So what's all this about Romney's tax returns being hacked?

This is an important point. Forging something as complex as Mitt Romney’s tax returns in a way that would pass simple consistency checks (internal and external consistency) would be difficult and require diverse knowledge and skills. Doing it in a way that would fool forensic accountants would be even more difficult if not impossible, and you can bet that the best forensic accountants on the planet would be poring over these things if they were released.

Liars often compensate with a lot of detail.

BitInstant To Romney Camp: ‘We’ll Convert $1,000,000 USD to Bitcoin For Free.’ BitInstant To Romney Camp: 'We'll Convert $1,000,000 USD to Bitcoin For Free.'

When I checked the “Release the Documents” address, there’s been over 2 BTC deposited to that account. I personally wouldn’t donate to this account because they’re going to release the decryption key on 9/28 even if the account doesn’t reach the amount.

I don’t think anything has been transferred to the “Delete the Documents” account over the past day.

I think if the statements about the building, room, etc were totally false or if PWC had entirely ruled out a data theft, that there would be a public announcement to prevent people from ‘donating’ to a complete hoax on either side.

Ummm, the [1] is just a long-distance code, not international. International would have looked like this:

[00] [1] (615) 503-2860

Typically, the interntional country code would be indicated with a “+”, so if you had +1 615 503 2860, I would say that has an international code in it, but I’ve never seen the country code written in brackets like that.

Actually
00 = country exit code for many countries
1 = country code for the US and Canada (+ some others)

That is why, when dialing US/Canada to US/Canada you only have to dial the ‘1’ Essentially you’re accessing the country level routers (exchange) [but not exiting the country level exchange] instead of your local phone company routers (exchanges).

It is not typical for a US person to write a US phone number with the country code included unless they are accustomed to dialing from outside of North America.

It also isn’t typical to include the country exit code for any phone numbers. Like, if I were to write a Mexican phone number, I would write +52/###… and not include the exit code. It would physically be dialed from the US as 00 52 ####… By using the 00 code, your call is routed to the border routers between countries, bypassing the local router and country level routers. Here is a list of country exit codes: List of country codes, international and national prefixes

I think the country code only tells us that the perpetrators are not likely to try to exchange the Bitcoins to a currency within the US. But, that would be a stupid thing to do anyway.

Yes, but what if those details are correct? As far as I know, no one is disputing them yet. And why add details that you know are false, risking immediate exposure? To pull of a scam like this, you would only release details that you know are true.

Exactly. It’s conceivable that authorities wouldn’t point out the incorrect details for some reason or other, but it seems like someone somewhere would say, “hey that’s not correct”.

No one with any sense who actually wanted to succeed with the plan would include such a detail if it wasn’t correct. It’s too easily checked.

This offer (not the blackmail attempt) is obviously a PR stunt by BitInstant.

It looks like that “release the forms” address is currently beating the “don’t release” address 6 to 1.

A Bitcoin is currently worth approximately USD $10 so it’s $30 to $5.

Interestingly there have been 18 transactions to the release address and 65 to the don’t release. So the release group seems to have a smaller number of larger donations while the don’t release consists of a larger number of smaller donations. Sort of the opposite of the real world where Obama is dependent on a larger number of small donors while the Romney camp is just the opposite.

Of course that means nothing since the donors are all silly people who are throwing away their money.

Meanwhile someone else is trying to get in on the act.
http://pastebin.com/EF3iEHET

This is followed by two new wallet addresses. Both those wallets currently have 0 bitcoins so this particular scam may be too obvious even for the fools who donated to the original miscreants.

I don’t think that Romney is involved in this, but I did think of another reason Romney hasn’t released the tax returns. Could it be that he has been planning to release them all along, maybe in early or mid October? Assuming they don’t show anything remarkable, he could then say that Harry Reid was lying all along, and try to embarrass the Democrats by showing their was no problem with the tax returns all along. I admit this is unlikely, but it sounds like a strategy some Romney advisor or another might have come up with.

Larry Flint is offering $1 million for the tax returns. I’m sure BitInstant has already emailed him and offered to set him up with a Bitcoin Wallet.

The only problem is that with the bitcoin offer, Flint would be out of the money BEFORE he could verify the contents of the files. Lets hope they can work out their differences.

Are there legal problems with paying these guys money to release the forms? It seems like it would be a form of helping them engage in criminal actions…

If the unencrypted information ends up at a news agency without payment to anyone, I know the news agency can use the information because they were NOT a part of the crime committed.

As to Flint paying the group with the bitcoin accounts? If the transactions happen in the US in a way that leaves a paper trail, then I’m sure he could get caught up as an accessory.

BUT, there are many countries who aren’t so picky and cash-in-hand is very hard to track. A person with cash in hand could create a bitcoin wallet and make the transfers (using exchanges external to the US - so BitInstant would be out) and that would be nearly impossible to track down given what law enforcement is actually permitted to do.

Of course, there isn’t anything to stop the holders of the data from selling it and the decryption key directly to Flint (w/out bitcoins) while still keeping their bidding war going on line. Notice that the ad if offering CASH for the information.

Even if there weren’t anything major, it would flood the news with each and every foreign-linked investment that could be sussed out from the returns for the final two weeks of the campaign and re-energize the ‘rich folk don’t pay enough taxes’ meme. I’m thinking that he’d have a hard time shouting about the economy over all that noise.

NOW, if he really doesn’t want to win, that sort of timing would be a sure way to send it down in a spectacular flaming ball.

The original Pastebin post mentions that a drive was also set to PWC. Presumably, if this was done, that drive wouldn’t be encrypted, since PWC already has the data and the only reason I can see for sending a drive to them would be to prove that the burglars have what they claim to have.

In fact, encryption isn’t mentioned at all in this post. It’s only in the second post, which may or may not be from the same people, that encryption (and ransom) are mentioned.

That second Pastebin post, two days later, makes no mention of sending drives to PWC or either of the political parties. Instead it says that all (which seems unlikely) major news outlets will be sent encrypted copies of the data.

If a large number of media outlets receive drives, some of them are going to talk about it. So far there’s nothing but silence. It could be that they haven’t been received yet, or it could be that they’ll never be received.

So far only the things threatened in the first post have happened (and not necessarily all of those things). The second one may be a different unrelated party trying to capitalize on the first post. One thing that gives me pause; if the second post was from an unrelated person, what was the point of the first post? If you’re not planning extortion, why give advance notice rather than just releasing the data immediately, and what is the significance of Sept. 28?

So, have any news outlets received copies? Will any? Has PWC recieved a copy?

If PWC hasn’t received a copy, you’d think that they would be loudly proclaiming that fact, since their reputation depends on security, but there may be reasons not to acknowledge it one way or the other.

Are both posts hoaxes? Were the drives sent but some third party simply stirring the pot for the hell of it?

Did those two packages contain the reference phrases at the bottom of those posts? Were those packages received before Sept. 2 (the date of the first post)?

It’s only been a couple of business days yet, so it’s probably too early to call it one way or the other. Nothing says anything was shipped within the United States, and it would be trivial to transfer any available data to Kazakhstan or wherever and mail the packages from there if someone wanted to and had the connections.

I admit I just scanned the thread but where is the mention of Karl Rove - Republican dirty trickster? Going back to George Bush then running (poorly) for Texas Governator, Rove planted and then discovered a bug in Bush’s campaign office. Rove never said it was Bush’s opponent; he just let the media and then voters run with it. The fact that the bug had a battery life of a few hours and range of about 30 yards never came out but Bush went on to win - and you know the rest. Fast forward to the Presidential election and CBS 60 minutes came up “magically” with some damning Bush service records. A closer examination showed the records to be copied and possibly altered. Who leaked the records to the media and then was able to point out the discrepanices? I suspect Rove or inspired hencemen carried out something similar with these tax returns.

No, what he’s planning to release in October – and has said so – is his completed 2011 return; what was originally released with the 2010 actuals was an estimate as the return for 2011 hadn’t been finished and was on extension.

The Romney campaign has been firm that nothing other than 2010 and 2011 will be released.

There’s something interesting happening with this.

I was looking at the amounts deposited in the “don’t release” bitcoin address

and noticed that a bunch of them are fractional amounts consisting of nothing but zeros and ones. Looking at them, I realized that they’re binary. Not only that, they’re ASCII, and if you translate them into characters they spell out three URLs. :eek:

One, http://x.co/nbvq, redirets to a sendspace.com page where you can download an encrypted rar file named “Tax - Copy.rar”.

The other two lead to images of QR codes. QR codes are often used to encode website addresses.


One of them encodes a broken URL. The other encodes a valid URL which leads to a page where you can download an audio file, “where.wav”.

http://www.sendspace.com/file/m6crjs

This is where I got stuck. If you listen to it, it’s nothing but noise. I thought maybe something was hidden in it via steganography, but that appeared to be a dead end (although that wasn’t certain).

Some Googling led me to a thread where others had discovered the binary codes and had gotten further than me.

Here’s a link to that discussion.

https://bitcointalk.org/index.php?topic=105929.0;all

The first mention of the ASCII codes is at post 41.

Someone used some sort of frequency analysis software to view an image of the “where.wav” file’s sound waves. Somehow there is text visually encoded in the sound waves.

The text is a URL and a date: 9.10.12. The date may be in European format, indicating October 10.

The URL is

and leads to a Google UK map of an American address: 815 Brazos St #500, Austin, TX 78701, USA

At the bottom of that same frequency image is a message “All Shall be Revealed”.

So far, the trail ends there. People are trying to crack the password on the “Tax - Copy.rar” file but I doubt that they’ll have any luck.

I think it’s all some third party troll playing games as it makes no sense for the extortionists to do this. But someone went to a LOT of work to set it up, and it’s fun trying to follow the trail.