7 ms·
ATT dumps Kevin Mitnick
- radu_floricica 17y ago20k per year? He's doing something wrong...
- hedgehog 17y agoIt's easy to run up long bills if you roam internationally, $3/minute adds up fast.
- irinotecan 17y agoThat's why you get an unlocked phone and buy an international SIM chip that you swap in overseas. $20K/year is ridiculous, and probably an exaggeration or lie on his part to try to make himself look like a desirable customer.
- pmjordan 17y agoExcept you also incur roaming charges for receiving calls, and expecting people to call an overseas number (let alone keep them up to date on your whereabouts) really is pushing it.
- tlrobinson 17y agoSo AT&T is basically admitting their approach to security is "security through obscurity"? As long as you're not a high profile celebrity you should be ok because not one wants to own you...
- roundsquare 17y agoWell, they are admitting that their security system isn't flawless. Having Kevin Mitnick using your service is the equivalent of asking to be hacked by a particular set of people... eventually your security will get broken. Which is not to say that AT&T has good security, all we can tell from this is that it can be broken...
- three14 17y agoSecurity through obscurity gets a bad rap. You rely on the "obscurity" of your password. The main issue is relying on false obscurity, both in systems (your program rot-13s your password) and in passwords (you pick an easy to guess password). There's no real security failing if you rely on obscurity that isn't exactly a password, so long as you can accurately assess the real obscurity, e.g. port knocking. If, let's say (and this is probably false) AT&T has a billing system where sending 100 specific, not-easily-guessable bytes allows you to get private data, that's no worse than a password, even if the reason that it works is a bug - unless the source code is available to the attacker. Of course, AT&T's problem here isn't obscurity, it's that they don't want to invest enough for real security at all. Which could be reasonable from a business perspective.
- Locke1689 17y ago"You rely on the "obscurity" of your password." Not really. Your password may be obscure (although it should probably be as random as you can get), but the key exchange protocols and encryption algorithms should be wide open. There's a reason why secret keys are called "secret" -- they should be the only thing you have to keep secret. If his hosting provider and wireless company can't keep his accounts secure, that's their problem, not his.
- three14 17y agoReading my comment over, I realize that I wasn't so clear. There are two almost unrelated issues: AT&T has poor security - agreed. Security through obscurity is a universal evil - not so fast. Quick example - you have ciphertext where you don't know the key vs. the same ciphertext where you don't know the key AND you don't know the algorithm. The latter is more secure, because it's harder to brute force. The reason security through obscurity is usually bad is because it causes people to make poor assumptions - "He'll never guess I encrypted it with rot-15 instead of rot-13," but for a given secure system, adding obscurity will make it harder to break. But it's the poor assumptions that do you in, not an inherent flaw in adding obscurity. The reason you use widely published encryption algorithms is because they've been vetted for poor assumptions. They need to be open to be vetted, not to be secure, and we've found that's always been a good tradeoff.
- travisjeffery 17y agoAn 8 digit, all numerals password? Really, Mitnick? Also, it wasn't just AT&T that is refusing service to him, his webhost HostedHere.net did the same thing. And if this has been happening over and over again for 9 years why didn't he just want to go to another service provider?
- ErrantX 17y agoIndeed. Other providers host and maintain the security of as-high-profile "targets". More importantly you have to question how much of the security problem Mitnick poses in this? If he is part of the cause I think AT&T & HostedHere probably are reasonable to want to get rid of him (btw I suspect the 8 numeral password is a pin number: similar to the ones handed out by banks for online logins. Could still be his fault it is out in the wild though)
- fauigerzigerk 17y agoHow is it reasonable for AT&T to admit blatant incompetence? Couldn't they have worked with Mitnick to secure his account and even use his case to attract more celebrity customers?
- ErrantX 17y agowell we have no specific information on any of the problems (plus Im a little biased personally in that Mitnick seems to be in a habit of loudly crying foul no matter what - I do that sometimes because it gets results, takes one to know one) It's been 9 years (we dont even know how much of it is AT&T vs. Mitnicks fault and what contact he has had with them): it's looking like an infinite battle to "secure" his identity. If there are crucial security flaws in their process then yes I am in agreement - but I doubt that is the case (because Mitnick would then be the least of their problems :)). Wash hands, move on.
- dundun 17y agoIt's probably just a business decision. (assumption)They can provide cell phone service for 1000 people for the same cost as Mitnick since he is a target. It's the same thing Sprint did a couple years ago when they dumped people that called customer service too much.
- peoplerock 17y agoA service provider whose top priority was security could have taken another approach to KM... using him like the canary in a mine shaft, an indicator of problems with their security system (allowing all-numerals password would be just one example of such a problem that ought to be fixed).
- jacquesm 17y agoI find Kevin Mitnick going to the authorities for protection a little bit weird. If your claim to fame is that you are the 'worlds baddest hacker' you take the script kiddies as going with the territory. It's like Billy the Kid complaining about the wanna-be's that want to meet him at noon on main street. "The move by AT&T came this week after Mitnick hired a lawyer to complain that his privacy was being invaded by people posting Mitnick's account information in public hacking forums" You need a lawyer to complain these days ? Most other 'celebrities' have these issues but being a high profile hacker makes you a great target. The best defence against this is don't get caught hacking... that way your privacy stays yours. What Mitnick should do is give tit for tat, expose the identities of his attackers. For such a hotshot security consultant (all digits?) that should be a piece of cake, really. That said, AT&T has no business cutting him off, rather the opposite, they should secure their systems and use the publicity surrounding this to brand themselves as the provider that is good enough to secure even Kevin Mitnicks account.
- davidw 17y agoHe did his time, and now he has the same right to protection as the rest of us.
- jacquesm 17y agoSure, but if you are a 'master burglar' selling your services to companies securing other peoples goodies your reputation as a 'master burglar' is what allows you to do that. It means that a lot of people that you are putting down will see you as their prime target. This goes with the territory. If KM would have taken a job as a programmer somewhere I highly doubt that this would have happened. After all, he is minting his reputation as a former bad guy, nobody forced him to do that. If he had been a white hat all along it would be different, but a burglar complaining he's been burgled is a bit hypocritical imo. I guess it sucks being on the receiving side. Basically all these little jerks do is make him look silly, personally I wouldn't even bother to respond to them, just take it as praise and laugh at it. By taking it so serious he is actually fanning the fire.
- 17y ago
- pmorici 17y ago"In recent years, he's committed the password to memory and has deliberately not shared it with anyone or kept it stored on a computer." Isn't that what everyone is supposed to do with their passwords?
- Tichy 17y agoWouldn't such a customer be worth gold? A single user that constantly get's attacked by hackers would provide a great opportunity to detect and fix security holes. If a hacker get's through, it is just one person's account compromised. But each detected attack could prevent attacks on other accounts. I think some other telco should pay Mitnick to become their customer. How else could you attract so many hacker brains and make them work on finding security flaws in your system?
- sketerpot 17y agoIt also keeps the hacking attempts more-or-less contained to a single known user's account. Handy!
- wmf 17y agoA single user that constantly gets attacked by hackers would provide a great opportunity to detect and fix security holes. Assuming that they want to fix the holes, which AT&T probably doesn't. They may be using the "infinite bugs" model, in which fixing one bug does not improve security because there are always other bugs the attackers can find.
- Tichy 17y agoBrilliant - an infinite number of bugs might confuse hackers so much that they don't know where to start and just give up.