US U.S. ‘No Fly List’ Leaks After Being Left in an Unsecured Airline Server - The list, which was discovered by a Swiss hacker, contains names and birth dates and over 1 million entries.

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.

1674308368663.png


A copy of the U.S. No Fly List has leaked after being stored on an unsecure server connected to a commercial airline. The No Fly List is an official list maintained by the U.S. government of people it has banned from traveling in or out of the United States on commercial flights.

As first reported by The Daily Dot, a Swiss hacker known as maia arson crimew discovered the list on an unsecured Jenkins server one night while poking around on Shodan, a search engine that lets people look through servers connected to the internet.

“Like so many other of my hacks this story starts with me being bored and browsing shodan (or well, technically zoomeye, Chinese shodan), looking for exposed jenkins servers that may contain some interesting goods,” crimew said in a blog about the leak. “At this point I've probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words. ‘ACARS,’ lots of mentions of ‘crew’ and so on. Lots of words I've heard before, most likely while binge watching Mentour Pilot YouTube videos. Jackpot. An exposed jenkins server belonging to CommuteAir.”

On the server was a large amount of company data about CommuteAir, including the private information about its employees. There was also a file containing a copy of a 2019 edition of the No Fly List. The list includes names and birth dates and more than 1.5 million entries, but many of those entries are aliases that all reference the same person.“It’s so much bigger than I thought it’d be,” crimew told Motherboard.

“TSA is aware of a potential cybersecurity incident, and we are investigating in coordination with our federal partners,” a spokesperson for the TSA told Motherboard.

The United States has maintained a No Fly List for decades, but its number was much smaller in the days before 9/11 and only contained 16 people. After the attacks and the creation of the Department of Homeland Security, the list rapidly expanded. The exact number of people on the list is unknown, and the leaked data is a few years old and contains multiple entries for a single individual, but recent estimates put the total number at somewhere between 47,000 and 81,000 people.

“It’s a perverse outgrowth of the U.S. police and surveillance state,” crimew said. “Just a list with no due process…mostly just based on them being related to someone or being from the same village as someone. It’s so massive. I feel like this has no place anywhere. I feel like this doesn’t solve the problem.”

crimew told Motherboard they weren’t shocked to stumble on an unsecured copy of the No Fly List. “I’ve been digging into various jenkins [servers] for a while and there’s just so much to find,” they said. “It was just a matter of time until I found something like this.”

CommuteAir said the leak happened because of a misconfigured development server. “The researcher accessed files including an outdated 2019 version of the federal no-fly list that included first and last name and date of birth,” it said. “Additionally, through information found on the server the researcher discovered access to a database containing personal identifiable information of CommuteAir employees. Based on our initial investigation, no customer data was exposed. CommuteAir immediately took the affected server offline and started an investigation to determine the extent of data access. CommuteAir has reported the data exposure to the Cybersecurity and Infrastructure Security Agency, and also notified its employees.”



Check the blogpost, it's actually quite amusing.

 
I know this isn't a lolcow thread but I couldn't help myself and did bit of digging on this person. For a 1337 tranny hacker, this guy seems to have quite a wide (though in most cases not very deep) internet footprint. I'm not gonna bother archiving most of these since there are so many and most of them don't contain anything all that interesting. He seems to have 3 main usernames he uses: deletescape, antiproprietary, and nyancrimew, though cybertillie is one I've also seen. Nyancrimew is the newest and most current username.

Wikipedia Article - https://en.wikipedia.org/wiki/Maia_arson_crimew

Current accounts that are actively used:
Personal website - https://maia.crimew.gay/
https://old.reddit.com/user/nyancrimew
https://ko-fi.com/nyancrimew
https://www.twitch.tv/nyancrimew/
https://www.instagram.com/nyancrimew/
Fediverse - https://crimew.gay/maia
https://www.youtube.com/@nyancrimew
https://soundcloud.com/nyancrimew
https://www.last.fm/user/nyancrimew
https://github.com/nyancrimew
https://git.lavender.software/nyancrimew
https://twitter.com/_nyancrimew
https://t.me/nyancrimew
https://bandcamp.com/nyancrimew
https://steamcommunity.com/id/deletescape

Less active, older, or less interesting accounts:
Old personal website - https://deletescape.ch/
Old telegram - https://t.me/deletescape
https://myanimelist.net/profile/deletescape
https://www.twitch.tv/antiproprietary
https://www.paypal.com/paypalme/deletescape
https://open.spotify.com/user/deletescape
https://open.spotify.com/artist/1YvQJvcjD7rqgLJ18yLxGO
https://www.tiktok.com/@nyancrimew
https://en.gravatar.com/deletescape
https://slides.com/deletescape
https://revolut.me/deletescape
https://www.producthunt.com/@deletescape
https://www.kaggle.com/deletescape
https://keybase.io/deletescape
https://hackerone.com/deletescape?type=user
https://www.hackerrank.com/profile/deletescape
https://www.duolingo.com/profile/deletescape
https://dev.to/deletescape
https://crowdin.com/profile/deletescape
https://gitlab.com/antiproprietary
https://devrant.com/users/deletescape
https://itch.io/profile/nyancrimew
https://www.deviantart.com/deletescape
https://www.flickr.com/people/deletescape/
https://flipboard.com/@Deletescape
https://deletescape.gumroad.com/
https://imgur.com/user/deletescape
https://www.pinterest.com/deletescape/
https://codepen.io/deletescape
https://news.ycombinator.com/user?id=deletescape
https://www.patreon.com/deletescape/creators
https://disqus.com/by/deletescape/
https://github.com/deletescape
https://medium.com/@deletescape

Known emails:
nofly@crimew.gay
me@deletescape.ch

A few interesting things can be found, like confirmation that he has autism. (which was pretty obvious but still)
View attachment 4315458View attachment 4315352

And to absolutely nobody's surprise he is also into anime.
View attachment 4315481

I also found more photos of him. Very feminine.

Even found some pre-transition photos. Notice how he looks happier and less ugly.

There was a slightly unhinged video on his TikTok account of him burning a Google Home Mini, but unfortunately it got deleted before I could download it.
View attachment 4315884

But I did at least save the video of him throwing it on the ground like an autist. So there's that.
View attachment 4315885
I'm not a gay but the dude wasn't fat or ugly like most faggot MtF trannies who took the incel pipeline. I'm still really amazed how autists are so perceptible to trooning out.
 
I assume that when they say "i will only give this data to parties that i believe will do the right thing with it" it means that they won't give it to anyone who would expose political biases in it. So far one article only talked about how it targets "poor innocent muslims and arabs" or some gay shit. I really want access to the list so I can analyze it.
 
Given how shitty everything is, I'm getting the feeling the feds will get to him before he leaks it to anyone who would make it public.
He is indicted by The U.S. for his previous hacks and if he ever steps foot in USA (he's from Switzerland), he can get arrested and be in prison for 20 years lol.
Sorry for double posting.
 
Also it's pretty fucking gay of him to only release this list to journos instead of just dumping it publicly.
Here's him giving the list to journos in a completely unbiased way
100% stunning and brave right there. Slay queen.

I know this isn't a lolcow thread but I couldn't help myself and did bit of digging on this person. For a 1337 tranny hacker, this guy seems to have quite a wide (though in most cases not very deep) internet footprint. I'm not gonna bother archiving most of these since there are so many and most of them don't contain anything all that interesting. He seems to have 3 main usernames he uses: deletescape, antiproprietary, and nyancrimew, though cybertillie is one I've also seen. Nyancrimew is the newest and most current username.
Im going to add a DOB into this pile of info since the guy's opsec is as retarded as his workstation setup

Maybe if my autism mana is high enough I will try to locate where he lives later today
 
Here's him giving the list to journos in a completely unbiased way
!00% unbiased right there. Slay queen.


Im going to add a DOB into this pile of info since the guy's opsec is as retarded as his workstation setup

Maybe if my autism mana is high enough I will try to locate where he lives later today
That shit is why I'm extremely skeptical of his claims. At this point I doubt he has anything and is instead doing this all for attention.
 
Given how shitty everything is, I'm getting the feeling the feds will get to him before he leaks it to anyone who would make it public.
I won't be suprised. I was just watching 2 videos on YouTube, one about Julian Assange and the other about osama bin laden. Because this is just a big leak and compromise to US secrets, I won't be suprised that the US will be willing to break international law to arrest them. They are stuck in Switzerland apprently but I have nothing to source that.
 
I won't be suprised. I was just watching 2 videos on YouTube, one about Julian Assange and the other about osama bin laden. Because this is just a big leak and compromise to US secrets, I won't be suprised that the US will be willing to break international law to arrest them. They are stuck in Switzerland apprently but I have nothing to source that.
Nah, it's just the no fly list, if he even has it. This isn't tens of thousands of diplomatic cables. At most they'll just throw more charges at him if he ever tries to leave Switzerland.
 
I did a bit of searching and found an article about his "hacktivism" which boils down to ADHD-fueled clicking on shodan, trying default passwords and then posting the unsecured shit he finds on his blog. I think when Lucerne polizei busted his flat in the morning that day, it made him think he is some super hacker villain trying to save the world from the evil government like the Washington DoT.
March 2021
In several cases, prosecutors said Kottmann improperly used valid employee credentials to gain access to source code databases. The indictment says Kottmann also hacked the Washington state Department of Transportation, an automobile manufacturer and a financial investment company.
Kottmann, who uses they/them pronouns, told The Associated Press last week they belonged to a group nicknamed APT-69420 Arson Cats, a small collective of "primarily queer hackers, not backed by any nations or capital but instead backed by the desire for fun, being gay and a better world."

I've put the indictment from US Attorney's Office Western District of Washington in the attachments

Before trooning out he made a sticker pack for Telegram

There was a slightly unhinged video on his TikTok account of him burning a Google Home Mini, but unfortunately it got deleted before I could download it.
He also (re)posted it on twitter later. Here: https://twitter.com/_nyancrimew/status/1579029045638930432


I have to point out how close he leaves the lighter fluid bottle, if there was a small path of drops from the squeezed stream, the bottle would light up like a bonfire, melt and leak burning fluid all over his balcony. Flammable liquids are dangerous as fuck.

And speaking of balconies, and dangerous things, I think I found where he lives / lived at some point (I know he switched flats early in 2022 because the mirror selfies have a different background). There is only a few photos on his twitter taken outside, and they were all taken in pretty much the same place (within 100 feet). If you want to be the worlds no. 1 cybervillain, you really need to pump up your opsec game.
FmLWt_eWAAItF24.jpgFnKnVG_XkAAaffH.jpgFVJHMhbXsAExIjG.jpg
What let me narrow down is his Wikipedia page which pointed me to Buch district in Lucerne.
The first pic gives a partial name of a bakery that is on the corner of Kloseterstrasse and Hirchengraben
The second pic, zoomed in, shows a "Gameorama" sign which is a board game museum, right next to the bakery.
The third pic is from a tweet where Maia complains to Lucerne Polizei that the cops parked on the space for more than 10 minutes. I had to link it because the context here is hilarious. This pic is how I found out where the address down to a floor.
house.PNG
This is a street view pic of two houses five blocks away from the bakery. Look at it for a while and guess how I found that this where Maia lives.
Look at the shadow in the police car photo and at the balcony railings

This is it. The OPSEC hat-trick. Now I can die in peace.

Somewhere on the second floor,
7 or 9 Kloseterstrasse, Lucern, Switzerland

Bonus content, ugly tits
 

Attachments

Back