Live data from Hacker News

NSA.gov Site Defacement

praetorianprefect.com

1–10 of 16 posts

Re: NSA.gov Site Defacement

#3
Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how they could rectify the problem. 1 or 2 months later an offer of employment (to a Canadian!) arrived at his doorstep.

Defacement of a public portion of the NSA's site is just going to land you in a world of hurt, even if you are in a far off country.

Re: NSA.gov Site Defacement

#4
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

Yikes, seems like things could easily turn out different if that email is directed to the wrong person or misunderstood.

Re: NSA.gov Site Defacement

#5
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

Do you know how he encrypted his email?

Re: NSA.gov Site Defacement

#6
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

Did he accept the offer of employment?

Re: NSA.gov Site Defacement

#7
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

1 or 2 months later an offer of employment (to a Canadian!) arrived at his doorstep.

This is a standard way to catch people who do this type of stuff. Once he sets foot on American soil, he would be arrested. You actually have to be pretty dense to fall for it. ~99% of employment at the CIA requires some form of security clearance, which in turn requires you to be a US citizen.

Re: NSA.gov Site Defacement

#8
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

> encrypted email

This tells us nothing of whether the NSA is good at finding people on the internet, however. Was the email anonymous? Did he use a proxy?

Re: NSA.gov Site Defacement

#10
post #7
post #3

Trivial SQL injections aside, the proper way to handle a hack/exploit/crack is the way my very close friend handled it. He used a google hack back when they were cool to take control of the CIA's video cameras for their parking lots. (default password to the cameras was 4321 or something similar) He sent an encrypted email to the CIA's public facing email address. He described how he did what he did and described how…

1 or 2 months later an offer of employment (to a Canadian!) arrived at his doorstep. This is a standard way to catch people who do this type of stuff. Once he sets foot on American soil, he would be arrested. You actually have to be pretty dense to fall for it. ~99% of employment at the CIA requires some form of security clearance, which in turn requires you to be a US citizen.

While I see the point, I'm not sure I believe you that easily. Not all clearance forms require you to be a citizen (besides there must be some way to cooperate with companies from other countries). Why are you sure he would get arrested? Has there been a documented case of something like that happening before? Isn't the offer of employment an official document that's legally forcing to hire someone if they accept? (not sure how do those work in US)

What you wrote is just a bit unlikely. If US can force a UK citizen and a "hacker" (NASA case) to be transported to US for the trial even after many appeals, why would it be a problem with Canada?

Post reply on HN