Live data from Hacker News

TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

theguardian.com

11–20 of 51 posts

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#11
post #5
post #2

> TalkTalk said it would only let customers leave without penalty in the “unlikely event that money is stolen from a customer’s bank account as a direct result of the cyber-attack”. Man, I would hate to get stuck with the carrier that got breached for "bank details and personal information of its four million customers" by a 15 year old kid. That sort of lack of security should in and of itself constitute a severe br…

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, un…

> they compensate for with a fresh, original mind, and nothing-to-lose

And time.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#12
post #5

Earlier quoted context omitted.

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, un…

Going by Kreb's analysis of the attack [1] it would appear that the breach was a run-of-the-mill SQL Injection attack. Proper security 1-0-1 stuff. [1] http://krebsonsecurity.com/2015/10/talktalk-hackers-demanded...

You would be suprised... There are startups out there who say "we don't care about an attack we're too small... we're going to write all of our sql by hand."

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#13

I immediately thought of Jonny Lee Miller's character in Hackers, who is caught in a major hack as a child and banned from using computers until he is over 18. Of course it is now many times more difficult to avoid computers than it was in in the early 1990s.

Samy Kamkar was banned from using a computer for three years in 2006 https://en.wikipedia.org/wiki/Samy_Kamkar#Samy_worm

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#14
post #11
post #5

Earlier quoted context omitted.

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, un…

> they compensate for with a fresh, original mind, and nothing-to-lose And time.

[deleted]

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#15
post #11
post #5

Earlier quoted context omitted.

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, un…

> they compensate for with a fresh, original mind, and nothing-to-lose And time.

but mostly a false sense of invulnerability.

Man, when I think back to the stupid things I did on the internet as a teenager that simply earned me a glare or a stern warning email.... I'm so glad I was a teenager in the 90s, because if I'd done that shit today, I'd be in jail.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#16
post #12

Earlier quoted context omitted.

Going by Kreb's analysis of the attack [1] it would appear that the breach was a run-of-the-mill SQL Injection attack. Proper security 1-0-1 stuff. [1] http://krebsonsecurity.com/2015/10/talktalk-hackers-demanded...

You would be suprised... There are startups out there who say "we don't care about an attack we're too small... we're going to write all of our sql by hand."

Just because they "write all of [their] sql by hand" doesn't mean they will be vulnerable to an attack as simple as this. This is just pure and unmitigated incompetence.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#17
post #5
post #2

> TalkTalk said it would only let customers leave without penalty in the “unlikely event that money is stolen from a customer’s bank account as a direct result of the cyber-attack”. Man, I would hate to get stuck with the carrier that got breached for "bank details and personal information of its four million customers" by a 15 year old kid. That sort of lack of security should in and of itself constitute a severe br…

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, un…

> because greybeard's IT stack and MO is entrenched, conventional, and defendable-against

this is utterly ridiculous

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#18

Earlier quoted context omitted.

Going by Kreb's analysis of the attack [1] it would appear that the breach was a run-of-the-mill SQL Injection attack. Proper security 1-0-1 stuff. [1] http://krebsonsecurity.com/2015/10/talktalk-hackers-demanded...

fair enough, though I think the idea that 15-year-olds are somehow to be dismissed as greenhorns is incorrect. We surely have a disproportionate distribution skewed towards the young among the hackerati, even if we take into account the fact that 50+ age groups didn't have computers in their childhood.

I totally agree. The stuff I myself was doing at 15 was more sophisticated than the "security consultants" I talk to professionally even consider.

At that age you have intelligence, lack of considering consequences and importantly lots of time. That's a dangerous combination.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#19
post #5

Earlier quoted context omitted.

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, un…

> because greybeard's IT stack and MO is entrenched, conventional, and defendable-against this is utterly ridiculous

What is ridiculous about it? I have been coding for 30 years and am happy to pronounce that younger coders have a far more nimble mind than me. I'll destroy them on complex software engineering but I'm constantly impressed by their innovations. Anybody who finds this "ridiculous" is either a rare evergreen genius, or more likely, self-satisfyingly complacent.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#20
post #12

Earlier quoted context omitted.

Going by Kreb's analysis of the attack [1] it would appear that the breach was a run-of-the-mill SQL Injection attack. Proper security 1-0-1 stuff. [1] http://krebsonsecurity.com/2015/10/talktalk-hackers-demanded...

You would be suprised... There are startups out there who say "we don't care about an attack we're too small... we're going to write all of our sql by hand."

It's not just startups. The stuff I've seen at some very large companies would make you cringe.

As a colleague developer of mine says: I don't want any of my personal information on the internet because I know how developers think.

Sigh.

Post reply on HN