Stories
Slash Boxes
Comments
typodupeerror delete not in

Comments: 96 +-   The Path From Hacker To Security Consultant on Saturday June 27 2009, @11:10AM

Posted by Soulskill on Saturday June 27 2009, @11:10AM
from the curiosity-killed-the-cracker dept.
security
CNet has a series of interviews with former hackers who ran afoul of the law in their youth, but later turned their skills toward a profession in security consulting. Adrian Lamo discusses taking "normal every day information resources and [arranging] them in improbable ways," describing a time when he broke into Excite@Home's system and ended up answering help desk questions from their users. Kevin Mitnick, famous for gaining access to many high-profile systems, warns today's young hackers not to follow in his footsteps, saying, "A lot of pen testers today have done unethical things in their past during their learning process, especially the older ones because there was no opportunity to learn about security. Back in the '70s and '80s, it was all self-taught. So a lot of the old-school hackers really learned on other people's systems. And at the time, I couldn't even afford my own computer." Mark Abene explains how he got interested in phone phreaking, and how it led to a prison term and a career in computer security. Like Mitnick, he says that easy access to powerful modern computers removes part of the motivation for breaking into other systems.
story

This discussion has been archived. No new comments can be posted.
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
 Full
 Abbreviated
 Hidden
More
Loading... please wait.
  • Or maybe... (Score:3, Insightful)

    by Anonymous Coward on Saturday June 27 2009, @11:22AM (#28495423)

    They just realize they can hide better as security researchers. :)

  • Sounds familiar (Score:5, Insightful)

    by unlametheweak (1102159) on Saturday June 27 2009, @11:28AM (#28495457)

    And at the time, I couldn't even afford my own computer."

    Don't do what I've done, do what I say. Things were also tougher for me. When I was a child I had to walk 20 miles to school everyday in a snow storm, through swamps and trying to avoid crocodiles. Things were tough. You kids today have it easy.

    • Re: (Score:1, Insightful)

      by Anonymous Coward

      I dunno, maybe they've learned a lesson and are trying to steer people away from needless hardship?

      • I dunno, maybe they've learned a lesson and are trying to steer people away from needless hardship?

        Perhaps, but unless they've been in jail then it's probably just the same old hypocrisy and moral superiority based on age.

        • Re: (Score:3, Insightful)

          by anagama (611277)
          As people age, they often realize that many of their youthful decisions, which seemed so correct at the time, were not such great ideas afterall. It's a natural part of growing up and the basis for the often heard cliche, "I if I knew then what I know now ..." Any person who gets to 40 and feels that he or she has made only correct decisions in life, probably has some sort of diagnosable condition because nobody does everything perfectly all the time.
          • As people age, they often realize that many of their youthful decisions, which seemed so correct at the time, were not such great ideas afterall.

            I haven't noticed this. I have noticed that people tend to rationalize their behavior. Unfortunately people (personality-wise) change very little with age. So an impulsive ten year old will likely grow into an impulsive forty year old. And depressive people will remain depressive and honest people will remain deviant.

            People will make excuses for their behavior if they get caught, and they will make excuses for their hypocrisy either way. There isn't much altruism in people. People only find religion after t

            • As people age, they often realize that many of their youthful decisions, which seemed so correct at the time, were not such great ideas afterall.

              I haven't noticed this. I have noticed that people tend to rationalize their behavior.

              Some people don't grow up. Some do. I did things as a teenager I have regrets over now because they were stupid or assholish. I understand WHY I did them, but I realize now they weren't the right choices to make in those situations. And in ten years I'll probably be kicking myself for something I'm doing now.

              and honest people will remain deviant.

              Freudian slip? :)

        • by omeomi (675045)
          Perhaps, but unless they've been in jail then it's probably just the same old hypocrisy and moral superiority based on age.

          So, yes, Kevin Mitnick was pretty famously put into prison. From what I remember, he got a particularly harsh sentence because the general public didn't really understand what it was that he did. He wasn't even allowed to use the phone in jail because their was a silly belief that he could launch nuclear missiles by whistling tones into the receiver or something. He did something wr
          • Just as a simple spell check could have spared you the embarrassment.
          • Did you even read the summary? In the summary you can clearly read that one of them spent time in prison.

            Really? I obviously wasn't referring to that one person referred to in the summary, and I obviously am not embarrassed. I have been aware of Kevin Mitnick since the 1990s; there is no Google search necessary.

      • That trick never works.

    • by sco08y (615665)

      When I was a child I had to walk 20 miles to school everyday in a snow storm, through swamps and trying to avoid crocodiles.

      Yeah, I remember, when I was a child I actually had to walk to a library to borrow an actual book.

      Don't do what I've done, do what I say

      Sounds familiar. [nizkor.org]

      Look, I'm not even saying that kids have it easy nowadays, far from it. I remember learning to program on a C-64. You could memorize all the important addresses. Your languages were BASIC and assembler. You had a grand total of 3 regist

  • by petes_PoV (912422) on Saturday June 27 2009, @11:31AM (#28495479)

    he broke into Excite@Home's system and ended up answering help desk questions from their users.

    Sounds like he's still being punished for his "crimes".

  • Old adage. (Score:4, Interesting)

    by dov_0 (1438253) on Saturday June 27 2009, @11:40AM (#28495555)
    It takes one to know one. This works in all sorts of industries. The best teachers for example were often the worst behaved students.
    • Re:Old adage. (Score:5, Insightful)

      by Antique Geekmeister (740220) on Saturday June 27 2009, @11:49AM (#28495617)

      No, the best teachers really weren't the worst students. That's a silly idea.

      The "worst behaved" students of my experience, and ossibly yours, are dead, massively crippled by their own foolishness, in jail, dying of AIDS or lung cancer, homeless, etc. Being homicidal, fundamentally stupid, a slut of any gender or orientation, constantly stoned, or spoiled does not help one as a teacher.

      There are kinds of behaviors that are frowned on by authorities, for lots of understandable reasons, but help people be leaders or teachers. Curiousity, interest in others, love of particular types of knowledge, etc. can all hinder someone in school but pay off for teachers, true.

      • Re:Old adage. (Score:5, Insightful)

        by dov_0 (1438253) on Saturday June 27 2009, @11:59AM (#28495699)
        Maybe your experiences are different to mine.
        • Maybe your experiences are different to mine.

          I think your right. Just a wild guess here, but you probably went to a public school in a rich suburb, and the GP probably teaches in the ghetto, where the "bad" end of the behavior spectrum has different motivations and higher stakes. Think John Hughes vs. Spike Lee.

          • by dov_0 (1438253)
            I didn't go to the 'nicest' schools, but I went to school in Melbourne, Australia. Yeah we have violence and drugs, but nothing like some schools in the US it would seem.
        • Apparently so. And to counter another poster, I attended both public and private schools, depending on various family circumstances. The private schools could _kick out_ the worst students, and dump them on the public schools to deal with. There were occasions where the private schools could also take on horrible cases that the public schools could not hope to handle properly: clergy who are willing to box a child's ears instead of public school teachers afraid to defend themselves were something I learned
    • Academia wise the worst students at my school dropped out (~20 from my class) or got expelled (1 from my class) and didn't graduate so there is no way they can become teachers.
    • Re:Old adage. (Score:5, Interesting)

      by thesandtiger (819476) on Saturday June 27 2009, @01:22PM (#28496199)

      If by "worst behaved" you simply mean the ones that would challenge authority and "color outside the lines," then sure - those kinds of "misbehaviors" are pretty common among people who are really good at their job. That seems to be a pretty milquetoast version of "worst behaved" though.

      As someone who went to Chicago Public Schools, I can say that the "worst behaved" students are the ones who were unable to handle any kind of structured environment, were disruptive and violent towards other students, were often high if they bothered to show up for classes, and generally couldn't handle even remedial work. The few of these kids that eventually straightened themselves out might make good mentors or counselors at programs to help at-risk children, but generally wouldn't be what I'd call good teachers because they're usually lacking the academic accomplishment that really good teachers must have.

      On the issue of taking one to know one - I think it's possible to be a good security expert without being a convicted felon. Given the choice between hiring someone who is very good but a convicted felon vs. someone who is very good and who has the moral compass necessary to avoid committing acts that are criminal, I'll take the latter any time. There are *millions* of people the world over who do computer security - most of them without criminal records - it's not exactly like it's some kind of arcane art or a skillset so hard to come by that one must hire a (hopefully former) black-hat.

      My guess is some of these guys are being hired by organizations who want to use their felony record as some kind of street cred - "Our security is the best; we've got one of the worst of the hackers in charge of it!" etc.

  • by syousef (465911) on Saturday June 27 2009, @11:42AM (#28495577) Journal

    It is the exception, not the rule, that a hacker becomes employed as a highly paid consultant. A lot of jobs require security checks, which you will fail if you have a criminal record. Some places have the flexibility to allow exceptions. Most don't. Even if they do you have to prove you offer something so unique and worthwhile that an exception should be made.

    It does happen. Hackers do sometimes get jobs. People also win the lottery. Doesn't mean it's smart to play against the odds.

    • Re: (Score:1, Informative)

      by Anonymous Coward

      Oh fuck!

      I went and got busted for: drugs, hacking, running guns, spying on a defence contractor, and bribing a judge. I was planning on becoming the most bad-ass security consultant on Earth.

    • Re: (Score:3, Interesting)

      by Anonymous Coward

      "A lot of jobs"? You mean jobs where you're an employee.

      This is why most of these guys are "consultants". That is, they run their own business and therefore don't typically require any of the normal checks that employees have to get. Some (government) things require security clearance but most stuff does not. All you need is a good reputation and proven skills.

      • Re: (Score:3, Informative)

        If you are hiring consultants to perform security-related functions, you're being negligent by not doing background checks and such on them. Any security-related processing you are doing on full-time employees should be done on contractors as well if they are doing similar jobs. If you're not doing that, you're doing it wrong.
        • Indeed. In healthcare in the US, any felony conviction keeps you completely out of employment or consultancy. Period. Significant potential downsides for not vetting employees and consultants. Even in our tiny little hospital we have one FTE for all of the 'compliance' issues we're forced to follow. Not saying it makes any sense at all, but there it is.
      • Most of the places I would work at have long standing policies that forbid the use of even gray hats in security. It doesn't matter if they are employees or contractors or consultants. If it is learned that you have a black hat record, you are out of security.

        Seem harsh? Maybe, but it sure beats the alternative of hiring yet another pretend reformer.

    • by smoker2 (750216) on Saturday June 27 2009, @12:58PM (#28496059) Homepage Journal

      It is the exception, not the rule, that a hacker becomes employed as a highly paid consultant.

      How do you know ?
      Surely if you were any good at it you wouldn't get caught, so no criminal record. It's only the ones who do get caught that have nothing to lose by exposing their past. And of course they're going to say "don't do it". I would argue that we need more people involved in it not less. Why should "the man" have everything his way ? Sometimes it is necessary to step outside the law, precisely because it is the law. If an authoritarian govt. says you can't access a website, should you just say "yes sir", or would you find a way to do it anyway ? I would have thought that with all the passive-aggressive angst on here recently regarding Irans internet policy, the answer should be obvious.

      "Hacking" drives security, and keeps the corporations and the govt. awake. Information is control, why should the powers that be have all the control ?

      • Surely if you were any good at it you wouldn't get caught

        Eventually most criminals get complacent or unlucky and slip up and are caught.

        Why should "the man" have everything his way

        Really this is the best you've got? 1960s rhetoric that didn't make much sense even back then unless you were completely stoned?

        "Hacking" drives security, and keeps the corporations and the govt. awake. Information is control, why should the powers that be have all the control ?

        I see. You are stoned.

    • It is the exception, not the rule, that a hacker becomes employed as a highly paid consultant. A lot of jobs require security checks, which you will fail if you have a criminal record.

      Hacker !imply Criminal

      Yes, some hackers are criminals but not all are - and *a lot* of the ones who aren't are in fact highly paid consultants. Please stop spreading the misperception that hacking is criminal or unethical.

      • Yes, some hackers are criminals but not all are - and *a lot* of the ones who aren't are in fact highly paid consultants. Please stop spreading the misperception that hacking is criminal or unethical.

        I am not spreading any such misconceptions. In the context of this story we're talking about hackers who have broken the law but managed to get a job inspite of or notionally due to their experience with hacking.

    • Thank you, I got here late.

      A criminal record is NOT a recommendation paper. Quite the opposite. These people got their jobs despite a record. Not because. A criminal record is, essentially, the proof that you made a mistake. Else you wouldn't have been caught. They are the icons of hacking, and that's what landed them jobs. DESPITE their records.

      That's not to say that there are no "white hats" that never crossed the legal lines. It's easier now today, who could afford a mainframe server in the 70s to test i

    • by Ihmhi (1206036)

      Remember kids, criminals never make money! Just look at Martha Stewart, 50 Cent, and Don King!

  • Speaking from experience, it is difficult to get back into the workplace after a battle with law enforcement due to a high-tech crime. It is possible, however. Keep your nose clean and keep up with the industry and eventually you can regain a bit of trust. I am proof that it is possible, as I was once the subject of a Slashdot interview regarding a pretty public piracy case.
      • no, because it lets you easily split files back in the days before there were a lot of compression technologies to choose from. Also, it has checksums that help when you're trying to correct corrupt downloads via parity files (i think.. haven't used newsgroups in a while)
  • Not in my experience (Score:4, Interesting)

    by Anonymous Coward on Saturday June 27 2009, @12:06PM (#28495735)

    I worked at a company who shall remain anonymous. I worked there as their security consultant and was in charge of keeping the systems secure.

    I noticed that their systems were insecure, I kept telling them that these things will get hacked, I kept telling them that they are wide open. Did they listen to me? No. They kept going on and on, I worked to patch as many holes as I can, but the system was insecure in itself (things like passwords stored in plain text on mysql databases etc...). Fixes I recommended were rejected by management because they would change things from how they were used to, or too expensive, or "but who would want to hack us" responses.

    A few weeks ago our external servers get hacked (surprise surprise), and the hacker notifies the company. What do they do? They pay the guy 600 euros per domain (we have a lot of domains) to fix it for us. That dude had the ear of all management, everything he said went, they changed things that I've been recommending to them for months because he said so. And to finish it off, he earned more money in those two weeks working for this company than I did in the last 6 months, to make fixes I've been telling them to do since I got the job.

    F*ck it, in future I will just break into computers and then offer them a huge fee to fix them, It seems to pay more to do it that way. The company didn't call the police, just kept it as quiet as possible so word didn't get out.

    Posting anonymously for obvious reasons.

    • by fluffy99 (870997) on Saturday June 27 2009, @12:25PM (#28495853)
      Have you expressed this very directly to your management? Perhaps now they will be more receptive to your wisdom. If they aren't, you need to either find another job or recognize that they really don't give a crap and work with what you've got. Otherwise, continuing to complain when they don't care will just get you labeled a whiner, or worse a scapegoat when another intrusion happens.
    • Re: (Score:3, Interesting)

      by bvankuik (203077)

      That dude had the ear of all management, everything he said went, they changed things that I've been recommending to them for months because he said so.

      I am reading a lot of stuff here that is very recognizable for me as well. The post ends somewhat bitterly. Instead I'd advise you brush up on your social skills and ask your employer in a good man to man conversation why your advice did not hit the mark and what you can do the next time. They might advise a couple of soft skills trainings and will probably be willing to pay for those. You'd probably also get something out of it.

    • Security is risk analysis. If you want your company to make security changes, you need to give the stakeholders the information they need to make decisions, in terms of dollars and cents and probabilities.
      I would recommend you pick up a few books like "The New School of Information Security" and "Security Metrics: Replacing Fear, Uncertainty, and Doubt". They do a good job of helping you to see security risk through business eyes.

  • Me don't like (Score:2, Insightful)

    by ZouPrime (460611)

    I don't like these articles on hackers becoming security consultants. Obviously it has happened in the past - and the story itself covers well known examples, but doing information security for private corporation is so much, much, much much much more than pen testing and other skills typical crackers are good at. In practice, the vast majority of security professionals aren't ex-hackers, and that's a damn good thing.

    Maybe it's because I'm actually working in the field, but I really don't like how the media

    • by cenc (1310167)

      Several of the security companies chiefs in interviews flatly say they don't hire hackers. Why? Because they are lazy workers. Not they do not have talents or experience, but the kind of social background that produces the best of them also produces the worst sorts of employees. It was not about their encounters with the laws.

  • Security Vendors need people with 'the cracker mentality' to join their ranks. Without 'morally gray' staffers, how could they supply regimes like the ones in Iran and China with the 'tools' they need to operate their repressive regimes? Morally blind nihilists, while not necessarily those to fill the ranks of the Ideologically 'pure' elite inside the regime, will always be necessary force.

    The people that they can't EVER become involved with are the real hackers.

  • A common theme of a lot of the replies seems to be that black hat behavior is the only way to learn computer security. Far from it. I don't need to have broken into an insecure network connection without permission to understand the problems of sending passwords in the clear. Often, it takes a little imagination, a bit of reasoning, and a bit of technical skill -- the same skills I often suggest for system administrators.

    The best security analysts I've worked with are so strictly white hat that they've m

  • by itomato (91092)

    A Hacker with the proven ability to create and execute a project plan should be seriously employable.

    Know what pieces overlap, understand how they impact the business, and what it takes to get from A to Z.

    • I've always thought that distinction was a woeful attempt to separate the negative connotations from the "coolness" factor. The fact is, I'm a coder or a programmer or a software engineer for the initiated. A hacker is someone who hacks out code and I've been forced to work with more than enough of those crappy libraries to embrace the title.
    • Re: (Score:2, Informative)

      by Anonymous Coward

      The widely-accepted definition of a hacker is different than your romanticized version of things. That horse has left the barn - you can be disappointed all you want but trust me, you're only bothering yourself with it.

      I bet you insist on GNU/Linux, too.

    • Re: (Score:2, Interesting)

      I'm disappointed, Slashdot reader/commenter. Everyone here should know that the meaning of the word "hacker" has changed over time and evolved to mean, most of the time, what "cracker" means. Word definitions change over time and this word has been assimilated with a new definition, accepted by the majority of the English-speaking world. If you want to hang on to the cracker vs hacker definitions, feel free. But most people have moved beyond this.

      Plus, your definition of "hacker" is off anyway. In
    • by ActusReus (1162583) on Saturday June 27 2009, @12:34PM (#28495905)
      Sorry, but I think it's time to acknowledge that there are some "Wordsmith Wars" that have simply been lost. Moreover, lost about 10-15 years ago. The general public is not going to refer to "Linux" as "GNU/Linux"... not going to use licensing terms like "Libre"... and thinks of "cracker" as a silly racial slur for white people.
It doesn't much signify whom one marries, for one is sure to find out next morning it was someone else. -- Will Rogers