrested due to using Heartbleed

Status
Not open for further replies.

OVERKILL

$100 Site Donor 2021
Joined
Apr 28, 2008
Messages
58,050
Location
Ontario, Canada
http://www.mykawartha.com/news-story/4468539-man-19-charged-in-heartbleed-privacy-breach/

Quote:
OTTAWA - Police have charged a 19-year-old man from London, Ont., in connection with the loss of taxpayer data from the Canada Revenue Agency website.

Stephen Arthuro Solis-Reyes was arrested at his residence Tuesday and is charged with unauthorized use of a computer and mischief in relation to data, the RCMP said Wednesday.

A search of the residence resulted in the seizure of computer equipment.

Solis-Reyes is a computer science student at Western University, a spokesman for the university said.

The Canada Revenue Agency was forced to shut down its publicly accessible website Friday as the world learned about the Heartbleed computer bug, a previously undiscovered global Internet security vulnerability.

Other government computer sites were also temporarily taken down over the weekend.

On Monday, the agency said 900 social insurance numbers had been compromised.

The loss was detected Friday, but the agency delayed telling Canadians about it at the request of the RCMP.

The police said the delay allowed them to pursue their investigation through the weekend and helped track down a suspect.

"The RCMP treated this breach of security as a high priority case and mobilized the necessary resources to resolve the matter as quickly as possible," said Assistant Commissioner Gilles Michaud.

"Investigators from National Division, along with our counterparts in O Division, have been working tirelessly over the last four days analyzing data, following leads, conducting interviews, obtaining and executing legal authorizations and liaising with our partners."

The fact police were able to follow the trail back to the alleged hacker — let alone so quickly — speaks to his level of experience, says an Internet security expert.

"They were not a very sophisticated attacker. Any attacker worth their salt would have been covering their track a lot better than that," said Mark Nunnikhoven, vice-president of cloud and emerging technologies at the software security firm Trend Micro.
 
More details here (and a picture of the kid):

http://www.thepeterboroughexaminer.com/2014/04/16/charges-laid-in-heartbleed-hack-of-cra-site

Quote:
A whiz kid who went to Canada's national spelling bee in 2006, and who with a team from Mother Teresa secondary school won the London-area Catholic school board computer programming competition two years ago, Solis-Reyes is the son of Western computer science professor Roberto Solis-Oba.

"I don't have anything to say to you," Solis-Oba told QMI Agency.

A former schoolmate at Mother Teresa, from which Solis-Reyes graduated in 2012, expressed surprise at the teenager's arrest.

"He was very smart, but he was kind of a loner," the ex-schoolmate said.

The RCMP searched the family home and "scared the [censored] out of his parents and his sibling," Joseph said.

"They also said if he did not go in voluntarily, they were prepared to arrest him in the middle of his exams and make a public spectacle of him," Joseph said.

Solis-Reyes voluntarily went to the London police station, he said.
 
If he's frightened about exam time, he should have been preparing for his exams, rather than hacking from his own IP.
wink.gif
 
Originally Posted By: Barkleymut
Back in my day we would go outside and kick a ball or go talk to girls.


LOL..i dont think he does sports or can pick up girls..based on picture..
 
Originally Posted By: Garak
If he's frightened about exam time, he should have been preparing for his exams, rather than hacking from his own IP.
wink.gif



If he was smart he would of used a different ip for hacking. I would of hacked to get answers to the exams..
 
The idiot didnt use an encrypted vpn to cover his tracks which just shows he is a complete noob. I run a 256 bit encrypted vpn 100% of the time I am online. A few years ago I used to get warnings from my provider and RIAA about downloading and sharing stuff. I finally had enough and went with a fast encrypted vpn and have received nothing since because they have no clue what I am doing. My vpn provider also stores absolutely ZERO logs which means even if they get a court order to give up a customer they can not because they have no logs of what ip's connect to there vpn tunnels.


For example I have tormented small forum owners before when they decided they would ban me for one reason or another. Sure you can ban my username but they tried to ban my ip LMAO. Disconnect and reconned and waaa laaa new ip. Rejoin and let them have it. Best $40 yearly subscription I have ever spent.
 
Status
Not open for further replies.
Back
Top