4 ms·
OK, so for the remaining 3 people out there who were pathologically not paying attention, computer hacking is easy. The state of computer security is poor. Lulz
by trotsky 15y ago
OK, so for the remaining 3 people out there who were pathologically not paying attention, computer hacking is easy. The state of computer security is poor. Lulzsec deserves a medal and a chest to pin it on for breaking this news to all of the people who don't have a facebook account, have never been on irc, didn't see the movie wargames, don't know anyone who plays world of warcraft, has never read the new york times, has never heard of china and has never heard anyone utter the word "stuxnet".
For the rest of us, it's pretty tedious.
There's another situation that fits the general parameters of what they describe. Almost no one is protected against it. Being a gunshot victim.
At least in the US, pretty much anyone can get their hands on a handgun either legally or illegally. Almost anyone can use one with a bare minimum of instruction. And almost no one is protected - if you pick a name out of a hat of all america, pretty much any possible outcome will be dead easy to track down, stalk, find the right opportunity and shoot dead. And a vanishingly small numbers of shooters make an announcement about the whole incident on the Internet.
But, all that said, if you go around shooting people for no real reason and bragging about it you're assuredly a psycopathic asshole.
- daeken 15y agoBeing a victim of a random person with a gun with no particular affinity for shooting you isn't easily avoidable; being a victim of a random person with Burp Proxy and a couple hours of work is. That's the key difference here. Security is hard, but we have great processes to make things secure and keep them secure against all but the most dedicated attackers. Mind you, these processes aren't perfect. Things fall through the cracks, and effectively nothing will keep out a significantly determined attacker, but that doesn't mean you shouldn't follow well-established security methodologies. In the vast majority of cases, they hold up well. Edit: I want to note that, in all likelihood, no amount of secure development and review would've kept people out of Sony -- there were just too many people that wanted to attack them, and too large an attack surface. It could've diminished the number of successful attacks, and it could have reduced the amount of data stolen, but in all likelihood attackers would've still made it in to some extent. However, things like the Brink attack might have been stopped entirely, since they didn't seem to be terribly determined to get in.
- sunchild 15y agoHonestly, I'm more worried about companies like Citi allowing users to change the uid param in the URL to access someone else's account data than I am about kids in it for the lulz.
- trotsky 15y agoWe must have a different definition of easily avoidable. The truth is that organizations that spend a much larger than average portion of their energy and resources on computer security can and do still fall the victim to intrusions on a regular basis. Outfits that follow generally accepted best practices get successfully spearphished on a weekly or monthly basis. Startups are encouraged by the industry to throw up websites in weeks, yet the tools they're given largely do very little to prevent them from shooting themselves in the foot on a regular basis. Lulzsec isn't even calling their shots. They're casting around for security issues widely without rhyme or reason. You're supposed to lock your front door, but if you go through a neighborhood and try everyone's front doors you'll always find one that's left open. Now imagine your neighborhood is the world. It's literally impossible that you'll ever run out of victims. The truth is that computer security isn't shit because all the noobs out there that don't have a CSO, don't hire matasano, don't have sufficient change review policies, don't have a 24x7 ops team with live instrumentaion and don't have DDOS protection are id1ots. Sure, any one of them can be pointed and laughed at and said they're losers. But taken in aggregate, it's not all their 30,000,000 individual failures, it's a failure of the computer industry that has long pushed speed and ease over safety and continues to sweep the current security environment under the rug. And also a failure of our own security industry for selling ineffective, labor intensive solutions and pricing most of the rest beyond the reach of most potential customers. And I dare say that Lulzsec isn't going to have much of an impact on any of that.
- mattmanser 15y agoTo be frank your point is bordering on meaningless, you've jumped from anyone can shoot someone to it's all a failure of the computer industry. I find the first assertion idiotic and the last begging the question. patio11 made a similar point about armed robbery, I mean seriously, what is wrong with you? It's fucking stupid. If someone gets shot a lot of cops will turn up within minutes. They'll devote a lot of manpower to it. In some of your states the perpetrator will be executed. There's a response. There's a massive immediate manhunt. Will people stop idiotically claiming that a serious, sickening crime is anything like hacking someone's server please? And to get back on topic, if someone gets hacked it's brushed under the carpet if possible if it's even noticed. People aren't even checking if it's happened. Where's the abnormal activity alert built into windows or linux? Or Apache or IIS?
- dexen 15y agoThe gunshot analogy fails hard. LulzSec pre-empted at least half of it, by stressing how harm occurs quietly all the time. Data gets stolen or destroyed and we just don't know it. Unlike gunshot wound, where a person lands in a hospital, or morgue, or goes missing, data can be, and indeed is, copied quietly. Of gunshots, people are informed most of the time; of security breaches, barely ever. Cops investigate most gunshots, but do they know of most security breaches? The big hope is the press will at last start paying attention to (in)security of our data. Thus the headline-grabbing tactics. The other half is that corporations don't shoot people, people shoot people. And to the wit, people don't store 200.000 bank accounts on a web server, corporations do. You can -- and should -- hold corporations to a somewhat higher standard when it comes to affording decent protection for customers. It's no coincidence LulzSec weren't after granny-loves-her-cat blogs, but after commercial services.
- rgbrgb 15y agoCorporations most definitely shoot people... http://en.wikipedia.org/wiki/Military http://en.wikipedia.org/wiki/Military
- deleted 15y ago[deleted]
- hugh3 15y agoThis is what I mean when I say that bad conversation drives out good.
- dazmax 15y agoExcept they didn't say that they are doing this to bring attention to security issues. They are doing it because they can, and because it brings them some entertainment – that's the point the gunshot analogy was addressing. They only bring up all the silent malicious hacking that happens as an argument that we shouldn't care so much about what they're doing.
- natural219 15y agoNone of this addresses the DDoS attacks. I agree with you in regards to the SQL injections / URL parameters, but your post fails hard to defend Lulzsec's DDoSing of anybody.
- 127 15y agoI don't see that analogy working very well. It's not about shooting single people. It's about banks building their vaults using cardboard and paper, instead of concrete and steel. It's just not that smart.
- hnsmurf 15y agoAs I mentioned below it does very much show psychopathic tendencies. These people clearly have no empathy for those they are harming. This includes far more than just the Sony executives that everyone hates (despite not knowing). Online security is poor for the same reason airport security is. Good security would take enough time and money to make the whole thing economically unviable.
- redthrowaway 15y ago>Online security is poor for the same reason airport security is. Good security would take enough time and money to make the whole thing economically unviable. Airport security in the US is poor because the policies are a series of politically convenient patches applied to a broken system. In Israel, where the threat of terrorism is far greater, their airport security is both much more effective and much less invasive. Why? Because it was designed to work, from the ground up. They don't hire legions of idiots at minimum wage or close to it to do their security. They hire ex-military and ex-mossad people to surveil travellers. They have highly-trained people who know how to spot potential terrorists, and multiple layers of security (usually just someone saying hi and engaging in light chatter) that catch the vast majority of problem people before they get anywhere close to an airplane. The US system is expensive, invasive, and ineffective. That doesn't mean airport security in general is doomed to fail, it means the US is incompetent at it.
- afterburner 15y agoIf my data was stolen, I'd be annoyed, not dead. And the law, and enforcement priorities, reflect that.