Live data from Hacker News

A hacker's mom broke into a prison and the warden's computer

wired.com

71–80 of 99 posts

Re: A hacker's mom broke into a prison and the warden's computer

#71
post #21
post #13

Earlier quoted context omitted.

Is it wrong that I find it a terrible thing that people aren't allowed computers with internet or cellphones in prison? How do we expect people to join back to society when they can't use literally the number one most important thing? Maybe give them phones with no cameras and monitoring of use, but just nothing seems very inhumane.

In the US sometimes the evidence isn't clear that facilitating "join back to society" is an actual goal (it's often a stated goal). It often doesn't seem to be a policy priority.

Why would it be, when your donors are the private prison owners?

Re: A hacker's mom broke into a prison and the warden's computer

#72
post #13

Earlier quoted context omitted.

Is it wrong that I find it a terrible thing that people aren't allowed computers with internet or cellphones in prison? How do we expect people to join back to society when they can't use literally the number one most important thing? Maybe give them phones with no cameras and monitoring of use, but just nothing seems very inhumane.

> Is it wrong that I find it a terrible thing that people aren't allowed computers with internet or cellphones in prison? I also think they should be allowed to grow their own weed.

Alright, Rick.

Re: A hacker's mom broke into a prison and the warden's computer

#73
post #67
post #63

Earlier quoted context omitted.

Many physical pentesters have gotten into places where they didn't have requisite deep domain knowledge because they can research particulars or just rely on regular social engineering. If someone is able to breach a prison without the deep domain knowledge, then it's not actually that important. It's good for demonstrating the damage an insider threat could pose. This article doesn't have a comparison engagement wit…

Depends on where you’re looking. Companies like the one in the article are not going to be in a position to do a lot of staff development unless they have no other choice..you need to be able to hit the ground running in many cases. Depending on what experience you do have you might find good luck in hiring on at larger firms like insurance, financial, healthcare where they are going to need in-house staff and can ma…

I personally am going back to a dev job. It pays better and there's work to be done (incl. security). I got OSCP and 5 months later eventually landed a security job and ended up sitting on my hands for 3 months doing nothing. It isn't what the industry sold to me as "needing talent".

I know there's smart people doing good work, but it could not deliver for me within a reasonable time despite putting in the work, and that was enough to realize most of the call-to-action was bullshit. If anyone asks me for career advice (no one should), I just tell them to learn to code and do code reviews in their spare time. Don't even bother with the pentesting side of it.

Re: A hacker's mom broke into a prison and the warden's computer

#74
post #73
post #67

Earlier quoted context omitted.

Depends on where you’re looking. Companies like the one in the article are not going to be in a position to do a lot of staff development unless they have no other choice..you need to be able to hit the ground running in many cases. Depending on what experience you do have you might find good luck in hiring on at larger firms like insurance, financial, healthcare where they are going to need in-house staff and can ma…

I personally am going back to a dev job. It pays better and there's work to be done (incl. security). I got OSCP and 5 months later eventually landed a security job and ended up sitting on my hands for 3 months doing nothing. It isn't what the industry sold to me as "needing talent". I know there's smart people doing good work, but it could not deliver for me within a reasonable time despite putting in the work, and…

I blame it on the security industry because we are terrible at communicating, but your idea of how this works isn't aligned with reality. Think of it as a dumbed down version of the current staffing situation with healthcare. We have a huge talent gap, but that doesn't mean we put fresh grads to work on surgery.

Pen tests and red teaming are about both skills and decision making, both of which have very high potential for significant damages if carried out incorrectly. For me personally, getting the OCSP would just tell me you have very basic skills and have demonstrated some interest. I would then have to fold you into the engagement pipeline, which would involve some thumb-warming, as basically a water person until i get feedback from the rest of the team that you are asking the right questions and are making good decisions. You would then get progressively more responsibilities and operate under scrutiny for a couple of years before you would be asked to lead anything. The fact that you did nothing for three months just tells me they were too busy to figure out how to get you started on that ramp...or they were idiots. Who knows.

Again, it's a communication issue and your expectations were set too high, but that definitely doesn't mean the industry is secretly flush with talent.

Re: A hacker's mom broke into a prison and the warden's computer

#75
post #26

Earlier quoted context omitted.

Ugh, I hadn't thought about that, but I'm sure it probably does.

I took one for the team and looked it up to confirm. I can report that yes, it’s exactly what you think it is.

Also, I used DuckDuckGo to look this up, because I do not want targeted ads based on that search.

Re: A hacker's mom broke into a prison and the warden's computer

#76
post #3

These stories always make me wonder how many malicious infiltrations occur that are never discovered or reported? It could happen all the time, especially at places much less secure. It's certainly far riskier to infiltrate a prison (where all the guards have guns) than a corporate office.

you just need one corrupt guard, or somebody who is willing to close their eyes. guards are only people and being on shift talking with and being exposed to those confined will eventually make them empathic, as they realize many of the prisoners (majority but not all) are just people who never had a chance (grew up in orphanages or on the street, or often just homeless looking to escape the cold of the winter by doing a small crime to get there on purpose). There is one common theme among all of them: poverty and/or trauma. Once you see it (and being a guard exposed to them all the time you will see it unless you're a heartless or dumb sh!t) all the binary thinking and indoctrination starts cracking. This is where the bribe comes in since the person bribing also just fulfills a need (addiction, social interaction or whatever).

Instead of Prisons: https://www.prisonpolicy.org/scans/instead_of_prisons/chapte...

Anyone looking for some Netflix/Chill which is also edutainment about prisons and that doesn't paint the problem as binary (good vs evil) I highly recommend Oz https://www.imdb.com/title/tt0118421/ or (a more recent show about the streets and problems in LE) The Wire https://www.imdb.com/title/tt0306414/ Edit: this is also an incredibly good read https://mises.org/library/defending-undefendable

Re: A hacker's mom broke into a prison and the warden's computer

#77
post #21
post #13

Earlier quoted context omitted.

Is it wrong that I find it a terrible thing that people aren't allowed computers with internet or cellphones in prison? How do we expect people to join back to society when they can't use literally the number one most important thing? Maybe give them phones with no cameras and monitoring of use, but just nothing seems very inhumane.

In the US sometimes the evidence isn't clear that facilitating "join back to society" is an actual goal (it's often a stated goal). It often doesn't seem to be a policy priority.

prison isn't designed for reintegrating back into society!

If you look at this recent paper[1] by the lancet on "The psychological impact of quarantine and how to reduce it: rapid review of the evidence" (coincidentally it's about the corona virus) then you might notice that the effects of isolation are exactly what prisons are designed to do[2]. For quarantines it's a huge dilemma ofc.

[1] https://www.thelancet.com/journals/lancet/article/PIIS0140-6...

[2] https://en.wikipedia.org/wiki/Panopticon

Re: A hacker's mom broke into a prison and the warden's computer

#78
post #8

Just listened to the Darknet Diaries Courthouse podcast about the pentest gone wrong that was referenced in the article. Highly recommended. https://darknetdiaries.com/episode/59/

That wasn't a good look for their employer, "Coalfire", and not only because no one answered when they got their jail phone call. How did Coalfire not notice that the target was owned by a completely different entity than the organization that signed the contract?

> How did Coalfire not notice that the target was owned by a completely different entity than the organization that signed the contract?

The courthouse was owned by who? The sherriffs? I thought the ownership was okay, but it was the over-eager law enforcement that refused to budge because they weren't informed.

Re: A hacker's mom broke into a prison and the warden's computer

#79
post #74
post #73

Earlier quoted context omitted.

I personally am going back to a dev job. It pays better and there's work to be done (incl. security). I got OSCP and 5 months later eventually landed a security job and ended up sitting on my hands for 3 months doing nothing. It isn't what the industry sold to me as "needing talent". I know there's smart people doing good work, but it could not deliver for me within a reasonable time despite putting in the work, and…

I blame it on the security industry because we are terrible at communicating, but your idea of how this works isn't aligned with reality. Think of it as a dumbed down version of the current staffing situation with healthcare. We have a huge talent gap, but that doesn't mean we put fresh grads to work on surgery. Pen tests and red teaming are about both skills and decision making, both of which have very high potentia…

OSCP has too high of a fail rate to only demonstrate very basic skills, it's a bit more than that (if so, that puts CISSP, CEH, etc. way futher down yet you see those as job requirements all the time). There are plenty of people without it and employed still doing pentesting. This was my reality, I don't know how actually going through that situation qualifies it as anything but reality.

This is another thing: people value those certs really differently and it's almost worth not doing them at all, again going back to: just learn to code. And to your point: more communicating badly.

There's not a single more valuable qualifier than experience and yet that's the hardest thing to get when it really shouldn't be. Med students assist with surgeries but they aren't put in charge, I don't see why pentesting can't be the same.

I think you've taken the rare, good, working parts of the industry and believe that to be a baseline, and I don't think it's realistic.

Re: A hacker's mom broke into a prison and the warden's computer

#80
post #3

These stories always make me wonder how many malicious infiltrations occur that are never discovered or reported? It could happen all the time, especially at places much less secure. It's certainly far riskier to infiltrate a prison (where all the guards have guns) than a corporate office.

you just need one corrupt guard, or somebody who is willing to close their eyes. guards are only people and being on shift talking with and being exposed to those confined will eventually make them empathic, as they realize many of the prisoners (majority but not all) are just people who never had a chance (grew up in orphanages or on the street, or often just homeless looking to escape the cold of the winter by doin…

The Corner https://imdb.com/title/tt0224853/
Post reply on HN