Live data from Hacker News

TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

theguardian.com

41–50 of 51 posts

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#41

Earlier quoted context omitted.

try Reddit. Your (zero insight) posts are not constructive here.

If it was my job to penetrate remote systems, you can bet that I wouldn't still be using the same stack and MO I was 30 years ago, in the just the same way that I'm not using an Amiga. The OP is ridiculous that it cannot be imagined that someone needs to be a child to break into systems. I'm at University and I run rings around my 20 something cohort.

The point is not that one needs to be a teenager ("child") to break into systems. None of what I have said is incompatible with the assertion that older coders have more skills, a point with which I agree. However it is not a contradiction to say that innovation does not require huge experience, and indeed is sometimes hampered by it.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#42
post #5
post #2

> TalkTalk said it would only let customers leave without penalty in the “unlikely event that money is stolen from a customer’s bank account as a direct result of the cyber-attack”. Man, I would hate to get stuck with the carrier that got breached for "bank details and personal information of its four million customers" by a 15 year old kid. That sort of lack of security should in and of itself constitute a severe br…

Not sure that 15-year-old kids are any less competent at hacking than adults. What they may lack in experience, they compensate for with a fresh, original mind, and nothing-to-lose. We've seen this picture many times before. I'd suggest that TalkTalk would be less competent if the hacker had been a greybeard rather than a kid, because greybeard's IT stack and MO is entrenched, conventional, and defendable-against, un…

15 year olds also have a hell of a lot of time to invest in whatever takes their fancy. Never underestimate the single minded focus of an inquisitive teenager!

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#43

Earlier quoted context omitted.

If it was my job to penetrate remote systems, you can bet that I wouldn't still be using the same stack and MO I was 30 years ago, in the just the same way that I'm not using an Amiga. The OP is ridiculous that it cannot be imagined that someone needs to be a child to break into systems. I'm at University and I run rings around my 20 something cohort.

The point is not that one needs to be a teenager ("child") to break into systems. None of what I have said is incompatible with the assertion that older coders have more skills, a point with which I agree. However it is not a contradiction to say that innovation does not require huge experience, and indeed is sometimes hampered by it.

I still stand by my original assertion :

> because greybeard's IT stack and MO is entrenched, conventional, and defendable-against

this is utterly ridiculous

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#44
post #38

Earlier quoted context omitted.

When you combine the potential lack of punishment for juveniles with the biological reality that prefrontal cortex development in adult humans doesn't really complete until the mid twenties, you get teenagers who don't think bad outcomes are possible, and whose brain is less capable of long term risk assessment. I would think that the 50+ crowd would be far more hampered by their risk assessment of the negative outco…

So they're less risk averse even if they're less competent. Probably right. Though I think there's also something intellectually liberating about having no risk constraints, which might allow for attack vectors that are unconventional.

What you should be really afraid of is 50 year olds without risk aversion. Like the decision-makers at banks, politicians who will never personally go to war or the welfare line, etc.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#45

Paul Moore covered their weak security a year ago [1]. Worth a read. I've always avoided TalkTalk because they keep sending me junk mail reminding me that they offer free broadband if I take out a phone package, etc. It just screams race to the bottom. 1. https://paul.reviews/value-security-avoid-talktalk/

>free broadband if I take out a phone package //

Monthly phone has been about £18-22 per month for a few years, whilst broadband has been Once you have the broadband they heavily push their TV packages.

Yes it's a race to the bottom but for POTS with broadband everything beyond your home socket to their servers is the same as with any other standard provider AFAICT.

They don't appear to do that much for their av.package x ~4.3 Million customers per month gross income; there should be considerable competition at the low end for what is essential a commodity.

WRT the review, I wouldn't use an ISP for my email provision but that's based primarily on lock-in; the company have https for their account pages and such (the Thawte cert is dated April 2014 FWIW).

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#46
post #32
post #28

Man, I have some real cognitive dissonance when it comes to physical versus cyber crimes. If someone were to leave their car unlocked then have items stolen out of it, I would find the criminal despicable; people make mistakes and don't deserve to be robbed for it. When a company leaves its data vulnerable and someone steals from it, I find the company despicable, as if they were "asking for it". Apparently the hacke…

There are two crimes. One is theft, the other negligence.

Negligence in this incident is a civil issue, not criminal.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#47
post #46
post #32

Earlier quoted context omitted.

There are two crimes. One is theft, the other negligence.

Negligence in this incident is a civil issue, not criminal.

Please take a moment to actually read the Data Protection Act 1998.

http://www.legislation.gov.uk/ukpga/1998/29

75 matches for 'offence' on that page.

Sections 61 and 47 are particularly relevant. European data protection legislation really does have teeth, though the Commissioner has to have the will to use it.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#48
post #28

Man, I have some real cognitive dissonance when it comes to physical versus cyber crimes. If someone were to leave their car unlocked then have items stolen out of it, I would find the criminal despicable; people make mistakes and don't deserve to be robbed for it. When a company leaves its data vulnerable and someone steals from it, I find the company despicable, as if they were "asking for it". Apparently the hacke…

It's more akin to a bank not protecting their clients assets. It doesn't make the robber less of a criminal but doesn't make it ok for the bank.

Perhaps class actions against negligent companies with big payout would push their insurers to breath down their neck and would result in better security.

But make no mistake, the #1 problem is incompetence among developpers. I am sure it's not a direct order from the CEO to code in a way that leaves them exposed to sql injections. It doesn't cost more money to use a parameterized query. It's just that so many people call themselves developpers and simply just don't have a clue.

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#49
post #7

Imagine what would happen if serious hackers decided to go after this company. Maybe they will implement https this time. The kid exposed a major security problem and overall helped everyone, even the company in the long term.

Unless he turned himself in, he didn't expose a security problem, he exploited a security problem.

He exploited and exposed it

Re: TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland

#50

Earlier quoted context omitted.

The point is not that one needs to be a teenager ("child") to break into systems. None of what I have said is incompatible with the assertion that older coders have more skills, a point with which I agree. However it is not a contradiction to say that innovation does not require huge experience, and indeed is sometimes hampered by it.

I still stand by my original assertion : > because greybeard's IT stack and MO is entrenched, conventional, and defendable-against this is utterly ridiculous

I stand by my original assertion:

> this is utterly ridiculous

A vacant comment devoid of insight, by a self-satisfied person oblivious to their predisposition to complacency.

Post reply on HN