Live data from Hacker News

I got an FBI record at age 11 from dabbling in cryptography (2015)

web.stanford.edu

61–70 of 373 posts

Re: I got an FBI record at age 11 from dabbling in cryptography (2015)

#61

Protip: an FBI record means nothing and you can check if you have one too! There is a gov site somewhere maybe someone else knows the url

I assume this one:

https://www.fbi.gov/services/cjis/identity-history-summary-c...

But it isn't clear to me if this would provide the kind of information presented in the article (e.g. if you've been simply investigated for a suspected crime).

> listing certain information taken from fingerprint submissions kept by the FBI and related to arrests and, in some instances, federal employment, naturalization, or military service.

Re: I got an FBI record at age 11 from dabbling in cryptography (2015)

#62
post #3

This story (assuming it's true) should serve as an excellent example of why you need privacy even if you think that you don't. In peace time the NSA is only looking for "terrorist" and leaves everyone alone, but in case of war they would start creating lists for any and everything. All it takes is one "tough" agent trusting their gut feeling/algorithm based on your browsing history and shopping habits to put a target…

> In peace time the NSA is only looking for "terrorist" and leaves everyone alone

If you say so.

Re: I got an FBI record at age 11 from dabbling in cryptography (2015)

#63

Earlier quoted context omitted.

> I like how you shared how you learned lesson to not share mischievous activities with people in the same post you then go and share more things you haven't been caught for American public schools are quite adept at teaching distrust in authority, particularly in bureaucrats. That doesn't mean distrust in everybody.

> American public schools are quite adept at teaching distrust in authority, particularly in bureaucrats. It's an important lesson to teach kids while they're young! Strange, though, how you never see it on the formal curriculum.

it’s a hidden lesson, only for privileged kids.

Re: I got an FBI record at age 11 from dabbling in cryptography (2015)

#64
post #27

My FBI file was for hacking into my school district's AS/400 that handled my school's attendance and grading system. Somehow using a public IP address with no access restrictions allowed a clear telnet path in from home. Compounding username and passwords that were all the same for every employee. I didn't change a thing, just LOLed and told someone. Bad mistake. This was the late 90s. Oh well, 2 week suspension and…

> I learned my lesson to not talk about such things I like how you shared how you learned lesson to not share mischievous activities with people in the same post you then go and share more things you haven't been caught for. This is going on your permanent school record! /s That's great. I know even as of recent of 2021 I've seen some places that had 0 security on things.

another thing probably learned is statute of limitations!

Re: I got an FBI record at age 11 from dabbling in cryptography (2015)

#66
post #5

Be sure to read the follow-up ( https://web.stanford.edu/~learnest/cyclops/bash1.htm ) about the challenges the author faced in trying to help move forward a reasonably safe standard for bicycle helmets.

Yeah, came to say the same. The multi-part saga of helmet safety is fascinating history, and enlightening to hear the story of the people who were fighting this fight for so long. I’m bookmarking this!

Re: I got an FBI record at age 11 from dabbling in cryptography (2015)

#67
post #27

My FBI file was for hacking into my school district's AS/400 that handled my school's attendance and grading system. Somehow using a public IP address with no access restrictions allowed a clear telnet path in from home. Compounding username and passwords that were all the same for every employee. I didn't change a thing, just LOLed and told someone. Bad mistake. This was the late 90s. Oh well, 2 week suspension and…

This reminds of a Costco bug I discovered, it appears that they fixed it lol.

So, Costco runs AS/400 in stores, and their online store is in .Net MVC. I worked with both technologies and often have to communicate with AS/400 devs and they are close to their retirement so little fucks are given. Plus, working with DB2 is annoying in general, the .NET data provider from IBM is expensive and sucks.

Now onto the bug, when you purchased items online at a discount, you were able to return to store at a full price as their systems were not communicating that a discount was applied. I returned several items, but did not realize until I bought a laptop that was $400 off and tried returning it. I ended up calling Costco and letting them know. Unfortunately, they didn't give me any lifetime membership or a good citizen award.

If any Costco devs read this and know about this send me some love.

Re: I got an FBI record at age 11 from dabbling in cryptography (2015)

#68
post #24

He was able to tinker with a radio at age of 10, in 1940. I had my first electronic at 19, in 2003, growing up in India. Today, almost anyone in the world can have access to the latest tech easily. Great minds were there and are everywhere in the world, they just didn't have access to resources. Think how fast the research monopoly of US is going to shrink.

Growing up in a Third-World country, I was tinkering with electronics at age 10 and built my first crystal radio at age 11 from junk parts. Dumpster-diving isn't hard as long as you don't mind the occasional dead dog.

I've found entire, functional computers thrown out. My first web server was a 386 built from dumpster-dived parts, quickly upgraded to a 486 as I found new stuff. I still have those computers, too. It's amazing how wasteful people are with tech. People, please don't throw out working computers if you can avoid it. Take them to a thrift shop or a specialized place that will fix them up and sell them, like Free Geek. Post an ad on Craigslist "free" section.

Re: I got an FBI record at age 11 from dabbling in cryptography (2015)

#69
post #27

My FBI file was for hacking into my school district's AS/400 that handled my school's attendance and grading system. Somehow using a public IP address with no access restrictions allowed a clear telnet path in from home. Compounding username and passwords that were all the same for every employee. I didn't change a thing, just LOLed and told someone. Bad mistake. This was the late 90s. Oh well, 2 week suspension and…

> I learned my lesson to not talk about such things because their egoes were too fragile.

Yip, ego's and people talk are the downfall of many an innocent `self-education` in the area of IT security.

Post 80's and laws started to change, prior, in the UK it was theft of electricity being the only way to nail some people. Crazy fun times.

Though I do miss the old phone system per-say, outdials, wardialing, things like that, was common with many and just seemed more mysterious as you could only learn thru word of mouth or self-education as no books or internets and BBS's were not as cheap in the UK or common as we never had the official free local calls aspect as you fine folks had in the US.

Do recall a chap getting kicked out of college for doing something I'd done previously, just that he had a bigger ego and not as delicate with the power to steal the admin password. Which involved an ICL George 3 OS mainframe in the times of very large disc platters and admin console journaling that had no encryption. so they rotated discs without adding extra wear of zeroing the previous content, only the file table so you could end up with a user disc platter that had formally been used as a admin console jounal reposatory and could create files without zeroing and dump the previous contents of the disc of that way...which eventually got you the admin password.

Do recall few instances of work related cases in which I needed to do things so, kinda hacked what I needed (resourcefulness) like upon a DPS7 Honeywell mini computer in which needed the admin password to do something and nobody had it at hand at that time of night and the passowrds were kept in a file that was encrypted so I worked out the encryption key by looking at the file as was poor encryption and text files have lots of spaces so saw a pattern with the word OPERA in and tried and tada, got what I needed. The spooked admin next day wondered how I did it so I told him fully, he then went and redid the encryption and challenged me to see if that was secure, I looked at the encrypted file and kinda worked out by the patterning that it had been encrypted twice....yes with the same password OPERA only encrypted with that and then encrypted again with the same. Educational for all back then. Today, not as easy to do that, but still a great story of times of old.

My ego prevents anything else and was an ethical hacker and the 90's was an era in which, we white hats would and was the internet security, bringing down pedo's and bad actors like that that frequented some platforms with ease (looking at you AOL). So whilst illegal per-say, was case of no real official policing of such things as we do today.

But darn, some things learned and worked out, well zero day exploits back then were not as financially economical as they are today and heck, and some never really appreciated how long they would stay obscured from the wild.

I also liked hardware back then, was also fun and many a hidden switch to get a feature you would normally pay silly money for some engineer to `install` though was just some hidden switch was not that uncommon. Heck even today you get kit that is same inside with a model up just adding some small thing and example would be some Fluke multimeters that you effectively pay hundred for a small capacitor and another digit on the outer shell, is a good example current today.

Fun times indeed, but darn, goalposts always moving.

Re: I got an FBI record at age 11 from dabbling in cryptography (2015)

#70

Earlier quoted context omitted.

> I like how you shared how you learned lesson to not share mischievous activities with people in the same post you then go and share more things you haven't been caught for American public schools are quite adept at teaching distrust in authority, particularly in bureaucrats. That doesn't mean distrust in everybody.

> American public schools are quite adept at teaching distrust in authority, particularly in bureaucrats. It's an important lesson to teach kids while they're young! Strange, though, how you never see it on the formal curriculum.

[deleted]
Post reply on HN