Chat Logs 2 and 3 (of hundreds) for TeamPatriot/TundraEatsYou

Tonight’s installment includes the celebration of knocking me off twitter. This is when Twitter’s TundraEatsYou, a lonely hardcore LARPer, gets together with the groypers and pepes.

Ironically, the two key people he’s talking to are journos. They have one beat: The alt-right on social media. Tundra includes them in the OP and then invites them into the larger and supposedly vetted chat room. So today was hectic. A virtual orgy of calls and emails. These brave folks had to get avatars changed fast, scrub posts, get clearance from their higher ups (as this is all technically property of someone else).

See last nights post here for background on Tundra aka “Louise Mensch’s dildo”

Lets move on shall we?

As usual the full res images will be on imgur

Thursday morning, 12/14, they realize Im knocked off twitter. It took a while. It likely took a  couple weeks since they started immediately after I posted the Blocktogether info via twitter and before I posted about it here on 11/29

Faux Celebration: You’ll notice the notepad document up as one of the journos was documenting this. Tundra seems awfully comfortable with these groypers and pepes. Is he jsut following orders or is this who he really is? Also, no vetting was needed to get them into the larger group for the more important Microchip ops. This will be important later.

scalped

So the chatroom is called “Jewp Die Pie”. I have no idea what that means. A distortion of Pew Die Pie is my only guess.

Image is zoomable opening in a new tab or directly here

And on Imgur here

Close up of them celebrating and summoning Tundra

scalpedchatblackedoutcroppedchatonly

“Crying on his blog” refers to the post I made immediately after getting suspended. I needed to have someone DM the group and I was hoping they remembered my blog.

But wait it gets worse…

See, building rapport is supposed to go in the direction of the “groypers” gaining Tundra’s trust. Well, in a perfect world thats how it should work. Here, Tundra is trying to build HIS rapport with them as if to signal “Im one of you”. Irony because they are undercover journos. You can facepalm yourself in a few seconds.

Tundra gets the alert and hops in to celebrate and build rapport in one swoop.

scalpedchat2blackedout

Oh, youre coming back are you?

Want a close up of that for posterity?

scalpedchat2blackedoutComingBack

Full size image available here

And on Imgur here

Tomorrow we will move onto Tundra coordinating the Micro ops with the larger group. And how they use their tactics against Resistance. Thats whats important. Oddly enough, it seems the group is very conscious of staying populist first. And of course their leader wants total control of everyone underneath her. But the division amongst Resistance was almost the effect of the inability to gain control. You’ll see. Even Tundra doesnt understand it fully. But that doesnt matter. He is just happy to be part of a group and is glad to take orders.

Note: After tonight youre not going to like what you see. The chat logs that I have span different social media platforms. They cover a lot of topics. A lot of it is irrelevant to our immediate concerns but are definitely very relevant to others.

Tomorrow I have to go through the process again. Back and forth with the journos and their editors, see what I can be allowed to use, etc. But Im ready to roll as soon as I get the green light. Sorry I made everyone wait since noon.

-DMS

Chat logs (1 of hundreds) for TundraEatsYou

Ready? We are gonna release them one at a time. First…

Lets establish something. “Tundra” has been on Gab since 2016. His cover is pretty simple. On the surface he appears to be enemies with the people he is actually cohorts with behind the scenes. There are countless journos that are anon on Gab. I know seven of them personally. 4 work for mainstream publications. Want to know how I knew my Twitter would be tango’ed ahead of time? Because I edit their work. They told me [sic] “Theyre going to come after you”. Now that Team Patriot has been caught lying every step of the way, lets put the final nail in this coffin.

gabTundraProfile

TundraEatsYou on Twitter and TundraGlobal on Gab.

https://gab.ai/TundraGlobal

http://archive.is/3NGFh

Here is one of the chats from November 27 when they decided to target me. I have blacked out some of the more offensive racial epithets. This is only 1 of hundreds of private chat logs I have from Tundra and other Team Patriot members across various platforms. Theyre crying about a warmup run on twitter of hashtag jacking? This one is from Novemeber. At this point Team Patriot had already logged many complaints against me. But none were valid. I did not receive a lockout nor was I shadow-banned. I like the “d. Kike Stewart”. Nice touch Tundra you fucking Neo Nazi douchebag. If bottom image isnt large enough use the imgur link to zoom it, here -> https://imgur.com/a/4cNbT

We also have server verification on these. When OD1NSH4MMER was ID’ed and geolocated he disappeared. Its ok. We obtained a real life ID on him. Recently arrested on unrelated charges. (we’ll touch on that later)

Tundrachatlogs2of637

Screengrab 2 of 637 (seriously)

Tundrachatlogs2cropped1

TundraChatLogs2Cropped2

Journo colleagues and friends (from various outlets including, The New Republic, Newsweek, The Atlantic, and more) have turned over nearly 700 chat logs between Team Patriot members and Alt-Right accounts running a mass ops across various social media platforms.

As I publish these I’ll explain how the network itself actually works (or barely works) to keep the connection away from TP. its a fairly simple disinfo tactic. Something out of the Hardy Boys. And all of us are starting to think that maybe, just maybe, McNeece saw this and wanted no part of it.

After all, Team Patriot zeroed in on me when I published an exploit that would help them the most by addressing it.

It looks like 11/26-11/27 is the earliest rallying to attack me. Oddly enough, this was prior to me addressing McNeece at all. This was strictly related to my Blocktogether post.

Think of it like this: They started trying to slander me anyway possible via twitter. That failed. Within a few days they are organizing their attacks to censor me through suspension and frat reporting. When Tundra says “we have cover”. Think of Mensch’s complaints of incoming attacks (when they are the ones doing the attacking) and the fact that they made 2 different fake Microchip accts. As seen below (note what Emma Peele says in first screengrab, she challenges Marla, correctly, and catches them in more bullshit). Every screenshot below has been proven to be a 100% lie by Louise Mensch, “Karol Cummins/Marla”, and others like the alternative-fetishist “Chief Covfefe” (Do you really want me publishing your browser history? Because thats coming. I promise.) I have way too many screenshots from Team Patriot where they are caught lying. They rob, steal, kill, blue-pill, repeat.

microchipphotoshoppedtweet

MMMMRussianOp

LuLwut

 

 

Finally!

 

That took much longer than expected 🙂

suspended2

Last post that got me nixed? Uncovering the obvious link…

It was all a sham. The same day they get a failed signature they also claim they “Got” his keybase. It never happened. The entire war was fake. It served its purpose. It divided the resistance further. I cant believe I didnt see this from the start.

microchipkeybase2

microchipkeybase

 

All of the accounts listed below in this fake war are still active with no problems. A war that never happened. I talked to Jeff Reifman tonight for the first time. And according to him, LM’s account was locked for doxxing him. Yet Microchip can unless leash whole armies on people and shes fine? And her entire crew? Highly unlikely…

allactive

 

And yet, everyone seemed to forget about BuzzFeed article

https://www.buzzfeed.com/josephbernstein/from-utah-with-love?utm_term=.ssLaP8p5ve#.kaPRwqaPpm

ThrowbackThursday – Stolen Libyan Missiles via SR

You know the deal. I reported in March 2011. MSM wouldnt report until Sept 2011. Here is my interview. Policy/Intel/News only. No politics.

 

Original posts can be found:

https://ameristroika.wordpress.com/2011/03/26/when-did-officials-know-al-qaeda-steals-libyans-missiles/

https://ameristroika.wordpress.com/2011/09/13/al-qaedas-new-missiles-courtesy-of-qaddafi-on-air-with-strictly-right-radio/

cc: https://20committee.com (so Mr. Provokatsiya can learn how to intel from the best) Cheers mate!

 

 

Recap: The BlockTogether Fiasco

To my fellow free-thinkers in and outside of The Resistance, I am going to recap the entire Blocktogether fiasco so that no key points are missed or in question. Since the release of the information much has happened. We have seen Blocklist managers go into all-out propaganda mode to protect their ability to censor. Twitter needing to take emergency measures to try and correct this issue. And most importantly, more of the message about censorship by 3rd party “sock-puppets” is being seen. This last part is arguably the most important. And the credit for spreading that message belongs to you.

In this first post we’ll take a look at the technical aspect of the problem. After that, we’ll move into the disinformation campaign being waged against us. Literally, nothing Louise Mensch has said is factual regarding this.

My goal was simply to protect the ones who were blocked. They were compromised as a direct result of Blocktogether. I had no intention of protecting the censors and abusers. Luckily, they would rather dig their heels in and continue using a flawed system even if it means they must suffer severe real-world consequences. And ironically, it turns out that the people that would’ve been helped the most are the list managers. But never fear, they will risk it all to hold onto the high that comes with having power over people.

Lets take a look at what happened, why it happened, and what it means as the problem currently stands. Here is the problem:

  1. Twitter has problems with its OAuth. Always has
  2. Blocktogether is a 3rd party application that users give read/read-write + DM access (thanks @1weesel)
  3. This endangers the subscribers, as well as the block list administrators

 

BTreadWrite2

Courtesy of @1weesel via twitter

The Genesis

Let us deal with Twitter and their OAuth problems first and cite a few examples. I will keep it in layman’s terms so even I can understand it. This stuff was always explained to me by very patient people; more patient than I could ever be.

For a long time now people have been using Twitter’s OAuthorization to gain control of accounts or to fool other users into giving up control of their accounts. Just for the record we will take a look at a few examples from a site that rewards devs for finding and fixing bugs along with a tutorial for account takeover:

[Critical] Steal OAuth Tokens

https://hackerone.com/reports/131202

Real-world application of above bug

https://www.geekboy.ninja/blog/turning-simple-login-csrf-to-account-takeover/

Keep in mind. This was active up until a few weeks ago. One of many OAuth bugs and security issues on Twitter’s side. The same technique is applicable to both Twitter and Facebook.

But here is where it starts to get interesting and the details matter…I hope I’m not boring everyone.

This “bug” on Twitter’s side can be used (with slight modification) to access an account using a Blocktogether list. This can be both as a subscriber or list manager. It does not matter. It creatively uses two routers to spoof credentials. Since Twitter will take temporary, or even outdated security certificates, this helps them gain the foothold and account takeover

https://hackerone.com/reports/168538

And a video of the demonstration. Important to note this is not me in the video:

 

The most recent tactic of gaining access to an account worked almost identical from what I can deduce. The attacker can spoof a security certificate or use an expired one and the job is complete. The creator of Blocktogether had already acknowledged using outdated security certificates. Even temporary certificates that were used in the beginning are still allowed and validated.

The Blocklists

The three blocklists that I published were

  1. Given to me by an operator who was using the lists, taking names at random, and demonstrating getting a foothold/access to the account
  2. None were ChiefCovfefe/Mensch/TeamPatriot blocklist
  3. None were altered in any way. I received them that way

Over the course of three days and ending on 11/21 I published 3 block lists. These were users affected by, or determined to be compromised by an attacker. This was a delicate agreement between myself and the operator. So delicate that I agreed to only “show it to select group of people in 24hr period”. That “select” group was the twitter community. So I published the lists with a 24hr expiration. Why? Simple.

  1. These are compromised accounts. The longer the info stays up the more danger they are in. Attackers will see the lists before the users. Keeping them up indefinitely can only multiply the harm
  2. When the lists “vanished” the liars could start their campaign. I claimed I had no access to them after the 24 hr time period. Are Team Patriot willing to bet on that info and risk it all? What if I still have them? Their claims fall to pieces. And I do have them (game over)

The operator was furious and I burned a bridge. So what? Many were saved. More are demanding change. And as long as the censors think the lists disappeared they felt free to lie about them. It worked perfectly.

Why Mensch Crew had to get defensive

We will address this in detail next time. As a primer, most of details of this attack were realized when this bug was found only because certain users seemed to be structuring tools to operate to take advantage of this flaw. It set off a red flag. Running those user ID’s we can see that the CounterChekist account and the ChiefCovfefe account were two that had created tools within the Twitter Dev options to use this exploit. I posted the raw data the operator showed me when he encountered researching this. I have redacted everything but the user ID which I believe to be CounterChekist. I should say that I do not believe he has the skills to create such tools. So this is likely the result of an attacker.

https://pastebin.com/dxm0JDdy

It is important to note that the chances that this was done by an outside operator vs the account owner is 50/50. And since the Big Chief runs the largest censorship tool he would obviously make himself a prime target. Ditto on CC. And if an attacker did anything illegal or broke a ToS then the responsibility would fall on the account owners, not the attacker.

Exposing this protects the Big Chief; which was not my intention at all but it is rather an unintended consequence. So why then is he – and also the entire crew – smearing people and fabricating evidence to keep this flaw in place? I can only deduce that he was the one creating the tool/script to access the nearly one million accounts on his list. An innocent person’s response wouldve been to shut it down and thank the messenger. Instead, they have taken a scorched earth approach to to keep this in place.

Meanwhile, people start seeing mass unsubscribing…

lolunblock

Twitter DMs Go Down. As Expected (11/21)

Another topic we will touch on more in the next post. But immediately after this was revealed Twitter needed to deploy a patch. Within hours on 11/21 (the same day I revealed the compromise) Temporary fixes were made. It was massive enough to require DM’s being taken off line. Since things like Blocktogether can give an attacker a foothold into DMs of accounts they dont own, new code needed to be written in. Unfortunately, OAuth flaws are so deep that it does not help. Twitter was able to minimize the impact by doing this in blocks of users. So DMs were not offline for everyone all at the same time. Matter of fact, it was likely only caught because some users were using it during what was normally their “off-peak” usage.

This link cites a few examples of users who witnessed it.

http://animeright.news/zanting/twitter-direct-messaging-dm-service-goes-down-during-outage/

 

Thank You, So Far, and Moving Forward

I mean that sincerely. And if you missed it in the mish-mash of Twitter replies, I believe in having no enemies. Having opponents is different. As a whacky Libertarian I tend to think everyone is nuts except me (which is likely pretty accurate according to my latest internal polling data).

In our digital age we tend to forget that there are real people behind avatars. And since most of the topics that help us clash are inseparable from from our emotions, the impersonal layer of “words on a screen” do not help us feel like we are talking among people but rather talking at avatars.

You have all demonstrated that you have the ability to talk with one another, not at them. And that warms my heart.

My biggest concern is that I do not want to lose people in the course of this explanation or confuse anyone. So I implore you to speak up and ask me anything at any time. I am even willing to do any sort of group chat if everyone wants to get into a single spot and address any issues. Discord and Google Hangouts come to mind. I have a decent mic and anyone, including Karol, Chief, or Lousie are welcome too. If this is something you guys would like to do, let me know.

Sincerely,

Douglas Stewart

PS: The post right after this one debunks the entire “Las Vegas Shooter was an Anti-Trump Antifa” with previously unseen photos. Notice no one on the right cared. I received only thanks from Resist folks. Keep these things in mind when the goons start trying to smear me as partisan or an ideologue. Cheers!