Live data from Hacker News

LulzSec Exposed

seclists.org

61–70 of 82 posts

Re: LulzSec Exposed

#61
post #25

Not surprising since they are just a bunch of weekend warriors and kids. Any real smooth operator wouldn't be working out of his house, and especially not on a personal browsing machine. From the opposite perspective of that, the government hasn't seen diddly when it comes to digital terrorism. Just wait until the FBI can't track down the culprits from their broadband bill and drive over to their parents house and ma…

[deleted]

Re: LulzSec Exposed

#62
post #43
post #25

Not surprising since they are just a bunch of weekend warriors and kids. Any real smooth operator wouldn't be working out of his house, and especially not on a personal browsing machine. From the opposite perspective of that, the government hasn't seen diddly when it comes to digital terrorism. Just wait until the FBI can't track down the culprits from their broadband bill and drive over to their parents house and ma…

Uh, when will that be? From what I observe, it just keeps getting progressively easier for the FBI to do that. Not harder.

I think you need to read up on cyber crime and cyber criminal groups. Your thesis is correct but only accounts for those who are not independent from the internet. A professional attacker wouldn't ever use the machine and network they were accessing the Internet from for anything else other then their attacks. No compromising search terms, emails, chats, page visits, internet billing, etc. I'm talking a machine totally devoid of personal information or anything that could potentially reveal the identity/location/details of the attacker. Now imagine this was scalable and you constantly were changing your point of access and machine. Actual cyber criminals (the ones cleaning out credit card companies, banks, high level blackmail, stolen secrets, etc, the shit you really only ever hear rumors about because it's too dangerous to leave executive circles at companies.) especially in Eastern Europe have access to an almost unlimited supply of cheap machines, false identities, "tunneled" networks and connections inside major established institutions and companies, and strict criminal group rules, make it almost impossible to identify anyone. Don't be naive this shit goes on everyday.

Re: LulzSec Exposed

#64
Last I checked they were alive and well. As for them supposedly being Amateurs, no... no they are not. The attacks they are pulling they could get away with if they kept the secret. But something is motivating them.

Re: LulzSec Exposed

#65
post #37

Are they? Or is this just some random guy who wants to get other random guy(s) in deep trouble? edit: Indeed, following the thread reveals http://seclists.org/fulldisclosure/2011/Jun/88 -> http://pastebin.com/mmvBT7n5 The root entry dated May 13.

http://twitter.com/#!/LulzSec/status/77782030020128768

Re: LulzSec Exposed

#66

Earlier quoted context omitted.

Given that a lot of their sites have been broken into with relatively unsophisticated means, such as SQL injection, I think that many Sony sites are certainly in the "low-hanging fruit" category.

Maybe in terms of vulnerability, but certainly not in terms of importance.

Low-hanging fruit simply means "reward" for little effort. The low-hanging fruit may very well be the biggest, sweetest of the bunch.

Re: LulzSec Exposed

#67
post #52

Earlier quoted context omitted.

Am I misinterpreting your comment? You said, the hackers "lowered people's trust in massive corporations [...] which is not good in any respect." It seems pretty clear to me that Sony is most decidedly not deserving of consumer's trust - and without these public disclosures, we would have never known that. Certainly - as I learned in the Gawker security breach - it sucks to have your login details broadcasted to the…

Why are you using the same password across the web in the first place. Worst case at least have a tiered system. High - These are high security risk, such as email accounts, and anything that can gain access to or control something that relates to it (domain names, server access, stuff like that). Medium - Passwords that give you access to very specific systems that if someone gained access would ruin your day but wo…

You're absolutely right, but, like (I suspect) many people, I knew better, but hadn't taken the time to implement unique passwords before the Gawker security breach. It basically forced me to act - and now I'm better for it.

Re: LulzSec Exposed

#70

Earlier quoted context omitted.

You say you are glad they were doing it for fun and wait for someone to do it not for fun? How do you know it's not already been done? A true hacker wouldn't expose their actions and would continue with the exploit. I think these kids have exposed the true lack of security around the world in general and it has raised some serious attention for other people to take a look at their own defence, which is good in some r…

Am I misinterpreting your comment? You said, the hackers "lowered people's trust in massive corporations [...] which is not good in any respect." It seems pretty clear to me that Sony is most decidedly not deserving of consumer's trust - and without these public disclosures, we would have never known that. Certainly - as I learned in the Gawker security breach - it sucks to have your login details broadcasted to the…

No, they might not be deserving of customers trust but that doesn't mean that throwing egg on their face is helping the situation any. If the hackers were doing it for the good of the community then it's counter productive. They should have informed Sony of the issue. They are kids who do not understand what effect the situation has on the economic climate.

Also, defacing the other music sites does nothing more than raise the profile of their hacking "skills".

As I mentioned, yes they are making people aware that there are security issues that companies need to iron out and Sony are having some serious bad media recently but who is this really helping? It's not helping the market and its not helping consumers?

You and I both know that they should not be storing stuff plain text or with some bad security practice and we understand what it takes to make it right but to the common person they are instantly put off all places where they have to put card details. The overall perception of the web is stepping back 15 years in the eyes of the general consumer, soon people will be afraid to put their details anywhere.

I agree completely with what you are saying but that's from my point of view, I'm thinking general consumer confidence.

Post reply on HN