3 ms·
Right, so it was just as much in their interest as it was in Clifford Stoll's to pretend that this was an international espionage incident?
by neilkk 3y ago
Right, so it was just as much in their interest as it was in Clifford Stoll's to pretend that this was an international espionage incident?
- p_l 3y agoNo, it literally was an international espionage incident. Documented down to money trails, separate "verification" action by soviet agents (who were attempting to verify the data they were being sold), and specific areas of interest. We're talking very early era of internet, barely 3 years after MILNET was separated from ARPANET, and computer security was less implemented than it should be. Which is why such outrageous hack could happen at all.
- th0ma5 3y agoIf your items are stolen from your car, the police officer can't care, but will take the report. If you say you left your doors unlocked, you also get a lecture. No one will welcome or be impressed by any sleuthing on your part. Maybe you can find your stuff, but is it worth the risk?
- p_l 3y agoThis is... an impressively bad analogy. As in it took me some time to even parse if it wasn't by chance something that was supposed to go somewhere else. Maybe if you're dealing with some innocent "looking" by obvious teen on unsecured system it would have a sliver of relation to what was happening. If anything, the biggest issue is that when the events happened, there were no "code of practice" to follow. Officials were even less useful than today. Checking for what the unauthorized access was used is today the basic of basics, and part of that comes from the experiences of what Germans call "KGB Hack". Especially when one works in national lab under auspices of Department of Energy, and traces intrusion (again, something I'd take for granted today, to check which way the attack comes if only to bolster future defenses) to a military contractor. The story probably would have ended there if it wasn't one of the first such cases - today I'd call up appropriate unit and led them lead the way. And even then, sometimes you have to sleuth your way if only to keep the agencies honest, because sometimes the only way to get them actually acting is to publicize what happened so that public starts asking questions. P.S. And I say that as someone who was born on the other side of the Iron Curtain and would be on short list to be vaporized under american policy of "kill as many civilians as soon as possible" P.P.S. Sometimes the police/others will, in fact, quietly mention that they might be interested in more data off the books.
- th0ma5 3y agoThe position of the US government as far as I can tell was that this was such little fish at the time that was the reason they didn't pay much attention compared to the ongoing direct network attacks against more valuable assets.
- p_l 3y agoThe position was that it was new enough they had no idea what to do. Direct network attacks weren't yet a thing, kremvax was still a joke that provoked because just the idea of having soviet machine on the same network was spooky. The direct result in government from "KGB Hack", combined with Morris Worm, was to essentially kickstart the whole Network Security Monitoring and creation of agencies that actually took in network security as core mission. Before, best chance would be that you could try hitting up your friendly neighbourhood fed who was pulling the duty of security officer for your facility. It was pretty damn new that one could connect from as far, and this was still dependant on modem lines. Far cry from the freedom some enjoyed in USA, that if one knew how to phone into a local TIP they could get onto ARPAnet and some places wouldn't ask for passwords at all. Before, the security was more concerned with what you did locally on specific machine, and in some more expensive cases, complex access controls so people could cooperate on files with different permissions.
- th0ma5 3y agoMy original post, and comment, was that the view of the government at the time was everyday boring security principles that we still use today that mirror a lot of physical security principles. The video goes in detail. I'm sorry I thought you had watched that... If you can make time for it I highly recommend it. It doesn't quite gel with the narrative you have... On public cable television networks nationally, in 1989, senior members of the government spent hours discussing this openly and honestly using the same terms we use today while Mr. Stoll was taking amateur, incomplete conclusions to extremes in the tabloid media.
- deleted 3y ago[deleted]
- fabianholzer 3y agoI don't think it was in their interest to incriminate themselves more than to the degree that prosecution was able to proof already.