Swedish Police Swoop on Dan Egerstad - UPDATE

Asher Moses writes on The Age.com.au.
The Swedish hacker who perpetrated the so-called hack of the year has been arrested in a dramatic raid on his apartment, during which he was taken in for questioning and several of his computers confiscated.
Dan Egerstad, a security consultant, intercepted data carried over a global communications network used by embassies around the world in August and gained access to 1000 sensitive email accounts. They contained confidential diplomatic memos and other sensitive government emails.
After informing the governments involved of their security failings and receiving no response, Egerstad published 100 of the email accounts, including login details and passwords, on his website for anyone curious enough to have a look. The site, derangedsecurity.com, has since been taken offline.
The hack required little more than tools freely available on the internet, and Egerstad maintains he broke no laws. In fact, he is confident the email accounts he gained access to were already compromised by other hackers, so his efforts in fact prevented them from continuing their spying.
More
here.
UPDATE: 19:23 PST: Kim Zetter has additional details
here on
Threat Level.
-ferg
Image source: The Age
Hacks Hit Embassy, Government E-mail Accounts Worldwide - UPDATE
A Computer Sweden article by Daniel Goldberg and Linus Larsson, via PC World, reports that:
Usernames and passwords for more than 100 e-mail accounts at embassies and governments worldwide have been posted online. Using the information, anyone can access the accounts that have been compromised.
Computer Sweden has verified the posted information and spoken to the person who posted them. The posted information includes names of the embassies and governments, addresses to e-mail servers, usernames and passwords. Among the organizations on the list are the foreign ministry of Iran, the Kazakh and Indian embassies in the U.S. and the Russian embassy in Sweden.
Freelance security consultant Dan Egerstad posted the information. He spoke openly about the leak when Computer Sweden contacted him.
"I did an experiment and came across the information by accident," he said. Egerstad says he never used the information to log in to any of the compromised accounts in order not to break any laws.
More
here.
UPDATE: 12:27 PDT, 31 August 2007: Kim Zetter has
additional details over on
Threat Level.
Security Researcher Intercepts Embassy Passwords From Tor
Jeremy Kirk writes on InfoWorld:
A security researcher who collected thousands of sensitive e-mails and passwords from the embassies of countries such as Russia and India blamed systems administrators on Monday for not using encryption to shield their traffic from snooping.
Dan Egerstad, a 21-year-old security researcher, revealed on Monday he was able to capture the information by setting up his own node in a peer-to-peer network used by the embassies to make their Internet traffic anonymous.
The embassies relied on a volunteer network of servers using software called Tor (The Onion Router) to hide their Internet traffic and make it anonymous. Traffic sent through a Tor node is transmitted through a randomly selected series of other Tor nodes before exiting the network for its intended destination, so as to disguise the source and destination of the traffic.
But although traffic between nodes in a Tor network is encrypted by default, traffic entering and exiting the system is not, so anyone wanting to hide not only who are they are communicating with, but what they are saying, must apply an extra layer of encryption themselves. Embassies and companies neglected to do this, which left their information open for Egerstad to collect.
More
here.