12.02 — LulzSec, the Lulzboat, AntiSec#
Three distinct subjects: (1) LulzSec as a group, (2) the Lulzboat as identity metaphor, (3) AntiSec as a movement (two versions: 1999 and 2011). The Holy Book invokes them in one breath; each has its own history.
1. AntiSec (1999) — the original movement#
Origin#
In the late 1990s, the infosec industry professionalized: companies formed around selling firewalls, antiviruses, audits. A norm emerged: full disclosure, publicly releasing vulnerabilities, their PoCs, their exploits, with the argument that it forces vendors to patch quickly.
Part of the underground community saw this practice as a business model dressed up as ethics. The argument: full disclosure doesn’t serve security, it feeds an economy where you sell the fear you helped create. The same actors releasing exploits sell the solutions.
The Anti Security (antisec) movement was born against it. Its principle:
No full disclosure. No public exploits. Bugs stay in the underground. Tools stay private. The mailing lists “Bugtraq”, “full-disclosure”, “vuln-dev”, “vendor-sec” are considered enemies.
Declared targets of the original AntiSec movement:
- Sites: SecurityFocus, SecuriTeam, Packet Storm, milw0rm.
- Mailing lists:
full-disclosure,vuln-dev,vendor-sec,Bugtraq. - Public IRC forums where exploits circulated openly.
Source: Antisec Movement — Wikipedia
Why it matters for Ocarina#
The original AntiSec did not win. Full disclosure became the norm. CVE, CVSS, NVD, bug bounty programs: the whole market aligned on the opposite stance.
But the structural argument — "this industry creates the problem it sells" — was never refuted. It came back in other forms (anti-vendor-lock, anti-SaaS, anti-No-Code movements). Ocarina inherits this line: refusal of testing vendors (BrowserStack, Sauce Labs, etc.), refusal of “platform solutions”, white-box auditability of the code.
The Holy Book formalizes it (chapter “Anti slipologues”):
For too long, computing has been held hostage by a minority, a “1%”, that thought it would be clever to turn it into a playground for insiders.
This “minority” is, roughly, the anti-AntiSec industrial complex. Modern full disclosure is its tool. Ocarina was born against it.
2. LulzSec (May – June 2011) — 50 days of chaos#
Origin#
Lulz Security (LulzSec) was born in May 2011, an Anonymous splinter group. Six main members:
| Pseudo | Identity | Role |
|---|---|---|
| Sabu | Hector Monsegur | Leader, turned FBI informant by June 2011 (revealed in 2012) |
| Topiary | Jake Davis | Spokesperson, communiqués author |
| Kayla | Ryan Ackroyd | Technical exploits |
| Tflow | Mustafa Al-Bassam | Exploits, dev |
| AVUnit | never identified | — |
| pwnsauce | Darren Martyn | — |
50 days of attacks hitting public, media, and entertainment sectors:
- PBS (May 2011), fake news “Tupac alive in New Zealand” on Newshour, in retaliation for an unfavorable WikiLeaks Frontline documentary.
- Sony Pictures, massive user-base dump after the PSN debacle.
- CIA.gov, DDoS.
- Fox, X Factor contestant DB leak.
- US Senate, site infiltrated.
- InfraGard Atlanta (FBI partner), credential dump.
- HBGary Federal (FBI partner), credential dump, attack carried out under the Anonymous banner before LulzSec formed.
Sources: LulzSec — Wikipedia, Operation AntiSec — Wikipedia
The LulzSec Manifesto (June 2011)#
For their 1000th tweet, LulzSec released a manifesto:
“We’re not, only because we don’t have to be. (…) We release personal data so that equally evil people can entertain us with what they do with it.”
Owned nihilism, aestheticized. Hacking for the “lulz”, not for political conviction, not for wealth — for fun and to exhibit the system’s fragility.
LulzSec brought back the term AntiSec under a new banner: Operation AntiSec (June 2011), in collaboration with Anonymous. Targets: governments, security organizations, vuln-dev mailing lists.
3. The Lulzboat#
The Lulzboat is LulzSec’s stylized pirate ship, repeated everywhere:
- Twitter banners.
- Pastebin headers:
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄ TheLulzBoat ▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄. - Communiqués signed “The Lulz Boat / Lulz Security”.
Boat ASCII art, Stuart Little / Captain Hook / Nyan Cat.
“If you’re sittin’ below deck / In the Lulzboat, salute, bitch, and show some respect”
— YTCracker,
#antisec(June 22, 2011), which became the official anthem of Operation AntiSec.
The line is quoted as-is in Ocarina’s Holy Book:
“In the Lulzboat, salute, bitch, and show some respect.”
A generational password.
YTCracker and LulzSec#
YTCracker (Bryce Case Jr.) is strictly speaking outside LulzSec — he wasn’t one of the 6 members — but he was associated:
- He personally knew several members.
- He wrote
#antisecduring the operation. - His song was used by Anonymous / LulzSec in their communiqué videos.
See 03-ytcracker-nerdcore-digital-gangster.md for the YTCracker detail.
4. The end (June 2011 → March 2012)#
The night of June 25–26, 2011, LulzSec released "50 days of lulz", their dissolution communiqué:
“For the past 50 days we’ve been disrupting and exposing corporations, governments, often the general population itself, and quite possibly everything in between, just because we could.”
Six months later, in March 2012, the US DoJ indicted five of the six members. Sabu had been cooperating with the FBI since June 2011 — he ratted.
Source: LulzSec finally calls it quits — GeekBurn
5. Rhetoric “Don't fuck with us.” → “YOU FUCKED WITH US!”#
The Don't fuck with us mantra comes from the original carding/defacement scene (see 05-indonesian-hackers.md, where its systematic presence on YogyaCarderLink deface pages is documented). LulzSec and Anonymous inherited it: it structured the entire grey hat scene of the 2000s before being picked up by the 2010–2012 operations.
| Grammatical tense | Effect |
|---|---|
Don't fuck with us. (future conditional, warning) | Defensive posture. We don’t do anything as long as you don’t attack us. |
YOU FUCKED WITH US! (declaration of retaliation) | We warned you, you did it anyway, now own up. |
Ocarina’s Holy Book phrases it word-for-word in the same language, in any translation:
YOU FUCKED WITH US!
The whole invective passage (see 06-yung-innanet-vxug.md) isn’t gratuitous aggression — it’s a late, explosive response to years of pressure. It’s the contextual adaptation of a framework author who spent years being dictated how he should write his code.
These “two-tense” codes are universal in this scene. You find them in:
- YogyaCarderLink defaces (
Don't fuck with us.signature at the bottom of the page). - Post-HBGary pastebins (Anonymous, February 2011).
- LulzSec retaliation communiqués (Operation Payback — RIAA, MPAA, then WikiLeaks defense).
- Lulz Boat communiqués responding to arrests.
6. Lineage with Ocarina#
Ocarina doesn’t obviously present itself as a hacker project in the 2011 sense. It’s MIT, hosted on GitHub, breaks nothing. But it inherits:
| LulzSec / AntiSec trait | Ocarina trait |
|---|---|
| Rejection of professionalization as a value | Rejection of “pytest plugin” and of ecosystems |
| Rejection of full disclosure as business | A single runtime dep, auditable code |
| Claimed group identity | “It’s my car” |
| Direct, no-politeness rhetoric | “Fuck You. Not complicated.” (DHH) |
| Underground aesthetic | AI illustrations, pamphlet tone |
| Lulz as tonality | Constant humor in the Holy Book |
Ocarina is what those people do 20 years later, when they write a test framework during the day. It’s the same ethic, in a different medium.
