Could be just some entity that buys websites with good expired domain names to late resell? But yes I don't understand why they are not empty.
HN user
cirosantilli
Check out: https://OurBigBook.com I am: https://cirosantilli.com Proof: https://cirosantilli.com/accounts
Codex has recently added a [terminal bell](https://en.wikipedia.org/wiki/Bell_character) on some recent update btw. I hear a little "beemp" sound on Ubuntu 25.10. Not as ideal as a notification since I don't know which terminal finished. But already a huge improvement. Tested on codex-cli 0.93.0.
They have a Sorted by Trending feature BTW on each question, it's just not the default sort method.
Nowadays at least, wonder if they could just pick a few of the most popular unblocked HTTPS websites with a private messaging system a la Twitter DM. Email possibly too. A GitHub private repo would be perfect for that as dictatorships relaly hate to block it and lose all the IT value. Maybe at the time things weren't so simple with less HTTPS adoption.
I suspect the agents knew little about the comms tech and were deeply reassured of their security.
Ah, I didn't implement RSS unfortunately. What you can do now is if you follow a user when they announce an article (there's an announce button), you get an email with a link. I suppose it could be modified to also put announced articles in an RSS feed. I never did much RSS for whatever reason. PRs open :-)
It is hard to balance both aspects. I tried to summarize more interesting things on initial sections and from "Methodology" downwards it is definitely not for casual reading. Also huge images and table, so don't be afraid of the bar.
Definitely. An OPSEC is only secure relative to the appropriate thread model. If those disconnect, it spells disaster.
Author of the research article here. https://www.404media.co/the-cia-secretly-ran-a-star-wars-fan... published today which kicked off this thread has a good summary, but let me know if anything is unclear.
The problem was called "Antihydra" by discoverers. This could mean that we might never be able to determine BB(6), and that it might be undecidable.
Thank for the submission! This was also previously posted at: https://news.ycombinator.com/item?id=36279375 from before my recent update that added ~75 new websites with a new technique: https://twitter.com/cirosantilli/status/1717445686214504830
Except the previous one was at: https://cirosantilli.com/cia-2010-covert-communication-websi... which is the corresponding static website version of https://ourbigbook.com/cirosantilli/cia-2010-covert-communic...
I started this research after YouTube suggested me that video. I knew about the sites, but I had missed the Reuters articles that gave the 7 starting points.
I would love to know... even finding the source of those stock photos would be awesome. My initial suspicion is that the image split is just an ancient webdev thing (which they used much after it was popular) to reduce the size of each individual image. But who knows!
The ultimate compliment.
Yeah. They just didn't have the patience to setup separate ranges for each of their ~900 sites. It's quite sad.
Thanks for the awesome service! I wish I had known this, I went to quite a few cybercafes to get some extra IPs XD
I really wish the reverse IPs would hit even when it's not the last IP though! Many more hits would come out of that. Related mentions under: https://ourbigbook.com/cirosantilli/cia-2010-covert-communic...
Of course :-)
Exactly. The best bet is to use a service that is used by a huge number of users and try to hide your traffic in it. I wonder why they didn't do gmail -> gmail for example. Maybe there are good reasons.
Hello HN.
Noble try :-)
Two related posts by me:
- https://stackoverflow.com/a/66105692 - https://webapps.stackexchange.com/a/149405
I wonder how Alexa found those domains in the first place. Were there links to them, or did it use some kind of DNS dump?
I have found that one of the communication mechanisms used does use HTTPS on subdomains, typically secure.*, as explained at: https://cirosantilli.com/cia-2010-covert-communication-websi... E.g.: https://secure.globalnewsbulletin.com However my quick and naive searches on https://search.censys.io/ for other certificates with the same public key failed.
I have researched this now.
According to https://tools.whoisxmlapi.com/whois-history-search the domains were registered June 11, 2023, shortly after my article came out.
They are therefore likely just made by wakatime's founder Alan Hamlett: https://www.linkedin.com/in/alanhamlett/ as a bit of Guerrilla Marketing. Fair play.
When I saw on LinkedIn that he worked for a web security contractor until September 2013, I almost flipped. But appears unrelated however unfortunately except for his general interst in WEBSEC, so another dead end.
If anyone has any more precise information on this, do let me know. I do suspect there's some kind of "protocol legel" fingerprint, as I can't find anything in the content that would be searchable so far.
Interesting psychological analysis XD
Nice, I hadn't noticed that! I'll add a mention to the article. Some do fail DNS resolution though.
Hi, third person: https://cirosantilli.com/why-ciro-santilli-refers-to-himself...
We includes me, and if at some point others might contribute. So when it's not something I did specifically, I tend to we.
Typos: fixed now and some others, thanks. Feel free to send any others. "Pubic" one was epic. Vim sometimes forgets to turn on spellcheck.
And also consider showing me some love! XD https://cirosantilli.com/sponsor
Third person: https://cirosantilli.com/why-ciro-santilli-refers-to-himself...
Conspiracy thinking: Example?
I think it is pretty safe to assume that essentially all opponents are capable. In particular, intelligence is one of the first things dictatorships will invest in, partly to spy on their own people, which the leaders fear above all else.
The ideal communication mechanism is one that blends in with a huge number of other "legitimate" users. E.g. for Tor, it only works if many people are also using Tor for other non-spy things. I wonder why not just email.