logoalt Hacker News

Some Epstein file redactions are being undone with hacks

551 pointsby vinni2yesterday at 8:10 PM417 commentsview on HN

Related: https://xcancel.com/vmfunc/status/2003292986650853825

https://old.reddit.com/r/law/comments/1ptlms6/some_epstein_f...

https://krassencast.com/p/breaking-we-just-unredacted-the-ep...


Comments

cmarschneryesterday at 6:11 PM

Befuddling that this happened again. It’s not the first time

- Paul Manafort court filing (U.S., 2019) Manafort’s lawyers filed a PDF where the “redacted” parts were basically black highlighting/boxes over live text. Reporters could recover the hidden text (e.g., via copy/paste).

- TSA “Standard Operating Procedures” manual (U.S., 2009) A publicly posted TSA screening document used black rectangles that did not remove the underlying text; the concealed content could be extracted. This led to extensive discussion and an Inspector General review.

- UK Ministry of Defence submarine security document (UK, 2011) A MoD report had “redacted” sections that could be revealed by copying/pasting the “blacked out” text—because the text was still present, just visually obscured.

- Apple v. Samsung ruling (U.S., 2011) A federal judge’s opinion attempted to redact passages, but the content was still recoverable due to the way the PDF was formatted; copying text out revealed the “redacted” parts.

- Associated Press + Facebook valuation estimate in court transcript (U.S., 2009) The AP reported it could read “redacted” portions of a court transcript by cut-and-paste (classic overlay-style failure). Secondary coverage notes the mechanism explicitly.

A broader “history of failures” compilation (multiple orgs / years) The PDF Association collected multiple incidents (including several above) and describes the common failure mode: black shapes drawn over text without deleting/sanitizing the underlying content. https://pdfa.org/wp-content/uploads/2020/06/High-Security-PD...

show 11 replies
OneMorePersontoday at 6:36 AM

It's funny seeing this play out because in my personal life anytime I'm sharing a sensitive document where someone needs to see part of it but I don't want them to see the rest that's not relevant, I'll first block out/redact the text I don't want them to see (covering it, using a redacting highlighter thing, etc.), and then I'll screenshot the page and make that image a PDF.

I always felt paranoid (without any real evidence, just a guess) that there would always be a chance that anything done in software could be reversed somehow.

show 12 replies
vincengomestoday at 4:20 AM

"Never interrupt your enemy when he is making a mistake" - Napoleon Bonaparte

Let all the files get released first.

Then show your hacks.

show 4 replies
nickpinkstontoday at 1:10 AM

I wonder if any of this is a conscious act of resistance vs. just incompetence.

And yes, I've heard of Hanlon's Razor haha

https://en.wikipedia.org/wiki/Hanlon%27s_razor

show 8 replies
digitaltreestoday at 3:42 AM

Its not a hack to copy and paste text that is part of the document data. The incompetence of the people responsible to comply with the law doesnt mean its reasonable to label something a hack.

Please change the title.

show 8 replies
scirobtoday at 8:05 AM

Man if you can do this should keep it secret until they release more bad redactions...

maCDzPtoday at 10:49 AM

Maybe someone knows law can answer this. Is it a crime to ”unredact” files in the US? You probably know that the information is classified since you are putting in the work. Where I live I believe it’s a crime if you share information that is classified even if it’s leaked. So I would not publicly brag about this online.

show 1 reply
jFriedensreichtoday at 11:24 AM

is there an overview page somewhere just about what was redacted?

tim333yesterday at 11:12 PM

It's quite funny really. Apparently you just cut and paste the text into Word. They just had the pdf put black rectangles on top.

show 2 replies
juujiantoday at 2:16 AM

Apart from the technological and procedural question, I would love to learn why the DOJ found it important to protect Indyke. He was Epstein's lawyer, and now we learn that he was personally involved. He is not a Washington person. We expected there to be politically motivated protection of certain people, but is the DOJ just going to blanket protect anybody in the docs?

show 7 replies
pfannkuchentoday at 5:19 AM

Stupid question: why is the government even allowed to redact stuff? Isn’t the government keeping secrets from the people totally antithetical to democracy?

show 6 replies
jtrntoday at 10:08 AM

Shout out to Stirling PDF that can be self hosted and has a relatively robust and easy to use redaction tool. All for free.... For now....

entropiaetoday at 9:27 AM

Not the first time; in 2005 the US report about Nicola Calipari's death in Baghdad was redacted (and unredacted by italian newspapers) in the same way.

KnuthIsGodtoday at 8:21 AM

Print on paper. Physically cut out the pieces you want to send to remove. Scan.

Still suspect that someone can undo this from data may have been accidentally steaganographed across non-deleted parts of the image.

show 4 replies
wutwut182today at 10:12 AM

I "hacked" my facebook account the other day. I forgot my password and used the "forget password" link to gain access .

pinkmuffineretoday at 8:08 AM

What is the proper way to do this? I see a couple suggestions in the comments:

1. Draw a black box over it in image editor, save a screenshot

2. Crop the info out

Are there other good ways?

show 1 reply
NicoJuicytoday at 7:06 AM

A mafia state puts loyalists on top and can't produce anything ( smart people leave) and smart people who think for their own can't be promoted.

That's also why a mafia extorts and doesn't run complex businesses in general.

Perhaps the US can survive this administration. But somewhere down the line it will become broken.

show 1 reply
montroseryesterday at 10:12 AM

Let's nobody make any fuss about this yet, lest they wise up before releasing the rest of the docs this way too!

cryptoegorophytoday at 5:02 AM

There is a book by Richard Dawkins- I am me I am free or something like that, and it has a main picture of Richard standing naked and having a private part being covered by black rectangle but somehow my laptop back then was slow and when you scrolled it would temporary remove the square for a split second

show 1 reply
UrineSqueegeetoday at 9:33 AM

i wouldn't trust any of these "undo's"

userbinatortoday at 4:45 AM

Part of me wonders whether they had some of the text under the "redactions" changed too.

rbbydotdevtoday at 9:10 AM

when i first saw this, i thought it was a meme. There is no way the DOJ could be so incompetent to fumble their own cover up.

tomekfyesterday at 2:13 PM

How it’s done from technical point?

show 6 replies
tpoacheryesterday at 8:04 PM

reminds me of that leaky redaction program that won the obfuscated c contest some years back

show 1 reply
nlitsmetoday at 12:33 AM

Can you post the document numbers, I can't find where these texts are in the original pdfs.

show 1 reply
delbronskitoday at 10:11 AM

This is probably just pure stupidity, but part of me hopes there is some tech person in there who knew exactly what they were doing. I’d take a job as a tech person in this administration just to sabotage stuff like this.

buhfuryesterday at 4:25 PM

Doesn't work on any PDF's of scanned documents , for example the contacts list.

show 1 reply
BigParmtoday at 5:19 AM

I wonder if it's purposeful misdirection

thinkcomptoday at 6:00 AM

I love how the entire internet thinks that this is a big deal when all that happened is that USDOJ re-posted some poorly-redacted court documents that were poorly redacted by non-USDOJ attorneys more than three years ago.

Yes, USDOJ is incompetent and dysfunctional, but this is not why. But sure, whatever, carry on...

sandworm101today at 4:29 AM

Ctrl-c and ctrl-v are not hacks.

They are unredacted because either those in charge are not familiar with basic office tasks, or someone wanted this stuff to leak and nobody checked thier work. Either brand of incompetance should cause heads to roll. But, just like the signal fiasco, nothing will happen. When your brand is perfection, you cannot ever admit a mistake.

NuclearPMtoday at 4:05 AM

There are people here that would still vote for these evil people.

sublineartoday at 3:11 AM

If you think mere human incompetence with documents is bad, imagine all the vibe coded apps.

sva_today at 4:43 AM

Am I crazy or didn't the same thing happen with Epstein's phone book some years ago? Coincidence?

Alifatiskyesterday at 1:06 PM

Alright, now when everyone knows this. I hope people have backed up all the files to unredact everything before DOJ retracts the sensitive documents.

lawnyesterday at 10:28 AM

Lots of these redaction doesn't make sense unless they're made to protect the rich and powerful. Not surprising of course.

Kaibeezyyesterday at 12:49 PM

See also:

We Just Unredacted the Epstein Files

https://news.ycombinator.com/item?id=46364121

I tried to ascertain, but am not certain, this is the original blog source. Maybe they made some prior X posts.

spacecadettoday at 4:46 AM

It has become more plausible that nothing of value was released and the level of obviously poor redaction was done as a tarpit to own the libs.

xhkkffbfyesterday at 4:19 PM

So is the data extracted the names of the victims that were supposed to be hidden to protect them? Or is there something else that might be worthy of exposing?

show 5 replies
binary132today at 5:18 AM

ah yes, “hacks”

vduprasyesterday at 9:17 PM

Trump's razor: Why attribute something to incompetence when you can attribute it to patriotic sabotage?

show 3 replies
tom86150today at 9:16 AM

[dead]

lisbbbtoday at 1:23 AM

Did we learn anything useful or is it exactly as I said in the other thread, which got downvoted to hell, that all the really juicy blackmail material is with the CIA and will never see the light of day?

show 2 replies
anovikovtoday at 9:21 AM

hacks :facepalm:

pengarutoday at 3:48 AM

"hacks"

copy and paste people, the idiots have taken over

eBombzortoday at 7:06 AM

This site has really gone downhill lately with drivel like this being upvoted. Any real developers on this site anymore?

show 1 reply
c420today at 1:52 AM

“Like you guys have had this stuff for a year. Doesn’t it seem like you could just throw all that into AI at this stage of the game? And just redact the names of the victims, and let’s go.” Joe Rogan

🔗 View 2 more comments