tech-team

RocketChat ID: 4xBSWiLiQjEDjp5Gp


2,194 total messages. Viewing 100 per page.
Prev | Page 6/22 | Next

Matthew MN @PF-6495

I think I recall Vincent being added in early August.

Jason NY @PF-3527

He was sent for in-person vetting on July 29th

Benjamin WI @PF-8943

Seems WA likely had a series of infiltrators @Matthew MN which you eluded to a couple days back. But until we see codes that don't go back to Vincent WA then we can only speculate.

Matthew MN @PF-6495

Robert WA was kicked because they all suspected him and he always wore a mask. Lines up with the other details. They likely are holding onto those screenshots to avoid implicating him or saving them for a dox.

Benjamin WI @PF-8943

I highly doubt that this guy joined and the next day was doing banner drops while having antifa follow them around. So I would expect another previously removed WA name to surface soon in these codes.

Benjamin WI @PF-8943

Yep, they will post them and clear it up for us soon.

Benjamin WI @PF-8943
Benjamin WI @PF-8943

Vincent WA
Created at
August 2, 2021 4:56 AM

Matthew MN @PF-6495

Ok when added to an RC channel I am pretty sure you can scroll up

Jason NY @PF-3527

Yes, you can

Matthew MN @PF-6495

Ok that explains that

Matthew MN @PF-6495

If they have caught on to the numbers they might avoid releasing screenshots from their active guy

Benjamin WI @PF-8943

So in the screenshot I posted from July 31st, Vincent was scrolling up basically then?

Matthew MN @PF-6495

yes

Benjamin WI @PF-8943

We may consider wiping network chats more frequently, if they aren't already under a policy.

Matthew MN @PF-6495

Retention is 7-15 days

Benjamin WI @PF-8943

Ok, that seems like a balanced amount of time.

Matthew MN @PF-6495

7 seems fair if it isn't already that

Thomas @thomas

We can flag people who have suspicious reception for further evaluation, but we can't act as if gut feelings are substance of their own. There have been more cases of people just coming off as weird and being fine, and we don't want to lean into paranoia, the very thing these infiltration are meant to inspire.

As for Jake's idea, Directors could have a red flag sort of note that applies to their membership. If someone is flagged with any strange acts, then they are investigated heavily until either removal or reassurance.

Activism Channel: Raw photos are nearly useless to infiltration considering they're all published as-is, have no meta-data, and have never been used in any infiltration or opposition strategy in any instance. If someone is only visiting their home town, then that's something for their local leadership to examine. Otherwise, they only indicate a vague metro area. There may be some more efficient way to log the photos, but I think this should not be a focus while there are generally any other pressing matters. That's a downtime project.

@Jake AR I did not rename Victory, I have not been given any instructions on it. Do you want me to implement those CF settings on the Victory domain?

@Vincent TX @Jason NY What precisely is the proposed content of the announcement, cease using the application, make a new password?

Vincent WA:
August 2, 2021 4:56 AM

Time-wipe on channels seems fine across the board.

Jason NY @PF-3527

Summary of announcement would be:
- We are imminently disabling access to rocket chat via the rocket chat app
- You can only access rocket chat from now on using a web browser
- Let us know now if you don't remember your password so that you are not locked out

Benjamin WI @PF-8943

I would add "As previously announced," to the first line. This is not a new thing, this was announced months back.

Thomas @thomas

@Jason NY You mean viewing on the web browser, and the desktop app, which does include the message codes? The disabling of the application is to ensure the codes are visible, correct? Only the [mobile] app is scheduled to be disabled, correct?

People may have a concern about functionality, driving people to use other platforms. Could updating the server to the latest version help alleviate this with the removal of the mobile application?

Jake AR @PF-3320

Was victory taken offline? It's offline right. I wanted it online so we can make sure our change didn't break it. Don't implement the cloudflare changes yet. We should let the announcement get to everyone first so they can start using browser on phone or computer.

Thomas @thomas

Just turned it on again.

Jason NY @PF-3527

Disabling the mobile app is to ensure the codes are visible, however we are also restricting API access to only requests from victory (necessary) which will kill the mobile app as a side effect. The API restriction is to limit the scope of potential exploits and to prevent a denial of service by people flooding the API with bogus requests. The disabling of the API might also make the desktop app defunct.

Jake AR @PF-3320

That is correct. Mobile app should be only thing that stops working. If the cloud flare firewall change does not create the outcome that we want we will undo that change and do something else that's a little bit more complicated but in the end that is the goal to disable the mobile app

Jason NY @PF-3527

Okay nvm about desktop app then

Jake AR @PF-3320

The desktop app essentially uses a browser

Thomas @thomas

Okay, so just to confirm, desktop app will be fine? Only mobile app.

Jason NY @PF-3527

Confirmed

Jake AR @PF-3320

Correct

Thomas @thomas

Thank you.

Jake AR @PF-3320

You can also put in the announcements that if anyone has any trouble and is unable to get back into the server they can use the website or mumble

Thomas @thomas

SOP is send a contact request or message via someone you know.

Jake AR @PF-3320

Gotcha

Jake AR @PF-3320

Victory is back up

Vincent TX @PF-4354

@Thomas Jason is correct with the announcements we need to throw out

Thomas @thomas

Will do that in conjunction with other announcements in the plans already.

Vincent TX @PF-4354

Thank you

Vincent TX @PF-4354

@all So what is being implemented this evening, and by who'm. Want to write this down

Jake AR @PF-3320

I'd make it clear they can use mobile browser. Ppl think everything on a phone is an app sometimes

Jason NY @PF-3527

@Vincent TX Tonight's goals are to prepare for API restriction. We will need to wait for some time after the announcement goes about, probably until the morning. We also need to get a development sandbox VPS up so that we can install the latest version of rocket and work on importing our scripts and database. We'll swap production with sandbox only once we're sure everything is working correctly. We can then move on to secondary goals.

Jake AR @PF-3320

Save password complexity for a different time, something that can be rolled out gradually?

Jason NY @PF-3527

Yep, secondary goal imo.

Jake AR @PF-3320

Okay

Jake AR @PF-3320

For upgrading rocket chat I think we should try to make a clone of the server and we might be able to do that through our host. Then run an incremental script to upgrade rocket chat through all the minor releases which will upgrade the database schema

Jason NY @PF-3527

Oh great idea, I didn't think about that. That'll make our job much easier.

Jake AR @PF-3320

If everything checks out, then we implement here.

Jake AR @PF-3320

There's a good chance that all of our customization will be fine the main issue is does the database update and does our front end layout change a whole lot like the colors the order of things sometimes they add features and so we have to go in and disable them in the settings

Jake AR @PF-3320

If Thomas can make a clone of the server we'll get a new IP address but I'll need to go in there and disable the firewall that only allows you to access the front end from cloudflare. After that we should be able to go into the IP address to test it

Jason NY @PF-3527

Sounds good.

Jake AR @PF-3320

Actually I forgot the firewall is through our host so when Thomas makes a clone we just need to disable the firewall settings for that clone server

Jake AR @PF-3320

I say we focus on the next 24 hours getting everybody onto the browser and making sure that's all working and then we can work on cloning a server because if this all gets messed up we're going to need Thomas to go in there and undo the cloudflare stuff so I don't want Thomas doing two things

Jason NY @PF-3527

Does restricting the API have the potential of messing up the server in a significant way?

Jake AR @PF-3320

No, it doesn't. It's all outside rules from cf, so simply delete rule and everything goes back to normal instantly

Jake AR @PF-3320

I just didn't want to rush it just in case we get bogged down helping ppl reset passwords and stuff

Jake AR @PF-3320

I'm cool with it either way. Glad we're getting changes done

Jason NY @PF-3527

We can fix every issue with the updated rocket chat / database schema on a dev sandbox and then only switch it over to production when we're absolutely sure it'll work as expected

Jason NY @PF-3527

I don't think we need to wait to get started on that

Jake AR @PF-3320

Okay. Also just so we're on the same page the goal is to use the sandbox just to test the upgrading process and if that is all good then we will do that live on the actual production server because we don't want to lose messages that happened since the clone

Jason NY @PF-3527

Depends on how quickly we can import the database and have it working properly I suppose

Jake AR @PF-3320

And just as a reminder before we do anything on the production server, we have to have Thomas make a snapshot so worst case scenario we can just revert back to a few hours before. But we'll do that once we're done testing with the sandbox and know that everything works

Jason NY @PF-3527

Yep definitely

Jason NY @PF-3527

If we figure out a method to import the database and upgrade the schema within 10 minutes we'll probably be good to just swap sandbox with production rather than building up production live

Jason NY @PF-3527

Someone can just do it at like 4 am and there probably won't even be any messages sent

Jake AR @PF-3320

If it's that fast we can consider swapping, but in the past we've just kept the same server.

Jason NY @PF-3527

We will soon find out

Jason NY @PF-3527

Another thing is to remember to record the steps that we're taking to upgrade the server on our cryptpad doc as we go along

Jake AR @PF-3320

Yea, I'd like to know what worked too. I keep docs on all RC processes

Jason NY @PF-3527

Excellent. I think we're good to go as soon as server is cloned.

Jake AR @PF-3320

@Thomas Steps to clone server: power down main rc server, create a snapshot, power on main rc server, go to MORE next to latest snapshot and choose CREATE, choose the same configuration of memory, I think it's 3gb but check, create some root password and send that to Jason NY, go into the newly created server, choose networking then under firewalls it should say no firewalls applied

Jake AR @PF-3320

@Jason NY I am not sure if the clone copies over ssh meys, but if not the root password should work

Jason NY @PF-3527

No worries

Jason NY @PF-3527

This either confirms that there is another infiltrator, or that antifa has obtained the police reports.

Jason NY @PF-3527

Or the guys who did it are in communication with him and are stupid enough to brag about threatening me with a firearm

Vincent TX @PF-4354

You know that is the case bro. These people live off of hubris alone.

Vincent TX @PF-4354

Putting on the hacker glasses

Vincent TX @PF-4354

This guy is real dumb if he is clicking random links

Jason NY @PF-3527

Or he's just trolling and opening it while on tails to waste our time. I hope he's dumb

Vincent TX @PF-4354

It's an android user agent

Vincent TX @PF-4354

Android 10

Vincent TX @PF-4354

Motorola Moto Z4

Vincent TX @PF-4354

Comcast-7922

Jason NY @PF-3527

It's not a tor circuit because it's on hardly any blacklists.

Jason NY @PF-3527

Might be connecting from phone but that's not a mobile hostname.

Jason NY @PF-3527

Residential VPN/Proxy or it's actually where he's at.

Matthew MN @PF-6495

@Thomas talk with Paul CA before doing anything with the infils information

Vincent TX @PF-4354

That IP is not listed in the mumble logs

Vincent TX @PF-4354

I did however find some of Vincents info

Vincent TX @PF-4354

On 11/17 he logged in from Corona California

Matthew MN @PF-6495

I mean he said some really stupid shit in a public Telegram chat when he got angry

Vincent TX @PF-4354

We also found a residential Seattle IP

Vincent TX @PF-4354

Lawrence FL just sent me screenshots of all of that

Jake AR @PF-3320

You know what I just noticed, the secret hashes are not added to new messages

Jake AR @PF-3320

Idk how if it's when I left and came back it's like it didn't update the new messages. Let me know if you guys notice that. I might have to update the JS. Those hashes are critical

Vincent TX @PF-4354

I see them in this channel

Matthew MN @PF-6495

works for me

Matthew MN @PF-6495

@Vincent TX sam should have sent you another even more incriminating screenshot

2,194 total messages. Viewing 100 per page.
Prev | Page 6/22 | Next