4 ms·
I hate to say it, but maybe you should tone it down a little bit on your Twitter account. People are always going to Google your name when your resume comes in.
by CanSpice 12y ago
I hate to say it, but maybe you should tone it down a little bit on your Twitter account. People are always going to Google your name when your resume comes in. Odds are they're going to find your Twitter account. Odds are they're going to find tweets like "Seriously tempted upload a sql.tar.gz that's just an archive full of obscene furry porn from the deepest trenches of fchan's /ah/ board."
If I was an employer and I saw a job applicant tweet something like that, their resume would immediately go in the shredder.
Think about it from the employer's point of view: "What happens if this guy is disgruntled with us for some reason? Is he going to joke about something that'll embarrass us? Maybe he'll turn our website into an archive of obscene furry porn?" Given you're tweeting things like that, why would I hire you?
(and yes, I know that that tweet's referring to the previous "HEAD /passwords.txt" tweet, but it's incredibly easy to take things out of context on the internets)
- tptacek 12y agoThis is not bad advice either.
- sarciszewski 12y agoThat's a fair point.
- 300bps 12y agoI've spent about 10 minutes reading articles from OP and I have to say he comes across poorly. To be very blunt, OP you come across as a jerk. The funny thing is I'm naturally sympathetic - I don't think what you did is even a crime! For examples: https://scott.arciszewski.me/blog/2014/03/black-and-white-2600-article https://scott.arciszewski.me/blog/2014/03/black-and-white-26... The total "intrusion" lasted only 23 minutes, according to court documents. I'd be concerned if someone intruded into my computer for 23 seconds. Attempting to minimize what you're accused of with statements like this will likely turn people against you. As usual, the game was rigged, and I lost Sometimes introspection allows us to see that we legitimately lose; that things aren't always rigged against us. It also lets us see that our attitude can be our own worst enemy. My last semester was erased (which screwed up my taxes for the next year and is probably illegal) "Woe is me" doesn't play well when you are experiencing the negative consequences of having committed an alleged crime. Also don't accuse others of illegal activities unless you can prove them; it destroys your credibility. For the digital equivalent of knocking on someone's front door, it swinging ajar, looking in, seeing nobody home, going on my way, and then being put on house arrest Again, you're minimizing what you did. A more apt analogy based on your own description of what you did would be coming up to a locked door, seeing it is Brand X locks, purposely seeking out an exploit on how to pick Brand X locks, spending time picking the lock and then broadcasting to the world what you did. I could go on, but the summary is that being a humble and contrite person will often allow a guilty person to go off scot-free. When I was arrested for hacking, that's what happened to me and I was literally let go with no record. On the flip side, rightly or wrongly coming across with a negative attitude can help an innocent person go to jail. Fair or not, that's the world we live in.
- tptacek 12y ago"runner up: Not using Tor, an overseas VPN, or an SSH tunnel when I knew how" wasn't a particularly great thing to say here.
- sarciszewski 12y agoThe number one response I hear from infosec people (which was the intended audience of 2600) was, "Dude, you should've used a proxy!" I recognize that failing to do so was reckless and stupid.
- danielweber 12y agoNo, talking about one your biggest regrets being "getting caught" is a problem today. The textbook example of someone who isn't sorry for what he did is that he explains his mistakes as "I got caught."
- sarciszewski 12y ago@danielweber: I think it's very easy to misconstrue what I'm saying for "I regret getting caught". My point is that I knew how to hide, but didn't, so anyone who calls me stupid for not doing so is correct. Poor risk management.
- tptacek 12y agoNo, I'm saying it was a bad idea to talk about what you did wrong to get caught. It creates the perception that you think exploiting flaws in someone's site without permission wasn't the big thing you did wrong. Which, you can believe that or not, but in terms of mitigating risks perceived by employers, not creating that impression should be your #1 priority.
- alt2319 12y agoWell he was kind of railroaded by a law that sucks. $9,000 in damages by planting 3 files on a website? Worse, it's impossible to argue intent / mens rea in these cases. It doesn't matter if your intent was to cause no damage because the crime isn't defined by the damage but by the access. As long as you intended to access the internet-connected device, and knew you were exceeding your permitted access, you're guilty. The "damage" doesn't have to be intentional. The opportunity is gone now, but I really wish he'd fought this case and gotten it in front of a jury. It's very technical testimony and I think a jury could really question the damage amount. If it were below $5,000 this law doesn't apply. How much did it really cost? They had to delete 3 files and apply patches that they should have applied all along. It's also just weird how punishment scales work. I used to go to my probation officer's office and see all the other guys he was monitoring. Most were serious drug dealers or weapons violations. It seemed so out of whack. But then when I'd go do community service I'd see people sentenced to 20 hours of community service, hundreds of dollars in fines, and weeks in jail for crap like shoplifting a 99 cent air freshener or a pack of cigarettes.