Pages:
Author

Topic: Cats lead Feds to KnightMB (worth 371kBTC) in Romney Tax Hack. - page 3. (Read 12385 times)

hero member
Activity: 868
Merit: 1000
he says he has been robbed before:

http://mbdonationfund.com/index.php?option=com_content&view=article&id=52&Itemid=59

Quote
Q: Why the financial issues?
A: The Secret Service came in a few months ago and a lot of important and expensive stuff has been missing since. It is difficult for any business to survive if all of its operating equipment is taken and not returned. Ask a local plumber what would happen if someone took his truck and all the tools used for the trade.

The FAQ isn't dated so it's difficult to know when he's talking about.  Where are the receipts for the stuff the SS supposedly took before?  He's posted the documents related to the September seizure, why not for the other stuff?

As I've said before, he's appealing to the anti-government brigade and he knows his audience well. 
legendary
Activity: 1708
Merit: 1020

I don't understand how a guy that once had 371,000 BTC at his disposal and runs an "internet provider business" (Huh) has like 15 harddrives ranging from 20GB to 160GB and only one larger one with 400GB. He's and IT pro for gods sake, so this is an indication he really doesn't have access to any kind of reasonable funds to even run his business. It seems he stopped buying equipment around the time his kids were born, which would make sense.

That's what makes no sense.  Even if he gave most of the BTC away as he claimed, why the hell didn't he upgrade his hardware and shit?  The evidence that he's the same guy who claimed to have 371,000 BTC is pretty compelling, but did he ever actually have them much less give them away?  Did his gloating about the manner in which he acquired them put him in a position where he was forced to return them before he could spend them?  For that matter, why didn't he upgrade his hardware when he sold the Endless Sphere forums?

[...]
he says he has been robbed before:

http://mbdonationfund.com/index.php?option=com_content&view=article&id=52&Itemid=59

Quote
Q: Why the financial issues?
A: The Secret Service came in a few months ago and a lot of important and expensive stuff has been missing since. It is difficult for any business to survive if all of its operating equipment is taken and not returned. Ask a local plumber what would happen if someone took his truck and all the tools used for the trade.
legendary
Activity: 1708
Merit: 1020
[...]
He filmed the last time he was raided by the SS. I wonder if he has new footage.
He filmed it allright, but the secret service took the harddrive of the h264 recorder. It's on the list of items seized.
There is a lesson here to be learned: Always stream your security video to a secure and distant place.
hero member
Activity: 868
Merit: 1000

I don't understand how a guy that once had 371,000 BTC at his disposal and runs an "internet provider business" (Huh) has like 15 harddrives ranging from 20GB to 160GB and only one larger one with 400GB. He's and IT pro for gods sake, so this is an indication he really doesn't have access to any kind of reasonable funds to even run his business. It seems he stopped buying equipment around the time his kids were born, which would make sense.

That's what makes no sense.  Even if he gave most of the BTC away as he claimed, why the hell didn't he upgrade his hardware and shit?  The evidence that he's the same guy who claimed to have 371,000 BTC is pretty compelling, but did he ever actually have them much less give them away?  Did his gloating about the manner in which he acquired them put him in a position where he was forced to return them before he could spend them?  For that matter, why didn't he upgrade his hardware when he sold the Endless Sphere forums?

If there's one thing life has taught me it's that smart people can be totally devoid of common-sense, so I don't think any "no-one who knew anything about IT argument would be that stupid" arguments hold water.  In my experience, technical competence in any field can lead to over-confidence.
donator
Activity: 2772
Merit: 1019
Any interviewer worth their salt would have mentioned that unless they were instructed not to. What if a million dollars in gold were requested? Silver? Diamonds? Unmarked twenties? KitKats? Either one of these would have been mentioned. But a million dollars in Bitcoin, a pseudo-currency, doesn't merit a mention? Odd!

They said: "one million in online currency". Probably instructed not to mention "bitcoin", I can believe that, because "bitcoin", "the online currency used to buy drugs on the internet" would certainly add to the story.

I'm not an expert on body language, but overall he does come across as innocent during the interview, but with a couple minor twists when answering in the negative.

I had the same feeling. When he denies being a hacker and having stolen the documents, after he finishes speaking the words, he puts on a quirky kind of smile (watch the lower lip). I don't know about such things, though. I still think he's innocent and being played by someone who really hates him. Who of us can say "I'm not a hacker" with a straight face, especially because they really mean "cracker" or "digital thief" or something.

I don't understand how a guy that once had 371,000 BTC at his disposal and runs an "internet provider business" (Huh) has like 15 harddrives ranging from 20GB to 160GB and only one larger one with 400GB. He's and IT pro for gods sake, so this is an indication he really doesn't have access to any kind of reasonable funds to even run his business. It seems he stopped buying equipment around the time his kids were born, which would make sense.

He filmed the last time he was raided by the SS. I wonder if he has new footage.

He filmed it allright, but the secret service took the harddrive of the h264 recorder. It's on the list of items seized.
hero member
Activity: 868
Merit: 1000
I'm still not following you Phin.  We can explain the EXIF data by the camera being new and cheap.  The images were edited in GIMP almost a week ago but I'm not sure why you think that the time of day when they were edited on 4 November is significant in some way.  Having family photos which were taken by someone else also isn't unusual.

I was kind of hoping that the EXIF data would be a smoking gun and prove that those images aren't of the 14 September raid, but unfortunately it's easy to explain the date discrepancy and maybe my brain isn't in gear today but I'm not seeing anything particularly notable about the images being modified on 4 November.
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
Quote
At 6:10 A.M. before daylight on September 14, 2012 while my wife and I were sleeping in our small Franklin, TN home...

Something is not adding up with all this. First, I can't believe MB's allowed to post information while an investigation is being conducted. Secondly, He registered the following 9 days after being questioned.

Furthermore, take a look at the EXIF of the photos on his site. Something doesn't add up there either. I was going to add more this post but was stopped by Google (see below the fold).

Source: http://who.godaddy.com/whois.aspx?k=RHD16SymJAqRP35/5oJAhaSvbaZL6sAO&domain=mbdonationfund.com&prog_id=GoDaddy

Quote
Registered through: GoDaddy.com, LLC (http://www.godaddy.com)
Domain Name: MBDONATIONFUND.COM
Created on: 23-Sep-12
Expires on: 23-Sep-13
Last Updated on: 23-Sep-12

Registrant:
Michael Brown
107 Cadet Circle
Franklin, Tennessee 37064
United States

Administrative Contact:
Brown, Michael [email protected]
107 Cadet Circle
Franklin, Tennessee 37064
United States
+1.6155551212 Fax -- +1.6155551213

Technical Contact:
Brown, Michael [email protected]
107 Cadet Circle
Franklin, Tennessee 37064
United States
+1.6155551212 Fax -- +1.6155551213

Domain servers in listed order:
NS21.DOMAINCONTROL.COM
NS22.DOMAINCONTROL.COM

This is the very first time I've ever encountered something like the following while using Google:

Quote
About this page

Our systems have detected unusual traffic from your computer network. This page checks to see if it's really you sending the requests, and not a robot. Why did this happen?

IP address: (edit)
Time: 2012-11-11T23:26:08Z
URL: http://www.google.com/search?hl=en&tbo=d&sclient=psy-ab&q=%22%22michael+*+brown%22&oq=%22%22michael+*+brown%22&gs_l=serp.3..0i30j0i10i30j0i30l2j0i10i30j0i30l5.3031.15264.1.15509.21.19.2.0.0.0.180.2162.8j11.19.0.les%3B..0.0...1c.1.m2OWSGZE6wY&psj=1&bav=on.2,or.r_gc.r_pw.r_cp.r_qf.&bpcl=38093640&biw=1280&bih=685&ech=1&psi=FzKgUN-mBKqVygGgqIGQBA.1352676345178.3&emsg=NCSR&noj=1&ei=5TKgUL_MJMOayQHbo4DAAg

Please don't tell me that theymos is now a mod at Google and I've been banned from using their services.  Grin

EDIT: I just edited out the IP address, for I thought it was only for Sandwich, IL, but luckily I checked for I think (seriously don't know) that it was truly personal. When I searched for it, it asked for log in info.

I'm having a blonde moment here Phin, so help me out.  Are you saying that when you typed Michael * Brown into Google you got that message, because I can't replicate it either with or without the *.

I can't think of any reason why he wouldn't be allowed to post while an investigation is under way.  He hasn't been charged with anything and even if he had been I doubt he'd be gagged by any court.

I'm not surprised that he decided to solicit donations after the search and seizure.  I think it's tacky as hell and that he's hoping to exploit anti-government sentiment, but begging for donations on the internet seems pretty common these days.

When I check the EXIF data it shows the images as having been taken on January 1, 2011 at around 1pm US Pacific time but there's no way of knowing whether the time and date on the camera were set accurately.

In re. Google search: I haven't had another instance yet. I simply copy & paste what was on Google's page, but not the captula.

As far as for the images, I understand that a new cheapo camera was purchased/used to snap those images, thus not setting the time on the camera. Yet look at the times (of day) they were snapped, then edited with Gimp showing the times up to the second. The family photo is copywrited by Angel____________.

In this TV interview with MB, not once is Bitcoin mentioned: http://www.wsmv.com/story/20006705/secret-service-investigate-franklin-man-in-romney-tax-return-theft

Any interviewer worth their salt would have mentioned that unless they were instructed not to. What if a million dollars in gold were requested? Silver? Diamonds? Unmarked twenties? KitKats? Either one of these would have been mentioned. But a million dollars in Bitcoin, a pseudo-currency, doesn't merit a mention? Odd!

MB also mentions in the interview that the only time he heard about this episode was on the news. Yet he's on record more than once stating he read about it on this forum prior to being questioned by the Secret Service.

I'm not an expert on body language, but overall he does come across as innocent during the interview, but with a couple minor twists when answering in the negative.

He filmed the last time he was raided by the SS. I wonder if he has new footage.

Janine Bolin's cat: Cats have nine lives. Bolin is similar to Bovine. Bovine is a cow. Josh uses Cowmail and once had a BBS in Franklin, TN. (facts, but not serious) (I reserve the right to revisit this if I latter learn that MB is also a Furry)
hero member
Activity: 868
Merit: 1000
Quote
At 6:10 A.M. before daylight on September 14, 2012 while my wife and I were sleeping in our small Franklin, TN home...

Something is not adding up with all this. First, I can't believe MB's allowed to post information while an investigation is being conducted. Secondly, He registered the following 9 days after being questioned.

Furthermore, take a look at the EXIF of the photos on his site. Something doesn't add up there either. I was going to add more this post but was stopped by Google (see below the fold).

Source: http://who.godaddy.com/whois.aspx?k=RHD16SymJAqRP35/5oJAhaSvbaZL6sAO&domain=mbdonationfund.com&prog_id=GoDaddy

Quote
Registered through: GoDaddy.com, LLC (http://www.godaddy.com)
Domain Name: MBDONATIONFUND.COM
Created on: 23-Sep-12
Expires on: 23-Sep-13
Last Updated on: 23-Sep-12

Registrant:
Michael Brown
107 Cadet Circle
Franklin, Tennessee 37064
United States

Administrative Contact:
Brown, Michael [email protected]
107 Cadet Circle
Franklin, Tennessee 37064
United States
+1.6155551212 Fax -- +1.6155551213

Technical Contact:
Brown, Michael [email protected]
107 Cadet Circle
Franklin, Tennessee 37064
United States
+1.6155551212 Fax -- +1.6155551213

Domain servers in listed order:
NS21.DOMAINCONTROL.COM
NS22.DOMAINCONTROL.COM

This is the very first time I've ever encountered something like the following while using Google:

Quote
About this page

Our systems have detected unusual traffic from your computer network. This page checks to see if it's really you sending the requests, and not a robot. Why did this happen?

IP address: (edit)
Time: 2012-11-11T23:26:08Z
URL: http://www.google.com/search?hl=en&tbo=d&sclient=psy-ab&q=%22%22michael+*+brown%22&oq=%22%22michael+*+brown%22&gs_l=serp.3..0i30j0i10i30j0i30l2j0i10i30j0i30l5.3031.15264.1.15509.21.19.2.0.0.0.180.2162.8j11.19.0.les%3B..0.0...1c.1.m2OWSGZE6wY&psj=1&bav=on.2,or.r_gc.r_pw.r_cp.r_qf.&bpcl=38093640&biw=1280&bih=685&ech=1&psi=FzKgUN-mBKqVygGgqIGQBA.1352676345178.3&emsg=NCSR&noj=1&ei=5TKgUL_MJMOayQHbo4DAAg

Please don't tell me that theymos is now a mod at Google and I've been banned from using their services.  Grin

EDIT: I just edited out the IP address, for I thought it was only for Sandwich, IL, but luckily I checked for I think (seriously don't know) that it was truly personal. When I searched for it, it asked for log in info.

I'm having a blonde moment here Phin, so help me out.  Are you saying that when you typed Michael * Brown into Google you got that message, because I can't replicate it either with or without the *.

I can't think of any reason why he wouldn't be allowed to post while an investigation is under way.  He hasn't been charged with anything and even if he had been I doubt he'd be gagged by any court.

I'm not surprised that he decided to solicit donations after the search and seizure.  I think it's tacky as hell and that he's hoping to exploit anti-government sentiment, but begging for donations on the internet seems pretty common these days.

When I check the EXIF data it shows the images as having been taken on January 1, 2011 at around 1pm US Pacific time but there's no way of knowing whether the time and date on the camera were set accurately.
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
I will suck everybody's dick if koinmaster and KnightMB is not the same person here (registered only 2 hours apart): http://forums.timekoin.org/viewtopic.php?f=2&t=84
legendary
Activity: 1918
Merit: 1570
Bitcoin: An Idea Worth Spending
Quote
At 6:10 A.M. before daylight on September 14, 2012 while my wife and I were sleeping in our small Franklin, TN home...

Something is not adding up with all this. First, I can't believe MB's allowed to post information while an investigation is being conducted. Secondly, He registered the following 9 days after being questioned.

Furthermore, take a look at the EXIF of the photos on his site. Something doesn't add up there either. I was going to add more this post but was stopped by Google (see below the fold).

Source: http://who.godaddy.com/whois.aspx?k=RHD16SymJAqRP35/5oJAhaSvbaZL6sAO&domain=mbdonationfund.com&prog_id=GoDaddy

Quote
Registered through: GoDaddy.com, LLC (http://www.godaddy.com)
Domain Name: MBDONATIONFUND.COM
Created on: 23-Sep-12
Expires on: 23-Sep-13
Last Updated on: 23-Sep-12

Registrant:
Michael Brown
107 Cadet Circle
Franklin, Tennessee 37064
United States

Administrative Contact:
Brown, Michael [email protected]
107 Cadet Circle
Franklin, Tennessee 37064
United States
+1.6155551212 Fax -- +1.6155551213

Technical Contact:
Brown, Michael [email protected]
107 Cadet Circle
Franklin, Tennessee 37064
United States
+1.6155551212 Fax -- +1.6155551213

Domain servers in listed order:
NS21.DOMAINCONTROL.COM
NS22.DOMAINCONTROL.COM

This is the very first time I've ever encountered something like the following while using Google:

Quote
About this page

Our systems have detected unusual traffic from your computer network. This page checks to see if it's really you sending the requests, and not a robot. Why did this happen?

IP address: (edit)
Time: 2012-11-11T23:26:08Z
URL: http://www.google.com/search?hl=en&tbo=d&sclient=psy-ab&q=%22%22michael+*+brown%22&oq=%22%22michael+*+brown%22&gs_l=serp.3..0i30j0i10i30j0i30l2j0i10i30j0i30l5.3031.15264.1.15509.21.19.2.0.0.0.180.2162.8j11.19.0.les%3B..0.0...1c.1.m2OWSGZE6wY&psj=1&bav=on.2,or.r_gc.r_pw.r_cp.r_qf.&bpcl=38093640&biw=1280&bih=685&ech=1&psi=FzKgUN-mBKqVygGgqIGQBA.1352676345178.3&emsg=NCSR&noj=1&ei=5TKgUL_MJMOayQHbo4DAAg

Please don't tell me that theymos is now a mod at Google and I've been banned from using their services.  Grin

EDIT: I just edited out the IP address, for I thought it was only for Sandwich, IL, but luckily I checked for I think (seriously don't know) that it was truly personal. When I searched for it, it asked for log in info.
legendary
Activity: 1428
Merit: 1001
Okey Dokey Lokey
Hey do we still have that bitcoin address that holds/held the 371k bitcoins? Have they been spent?
legendary
Activity: 1330
Merit: 1000
Quote
There is no national database of cats.

From what I have learned over the last 9 months or so, the National Database of Cats can be found here
newbie
Activity: 49
Merit: 0
wow thats sad and crazy.. What would i do lol
legendary
Activity: 1512
Merit: 1049
Death to enemies!
Quote
My understanding is that it can be difficult to completely erase data from flash drives - I'm guessing there were other fragments of data on there which were more specific and that's why he can't outright deny having ever possessed the flash drive.
It is possible to erase data from flash drive that it returns nothing useful when accessed with normal interface. But the wear leveling varies from one model to another and it might be possible to recover bits of data from spare areas.

If he was so stupid to send FBI the drive he used himself then he might as well be stupid enough to not erase the flash drive at all.

He probably made some other mistakes. There is no national database of cats. DNA on flash drive or envelope. If he would do this only with internet and do it properly there is no way FBI could trace him.

I recommend to use Heidi Eraser for non-destructive erase and DBAN for complete nuking of all accessible sectors on drive. Filling the drive from output of /dev/random/ is also acceptable. But never be sure about flash or SSD drives.
donator
Activity: 2772
Merit: 1019


they forgot to confiscate the cat. They money is in a cat-brain-wallet!
donator
Activity: 2772
Merit: 1019
He is either stupid or innocent.

Technically, he could be both.
hero member
Activity: 868
Merit: 1000
So a pile of clothes and a kee kat led the cops to this dude. Cat people be warned.
I highly doubt that cat alone led to KnightMB.

Nothing in the article suggests that it was the catte images alone which led them to Brown.  My understanding is that it can be difficult to completely erase data from flash drives - I'm guessing there were other fragments of data on there which were more specific and that's why he can't outright deny having ever possessed the flash drive.

legendary
Activity: 1022
Merit: 1000
legendary
Activity: 1512
Merit: 1049
Death to enemies!
If he was not caught then everyone will forget about this fake hack.
Pages:
Jump to: