Live data from Hacker News

Threatening Lawsuit, HBGary Federal Intimidates Aaron Barr Out of DEFCON Panel

threatpost.com

1–10 of 16 posts

Re: Threatening Lawsuit, HBGary Federal Intimidates Aaron Barr Out of DEFCON Panel

#2
I believe this falls into "doing it wrong".

Backing out because they threaten to file an injunction is to capitulate too soon. You're supposed to keep going until/unless they actually get an injunction, and then challenge it (plus, civil lawsuit for loss of income due to the injunction once it's rescinded).

BlackHat/BSidesLV/DEFCON is going to be really interesting this year, for a change.

Re: Threatening Lawsuit, HBGary Federal Intimidates Aaron Barr Out of DEFCON Panel

#3
I find this one the most worrying:

"In 2008, the Massachusetts Bay Transportation Authority (MBTA) obtained a temporary restraining order to prevent a talk at DEFCON by three MIT students who had uncovered physical and logical security holes in MBTA infrastructure."

I mean, the IOS guy worked for IOS, so he was divulging information that Cisco paid him to obtain. HBGary paid Aaron Barr to research anonymous, so they have a case for him doing the same thing. However, what kind of case could MBTA possibly have against some kids who found problems with their infrastructure? I fail how to see how such an injunction was anything but unconstitutional.

Re: Threatening Lawsuit, HBGary Federal Intimidates Aaron Barr Out of DEFCON Panel

#6

Why would DEFCON want Aaron Barr on any sort of panel? The guy is at best a hack of a security professional and at worst a complete idiot of a slime ball who doesn't understand the first thing about technology.

It's sort of like staring at a car wreck as you pass by. Doesn't mean you approve of car wrecks or are glad they happen, but you can't help it.

Re: Threatening Lawsuit, HBGary Federal Intimidates Aaron Barr Out of DEFCON Panel

#7
post #4

Kinda reminds me of this: http://news.infracritical.com/pipermail/scadasec/2011-May/01... the more I see in the security world, the more I think full disclosure is the only responsible way to work towards a more secure system.

What geeks think of as "full disclosure" is thought of as "cyber crime" or "cyber terror" by some companies and agencies. Things have changed a lot in the last five or ten years.

So, be cautious and get legal advice if you do decide to disclose anything, and understand that while geeks mainly just want to share what they found and help fix it, that others may accuse you of being a criminal, or worse a terrorist if you do that.

Re: Threatening Lawsuit, HBGary Federal Intimidates Aaron Barr Out of DEFCON Panel

#8
post #6

Why would DEFCON want Aaron Barr on any sort of panel? The guy is at best a hack of a security professional and at worst a complete idiot of a slime ball who doesn't understand the first thing about technology.

It's sort of like staring at a car wreck as you pass by. Doesn't mean you approve of car wrecks or are glad they happen, but you can't help it.

I'm not at all a computer security professional(considering getting into the field, though) but I can't help but wonder if this mars DEFCON's image by having this guy there.

I see your car accident analogy, but Aaron's probably accepting money to be on the panel. Why should they pay him when they know his reputation is tarnished?

Re: Threatening Lawsuit, HBGary Federal Intimidates Aaron Barr Out of DEFCON Panel

#9
post #3

I find this one the most worrying: "In 2008, the Massachusetts Bay Transportation Authority (MBTA) obtained a temporary restraining order to prevent a talk at DEFCON by three MIT students who had uncovered physical and logical security holes in MBTA infrastructure." I mean, the IOS guy worked for IOS, so he was divulging information that Cisco paid him to obtain. HBGary paid Aaron Barr to research anonymous, so they…

I don't think it had to do with the constitutionality of the issue for the MIT hackers, but more the practical issues that arise from them sharing with the public security loopholes before they were fixed.

Re: Threatening Lawsuit, HBGary Federal Intimidates Aaron Barr Out of DEFCON Panel

#10
post #7
post #4

Kinda reminds me of this: http://news.infracritical.com/pipermail/scadasec/2011-May/01... the more I see in the security world, the more I think full disclosure is the only responsible way to work towards a more secure system.

What geeks think of as "full disclosure" is thought of as "cyber crime" or "cyber terror" by some companies and agencies. Things have changed a lot in the last five or ten years. So, be cautious and get legal advice if you do decide to disclose anything, and understand that while geeks mainly just want to share what they found and help fix it, that others may accuse you of being a criminal, or worse a terrorist if yo…

How is information a crime if you're not in the government service?

No, seriously!

Post reply on HN