Recently, some kid hacked Sarah Palin’s Yahoo! email. He explained how he did it in detail on the 4chan forum.
Turns out, he made a huge mistake of only bouncing through one proxy server. Oops!
When he realized that, he chose to do what, at first glance, sounds like a stupid idea: post the password and the story to the forum. Upon further consideration, what he did might have increased his chances of evading discovery better than just walking away:
By posting the password and login information to a widely travelled public forum, he effectively decreased the signal to noise ratio by two orders of magnitude (at least). With 1000 IP addresses to comb through, instead of just 1, your chances of escape are infinitely better.
Finding the person behind the first IP would constitute circumstantial evidence at best, and not conclusive that he was the one responsible. He could just as easily have been one of the 1000s of people on the forum who logged in out of curiosity (still probably illegal, but I’d imagine it’d be a) way harder to bag them all, and b) much less of a sentence than the original break-in and leak).
However, there’s still the major gaffe that he posted under an account on a forum. An anonymous craigslist ad posted from a public library in a neighboring town, all while bouncing that through a couple of proxies would have been a much better idea.
The only way security researchers “tentatively identified” him was by his forum post.
EDIT: Ctunnel is apparently cooperating with the FBI, and the hacker’s screenshots with the Ctunnel URL in it may be his undoing. Three proxies would have been better. And do it from a library, you fool.