December 3, 2009

  • Hacking

    I saw a post on Discovery.Com this morning entitled My Favorite Hackers, written by a Ryan Draga.  In this article, Mr. Draga names a few well known hackers and suggests that while he is a new comer to the world of hacking, he is not a criminal when he engages in the practice of hacking into systems, suggesting rather that he is some kind of a technocrat who is just experimenting to see what happens.  In his closing paragraph -- which has now been deleted along with the ability to leave comments -- he said he just wants to know what happens when he pushes a button. "Turning all the Web sites you read upside down for a couple minutes is not a crime, it's a joke."

    What a bunch of BS.  It may be a joke to him, and it may be fun to him, but it is neither to the millions of us who have to suffer so that he can play like a little child.  Even if he doesn't take our credit card numbers, he still costs us time and money.  Untold millions of dollars of revenue have been lost because of guys like him, who accidently took a sales site down.  
     
    He goes into an unknown system, pushes a button, and emergency generators go down in a hospital, resulting in a blackout.  People may die.  He pushes another button and the Air Traffic Control system goes down for a hour with 6000 planes in the air.  People may die.  He pushes yet another button, and the New York stock exchange goes down.  Hundreds of millions of dollars worth of transactions are lost.  Why?  Because he wants to have fun.  He just wants to see what will happen!  It was just a joke! 

    He may say that he is uncovering the holes in a system so that "bad guys" can't exploit them, but the rest of us say that if it wasn't for guys like him, there wouldn't be any bad guys to exploit us.

    I don't mind his playing around so long as he does it on his own equipment in a closed environment that belongs exclusively to him; but when he moves into the public environment, or any environment where he is not authorized to go, he is a cyber criminal and needs to do a little time behind bars.

    The Dictionary defines a hacker as
    "Slang. a person who engages in an activity without talent or skill."

Comments (6)

  • I bet his mommy didn't believe in punishing him for fear of hurting his precious little ego. Now look what she created. :nono:

  • The internet has created a whole new branch of hacking. I use an Apple MacBook running OS 10.4 which is generally pretty secure from malware and I seldom (never) go Airport wireless, but my NetBarrier firewall sometimes detects, locks out, and attempts to chase down "pings". These are repeated attempts to check out, dump data from, and maybe take over your computer. You would not ever be aware of this unless you have an anti-pinging firewall. This can happen whenever you are connected to the internet - mostly pinging seems to be commercial groups attempting basic info collecting about your computer and interests

  • :goodjob: Love the dictionary definition.

  • Isn't the Internet fun? You can slander people without feeling that the slandered party will eventually read what you wrote and defend themselves! Y'know what's also fun? Google. :)

    I find it interesting that you call me childish, because I see nothing more childish than bellyaching on the internet because you have a false sense that you won't have to be held accountable for your words.

    Well Sir, I am here to hold you accountable. Might I first ask, how much do you know about Network Security or computing in general? Do you read 2600? Do you contribute to open source projects? Do you do anything aside from post slanderous ignorant self-righteous drivel to your xanga blog? Show me proof that you have any right to complain, and I will take your complaints as something more than what I see them as currently: ignorant garbage.

    You go on about me crashing planes and shutting down hospitals as if I am some immoral monster. There is a great deal of difference between such horrid actions and goofing with an unsecured wifi connection at a coffee shop. Do I want your personal data? No, I think I made it clear in my article that I do not...believe it or not, though I am at heart a bit of a prankster, I have my limits. And I find it reprehensible that you would DARE compare me to someone who would do such heinous things. You do not know me personally sir, thus you have no business making any sort of judgement call on what I will or will not do.

    Also, before I finish, I'd like to note one last thing from your little rant: "He may say that he is uncovering the holes in a system so that "bad guys" can't exploit them, but the rest of us say that if it wasn't for guys like him, there wouldn't be any bad guys to exploit us."

    I have never heard such flawed logic in my entire life. Without people like me, you would have absolutely NO defense against the people whom you so fervently describe shutting down hospitals, crashing planes and screwing with stock markets. Would any of you out there know how to defend against a DDoS Attack? What would you do if someone managed to inject a nasty little stored procedure in your company's payroll database that was taking advantage of an arbitrary code execution bug that was left unpatched because a hacker like me never found the bug in the first place, and wasn't there to tell you to sanitize your database inputs so that the stored procedure would get thrown out in the first place. Who do you think develops all the anti-virus programs you use?

    I will sum all this up with a single argument: A cop has a gun...does that mean he will go on a killing spree? If he's corrupt and managed to hide his psychopathic tendencies from a psych evaluation, sure...but generally, he won't. You, a civilian, also have a gun. Will you go on that same killing spree? Again the answer is the same. However, do you enjoy going to the firing range? Do you hunt wild game?

    Hackers are the exact same. We have a skill, what we do with it defines who we are.

  • @tychecat - 

    Your definition of "ping" is a bit off. Ping is just a simple call-and-response. All it does is lets someone know that a given address or host is alive, working, and connected to a network. Having said that, blocking ICMP (Ping) requests CAN be a good idea as ICMP is the backbone for some simple port scanning and enumeration techniques like nmap and netcat. Some better tactics though, would be to simply close off those ports that you don't use, move as many services you DO use to non-standard ports (example if you use SSH or Remote Desktop, move them from port 22 and 3389, respectively, to a random number between 10240 and 65535) and to disable uPnP (Universal Plug-n-Play) on your router, as uPnP can be very easily exploited.

  • @Ryan Draga - I'll address your comments in the order made.  First, you suggest that I may have slandered you.  You apparently don't understand the definition of the word slander.  To meet the requirement of slander, what I said must be verbal, untrue, and must result in irreparable and long-term damage to your reputation.  Neither condition is satisfied.  You did write the mentioned article, did you not.  No need to deny it: it's still up on the internet at DiscoveryNews, and hackers have done damage to systems, have they not.  Some have even been sent to jail.  Other than that, I have not accused you personally of causing any specific damage.  I have merely noted that hackers fooling around in systems where they don't belong can cause harm and cost companies money.

    Second, you suggest that I have a "false sense" that I won't be held accountable for what I say on the internet.  That sir is an unwarranted assumption.  I am well aware that people Google their names all the time.  And by the way, I don't consider your response to my post to be "held accountable" in any way.

    Third, I appreciate your kind attempt to properly address me; however, the most basic of research efforts would have revealed that I am female.  Thus "sir" is not an appropriate form of address.  If you can fail to do even this small research before committing yourself to a discussion with me, how can I expect you to be more careful as you fool around for fun with somebody else's computer systems?  I at least took a look at your resume before writing this response.  Shouldn't you have at least tried to learn something about me before trying so hard to justify yourself?

    Fourth, you want to know what background entitles me to even express an opinion on hacking.  Well, my background doesn't have anything to do with whether or not I can have an opinion, but if you must know, I have an undergraduate degree in computer science and a masters degree in business.  I also have nearly 40 years of continuous experience in computer systems design and software development, as well as indepth knowledge of mainframe and mini computer operating systems.  Some of that experience was paid for by employers who hired people like me to keep people like you out of their systems.  My salary cut into their profits and/or forced them to raise the prices of their goods.  One might say that people like you have robbed them and their customers by the amount of my salary and the funds necessary to support system security in general, not to mention the cost of computing power itself.

    Finally, I find your analogy of a policeman with a gun to be completely nuts.  The policeman is authorized to carry the gun and undergoes rigorous training in their use as well as in the law while hackers don't have either.

Comments are closed.

Post a Comment