5 ms·
How to Learn Hacking
- FLUX-YOU 12y agoIn case readers were interested in security: http://data.langly.fr/blackhat http://data.langly.fr/blackhat
- rifung 12y agoThanks!
- fabulist 12y agoThis guide is very hand-wavey. Tor alone is a poor operational security strategy; using nikto and unix-privesc-check does not a hacker make. This may be a decent place to begin one's inquiry, but don't let it end here too. Here are some talks I recommend: Tricks for Defeating SSL in Practice - Moxie Marlinspike https://www.youtube.com/watch?v=MFol6IMbZ7Y https://www.youtube.com/watch?v=MFol6IMbZ7Y OPSEC: Because Jail is for wuftpd - thegrugq https://www.youtube.com/watch?v=9XaYdCdwiWU https://www.youtube.com/watch?v=9XaYdCdwiWU
- hagmonk 12y agoI can't see myself recommending this guide to anyone. A few things stand out: - the invitation to "go away" if you confuse ESR's definition of hacking with the definition the general public uses. - the suggestion that hacking is something for those with above-average talent for programming. Perhaps you should keep reading if you count yourself as above average? - the proposal of a system for learning how to hack that is apparently so robust that it is self-evident. No examples need be brought in to support this proposal, nor does it need to defend itself from alternative systems. - it is suggested that hacking is the only way for software architects to train their design sense. Ok, sure. The biggest problem I have is that the vast majority of ESR's suggestions are really good ones. I agree with plenty of things he's saying. I just wish, like many open source products, it was packaged in a more digestible fashion, so I could recommend it to less experienced friends.
- titanomachy 12y agoMaybe some of this is a matter of interpretation. * to me, his opening line means that you should "go away" if your reason for reading this article was to learn how to commit cybercrime * "above-average" could also be interpreted several ways. Perhaps most programmers have an above-average talent for programming, which is part of what attracted them to it in the first place? In this interpretation, the people who have below-average talent give up and choose to do something that they are talented at.
- notduncansmith 12y ago> Perhaps most programmers have an above-average talent for programming I believe "average" was in the context of all programmers, not all people, making this logically impossible.
- cinquemb 12y agoI think I agree to some degree, but I think I would still recommend this to a friend if they asked about something related. At best, at least for me, I think it would be nice to have a process for someone who hasn't figured out what works for them best, so they can at least be knowledgeable of and refer to a way of approaching a task they want to achieve if they feel like they don't have one. And at worse, it would save me time trying to codify my way of doing things and trying to tailor it to who is asking. It was also kind of interesting reading this, and thinking "this process seems too rigid for me", as I was thinking about how yesterday I decided to hack at firefox's http client and set the user agent based on the current most popular user-agent field from the public data released by companies like statcounter or the most frequent user agent sent over a local network while at the same time thinking, "if I followed this more closely I could have saved some time in some places".
- navait 12y agoI think this guide has a good place for children who are interested in computers and get in trouble for messing with their schools network. Many of these kids will have absorbed media which does not really understand the diffrence between being a software engineer and breaking into computers. They may not know about the FOSS/unix world. I think giving this to them would do them a lot of good. My main problem with it is that ESR is unable to differentiate between being a good programmer and being ESR. Really what we need is a guide written by a prominent member of the FOSS community who can show budding programmers what's out there in modern FOSS(this was written in 1996) without couching it in language designed to sate the author's ego.
- hartator 12y ago> If you think “hacking” has anything to do with computer crime or security breaking and came here to learn that, you can go away now. There's nothing for you here. This. I don't think the author realizes that the reality out there is complex. You can "hack" for "good" or for "bad". Open-source is about not putting a moral judgment about what you want to achieve.
- notastartup 12y agoso how are people coming up with zero-day vulnerabilities all the time? How are these people able to find a way to inject code in pdf or word documentation year after year? Is software forever vulnerable, even ones written by huge number of engineers?
- rifung 12y agoI imagine having a huge number of engineers actually increases the chances that software is vulnerable. This is because bugs often arise when different people are making different assumptions about what some code does or doesn't do. It always makes me uneasy when I have to go and make modifications to other people's code, especially in the workplace where you usually don't have the luxury of time to fully understand the code base.
- eru 12y agoWhat does this have to do with the article? Btw, if you want secure software, you better prove it correct. See eg http://sel4.systems/FAQ/#verif http://sel4.systems/FAQ/#verif
- harry8 12y agoThis is from the man who wrote a "how to sex" no really, it's here if your eyes can stand it. http://www.catb.org/esr/writings/sextips/bedplay.html http://www.catb.org/esr/writings/sextips/bedplay.html
- noname123 12y agoI read it without consideration about the author. Overall I thought it was good general information and took note of the sincerity of the tone to urge readers to snuggle "post-coital esp. with virgin". Was expecting more diving into kinky human sexuality but perhaps seems more like the author is trying to educate the basics to us his brethren.
- eanplatter 12y agoHe also wrote The Cathedral and the Bazaar if I'm not mistaken. If that can balance it all out.
- simi_ 12y ago> catb.org It took me a while to get why the site's named that way, too.
- cosarara97 12y agoWhy is the site named that way?
- simi_ 12y agoCatb - cathedral and bazaar :) Unless I am embarassingly wrong.
- lookACamel 12y agoAnd what exactly is so bad about his advice?
- Goldenromeo 12y agoHow to become a Hacker http://www.catb.org/~esr/faqs/hacker-howto.html http://www.catb.org/~esr/faqs/hacker-howto.html
- Goldenromeo 12y agoSame guy but content is different
- _tb 12y agohacking is a style of programming, hacking is being a cool start up guy, hacking is being a computer wizard, hacking is X, hacking isn't Y. why some people keep trying to use the word hacking for what they do no matter what, it's because it sounds cool?
- krapp 12y agoThey're hacking hacking.
- bottled_poe 12y agoIn particular, hacking seems to be about doing things that are not by-the-book. So...how can it be learned?
- gtop 12y agohttp://paulbuchheit.blogspot.ca/2009/10/applied-philosophy-aka-hacking.html http://paulbuchheit.blogspot.ca/2009/10/applied-philosophy-a... This is good too by Paul Buchheit.
- stillsut 12y agoWhen not open-source is okay: Basically hardware. Say you're trying to create scientific image proc for an an off-the-shelf smartphone. The following review of the 40MP android nokia shows the debate. http://www.cnet.com/news/the-secret-behind-nokias-41-megapixel-camera-phone/ http://www.cnet.com/news/the-secret-behind-nokias-41-megapix... The key point takeaway for me is how you create cheap consumer level electronics with a research team behind it. (Hint - Nokia's investment in R&D depends on them expecting to get lots customers) Con: There is contention that this order of magnitude increase in pixels is not useful to image quality. And proprietary algo's on embdeded hardware in the camera module (7px "sampling" -> 1px "stored") is not available. Pro: In some cases, there is contention that this innovative smartphone camera increases signal to noise ratio, so maybe we live with the black-box of the hardware to get better images downstream. And if "gimmicks" like this huge camera sensor sell units, we can expect more cheaply available units for mass deployment of the hardware/software. -> Thus for hacking we're riding the wave of mass adoption of what we're once esoteric technologies - high-end digital image sensors.