Live data from Hacker News

ATT dumps Kevin Mitnick

theregister.co.uk

11–20 of 45 posts

Re: ATT dumps Kevin Mitnick

#11

So AT&T is basically admitting their approach to security is "security through obscurity"? As long as you're not a high profile celebrity you should be ok because not one wants to own you...

Security through obscurity gets a bad rap. You rely on the "obscurity" of your password.

The main issue is relying on false obscurity, both in systems (your program rot-13s your password) and in passwords (you pick an easy to guess password).

There's no real security failing if you rely on obscurity that isn't exactly a password, so long as you can accurately assess the real obscurity, e.g. port knocking. If, let's say (and this is probably false) AT&T has a billing system where sending 100 specific, not-easily-guessable bytes allows you to get private data, that's no worse than a password, even if the reason that it works is a bug - unless the source code is available to the attacker.

Of course, AT&T's problem here isn't obscurity, it's that they don't want to invest enough for real security at all. Which could be reasonable from a business perspective.

Re: ATT dumps Kevin Mitnick

#12
post #8

I find Kevin Mitnick going to the authorities for protection a little bit weird. If your claim to fame is that you are the 'worlds baddest hacker' you take the script kiddies as going with the territory. It's like Billy the Kid complaining about the wanna-be's that want to meet him at noon on main street. "The move by AT&T came this week after Mitnick hired a lawyer to complain that his privacy was being invaded by p…

He did his time, and now he has the same right to protection as the rest of us.

Re: ATT dumps Kevin Mitnick

#13
post #12
post #8

I find Kevin Mitnick going to the authorities for protection a little bit weird. If your claim to fame is that you are the 'worlds baddest hacker' you take the script kiddies as going with the territory. It's like Billy the Kid complaining about the wanna-be's that want to meet him at noon on main street. "The move by AT&T came this week after Mitnick hired a lawyer to complain that his privacy was being invaded by p…

He did his time, and now he has the same right to protection as the rest of us.

Sure, but if you are a 'master burglar' selling your services to companies securing other peoples goodies your reputation as a 'master burglar' is what allows you to do that.

It means that a lot of people that you are putting down will see you as their prime target. This goes with the territory.

If KM would have taken a job as a programmer somewhere I highly doubt that this would have happened. After all, he is minting his reputation as a former bad guy, nobody forced him to do that.

If he had been a white hat all along it would be different, but a burglar complaining he's been burgled is a bit hypocritical imo.

I guess it sucks being on the receiving side.

Basically all these little jerks do is make him look silly, personally I wouldn't even bother to respond to them, just take it as praise and laugh at it. By taking it so serious he is actually fanning the fire.

Re: ATT dumps Kevin Mitnick

#14

An 8 digit, all numerals password? Really, Mitnick? Also, it wasn't just AT&T that is refusing service to him, his webhost HostedHere.net did the same thing. And if this has been happening over and over again for 9 years why didn't he just want to go to another service provider?

I had to re-read the article about the eight digit password. As it is for his phone provider, I presume it has to be numbers so it can be typed in from any phone keypad. I can't believe someone with Mitnick's track record would use an all-numbers password by choice.

Re: ATT dumps Kevin Mitnick

#15
post #12

Earlier quoted context omitted.

He did his time, and now he has the same right to protection as the rest of us.

Sure, but if you are a 'master burglar' selling your services to companies securing other peoples goodies your reputation as a 'master burglar' is what allows you to do that. It means that a lot of people that you are putting down will see you as their prime target. This goes with the territory. If KM would have taken a job as a programmer somewhere I highly doubt that this would have happened. After all, he is minti…

When he sells his services, he either has access to the systems to look at their security, or has authorization to try and get in (don't know how he works, really). With ATT, he does not legally have access to fiddle with their vulnerable systems in order to keep the pests out.

Re: ATT dumps Kevin Mitnick

#16
post #6

Earlier quoted context omitted.

Indeed. Other providers host and maintain the security of as-high-profile "targets". More importantly you have to question how much of the security problem Mitnick poses in this? If he is part of the cause I think AT&T & HostedHere probably are reasonable to want to get rid of him (btw I suspect the 8 numeral password is a pin number: similar to the ones handed out by banks for online logins. Could still be his fault…

How is it reasonable for AT&T to admit blatant incompetence? Couldn't they have worked with Mitnick to secure his account and even use his case to attract more celebrity customers?

well we have no specific information on any of the problems (plus Im a little biased personally in that Mitnick seems to be in a habit of loudly crying foul no matter what - I do that sometimes because it gets results, takes one to know one)

It's been 9 years (we dont even know how much of it is AT&T vs. Mitnicks fault and what contact he has had with them): it's looking like an infinite battle to "secure" his identity. If there are crucial security flaws in their process then yes I am in agreement - but I doubt that is the case (because Mitnick would then be the least of their problems :)). Wash hands, move on.

Re: ATT dumps Kevin Mitnick

#17
Wouldn't such a customer be worth gold? A single user that constantly get's attacked by hackers would provide a great opportunity to detect and fix security holes. If a hacker get's through, it is just one person's account compromised. But each detected attack could prevent attacks on other accounts.

I think some other telco should pay Mitnick to become their customer. How else could you attract so many hacker brains and make them work on finding security flaws in your system?

Re: ATT dumps Kevin Mitnick

#18
post #15

Earlier quoted context omitted.

Sure, but if you are a 'master burglar' selling your services to companies securing other peoples goodies your reputation as a 'master burglar' is what allows you to do that. It means that a lot of people that you are putting down will see you as their prime target. This goes with the territory. If KM would have taken a job as a programmer somewhere I highly doubt that this would have happened. After all, he is minti…

When he sells his services, he either has access to the systems to look at their security, or has authorization to try and get in (don't know how he works, really). With ATT, he does not legally have access to fiddle with their vulnerable systems in order to keep the pests out.

Obviously AT&T is responsible for their own systems. But what better publicity for the two parties than to come together and fix this.

My personal take on all this is that Kevin Mitnick once was a hacker, good but probably not even that great (he did get caught, remember) who is now minting his newfound reputation.

These kids prove that his reputation is somewhat less than he presents it to be and he's pissed off about that.

There is a proverb in there somewhere: High trees catch lots of wind...

AT&T is a bunch of weaklinks for terminating his account (same goes for his provider), they should secure their stuff with or without Kevins help. To terminate a user because they 'attract bad people' is ridiculous, imagine your bank telling you that they can no longer take your business because because of you the keep having burglary attempts. It's too silly for words.

Re: ATT dumps Kevin Mitnick

#19

An 8 digit, all numerals password? Really, Mitnick? Also, it wasn't just AT&T that is refusing service to him, his webhost HostedHere.net did the same thing. And if this has been happening over and over again for 9 years why didn't he just want to go to another service provider?

An 8 digit, all numerals password? Really, Mitnick?

It's not super secure, but it really should be secure enough if a website cares about security -- they should be limiting login attempts, and shouldn't be storing them in plain text.

Re: ATT dumps Kevin Mitnick

#20
post #15

Earlier quoted context omitted.

When he sells his services, he either has access to the systems to look at their security, or has authorization to try and get in (don't know how he works, really). With ATT, he does not legally have access to fiddle with their vulnerable systems in order to keep the pests out.

Obviously AT&T is responsible for their own systems. But what better publicity for the two parties than to come together and fix this. My personal take on all this is that Kevin Mitnick once was a hacker, good but probably not even that great (he did get caught, remember) who is now minting his newfound reputation. These kids prove that his reputation is somewhat less than he presents it to be and he's pissed off abo…

> These kids prove that his reputation is somewhat less than he presents it to be and he's pissed off about that.

I think you're right that he wasn't all that great - IIRC, he mostly got into stuff by getting information out of people.

However, the kids aren't proving anything - they're hacking other people's systems, not his.

Post reply on HN