HZFQ.COM
welcome to my space
X
Welcome to:hzfq.com
Writing | Self Help | Travel | Wines and Spirits | Plastic Surgeries | Advertising | Forums | Banking | Related articles
Search:  
 HOME   An Hour with Kevin Mitnick, Part 2
An Hour with Kevin Mitnick, Part 2
Published by: smith 2008-12-04
This is part two of my conversation with Kevin Mitnick. Part one can be found here.

A Hacker's Point of View

Kevin Mitnick: The hacker mindset doesn't actually see what happens on the other side, to the victim. As a hacker you think "Well, they were kind of naive, they picked easy passwords, I got in, I installed an SSHD Trojan, and when they figure it out all they've got to do is fix the Trojan and change a couple of passwords, so what's that going to take - ten minutes?"

That's how a hacker thinks, but on the other side, now that I work as a security specialist, it's more like "Oh my God! Who is this? What are they trying to do? We have to reload everything, we have to check every system on the network for integrity issues." Now it's a question of integrity — can we really trust our information? So now you're seeing man hours build into tens of thousands of dollars worth of loss in time and productivity. As a hacker you don't think about that.

There's also a question of ethics. As a young boy, I was taught in high school that hacking was cool. My first program was supposed to be written in basic and was supposed to find the first thousand Fibonacci numbers, but I decided I was going to write a program that was a log-in simulator so that when the teacher would go up to the computer and sign us in, it would snarf his password and log him in.

An Analyst’s Handbook::
File Format: Microsoft Word - View as HTMLThe first case, which explains how Kevin Mitnick successfully attacked Tsutomo intrusion-detection should be a part of an overall security architecture.
http://www.si.umich.edu/Classes/540/Readings/Cotter-review-Network%20Intrusion%20Detection.doc
HOME
He would never know. Then I would tell him his password all the time. It was like a cat and mouse game with the teacher. When he finally figured it out and I told him about the program — I also told him that I didn't have enough time to do his assignment — he still gave me an "A".

Today, I'd be expelled, hauled off by the police, and my Mom would be picking me up from the police. Back in the seventies it was more like "this guy's smart, he's gifted, he's a whiz-kid," and I was actually patted on the back for this type of conduct. So the ethic I was taught in school resulted in the path I chose in my life following school.

Q: Do you think either approach is right? The seventies' approach or today's approach?

KM: I think equating hacking with a sort of cyber-terrorism is a bit of overkill, for example there's a new law that says that if you use a computer and cause serious bodily injury or death to a victim you get life without the possibility of parole — because there's no parole in the Federal system — but if you take a hammer or a motorcycle and you kill someone or seriously injure them it's not nearly as punitive. So, why? If the computer is the tool, why is the punishment so harsh? We should punish the person based on the harm they caused, not on the tool they used.

Q: Except that Joe on the street understands a hammer but he doesn't understand the computer, right?

KM: Right. So he's that much more scared of it.

Q: Isn't that one of the problems with legislators getting involved and trying to mandate defenses, because they don't understand the problem?

KM: Well, I'll give you an example. I went to Capitol Hill to testify about identity theft. So these older, people — much senior to me — decided that one of the biggest ways they were going to combat theft is that when you go to a restaurant they were going to make it mandatory that they don't print the whole credit card number on the receipt, so nobody could fish it out of the dumpster. So I'm thinking they're going about this all wrong.

They've got to start thinking like the bad guys. All they need to do is to set up some website somewhere selling some bogus product at twenty percent of the normal market prices and people are going to be tricked into providing their credit card numbers. So what you have to do is think about authenticating credit card transactions more than thinking about obfuscating the credit card number. They just didn't get it. They just don't understand the problem, so they're never going to come up with the solution.

Q: Which is the bigger threat, social engineering or specific technologies?

KM: Both! If the truth be known, you actually use a combination to compromise any type of security controls, where there is the least risk and it's the least costly. For example, Motorola; let's say I wanted to get a copy of the source code for Digital Voice Privacy because I wanted to eavesdrop on the FBI and they use DVP Astro Motorola radios. And I think maybe they made a programming error so the crypto they implemented in this product might not be sound and I could eavesdrop on Federal Agents and that would be fun, right?

So you find a vulnerability into one of Motorola's gateways into their network through a technical flaw. So once there, the hacker wants to know "where is the DVP source code?" So what's the quickest way of finding out? Social engineering, right? So he calls the department and finds out who's working on that project, and that's a lot faster than trying to scour every machine on Motorola's campus. It's a blended attack.

Page 2: Cat and Mouse Game


W3C Advances Specs For Web Interoperability
Bouquets, Brickbats for Microsoft's 'Channel 9'

PRINT Add to favorites
  • how to get the cut tm at pokemon
  • when should i give my newborn son a bath
  • what are some sleepover party games for agers
  • what are your favorite names for kids
  • what do you think of the name jonah for a little boy
  • how many nieces and nephews do you have and what are their names
  • need help with screaming baby
  • call of duty world at war return to gamestop
  • in zoo tycoon how do i remove bushes trees and rocks etc
  • out of these boys names what are your favourites
  • opinion on personal drug use
  • would you call your child lillian
  • do you like the name 039 adolf 039 039
  •  
  • how to open wwe smackdown vs raw 2008 pc game flt exe
  • rate my pokemon diamond team out of 10
  • rate my pokemon pearl team out of 10
  • world of warcraft account how do i sell it
  • do you have a webkinz account
  • in the hospital for something for my baby help
  • my daughter has hand foot and mouth disease she wont eat or drink anything any suggestions
  • what do you think of this girl name
  • how can i play pkmn pearl for no gba also it always appears that i shall remove and reinsert the
  • competitions worth entering i have found a site called compingforfun com au with some awesome comps
  • need a name to go with bailey
  • what do you do when you get bored
  • baby 039 s heartbeat at 8weeks
  • pokemon diamond questions
  • #If you have any other info about this subject , Please add it free.#
    Your name:
    E-mail:
    Telphone:

    Your comments:


    If you have any other info about An Hour with Kevin Mitnick, Part 2 , Please add it free.

    About us -Site map -Advertisement -Jion us -Contact usExchange linksSponsor us
    Copyright© 2008 hzfq.com All Rights Reserved
    Site made&Support support@hzfq.com    E-mail: web@hzfq.com