Earlier quoted context omitted.
Obviously AT&T is responsible for their own systems. But what better publicity for the two parties than to come together and fix this. My personal take on all this is that Kevin Mitnick once was a hacker, good but probably not even that great (he did get caught, remember) who is now minting his newfound reputation. These kids prove that his reputation is somewhat less than he presents it to be and he's pissed off abo…
> These kids prove that his reputation is somewhat less than he presents it to be and he's pissed off about that. I think you're right that he wasn't all that great - IIRC, he mostly got into stuff by getting information out of people. However, the kids aren't proving anything - they're hacking other people's systems, not his.
ATT dumps Kevin Mitnick
21–30 of 45 posts
Re: ATT dumps Kevin Mitnick
#22Earlier quoted context omitted.
Indeed. Other providers host and maintain the security of as-high-profile "targets". More importantly you have to question how much of the security problem Mitnick poses in this? If he is part of the cause I think AT&T & HostedHere probably are reasonable to want to get rid of him (btw I suspect the 8 numeral password is a pin number: similar to the ones handed out by banks for online logins. Could still be his fault…
How is it reasonable for AT&T to admit blatant incompetence? Couldn't they have worked with Mitnick to secure his account and even use his case to attract more celebrity customers?
It's the same thing Sprint did a couple years ago when they dumped people that called customer service too much.
Re: ATT dumps Kevin Mitnick
#23Earlier quoted context omitted.
How is it reasonable for AT&T to admit blatant incompetence? Couldn't they have worked with Mitnick to secure his account and even use his case to attract more celebrity customers?
It's probably just a business decision. (assumption)They can provide cell phone service for 1000 people for the same cost as Mitnick since he is a target. It's the same thing Sprint did a couple years ago when they dumped people that called customer service too much.
Re: ATT dumps Kevin Mitnick
#24An 8 digit, all numerals password? Really, Mitnick? Also, it wasn't just AT&T that is refusing service to him, his webhost HostedHere.net did the same thing. And if this has been happening over and over again for 9 years why didn't he just want to go to another service provider?
Re: ATT dumps Kevin Mitnick
#25Earlier quoted context omitted.
It's probably just a business decision. (assumption)They can provide cell phone service for 1000 people for the same cost as Mitnick since he is a target. It's the same thing Sprint did a couple years ago when they dumped people that called customer service too much.
I'm sure it is, but it doesn't seem like a bright business decision. He claims he spends up to $20K a year - sure, maybe this still isn't worth it to AT&T. But more importantly, you'd think they would see this as an opportunity to make their system more robust for all their clients, save money that way (more than $20K/year? likely), AND turn it into a good PR piece.
Cue mass attempts to break into AT&T from every angle (which is sure to end badly) :)
Re: ATT dumps Kevin Mitnick
#2620k per year? He's doing something wrong...
Re: ATT dumps Kevin Mitnick
#27So AT&T is basically admitting their approach to security is "security through obscurity"? As long as you're not a high profile celebrity you should be ok because not one wants to own you...
Security through obscurity gets a bad rap. You rely on the "obscurity" of your password. The main issue is relying on false obscurity, both in systems (your program rot-13s your password) and in passwords (you pick an easy to guess password). There's no real security failing if you rely on obscurity that isn't exactly a password, so long as you can accurately assess the real obscurity, e.g. port knocking. If, let's s…
Not really. Your password may be obscure (although it should probably be as random as you can get), but the key exchange protocols and encryption algorithms should be wide open. There's a reason why secret keys are called "secret" -- they should be the only thing you have to keep secret. If his hosting provider and wireless company can't keep his accounts secure, that's their problem, not his.
Re: ATT dumps Kevin Mitnick
#2820k per year? He's doing something wrong...
It's easy to run up long bills if you roam internationally, $3/minute adds up fast.
Re: ATT dumps Kevin Mitnick
#29An 8 digit, all numerals password? Really, Mitnick? Also, it wasn't just AT&T that is refusing service to him, his webhost HostedHere.net did the same thing. And if this has been happening over and over again for 9 years why didn't he just want to go to another service provider?
Re: ATT dumps Kevin Mitnick
#30An 8 digit, all numerals password? Really, Mitnick? Also, it wasn't just AT&T that is refusing service to him, his webhost HostedHere.net did the same thing. And if this has been happening over and over again for 9 years why didn't he just want to go to another service provider?
Mitnick said that per AT&T policy, his password could only be digits and no more than eight characters long.