How did you find out they were involved in that?
With regards to LFJ, LFJ was openly collaborating with a German hacker called Kevin Karhan who repeatedly openly indicated his willingness to break the law just to target KF. He posted many many unhinged threats against KF and Kiwis, threatening that he take care of them himself so he wouldn't have to get LE involved. Together with Kevin Karhan, LFJ started the GreyHat Academy on Github, a reference to grey hat hackers who operate on the boundaries of illegality. On the GreyHat Academy's github account, Kevin and LFJ uploaded and maintained so-called
DROP lists, but these DROP lists were really meant to be
"dual use weapons", that were intended to be used as DDoS lists by the hackers targeting KF. They effectively concealed the cybercriminal intent behind the creation of these lists by misrepresenting them as DROP lists.
Here is Kevin Karhan himself posting on Twitter about the GreyHat academy lists, while openly tweeting out a blackmail threat to Cloudflare that he would add them to these DROP lists within 48 hours if they refused to stop protecting KF:
"Fair Warning: @cloudflare - or every other hoster providing services to #KiwiFarms - will be added after a max. 48 hour grace period if they don't #DropKiwifarms...", "I hope @Cloudflare , @fiberhub & @VSYShost consider this the last warning shots..."
https://archive.ph/P8Vn2
Liz Fong Jones posted many many tweets at the time, such the following, where he made it clear that he had closely studied KF's architecture and had termined which specific kind of DDoS attack would be the most effective way to target the website ("L3" and "L7" in this tweet refers to Layer 3 and Layer 7 DDoS attacks, these are two different types of DDoS attacks that LFJ had considered would be the most effective against KF):
While LFJ and Kevin Karhan were posting their "dual use weapons" onto Github, hackers on Twitter were openly bragging about targeting KF with DDoS attacks:
There was widespread speculation at the time on Twitter that the reason Liz Fong Jones campaigned Cloudflare (KF's anti-DDoS protection ISP) to drop KiwiFarms was because he knew that the moment KF lost their anti-DDoS protection, they would be attacked by hackers and DDoSers. There were countless of tweets at the time speculating that LFJ was essentially aiding and abetting anticipated cybercrimes against KF by targeting Cloudflare and making sure KF had to protection. LFJ and Alejandra Caraballo, throughout the summer of 2022, were doing public interviews and podcasts where they openly bragged about the denial of protection being a great way to target websites like KF. An example of such media coverage at the time:
A Technical Guide to Burning Down a Troll Farm - The New Stack
https://thenewstack.io/a-technical-guide-to-burning-down-a-troll-farm/ Archived:
https://archive.is/ghF0l
Here are some examples of these tweets from others that I saw at the time:
On top of this, there was Ellen Murray, Keffals' Irish partner, who had posted detailed technical information about the DDoS attacks being carried out, information he could've only garnered if he was in touch with the hackers carrying out the DDoS attacks. Whenever there was a DDoS attack, Ellen and Keffals would go into a secret Signal channel where apparently they would discuss the details of these DDoS attacks:
"It's less than a thousand requests a second"... how did Ellen know this specific number, unless he was personally involved with those DDoS attacks, or knew the people who were carrying them out and they were the ones who gave him that number?
Here's Ellen Murray again, referring to
"very small scale DDoS attempts"... again, how did he know they were "very small scale", unless he was personally involved or was in touch with the people doing them?
Again, all this evidence is circumstantial, speculative and hearsay, but for me personally it's sufficient to conclude that there was a 99.99% chance that Liz Fong Jones and the rest of #DropKiwiFarms, including Keffals and Murray, were directly in touch with the hackers carrying out the DDoS attacks, if they weren't personally involved with those DDoS attacks themselves (especially Murray given his public technical knowledge of the specifics of those attacks). Liz Fong Jones condoned this activity for weeks, bragging the onslaught of cybercrime he had allowed to commence against KF by taking Cloudflare out of the way. Liz Fong Jones also kept on posting various technical details about Null's software, hardware, IP addresses and ISPs, seemingly to aid and abet the cybercrimes being committed against the website. Liz Fong-Jones admitted that he had collected this information about Null's systems by obsessively port-scanning KF's IP addresses (non-consensual port-scanning is something that many ISPs around the world consider to be malicious activity in and of itself). In anything, LFJ knew that by making this technical information public on his Twitter account it would aid and abet the hackers, who had already admitted they were targeting the site, with their attacks.
But Null is not going to sue Caraballo and LFJ over any of this actually cybercriminal shit. He's gonna sue them over some bullshit xeets and for sending e-mails to ISPs, both of which are protected activity in California under anti-SLAPP. He thinks he will totally win this.