Hacker News new | ask | show | jobs
by csande17 1352 days ago
Team Cymru (the company the article is about) has a response to the coverage: https://www.team-cymru.com/post/team-cymru-myth-vs-fact

In short, they claim that:

- The "PCAP" data, email addresses, etc that they sell comes from them running malware samples on their own infrastructure. It's not based on captured Internet data.

- The web page addresses etc that they sell are the results of automated vulnerability scans and honeypots, not captured Internet data.

- The netflow data they sell is captured from real ISP traffic, but it is a small sample (only 1 in 10,000 netflows is captured), and it can't identify individual websites if they use a CDN or shared hosting infrastructure (which most websites do).

I have no clue how true these claims are, but those are the claims.

1 comments

Wouldn't captured netflow data show which tor nodes users were connected to?
Only entry guards which isn't secret info. You will need to get very lucky to correlate that with relay traffic with the guard. Even with decent 1:10 sampling I would say it us only a little better than a random guess at best.