Live data from Hacker News

TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

theguardian.com

1–10 of 51 posts

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#2
> TalkTalk said it would only let customers leave without penalty in the “unlikely event that money is stolen from a customer’s bank account as a direct result of the cyber-attack”.

Man, I would hate to get stuck with the carrier that got breached for "bank details and personal information of its four million customers" by a 15 year old kid. That sort of lack of security should in and of itself constitute a severe breach of customer trust and confidence.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#4
I immediately thought of Jonny Lee Miller's character in Hackers, who is caught in a major hack as a child and banned from using computers until he is over 18.

Of course it is now many times more difficult to avoid computers than it was in in the early 1990s.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#5
post #2

> TalkTalk said it would only let customers leave without penalty in the “unlikely event that money is stolen from a customer’s bank account as a direct result of the cyber-attack”. Man, I would hate to get stuck with the carrier that got breached for "bank details and personal information of its four million customers" by a 15 year old kid. That sort of lack of security should in and of itself constitute a severe br…

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, unlike Kiddo over here whose mind will skateboard around the pros leaving them standing.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#6

Imagine what would happen if serious hackers decided to go after this company. Maybe they will implement https this time. The kid exposed a major security problem and overall helped everyone, even the company in the long term.

They didn't use https? That will teach me not to read the article.

Talk Talk are negligent, I hope a newspaper covers that angle.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#7

Imagine what would happen if serious hackers decided to go after this company. Maybe they will implement https this time. The kid exposed a major security problem and overall helped everyone, even the company in the long term.

Unless he turned himself in, he didn't expose a security problem, he exploited a security problem.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#8
post #5
post #2

> TalkTalk said it would only let customers leave without penalty in the “unlikely event that money is stolen from a customer’s bank account as a direct result of the cyber-attack”. Man, I would hate to get stuck with the carrier that got breached for "bank details and personal information of its four million customers" by a 15 year old kid. That sort of lack of security should in and of itself constitute a severe br…

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, un…

Going by Kreb's analysis of the attack [1] it would appear that the breach was a run-of-the-mill SQL Injection attack. Proper security 1-0-1 stuff.

[1] http://krebsonsecurity.com/2015/10/talktalk-hackers-demanded...

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#9
Paul Moore covered their weak security a year ago [1]. Worth a read. I've always avoided TalkTalk because they keep sending me junk mail reminding me that they offer free broadband if I take out a phone package, etc. It just screams race to the bottom.

1. https://paul.reviews/value-security-avoid-talktalk/

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#10
post #5

Earlier quoted context omitted.

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, un…

Going by Kreb's analysis of the attack [1] it would appear that the breach was a run-of-the-mill SQL Injection attack. Proper security 1-0-1 stuff. [1] http://krebsonsecurity.com/2015/10/talktalk-hackers-demanded...

fair enough, though I think the idea that 15-year-olds are somehow to be dismissed as greenhorns is incorrect. We surely have a disproportionate distribution skewed towards the young among the hackerati, even if we take into account the fact that 50+ age groups didn't have computers in their childhood.
Post reply on HN