Live data from Hacker News

Kevin Mitnik FOIA Final

vault.fbi.gov

81–90 of 99 posts

Re: Kevin Mitnik FOIA Final

#81
post #36
post #20

Earlier quoted context omitted.

I've far more respect for Tsutomu. In the end he turned out to be the better hacker. Reading Mitnicks book I sometimes get the impression that the he is making up half of it.

To the best of my knowledge, Mitnick didn't really code at all. There are (let's call them) intrusion specialists whose skillsets don't really involve systems programming, but rather intuition and tenacity, and there are others who write exploits. My understanding is that Mitnick was the former, and was using tools he got from friends and peers.

I have met the type on my time on the internet. All it takes is having the guts to push through with what others give you, things they themselves know would get them in legal hell.

Re: Kevin Mitnik FOIA Final

#83
post #20

Earlier quoted context omitted.

If you are into this topic, read as many point of view as possible and take a look at http://www.takedown.com/ (Tsutomu Shimomura's side of the story).

I've far more respect for Tsutomu. In the end he turned out to be the better hacker. Reading Mitnicks book I sometimes get the impression that the he is making up half of it.

John Markoff was the one that made everything up.

Freedom Downtime is a documentary that explains it.

Re: Kevin Mitnik FOIA Final

#84
post #43

Earlier quoted context omitted.

The Mitnick files contain information about innocent people who are alive and whose privacy rights remain paramount.

Perhaps too naive a question, but if they are innocent what is there to protect? I get it in the case of informants or agents that operate undercover or in plains clothes but if just a bystander how is it different than some news article?

maybe you told someone you were going to be some place else

maybe you were with your other family and this unwarranted disclosure revealed that to a scorned spouse and friend group that are always looking for holes in the story 40 years later

not criminal issues, not an FBI problem, and yet can alter your private life

Re: Kevin Mitnik FOIA Final

#85

Earlier quoted context omitted.

What's your name and address? (Rhetorical question, please don't answer.) Is that info you'd be comfortable sharing on a public forum? I presume you're not doing anything particularly wrong. This also assumes that we can all agree on a definition for "innocent." > what is there to protect? Their privacy. Some people have strong opinions on 3 letter agencies and poor reading comprehension. Some people are just mean sp…

Licensed ham radio operators give their address every 15 minutes by law. And their full name. Sometimes it's a PO box, but mostly a home address's. I can't think of anything more public than airwaves.

This is a bad take. Plenty of licenses involve essentially exchanging a right for a privilege (in simple terms). People who aren't comfortable with this compromise have the choice to not get a certain type of license (and many don't, HAM radio licenses aren't held by anywhere near a sizeable chunk of the population).

Is the underlying assumption that everyone redacted in that report is a licensed HAM radio user deprived of their right to have a private name and address?

Re: Kevin Mitnik FOIA Final

#86
post #51

Earlier quoted context omitted.

He also comes from an era of intrusions where systems were so bad you didn't really need to code to get into them. For an alarmingly long time, the most effective tool you could use to pop a network was simply `showmount`.

That time is still today, as people are still the weakest link. A talented scammer can convince people to give them access to their WhatsApp account despite the E2EE, 2FA, and SMS verification codes. In Mitnik's version, he RTFMs, learned the technical lingo, procedures, and even the names of telco employees.

100%

The majority of corporate breaches are a combination of poor Least Privilege practices and phishing/smishing.

Even with well secured, alert personnel, you often see ISPs and Telcos socially engineered to gain access to an employee account.

Re: Kevin Mitnik FOIA Final

#87
post #16

It should be illegal for the government to keep redactions in anything made public/declassified. It's a slap in the face to see entire sections of text (that most certainly contain important context) blocked out with a white blob.

Also, the human effort required to make the redactions is high.

That means records cannot be automatically declassified after N years because the effort to redact every document created N years ago would be extreme.

Re: Kevin Mitnik FOIA Final

#88
post #70

Earlier quoted context omitted.

I think you possibly haven't read very many court documents. When these cases actually get tried much of this becomes public anyways. In particular this document details agents Mitnick _himself_ spoke with. Are you really suggesting their redactions here are to prevent reprisals? How could that possibly work?

It's one thing if Kevin Motnick knows and the other if all of the internet knows and it's indexable

So he goes on a blog and types it.

Are we not at square one again?

And did Mitnick ever know Motnick? Am I experiencing the Mandala effect here?

Re: Kevin Mitnik FOIA Final

#89
post #51
post #42

Earlier quoted context omitted.

In the book he spends a lot of time on the social engineering parts of it to be honest. It's been a few years but I remember him mostly bragging about that rather than developing custom exploits.

He also comes from an era of intrusions where systems were so bad you didn't really need to code to get into them. For an alarmingly long time, the most effective tool you could use to pop a network was simply `showmount`.

Yeah I think Mitnik’s abilities were mostly around thinking about doing stuff that no-one had considered that you could do. It’s still a big skill, but nowadays, there’s less stuff that no-one has thought about before.
Post reply on HN