Live data from Hacker News

Kevin Mitnik FOIA Final

vault.fbi.gov

31–40 of 99 posts

Re: Kevin Mitnik FOIA Final

#31
post #16

It should be illegal for the government to keep redactions in anything made public/declassified. It's a slap in the face to see entire sections of text (that most certainly contain important context) blocked out with a white blob.

Why do we need to have the names of people like a random security guard that was duped by social engineering? To make sure he pays for a mistake or something? What is the reason for not reacting his name?

Re: Kevin Mitnik FOIA Final

#32
This is pretty damn interesting, it's definitely the earliest example of a computer intrusion incident response report that I've ever seen. These reports detail stuff he was doing in 1980/1981 at the earliest I can see just skimming the top few pages. His own side of this particular chapter of his history is maybe worth a read, maybe not - he was known for embellishments:

https://web.archive.org/web/20090317050834/http://www.themem...

Re: Kevin Mitnik FOIA Final

#33
post #16

It should be illegal for the government to keep redactions in anything made public/declassified. It's a slap in the face to see entire sections of text (that most certainly contain important context) blocked out with a white blob.

The Mitnick files contain information about innocent people who are alive and whose privacy rights remain paramount.

Re: Kevin Mitnik FOIA Final

#34
post #31
post #16

It should be illegal for the government to keep redactions in anything made public/declassified. It's a slap in the face to see entire sections of text (that most certainly contain important context) blocked out with a white blob.

Why do we need to have the names of people like a random security guard that was duped by social engineering? To make sure he pays for a mistake or something? What is the reason for not reacting his name?

> What is the reason for not reacting his name?

The reason is GP doesn't understand the reason, so there is no reason, so it must be made public. /s

Re: Kevin Mitnik FOIA Final

#35

Surprised that personal info such as Kevin’s SSN wasn’t removed prior to release.

Other people have mentioned this… but it’s been established in policy that the SSN of a deceased person is not PII. There are a ton of different ways to get the SSN of someone who is deceased.

If anything, having it public could dissuade others from trying to use it.

Re: Kevin Mitnik FOIA Final

#36
post #20

Earlier quoted context omitted.

If you are into this topic, read as many point of view as possible and take a look at http://www.takedown.com/ (Tsutomu Shimomura's side of the story).

I've far more respect for Tsutomu. In the end he turned out to be the better hacker. Reading Mitnicks book I sometimes get the impression that the he is making up half of it.

To the best of my knowledge, Mitnick didn't really code at all. There are (let's call them) intrusion specialists whose skillsets don't really involve systems programming, but rather intuition and tenacity, and there are others who write exploits. My understanding is that Mitnick was the former, and was using tools he got from friends and peers.

Re: Kevin Mitnik FOIA Final

#38
post #17

Earlier quoted context omitted.

Him, probably not. His estate, however, potentially. Perhaps one could get a loan, using his SSN, and his estate gets the bill and subsequent harassment. SSNs make terrible secrets and it's insane that you could harm a live person by knowing their SSN. I doubt that insanity stops just because you're dead.

> I doubt that insanity stops just because you're dead. It really does stop. What can you do with someone’s SSN? Get loans, open bank accounts, receive government benefits, set up utilities, etc. It harms someone because creditors falsely believe that the SSN’s holder owes the debt, or the government believes that the SSN’s holder received benefits, etc. People who are falsely reported as dead have a difficult time d…

If someone is asking for an SSN they’ll be doing a credit report which will show if you’ve died.

Re: Kevin Mitnik FOIA Final

#39
post #20

Earlier quoted context omitted.

If you are into this topic, read as many point of view as possible and take a look at http://www.takedown.com/ (Tsutomu Shimomura's side of the story).

I've far more respect for Tsutomu. In the end he turned out to be the better hacker. Reading Mitnicks book I sometimes get the impression that the he is making up half of it.

Anyone who has studied the later parts of the phone system know that at least a few of his stories are actually bullshit.

It wouldn't be until much later (in the 90s at least, while he was in prison) that the advent of pure digital switching would enable the random reassignment of phone lines like he describes in the story about turning his friend's home phone into a payphone.

The lines were separated and had differences in sender frames just for payphones, plus typical phones weren't too happy when 130VDC was applied to them for very long.

The fact of the matter is that Mitnick went around and shook doorhandles until something opened and occasionally convinced someone to open a door for him her and there, and the fact that the emperor had no clothes was too politically inconvenient for the kinds of companies that Mitnick hit up.

Re: Kevin Mitnik FOIA Final

#40

Earlier quoted context omitted.

Other people have mentioned this… but it’s been established in policy that the SSN of a deceased person is not PII. There are a ton of different ways to get the SSN of someone who is deceased.

If anything, having it public could dissuade others from trying to use it.

They aren't "public" but if you have a good reason, the govt will let you see the list of dead people SSNs. It's one of the first things checked when you're trying to open a line of credit because it's so easy to verify.
Post reply on HN