Live data from Hacker News

LulzSec Exposed

seclists.org

51–60 of 82 posts

Re: LulzSec Exposed

#51
post #17

So they got exposed because they were acting like a bunch of children and taking no precautions? Man, if people who don't know what they're doing are this successful, imagine what it means about people who are. And how any laws we make about computer security are just security theater.

When you talk about IT security with people with real secrets (governments), they talk about LulzSec-types being the "lowest risk" category of attackers. The mid-risk category are the real professionals; they leave no trace, you never hear about them, you never know they were on your system, they just take your data and sell it. The highest-risk category is true information warfare, targeted attacks by other governme…

To be honest, if your opponent has a couple of million dollars or more to spend on hacking you, and you aren't willing to expend several multiples of that on defence, you should probably give up on the convenience of having your secret data on the internet and just have it encrypted on HDDs surrounded by handpicked armed guards who owe you a blood debt.

Computers and especially networks are just fundamentally insecure for the purposes of high-value information.

This is the same reason why internet voting will never be a good idea.

Re: LulzSec Exposed

#52

Earlier quoted context omitted.

You say you are glad they were doing it for fun and wait for someone to do it not for fun? How do you know it's not already been done? A true hacker wouldn't expose their actions and would continue with the exploit. I think these kids have exposed the true lack of security around the world in general and it has raised some serious attention for other people to take a look at their own defence, which is good in some r…

Am I misinterpreting your comment? You said, the hackers "lowered people's trust in massive corporations [...] which is not good in any respect." It seems pretty clear to me that Sony is most decidedly not deserving of consumer's trust - and without these public disclosures, we would have never known that. Certainly - as I learned in the Gawker security breach - it sucks to have your login details broadcasted to the…

Why are you using the same password across the web in the first place. Worst case at least have a tiered system.

High - These are high security risk, such as email accounts, and anything that can gain access to or control something that relates to it (domain names, server access, stuff like that). Medium - Passwords that give you access to very specific systems that if someone gained access would ruin your day but won't allow them to do anything really bad (personal home file server, the password to your FTP, web forums where you have a trust based relationship with people) Low - If it gets hacked, who cares. Won't make a bit of difference (throwaway accounts on forums, news sites, stuff like that).

Re: LulzSec Exposed

#53
post #12

Earlier quoted context omitted.

Sony isn't low-hanging fruit.

Given that a lot of their sites have been broken into with relatively unsophisticated means, such as SQL injection, I think that many Sony sites are certainly in the "low-hanging fruit" category.

Maybe in terms of vulnerability, but certainly not in terms of importance.

Re: LulzSec Exposed

#55
post #28
post #5

Earlier quoted context omitted.

Indeed; the trial, if any (Private Manning?), will be interesting for the evidence collection techniques.

Manning is a totally different story that doesn't even fall the same branch of law. Plus state security in the US is somewhat touchy I hear. They're kids, they're gonna be all-right.

[deleted]

Re: LulzSec Exposed

#56
post #17

So they got exposed because they were acting like a bunch of children and taking no precautions? Man, if people who don't know what they're doing are this successful, imagine what it means about people who are. And how any laws we make about computer security are just security theater.

When you talk about IT security with people with real secrets (governments), they talk about LulzSec-types being the "lowest risk" category of attackers. The mid-risk category are the real professionals; they leave no trace, you never hear about them, you never know they were on your system, they just take your data and sell it. The highest-risk category is true information warfare, targeted attacks by other governme…

I know the high risk actors are there, my post was fueled by my continuing fascination of how low the barrier to entry to the low-risk category is, and how high the potential they have is.

Re: LulzSec Exposed

#58
post #17

So they got exposed because they were acting like a bunch of children and taking no precautions? Man, if people who don't know what they're doing are this successful, imagine what it means about people who are. And how any laws we make about computer security are just security theater.

When you talk about IT security with people with real secrets (governments), they talk about LulzSec-types being the "lowest risk" category of attackers. The mid-risk category are the real professionals; they leave no trace, you never hear about them, you never know they were on your system, they just take your data and sell it. The highest-risk category is true information warfare, targeted attacks by other governme…

Exactly, I am almost certain this was floating on carders' forums weeks if not months before.

Re: LulzSec Exposed

#59
post #57

http://pastebin.com/yut4P6qN Guess this was a joke/defamation attempt after all.

Yep, the dox linked here are pretty old. Topiary, Kayla and a bunch of others listed are members of Anon as well, giving the theory of Lulzsec and Anon being related more credibility.

Re: LulzSec Exposed

#60
post #33

I'm glad they were doing it for the lulz. Some day someone's going to be doing it, not for the lulz, and the price we'll have to pay for this kind of massive developer/it-sec incompetence will be extremely high. Hopefully this has served as a wake-up call to people who weren't already aware how low the fruit has been hanging.

These guys are like the kids who paint your cat with spray paint. It seems with most groups, and computer criminals doesn't seem to have escaped, they have people who span the range from 'harmless' to 'lethal'. This prank (and it was a prank) was more in the 'harmless' side, Stuxnet was more on the 'lethal' side.

Some people see the end of the internet as we know it in these stories, I see new opportunities to sell locks :-)

Post reply on HN