16 ms·
I worked at a company that had hired Mitnick as a security consultant. His report for a client that turned out to have been rife with SQL injection at the time
by mcfunley 3mo ago
I worked at a company that had hired Mitnick as a security consultant.
His report for a client that turned out to have been rife with SQL injection at the time was largely movie plot physical security stuff. Not wrong exactly, but not the center mass of the threat model they needed either.
He seemed to lack systems thinking, producing a report that focused on calling out specific employees as dumb or incompetent. Counterproductive at best. It seemed like his PR exceeded his utility by a great deal.
That trend continues beyond the grave, maybe.
- lern_too_spel 3mo agoHe social engineered your company into contracting him, and that adds to the legend, but people don't see how many other companies he failed to social engineer.
- topham 3mo agoThe hero worship of him makes me physically ill, always has. He did cost people their jobs though, so I guess he's a good person.
- deepsun 3mo agoIt's like we don't have any messiah's today that are mediocre professionals at best.
- shuwix 3mo agoBeing incompetent didcause people to lose job which required certain level of competence. Job they shouldn't have in fiest place. Social engineering is just that, exploiting people having insufficient intellect for the job.
- kingforaday 3mo ago> "He was a hacker-turned-security consultant who, later in life, helped shape the modern white-hat." They left out convicted criminal.
- firefax 3mo agoI have so many stories about his absolutely terrible behavior at conferences. He once refused to pay the entry fee to a charity event and had to be physically ejectedy. Absolutely better at PR than any actual work, pay careful attention and none of his early stuff was particularly novel, from a technical perspective. But for whatever reason, we venerate him just because he was victimized by the state. The world is not a dichotomy -- sometimes bad things happen to bad people.
- colechristensen 3mo agoHe got all of the "Free Kevin" attention because of how long he was left in jail before trial and then being stuck in solitary confinement after sentencing for months. If he had been treated fairly by the justice system he wouldn't have gotten nearly as much attention. He was also autistic, a lot of the behavior can be explained through that lens.
- firefax 3mo ago>He got all of the "Free Kevin" attention because of how long he was left in jail before trial and then being stuck in solitary confinement after sentencing for months. That was uncalled for on the part of DOJ. >He was also autistic, a lot of the behavior can be explained through that lens. I'm autistic. Maybe I should go commit a bunch of felonies to increase my chances of a good job and stature in the hacker community, since things like publishing code, publishing peer reviewed papers, and mentoring newbies have not been productive ways of finding gainful employment nor respect of my peers. I have friends who did things like take a gap year to travel the world or met their spouses on nights I stayed in to study, and some evenings when browsing HN I feel very sad that I wasted my 20s on a society that does not care about me. Anyways, sorry to wall of text, but what you said really struck a nerve with me -- there are hierarchies in any community, and one thing I've noticed with the hacker scene is one group of people can mess up over and over using the same sets of facts or diagnoses, but others can expect to have worse outcomes with better behavior for reasons that elude me to this day.
- the_af 3mo agoKevin's security company is also a mess, and the training videos they produce are embarrassing at best. I understand he probably just lent his name to the company (though he did show up in some of the videos), but still...
- anthk 3mo agoThis is what happens when the 90's PC community renamed crackers as hackers. Proper hackers would have been the ITS/WAIS ones doing crazy things with computers for its era.
- deleted 3mo ago[deleted]
- leetrout 3mo agoDude I was called out by name in the report either right before you got there or the first one you were there. I was called out in the one where they got B's Audi keys in his office. Whole thing was so dumb. A floor full of smart monitors that they could have put a keylogger on. A plethora of physical network access and I get called out for leaving my laptop on the lock screen and going downstairs for food. And they got found out because I ran little snitch I paid for myself and it caught their hijacked chrome making all sorts of weird network calls. But I don't remember being given credit for that. (Sips mojito)
- sersi 3mo agoHow would they have been able to install a hijacked Chrome if your computer was on the lock screen?
- simg 3mo agoperhaps, back in the day, when windows machines would automatically run autorun.inf if present on a cd or usb drive regardless of whether the machine was locked or not.
- speedgoose 3mo agoLittle Snitch is Mac software though.
- RetroTechie 3mo agoThere's often ways around things. Back in the day I worked in a callcenter. You'd screen-lock & take a short break. Screen-lock itself required a password. But lo & behold, if you'd pick up the headset & hit a button "accept call" (usually meaning you're back in action), screen would be unlocked. Convenience (read: profit) trumps security every time.
- leetrout 3mo agoMac's had several vulnerabilities during that time including the ability to log in from lock screen with the user "root" with no password. There was also a vulnerability with executing a rubber ducky even with file vault. It was almost 10 years ago so I don't remember the specifics but the point was they had physical access to the building so they could do anything. People walked to conference rooms and to get food without taking their laptop with them all the time (of course) so it's not like I did something out of the ordinary or against policy. I remember them accusing me of leaving my laptop over night but I was just working late. And this was in a secure area with cameras within earshot of the over night crew and behind a door in a private shared office (glass door, glass wall so someone could have seen them) so it's not like I was at a common area and just walked out leaving my laptop on a random table).
- skeaker 3mo agoIn all fairness, a genuine attacker WILL be abrasive and abusive. They WILL single out employees that are gullible and exploit them. It's not pretty because a genuine attack is not pretty. Of course a simulated attack will be indecent and discourteous in nature, that is how attacks are.
- deleted 3mo ago[deleted]
- deleted 3mo ago[deleted]
- deepsun 3mo agoNot necessarily WILL. I've seen awesome attackers who were mostly checkbox spreadsheet clerks. Friendly, methodical, boring, expert.
- wjnc 3mo agoYeah, this is a part about itsec I don’t understand in my firm. They run social engineering tests, but never notify management when individuals fail, only in general terms. While being psyopped needs to be activelly discussed among coworkers imho.
- garbagewoman 3mo agoAssigning individual blame is missing the point of improving the security culture in general
- hypfer 3mo agoYes and no. Yes in general, because usually it's culture and not an individual failing. No in specific situations, because it's not just culture but also some people are just the weakest link. Only focusing on either of these while ignoring the other is going to lead to bad results.
- quantummagic 3mo ago
- firebot 3mo agoHe mostly used social engineering. Not technical exploits. So that's how he succeeded. Call it crazy, but it worked.
- fma 3mo agoWhy hack a password when you can get the employee to just tell you.
- ErroneousBosh 3mo agoAnd now all that shitty KnowBe4 nonsense we have to sit through every couple of months is all "What do you do if your manager phones you up and says they're on a business trip and need you to use the company credit card to buy Amazon gift cards", over and over and over. Bold of them to assume I'll answer the phone if I see my manager's number come up.
- walrus01 3mo ago> What do you do if your manager phones you up and says they're on a business trip and need you to use the company credit card to buy Amazon gift cards" If I've learned anything from the scambait people such as kitboga on youtube, if you're bored you play along with it, pretend to have acquired the gift cards, and then tell the "boss" you've scratched off and emailed their company address the codes, as the scammer on the phone wails "do not redeem! SIR DO NOT REDEEM!"
- esikich 3mo ago"He didn't breach us the way we wanted him to do it so it was dumb." Idk man, sounds like you locked your doors but left the windows open. That's the point of these things.
- murderfs 3mo ago"a client that turned out to have been rife with SQL injection" sounds more like they left the doors open, but the report focused on the lack of security bars on the windows.
- mcfunley 3mo agoThe point is really after working through remediations, there were pretty massive issues remaining that weren’t hard to find and were relatively vastly easier to exploit if the attacker is a Russian teen and not Bruce Lee. And the budget for such things was blown. Priorities, etc
- bawolff 3mo agoIsn't he famous for social engineering/physical security type things? If you hire an expert in X, you are probably going to get X.
- mcfunley 3mo agoYeah I agree, caveat emptor and all that. The blameful framing is bad work product though.
- antonymoose 3mo agoHow did he go about it? Giving a manager a report saying Foo and Bar are suck at security gives the manager good information on who needs training. If he walked into a conference room and called them out by name, that would be a touch abrasive.
- rixed 3mo agoIsn't he famous for getting caught?
- ActorNightly 3mo agoI mean, the landscape changed quite a bit since early days of what Mitnick did as a blackhat. He did his best to adapt and make money, which given his prison term, isn't really that surprising.
- shuwix 3mo agoDumb people are dumb. And will be. Their ability to learn from experience is almost non-existent. They are biggest security threat. Corporate structure didn't identify their mental limits and gave them way more access. So Mitnick, as outsite observer identified them and did good job. I might say "sorry for your loss of job" .... but seriously not. You shouldn't got that job in first place. Atleast you can brag about getting unemployed thanx to Mitnick.
- bootload 3mo ago“He seemed to lack systems thinking, producing a report that focused on calling out specific employees as dumb or incompetent.” VS 2002 “Companies spend millions of dollars on firewalls, encryption, and secure access devices and it's money wasted because none of these measures address the weakest link in the security chain: the people who use, administer, operate and account for computer systems that contain protected information.” — Kevin Mitnik “Amateurs hack systems, professionals hack people.” — Bruce Schneier source < https://archive.md/LiQN4 https://archive.md/LiQN4> / (paywall) <https://economist.com/special-report/2002/10/26/the-weakest-link https://economist.com/special-report/2002/10/26/the-weakest-...>