Slashdot Mirror


Mitnick Testifies on Telco's Security

Woefdram writes "Our favourite computer criminal (?) Kevin Mitnick testified in a case against Telco Sprint that their security was like Swiss cheese: full of holes. The story on SecurityFocus quotes Mitnick, saying, 'I had access to most, if not all, of the switches in Las Vegas,' and tells how he came up with a list of 100 challenge-response codes." We've written about this case before.

206 comments

  1. Why do it? by Anonymous Coward · · Score: 2, Interesting

    Why give yet more attention to a pathological 'social engineer' (liar)?

    1. Re:Why do it? by JPriest · · Score: 2, Interesting

      As someone that was following the series of articles that securityfocus was publishing on "phone phreakers owning Vegas" this is actually very interesting news. The articles detail about how "hackers" are stealing business by re-routing phone calls. After multiple complaints from the business owners sprint could never seem to find a problem during its investigations and insisted they were crazy. It was concluded that the "hackers" had someone inside working for sprint tipping them off because the phone system always seemed to route just fine while sprint was doing its audits. One of the frustrated business owners hired Kevin Mitnick to come in and help straighten things out, and that was the last I've heard till now. The Security focus has a write up is here

      --
      Saying Java is nice because it works on all OS's is like saying that anal sex is nice because it works on all genders.
    2. Re:Why do it? by JPriest · · Score: 0, Redundant

      "he Security focus has a write up is here" Sorry, I stopped making since hours ago.

      --
      Saying Java is nice because it works on all OS's is like saying that anal sex is nice because it works on all genders.
    3. Re:Why do it? by GodInHell · · Score: 5, Funny

      You gotta admit though, he's got the earmarks to be one of those great mythological figures one day.

      Can you prove it?
      Wait here for a few minutes..
      **a few minutes later**
      Here are the passwords for your central switches, I had them on file in one of my drop points down the street. Lucky me that it was still there.
      **laywer fumbles and swears**

      Remember, Hackers are like boyscouts, they're always prepared.. they just prepare for alot more than preventing forest fires and walking old ladies across the road.

      -GiH
      -This isn't my dog, this is an aibo. My dog is years more advanced than this.

    4. Re:Why do it? by Anonymous Coward · · Score: 0

      dude, he's typing.

    5. Re:Why do it? by dubiousmike · · Score: 1

      I thought Superman sent Mitnick back to his own dimension by saying his name backwards...

    6. Re:Why do it? by rbeattie · · Score: 2


      And what's up with that question mark (?) after the word criminal? If Mitnick's not a criminal, I don't know who is.

      -Russ

      --
      Me
    7. Re:Why do it? by Ozymandias_KoK · · Score: 1

      Maybe they aren't sure if he is their "favorite computer criminal".

    8. Re:Why do it? by kesuki · · Score: 2

      Robin rood maybe?
      Yeah he broke laws, he intruded on systems, he stole source code. He's not a criminal anymore though, because now he's an independant security consultant, and can essentially do almost everything that he did as a 'criminal' (except steal source code) and get paid to do it, all legally. As for source code, as a consultant he can look at it for security vulnerabilities, which was why the guy stole code in the first place.
      He always had ethics about what he did, and he was sorely mistreated by the criminal justice system. To congressmen and the legal system a "Hacker" Is a terrorist, and they may as well be Witch Doctors too. Judges, police the FBI none of these guys had a clue about what mitnick could really do. It was all bad rumours, you'd think the guy had a modem in his head, because they expected him to be able to send faxes and access the internet from an ordinary jail phone.
      Mitnick found a way to hack while obeying the law, and I seriously doubt the guy wants to deal with the crap that the legal system throws at (cr/h)ackers again.

    9. Re:Why do it? by RyuMaou · · Score: 1

      So are Boy Scouts, pal. Check in the recent stories right here on /. and you'll find a Boy Scout that nearly built a reactor in his backyard.

      I was an Eagle Scout, back in the day, and you'll find that quite a few interesting people were, too. My brother who's in R&D at Motorola is an Eagle Scout. In fact, check on war heros from WWII, Korea, and Viet Nam. You'll find that a fair percentage of them were Boy Scouts. I use stuff I learned in the Boy Scouts every day. And not just First Aid stuff, either. (Though, I have to admit, in retrospect, Farm Mechanics merit badge was a weird thing for a future techie to have gotten.)

      Anyway, my point is, before you start making fun of the Boy Scouts, you might want to check into what they're *really* all about.

      --
      Oh, the trials and tribulations of a network geek! Read about them at: http://www.ryumaou.com/hoffman/netgeek/
    10. Re:Why do it? by GodInHell · · Score: 1

      Anyway, my point is, before you start making fun of the Boy Scouts, you might want to check into what they're *really* all about.

      Eh, no offense intended, the focus was more on the hackers than the Boy Scouts there for me.

      -GiH
      This is my rationalizer, for centuries men have used it to make the world makes sense, some call it; Beer.

  2. well by Anonymous Coward · · Score: 0

    We've written about this case before. Then STOP writing about it. Waste of electrons, as usual.
    Mitnik is not such a wonderful person. He is free now, get off the soapbox and stay off it.

    1. Re:well by heybrakywacky · · Score: 1

      We've written about this case before. Then STOP writing about it.

      Why? It's an ongoing case, with new developments, that involves a technical subject and curiosity. Isn't that what SlashDot is supposed to write about?

      As for the Mitnick angle, I don't know why some of you are getting all bent out of shape about the fact that Mitnick is one of the protagonists in this case. Yes, protagonist. He's helping in a lawsuit against a big telco that's lying about the level of security in their system. Or do you think security through obscurity and, by extension, misinformation, is actually a good thing?

      Who cares which particular hacker it is that's exposing them. The idea is that, in the end, your telecommunications will be more secure as a result.

      --
      I'm sorry sandwich! --Brak
    2. Re:well by packeteer · · Score: 1

      actually saying this is a "waste of electrons" is not true... if anything its a waste of electricity but no electrons are lost during the process of you reading this... remember that electrons flow in a circular direction and tis the MOVEMENT of those electrons that creates what you see... NOT actual electrons being "given" to your computer...

      --
      unzip; strip; touch; finger; mount; fsck; more; yes; unmount; sleep
  3. Should they by af_robot · · Score: 1

    hire a better system administrator?

    or this is a company policy to keep system insecure to gain more PR from hacker incidentes?

    1. Re:Should they by Anonymous Coward · · Score: 0

      Unfortunatly this is how businesses run. When they want to cut money, the first to go are the sysadmins cause I mean golly anyone can do it right? Kinda going off subject here but, it is damn hard to convince people that they NEED a competant sysadmin and they NEED someone who's life is to sit there watching and maintaining their computers. Look how hard it is to get a job nowadays in that field. I can bet you 80% of the sysadmins out there arn't doing it as thier full time job, they are programmers/sysadmin or documentation writer/sysadmin. There is not cost cutting strategy that works, security, maintenance, and troubleshooting is a fulltime job and distractions hurt the overall network schem.

  4. Publicity grubbing... by Ratface · · Score: 4, Interesting

    The only thing Mitnick is better at than hacking (or possibly eating pizza!) is publicity grubbing. Let's face it, there have been thousands of better crackers, but Mitnick manages to always claim the spotlight. Most people would want to lie low after what Mitnick has been through - but he has a career as "Celebrity Cracker" to maintain.

    I liked this quote "The only way I know that this is a Nortel document is to take you at your word, correct?," asked Riley. "How do we know that you're not social engineering us now?" - now *that* guy is thinking correctly!

    --

    A little planning goes a long way...
    1. Re:Publicity grubbing... by Anonymous Coward · · Score: 0

      Well think about it man, if all you knew and worked for involved computers, then how the hell would you make a living when the courts have taken your right to use any type of computer at all. I think he has said that if he even placed his hands on a keyboard the feds would take him in for violation of parol. I mean how else is a super cocky computer nerd going to make a living? By sticking it to the man thats how.

    2. Re:Publicity grubbing... by CodeMonky · · Score: 4, Insightful

      You left something out, Mitnicks response to the question.

      Mitnick suggested calmly that Sprint try the list out, or check it with Nortel. Nortel could not be reached for comment after hours Monday Perhaps he knew that spring/nortel couldn't be reached. But you should still at least include the response if you're gonna quote something like that.

      --
      --"Karma is justice without the satisfaction"
    3. Re:Publicity grubbing... by Your_Mom · · Score: 3, Insightful
      Let's face it, there have been thousands of better crackers...
      I have to say that Mitnick is one of the better crackers in recent memory, sure he gets the spotlight a lot, but I think thats because he got thrust into the public spotlight back during the Shimomura episode. I mean, how many crackers made the front page of newsweek?

      Yes, there are other deserving people out there, but I don't mind Kevin cashing in on his "fame". Who wouldn't?
      --
      Objects in the blog are closer then they ap
    4. Re:Publicity grubbing... by Anonymous Coward · · Score: 0

      Has Mitnick ever actually worked in a job related to computers?

      I've always gotten the feeling he never held a job, has zip formal training, and is just a pathological liar type, street smart and good at fooling people. He knows 'some' about computers, but nobody anywhere would ever hire him as anything more than a cable puller based on his credentials.

      Really, with his experience, he should be looking for work as an office boy.

    5. Re:Publicity grubbing... by Anonymous Coward · · Score: 0

      As a matter of fact he has. He used to work for as a sysadmin for a law firm when he was hiding under the gun of the law. He was making pretty good money and used this oportunity to attack even more unsuspecting victims.

    6. Re:Publicity grubbing... by Ami+Ganguli · · Score: 5, Interesting

      Under the circumstances, I can't say I blame him. The man isn't allowed to touch a computer. Nowadays that means he can't even work at McDonalds.

      Cashing in on his celebrity is the only carreer option the guy has.

      --
      It is tempting, if the only tool you have is a hammer, to treat everything as if it were a nail. - Abraham Maslow
    7. Re:Publicity grubbing... by Anonymous Coward · · Score: 0

      Sorry my first thought when I read "Celebrity Cracker" was Chris Rock saying it. Dont we have enough famous crakas?

    8. Re:Publicity grubbing... by Jesus+IS+the+Devil · · Score: 2, Insightful

      You have to compare apples to apples and oranges to oranges. Kevin did all of this back when the internet was still in its infancy. Back then there wasn't this vast sea of information script kiddies can just search for and dig up. If you wanted to crack, you had to figure it out by yourself. No doubt. He was one of the best crackers out there. His deeds were evil but he was a good cracker.

      --

      eTrade SUCKS
    9. Re:Publicity grubbing... by LittleGuy · · Score: 2, Insightful

      Gaining celebrity out of being on the wrong side of the law (whether justly or unjustly) has been long prevalent, from Jesse James to Bonnie & Clyde to Al Capone to John Gotti to 'Mayflower Madam' Sydney Biddles Barrow and beyond (with Winona in the on-deck circle).

      Why should we surprised by whoring notorious characters on the tech side?

      --
      Mod Karma -1: I sed bad wurds. If I cep my mouf shut, I wud be at riyses.
    10. Re:Publicity grubbing... by Anonymous Coward · · Score: 0

      But he wasn't a cracker (which implies some sort of technology), but a social engineer. He basically got people to tell him logins, access codes, etc. If anything all he had was a nack for fooling people, I tend to think of him more as a used car salesman and less as a computer wiz.

    11. Re:Publicity grubbing... by g051051 · · Score: 1

      Mitnick should not be classified as "one of the better crackers in recent memory". He was actually pretty incompetent. Cracking is just 1/2 of the equation. Not getting caught is the other 1/2. A "better cracker" would not have been noticed, and would not have been caught.

      I'll say it again: He's the computer equivalent to the shaking junkie who sticks a gun in the face of a 7-Eleven clerk to get money for a fix, then waves to the security camera on the way out. He left a trail a mile wide, and couldn't stop his illegal activities even when he knew the authorities were after him.

      I thnik Slashdot needs a "Kevin Mitnick" category so I can exclude stories about him.

    12. Re:Publicity grubbing... by Mr_Silver · · Score: 2
      The only thing Mitnick is better at than hacking (or possibly eating pizza!) is publicity grubbing. Let's face it, there have been thousands of better crackers...

      Of course there are. We don't know who they are though because they haven't been caught.

      --
      Avantslash - View Slashdot cleanly on your mobile phone.
    13. Re:Publicity grubbing... by Your_Mom · · Score: 3, Insightful
      I'll say it again: He's the computer equivalent to the shaking junkie who sticks a gun in the face of a 7-Eleven clerk to get money for a fix...
      No disagreement there, I think hes been quoted along the lines of not being able to stop despite knowing that he will eventually get caught.(Link anyone? I could be wrong)

      He left a trail a mile wide...
      I have to disagree here. There were no real ties between him and the Shimomura attacks. I think he was the target that first popped up on their radar screen after the attacks and was lassoed. There are a lot of weird bits in the "official" version of the story (unsigned warrants, etc) and instead of detailing them I will say:

      I strongly recommend reading both The Fugitive Game By John Littman and, to get the other side Takedown by John Markoff, I find Littman a much better read and does much more research into the story then Markoff. Littman presents the story from a impartial 3rd person, and scrutinizes both accounds (Mitnick, who he interviewed via phone while on the lamb, and Markoff's story from his book, NYT stories, and interviews.) I've lent Littman out to techie and non-techie friends and it always recieves high marks, and I think the "Something was Fishy with the govt's case" viewpoint usually results.

      --
      Objects in the blog are closer then they ap
    14. Re:Publicity grubbing... by dohcvtec · · Score: 1

      I doubt he was just bluffing. Just because SecurityFocus couldn't reach Nortel's 9-5 PR people doesn't mean the court couldn't page a Nortel engineer (whose number would be supplied by Sprint.)

      --
      -- Never hit a man with glasses. Hit him with a baseball bat.
    15. Re:Publicity grubbing... by Anonymous Coward · · Score: 0

      You have not followed the case. Throughout his life as a hacker, Mitnick wanted nothing less than publicity for his actions. John Markoff was the one who gave him unwanted and unwarranted attention in the New York Times.

      Since completing his sentence, Mitnick has found that his release restrictions has left him with little or no resources for mere survival. So he has little left to him other than self-promotion until he can rejoin our computerized society.

    16. Re:Publicity grubbing... by Anonymous Coward · · Score: 0

      There is no way Mitnick could know or not know that a massive corporation such as Nortel will or will not comment on this.

      At this point I believe Mitnick is being geniune. If, for one second, you find the claim that Sprint/Nortel is using an insecure protocol on their switches questionable, you are extremely naive.

      There is nothing surprising or even remotely suspicious about Mitnick's testimony.

    17. Re:Publicity grubbing... by nanoakron · · Score: 2, Insightful

      Cruel and unusual punishment, anyone? anyone?

      -Nano.

    18. Re:Publicity grubbing... by jjshoe · · Score: 1
      can you blame him for trying to fuck the system that fucked him?


      i havent heard a lick about mitnick since he was set free. i totaly support mitnick with his actions. if the court decides information mitnick has is publicaly available i think he should appeal his suit and get less time away from comptuers.


      go mitnick.


      fuck them hard

      --
      -- botsex is {grep;touch;strip;unzip;head;mount} /dev/girl -t {wet;fsck;fsck;yes;yes;yes;umount} {/de
    19. Re:Publicity grubbing... by Felinoid · · Score: 2

      In the book outside the inner circle one of the techniques used to hack into systems was to get employees to fill out servays or walk into the office like you worked there.
      Now a days your not allowed in the lobby unless you have a pass card.

      No doupt based on the kinds of cracks he was found guilty of he used socal hacking techniques.

      He may be forbidden to use his technical skills but there is nothing keeping him from using the human conterpart.

      --
      I don't actually exist.
  5. Plead the Fifth! by TheDick · · Score: 3, Funny

    Never EVER testify like this, no matter WHAT the DA promises you. Shit Kevin, I thought you knew better?

    *FREE KEVIN*

    --

    1. Re:Plead the Fifth! by AndrewSchaefer · · Score: 1

      You retard... It's a civil suit, not a criminal trial. The DA has nothing to do with this. There's a 5 year statute of limitations on the crimes that he is testifying to, so it doesn't matter what he says.

  6. The real speech... by alapalaya · · Score: 4, Funny

    "their security was like Swiss cheese: delicious."

    (yeah, my .sig is wrong, so what?)

    --
    667 The Neighbour of the Beast
    1. Re:The real speech... by Anonymous Coward · · Score: 0

      (yeah, my .sig is wrong, so what?)

      There's many places in the world where the numbers of neighbouring houses differ by one. Maybe the beast comes from one of those.

    2. Re:The real speech... by alapalaya · · Score: 0, Redundant

      ...you are the smartest AC I've ever met!

      (my .sig is not wrong... have a look at the parent message!)

      --
      667 The Neighbour of the Beast
  7. Sentence by Dilbert_ · · Score: 3, Interesting

    Wasn't he forbidden to do any kind of computer related work ever again? And would testifying in this case mean breaking his parole? Just wondering...

    --
    superblog.org: all your favourite blogs on o
    1. Re:Sentence by CodeMonky · · Score: 2

      He's gotten exemptions to speak at conferences so I am assuming that something like that occured for this.

      --
      --"Karma is justice without the satisfaction"
    2. Re:Sentence by cyborch · · Score: 1

      Being forbidden to do any computer related role makes it hard to maintain any job these days. Actually he cannot even sit at a counter nor a bus driver... almost any device has a omputer in it these days... I haven't read the minutes of Kevins trials but I think the sentence was a bit less restrictive than that.

    3. Re:Sentence by ranulf · · Score: 2
      Given that there are accurate minutes taken of everything that is said in court, I think they'd be able to keep pretty close tabs on what he testifies in court, don't you?

      And besides, the judge knows the system. He wouldn't even be allowed to testify in court if it broke his parole.

    4. Re:Sentence by Wingchild · · Score: 4, Interesting
      From http://www.usdoj.gov/criminal/cybercrime/mitnick.h tm :

      "Once he is released from prison, Mitnick will be on supervised release for three years, during which time his access to computers and his employment in the computer industry will be severely restricted."

      While testifying in a case isn't technically work in the computer industry, consulting definetly would be. Maybe this is outside the scope because we're talking about telco equipment and not computers per se (which, coincidentally, goes back to Mitnick's roots as a marginally talented phreaker and a decent social engineer)?

      Or perhaps Mitnick's just an outright idiot. I don't recall him getting wailed on by Sprint during his legal proceedings, so I'm not certain that he's exempted from prosecution by way of double jeopardy. A curious thing, this testimoney.

    5. Re:Sentence by Coward+the+Anonymous · · Score: 1, Informative

      One again, he is not working with computers at all, just recounting his experiences from 7+ years ago. And the crimes he committed then have a 5 year statute of limitations.

      --
      -- Jason
    6. Re:Sentence by aberkvam · · Score: 1
      Well, I am pretty sure that by now Mitnick has learned his lesson and has everything like this that he does vetted by his own lawyer first. If there was a danger of this testimony getting him in any sort of trouble, he would have just refused to consult on this case.

      Of course, maybe that's what the delay they had in getting him on the stand was all about. Hard to tell...

    7. Re:Sentence by vinnythenose · · Score: 3, Informative

      If you had read you would have noticed that he's protected by the statute of limitations. It's been over five years.

      --
      --- I used to moderate, then I read the -1 articles and decided having to filter through them was not worth it.
    8. Re:Sentence by unFKNreal · · Score: 1, Interesting

      I especially like this part... "Judge Pfaelzer ordered Mitnick to pay only totalling just over $4,125. Judge Pfaelzer said she was issuing this nominal restitution order based on the Court's determination that the defendant would have limited earnings in the future."

      Limited earnings my ass. You just know as soon as those 3 years are up (which should be soon), he's gonna be raking it in as a security consultant for somebody like IBM or Sun... Wonder what that judge thinks now!

    9. Re:Sentence by Geekboy(Wizard) · · Score: 1

      That's to get busted for his confession. The parent post was asking if this violated his parole.

    10. Re:Sentence by GeneralEmergency · · Score: 2
      AUTHORITATIVE:

      Kevin works very closely with those monitoring his "Supervised Release". Kevin is very serious about having his life and freedoms returned to him.

      I worked with Kevin for several months on his Radio Show, "The Darkside of the Internet" on KFI, Los Angeles.

      --
      "A microprocessor... is a terrible thing to waste." --
      GeneralEmergency
    11. Re:Sentence by meatplow · · Score: 1

      I like that show.
      I couldn't have been the only one listening ?.

      Why was it cancelled ?



      Meatplow

    12. Re:Sentence by DavidTC · · Score: 1
      Testifying in court can never break someone's parole. God, that would be a horrible civil rights violation just waiting to happen, saying someone isn't legally allowed to testify in court. The judge would be disbarred before the trial was over. People always always always have the right to be in court.

      As an aside, testifying in court is one of the few things you can always do from prison, and you will automatically be given travel permission if your parole includes location limitations and you need to appear in court outside that area.

      --
      If corporations are people, aren't stockholders guilty of slavery?
    13. Re:Sentence by GeneralEmergency · · Score: 2
      ClearChannel was (and still is) having financial difficulties and they axed several shows at once. In Kevin's case, this made little financial sense because when the Arbitron ratings did finally come out, they showed we had a relatively large audience for such a wierd time slot. I largely did hands on research and software evaluation for Kevin. The show's producer, Chris Pelton, did an amazing job keeping this small nerd herd focused on making the material interesting to the general public. The final on-air pairing of Kevin and his long time friend Alex was an outstanding combo of experience and explanitory know-how. Last I heard, there was talk of Syndicating the show, but I suspect that Kevin's book authoring chores are taking front seat in his life right now.

      Kevin is an amazing guy. One little known fact about him is that he can dial a phone faster than I thought humanly possible. He has an almost photographic memory for phone numbers, IP addresses, URLS and other snippets of information.

      --
      "A microprocessor... is a terrible thing to waste." --
      GeneralEmergency
    14. Re:Sentence by GeneralEmergency · · Score: 2

      "...his access to computers and his employment in the computer industry will be severely restricted."

      I re-interate. It was my experience that Kevin clears all of his significant activities that could possibly be construed as "consulting" with the individual responsible for supervising his release. At this time I worked with him, I do believe he even had to clear visits to his mom (a LasVegas resident) because the trip exceeded his residency area boundaries.

      Kevin's participation in this proceeding could ONLY happen if he had permission. With only 0 years, 6 months, 24 days, 8 hours, 43 minutes, 25 seconds left to go, why Fsck this up now?

      --
      "A microprocessor... is a terrible thing to waste." --
      GeneralEmergency
  8. You have to wonder. by Nomad7674 · · Score: 3, Interesting

    The article indicates that Mitnick is calmly able to lay out what he did, because the statute of limitations has expired on his alleged crimes. Anyone who has spent anytime watching LAW & ORDER (and of its spin-offs) has to wonder if there is an enterprising District Attorney somewhere combing the law for any permutation of the law WITHOUT a statute of limitations to use against him based on this testimony. For example, he can not be tried for the hacking itself, but could he be tried for Conspiracy?

    1. Re:You have to wonder. by SuiteSisterMary · · Score: 2

      Actually, if he's at all intelligent, which is apparently is, he's garnered immunity in exchange for his testimony.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
    2. Re:You have to wonder. by parking_god · · Score: 1

      It was a hearing of Nevada's Public Utilities Commission; there doesn't seem to be a DA involved anywhere, so I doubt he'd get immunity in exchange for anything.

      --
      Brandishing Dangerous Logic
    3. Re:You have to wonder. by Get+Behind+the+Mule · · Score: 2

      Anyone know if Mitnick was ever questioned or tried for his hacking in Las Vegas? If he has stated under oath that he didn't do any of that stuff, he might be risking a perjury charge -- unless the statute of limitations has run out on that as well.

      BTW, this testimony is a real-world example of what "white-hat" hacking is supposed to be all about -- exposing security weaknesses that might be exploited by others. Of course, Mitnick might have had his black hat on back in the day when he was doing it.

    4. Re:You have to wonder. by Anonymous Coward · · Score: 0

      the new terrorism law includes grand fathering -- they could proly nail him with that.

      or possibly purjory if he claims he was innocent when he was originally endeited.

  9. What I want to know... by DutchSter · · Score: 3, Interesting

    ...is this testimony going to come back for possible charges in the future? In other words, could Sprint now decide to go after him? You really can't take the fifth once your statements have entered the public record. You can refuse to answer any further, but only in a trial in which you are accused. This is 1) Not a trial for Mitnick 2) Is not in a court of law, it is being held in the State Public Utility Commission. Consequently, all his testimony becomes public record, and he could never claim immunity or something should Sprint decide to turn around and come after him for 'losses' or the DA for criminal purposes. His only hope might be statute of limitations.

    Any ideas?

    1. Re:What I want to know... by Brento · · Score: 5, Informative

      ...is this testimony going to come back for possible charges in the future? In other words, could Sprint now decide to go after him?

      No. He's already been tried for this specific crime - it would be double jeopardy. (Yes, like the movie with Ashley Judd, only with less sex appeal, since there's no women's prison involved.) You can't be tried for the same crime twice. If you commit two murders you can be tried twice, but they can't try you twice for the same murder.

      --
      What's your damage, Heather?
    2. Re:What I want to know... by jacoberrol · · Score: 4, Informative

      A quote from the article:

      "With the five year statute of limitations long expired, Mitnick appeared comfortable describing with great specificity how he first gained access to Sprint's systems..."

    3. Re:What I want to know... by SuiteSisterMary · · Score: 2

      Aye, but they could pull an OJ and sue him civilly.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
    4. Re:What I want to know... by DutchSter · · Score: 2

      Yeah I read that but my thought was that if Sprint has long been claiming they are untouchable and someone goes on record as having broken it - They just might come looking at your door for problems they have been experiencing recently. If you've got someone who admits he knows how to break in, and you had a break in a year and a half ago that never went public, it seems obvious who you start looking into. Remember, Spring was "unaware" of these vulnerabilities. That means that probably until yesterday (and maybe even now), those doors were still open. One person has confessed to being there before.....

    5. Re:What I want to know... by DEBEDb · · Score: 1

      A subtle point: a crime is a violation of the law. So if by a single act you violated 2 laws, you committed 2 crimes, and you can be tried for each.

      --

      Considered harmful.
    6. Re:What I want to know... by taliver · · Score: 1

      So if by a single act you violated 2 laws, you committed 2 crimes, and you can be tried for each.


      But they must be pursued at the same time. As an example, the prosecutors did not have 400 or so attempts to try McVeigh for blowing up the building, even though he committed 400 or so murders in that event.

      --

      I demand a million helicopters and a DOLLAR!

    7. Re:What I want to know... by Zapman · · Score: 2

      No, the really funny bit is that this challenge/response list is now A PART OF PUBLIC RECORD. If (important if) it's true, phreaking could have quite the little renaissance.

      --
      Zapman
    8. Re:What I want to know... by Anonymous Coward · · Score: 0

      167 is the actual number.

    9. Re:What I want to know... by monkeydo · · Score: 2

      You are misinformed. McVeigh was only charged with 8 counts of murder even though he killed 168 people. He was charged with the murder of the 8 federal officers, this was sufficient when convicted to get him the death penalty.

      In the case of multiple homicides especially prosecuters will hold back counts if they would not increase the penalty and leaving them out do not affect the case. For example, if a mother drowns her 5 children you first carge and try her for 2 counts of murder. If for some reason she is aquitted you can charge her with the other counts. There is no double jeopardy in this case.

      --
      Si vis pacem, para bellum
      The only thing more annoying than a Libertarian is an (un|mis)informed Libertarian
    10. Re:What I want to know... by mark_lybarger · · Score: 2

      where does it say that "related" crimes must be tried together? most prosecutors lump crimes into one trial in order to expidite the process and to get a hefty sentence.

      if two people commit a crime together, they are tried together or separately depending on how the prosecutors think the outcome might be. maybe one will squeel on the other and as a result might be tried separately under lesser charges.

    11. Re:What I want to know... by HD+Webdev · · Score: 1

      If you commit two murders you can be tried twice, but they can't try you twice for the same murder.

      Sure they can.

      First, you get tried by the State.

      At a later date, the Federal Government can prosecute the Murder as a Hate Crime.

      It's a way to do an end-run around the double jeopardy rule.

      --
      This is not a dream, not a dream...we are transmitting from the year 1-9-9-9.
    12. Re:What I want to know... by gallen1234 · · Score: 1

      Does anyone know if statutes of limitations apply to civil cases or only to criminal ones? If it's the later then Sprint might still have be able to make a case.

    13. Re:What I want to know... by proj_2501 · · Score: 2

      OJ didn't get convicted of the murders.

    14. Re:What I want to know... by ajakk · · Score: 2

      You are misinformed. McVeigh was only charged with 8 counts of murder even though he killed 168 people. He was charged with the murder of the 8 federal officers, this was sufficient when convicted to get him the death penalty.

      Yes. That is absolutely correct.

      In the case of multiple homicides especially prosecuters will hold back counts if they would not increase the penalty and leaving them out do not affect the case. For example, if a mother drowns her 5 children you first carge and try her for 2 counts of murder. If for some reason she is aquitted you can charge her with the other counts. There is no double jeopardy in this case.

      Nope, you are absolutely wrong here. You must charge all of the crimes following out of a single act at the same time. You cannot bring two charges against a mother and then see if she is convicted on those two, and then file for the other three if she got off. McVeigh was slightly different because there were both state and federal claims against him. The eight murders he was first convicted of were brought in federal court. The federal DA couldn't charge him of the state law crimes of murder, so there is no due process violation, and the trials must be difurcated.

    15. Re:What I want to know... by Anonymous Coward · · Score: 0

      Conviction is irrelevant. Ciminal and civil courts are seperate in regards to double jeopardy.

    16. Re:What I want to know... by Anonymous Coward · · Score: 0

      A better example would be the cops who beat Rodney King -- aquittal at the local trial (leading to a massive riot), convicted under Fed civil rights laws, not double jeopardy.

      Mitnick could probably still be brought up on additional charges -- he probably has agreement from the judge/DA that consulting on such things is OK.

    17. Re:What I want to know... by DutchSter · · Score: 2

      I asked around some of my 'lawyerly' friends and the answer to statutes of limitations is that it depends. Some states don't allow any for civil penalty, others allow the same time period as criminal cases, others allow different periods (generally civil is longer). In some wacked situations there is a set statute of limitations, but if new evidence is introduced some time after, it can be reinstated for so many years beyond that. Seeing as I am thousands of miles from Nevada, I just don't know. The problem with civil cases is that the burden of proof shifts somewhat to the defendant. If Sprint would say "We know you just got out of jail, and we were broken into around that time, and you're the only documented person who has done that, and the break ins resemble your trademarks", depending on the judge/jury (whoever Sprint decided) it might be more up to Mitnick to prove that it wasn't him.

      Bottom line though - not that he has any money to be sued for, and since noone does any jail time for civil cases, the smart thing to do would be to chalk it up as a business expense and not harass him over it. But hey, these are the same people that call my house 5 times a week and harass me, and I have no money to give either. ;)

    18. Re:What I want to know... by SuiteSisterMary · · Score: 2

      Correct, he was absolved of criminal wrongdoing. He was then sued in civil, as opposed to criminal, court, by the famlies of the victims, and was found responsible for their 'wrongful deaths.' Or some such, I forget the actual wording. But the point here is that he was found civilly liable for the deaths, if not criminally guilty.

      So, similarly, Mitnick might not be criminally liable for his actions, but they might still be able to take him to civil court and sue for lots of money.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
    19. Re:What I want to know... by daBum · · Score: 1
      Not necessarily. From the article:
      Mitnick's return to the hearing room with the list generated a flurry of activity at Sprint's table; Ann Pongracz, the company's general counsel, and another Sprint employee strode quickly from the room -- Pongracz already dialing on a cell phone while she walked.

      I'm thinking that she was calling the office to get those passwords changed (or to disable the access until they can be changed).
      --
      I am dyslexia of borg - your ass will be laminated.
    20. Re:What I want to know... by Zapman · · Score: 2

      I know that, you know that, and Sprint Las Vegas now knows that.

      How many other telcos do? That's my point.

      --
      Zapman
    21. Re:What I want to know... by DavidTC · · Score: 1
      An important phrase is 'a single act'. McVeigh commited a single act, and, with that, commited 167 murders.

      If a mother shoots all five kids in a row, bang bang bang bang bang, as an example, (Gah, what an example.), that can either be five seperate trials or one, as there were five seperate acts that happened all together, but were nevertheless seperate.

      Same thing applies with murder/robbery. The murder happens during the robbery, so they can, I believe, be charged seperately. The robbery and the murder were not the same act. (This get iffy with the felony murder rule. The act, 'killing someone during a felony', automatically happens because you commited a felony. But they can only charge you in addition to commiting a felony. I don't really know how it works.)

      Basically, there is no restriction on lumping acts together. It's possible to try someone for two crimes that happened weeks apart in the same trial. But, remember, the courts have to prove beyond a reasonable doubt that he commited all crimes, so if they prove he committed one but fail to prove the other, the criminal is off the hook for all of them and cannot be tried again. But when they are two crimes from the same act, it has to be the same trial, barring crimes in different juristidictions.

      The reason is that courts don't prove crimes, they prove acts, and thus they have to include all the crimes you committed with that act. They can't keep claiming you commited the same act, just different crimes. If the court says that you didn't commit the act, you didn't commit the act, period, and thus you didn't commit any crimes with said act.

      Note while you cannot be charged with crimes for said acts, the court does not always assume you didn't commit the act. If you're charged for another crime from another act, and your first act, the one you were aquitted for but they can prove now, shows motive or something, they are allowed to prove you commited the first act. (But you still can't be charged with any crime from that act.)

      --
      If corporations are people, aren't stockholders guilty of slavery?
    22. Re:What I want to know... by proj_2501 · · Score: 2

      But didn't Mitnick get convicted in the end anyway?

    23. Re:What I want to know... by SuiteSisterMary · · Score: 2

      Not for this. Apparently this is the first time Sprint even realized they got owned by Mitnick in '94.

      --
      Vintage computer games and RPG books available. Email me if you're interested.
  10. Have to wonder. by prof187 · · Score: 1

    You kinda have to wonder if all of this publicity of someone getting money because their system had been compromised before will spur an onslaught of similar lawsuits, possibly from the same people who got into the system. The trend seems to be, where the media goes, the people will follow.

    --

    My other sig is an import.
  11. Re: Double Jeopardy by Anonymous Coward · · Score: 1, Interesting

    Of course, the problem with the movie "Double Jeopardy" is the fact that there was no double jeopardy involved. If you kill someone and are tried for that, and it turns out the person isn't dead after all, you can still be tried for killing them again since it's a different crime. Same person, but different crime.

    It's like saying that if you rob a bank the first time, you're going to jail. But each time you rob it after that, you can't be tried because you've already been tried once. Not likely, you're still going to jail again and again.

  12. Not surprising by nakedsavage · · Score: 5, Interesting

    This does not surprise me at all. I work for a large telecommunications company. 4 years ago our group took over responsibility for 40 switches, 32 of which were DMS-100s. The forst thing we had to do was change the admin passwords- some were still the default password installed by Nortel when the switch was first built, others were as simple as admin:admin. All someone would have needed to do is call a NOC and pose as a Nortel engineer to get the dial up numbers and voila! Tens of thousands of customers without service and a very long report to the FCC.

  13. An interesting turn-about by tshoppa · · Score: 5, Interesting
    The SecurityFocus article takes a very interesting look at the PUC hearing and is, I think, very newsworthy and a significant legal development.

    What is most vital is that in this case, unlike other previous Mitnick cases, the telco is arguing that Mitnick didn't break in while Mitnick is insisting that he did. Mitnick is offering proof in the form of documents and passwords and the Sprint of Nevada lawyer is saying that the information Mitnick is bogus or publicly available. This is such an exact turnaround from the last legal tangle that Mitnick was in that I gotta wonder if it's even the same universe.

    Does this have any relevance to legal cases outside the Munoz "Vegas escort" case? I don't know, but I could see it happening: Hollywood lawyers calling on DeCSS authors and users, arguing that the software they have doesn't actually promote piracy. Could be interesting!

    1. Re:An interesting turn-about by Peyna · · Score: 2

      It makes sense to challenge something like this. Obviously someone is going to be a little be skeptical if you tell them you broke something they were assured is 100% secure. That would be kind of interesting to turn a few other cases around like that.

      --
      What?
    2. Re:An interesting turn-about by Anonymous Coward · · Score: 0

      Not at all. Lawyers are paid to argue whichever side of the case their client is on. In this case Mitnick makes Sprint look bad, so the Sprint lawyers have to try to discredit him by making him look incompetent or innocent. Incompetent won't cut it so innocent (which is going to be tough after he served five years) is the next best argument.

  14. Security through Obscurity by swm · · Score: 2

    Security through Obscurity Rules!

    'nuff said

    - SWM

    1. Re:Security through Obscurity by teamhasnoi · · Score: 1, Offtopic
      I wXuld have replied tX this earlier, but I use a mirrXr and stylus tX enter pXsts Xn my Atari 800XL. (Translated from Ancient Mayan)

      Please wait until August XX, 2XXX tX read the Elvish Runes I have embedded here.

  15. from a former Nortel employee... by deander2 · · Score: 4, Insightful

    I worked for a year and a 1/2 on a project designed to replace the DMS-100 provisioning and configuration systems. I can tell you that those systems are complex in the extreme to set up correctly. I knew people who had worked with them for 20 years and still had questions about how they worked. It's not through Sprint's stupidity that they were hackable, it is a by-product of overly complex system engineering.

    This is a common problem in this industry. Having complex systems when you're the defacto standard makes a great revenue stream in your consulting and training systems, but kills the reliability of said systems. Nortel/Cisco/IBM never take the fall for it however, because they can just say "well, you didn't configure it right" and Sprint/etc can't even argue - it would take 2 years and 10 consultants to even find out.

    1. Re:from a former Nortel employee... by WolfWithoutAClause · · Score: 3, Insightful
      To be fair to Nortel, these particular systems were hacked 7 years ago, at a time where encryption on the internet was a rarity, and orginally designed well over a decade ago. Security features weren't much of an issue with customers at that time, clearly security is becoming much more of an issue now.

      However, very few systems are proof against social engineering, encryption or not.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    2. Re:from a former Nortel employee... by JUSTONEMORELATTE · · Score: 5, Insightful

      To be REALLY fair to nortel, while the web was young seven years ago, (the net was old, even then) that has absolutely nothing to do with this crack job.
      The DMS-100s were broken the good old fashioned way -- use a war dialer to find the dialup number, then call the switch directly. Once connected, try the obvious passwords first (either admin/admin or admin/NORTEL_DEFAULT_PASSWORD, which Mitnick had learned from Nortel docs)

      Deander2 got it right -- Nortel designed an absurdly complex product, and was unmotivated to clean house because they were able to rake in the consulting bucks. WHEN (not if) this comes back to bite a client in the butt (like it did with Sprint) Nortel takes no heat for it, and in fact most likely gets even MORE consulting dollars for a hasty clean-up effort.

    3. Re:from a former Nortel employee... by Grax · · Score: 1

      So you're arguing that it isn't through Sprint's stupidity that they were hackable? that the stupidity was actually Nortel's stupidity?

    4. Re:from a former Nortel employee... by Kellog · · Score: 2, Informative

      I am a current nortel employee and I work on the DMS-100 system. Just to give you an idea of the complexity: the product's 35 million+ lines of code (in a proprietary language called protel) have been written over the past 24 years. It came out in 1976 as the first digital switch. It is old and fussy and really, really hard to improve. The legacy problem strikes again.

      a.c.

    5. Re:from a former Nortel employee... by Beryllium+Sphere(tm) · · Score: 2

      Bingo.

      The article explains that employees were willing to give away "secret" phone numbers and challenge/response pairs to a stranger over the phone.

      Encryption won't help with that. Token-based authentication won't help much -- "Hi, this is system security, we're upgrading the smart card system, could you please help us test by inserting your card and going to this URL?"

      I have to quibble about the awareness of security in the telco industry, though. Phone system security has been a headline issue since Captain Crunch. I'm not willing to excuse anyone who used an unlisted phone number and a cleartext password to "secure" a mission-critical system. They knew they'd be attacked.

    6. Re:from a former Nortel employee... by deander2 · · Score: 1

      ah, protel. how i hated thee... :-)

      never had to code it myself thank god...
      How's NTAccess still running over there?

    7. Re:from a former Nortel employee... by WolfWithoutAClause · · Score: 2
      Look there's no significant evidence of any 'absurdly complex product' features here. These suckers didn't change the password from the factory default. That's all. Or they spouted off to anyone on the phone about what they were.

      From what I know of Nortel, I'd bet that the company ran courses that laid out exactly what you should do to secure the equipment. Its no use these companies going crying to their mommies because they didn't use the flipping equipment properly. Kevin RTFM and they didn't. So it's in the manual too.

      The use of default passwords wasn't out of line with the time. Nowadays you'd have to explicitly switch it on to get it to work. Back then, probably not. Heck, over the weekend I was reading about the Alcatel ADSL modem. Apparently the tftp server on it doesn't even HAVE a password- that modem looks wide open to me. And that wasn't designed 15 years ago, more like 2 or 3. Who's more culpable?

      The customer. They bought the equipment, they specified the equipment, they didn't set the passwords on the equipment, they didn't read the manual that comes with the equipment. They didn't make a big fuss to Nortel about how insecure the equipment was. It certainly wasn't the customers fault that they were hacked, but they did everything except hold the door open for him.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    8. Re:from a former Nortel employee... by crucini · · Score: 2
      Token-based authentication won't help much -- "Hi, this is system security, we're upgrading the smart card system, could you please help us test by inserting your card and going to this URL?"

      In which case the owner of that URL learns nothing useful about the token. Assuming that the token has a crypto processor on board capable of public-key signature, it neatly prevents this attack. The web server sends a random string, the token signs the string with its private key, and the web server validates the signature with the token's public key. The web server does not gain the ability to impersonate the token.
    9. Re:from a former Nortel employee... by JUSTONEMORELATTE · · Score: 1

      I don't buy it.
      Of course the owner of a tool is responsible for making that tool perform correctly. In this case, Sprint was certainly responsible for ensuring that the DMS didn't have the default admin passowrds in production. But saying that Nortel is blameless because they documented this fact is bullshit. The right answer is to design tools where the default condition is secured, and make the customer read the manual, attend the training, and jump through hoops to make it insecure. Nortel shipped the box 180 degrees opposite of this.
      There's enough blame to go around, but Nortel shipped gear designed for production. The default state of this gear should not be insecure.

      And for what it's worth, your Alcatel DSL router isn't a case of bad design. If I recall correctly, TFTP doesn't have a password scheme. The first T is for trivial. There's no authentication and it's sessionless. For a DSL router this isn't a big deal if you don't accpet connections on the WAN port. Sure, a small business using this as the only router between employees and the net could be cracked, but only by a disgruntled employee, not by some script kiddie on the other side of the world.

    10. Re:from a former Nortel employee... by WolfWithoutAClause · · Score: 2
      The default state of this gear should not be insecure.

      It isn't insecure. It's only when the customer wires it up to the public telephone networks, without first bothering to set the passwords up that it becomes insecure.

      And for what it's worth, your Alcatel DSL router isn't a case of bad design.

      Yes it is, no default passwords, tftp server you can't switch off; oh and did I forget to mention the so called 'cryptographic' backdoor?

      For a DSL router this isn't a big deal if you don't accpet connections on the WAN port.

      It doesn't but it still is a big deal because there is a way of bouncing packets off the LAN and accessing the tftp server that way.

      If I recall correctly, TFTP doesn't have a password scheme. The first T is for trivial. There's no authentication and it's sessionless.

      Ok... But what you seem to have missed is why did they have a tftp server at all... why IS there a tftp server in the box in the first place? Oh yeah, one file is readable that might interest you, via the tftp server you can do little things like read/set the password file.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    11. Re:from a former Nortel employee... by JUSTONEMORELATTE · · Score: 1
      The default state of this gear should not be insecure.

      It isn't insecure. It's only when the customer wires it up to the public telephone networks, without first bothering to set the passwords up that it becomes insecure.
      Surely you don't believe this statement, do you? The default state of the gear is insecure. If the customer "wires it up to the public network" they're turning it on. If they do so without taking an additional step of setting the passwords, the system is vulnerable. The default state is what you get PRIOR to taking the additional steps.
      Saying that it's secure until you wire it up and turn it on is absurd. Dynamite is harmless, until you light the fuse.
    12. Re:from a former Nortel employee... by WolfWithoutAClause · · Score: 2
      If the customer "wires it up to the public network" they're turning it on.

      Oh right, if you redefine the English language then of course you are completely correct. Normal people call plugging the mains lead in the back, and pressing the power button "turning it on". Connecting a node to the public networks is referred to as "turning it up"; but not in your world apparently. Oh yeah, and that Alcatel ADSL modem is "secure" in your terms too. Way to go!

      p.s. you seem to have an axe to grind- when were you fired from Nortel?

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    13. Re:from a former Nortel employee... by JUSTONEMORELATTE · · Score: 1

      Never worked for Nortel, and I certainly don't think their gear (Telco switches like the DMS, or optical boxes like the Optera line) are any more or less secure than their competitors in each arena. The "axe" that I've got to grind is the attitude of "Sure I shipped a product with all the doors wide open, but page 497 of the installation guide clearly states how to close them."

      The default state for the DMS-100 is inherently insecure.

      If well-known (or even documented) authentication keys exist, and it's up the user to take the initiative to go find and change these keys, then the product vendor should get the lion's share of blame when an outside party exploits this design weakness.
      Decent design would either not have well-known keys in the first place, or would force the user to take explicit steps to enable them.
      It's not that hard to prompt the user at configuration time for passwords, and enforce even half-way "good" passwords at that. Nortel didn't (and most vendors don't) because it's extra work to do and there's not a payback. The customers won't say thank you, they'll be pissed that they can't install The Way We Have Always Done It(tm)
      The public won't blame them when someone cracks the system, because folks like you will jump up and blame the telco for not following Nortel's proceedures (as documented on page 497 of the installation guide!)
      I'm not trying to play games with semantics. Sprint used the DMS the way Nortel intended the box to be used: Powered Up, Connected to the public network, switching telephone calls. You say we should blame Sprint for not securing the device when they turned it up. I say shame on Nortel for making that an extra step.

    14. Re:from a former Nortel employee... by WolfWithoutAClause · · Score: 2
      It would have made no difference, according to his testimony, Kevin would have just rung up some bottom feeder in Sprint and asked for the passwords, pretending to work for Nortel, and they'd have given it to him. Shared passwords don't actually work. Right?

      So then you're not talking about the defaults, you're talking about authentication infrastructures; and then you have to get customer buy in that its even a good idea. It all gets hugely messy. It's worth doing, but persuading people that, is hard.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    15. Re:from a former Nortel employee... by mpe · · Score: 2

      To be fair to Nortel, these particular systems were hacked 7 years ago, at a time where encryption on the internet was a rarity, and orginally designed well over a decade ago.

      This has nothing to do with the internet. Configuration was apparently by a dialup modem on an obscure telephone number.

    16. Re:from a former Nortel employee... by mpe · · Score: 2

      The use of default passwords wasn't out of line with the time. Nowadays you'd have to explicitly switch it on to get it to work.

      Since the telephone numbers of the configuration modems were apparently random then most likely someone had do do some sort of configuration. It's not as if using a dialup modem is the only way to remotely configure the system anyway. Alternatives would be a private IP or X25 network or a direct line to a NOC. Indeed using a dialup connection has the problem that a misconfiguration could disable the dialup line.

      Heck, over the weekend I was reading about the Alcatel ADSL modem. Apparently the tftp server on it doesn't even HAVE a password- that modem looks wide open to me.

      The TFTP protocol dosn't use passwords. The question would be more "why does an ADSL modem need a TFTP server in the first place?"

    17. Re:from a former Nortel employee... by mpe · · Score: 2

      Surely you don't believe this statement, do you? The default state of the gear is insecure. If the customer "wires it up to the public network" they're turning it on.

      "Turn it on" would simply be a case of applying power to it. (Which in the case of telephone switching equiptment is typically 50V DC from a battery.)

      If they do so without taking an additional step of setting the passwords, the system is vulnerable. The default state is what you get PRIOR to taking the additional steps.

      Actually it's even worst than that. Since you can't simply plug it into the telephone network and expect it to work. You'd first need to configure both it and other bits of the telephone network in order for it to do anything at all.

      Saying that it's secure until you wire it up and turn it on is absurd.

      If it's simply wired and powered up then it is perfectly secure. It's once it has been configured to be part of the telephone network and such things as dialup remote admin ports have been configured that it becomes insecure.

    18. Re:from a former Nortel employee... by mpe · · Score: 2

      The public won't blame them when someone cracks the system, because folks like you will jump up and blame the telco for not following Nortel's proceedures (as documented on page 497 of the installation guide!)

      The telco managed to read the rest of the installation manual. They must have since they have hardware people can use to make telephone calls with. As opposed to a pile of hardware which dosn't do anything useful.

      Sprint used the DMS the way Nortel intended the box to be used: Powered Up, Connected to the public network, switching telephone calls.

      So Nortel shipped Sprint some hardware which was pre configured, they also have access to the rest of Sprint's network to configure it to realise that the new box was there? Or did Nortel ship Sprint some hardware which Sprint needed to configure?
      If Sprint gave Nortel access to their network then it was their responsibility to ensure that they did so in a secure way. If Sprint configured their own hardware then it's their responsibility to know what they were doing.

    19. Re:from a former Nortel employee... by WolfWithoutAClause · · Score: 2

      Yeah, I know, I never said it was, I said it was hacked at a time where encryption... was a rarity. I was trying to remind people that all this equipment is really old. The industry standard in security is rather further forward now; and they aren't comparable. The DMS100 probably wasn't out of line with the standards of the day when it was designed; although it certainly wasn't state of the art. And it's still better than some other equipment you can buy today from companies.

      --

      -WolfWithoutAClause

      "Gravity is only a theory, not a fact!"
    20. Re:from a former Nortel employee... by JUSTONEMORELATTE · · Score: 1
      The public won't blame them when someone cracks the system, because folks like you will jump up and blame the telco for not following Nortel's proceedures (as documented on page 497 of the installation guide!)

      The telco managed to read the rest of the installation manual. They must have since they have hardware people can use to make telephone calls with. As opposed to a pile of hardware which dosn't do anything useful.
      I'm not complaining about bad documentation, I'm claiming that the DMS was ill-designed with respect to security. Even within that, I'm only arguing against one design choice: The default state is for well-known authentication keys to be enabled. That's it. That's all. That's a flawed design. The user has to take an explicit step to secure the box as part of configuration, rather than the default state being secure and the user taking an explicit step to open it up if they choose.

      As I said to Wolf earlier, you say we should blame Sprint for not securing the device when they turned it up. I say shame on Nortel for making that an extra step.
  16. No need to scour the books... by Anonymous Coward · · Score: 0

    just call Mitnick a terrorist and make the rules as you go.

  17. Re: Double Jeopardy by djweis · · Score: 1

    But you can only be dead once. You can rob a bank over and over (until they lock you up, I guess).

  18. Incredible article. by Viewsonic · · Score: 1

    It is hilarious reading this ... If this doesn't bring Mitnick from Legendary to Godly I dont know what will. He still has old lockers with passwords and infos.. This is stuff that books and movies are made of, not real life! Incredible.

    1. Re:Incredible article. by Anonymous Coward · · Score: 0

      Well -- *A* movie was already made about him (released in France under the name "Cybertraq"). Unfortunately, they didn't consult anyone with any real familliarity with the case, and the script was poorly written to begin with, so there was nothing "incredible" about this movie.

      But I agree with you, that the just the very idea that Mitnick has kept some old locker around with his "resources" is cool and very in character for him (remember what he did with his hard disk before the feds confiscated it from him ...)

  19. What I think is cool by Ryan_Singer · · Score: 0

    Is that he went and got the list from a nearby storage locker, a not-too-subtle hint that he has lots more potentially powerfull stuff where that came from.

    --
    Ryan Singer
  20. Telco myths resolved. by Netw0rkAssh0liates · · Score: 2, Funny
    Hi there.

    After working for several Fortune infinity companies, I have come to the conclusion of my $5,000,000 granted study that anyone able to pick up a telephone is a susceptible hacker. It is about time the telco in every neighborhood started locking down their systems with finger-printing and place a mark on the wrist or hand of every telephone subscriber that he may not buy or sell anything over the phone without this mark. With further granted jurisdiction, the telco should be able to establish a real-time video and audio presence in the homes of each and every telco subscriber and relay this information across satelites so the whole world may be allowed to intrude on anyone's privacy in attempt to prevent people from worshipping anyone but the telco. Kevin Mitnick shall, upon appearance, be put to confinement in a maximum security stone cave, a rock rolled in front of it, and the cave sealed with wax so the telco will know whether the prison had been disturbed within any 3-day period. This is the only way people, and the telco shall have rights to your first post and first born. Anyone that has not lathered sheep's blood above their doorway shall have their building demolished by the telco. As of yesterday, the staff of slashdot.org and the users of the United Nations' oxygen on planet earth must comply or face harsh punnishment from internation agencies that don't like United States citizens. Thankyou for your time.

    Sincerely,
    Bob Grover

  21. What's the '?' for... by nochops · · Score: 3, Insightful

    Why use a '?' in the post?

    Is there any doubt that Mitnick is a criminal?

    Since is when is cell phone cloning, carding, and cracking legal?

    Since when is running from the law (he was a fugitive) legal?

    I think there's no question as to the legality of Mitnick's actions. Weather or not the legal system handled the case correctly is another story, but he is definitely guilty of those crimes.

    --
    "A terrorist is someone who has a bomb but doesn't have an air force." -William Blum
    1. Re:What's the '?' for... by vidarh · · Score: 2

      Presumably the '?' was there because it is an open question whether he is our "favorite computer criminal", not whether or not he is a criminal. (Note the "favorite" there).

    2. Re:What's the '?' for... by Phreakiture · · Score: 1

      Mitnick is a convicted criminal. That is a fact.

      Far more criminal than anything he's done, though, is the fact that he spent so much time behind bars without a trial. So much for a fair and speedy trial....

      --
      www.wavefront-av.com
    3. Re:What's the '?' for... by blueskies · · Score: 2, Insightful

      It should have been:

      "Our favourite (?) computer criminal...."

    4. Re:What's the '?' for... by Eil · · Score: 2


      Now I'll be the first to admit that yeah, Mitnik screwed up. He made several mistakes and more importantly, broke the law. However, he more than paid for it by the inhumane (at best) treatment that the law system gave him[1], even when he admitted his guilt. The courts used him as an example of how they treat hackers who get caught.

      It's yet another perfect example of what's wrong with the legal system in this country.

      Mitnik's "officially" done his time, but thanks to the power of the government, media, and press, he'll continue be prosecuted by the public for the rest of his life.

      1) Details of his unfair and unconstitutional treatment can be found all over the internet from independent resources. The government still won't admit that they did anything wrong and you can bet the press wouldn't challenge that.

    5. Re:What's the '?' for... by Rossalina+W+Sanchez · · Score: 1
      Why not learn what really happened?

      He spent time behind bars because he pleaded guilty to cloning cel phones.

      To summarize: He was not being held in jail awaiting trial, he was serving time for cloning cel phones.

      Don't believe me? Look it up.

      Sorry to destroy another great Internet myth pal.

      --

      --Rosie

    6. Re:What's the '?' for... by Anonymous Coward · · Score: 0

      "Those crimes"? Read the record -- exactly what crimes?

      The government actually never made a "cracking" case against Kevin, because they had virtually nothing on him. Read the details of the case.

      What Kevin did was wrong -- but its on the order of "graffiti" or "jay-walking". It doesn't even rise to the level of the Melissa virus, whose author is serving *less* time than Mitnick.

    7. Re:What's the '?' for... by Anonymous Coward · · Score: 0

      Your post shows your general ignorance of the subject matter, ie. Mitnik's crimes. Or perhaps you are just jealous. whatever, that is between you and your shrink.

      Mitnik didnt do any damage to anything he touched. He broke into places to gain information. His real crimes (ironically, what he was put in jail for), were for illegal wiretapping and I think interfering with a federal investigation, and some other stuff.

      My point is that what he went to jail for was what he did once he BECAME a fugitive, not for what he did before that.

      So know your facts before you bash someone.

      Personally, I think the situation is amusing. Mitnik seems to enjoy thumbing his nose at the man =)

    8. Re:What's the '?' for... by kesuki · · Score: 2

      For the two people reading slashdot who've never heard of 2600 magazine, the url is
      Complete with a realtime ticker of how long until he's a free man.

  22. Re: Double Jeopardy by vinnythenose · · Score: 2

    But if they found you guilty the first time and you hadn't committed the crime, then you could sue the government right?

    Land in jail for 20 years.
    Sue goverment, get 20 million or so.
    Land back in jail for another 20 years.
    Use eBay extensively.

    That'd be the pattern right?

    --
    --- I used to moderate, then I read the -1 articles and decided having to filter through them was not worth it.
  23. Why the question mark? by Marcos+the+Jackle · · Score: 0

    "Our favourite computer criminal (?)"

    Are you questioning whether he's our favourite or a criminal? Never the less, he did break the law, therefore he is a criminal. Granted, spending 4 years in jail awaiting trial is pretty screwed up, but he did commit the crime. He got caught - get over it!

    Have a day.
    Mk.

  24. Why is he a free man? by Anonymous Coward · · Score: 0

    This piece of shit should have been buried under the jail in a dark hole to rot. Now he is out FUDing up the place and 'social engineering' his way to star status, but his skillz suxor and always have. He got caught, committing crimes, and that speaks volumes as to how good he really was. No thanks Kevin, I don't think I need security advice from you.

    1. Re:Why is he a free man? by Phreakiture · · Score: 0

      So what have you got, you anonymous piece of shit? Show me your "skillz", or are you just another script kiddie with an attitude?

      --
      www.wavefront-av.com
    2. Re:Why is he a free man? by Phoenix · · Score: 2, Insightful

      Regardless of what you think of him, he did get shit upon by the justice system. As a citizen of this country he is entitled to a speedy trial. They left him to rot for a long time before they got down to putting up on trial. Personally I have no use for one such as he, but regardless of anyone's opinions he has rights to fair judgement under the constitution of this country. To deny such to him is to leave an opening to deny others of those same rights.

      For example...you are miffed at Kevin for what he did (as am I) but would you feel the same way if someone were arrested for hacking a CueCat scanner and making software that didn't report to the company, then left "to rot"? Or would you be shouting that the government was commiting a travisty of justice?

      You can not have it both ways...It has to be fair to all or fair to none.

      Phoenix
      (and yes I know that it frequently doesn't live up to the ideals on the Constitution, but let's not help make it worse Ok?)

      --
      -- Wiccan Army, 13th Airborne Division "We will not fly silently into the night"
    3. Re:Why is he a free man? by Anonymous Coward · · Score: 0

      Sure! I mean why should we let a little thing like the Constitution come into play anyway? It's just paper. if Kevin Mitnick wants to fight to prove that he broke the law, and he gets arrested for him, fuck him. You aren't going to see a "Free Kevin Mitnick again, the dumb bastard" bumper sticker on my car.

    4. Re:Why is he a free man? by Anonymous Coward · · Score: 0
      Bah. You're talking out of your ass. He spent time in prison for cloning cel phones. A crime he was most certainly guilty of. I think he did 3-4 years for that, if memory serves me.

      Regardless, why not do a little research to find the facts instead of mindlessly repeating the crap you read on the Interweb?

    5. Re:Why is he a free man? by Anonymous Coward · · Score: 0

      "Regardless, why not do a little research to find the facts instead of mindlessly repeating the crap you read on the Interweb?"

      I thought it was called the World Wide Web, something that ran under the Internet.

      Interweb...who are you? James Hetfield from the "Napster Bad" cartoons showing on www.campchaos.com?

    6. Re:Why is he a free man? by Anonymous Coward · · Score: 0

      INTERWEB BAD!

  25. Re:Sad day ... Stephen King dead at 54 by GETerry · · Score: 0

    I would certainly think that there would be at least a small story about this in the freaking Portland ME newspapers... Sorry ass AC...

    --
    Why did I even bother?? (my sig sucks, but it's better than yours!!)
  26. Find Kevin Mitnick's Locker by Anonymous Coward · · Score: 0

    Sounds like a job for Geraldo!

  27. statute of limitations by caveat · · Score: 1

    I'm not certain that he's exempted from prosecution by way of double jeopardy.
    the statute of limitations in nevada for these crimes is 5 years (says the article, at least), and all his breakins were prior to 95. he simply can't be prosecuted for these illegalities; the clock's run out.

    --

    Facts do not cease to exist because they are ignored. - Aldous Huxley
  28. shouldn't that be... by caveat · · Score: 2, Funny

    ...ski11z sux0r? (0r s0m3such, i'm n0t th4t up 0n my h4cksp34k)

    jealous script kiddie.

    --

    Facts do not cease to exist because they are ignored. - Aldous Huxley
  29. social engineering from the movies by rjamestaylor · · Score: 1
    All you need to do is fake a computer date with a nerdish priveleged employee and get him to say "Hello, my name is ______ ________. My voice is my passort. Verify me." Then you're in!

    Farm out. Right arm.

    --
    -- @rjamestaylor on Ello
    1. Re:social engineering from the movies by Anonymous Coward · · Score: 0

      The only part of that which would be social engineering is the date. Recording the voice is a playback attack. Social engineering is convincing a person to *give* you access or information you do not have the authorization to obtain.

    2. Re:social engineering from the movies by rjamestaylor · · Score: 1
      I am so happy to point out that you are incorrect!
      • The
      • only part of that which would be social engineering is the date. Recording the voice is a playback attack.
      I can understand your mistake, since you have obviously never been on a date and do not realize that conversation on a date with another person (as opposed to your dates with Real Dolls) is not a simple matter. Also, extracting the exact words necessary for the voice-print id requires extensive social engineering. Or, do you not recall how incredibly difficult it was for Liz to get Warner to say, "Passport"?

      Another Anonymous Coward dashed to the ground in flames!

      --
      -- @rjamestaylor on Ello
  30. Shady characters... by wub · · Score: 1

    Does anyone find it amusing that this pr0n guy Munoz hires one of the people allegedly responsible for his interruption of service to testify on his behalf.

    1. Re:Shady characters... by Anonymous Coward · · Score: 0

      No -- Mitnick was *not* likely responsible for his interruption of service. Vegas has a lot of money to hire black hat hackers, but Mitnick was not one of them. Mitnick was never in it for the money.

      The mistake you are making is assuming that since this sounds so incredible, that Mitnick was the only one able to do it. The fact is, Mitnick is the only one who could do it who also happens to have "paid his debt to society" and has immunity from prosecution (double jeopordy) on the matter.

      Mitnick just happens to be the most suitable person to testify about the weakness of the system, not the *only* person who could do so.

    2. Re:Shady characters... by DavidTC · · Score: 1

      Kevin was in prison when all this was happening, or out on parole without a computer, thus he would have found it rather hard to dial up said modems and hack Sprint.

      --
      If corporations are people, aren't stockholders guilty of slavery?
  31. Mitnick Should Be Shot! by egg+troll · · Score: 0

    And so should all of his lame ass supporters. Mitnick got what he deserved. Actually, he didn't because he wasn't shot. But still, he deserved to be punished.

    --

    C - A language that combines the speed of assembly with the ease of use of assembly.
  32. Re:My name is Kerry Getz by Anonymous Coward · · Score: 0

    fuckfuckfuck i am angry with my skateboard

  33. Unwarrented comparison by burgburgburg · · Score: 1

    I was always under the impression that Winona got her celebrity by ... acting. And while she's received unwanted publicity with her alleged illegal acts, I'd be hard pressed to consider her worthy of inclusion of a list like Bonnie and Clyde, Al Capone and John Gotti.

  34. Vendors to blame by scoove · · Score: 3, Interesting

    were still the default password installed by Nortel

    Had the same problem with a bunch of calling card switches installed by PCM (Priority Call Management - somewhat of a bigger name in that world).

    Root passwords were "root", no OS patches (SCO & QNX) were ever applied since "they hadn't tested whether their software would interoperate with a patched version of the OS", .rhosts were common between systems to enable trusting, all the usual sockets were wide open, etc.

    Course, then there's the time we were paying Lucent $75,000 to install voice access concentrators and they complained that they couldn't telnet to them. Lucent set 200.200.200.0/24 addresses on all the systems they built - just made up a number - and couldn't figure out why the numbers wouldn't route across the open Internet. Boy did I get a stupid look when I asked the Lucent people what the Comite Gestor no Brasil thought about their address scheme... (whois 200.200.200.0@whois.arin.net)

    Really, how do these folks stay in business?

    *scoove*

    1. Re:Vendors to blame by Safety+Cap · · Score: 2
      Really, how do these folks stay in business?
      They do because everyone is just as bad, so now it is the norm. Kinda makes you wonder how we ever manage to actually advance without collapsing.

      Maybe that's why we aren't "beaming" up, telecommuting on Mars, or any of the other cool futuristic stuff we should've done by now --- because we're dragged down by the Norms.

      --
      Yeah, right.
    2. Re:Vendors to blame by mpe · · Score: 2

      Really, how do these folks stay in business?

      Right now it looks like some of them might not.
      It's probably an issue of how easy it would be for someone to switch supplier. Even though modern telephone systems are highly modular you can't mix and match bits from different suppliers.

  35. Re:NOT Double Jeopardy by dohcvtec · · Score: 3, Informative

    First off, RTFA. Mitnick is detailing all of his Sprint Nevada exploits for the first time; why do you think they were so caught off guard? So apparently (the article itself doesn't expicitly say) this is the first time anyone's heard of Mitnick 0wning Sprint Nevada's switches back around '94. Therefore he hasn't been charged (or convicted) for these activities before, so duble jeopardy does not apply here, but due to the 5 year statute of limitations for these matters, he cannot be prosecuted anyway. HTH

    --
    -- Never hit a man with glasses. Hit him with a baseball bat.
  36. Actually by N8F8 · · Score: 2

    Hacking the CueCat would only be (potentially)hurting the CueCat company.

    Hacking the Phones, listening in on private conversations, using blackmale, stealing credit cards, etc. harms us all.

    Your moral equivalancy doesn't hold up.

    --
    "God fights on the side with the best artillery." - Napoleon, Marshal of France - speaking truth to power
  37. Another example by sigxcpu · · Score: 1

    I work for a company that makes routers, and on most of our costumer's instalations (I am talking a bout small to medium ISPs) I have found that the default root password remaind unchanged (a one letter password!)
    (on the newer software update we changed it to somthing a little more secure and didn't give it to the users)

    --
    As of Postgres v6.2, time travel is no longer supported.
    1. Re:Another example by DavidTC · · Score: 1

      You changed it to something 'more secure' and didn't give it to them? I hope they can still change it, because, if not, you're going to get sued when some cracker finds out what it is and suddenly has twenty thousand open routers.

      --
      If corporations are people, aren't stockholders guilty of slavery?
    2. Re:Another example by darkonc · · Score: 2
      Why not do like redhat, and have them set up the root password on install?

      Include a little ditty on secure passwords in the preamble to the install instructions.

      --
      Sometimes boldness is in fashion. Sometimes only the brave will be bold.
  38. On the good side of the Mafia... by sfgoth · · Score: 3, Interesting

    So one theory is that the Mafia was behind Munoz's problems. Forget legal trouble... how much trouble might Kevin be getting himself into now?

    1. Re:On the good side of the Mafia... by Anonymous Coward · · Score: 0

      * PROTECT KEVIN *

  39. Say what you will about Mitnick... by Anonymous Coward · · Score: 0

    ..but if a guy like him can obtain this kind of access to supposedly "secure" systems, wouldn't you think that government agencies have been using this sort of access for years to illegally obtain information that may be beneficial to them?

  40. Sprint's security DOES suck, first hand story. by rice_burners_suck · · Score: 5, Interesting
    How Sprint's crappy security directly affected me.

    I live in Arizona, and I have four Sprint PCS phones: One for myself and three are for my "on-call" employees. These phones are on 24 hours a day for obvious reasons.

    A disgruntled ex-employee in Delaware (who had been fired years ago), who happens to know my phone number, strolled into a Sprint PCS store in Kentucky, and asked the proprietor (or rather, the idiot working there) to bring up my account information. Now remember: All this person knew was my phone number. The Sprint PCS idiot happily punched up my account and showed the unidentified person my account details: All my phone numbers, numbers that had been called on these phones, how much my bill was... it goes on and on. In short, someone who only knew my phone number got access to all my "private" information, no questions asked.

    I discovered this when the person in Delaware (who was in Kentucky at the time) called and told me, in the form of a threat. I immediately called the Sprint PCS customer support line and told them of the problem. They had some explaining to do, and I expected them to immediately change my phone numbers and account information. They refused, and explained that any such breach of security was impossible: The gentleman in the store should have asked for an account password. If the customer didn't know the password (or so claimed the customer support woman), the account information could not be accessed. This made sense, as computers do ask for passwords before showing any protected information. So I assumed the ex-employee was lying to annoy me, and dropped the issue.

    Later that night, angry employees began calling me repeatedly and complaining of crank calls. Then, I got a call from the disgruntled shmoe in Delaware. Turns out, my assumption had been wrong. I came to the conclusion that private account information is protected by nothing more than a company policy: The employees in the stores can bring up any account, and the password is DISPLAYED along with all the other information. They're SUPPOSED TO ask you for the password before giving out any information. That's one hell of a security system, eh? So I immediately called Sprint PCS's customer support thing again, but this time, when they answered, I demanded to talk to a supervisor. The conversation went something like this:

    Sprint PCS lady: May I ask about the nature of the call?

    Me THE NATURE OF THE CALL IS SPRINT PCS GIVING OUT MY PERSONAL INFORMATION TO STRANGERS WITHOUT MY CONSENT!

    Sprint PCS lady: One moment...

    At this point, a supervisor lady answered, and I explained (rather angrily, I may add) exactly what happened, and DEMANDED that they change all my phone numbers IMMEDIATELY. (I was doing this as an immediate action, to be followed by any number of things, including the high possibility of cancelling my account altogether, followed by strong legal action.) Now the supervisor freaked out and got a bunch of people on my case within minutes. She explained that my conclusion about their security had been correct (that nothing is password protected at all), but that I could optionally make my account "high security", which basically means that certain other information (like a social security number or something) is needed before account details can be accessed. So I demanded that my account immediately be made high security. Then, she began the process of changing my phone numbers, and mentioned that it would cost some amount of dollars to make the change. At that point, I became pissed and said, "I'M STILL CONSIDERING WHETHER I'M GOING TO SUE YOU AND YOU'RE GOING TO CHARGE ME TO CHANGE THE PHONE NUMBERS, AFTER YOUR COMPANY SCREWED UP?!?!?!?" She realized the error of her ways and waived the fees. I continued to raise hell with Sprint PCS for an hour or so, making DAMN SURE that no errors would occur in my next bill (because every time a change is made with them, errors show up in the next bill or two and you have to call and bitch about it, especially when you have multiply phones), and that international calls won't be disabled on the phones (because enabling international calls is a long and complicated process with them, one that raised my blood pressure to the sky too), and that various other problems won't pop up. In all, they were a bit helpful, considering they did screw me over.

    But anyway, that was MY story of how much their security sucks.

    1. Re:Sprint's security DOES suck, first hand story. by Anonymous Coward · · Score: 0

      and if i were you as soon as it happened I would have gone the following day to try and S.E. my own information back from them.

    2. Re:Sprint's security DOES suck, first hand story. by Anonymous Coward · · Score: 0

      Next time, don't bother threating to sue. Just say the magic letters of P.U.C.

    3. Re:Sprint's security DOES suck, first hand story. by rice_burners_suck · · Score: 2

      what's p.u.c.?

    4. Re:Sprint's security DOES suck, first hand story. by Drunken+Philosopher · · Score: 1

      The Public Utilities Commission. Every state has one; they regulate (you guessed it!) the public utilities for their state. Complaints to the PUC generate a mound of unpleasant paperwork; patterns of complaints tend to be dealt with by the levy of large, unpleasant fines. PUCs move slowly, but their wrath is formidible when extracted.

      Most utilities do whatever they can to keep those complaints to a minimum.

      --

      "There is a diminishing return on caution."
  41. No, troll... by Anonymous Coward · · Score: 1, Interesting

    It doesn't harm us "all". It harms those people whose card numbers were misused, those who were blackmailed, and those who were spied upon.
    Pirating music albums only hurts the RIAA....

    Your "logic" doesn't hold up.

  42. Mitnick rocks.. by DaPhoenix · · Score: 1

    By god I love that man... He just happened to have the seed list in a storage locker he hadnt visited in 7 years... lol. That rocks.

    --
    -- -=innocent ramblings from the mind of an insomniatic programmer=-
  43. CueCat by zoloto · · Score: 1

    I declawed mine, big deal. Who's to say I can't do such a thing to keep my privacy (eg; all the source IP's from the scanners are recorded, don't kid yourself for one minute)

  44. mitnick bung buster by Anonymous Coward · · Score: 0

    The reason for Mitnicks' testimony was his notorious cellmate, Anthony "supershaft" Edwards
    who was disappointed with Mitnicks candor.
    "There goes my bitch.." edwards said gloomily as a jubilant mitnick was relocated to the "circumcised and tiny" wing of the penal institution.

  45. Re:Sad day ... Stephen King dead at 54 by rlg1000 · · Score: 1

    This would be national, no, international news if he did indeed die today. I haven't seen it anywhere but here.



    --
    "Since I gave up hope I feel a lot better" - Steve Taylor
  46. Re:Sad day ... Stephen King dead at 54 by Anonymous Coward · · Score: 0

    i think he died last night

  47. Launch an action is my advise by cdn-programmer · · Score: 1

    Thank god form people like kevin . If it weren't for people like him there would be no security at all. But it seems that the US has a propensity to shoot the messenger.

    After reading some of the assinine remarks about how Metnick is such a horrible criminal it just makes me want to vomit. Correct me if I'm wrong - but it seems to me that Metnick never revealed any confidential information to anyone and that at least _some_ of the confidential information he was accused of reading was opensourced before his sentance was over.

    Contrast this to the clearly vicious and insane antics by the sprint employees who clearly have revield confidential informaion and the injustice makes one want to vomit.

    If you can prove what you say, read up on your criminal law and demand the police file charges.

  48. Why does michael always post repeats? by brianosaurus · · Score: 1

    Seriously. Why is it that every time 'michael' posts a story, he adds the comment "we've written about it before" (sometimes with multiple old links)?

    I mean, dude, if you're already run the story, and the best add-on you can come up with is "we already did this", why run it again?

    Who do you think you are? CmdrTaco? :)

    --
    blog
  49. Re:Sad day ... Stephen King dead at 54 by Anonymous Coward · · Score: 0

    He always says this. Had me thinking SK was dead too a few weeks ago.

  50. No ... this must be cool. by Anonymous Coward · · Score: 0

    You clearly haven't followed Mitnick's case very closely. Kevin is extremely paranoid about falling afoul of the law these days. He's seen the inside of a cell, and an 8 month solitary confinement stint has convinced him he never wants to be on the inside again.

    He checks these things with his parole officer. If he's doing it, then it must be legal and sanctioned by his parole officer.

    In particular notice that he is not hacking or using a computer. He is just describing past events.

  51. Re: Double Jeopardy by DavidTC · · Score: 1
    Yeah, that was just silly. It wouldn't be double jeopardy, she was convicted of a non-existence murder, it's not legal to kill him 'again'. She can't be convicted of killing him the first time again, but, obviously, the justice system doesn't go around arresting people for something they just finished their sentence for. (A much better solution would be to go to the police with her information and have the guy locked up. Start with 'kidnapping' (Why, I don't believe people who are legally dead can, in fact, be the guardian of their children.) and work from there. And sue him while you're at it.)

    However, I always thought it was possible the jury would simply fail to convict her. If I were on the jury, and she showed up, I'd figure, hey, she already paid for the crime, and I'd let her off.

    Of course, once you get the media on your side, who knows what would happen. While it might not be legal, I'll argue that it should be legal to do to a person what they framed you for doing and sent you to prison for, and a lot of people would agree with me.

    --
    If corporations are people, aren't stockholders guilty of slavery?
  52. To stop you people from bitching, of course. by Anonymous Coward · · Score: 0

    Oh, look! Slashdot.org is talking about the Las Vegas casino thing!
    Yes, a whole bunch of new information is available, but everyone knows they covered this in the past.

    Slashdot sucks. etc.

  53. Would you trade lives with Kevin Mitnick? by imbezol · · Score: 1

    I'm curious to know how much the people really love Kevin. Do you look up to him? Would you take your life down a similar route? Would you want to see and do the amazing things he's done at the expense of your freedom as he has? Would it be worth it? Would you trade lives with Kevin?

  54. Just has to get the parole officer to approve it.. by kesuki · · Score: 2

    Mitnick was allowed to get a cellular telephone, after his parole officer okayed it. Also, I believe he's allowed to use a computer under police supervision, however he's not allowed to own one.
    He's a security consultant now, and I'm sure that he can get work related use of computers approved, as long as the company is wiling to keep mitnicks activites on computers as detailed as law enforcement requires.
    And if he has to agree to run everything through a keylogger, I'm sure he's not going to break any laws while using a PC for supervised work related activities.

  55. If Law & Order is correct... by x-wing-knight · · Score: 1

    Double jeopardy only applies to a single jurisdiction. Ashely Judd was convicted by one state, then confronted her husband in a different state, so there would be no problem charging her again. Also, there was a Law & Order ep where the guy thought the statute of limitations had run out, but it turned out that time when you were not in the state didn't count, and he had been living in another state, so they could still charge him. "The clock stops ticking when he leaves the state." So maybe this 5 year limit in Nevada has not expired yet.

  56. Slashdot Karma HOWTO by Anonymous Coward · · Score: 0

    / /It / /is / /10pm / /Do / /you / /know / /where / /your / /karma / /is / /Right / /Let / /us / /get / /startedIn / /order / /to / /get / /maximum / /karma / /from / /Slashdot / /posting / /you / /can / /follow / /a / /few / /simple / /guidelines / /The / /University / /you / /go / /to / /Regardless / /of / /where / /you / /actually / /study / /saying / /that / /youre / /at / /MIT / /automagically / /gains / /you / /2 / /Slashdot / /like / /the / /glorified / /student / /notice / /board / /that / /it / /is / /has / /a / /special / /place / /in / /its / /heart / /for / /anything / /from / /MIT / /whether / /it / /be / /a / /teddy / /bear / /stuffed / /with / /a / /switch / /or / /some / /wankers / /wrapping / /a / /yellow / /banner / /with / /elvish / /text / /around / /the / /main / /dome / /Even / /if / /you / /didnt / /go / /to / /university / /qualify / /every / /comment / /with / /a / /My / /professor / /told / /me / /to / /bask / /in / /the / /warm / /fuzzy / /glow / /of / /2 / /Insightful / /Linux / /The / /basis / /of / /the / /Slashdot / /Experience / /Claiming / /you / /run / /Linux / /also / /gets / /you / /1 / /Interesting / /It / /doesnt / /really / /matter / /if / /youve / /never / /actually / /installed / /it / /or / /your / /Red / /Hat / /box / /still / /doesnt / /have / /PPP / /running / /after / /2 / /years / /of / /reading / /FAQs / /The / /important / /bit / /is / /Youre / /part / /of / /the / /community / /You / /can / /bathe / /in / /the / /refelected / /glory / /of / /years / /of / /shoddy / /buggy / /code / /You / /are / /exempt / /from / /the / /Microsoft / /penalty / /see / /below / /as / /of / /course / /your / /Win / /98 / /install / /is / /only / /used / /for / /playing / /games / /And / /reading / /Slashdot / /And / /using / /MS / /Word / /And / /Photoshop / /And / /Microsoft / /Slashbots / /and / /the / /editors / /hate / /Microsoft / /Period / /Use / /of / /a / /symbol / /in / /every / /iteration / /of / /their / /trademarks / /gets / /you / /a / /4 / /Funny / /Even / /though / /it / /is / /far / /from / /original / /it / /still / /manages / /to / /raise / /a / /grin / /in / /those / /people / /reading / /Slashdot / /between / /episodes / /of / /Cowboy / /Bebop / /You / /will / /get / /a / /1 / /Flamebait / /or / /Troll / /for / /any / /post / /even / /hinting / /that / /Microsoft / /products / /are / /any / /good / /useful / /intuitive / /user / /friendly / /You / /will / /also / /quickly / /be / /shot / /down / /with / /replies / /about / /how / /good / /GNOME / /and / /KDE / /are / /which / /will / /then / /in / /turn / /erupt / /into / /a / /flame / /war / /Freedom / /Privacy / /YRO / /The / /bread / /and / /butter / /of / /Slashdot / /It / /fits / /in / /sublimely / /with / /the / /whole / /Linux / /thing / /Youll / /get / /a / /3 / /Informative / /for / /any / /post / /containing / /the / /Ben / /Franklin / /quote / /about / /sacrificing / /essential / /liberty / /It / /makes / /no / /difference / /that / /the / /quote / /is / /totally / /irrelevant / /in / /the / /modern / /world / /Hey / /youve / /got / /karma / /Miscredting / /the / /quote / /will / /not / /end / /up / /in / /a / /karma / /penalty / /as / /has / /been / /demonstrated / /countless / /times / /You / /will / /gain / /extra / /karma / /if / /you / /make / /reference / /to / /your / /experiences / /of / /being / /wiretapped / /by / /the / /NSA / /and / /throwing / /in / /a / /vague / /link / /to / /Echelon / /black / /helicopters / /or / /Tin / /Foil / /Hat / /Linux / /Include / /a / /link / /to / /the / /First / /Amendment / /for / /a / /1 / /Interesting / /mod / /Give / /yourself / /a / /pat / /on / /the / /back / /if / /you / /manage / /to / /include / /some / /extra / /raging / /paranoia / /with / /no / /evidence / /to / /back / /it / /up / /Nice / /BSD / /If / /you / /use / /it / /dont / /mention / /it / /on / /Slashdot / /Most / /of / /the / /Linuxusing / /friendless / /wonders / /that / /inhabit / /Slashdot / /wouldnt / /know / /quality / /and / /stability / /if / /it / /strolled / /up / /and / /kicked / /them / /in / /the / /throat / /with / /a / /size / /13 / /HiTec / /Magnum / /boot / /Any / /mention / /of / /how / /a / /Firewall / /running / /OpenBSD / /with / /pf / /is / /far / /superior / /to / /Linuxs / /pathetic / /offering / /will / /soon / /see / /you / /as / /1 / /Troll / /Much / /like / /the / /post / /youre / /reading / /now / /Yearning / /for / /yesteryear / /Although / /most / /comments / /are / /written / /by / /first / /year / /wannabeCSguru / /students / /or / /links / /to / /goatsecx / /there / /is / /still / /the / /fallout / /dregs / /of / /the / /dot / /com / /boom / /lurking / /around / /slashdot / /You / /can / /get / /5 / /Insightful / /for / /telling / /how / /you / /were / /so / /badly / /treated / /after / /the / /bubble / /burst / /Whining / /about / /the / /lack / /of / /jobs / /where / /you / /get / /paid / /to / /fire / /foam / /darts / /at / /colleagues / /is / /a / /good / /start / /Dont / /forget / /to / /mention / /how / /youve / /now / /been / /out / /of / /work / /for / /months / /It / /starts / /a / /Im / /about / /to / /graduate / /and / /theres / /nothing / /going / /fuckfest / /which / /can / /spill / /over / /into / /hundreds / /of / /comments / /Although / /all / /the / /staff / /who / /were / /any / /good / /simply / /got / /hired / /into / /another / /company / /it / /makes / /Good / /Karma / /Senseto / /hide / /the / /fact / /that / /your / /passing / /familiarity / /with / /Perl / /and / /C / /simply / /cant / /get / /you / /a / /job / /This / /is / /also / /a / /prime / /opportunity / /to / /show / /your / /egregious / /personality / /as / /Slashdot / /rewards / /arrogance / /and / /elitism / /DONT / /FORGET / /TO / /MOD / /ME / /DOWN

    -pwpbot

  57. Re: Double Jeopardy by Jesus+the+Annointed · · Score: 1
    But if they found you guilty the first time and you hadn't committed the crime, then you could sue the government right?

    IAMNAL+IIRC but I believe a number of states have passed legislation that means you can't sue, or if you can you have a limited right to compensation. IIRC, there was a dude in California who was on death row for 15years (or sumthen) and then it turned out he didn't do it but he can't get no money from the government...

    --
    Spreche Deutsche, aber nicht so gut, ja. :)