Live data from Hacker News

Kevin Mitnick has died

dignitymemorial.com

561–570 of 666 posts

Re: Kevin Mitnick has died

#561

To be candid; fuck this narrative. Nobody "Beats" cancer based on sheer will. Same scenario as those that did not "Fight hard enough". It's a disease. It does not care about your wants, and needs.

IDK.

The way I read u/ecohen16's telling is that Mitnick first beat apathy and bureaucracy just to have a shot at mitigating a disease, thereby postponed the inevitable.

I've lived it. Late 80s, I had a terminal diagnosis. Lucky me, my doc found a clinical trial, and fought like hell to get my HMO to pay. Justification was for org to use me to learn about emerging treatment (stem cell transplant is current variation).

A few years ago, my buddy got a terminal diagnosis. Apparent chronic sports related injury turned out to be a late stage tumor, which had spread. Prognosis was 3 - 6 months. None of his care providers were interested in escalating, only talking about palliative care and hospice. He did exactly as Mitnick. Managed to get enrolled in a clinical trial using immunotherapy for his precise diagnosis. Timing wise, a few weeks either way and he'd be dead. Dumb luck.

I can give a few more examples. (And 100s of counter examples.)

Do patients beat cancer?

Of course not. Among the survivors I know, disease (like cancer) is part of life and you deal with it. Or not.

But, some times, if we're really stubborn, and have sufficient resources and support and dumb luck, we can do things to live a little bit longer.

> that did not "Fight hard enough"

Sometimes the patient, family, and especially the care providers don't fight hard enough. For all sorts of reasons. Probably because awareness of mortality made humans neurotic and we're all just winging it. Probably because everything is russian dolls of triage.

Any way, it's just a metaphor. Chose the one that works for you.

Just like I refuse to victim blame/shame, I'm not going to judge another person's coping mechanisms.

Re: Kevin Mitnick has died

#562

Earlier quoted context omitted.

213-954-8607 Random number, legit area code. Unless you are looking for all 10 digits, pretty easy social hack

Yeah, the only worry is someone saying mine fifty four. And you don't catch 5. But that's pretty easy. Sorry I didn't catch that could you do it one number at a time?

"Was that sixty four, as in six-four?"

"Sorry, no 54, five-four."

"You said five ... four?"

"Yes, five ... four."

Doing the thing you want people to do is actually a pretty good strategy.

Recognizing when people are employing this strategy on you and intentionally not doing the thing is good fun too.

Re: Kevin Mitnick has died

#563
post #491
post #488

Earlier quoted context omitted.

Seemingly sensible? This one? > the authentication mechanism was reading out your own account number in your voice That's the most suspect part of it to me - even vulnerability to malicious attack like this aside, who would think that's a good idea or going to work well? What percentage of people could successfully use a voice assistant to make a note of their bank account number the first time? Nevermind have it det…

I think something was lost in the retelling. It could just be an era when people didn't figure out biometrics yet. It makes sense today, but caught up in new hype, people often implement cutting edge technology where it doesn't belong.

“Your voice is your password” kind of systems are still around.

Re: Kevin Mitnick has died

#564

Earlier quoted context omitted.

You send the money to a literal mailbox instead. That’s how. (Using a check, the very infrastructure we’ve been talking about!!)

But then you've given out your bank account number, so the secrecy is bunk.

The US bank security system confuses me. To accept money, I need to give out my routing number and account number. Using those numbers, someone could theoretically withdraw money... Maybe... The whole system is built upon obscurity. Why do some stores need a pin on my debit card, and some do not? Why do online stores need my name and address, but IRL ones do not? How did that one online store charge me without my CVV? How can restaurants swipe my card now and charge me later?

I only send and receive money with Google/Apple Pay & PayPal at this point. This flow is reasonable (every transaction is authorised in a trusted location (ie: PayPal). Further transactions are impossible without additional authorization). It boggles my mind that banks & CC companies haven't made some standard for this. Would save them so much money in fraud protection.

Re: Kevin Mitnick has died

#566

Earlier quoted context omitted.

Pro-er tip: if you are in the US and access a computer over any kind of service provider network (Internet, leased line, etc.) you should operate on the assumption your traffic is crossing state lines and the CFAA applies to your activities. Tools like traceroute cannot show you where your traffic is physically being sent because: there may be no geographic information in the router reverse DNS records, that informat…

How can the DNS records not be accurate?

rDNS information is provided by the owner of the IP address, not the owner of the domain. More generally there are spoofing and poisoning attacks against DNS.

Re: Kevin Mitnick has died

#567
There was something I always wanted to ask him:

He was so meticulous is setting up new identities and moving to random places around the country to avoid the authorities. But would then log back into his previously compromised systems in a way that would expose his current geographic location. It always seemed like such a glaring hole in his otherwise well thought out personal opsec. I'm sure the story was more complicated than what appeared in the press at the time, or in the 2600 knock-off zines that were going around at the time, or in his books. It always confused me. I could never figure out if that was an oversight, or he just wasn't aware he was being watched.

I think I share a similar pendulum swinging feelings about km as other folks here, especially as his story unfolded across many different phases of my life: from adulation as a teen, to realizing that he was just another a*hole who would lie to your face to get what they want. Recently it has swung waaay back the other way -- especially as more of our access to customer service for critical aspects of our lives get buried behind obstructionist systems -- to understanding that we always need people who can tear any system apart.

As an addendum...I think the term hacker should be handed to the sys admin that started was instrumental in getting km located by (If my foggy mind remembers correcly) by emailing logs or log stats to himself and noticing that size was shrinking so someone was deleting them -- that blew my mind at the time.

He will be missed.

Re: Kevin Mitnick has died

#568

Wow. My first encounter with Kevin Mitnick was a random one.. joining one of my school's IRC channels one day there was there guy on it who was bragging about how he had broken into our central AIX server, would read the admins' e-mail all the time and for every hole they plugged he would just find another one. I was just a university Freshman just starting my CS classes, and seeing this discussion, it was like I had…

https://www.youtube.com/watch?v=MctHTxESCFM

Re: Kevin Mitnick has died

#569

Earlier quoted context omitted.

Pro-er tip: if you are in the US and access a computer over any kind of service provider network (Internet, leased line, etc.) you should operate on the assumption your traffic is crossing state lines and the CFAA applies to your activities. Tools like traceroute cannot show you where your traffic is physically being sent because: there may be no geographic information in the router reverse DNS records, that informat…

How can the DNS records not be accurate?

You can make a reverse DNS record (or any DNS record, for that matter,) say anything at all. There isn't a National Committee for the Verification of DNS Updates checking this stuff out and demanding in-person inspections and notarized affidavits swearing that 100% of all information in the DNS is accurate and means whatever the end-user might infer it to mean.

For instance, part of the tracroute from my house to Google looks like this:

6 be-33112-cs01.doraville.ga.ibone.comcast.net (96.110.43.81) 19.602 ms

7 be-33142-cs04.doraville.ga.ibone.comcast.net (96.110.43.93) 22.738 ms

8 be-302-cr13.56marietta.ga.ibone.comcast.net (96.110.39.49) 23.202 ms

You can see these hostnames are obviously meant to encode some geographic data -- strictly for the convenience of the provider, it doesn't mean anything else -- but you, as the user, cannot tell from these records that these routers are actually where you think they are, based on the host names.

Another issue is the server you're communicating with might take a completely different path to get back to you, and you'd have no real way of knowing that.

Re: Kevin Mitnick has died

#570
From Wikipedia: "Mitnick also intercepted and stole computer passwords, altered computer networks, and broke into and read private emails." - what a nice guy he was.
Post reply on HN