- TalkBack 16 of 74:
- Next »
- « Previous
- Thread View
- Flat View
- DCS: Answers to barred posts...
-
Answer to "You've been fed a falacy(sic)":
This from the man whose counter-argument was a classical fallacy? I digress with much wrining of metaphoric hands...
Cracking and phreaking have been around for a very long time, basically for as long as a dial-up connection and war-dialing - 1972 or so. In the '70s there were a number of low-profile compromises of MVS systems. There are none now. Why? IBM secured the compromised areas by hiring the infiltrators after said infiltrators had served their prison terms. The systems were rendered too secure on that advice for easy infiltration and the crackers migrate to softer targets. Crackers are lazy souls, by and large. A simple ROI equation tells them 20 soft targets are worth one hardened target.
A similar proof exists for AT&T UNIX prior to SYS-III. AT&T used the convicted cracker base to secure the OS they sold. Other licensees did not, fearing a consumer backlash with the end result of more pernicious flaws with longer time to realization and higher internal expense to secure the system.
A similar answer exists in-re the phone system. How much phone phreaking is done right now with a blue box or red box (in the US)? Answer: none. That system has been secured against those technologies. There wasn't a rise in phone phreaking until the introduction of new technologies and the failure of service providers to glean knowledge from those who broke the system.
Failure to use the best source of intelligence, because of people whose ideal is "Punish the criminal in jail and then punish them after they've repaid their debt to society as a deterent to others. Ruin the criminal for life to discourage others", has led companies to be either discrete about consulting the reformed criminal or completely ignoring the intelligence they could gain by doing so. This seems to be very much your opinion, which leads us to your next post.
Answer to: "Show me were(sic) it SOLVED anything"
Refer to the two earlier examples. MVS was secured and the crackers moved on to easier targets. UNIX SYS-III was secured using former criminal consultation and again the criminal crackers moved on to softer targets. Windows is that softer target and crackers know it - and the two in the article have told you the Windows is the softer target. They don't choose Windows because of ubiquity. They choose Windows because it is so fawed they can attack it easily!
Now, that said, I agree that crackers are rat reamers who should go to prison. I do not agree that we should not learn from them or that their knowledge is somehow tainted and we should therefore not benefit from it. Better to learn from our mistakes no matter who teaches the lesson.
Your moral code, however, seems to include the moral code I cited earlier - you want to punish forever? You want stronger sentences as a deterent. Consider though that the sentences now are three times harsher than they were in 1972. In 1972 a cracker wasn't even pursued unless he stole money and this lack of punishment persisted until 1987, then new laws were passed which not only doubled the sentence if money was stolen, but set a minimum two year term if no money was stolen. In 1997 the guideline was raised to 8 years. In 2001 via the Patriot Act and the provisions for electronic identity theft the minimum term became 20 years - more than a multiple rapist could receive. More than a first time murderer could receive. On par with what a drug dealer would receive. And this was without any money stolen!
Has there been a reduction in cracking of soft target systems? No. Your view is slanted, perhaps because you favour a soft target system I suspect? If you favoured a hardened target OS or platform; your perspective would be different. Anecdotally, I've worked at a number of government agencies in the last twenty years. In that time I've seen at least 30 massive and successful attempts to infiltrate, compromise, infect or worm soft targets (Windows desktops) from an external source. In that same time, I've seen UNIX and GNU/Linux attacks succeed only once by utilizing an unsecured web server as a proxy relay. In that same time I've seen zero MVS attacks succeed. I've seen numerous attempts via password guessing and trip routing: none succeeded.
So, the answer is obvious to me. Where proper intelligence gathering was used, and a "know your enemy approach" was employed; systems became hardened beyond the skills of the duffer cracker and for the serious cracker a bad ROI. That resulted in more secure systems.
You have one chance to punish and that's in prison, but after that failure to exploit them for knowledge is detrimental to increasing security. Not to mention it breeds an underground of the disenfranchised, who will likely try again. You want them on your side.
Aside - For my own thought, Mitnick should have gotten more time. I'm not a member of the Free Mitnick brigade and never was. However, I see nothing wrong with him consulting for security now and Congress seems to agree with me. Mitnick has paid his debt. His punishment is over. You are of course permitted to have your own emotionally driven opinion and even to expound it. What you are not permitted to do under argument, however, is use the fallacy of "consider the source" to fallaciously discount the statements of someone merely because they were previously convicted of a felony. Such arguments are false and unproductive.
I now return you to your regularly scheduled life with an admonition to read Carl Sagan's "Baloney Detecton Kit" in which fallacious argument is described. You would really profit from such a reading, I think. - Posted by: John Le'Brecage Posted on: 10/28/03 You are currently: a Guest | Members login | Terms of Use
What do you think?
SponsoredWhite Papers, Webcasts, and Downloads
- Five Steps to Determine When to Virtualize YourServers VMware Server virtualization isn't just for big companies. Entry-level ... Download Now
- Building the Virtualized Enterprise with VMware Iinfrastructure VMware VMware virtualization software has been adopted by over 120,000 enterprise ... Download Now
- Server Consolidation and Containment With Virtual Infrastructure VMware To meet the constant demand to deploy, maintain and grow a broad array of ... Download Now
Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors
- Learn more about tools to grow your business
-
The Business Essentials Guide provides you useful tools and templates to help grow your business and save you time with automated shipping solutions.
- Save time with the UPS Business Essentials Guide
- New Online Dashboard for IT Leaders
-
Read about top issues IT decision-makers face every day, plus get cost-effective solutions to real-life IT problems.
- Learn more >>
- Microsoft Dynamics CRM Online - Free Six-Month Trial for Eligible Organizations
-
Microsoft Dynamics CRM Online provides fast online access, simple contact management and better sales performance for a low monthly cost - the best value on the market today.

- Learn more about the free, six-month trial offer >>
- The more you simplify, the more you save
-
When you transition from your existing Red Hat environment to SUSE Linux Enterprise from Novell, you can recognize dramatic cost savings, perhaps as much 50%
- Learn more >>
SmartPlanet
- Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
- More from IBM
- How to Drive Better Business Outcomes with Exceptional Web Experiences Download the eBook
- Driving Business Agility through SOA Connectivity & Integration Read the White Paper from IBM
- Linking Decisions and Information for Organizational Performance Read the Tom Davenport study







