Live data from Hacker News

ATT dumps Kevin Mitnick

theregister.co.uk

31–40 of 45 posts

Re: ATT dumps Kevin Mitnick

#31

An 8 digit, all numerals password? Really, Mitnick? Also, it wasn't just AT&T that is refusing service to him, his webhost HostedHere.net did the same thing. And if this has been happening over and over again for 9 years why didn't he just want to go to another service provider?

I had to re-read the article about the eight digit password. As it is for his phone provider, I presume it has to be numbers so it can be typed in from any phone keypad. I can't believe someone with Mitnick's track record would use an all-numbers password by choice.

"Mitnick said that per AT&T policy, his password could only be digits and no more than eight characters long."

Re: ATT dumps Kevin Mitnick

#32
post #8

I find Kevin Mitnick going to the authorities for protection a little bit weird. If your claim to fame is that you are the 'worlds baddest hacker' you take the script kiddies as going with the territory. It's like Billy the Kid complaining about the wanna-be's that want to meet him at noon on main street. "The move by AT&T came this week after Mitnick hired a lawyer to complain that his privacy was being invaded by p…

Dear downmodders, if you disagree speak your mind. Feel free to downmod away but at least let me know which bit you disagree with and why.

Re: ATT dumps Kevin Mitnick

#33
post #8

I find Kevin Mitnick going to the authorities for protection a little bit weird. If your claim to fame is that you are the 'worlds baddest hacker' you take the script kiddies as going with the territory. It's like Billy the Kid complaining about the wanna-be's that want to meet him at noon on main street. "The move by AT&T came this week after Mitnick hired a lawyer to complain that his privacy was being invaded by p…

Dear downmodders, if you disagree speak your mind. Feel free to downmod away but at least let me know which bit you disagree with and why.

Downmodding isn't for disagreement anyway; it's about the kind of comment HN users want, not the stance taken by the commenter. I don't have downmodding power, but I chose not to upmod you because of your flippant tone.

Re: ATT dumps Kevin Mitnick

#34
post #17

Wouldn't such a customer be worth gold? A single user that constantly get's attacked by hackers would provide a great opportunity to detect and fix security holes. If a hacker get's through, it is just one person's account compromised. But each detected attack could prevent attacks on other accounts. I think some other telco should pay Mitnick to become their customer. How else could you attract so many hacker brains…

It also keeps the hacking attempts more-or-less contained to a single known user's account. Handy!

Re: ATT dumps Kevin Mitnick

#35
post #17

Wouldn't such a customer be worth gold? A single user that constantly get's attacked by hackers would provide a great opportunity to detect and fix security holes. If a hacker get's through, it is just one person's account compromised. But each detected attack could prevent attacks on other accounts. I think some other telco should pay Mitnick to become their customer. How else could you attract so many hacker brains…

A single user that constantly gets attacked by hackers would provide a great opportunity to detect and fix security holes.

Assuming that they want to fix the holes, which AT&T probably doesn't. They may be using the "infinite bugs" model, in which fixing one bug does not improve security because there are always other bugs the attackers can find.

Re: ATT dumps Kevin Mitnick

#36
post #11

Earlier quoted context omitted.

Security through obscurity gets a bad rap. You rely on the "obscurity" of your password. The main issue is relying on false obscurity, both in systems (your program rot-13s your password) and in passwords (you pick an easy to guess password). There's no real security failing if you rely on obscurity that isn't exactly a password, so long as you can accurately assess the real obscurity, e.g. port knocking. If, let's s…

"You rely on the "obscurity" of your password." Not really. Your password may be obscure (although it should probably be as random as you can get), but the key exchange protocols and encryption algorithms should be wide open. There's a reason why secret keys are called "secret" -- they should be the only thing you have to keep secret. If his hosting provider and wireless company can't keep his accounts secure, that's…

Reading my comment over, I realize that I wasn't so clear.

There are two almost unrelated issues:

AT&T has poor security - agreed.

Security through obscurity is a universal evil - not so fast. Quick example - you have ciphertext where you don't know the key vs. the same ciphertext where you don't know the key AND you don't know the algorithm. The latter is more secure, because it's harder to brute force.

The reason security through obscurity is usually bad is because it causes people to make poor assumptions - "He'll never guess I encrypted it with rot-15 instead of rot-13," but for a given secure system, adding obscurity will make it harder to break. But it's the poor assumptions that do you in, not an inherent flaw in adding obscurity.

The reason you use widely published encryption algorithms is because they've been vetted for poor assumptions. They need to be open to be vetted, not to be secure, and we've found that's always been a good tradeoff.

Re: ATT dumps Kevin Mitnick

#37
post #35
post #17

Wouldn't such a customer be worth gold? A single user that constantly get's attacked by hackers would provide a great opportunity to detect and fix security holes. If a hacker get's through, it is just one person's account compromised. But each detected attack could prevent attacks on other accounts. I think some other telco should pay Mitnick to become their customer. How else could you attract so many hacker brains…

A single user that constantly gets attacked by hackers would provide a great opportunity to detect and fix security holes. Assuming that they want to fix the holes, which AT&T probably doesn't. They may be using the "infinite bugs" model, in which fixing one bug does not improve security because there are always other bugs the attackers can find.

Brilliant - an infinite number of bugs might confuse hackers so much that they don't know where to start and just give up.

Re: ATT dumps Kevin Mitnick

#38
post #36

Earlier quoted context omitted.

"You rely on the "obscurity" of your password." Not really. Your password may be obscure (although it should probably be as random as you can get), but the key exchange protocols and encryption algorithms should be wide open. There's a reason why secret keys are called "secret" -- they should be the only thing you have to keep secret. If his hosting provider and wireless company can't keep his accounts secure, that's…

Reading my comment over, I realize that I wasn't so clear. There are two almost unrelated issues: AT&T has poor security - agreed. Security through obscurity is a universal evil - not so fast. Quick example - you have ciphertext where you don't know the key vs. the same ciphertext where you don't know the key AND you don't know the algorithm. The latter is more secure, because it's harder to brute force. The reason s…

Please give the public origins of the notion that security through obscurity is broken a closer look. Until you understand what that means, you will keep making arguments like "keeping your key" (such as a password) "secret is just security through obscurity".

I recommend starting with Kerckhoffs' Principle.

Basically, you can regard "security through obscurity" as any violation of Kerckhoffs' principle -- which translates to any reliance on keeping secrets beyond the key itself.

Re: ATT dumps Kevin Mitnick

#39

Earlier quoted context omitted.

It's easy to run up long bills if you roam internationally, $3/minute adds up fast.

That's why you get an unlocked phone and buy an international SIM chip that you swap in overseas. $20K/year is ridiculous, and probably an exaggeration or lie on his part to try to make himself look like a desirable customer.

Except you also incur roaming charges for receiving calls, and expecting people to call an overseas number (let alone keep them up to date on your whereabouts) really is pushing it.

Re: ATT dumps Kevin Mitnick

#40
post #36

Earlier quoted context omitted.

"You rely on the "obscurity" of your password." Not really. Your password may be obscure (although it should probably be as random as you can get), but the key exchange protocols and encryption algorithms should be wide open. There's a reason why secret keys are called "secret" -- they should be the only thing you have to keep secret. If his hosting provider and wireless company can't keep his accounts secure, that's…

Reading my comment over, I realize that I wasn't so clear. There are two almost unrelated issues: AT&T has poor security - agreed. Security through obscurity is a universal evil - not so fast. Quick example - you have ciphertext where you don't know the key vs. the same ciphertext where you don't know the key AND you don't know the algorithm. The latter is more secure, because it's harder to brute force. The reason s…

"The reason you use widely published encryption algorithms is because they've been vetted for poor assumptions. They need to be open to be vetted, not to be secure, and we've found that's always been a good tradeoff."

True. Most people (including Schneier, Ferguson, Rivest, etc) agree that the NSA is secure. This is because they have a veritable army of cryptographers at their disposal. Peer review is the most important part of cryptographic development. The key part of this is that there is probably no other entity in the United States that can satisfy these requirements. AT&T certainly does not have an impressive cryptographic department and they shouldn't pretend like they do.

"The reason security through obscurity is usually bad is because it causes people to make poor assumptions - "He'll never guess I encrypted it with rot-15 instead of rot-13," but for a given secure system, adding obscurity will make it harder to break. But it's the poor assumptions that do you in, not an inherent flaw in adding obscurity."

I don't think anyone would argue that the obscurity in the algorithm is the weakness. However, obscurity can never make a secure algorithm more secure. If your algorithm and key space are sufficient to prevent decipherment before the heat death of the universe, the two months it takes to reverse engineer the protocol are as close to zero as makes no difference.

Post reply on HN