US U.S. ‘No Fly List’ Leaks After Being Left in an Unsecured Airline Server - The list, which was discovered by a Swiss hacker, contains names and birth dates and over 1 million entries.

  • 🐕 I am attempting to get the site runnning as fast as possible. If you are experiencing slow page load times, please report it.

1674308368663.png


A copy of the U.S. No Fly List has leaked after being stored on an unsecure server connected to a commercial airline. The No Fly List is an official list maintained by the U.S. government of people it has banned from traveling in or out of the United States on commercial flights.

As first reported by The Daily Dot, a Swiss hacker known as maia arson crimew discovered the list on an unsecured Jenkins server one night while poking around on Shodan, a search engine that lets people look through servers connected to the internet.

“Like so many other of my hacks this story starts with me being bored and browsing shodan (or well, technically zoomeye, Chinese shodan), looking for exposed jenkins servers that may contain some interesting goods,” crimew said in a blog about the leak. “At this point I've probably clicked through about 20 boring exposed servers with very little of any interest, when I suddenly start seeing some familiar words. ‘ACARS,’ lots of mentions of ‘crew’ and so on. Lots of words I've heard before, most likely while binge watching Mentour Pilot YouTube videos. Jackpot. An exposed jenkins server belonging to CommuteAir.”

On the server was a large amount of company data about CommuteAir, including the private information about its employees. There was also a file containing a copy of a 2019 edition of the No Fly List. The list includes names and birth dates and more than 1.5 million entries, but many of those entries are aliases that all reference the same person.“It’s so much bigger than I thought it’d be,” crimew told Motherboard.

“TSA is aware of a potential cybersecurity incident, and we are investigating in coordination with our federal partners,” a spokesperson for the TSA told Motherboard.

The United States has maintained a No Fly List for decades, but its number was much smaller in the days before 9/11 and only contained 16 people. After the attacks and the creation of the Department of Homeland Security, the list rapidly expanded. The exact number of people on the list is unknown, and the leaked data is a few years old and contains multiple entries for a single individual, but recent estimates put the total number at somewhere between 47,000 and 81,000 people.

“It’s a perverse outgrowth of the U.S. police and surveillance state,” crimew said. “Just a list with no due process…mostly just based on them being related to someone or being from the same village as someone. It’s so massive. I feel like this has no place anywhere. I feel like this doesn’t solve the problem.”

crimew told Motherboard they weren’t shocked to stumble on an unsecured copy of the No Fly List. “I’ve been digging into various jenkins [servers] for a while and there’s just so much to find,” they said. “It was just a matter of time until I found something like this.”

CommuteAir said the leak happened because of a misconfigured development server. “The researcher accessed files including an outdated 2019 version of the federal no-fly list that included first and last name and date of birth,” it said. “Additionally, through information found on the server the researcher discovered access to a database containing personal identifiable information of CommuteAir employees. Based on our initial investigation, no customer data was exposed. CommuteAir immediately took the affected server offline and started an investigation to determine the extent of data access. CommuteAir has reported the data exposure to the Cybersecurity and Infrastructure Security Agency, and also notified its employees.”



Check the blogpost, it's actually quite amusing.

 
This is not a suggestion for anyone on Kiwi Farms to follow, but I am suprised that no one has approached this hacker pretending to be some liberal news agency to see if they actually have the goods or not.
 
I know this isn't a lolcow thread but I couldn't help myself and did bit of digging on this person. For a 1337 tranny hacker, this guy seems to have quite a wide (though in most cases not very deep) internet footprint. I'm not gonna bother archiving most of these since there are so many and most of them don't contain anything all that interesting. He seems to have 3 main usernames he uses: deletescape, antiproprietary, and nyancrimew, though cybertillie is one I've also seen. Nyancrimew is the newest and most current username.

Wikipedia Article - https://en.wikipedia.org/wiki/Maia_arson_crimew

Current accounts that are actively used:
Personal website - https://maia.crimew.gay/
https://old.reddit.com/user/nyancrimew
https://ko-fi.com/nyancrimew
https://www.twitch.tv/nyancrimew/
https://www.instagram.com/nyancrimew/
Fediverse - https://crimew.gay/maia
https://www.youtube.com/@nyancrimew
https://soundcloud.com/nyancrimew
https://www.last.fm/user/nyancrimew
https://github.com/nyancrimew
https://git.lavender.software/nyancrimew
https://twitter.com/_nyancrimew
https://t.me/nyancrimew
https://bandcamp.com/nyancrimew
https://steamcommunity.com/id/deletescape

Less active, older, or less interesting accounts:
Old personal website - https://deletescape.ch/
Old telegram - https://t.me/deletescape
https://myanimelist.net/profile/deletescape
https://www.twitch.tv/antiproprietary
https://www.paypal.com/paypalme/deletescape
https://open.spotify.com/user/deletescape
https://open.spotify.com/artist/1YvQJvcjD7rqgLJ18yLxGO
https://www.tiktok.com/@nyancrimew
https://en.gravatar.com/deletescape
https://slides.com/deletescape
https://revolut.me/deletescape
https://www.producthunt.com/@deletescape
https://www.kaggle.com/deletescape
https://keybase.io/deletescape
https://hackerone.com/deletescape?type=user
https://www.hackerrank.com/profile/deletescape
https://www.duolingo.com/profile/deletescape
https://dev.to/deletescape
https://crowdin.com/profile/deletescape
https://gitlab.com/antiproprietary
https://devrant.com/users/deletescape
https://itch.io/profile/nyancrimew
https://www.deviantart.com/deletescape
https://www.flickr.com/people/deletescape/
https://flipboard.com/@Deletescape
https://deletescape.gumroad.com/
https://imgur.com/user/deletescape
https://www.pinterest.com/deletescape/
https://codepen.io/deletescape
https://news.ycombinator.com/user?id=deletescape
https://www.patreon.com/deletescape/creators
https://disqus.com/by/deletescape/
https://github.com/deletescape
https://medium.com/@deletescape

Known emails:
nofly@crimew.gay
me@deletescape.ch

A few interesting things can be found, like confirmation that he has autism. (which was pretty obvious but still)
View attachment 4315458View attachment 4315352

And to absolutely nobody's surprise he is also into anime.
View attachment 4315481

I also found more photos of him. Very feminine.

Even found some pre-transition photos. Notice how he looks happier and less ugly.

There was a slightly unhinged video on his TikTok account of him burning a Google Home Mini, but unfortunately it got deleted before I could download it.
View attachment 4315884

But I did at least save the video of him throwing it on the ground like an autist. So there's that.
View attachment 4315885
My guy went from a lovable geek to a hideous freak. (:_(

He seemed like he'd make a great friend to be with if he didn't fall for the tranny menace and seeked some good self-esteem training.
 
This is not a suggestion for anyone on Kiwi Farms to follow, but I am suprised that no one has approached this hacker pretending to be some liberal news agency to see if they actually have the goods or not.
He's probably only taking requests from people already in the troon network.
 
1674770693829.png

uwuspeak should be considered a violation of the Geneva convention. Doubly so if it's a fat male tranny behind the screen doing it.

Standalone left panel, because I think it's funny:
1674770049407.png
Do it, I want to see it but I'm not deep enough in the twitter troon circles
He tweeted this stupid shit:
1674769872172.png
Tons of twitter lesbos got mad at him for calling himself a "bi lesbian" so he deleted the tweet and started melting down.
1674769937560.png

1674770152671.png
1674770450579.png

1674770238455.png

1674770809649.png

There's a lot more including thinly veiled "Kill yourself" messages and death threats, but I can't be arsed to fish for them again at the moment, it would be too harmful to my health.
There was also tranny cope and seethe in defense of Tillie Kottmann ("maia") which was pretty funny, might edit this post to add it.
1674769695199.png1674769835051.png

1674769988472.png
It's the typical obnoxious LGBT twitter game of playing Pokemon (Gotta Catch Em All!) with labels no normal person gives a fuck about and getting mad over people calling out how absurd neo-identities are.
 
Hey lads, I found the list in the new ebin fork of raidforums. Honestly, it's a whole load of nothing.
Yeah, thats obviously been pruned to only names and DOB.
Still nice to look at. Someone should do the dedup on the entries and host it somewhere searchable, but it'll probably get some heat for the glowies.
 
Josh could still be on the selectee list. That's the one where the government will harass and grope you every time you fly, maybe to the point you miss your flight, but they won't outright tell you you're not getting on the plane.
They're both in the file provided and he's not on either one.
For some reason there's an eleven-year-old selectee though. Poor kid.
 
Hey lads, I found the list in the new ebin fork of raidforums. Honestly, it's a whole load of nothing.
so it got castrated and all the good info is gone? awesome..... there goes my plans to analyze it for political biases. of course some tranny faggot would find this and only make it accessible by "trusted" sources.... useless garbage fucking troons
 
His real name is Till Kottmann.

Here's the docket of his case complete with documents:
Lmao the complaint uses the correct male pronouns.

Hope the dipshit tranny has the info on a deadman switch of some sort.
He already has a thread here from April 2021 when the Swiss police raided his apartment and confiscated his stuff; If I remember correctly it was requested by the FBI and Swiss police handed over his stuff to them:
1675691579064.png1675691499684.png1675691331629.png
He also used to work with Kirtaner who also has his own thread:
 
Back