THE ANTISECURITY MOVEMENT

The oldest grudge in hacking, distilled to a slogan: own the whitehats. For fifteen years a loose lineage of crews — ADM, ~el8, the Phrack High Council, blackhatbloc, h0no, and finally 2011's Operation AntiSec — argued that the security industry manufactures fear, sells the cure, and feeds the people who post exploits into a Federal police state. It was a real critique of a real revolving door. It was also, in practice, a campaign of doxing, harassment, and in its ugliest moments printed fantasies of murdering named engineers. The argument had a point. The method owned a lot of people who mostly ran badly-secured websites.

We're a movement dedicated to the eradication of full-disclosure. … If you own a security blog, an exploit publication website or you distribute any exploits — you are a target and you will be rm'd. Only a matter of time.

The Anti-sec Movement, 2009 — the message left on every ImageShack image after the crew replaced them all with a single defacement

WHO
An ideology and a lineage, not a person: ADM → ~el8 → the Phrack High Council ("pr0jekt MAYHeM") → blackhatbloc / h0no → the 2009 Anti-sec crew → 2011 Operation AntiSec FACT
SCENE
Born in the exploit-disclosure wars of the late 1990s; overlaps cDc, w00w00, TESO, and the crews of Crew Rivalries. The archetypal target was L0pht / @Stake; the exploit-disclosure fight itself is the Disclosure Wars
THE THESIS
Full-disclosure is a business model. Whitehats who publish exploits get rich selling fear — and, the movement argued, hand the state the tools and the funding to jail hackers. Sellout = Fed enabler
THE METHOD
Own the whitehats, dump their mail, publish "know your enemy" dossiers, and — per its own zines — "murder the security industry." Real intrusions, real harassment, against named people
STATUS
RECURRING — the crews die, the slogan doesn't. Its 2011 revival, Operation AntiSec, was partly steered from inside by an FBI informant

This file is not a verdict on full-disclosure, which is a genuine and unsettled argument. It is a record of what the antisecurity movement actually said — in its own zines, at full volume — and what it actually did, which ranged from a sharp critique of the security industry's fear-marketing to the doxing of a sixteen-year-old and printed fantasies of killing engineers by name. The through-line is the gap between the thesis, which had a target worth hitting, and the tactics, which mostly hit whoever left a port open.

the drama timeline

ACT I — ADM AND THE FIRST ANTI-SEC (1998–2001)

A French crew called the Criminals' Association decides that posting exploits is helping the enemy, and builds a forum to say so.

  1. 1990s

    ADM — the Criminals' Association

    By Phrack's own history, one of the most influential international groups of the 90s was ADMAssociation De Malfaiteurs, "Criminals Association." That crew, "under additional influences, gave a new life to the antisecurity movement in the early 2000, by creating public web forums to justify the non-disclosure of exploit software." The forum was anti.security.is.

  2. 1998–

    ~el8: "FUCKN UP WHITEHATS SINCE 1998"

    A zine called ~el8 gives the movement its voice and its house style: banner art reading "FUCKN UP WHITEHATS SINCE 1998," a recurring column called "Know Your WhiteHat Enemy," and a sign-off that became a slogan — "NO MERCY FOR WHITEHATS." The life of a whitehat, one issue sneered, could be "summed up in: m0nEy-Ca$h-lameness."

ACT II — pr0jekt MAYHeM (2002)

The Phrack High Council turns the argument into an operation: name the sellouts, own their boxes, and dump the proof.

  1. 2002

    The Phrack High Council and its "missions"

    A crew operating as the Phrack High Council (PHC) runs a numbered campaign it calls pr0jekt MAYHeM — a mission list that includes "The Whitehat Briefings," a "war on public key infrastructure," and an order to "establish cells on different networks." The bit was that the security scene's own heroes were the mark.

  2. JUL 2002

    The K2 feud — blackhat until he got owned

    ~el8 profiles K2 — a member of ADM and w00w00, and an employee of the security firm CORE-ST — as the model "whitehat enemy." When K2 allegedly circulated a mass email ("narcing," in the scene's word) naming the people he suspected of owning him, a #phrack op writing as nwonknu published a rebuttal: "ADM sponsored the antisecurity movement, and K2 is a member of ADM." K2's side: he says he was slandered, and that the people he named were engaged in real criminal hacking. Both positions are on the record; neither is adopted here.

  3. JUL 2002

    Gweeds at H2K2: "the Federal police state"

    At the H2K2 conference, Gweeds gives the thesis its manifesto — "Black Hat Bloc, or How I Stopped Worrying About Corporations and Learned to Love the Hacker Class War." His charge, as reported by The Register: L0pht testified to Congress, the state got more cyber-defense funding, L0pht (now @Stake) got contracts, and so the security industry is "increasing the reach of the Federal police state at the expense of fellow hackers who are being caught and put in jail." ATTRIBUTED The claim that @Stake lived off federal contracts was never substantiated — see both sides.

  4. 2002

    "Murder the security industry"

    Where the argument curdled: a blackhatbloc zine piece — a rap under the byline "BLACKHAT LIKE ME" — ran the refrain "murder the security industry, we gotta take back the net," then spent forty lines fantasizing, in print, about killing named security professionals. It is rhetoric, not a plan; it is also the moment the movement stopped being a disclosure argument and became a threat directory.

ACT III — THE HOLOCAUST RHETORIC, AND PHRACK BACKS AWAY (2002–2007)

A follow-on zine escalates the language past any defense of it — and Phrack's own new staff publicly declines to sign on.

  1. 2002–04

    h0no: "wh1t3h4t h0l0c4ust"

    The h0no zine pushes the rhetoric to its worst: a cover reading "Pr3p4r3 4 a wh1t3h4t h0l0c4ust" and "MERRY XMAS SEC INDUSTRY." This is the register the movement's critics point to — the point at which "stop selling fear" became a genocide joke aimed at people whose job was patching bugs.

  2. 2007

    Phrack's own staff distances itself

    When Phrack is revived by The Circle of Lost Hackers, they field the question directly and decline the war: "we have a problem with unjustified arrogance … The main battle of PHC is fighting whitehats but it's not Phrack's battle. It's never been the purpose of Phrack." Even the underground's flagship wouldn't co-sign the harassment.

ACT IV — ANTI-SEC 2009 (THE REVIVAL)

The slogan comes back with a new crew, a mass ImageShack defacement, and a security portal owned live.

  1. JUN 2009

    Every image on ImageShack, replaced

    A crew simply calling itself Anti-sec breaches ImageShack and swaps its hosted images for a single manifesto image — the "eradication of full-disclosure" text at the top of this file. The old thesis, restated for a new decade: "It's about money … the security industry uses full-disclosure to profit and develop scare-tactics."

  2. JUN 2009

    Astalavista owned; the definitions restated

    The crew owns the security portal Astalavista and, in a follow-up addressing its critics, publishes the movement's whole worldview as a dictionary: a whitehat is an "asshole who publicly posts exploits … normally sucks dick for money"; a greyhat is "no such fucking thing." The complaint underneath the bile: "They cause a problem, and provide (commercially) a fix for it."

  3. 2009

    Anti-anti-sec — the funded counter-crew

    The predators get a predator. A group calling itself ProSec — described by its own release as "well-funded and top notch security experts" — publishes a doc it titles "the complete destruction of the 'Anti-Sec' group," claiming to have profiled and back-owned the crew and its members. The scene's oldest lesson, applied to the antisec crews themselves: whoever owns you writes the history.

ACT V — OPERATION ANTISEC (2011)

The slogan goes mainstream, gets a logo and a Twitter account — and the flagship op turns out to be partly run from inside the FBI.

  1. JUN 20, 2011

    LulzSec + Anonymous launch Operation AntiSec

    LulzSec announces it is "teaming up with … Anonymous" for Operation AntiSec — the same anti-security banner, now aimed at governments and defense contractors. Targets over the following months included Arizona DPS (Jun 23), Booz Allen Hamilton, ManTech, and the intelligence firm Stratfor. The teenage disclosure-war grievance had become a global op.

  2. JUN–AUG 2011

    The FBI is already inside

    LulzSec's purported leader, Hector "Sabu" Monsegur, is arrested in June 2011 and pleads guilty on Aug 15, 2011, becoming an FBI informant. For much of Operation AntiSec, the movement's flagship was being steered, in part, by a cooperating witness — the exact "Fed enabler" the whole ideology was built to hate, now at the center of it.

  3. 2011–12

    Fallout: Hammond, Topiary, TeaMp0isoN

    Jeremy Hammond is charged over the Stratfor hack; Jake "Topiary" Davis is arrested Jul 27, 2011. In the UK, TeaMp0isoN — led by "TriCk," Junaid Hussain — rode the same anti-security wave before arrests in 2012. Hussain later fled to Syria, joined ISIS as a propagandist, and was killed in a 2015 drone strike. The arc from "own the whitehats" to that end is the whole cautionary tale in one biography.

both sides, on the record

The movement's argument (attributed to the movement, not adopted here): full-disclosure is a business model. A security firm finds a bug, publishes it with its logo attached, sells the fear and the fix, and — per Gweeds — when its founders testify to Congress, the state gets more surveillance funding while the hackers who post exploits get "caught and put in jail." On this account the "sellout" whitehat is not neutral; he is an enabler of a Federal police state, profiting off a scene he helps criminalize. Real firms did sell fear, and the revolving door between the underground and the security industry is real.

Sometimes they were right about a target: the movement named a genuine dynamic — fear-marketing, exploit-brokering dressed as public service, and researchers monetizing a community they came up in. That critique outlived every crew that shouted it, and mainstream security has spent twenty years arguing the same disclosure question, minus the death threats.

The headline accusation was unsubstantiated: L0pht testified to Congress at the invitation of Senator Thompson's office — not, as claimed, at the behest of the NIPC — and the charge that @Stake lived off "lucrative federal contracts" was never backed by evidence, a point made in the very Register coverage the movement cited. The "Fed enabler" thesis was, at its center, a story [5].

Disclosure demonstrably works: publishing vulnerabilities is how they get patched. Defensive security work — the audits, the advisories, the honeypots the movement mocked — is legitimate and protects users the movement never thought about. "Semi-disclosure" and "keep your bugs for yourself" are a coherent position, but they are not obviously the safer one.

The method was harassment, not argument: the movement did not merely debate. It doxed people — the NARC files reportedly circulated a sixteen-year-old's personal contact data — dumped private mail spools, printed "know your enemy" dossiers, joked about a "whitehat holocaust," and fantasized in verse about murdering named engineers. In 2009 and 2011 it simply owned and dumped victims whose worst offense was a badly-secured server. Whatever the thesis, the receipts are full of people who got hurt for it [2] [6].

YOU DECIDE

The antisecurity movement is the rare case where the critique and the crime are both real and neither cancels the other. Fear-marketing exists; the revolving door exists; the disclosure debate is genuinely unsettled. And the movement that named those things also doxed a teenager, threatened engineers by name, and — by 2011 — ran its flagship operation with an FBI informant near the controls. Keep the argument. Keep the body count too.

The archive does not pick a hat. It keeps the manifesto — and the list of everyone the manifesto owned.

evidence locker

PRIMARY / ZINES (research mirror)

  1. ~el8 #3 — "Know Your WhiteHat Enemy" / "NO MERCY FOR WHITEHATS" PRIMARY — the banner "FUCKN UP WHITEHATS SINCE 1998," the recurring whitehat-profile column, and the "m0nEy-Ca$h-lameness" sign-off. Held as primary text; the personal data the issue contained is not reproduced here.
  2. nwonknu — "statement" (the K2 feud) ATTRIBUTED — "ADM sponsored the antisecurity movement, and K2 is a member of ADM"; the CORE-ST employment claim; and K2's counter-claim of slander. A two-sided dispute; underlying contact data omitted.
  3. PHC "pr0jekt MAYHeM" mission index PRIMARY — the numbered harassment-op list ("The Whitehat Briefings," "war on public key infrastructure," "establish cells on different networks").
  4. "murder the security industry" (blackhatbloc, by "BLACKHAT LIKE ME") PRIMARY — the violent-rhetoric refrain, quoted to document how far the language went; named targets not reproduced.
  5. h0no zine — "wh1t3h4t h0l0c4ust" PRIMARY — the escalation cover text ("MERRY XMAS SEC INDUSTRY"). Directory listings and mail spools inside the issue are not reproduced.
  6. Anti-sec 2009 — ImageShack defacement + Astalavista comments PRIMARY — "eradication of full-disclosure," "you will be rm'd," and the whitehat/greyhat/blackhat "definitions."
  7. Anti-anti-sec — ProSec release PRIMARY — the "well-funded" counter-crew's "complete destruction of the 'Anti-Sec' group" claim.

CONTEXT & CROSS-LINKS

  1. Phrack #64 — International scenes & Pro-Phile ATTRIBUTED — the ADM / Association De Malfaiteurs lineage of the antisecurity movement (file 15), and the Circle of Lost Hackers declining PHC's war on whitehats (file 2). phrack.org/issues/64/15
  2. Wikipedia — Operation AntiSec / LulzSec / TeaMp0isoN ATTRIBUTED — the 2011 revival: the Jun 20 launch, the targets, Monsegur's guilty plea and FBI cooperation, the arrests, and TeaMp0isoN's arc. en.wikipedia.org/wiki/Operation_AntiSec
  3. troll.fan — Peter Zatko / L0pht / @Stake CROSS-LINK — the archetypal "sellout" target, with L0pht's Congressional testimony and the @Stake context. troll.fan/dossiers/peter-zatko.html
  4. troll.fan — Crew Rivalries (the ZF0 sequel) CROSS-LINK — how "own the whitehats" kept mutating into the next decade's crew wars. troll.fan/crew-rivalries.html
  5. troll.fan — cDc & the scene timeline CROSS-LINK — the Cult of the Dead Cow milieu Gweeds came out of, and the timeline / DEF CON context. troll.fan/dossiers/cult-of-the-dead-cow.html
  6. troll.fan — the antisec lineage CROSS-LINK — the crews and figures the movement ran on: ADM (the root), TESO and w00w00 (the elite tool crews it overlapped), K2 (the model "whitehat enemy"), and Gweeds (the H2K2 manifesto). troll.fan/dossiers/adm.html
  7. troll.fan — Operation AntiSec (2011) CROSS-LINK — where the slogan went mainstream: LulzSec, its informant leader Sabu, the Stratfor hacker Jeremy Hammond, the voice Topiary, and the rival crew TeaMp0isoN. troll.fan/dossiers/lulzsec.html
  8. troll.fan — the Disclosure Wars CROSS-LINK — the underlying full-disclosure fight the whole movement was a violent wing of. troll.fan/dossiers/disclosure-wars.html
The standard. The antisecurity movement is documented here through its own published zines and the public record. Its central thesis — that full-disclosure is a business model and that "sellout" whitehats enable a Federal police state — is presented as the movement's argument, attributed, not as this archive's finding; the load-bearing rebuttal (L0pht testified at a Senator's invitation and the federal-contract claim was never substantiated) is given at full strength, from the same sources. Legitimate defensive security work is stated to be exactly that. The movement's harms — doxing, harassment, violent rhetoric against named people — are documented as fact from its own texts, and none of the private data those texts contained is reproduced. If a line here couldn't survive scrutiny, it wouldn't be on the page.

The ethos, not the crew. The same "your defenses are performative" contempt ran through the trolling scene — the GNAA and Goatse Security milieu, and weev, whose "the best trolls I know are also all hackers" is provocation-as-disclosure in one line. That is an ethos overlap, not a roster: weev's documented affiliations were GNAA and Goatse Security, not the ~el8 / Operation-AntiSec crews above. The shared thread is disdain for the security industry's theater — kept to what the record supports.