Slashdot Mirror


Ethical Lines of the Gray Hat

Facter writes "There is a great article on CNET about the ethical debate between white/gray/black-hat hackers - interesting to note is that it reports the "fading away" of the "gray" definition between white and black, due to the DMCA hindering anything in between.."

249 comments

  1. Do we really need a hat? by netphilter · · Score: 3, Insightful

    IMO, there are hackers, and there are security professionals. If you were a hacker and are now a security professional...great. If you continue to break the law, you should go to jail. Pretty simple, and none of this hat confusion.

    --
    "Herbivores eat well cause their food never, ever runs."
    1. Re:Do we really need a hat? by 56ker · · Score: 0, Offtopic

      A lot of security professionals are ex-hackers. Good security professionals need to learn the ways of the hacker in order to protect their systems and probe them for security reasons. Hacking your own systems to see if they're secure - is not a crime as you have access to them anyway.

    2. Re:Do we really need a hat? by Misao-Chan · · Score: 3, Insightful

      Most good security professionals used to be good hackers. I hate this white hat black hat shit that people tout, doesn't mean a damn thing to anybody except marketing people. You're either good at what you do, or you're not, legal or illegal.

      --
      -Misao Little Weasel Girl
    3. Re:Do we really need a hat? by JUSTONEMORELATTE · · Score: 5, Funny

      The question "Do we really need a hat?" from someone who's blog is at whitehatorganization.com
      Yes, apparently you really need a hat.

    4. Re:Do we really need a hat? by netphilter · · Score: 1

      how observant. You're right....and that's kind of the point. The industry (including myself) has adopted this model, but that doesn't make it right. The thinking behind the whole white/grey/black hat thing is flawed. You don't see this in other industries. We don't call burglars black hats and alarm system installers white hats.

      --
      "Herbivores eat well cause their food never, ever runs."
    5. Re:Do we really need a hat? by unicron · · Score: 1

      I agree. I think a lot of computer users, especially those that admire hackers and aspire to be like them, find a nobility in hacking that they feel some how excludes it from being "wrong" and it's just not true. Even if know damage is done, if you're in my system I consider that a trespass and you should be punished accordingly. Laws aren't there for people to pick and choose the ones they're going to obey. You're not allowed to break into a building at 2am and walk around, are you? So why do people feel they're not doing anything wrong by hacking into some computer and snooping around?

      --
      Finally, math books without any of that base 6 crap in them.
    6. Re:Do we really need a hat? by (trb001) · · Score: 4, Insightful

      Where do you draw the line? Are the only sanctioned hackers the ones that work for a security company? Personally, if I'm using software, I want to find out about any vulnerability that exists. If I find one, I want to report it. I have no trouble reporting it to only the company that produced the software, but let's face it...they don't always respond with a patch or a fix. If you've taken the legit route and the company has done nothing, I don't see a problem reporting it. I think this is a notable difference between the Hats.

      Not to sound like I'm getting up on my soapbox (I'm not), but it's one of the reasons I like Linux software. I know that if someone finds a problem with bind/apache/ftp that a fix is going to be published somewhere I'll read it (fyi, I don't go surfing the Microsoft website for patches) and I can fix the hole. It's comforting, and that's the defense I give people when they ask why they should use OSS for secure systems.

      --trb

    7. Re:Do we really need a hat? by Anonymous Coward · · Score: 1, Insightful
      IMO, there are hackers, and there are security professionals. If you were a hacker and are now a security professional...great. If you continue to break the law, you should go to jail. Pretty simple, and none of this hat confusion.

      You seem to be confusing hacking with something illegal. Why can't someone who's a "Security Professional" still be a hacker? Being a hacker is a mindset, an ideology, and NOT something illegal. People do illegal things regardless of what label they have, self proclaimed or otherwise.

      Just because someone proclaims that they are a hacker doesn't make it so. A hacker should not be confused with a criminal, just because some hackers have broken the law. Likewise, CEO's should not be confused with criminals, just because some CEO's have broken the law. CEO's just have better PR.

    8. Re:Do we really need a hat? by Zathrus · · Score: 5, Insightful

      If you continue to break the law, you should go to jail

      Ok. So you realize that merely reporting a security hole in a protocol to a company, with working source code, is a violation of the DMCA?

      So, as a "security professional" you have now broken the law and should go to jail.

      If we want to be sane about the situation then people trying to uphold themselves as being better than black hats need to get off their high horse. Realize that if you've found a security hole in a product then you're probably not the only one. And yes, you should dutifully report it to the company with enough data/code for them to verify your claim, and give them time to address it (which is a key issue - how long is long enough?).

      But what happens when they don't fix it? Do you just decide that you've done your duty and ignore the fact that someone else out there either has or will discover the hole and exploit it? Or do you report it to a public independant organization like BugTraq? To whom do you owe loyalty? The company producing the product, or to the customers who are being left hanging in the breeze by the company?

      I'll admit that I'm no hacker or security professional, but as a programmer I'd damn well want you to do the latter. It's called whistleblowing, and it's accepted as a viable method to right wrongs when other attempts to solve a problem have failed. This isn't a new concept, nor is it limited to the computer world. The only real difference is the speed at which companies are expected (and needed) to act.

    9. Re:Do we really need a hat? by RevDobbs · · Score: 2, Funny

      I prefer my red hat... I don't have to shave, all the white hats respect and revere me, and I can get it on with Smurfette.

    10. Re:Do we really need a hat? by neuroticia · · Score: 5, Insightful

      White hat and black hat are necessary distinctions. Either someone intends to cause harm, or does not. Those terms are an easy way of explaining to the average layperson that there are 'good' and 'bad' hackers, otherwise they'll lump us all together.

      The 'bull' is that there is no longer a 'gray hat' hacker. The elimination of the 'gray areas' is a legality, and a stupid one, at that. It is not a reality. Hackers will still walk the line, and things they do will still be thought of as "good", "bad", or "fuzzy line down the middle". The only difference is that the DMCA has moved the line of acceptable actions so far over, that people can be White Hat hackers and still end up being persecuted under the DMCA for doing something that even the majority of the population would consider "GOOD" as opposed to bad.

      This doesn't mean that the hackers are "black hat", and it's stupid to imply so.

      -Sara

    11. Re:Do we really need a hat? by Anonymous Coward · · Score: 0

      Do you really intend to make the analogy that a burglar's skills and knowledge are as similar to those of an alarm system installer as a black hat is to a white hat? Or were you simply using this comparison for the emotive response of the analogy? The entire reason the "hats" are used is because of the similarity between the two groups. I think a better analogy would be between freedom-fighters (white hats) and terrorists (black hats). In some cases, you might think the line is quite clear. But in other places, the distinction is not so clear and becomes almost political. It is this ambiguity that the hat designation serves to illustrate. A person who may think they are a white hat may find themselves at the wrong end of a lawsuit, making them a black hat. After all, what color hat is someone who finds a security flaw in free software, the source of which is available to everyone, but is sued for informing someone? That's the issue, and pretending it's not an issue in your holier-than-thou way convinces nobody, although I assume it made you feel good about yourself.

    12. Re:Do we really need a hat? by deepchasm · · Score: 3, Insightful

      We don't call burglars black hats and alarm system installers white hats.

      Your post indicates that you think to earn the title "hacker" you have to break into other people's computer systems. Well, that's one definition I suppose (one I hate, and I'm not the only one ), but it is by no means the only definition.

      Anyway, in order to answer to the overall theme of this thread - "why the coloured hats" - it is helpful to understand both the history of the term "hacker", and appreciate the prevalence of moral relativism. So, if you're sitting comfortably, then I'll begin...

      The origins of the term "hacker" being used in relation to computers are described in the very detailed and entertaining book Hackers: Heroes of the Computer Revolution by Stephen Levy. From the Amazon editorial review:

      Steven Levy's classic book explains why the misuse of the word "hackers" to describe computer criminals does a terrible disservice to many important shapers of the digital revolution. Levy follows members of an MIT model railroad club--a group of brilliant budding electrical engineers and computer innovators--from the late 1950s to the mid-1980s. These eccentric characters used the term "hack" to describe a clever way of improving the electronic system that ran their massive railroad. And as they started designing clever ways to improve computer systems, "hack" moved over with them.

      So how did the meaning of the word change?

      Well, this is where moral relativism comes in. It's human nature to justify yourself, and that's what people did. When mischievous computer users began entering computer systems without authorisation they justified (in their own minds) themselves by claiming that they weren't doing any damage - just satisfying their curiousity.

      "I'm not a criminal, I'm a hacker", they'd say.

      Hence you have an entire culture of people that rate each other according to technical ability and/or morals, spawning such terminology as "lamer", "elite", "black hat", "grey hat", "white hat", and "script kiddie"; but funnily enough, it all seems to come down to the fact that people don't want to admit that they are doing something wrong - there is always someone worse than them.

    13. Re:Do we really need a hat? by Anonymous Coward · · Score: 0

      You ever seen those WatchDog programs? Where consumers who have not got a satisfactory answer or any reply at all from the manufacturer get their complaints aired on TV?

      Whats the difference?

      When was the last time you saw Esther Rantzen get sued for releasing details on a security flaw in the door latch of a washing machine?

    14. Re:Do we really need a hat? by ebyrob · · Score: 5, Insightful

      Hmm... this sounds like an obvious troll, but since you've been modded insightful, I'll byte.

      The term "hacker" has a lot of confusion tied to it. Where I come from it's a term of respect for someone's raw technical abilities. A hacker is someone who is so good at taking things apart and understanding them that they can make gadgets and software do things the original designers never dreamed of. If you think everyone fitting that description without "proper approval" belongs in jail you've got another think coming.

      Maybe when you say hacker you mean someone who breaks into systems belonging to someone else without permission. Yes, that is a minor criminal act, much like trespassing. And there is no excuse for responsible adults doing such things without very good reason, but kids will be kids (Sometimes a system is so insecure this can happen by accident. )

      The term hacker in general usage today usually covers both the system hacker who gains access to systems not belonging to them as well as the software hacker who takes apart software they have rightfully purchased on their own system. Classically system hacking has been seen as wrong or illegal, but software hacking has always been accepted, and only disclosure has ever been at issue. The DMCA attempts to deal with both in one fell swoop and does so very badly. I take your comment to mean we should just enforce the law to it's fullest even while it is changing in subtle and terrible ways.

      White hats hide information. It seems they *never* disclose exploit code. Black hats hide information. They only use vulnerabilities for themselves. It would seem to be only Grey hats who hold the advancement of security important by sharing their code and knowledge fully. In fact, I'd say it is highly unethical for a White hat to get a vulnerability fixed without ever disclosing it. Perhaps we need criminal penalties for that as well? It also seems a tragedy that white hats will never be inclined to disclose their exploit code even after a fix has been made. They just don't seem to realize that information sharing really is a power positive good. (wasn't that the hacker eithic?)

      Actually there are a whole host of other things White hats can and do that are wrong. Like implanting spyware in a product or being negligent in protecting customer information. I don't see criminal penalties for those...

    15. Re:Do we really need a hat? by Anonymous Coward · · Score: 0

      Well, it can be hard to get a job if you are an admitted black-hat. Basically it comes down to whether you have been caught.

    16. Re:Do we really need a hat? by dwaggie · · Score: 1

      I agree with you on a lot of your points. A lot of the legislation these days are defined by people who just don't understand the culture that is bound up within what is now the internet. It has changed a lot over a very few short years, but the same people still run our Media, Governments and Companies. I capitalise because they're usually the ruling bodies of just about everything. What? No 'Public'? That's simply because the general public doesn't run things. They are fed FUD about what people who really know their way around a computer can do. What if that bad man gets ahold of my Microsoft Money portfolio?! What if he takes down my business!?

      Most of it, of course, is smoke and mirrors. Examples, like 'another Kevin,' to stop people from doing those 'badbad' things. People fear things they don't understand, and one of the things Companies will never understand is advice for Free. They have to pay consultants to do all that, consultants with Degrees and Certifications.
      Advice from someone off the street will just be shoved to the legal department to see if they can't shut him up, or put him away.

      Funny thing is, most companies don't have anything to offer in the way of financial 'secrets' or documents of any worth that are on a network. Most of them are stored on local PCs, and that would take a whole new world of work. First you'd have to get in, and identify a local computer with the up-to-date information, and then crack it. There would be weeks, almost, working on just this.

      And if someone hasn't noticed something by then, this Black Hat has found the honeypot of all honeypots. One he can visit freely, openly, and just walk in and out like he owns the place.

      They could even hire him as sysadmin to monitor their own stuff. But not many places are flexible enough for that kind of thinking.

    17. Re:Do we really need a hat? by ealar+dlanvuli · · Score: 2

      You like that nice cheap x86 hardware your using? You ever wonder how IBM ended up with competition in the market of making x86 machines that could run DOS.

      Oh whats that? The bios got cracked. Oh no, you benifit from the fruits of a hacker, shame on you! You should go to jail.

      Some people...

      --
      I live in a giant bucket.
    18. Re:Do we really need a hat? by chris_mahan · · Score: 2, Insightful

      You're right.

      The DMCA is criminalizing the White-ish hat, meaning that if you are not 100% pure cotton white hat then you must be, by law, a rotten, credit-card thieving, hard-drive reformatting, website-defacing, hardcore-porn-trading, no-good, evil, and overall bad person.

      Of course, it's equivalent to saying that people that drive over the speed limit are killers.

      Just because you bend a little stupid and useless law does not make you a hard-core, purse-snatching, nigerian-money-laundering uberhaxor whose handle rhymes with Phuckiaul.

      I say: Hacking is good: It's called creativity, perseverence, and curiosity. Take these things away from society and people become sullen, unimaginative, short-attention-spanned. Which, come to think of it, is exactly what the entertainment industry wants people to be like.

      {voice of irate teacher in pink floyd's The Wall]
      "You will sit on the couch and watch our programming! Any demonstration of self-awareness will be punished! How can you become a couch potato if you don't eat your meat?" Da-dum-dum da-dummmm.

      --

      "Piter, too, is dead."

    19. Re:Do we really need a hat? by ebyrob · · Score: 2

      They could even hire him as sysadmin

      Funny that you mention that. Most actual mis-uses of sensitive information and computer networks come from current or past employees of the company compromised.

      Funny thing is, most companies don't have anything to offer in the way of financial 'secrets' or documents of any worth that are on a network.

      This isn't nearly as true as it used to be, even for the government.

      One of the things Companies will never understand is advice for Free

      IMHO, companies like that deserve to go out of business.

      There's a reason 50% of all employees work for a small business in the US. Some large companies do an ok job of learning from their mistakes and not punishing those wishing to help them (cough*IBM*cough). But if a company thinks they can stay in business just by leveraging their position at the top (cough*Microsoft*cough), they've got another think coming.

      If you can't know your own products well enough to know when something important comes up, and if you aren't willing to learn from your mistakes, I don't think you've got much business in software. (Yes, there is some hope for Microsoft left, but I don't see them properly chasing it just now)

    20. Re:Do we really need a hat? by JUSTONEMORELATTE · · Score: 2
      We don't call burglars black hats and alarm system installers white hats.
      Alarm system installers generally come in, invited, through the front door.
      There are folks who are hired to test phsyical security systems (airport security audits have got a lot of press lately) who make use of the same approach as criminals would. These could well be considered "white hat" professionals.
      Or were you explicitly taking exception to the entire Merlin vs the Evil Sorcerer aspects of the colored hats?
    21. Re:Do we really need a hat? by dwaggie · · Score: 1

      Re:Do we really need a hat? (Score:2)
      by ebyrob on Monday September 23, @04:44PM (#4314352)
      (User #165903 Info | http://slashdot.org/)
      They could even hire him as sysadmin

      Funny that you mention that. Most actual mis-uses of sensitive information and computer networks come from current or past employees of the company compromised.

      Funny thing is, most companies don't have anything to offer in the way of financial 'secrets' or documents of any worth that are on a network.

      This isn't nearly as true as it used to be, even for the government.


      What I meant by that was that often times, employees will mistrust the network, and do things on a local machine rather than keeping backups updated regularly on the network. Having had experience working with a company within a larger company (a franchise that was umbilically connected, metaphorically speaking), Finance had to regularly update their files, but never kept any files on the network that they had to work with regularly, simply because of complaints of slow network and/or some downtime that caused a mistrust.

      The thing about large companies, however, is momentum .. the bigger you are, the harder it is to stand on a dime with your policies and products.. mainly because you already have a production schema and 15 leagues of red tape to change one part of it.

      At least, that's how I've seen it. Small businesses are MUCH more flexible.

      And, yes, I would agree that almost all misuses of company resources are usually done by former employees. Heck, I still have an admin e-mail account at a company I haven't worked for for 3 years, simply because they have transitioned through three different kinds of databases and the original one used child accounts, and one of the merges cut off children accounts... so the account is on the mail server, spawned by a process long ago, but the account software has no idea it exists. And no new accounts can be added to that software.

      It'd probably still let me log in to the old system, and allow me to do things on the old account database, but they wouldn't propogate those changes, as that system is no longer in use. . . It's a minor thing, but an example of how company mergers can impact security, too, I suppose.

      I digressed a lot, there.

    22. Re:Do we really need a hat? by neuroticia · · Score: 2, Insightful

      Hm. No. I disagree with your analogy (people who drive over the speed limit are killers)--driving over the speed limit, while it doesn't always result in death, is a dangerous activity that could more easily be classified as killing than the majority of gray-hat hacking could be called theivery or even illegal, if it weren't for the DMCA.

      A more appropriate analogy would be "It is illegal to research into, and document the progress of a disease", or "It is illegal to test the security of the locks that the locksmith installs on your door."

      Even 100% cotton white hats check the security of things, and attempt to make sure that they work on their systems--under the DMCA this could be considered attempts at hacking, and thus illegal.

      If the DMCA just made it possible to crack down on "law benders", or "law breakers", I'd be unhappy about the law-bending category, but hey- they're laws. However, the DMCA outlaws things that it should not touch. Things that are beneficial for society, things that keep technology moving forward, and that keep the country's data safe. Gray hat hackers are *NECESSARY*, if only because black hat hackers exist, and at least gray hats are less malignant.

      In a lot of ways, the DMCA is equivilent to the US Gov't outlawing a cure for aids because it caused people to have a cold for a week.

      It's over-reaching, and goes beyond being restrictive--straight into the field of being suffocating and damaging.

      -Sara

    23. Re:Do we really need a hat? by Raichlea · · Score: 1

      I agree with you, but I feel that for liability reasons that a time limit should be set. I think that a hacker should be protected from prosecution if he alerts the company to a security flaw and no action has been taken in 2 weeks.

    24. Re:Do we really need a hat? by chris_mahan · · Score: 1

      The police cars can exceed the speed limit in an attempt to catch someone who is exceeding the speed limit.

      --

      "Piter, too, is dead."

    25. Re:Do we really need a hat? by Anonymous Coward · · Score: 0
      Pretty simple, and none of this hat confusion.

      Yes, a simle solution for a simple mind. Ab hoste doceri.

    26. Re:Do we really need a hat? by Anonymous Coward · · Score: 0
      Hm. No. I disagree with your analogy (people who drive over the speed limit are killers)--driving over the speed limit, while it doesn't always result in death, is a dangerous activity that could more easily be classified as killing than the majority of gray-hat hacking could be called theivery or even illegal, if it weren't for the DMCA.

      You fucking namby-pamby bedwetter.

    27. Re:Do we really need a hat? by Anonymous Coward · · Score: 0
      The question "Do we really need a hat?" from someone who's blog is at whitehatorganization.com
      Yes, apparently you really need a hat.

      And a brain to go under it. His first blog comment includes "My irritation with the Internet community comes in where, rather than trying to get file sharing legalized (like that's ever going to happen), they try to prevent our government from enforcing the laws that exist." Never mind that the laws were bought and paid for by the **AA. So we should just shut up and knuckle under. Yeah.

      By the way, does anyone else see the vast difference between www.whitehatorganization.com and jason.whitehatorganization.com, and think somethhing is moderately fishy?

    28. Re:Do we really need a hat? by Anonymous Coward · · Score: 0
      (Sometimes a system is so insecure this can happen by accident [zdnet.com.au]. )

      No shit. Some years back, I was checking how many books I had out on our lical library dial-up line. Suddenly, instead of the text screen with options (place hold on book, find library address, etc.), I was presented with a banner from the HP-UX system and a command prompt. Too bad I didn't know what to do with it at the time.

    29. Re:Do we really need a hat? by ebyrob · · Score: 2

      What I meant by that was that often times, employees will mistrust the network, and do things on a local machine rather than keeping backups updated regularly on the network.

      Well... while obscurity helps a bit, disorganization is a poor substitute for security. I should know, it was the predominent method my company used to use!

      Also, keep in mind that computers are getting more reliable, and most mid to large sized companies I've seen lately (okay a lot more mid-sized ie: 100-1000 employees) do have very reliable networks. Once a network works for a year or two without hicups, people start to trust it... Whether it is secure or not.

    30. Re:Do we really need a hat? by ebyrob · · Score: 2

      Too bad I didn't know what to do with it at the time.

      Maybe too good if you enjoy your freedom...

  2. DMCA by Anonymous Coward · · Score: 1, Interesting

    Gone forever are the days when hackers could roam through corporate systems, not really doing any damage, but just playing around.

    *sniff*

    1. Re:DMCA by Golias · · Score: 5, Interesting
      Gone forever are the days when hackers could roam through corporate systems, not really doing any damage, but just playing around.

      One could take that to mean that early "white hat" hackers served their purpose successfully. By roaming through corporate systems, they managed to call attention to a lot of gaping security flaws that ended up getting fixed.

      Also, roaming through corporate streams was a necessity for hard-core geeks in the days when Internet connectivity was prohibitively expensive. Much of what recreational hackers where "borrowing" other people's network resources for can now be done on a common consumer connection.

      --

      Information wants to be anthropomorphized.

    2. Re:DMCA by TheOste · · Score: 5, Insightful

      The days aren't gone, but now we must use techniques that will keep all of our tracks hidden.

      One of the largest holes that I currently see is the lack of any security on all of the wireless networks! You can load a machine up and use a card with a MAC address that you use for nothing but hacking and NEVER be caught. The good ole days aren't gone, but the good ole days are here right now. UNTRACEABLE baby, with COTS equipment at that. From my house with a 24db antenna I can see ten networks that are not encrypted. I was thretened with a lawsuit recently when I informed a company of an unencrpted network that I found while driving to my house, I will never do that again, but now I will keep them to myself just incase I want to do some "gray" actions. Don't get me wrong, I don't go around destroying networks, but with wireless in the state that it is in today, I could definately do that.

      Cheers

    3. Re:DMCA by Anonymous Coward · · Score: 0

      Yes. Gone are the days where you could walk through someone's private home, looking in drawers - just out of curiosity, and then get away with it. Today they have burglar alarms.

    4. Re:DMCA by GlassUser · · Score: 2
      I was thretened with a lawsuit recently when I informed a company of an unencrpted network that I found while driving to my house

      "Get your network out of my airspace or I will sue you for trespass."
    5. Re:DMCA by rawsocket · · Score: 1

      Yeah..everyone $old out. I must admit, a lot of hackers that I thought were hackers turned out to be a bunch of money hungry sell outs that simply go around lying about computer security to suck the dollars out of peopes pockets. Only real hackers are in open source.

    6. Re:DMCA by Anonymous Coward · · Score: 0

      "to call attention to a lot of gaping"

      Like this?

    7. Re:DMCA by Anonymous Coward · · Score: 0

      One could take that to mean that early "white hat" hackers served their purpose successfully. By roaming through corporate systems, they managed to call attention to a lot of gaping security flaws that ended up getting fixed.

      If only that were true. Instead we just got laws passed leaving the flaws gaping away and even opening up new ones. Why is it that given a choice, most people will choose to put their faith in the laws of man instead of the laws of nature? How many times do people like Newt Gingrich have to be bitten by their own ostrich head-in-the-sand legislation before they figure out that the laws of man are merely deterrants and not prevention - especially when the stakes are high?

    8. Re:DMCA by sdowney · · Score: 1

      Tell them that their wireless access point attempted to gain unauthorized access to your computer network.

  3. From the so-stupid-it-may-just-be-legal dept by MalleusEBHC · · Score: 0, Offtopic

    Finisterre--who also goes by "dotslash"
    Hey Taco, you better go after this copyright infringer! You can sick the DMCA... uhh or... the RIAA... uh or... well that's gotta be an acronym to help prosecute him.

    1. Re:From the so-stupid-it-may-just-be-legal dept by anonymous_wombat · · Score: 1, Offtopic
      The Simpsons is the culmination of Western civilization. It's all downhill once they go off the air.

      What about Futurama?

    2. Re:From the so-stupid-it-may-just-be-legal dept by ebyrob · · Score: 2

      Like he said... down hill.

  4. Cracker by SquadBoy · · Score: 3, Insightful

    You mean Cracker. While some of these people might be hackers I can't think too many of them are. Please I know everyone else uses the term hacker in this way. But can't we use the real term?

    --

    Cypherpunks: Civil Liberty Through Complex Mathematics. Those who live by the sword die by the arrow.
    1. Re:Cracker by MalleusEBHC · · Score: 2

      When I first read the blurb without reading the whole story, I was thinking to myself, "So do kernel hackers fall under the grey hat?"

      These writers really need a geek consultant to get their terminology correct.

    2. Re:Cracker by Hallow · · Score: 2

      The problem is the general populace doesn't know enough to make a distinction between hacker and cracker. They hear one news report that says hacker == bad, and it has a negative connotation forever with these people.

      There's also the problem of the use of cracker as a racial slur in the south.

    3. Re:Cracker by RevDobbs · · Score: 1
      You mean Cracker. While some of these people might be hackers I can't think too many of them are.

      But why do you assume that they're white guys?

    4. Re:Cracker by kaaphi · · Score: 1

      There is no distinction between the terms "hacker" and "cracker" anymore. Hacker means what the general population thinks it means. Face it: language changes and evolves. This is just another example of that evolution.

      --
      [paok]
    5. Re:Cracker by Richard_at_work · · Score: 1, Flamebait

      Oh come on, the meaning of the term has changed, accept it. Language does this sometimes, people change the meaning of words, and it becomes accepted by the majority, jsut like words such as "gay" and "queer" (no, sorry im not picking on homosexuals, but those two words jsut spring to mind).

      I program, and i call myself a coder, not a hacker. I alter stuff and call myself a modder, not a hacker. I break into systems, i call myself a hacker.

    6. Re:Cracker by Anonymous Coward · · Score: 0

      they're white guys

      from Georgia

    7. Re:Cracker by milkman_matt · · Score: 1

      The problem is the general populace doesn't know enough to make a distinction between hacker and cracker. They hear one news report that says hacker == bad, and it has a negative connotation forever with these people.

      Yeah, but if nobody corrects them, they'll think of hacker as the correct term.. if we correct them, then they learn, then they correct their friends who use the wrong term, who in turn tell their friends... eventually, everyone's on the right track.. (and yeah, that's probably terribly optimistic) but if you don't correct people, nobody learns, and we move backwords. -matt

    8. Re:Cracker by Hallow · · Score: 2

      It doesn't matter if you correct them or not. You would have to send them to a re-education camp and put them through some massive clockwork orange style classical conditioning for them to be able to tell the difference. People are dumb.

    9. Re:Cracker by red_dragon · · Score: 3, Funny

      Well, there's The Jargon File, a.k.a. The New Hacker's Dictionary, which the writers could presumably consult whenever they write anything with a geek factor greater than 0. However, even The File's contents can be tough to grok by non-geeks, so I've decided to condense it into a form more easily digested by non-geeks:

      Hacker good, cracker bad!

      Hopefully they'll get that one.

      (I make no warranty of accuracy of my statements.)

      --
      In Soviet Russia, Jesus asks: "What Would You Do?"
    10. Re:Cracker by gosand · · Score: 2, Informative
      There is no distinction between the terms "hacker" and "cracker" anymore. Hacker means what the general population thinks it means. Face it: language changes and evolves. This is just another example of that evolution.

      This may be true, but I refuse to use the term incorrectly when I know better. Please read the following. I did not write it, it is from someone on a mailing list, when someone misused the term "hacker", then argued that it was the accepted use of the word. The author puts it better than I ever could. (you can view the original post to the list here

      -------

      If you haven't already, read Orwell's "1984".

      The use of words is absolutey critical, and using language for social engineering by governments, churches, and corporations is not the stuff of science fiction ... just ask anyone who works in marketing. It happens every day, and the deleterious effects on our society and our world which result are trivial to see. (ponder the definition of the word 'terrorist' and how fluid it has become, and the real, physical consiquences which are apparent and resulting in no small part from the misuse and mutation of that word)

      Now think to yourself: Who owns the rights to every dictionary in circulation (Merriem-Webster, Oxford, what have you)?

      That's right, the publishers. Organizations that have been members of the copyright cartel since the sixteenth century, a cartel which in its history had at least one person drawn and quartered for possessing a printing press and not being a member of the cartel.

      With respect to the word 'hacker' it is highly debatable whether the misuse of the term was deliberately and knowingly inserted into the dictionary as a form of semantic engineering, or whether the publishers simply picked up on the misuse of the term being promoted and propogated by another copyright cartel: the entertainment cartel.

      The same applies to the word 'piracy,' though poking through some very early dictionaries certainly suggests its definition was changed as part of a conscious effort at semantic engineering (the incorrect, propoganda definition of the word equating copyright violators with rapists, pillagers, and murderers on the high seas was in at least one dictionary long before misuse of the word had become widespread).

      What is known for certain is that, for other words of political significance, dictionaries have been known to publich definitions adhering to one political agenda or another PRIOR to their widespread use in language. The "authority" of the dictionary has been used, more than once, to deliberately modify and change the use of language to promote a political agenda.

      If you're really interested in such things, look up the history of the usage of the word 'he' and 'his' as a gender-neutral or gender-indeterminate pronoun. In the United States, the use of 'they' and 'their' (singular) was in widespread use around the turn of the 20th century. Grammaticians displaced that, deliberately, with 'he' and 'his'. One of the comments made by one of these early 'semantic engineers' was something to the effect of "as in nature, when there is a choice, the male pronoune shall dominate." It is only in recent years that the use of 'they' and 'their' (singular) as a gender-neutral pronoun has come back into use, despite the linguistic orthodoxy to the contrary.

      There are other examples, indeed a plethora of them from the cold war and even the war on drugs.

      In other words, blind faith in the dictionary is as misplaced as blind faith in anything else (e.g. religion, government, or McDonald's). The publishers have as many ulterior motives, and as unreliable ethics in persuing those motives, as every other industry has come to have.

      You misused the word 'hacker' on a mailing list of people who know better. You were corrected, you have been educated, and your response is to call everyone a hypocrit.

      A community of hackers, in the old and august meaning of the word, is not at all hypocrictical for being annoyed with you for misusing the term and equating them to a bunch of petty criminals, any more than a person of a particular ethnicity, who stands for freedom, is a hypocrit for being angry when another group deliberately denigrates them. Or, put another way, fighting speech with speech is not the same as advocating censorship, and you should recognize the difference.

      Frankly, you should drop the attitude, admit you made a mistake, and move on. Everyone makes mistakes ... that is part of life. Clinging to them out of stubbornness, however, is just silly.

      --------

      --

      My beliefs do not require that you agree with them.

    11. Re:Cracker by MrResistor · · Score: 2

      I was about to mod this down, but I decided that it would be better to respond.

      The "real term" is hacker, not cracker. Why? Because that's what the majority of the english speaking population says it is. Get used to it, because unless you can convince Joe Sixpack and his favorite news anchor otherwise, that's the way it's going to stay.

      You'd need to find another term anyway; cracker already has a commonly accepted meaning when it's applied to a person, and it has nothing to do with computers.

      --
      Under capitalism man exploits man. Under communism it's the other way around.
    12. Re:Cracker by Anonymous Coward · · Score: 0

      Labels labels labels. I'm glad you like to attach them to yourself.

    13. Re:Cracker by TKinias · · Score: 1

      MrResistor wrote:

      The "real term" is hacker, not cracker. Why? Because that's what the majority of the english speaking population says it is. Get used to it, because unless you can convince Joe Sixpack and his favorite news anchor otherwise, that's the way it's going to stay.

      I hear what you're saying (erm, read what you're writing?), but I can't agree.

      If the mass media made no distinction between the terms `paedophile' and `homosexual', would that be reason to give up and say ``the `real term' is `homosexual', not `paedophile'''? This isn't a totally far-fetched concept; there are people who really believe that all gay men prey on adolescent boys. So, if the media simply referred to paedophiles as `homosexuals', making no effort to distinguish criminal behaviour from the private acts of consenting adults, that would be OK, in the interest of not confusing Joe Sixpack who thinks there's no difference?

      --
      In principio creauit Linus Linucem.
    14. Re:Cracker by Sneftel · · Score: 1

      The mass media tends to reflect common usage. If MSNBCBS started using "homosexual" to mean "paedophile" tomorrow, they'd just end up confusing everybody. Language changes slowly and nondeliberately; the media actually has relatively little sway. And if they were using it to reflect common usage, then in that scenario it'd be too late anyway.

      Moreover, the mass media really has no vested interest here. If the NY Times (registration required) wants to sell papers, they'd damn well better make that headline "HACKER SABOTAGES DEFENSE THINGIES". "CRACKER SABOTAGES DEFENSE THINGIES" wouldn't play to common usage, and would furthermore be somewhat misleading if run next to a picture of John Ashcroft.

      --
      The opinions stated herein do not necessarily represent those of anybody at all. Deal with it.
    15. Re:Cracker by Anonymous Coward · · Score: 0

      A few factual points:

      Both usages of the word "hacker" are 'old and august'.

      However, the 'bad' version was pretty much a MIT regionalism until Steven Levy published the book "Hackers" and ESR modified the jargon file in the 1980s. By then the 'bad' definition was already in nation-wise usage. We don't elevate every Bostonian mis-use of the language to official status, and "hacker" is no exception.

      People who break into computer systems often identify themselves as "hackers". The politically correct thing to do is to allow them to self-identify.

      Even the positive defintion of "hacker" is considered a negative trait in many, if not most commercial development environments.

      "Cracker" is racist slang in parts of the US, and therefore an unacceptable alternative for mainstream press reporting.

      Also, the usage of "piracy" to mean copyright infringement is several hundred years old.

      In short, many of us on this "mailing list" are educated in the matter, probably more so than you, and still disagree with the ESR zombies on this point. Trying to call a honest disagreement about language usage "a mistake" is the sign of a very small pre-programmed mind.

      Hope you feel educated after reading this.

    16. Re:Cracker by Anonymous Coward · · Score: 0

      No you are wrong, give it up! Crackers are whities. Hackers break into computers.

    17. Re:Cracker by MrResistor · · Score: 2

      If the mass media made no distinction between the terms `paedophile' and `homosexual', would that be reason to give up and say ``the `real term' is `homosexual', not `paedophile'''

      I understand what you're trying to say, but you use a very poor example. 'Pedophile' and 'homosexual' are both made up of Greek/Latin roots whose definitions have been set for centuries, even millenia, and are widely known. Additionally, the distinction between them is already set in the public consciousness.

      That puts them in a whole different catagory than 'hacker', which has only really been used in the context we are discussing for perhaps 20 or 30 years. In that time the definition has been set in the public consciousness as "someone who knows a lot about computers", generally with a negative connotation. Just because you disagree with that definition, that doesn't make the definition wrong, it makes you wrong.

      It comes down to this: if you don't want to be associated in the public eye with people who break into computer systems with malicious intent, don't call yourself a hacker. Trying to get everyone else to call computer vandals something other than 'hacker' is pointless because that definition is already set, and 'cracker', as I've already pointed out, is already used elsewhere. There are plenty of other words you can use to describe yourself and what you do that don't carry that negative conotation, such as 'coder', 'techie', etc. Use one of them. 'Hacker' is a lost cause.

      --
      Under capitalism man exploits man. Under communism it's the other way around.
    18. Re:Cracker by Rainier+Wolfecastle · · Score: 1

      I think that this is one of the biggest problems when it comes to "hackers." There is no universally-accepted definition for a hacker, which leads to the media calling anyone that knows what TCP/IP is a hacker. You just said, "You mean Cracker.", but there are a lot of hackers that don't like this term either.

      I think that the most important step is making sure we can define the point where someone crosses from hacker to criminal. The rest of the monikers are then basically superfluous.

    19. Re:Cracker by gosand · · Score: 2
      I see. So the meaning of the word hacker can be changed because of popular use, but you cling to the word cracker as racist slang. I see where priorities are.

      And the use of the word hacker was in nation-wide usage in the 1980's? I really really doubt that. If it was in use, it was most certainly underground and not in mainstream media in any great capacity.

      People who break into computer systems often identify themselves as "hackers". The politically correct thing to do is to allow them to self-identify.

      Really? Hmm, I don't know anyone who breaks into computer systems who writes for the NY Times, or the Chicago Tribune, or any other major media outlet. Or are you telling me that all of the stories about "hackers" over the past decade have sources in the illegal hacker community? Interesting. Or maybe just BS. Do you honestly think that people reporting on people who break into computers ask them what they consider themselves to be?

      Gee, so you consider yourself to be more educated about this issue than me, whooptie-do. You seem to be quite pleased to point it out, as an Anonymous Coward. I would think that such an educated person wouldn't stoop to the level of petty insults, no matter how cleverly and intellectually they try to phrase them. There is always going to be someone who is more educated in this or that. But it seems that no matter how smart some people claim to be, they can't resist the urge to act like an asshole.

      Hope you feel educated after reading this.

      Oh yes, great master, your vague references to "factual" events has greatly educated me. May I go now?

      --

      My beliefs do not require that you agree with them.

    20. Re:Cracker by Zebbers · · Score: 1

      the people discovering these exploits are most definitely 'hacker's. Prollly moreso than you.

  5. Dragonlance saga by Dexter77 · · Score: 0, Offtopic


    This must be from those AD&D novels where commoners thought that all magic users were evil regardless whether they used white, red or black robe .

    1. Re:Dragonlance saga by stefanlasiewski · · Score: 2, Insightful

      Dragonlance, heck...

      Reminds me of some primitive societies on our own planet, where they burn witches, medicine-men, doctors, anyone-with-specialized-knowledge-who-challenges-a uthority...

      Smart people, regardless of their intentions, have always been feared...

      --
      "Can of worms? The can is open... the worms are everywhere."
  6. Forget the DMCA... by Spazholio · · Score: 2, Insightful

    What about the new legislation (forget the name) that makes 'hacking' a federal crime, and heavily punishable. I think I remember reading that you can get a life sentence for hacking? What the hell? And I can guarantee you that they're just WAITING for another Kevin to come around so they can make an example of him:

    "See? Look what he did! He 'hacked' into someone's computer, and now he's someone's bitch for life."

    "But he didn't do anything damaging."

    "He was HACKING. That's BAD. He's gone for LIFE. Let that be a lesson."

    The lesson is that curiousity is now punishable by life in prison. Great. Don't get me wrong, traipsing into someone's computer isn't exactly ethically RIGHT (I don't care HOW wide open they leave it), but it's certainly not criminally WRONG.

    1. Re:Forget the DMCA... by Anonymous Coward · · Score: 0

      Yes, it is criminally wrong.

      Or would you insist that someone breaking and entering into your home is just 'not quite ethically right'?

      Computer = Property.

      Infiltrating someone else's property without their permission = Criminally wrong.

      (That said, if you commit one crime this year, go murder someone. You'll get a shorter sentence than if you just rooted their box.)

    2. Re:Forget the DMCA... by netphilter · · Score: 4, Insightful

      traipsing into someone's computer isn't exactly ethically RIGHT
      I was under the impression that right and wrong were mutually exclusive. If it's not right then it has to be wrong. If you "traipse" into my computer you will go to jail. Pretty simple. Should I be able to pop the hood on your car if it's in the parking lot of Wal-Mart because I'm curious as to how your car is different from mine. What about your house? I'm interested in the architectural differences between our houses, so I break into your house because of my "curiosity." Please try to refrain from ridiculousness in the future.

      --
      "Herbivores eat well cause their food never, ever runs."
    3. Re:Forget the DMCA... by GlassUser · · Score: 4, Insightful

      Well, if you leave your car's hood propped open, with a flashing blue light on top of it. Or if you prominently display your house with open doors (commonly known as an "open house", at least in america, they're kept near the entrance to new neighborhoods, specifically so people can come in and examine the workmanship and . . . architecture).

    4. Re:Forget the DMCA... by Nazmun · · Score: 1

      He truly isn't that ridiculous. But the real question is... Would someone get life in prison for popping your hood and checking what's underneath it? I'm sure you could end up with some jail time but not nearly as much as for hacking. Same thing with the house... (But it is a little different, breaking into your computer is not really breaking something but finding an open door and going through it). Once again, all of these things are ethically wrong in our society BUT punishments shouldn't be cruel and unusual. I don't see any reason for someone getting more then a month of jail time (maybe even less) for doing some hacking. BUT this is only when the hacker causes zero damage (not including mental shock or any of that BS) or doesn't steal anything.

      --
      Hmmm... Pie...
    5. Re:Forget the DMCA... by Flamerule · · Score: 2, Insightful
      I was under the impression that right and wrong were mutually exclusive.
      Is abortion right, or wrong?
      Should I be able to pop the hood on your car if it's in the parking lot of Wal-Mart because I'm curious as to how your car is different from mine.
      If you don't fuck anything up, no harm was done, regardless of whether your actions were illegal.

      An example more salient to this discussion: if your hood was open, and your windows were down, and your doors were open, etc., would you seriously expect your car to be untouched after you got out of Wal-Mart?

    6. Re:Forget the DMCA... by comic-not · · Score: 1
      I was under the impression that right and wrong were mutually exclusive. If it's not right then it has to be wrong.

      One man's right is another's wrong. Why else would we vote on things? I find it funny that some people seem to be uncomfortable with the idea that most things are much more complicated than the black-and-white ethics of (cheap) children's cartoons.

      Comic-not

      --
      Existence usually comes as a surprise (Idem)
    7. Re:Forget the DMCA... by geekoid · · Score: 2

      Is it really that simple?
      What is I am unknowingly in your computer because someone else is routing through a hole in your system? or is storing images on your system that are linked to a different site? Is requesting something from your computer wrong?
      It's not wrong for met to go to your door and request to borrow a cup of sugar from you, nor it it wrong for me to equeste a ride from you.
      This is why there is such confusion with computeres, so many different analogies can be made to prove any side of any argument. Computer really need more concrete examples that belong to them.
      Todays, computer are designed to share informatiuon, the internet is designed to share information.
      Really, we need to accept that, and focus on good security mothodologies and technology implimentation in all products.
      Gone are the days when computers where isolated machines. It seems obvious, but people can't seem to get that through there heads.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    8. Re:Forget the DMCA... by Anonymous Coward · · Score: 0

      You just don't hear about the people getting arrested for it. They're all pasty face living-in-the-basement geeks without friends to miss them. Ashcroft has them all locked up down in Cuba. That's why they're all wearing hoods so you can't see thier faces.

    9. Re:Forget the DMCA... by Zathrus · · Score: 2

      If it's not right then it has to be wrong

      Yes, and if it's not in light then it must be in darkness, right?

      I won't even go into the myriad of ideas or situations that exist in the grey area between right and wrong.

      If you "traipse" into my computer you will go to jail. Pretty simple.

      Ok, so what if I find a backdoor onto my own computer? Should I report it to the company? If I do and they do nothing to fix it what then?

      This shouldn't be hard for you to answer. After all, by your own statement there's one right answer and everything else is wrong.

    10. Re:Forget the DMCA... by klaviman · · Score: 0, Interesting
      Is abortion right, or wrong?

      it's wrong.

      An example more salient to this discussion: if your hood was open, and your windows were down, and your doors were open, etc., would you seriously expect your car to be untouched after you got out of Wal-Mart?

      you should always plan for the worst and hope for the best. but regardless of your actions (leaving car windows down) it's still wrong to reach in and start screwing around with stuff.

    11. Re:Forget the DMCA... by netphilter · · Score: 1

      I'm not against responsible disclosure, and I'm certainly not trying to appear to be defending the DMCA. I'm simply saying that I think the lines should be much less blurry than they currently are. It shouldn't be considered ok to invade someone else's computer as long as there's "no harm done."

      --
      "Herbivores eat well cause their food never, ever runs."
    12. Re:Forget the DMCA... by Anonymous Coward · · Score: 0

      If it's not right then it has to be wrong.
      Is this table right? No.
      Therefore, this table must be wrong.

      go read some books and learn not to say things so obviously incorrect.

    13. Re:Forget the DMCA... by SN74S181 · · Score: 1

      Ok, so what if I find a backdoor onto my own computer? Should I report it to the company? If I do and they do nothing to fix it what then?


      Then a question arises about wether the company is at fault. It has nothing to do with wether someone intrudes into your computer through that 'backdoor' or not. If they do so, without your approval, they have done something wrong.
    14. Re:Forget the DMCA... by Anonymous Coward · · Score: 0
      Is abortion right, or wrong?

      it's wrong.

      Congrats on totally missing the point. Your reply here was not completely worthless though. Now at least we know we're dealing with a self-centered, closed-minded individual. There is no gray area for you... congrats, now let the people who actually want to SOLVE problems (instead of judge them) talk this over.
    15. Re:Forget the DMCA... by cmstremi · · Score: 1

      And they used to burn women at the stake for being witches. Fear of the unknown, man. It makes politicians do irrational things.

    16. Re:Forget the DMCA... by Quixadhal · · Score: 5, Insightful

      Right and Wrong are only mutually exclusive in today's simplistic binary computers, and the minds of some simplistic people.

      Should you be able to pop the hood on my car in the Wal-Mart parking lot to see how my car is different than yours? No.

      Should you be able to pop the hood on my car to extinguish a fire in the engine compartment and keep it from destroying the vehicle, anything in it, and probably the vehicles on either side? Yes, please do!

      But... you still "broke into" my car. Do you want to go to prison and enjoy the tender thrusts of Bubba for your good deed?

      If you have an ftp server running on your machine, and I happen to notice it, I feel perfectly justified in connecting to that server. If it allows anonymous logins, I feel fine looking around. If not, I won't sit there and try to guess passwords, as that *would* be wrong.

      Yet, if after logging in as an anonymous user, I manage to get access to your filesystem, I would feel obliged to leave you a note, telling you that maybe / isn't the best anonymous ftp root. Would you send me to prison for that? If so, I'd suggest you seek counseling, since you obviously have some personal insecurities and ego problems beyond your server.

      The DMCA is an abomination. It creates a situation where one can be punished without actually doing anything beyond research. How many people who just happen to own Sharpies bought them with the criminal intent of listening to protected music CD's? Most of my sharpies pre-date the DMCA, yet I am technically a criminal because they COULD be used to circumvent copy-protection??? All of you out there who have screwdrivers -- you can use those to unscrew poorly secured locks. There, now I'm in trouble for disseminating information about circumvention, and you're all screwed for having the tools. Go Law!

    17. Re:Forget the DMCA... by morgajel · · Score: 1

      if you leave the hood up on a 1969 Nova in mint condition in a walmart parking lot, you can bet your ass every mechanic within 5 miles will be sitting there staring at it.
      they won't touch anything because they don't want to break anything, but you can bet they'll be checking it out. granted, there might be some jerky that comes around with a crowbar and breaks it, but you gotta differenciate between that and gawking.

      --
      Looking for Book Reviews? Check out Literary Escapism.
    18. Re:Forget the DMCA... by polin8 · · Score: 2, Insightful

      even more apropriate: if your hood was open, and your windows were down, and your doors were open, etc., would you not want someone(wh) to come into wallmart and warn you before someone else(bh) took your car and ran over grandma?

    19. Re:Forget the DMCA... by Anonymous Coward · · Score: 0

      The law officials dont even give a shit about joe blow's compaq running windows me at his house getting a cracked.
      They care about people breaking into computers like gary7.nsa.gov, I mean take a look at jpl.nasa.gov.. they have every possible daemon running and wide open to the public including fingerd. You try to call them up or e-mail them informing them of their lack of security and see how long it is before your internet connection is shut off and you're being raided by the fbi and labeled as a terrorist.

    20. Re:Forget the DMCA... by MindStalker · · Score: 1

      Its more simular to trespassing laws. If you make your entrance known and stay on the well placed path, your alright, but get distracted by the pretty flowers, and go and step on the grass. Your in jail, as a terrorist for life!!!

    21. Re:Forget the DMCA... by photon317 · · Score: 2


      netphilter is right that open doors don't make B&E legal. If you leave your door hanging open, and a robber comes in in the middle of the night, "the door was open" does not work as a defense strategy.

      That being said, the important problem with the new federal hacking bill(s) is the harshess of the punishment. You can spend more time in jail for cracking someone's podunk little website than for rape.

      --
      11*43+456^2
    22. Re:Forget the DMCA... by Anonymous Coward · · Score: 0

      well you don't exactly get put in jail for life for opening up someone's hood in walmart or even for entering their unlocked house. I would rather have someone take a quick look at my computer and then tell me what is wrong with it rather than someone do the same with my house also.

    23. Re:Forget the DMCA... by amitola · · Score: 2, Insightful
      Should I be able to pop the hood on your car if it's in the parking lot of Wal-Mart because I'm curious as to how your car is different from mine.

      No. Should you get life in the big house if you do that?

      I'm interested in the architectural differences between our houses, so I break into your house because of my "curiosity."

      If you did that, but did not take or break anything, do you think you would get life in prison?

      I was under the impression that right and wrong were mutually exclusive. If it's not right then it has to be wrong.

      This Axis-of-Evil crap, which you are parroting here, is one of the worst abuses that two useless Bush administrations has come up with. Before, it was the War on Drugs, now it's the War on Terrorism. Hey, future presidents! Got some societal ill that's obviously far too complex and pervasive for you to begin to address? Declare war on it!

      The rhetoric has not changed: You are either for us or against us! God bless the USA! (insert patriotic theme a la Animal House.)

      The methodology has not changed: Caught with a couple grams of an herb considered harmful by some? Lose your house, lose your car, do prison time comparable to assault or manslaughter. Caught using or (God forbid) writing a sequence of computer code that an American media corporation finds inconvenient? Lose your house, lose your equipment, and off to the cooler where you can only hope that someone like EFF or the ACLU takes up your case.

      [Y]ou will go to jail. Pretty simple.

      Indeed! As in, simplistic, oversimplified, and simple-minded. Who did more damage to life, liberty and the American Way--Kevin Mitnick or Kenneth Lay?

    24. Re:Forget the DMCA... by Anonymous Coward · · Score: 0

      There should be laws against using God and ACLU in the same sentence...since they are diametrically opposed to one another.

    25. Re:Forget the DMCA... by ebyrob · · Score: 2

      I was under the impression that right and wrong were mutually exclusive.

      So is posting to slashdot on company time "RIGHT"?

    26. Re:Forget the DMCA... by Flavius+Stilicho · · Score: 1

      Come on moderators -- mod this guy up! He's dead on.

    27. Re:Forget the DMCA... by Anonymous Coward · · Score: 0

      And congrats to you on raising to the troll...

    28. Re:Forget the DMCA... by Teknon · · Score: 1

      I know that there are "Good Samritan" laws that protect one while trying to save another. I know that they specificaly apply to health related matters. Depending upon the wording, (and difinatly this is supported by the sprit of the law) poping the hood of a car to extinguish a fire to save the car and those around it could be coverd. If it is, than so is entering a computer system through a hole in the securty to warn, or fix a potentaly hazadous problem.now this is a little streth, but with a good lawyer, this could probably be argued

    29. Re:Forget the DMCA... by MCZapf · · Score: 1

      If you leave your door open and someone comes in, they won't be convicted of "Breaking and Entering." They can just be charged with "Entering" (trespassing?). And if they take something, then maybe theft too. They're all separate, AFAIK. Maybe I got the terms wrong, but I hope my little nitpick is understood.

    30. Re:Forget the DMCA... by Anonymous Coward · · Score: 0

      The analogy you're making is flawed. People don't intentionally display their computers with a "flashing blue light" on them in the security sense; there might be one there, but they may not know that it's turned on. Are they at fault due to their ignorance? Perhaps. But if someone decides to explore their private space, virtual or otherwise, it's no longer their fault..it's criminal action by a third party, and fully deserves jailtime.

    31. Re:Forget the DMCA... by ebyrob · · Score: 2

      It's funny, but it seems many of the "grey areas" exist precisely because so called "white hats" haven't done their job very well. Here's one example.

      It shouldn't be considered ok to invade someone else's computer as long as there's "no harm done."

      Most of the computer profession had been starting to agree with that statement. Unfortuneatly gaining closure requires some compromise from both sides. You see it also isn't RIGHT to create a shoddy piece of software and bill it as "secure and easy to use". Just as it isn't RIGHT to manage a "critical" server so poorly an average 12 year old can break in. Further it's outright WRONG to misuse consumer information or to create and sell spyware to unsuspecting folks.

      Perhaps "grey hats" are merely "white hats" willing to get a bit dirty in order to ensure that others don't stray into even worse colors. I personally applaude the work of bugtraq, @stake and others like them.

    32. Re:Forget the DMCA... by Trepalium · · Score: 1

      I was under the impression that laws for these sorts of things already exist. In cases where there is a loss of life, they should already be able to get you for manslaughter and the original intrusion that caused that. Something that might cause a great chance of loss of life would probably be reckless endangerment or something similar. The additional laws are just silly -- they promote a punishment that is not appropriate for the crime (life sentance), when resonable, time-tested laws already exist outlawing those actions. If there's problems with applying those other laws against people who use computers to commit crimes, the laws should be fixed, not new ones added.

      --
      I used up all my sick days, so I'm calling in dead.
    33. Re:Forget the DMCA... by Romanmir+Cumelon · · Score: 1

      I was under the impression that right and wrong were mutually exclusive. If it's not right then it has to be wrong.

      I wish I lived in a world as black and white as you do. This arguement reminds me of the story in the Bible about Jesus healing a man on the Sabbath.

      Likewise, We live in a legalistic society. Not only ready to pounce on someone if they cross our boundary, but we also expect, nay, demand grace when we ourselves do it. Not to mention the idea that What's good good and right for one person is often times bad and wrong for another. And what about times when something is good and at the same time wrong. I know for my life, that so often what I believe is good is also almost as often wrong for my life. (I would love to do nothing more than play video games all day long, but I konw that this would be wrong for my life and goals.)

      So, often times, the ideas that mankind has of right and wrong are so intertwined that it's really no wonder that this country is as bad off as it is.

      --
      I can't believe you cited Total Recall as a reliable source of science. I just. Wow. I'm flabbergasted.
    34. Re:Forget the DMCA... by dogfart · · Score: 1
      netphilter is right that open doors don't make B&E legal. If you leave your door hanging open, and a robber comes in in the middle of the night, "the door was open" does not work as a defense strategy.

      Though it DOES make a great deal of difference to your insurance company. Which is why all cars for which theft claims are filed have always been diligenty locked.

      --

      "dope will get you through times of no money better than money will get you through times of no dope"

    35. Re:Forget the DMCA... by dogfart · · Score: 1
      Right and wrong depend on the context in which the action occurs, and whether the "recipient" of the action has reason to believe the purpetrator is acting maliciously, benevolently, or with neutral intent. For example:

      Should you be able to pop the hood on my car in the Wal-Mart parking lot to see how my car is different than yours?

      Did you ask first? Do I know you and know your intent is harmless? If I brought my car in for unrelated servicing (tire change, etc.), and you are a mechanic, could you do this? Are you a valet to whom I have entrusted the car for secure parking (in which case it would be inappropriate and you wouldn't get a tip but I certainly wouldn't have you arrested)?

      This is what makes the difference and is why the blanket rules against grey-hat hacking are wrong.

      A blanket rule "never look under the hood" might mean there was something wrong with the car that the manufacturer didn't want you to know. Not allowing individuals with harmless intent to examine something indicates something else is wrong and maybe the provider of the goods doesn't want you to find it out.

      Would I trust the manufacturer of a car that takes people to court for examining flaws in the engine without THEIR authorization? No way!

      --

      "dope will get you through times of no money better than money will get you through times of no dope"

    36. Re:Forget the DMCA... by PhxBlue · · Score: 1

      All of you out there who have screwdrivers -- you can use those to unscrew poorly secured locks. There, now I'm in trouble for disseminating information about circumvention, and you're all screwed for having the tools.

      Pun intended. . ?

      --
      !#@%*)anks for hanging up the phone, dear.
  7. gray/grey hats by cetan · · Score: 4, Insightful
    It's a bit ironic that the c|net article tried to put such a boundry around so-called "gray-hat" hacking. I'm sure there's a number of "gray hats" that don't release the info about a security problem until after a suitable time period has passed and the company has either not responded or is not being speedy enough in issuing a patch.


    It seems to me that giving companies time to fix their holes is always a Good Thing (tm) but that a lack of public disclosure by a 3rd-party will only help obscure legitimate problems. People with the attitudes similar to that of Peter Lindstrom* demonstrate, to me at least, a lack of care towards users and their potentialy open/vulnerable systems. One of the easiest ways to get a slow company to fix something seems to be to talk about it in the press.


    * quote: ("If you are gray, you are black," Lindstrom said. "It's not that I don't understand what they are trying to do, but it comes down to what you are actually doing.)

    --
    In Soviet Russia...michael would be rotting in Siberia!
    1. Re:gray/grey hats by DustMagnet · · Score: 2
      I'm sure there's a number of "gray hats" that don't release the info about a security problem until after a suitable time period has passed and the company has either not responded or is not being speedy enough in issuing a patch.

      Actually, they consider them white hats (as do I). In the side bar for white hats read:

      Information handling: Works with software companies to resolve vulnerabilities; won't announce vulnerabilities until company is ready or found to be unresponsive.

      Typos are mine. The source is a gif.

      --
      'SBEMAIL!' is better than a goat!!
  8. Never understimate a suit's fear. by raehl · · Score: 3, Insightful
    Suits are scared of the public knowing about holes in their product, because that could erode trust in the product. That's the short term vision that motivates suit fear, and causes them to lash out with threats of lawsuits.

    Unfortunately, this fear overwhelms the suit's intelligence, which would tell the suit that in the long term, a climate where disclosing holes is discouraged merely limits access to the information to the so-called "black hats".

    Obviously, an environment where most of the flaws and holes are only known by the less scrupulous because you'd lawsuit-threatened the scrupulous out of finding the holes and telling you about them just makes it that much easier for your programs to be hacked and your customer's data to be stolen - and then they definitely won't trust your product.

    1. Re:Never understimate a suit's fear. by atomico · · Score: 1

      ... the short term vision that motivates suit fear...

      My God! A suit motivated by anything short term!

    2. Re:Never understimate a suit's fear. by Blue+Stone · · Score: 1

      Maybe what is needed is a positive enviroment where a security weakness revelation can be seen clearly to be a good thing, by the people who use the product, and the people who make it.

      I see plenty of "negative" reports of "this, that or whatever," discovered to have another security flaw, as if that revelation were a bad thing. Every tech news source seems to portray them as such

      If you could present these disclosures in an intellectually/philosphically "positive" light, I think the fears of these law-suit happy people might go away.

      I can't think of a way to do it, but maybe some advertising people could (they've got to have some use.)

      --
      Corporation, n. An ingenious device for obtaining individual profit without individual responsibility. - Ambrose Bierce
  9. Just wait until paladium by Billly+Gates · · Score: 0, Troll
    Just blacks and grays as far as the eye can see, petitioning in front of the Santa Clara court house where Linus is being jailed, while their linux jobs are being replaced with MCSE's due to redhat falling under and shacking confidence in this "has been former" os rather then for any technical reasons. All thanks to one critical bussiness decision. Use palladium or else....


    Amazing what power this new technology has in combination with the dmca. Linux may seriously become the next os/2 or minux. Sadly I am serious too. Linux will be a small nitch of hobbiest for macs and nothing else. I said something here 2 years ago. Never and I mean never underestimate Microsoft! Everyone who has, has been stomped on or crushed. Their bussiness model couldn't compete with oss so they are now using a legal model to squash us. Its perfect agaisnt individuals who do not have the finiancial power to defend themselves in court.

    1. Re:Just wait until paladium by Anonymous Coward · · Score: 0

      I seriously doubt anyone has underestimated them. They simply haven't been able to defeat them -- yet.

    2. Re:Just wait until paladium by Anonymous Coward · · Score: 0

      Just blacks and grays as far as the eye can see, petitioning in front of the Santa Clara court house where Linus is being jailed, while their linux jobs are being replaced with MCSE's due to redhat falling under and shacking confidence in this "has been former" os rather then for any technical reasons. All thanks to one critical bussiness decision. Use palladium or else....

      I can just imagine the stench.

  10. None of the above by rppp01 · · Score: 1

    I prefer a red hat. I gives me the right to bash and kill as I please. Course then I must be the root of all evil. So, I must be in alliance with the black hatters.

    --
    They stuck me in an institution, said it was the only solution, to...protect me from the enemy, myself
  11. There's no such thing as a whitehat by Anonymous Coward · · Score: 1, Insightful

    These so-claimed whitehats happily search for vulnerabilities and post them to bugtraq, only to know that someone will code an exploit for it... IF you don't want to cause any damage, you only inform the vendor, not the entire community about it.

    1. Re:There's no such thing as a whitehat by Anonymous Coward · · Score: 0

      Yes, because the people who actually own the vulnerable systems don't have any right to know they're vulnerable and potentially already compromised. Riiiight.. [sighs]

    2. Re:There's no such thing as a whitehat by N3WBI3 · · Score: 2
      Security through collective ignorence?? How long was M$ saying there was not blue screen of death in NT? If you dont publically say what is wrong a company wont fix it.

      That being said I do thing ou give the comapny a little notice (at most 5 days) before you release it..

      --
    3. Re:There's no such thing as a whitehat by geekoid · · Score: 2

      5 days ought to be enough time for them to get a court order telling you to keep your yap shut, and they still won't fix the problem.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    4. Re:There's no such thing as a whitehat by daveoj · · Score: 1

      Usual practice is to inform the vendor first and give them *reasonable* time to form a response... THEN go to Bugtraq with the information.

    5. Re:There's no such thing as a whitehat by Ziviyr · · Score: 1

      Need a delayed publication mechanism. Yap is shut, and the cat is already outside.

      --

      Someone set us up the bomb, so shine we are!
  12. Does anyone know why children are invovled? by Anonymous Coward · · Score: 0
  13. What's that got to do with Copyright protection? by Anonymous Coward · · Score: 0
    due to the DMCA hindering anything in between..

    What's that got to do with Copyright protection?

  14. This article starts with a poor example by GuyMannDude · · Score: 5, Insightful

    Facter writes "There is a great article at CNet..." but I wasn't so impressed. This example of Kevin Finisterre isn't really that amazing. Finisterre's employee publically disclosed the vulnerability. You gotta expect to piss off HP when you do something like that. Look, I'm a fan of open-source software and I understand that publically disclosing software bugs is one way of motivating a lazy company to plug those holes but I'm not sure you can really defend this ethically. If you find a bug in Company A's software, then let A know about it. If A decides not to do anything about it (or if they are taking longer to plug the hole than you thought) I don't see how you are morally justified in leaking that info to the world.

    Finisterre, who was not hired by HP, now says he'll think twice before voluntarily informing another company of any security holes he finds.

    This is just silly. If he had just informed HP, there wouldn't have been a problem. However, his employee decided to inform the entire world and that's what triggered HP's retalliation. If Finisterre and his employees restrict themselves to informing the company, they should be okay.

    The rest of the CNET article is okay. But starting off with such a stupid example really weakens the story. They could have started off this story with the Sklyarov example. That would make a stronger case for the idiocy of the DMCA.

    GMD

    1. Re:This article starts with a poor example by geekoid · · Score: 4, Insightful

      So companies have the right to prevent my freedom of speech?
      If I find a hole, I shoule be able to tell anybody I want about it, because it is speech.

      If I found a hole in a major software product that could be damaging, would I tell the company first? Yes, because I believe that would be the moral thing to do, but freedom of speech is not about morals, its about being able to say/write what I want to, even if it is not what society, or an individule, or a corporation, think is moral or right.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    2. Re:This article starts with a poor example by 56ker · · Score: 0

      If it was Microsoft and millions of computers were inherently at risk - would you feel the same way? Sometimes publicly stating a security flaw is the only way to get companies to fix things quickly! It effectively forces their hand into bringing out a fix unless they wish to endure bad PR or have some decent explanation as to why they can't fix it quickly.

    3. Re:This article starts with a poor example by Thomas+A.+Anderson · · Score: 2

      If you find a bug in Company A's software, then let A know about it. If A decides not to do anything about it (or if they are taking longer to plug the hole than you thought) I don't see how you are morally justified in leaking that info to the world.

      Wrong!! Read the above staement again. Still wrong.

      Bugs and exploits make us (as users of the software) vulnerable - and because the software is question (HPunix) is closed source, we are dependant on the software maker to fix these exploits. If they choose to not do so, or take their time, the we are obligated to ourselves and other users of the software to push the issue.

      Any eula or law that prevents this is flawed and needs too die (die! die!).

      Now, the Finisterre story may still not have been the best argument - the article does say that HP was creating a patch - but no mention of how long it too them.

      just my opinionated 2 cents...

      --
      Personally its not God I dislike, its his fan club I cant stand (bash.org)
    4. Re:This article starts with a poor example by Dephex+Twin · · Score: 1

      Nobody's talking about restricting freedom of speech. I don't think the original comment was trying to say that it should be illegal to publicly announce a hole you've found. You can tell the company or make it public, but don't expect the company to be so appreciative if you do the latter. Sounds reasonable to me.

      --

      If you want to make an apple pie from scratch, you must first create the universe. -- Carl Sagan
    5. Re:This article starts with a poor example by Kilmor · · Score: 2, Insightful

      What if this was ANYTHING other than the software industry?
      What if HP made the car you drive your family around in?

      Of course we should TRUST the corporations to fix all the problems with their products. Why wouldnt they? And of course dont let the public know that new car SuperFastExpensive SUV can explode if hit at the right spot, why should they know about that???

    6. Re:This article starts with a poor example by GuyMannDude · · Score: 2
      Thanks, Dephex Twin. You read my original post correctly and have saved me the trouble of responding.

      GMD

    7. Re:This article starts with a poor example by the+grace+of+R'hllor · · Score: 1

      What moral or legal responsibility do I, a user, have to HP, a company?

      If there is a toll passageway with a 3 meter deep pothole, would I be sued if I put up a sign that points out this pothole, even if it would mean less people would go through that passageway?

      (yes, I always think of stupid analogies like that. Sue me.)

    8. Re:This article starts with a poor example by Blue+Stone · · Score: 1

      Kevin wasn't being paid by HP, so why should he owe them anything?
      He didn't have to tell them their product had a flaw.
      If I buy a microwave and discover that it'll leak radiation, say, if the user does something out of the usual, I could tell the maker, or I could tell the press.

      Why do I owe the maker anything? Why do I owe it to them to help them out? They don't pay me.
      If it's my civic duty to inform someone about the product flaw, so people don't get hurt, why should I be forced to only tell the manufacturer?

      I say a blacklist is created of all the companies who threaten people who disclose the faults in their products, with the intention that those who care about their own legal safety, know who not to help.
      They leave them to their own devices, let the bugs build up and let the truth out, through black-hat hackers, exploiting the flaws.

      Much greater negative publicity for the company involved, (if that's what they're scared of) then we'll see them change their stupid attitudes.

      --
      Corporation, n. An ingenious device for obtaining individual profit without individual responsibility. - Ambrose Bierce
    9. Re:This article starts with a poor example by Reality+Master+101 · · Score: 2

      So companies have the right to prevent my freedom of speech?

      No, they have the right to fire your ass if you exercise your free speech in an a way they don't like, or even take legal action against you (such as disclosure of trade secrets).

      Freedom of speech != freedom from consequences.

      --
      Sometimes it's best to just let stupid people be stupid.
    10. Re:This article starts with a poor example by cheese_wallet · · Score: 1

      "No, they have the right to fire your ass if you exercise your free speech in an a way they don't like, or even take legal action against you (such as disclosure of trade secrets)"

      That is exactly right. I never expected someone to realize that on slashdot though.

    11. Re:This article starts with a poor example by Anonymous Coward · · Score: 0

      so you discovered the hole, told the company, and they've done nothing. What if a black hat figures out the whole you caught as well? Without disclosing to the public the flaw, there would be thousands of open systems and NO ONE would know about it.

    12. Re:This article starts with a poor example by Anonymous Coward · · Score: 0

      If you find a bug in Company A's software, then let A know about it. If A decides not to do anything about it (or if they are taking longer to plug the hole than you thought) I don't see how you are morally justified in leaking that info to the world. You are one person,the "disgruntled" user that is p***ed off that this program won't do what you demand it do. Now the support staff learns to ignore you as a PIA (Pain in the A**) What is your next step? Do you keep sending reports about your fav "bug" that gets no response or do you "go public hoping that there is safety in numbers" and you are not just "tilting at windmills^H^H^H^H dows" As a concerned user/citizen what do you do? You use your "morals" as to what to decide what to do. Whether this makes you a black/gray/white "hacker" is up to someone with more cahoona's than you to decide what your punishment shall be.

  15. At what point are we going to by Anonymous Coward · · Score: 0

    ... demand that companies handling our (we the "consumers") sensative
    data be punished for not making security a top priority? Why is it other than blatant shortsightedness (inability to see beyond the self) that companies keep pushing for legislation that
    crucifies anyone who points out blatant security flaws instead of commending those said messengers as catalysts for
    improving the overall security? Let's not kid ourselves.

  16. Hacking/Cracking ambiguity will soon be resolved by ites · · Score: 1

    When TCP makes open computing illegal,
    then unsanctioned programming will be a crime.
    Those using 'hacker' to mean 'guru programmer'
    will find that perception has become law.
    Cracker, hacker, what's the difference when you work outside the law?

    --
    Sig for sale or rent. One previous user. Inquire within.
  17. What is unethical??? by Troy+Roberts · · Score: 1

    Which is the more unethical?

    Telling users of a software set that it has holes, so that they may protect themselves? or not telling them, but just the producer of the code?

    Why is stating a fact in public unethical? I personally think a company that does not disclose holes in it's software to their customers in a timely fashion are unethical.

  18. Comment removed by account_deleted · · Score: 2

    Comment removed based on user account deletion

  19. Re:Hacking/Cracking ambiguity will soon be resolve by Anonymous Coward · · Score: 0

    When TCP makes open computing illegal ...

    Then, we could just use UDP -- problem solved. Yuk, yuk ;-)

  20. morally justified by slashkitty · · Score: 2
    If A decides not to do anything about it (or if they are taking longer to plug the hole than you thought) I don't see how you are morally justified in leaking that info to the world.

    Just because you found a hole, it doesn't mean that you are the ONLY one to find the hole. It's possible that any hole you find is an actively exploited hole.

    While I'm not familiar with Kevin's case, I've been in a similar situation before. Bank A would not patch their holes in their banking websites. I notified them again and again. After months waiting, I went public. Problem was solved the NEXT DAY! It was simply a matter of getting the right people to make it a priority. I feel that this is completely morally justified and I don't think that the bug was exploited, and I don't think that USERS were harmed just because it was public. It may however have hurt Company A's reputation.

    --
    -- these are only opinions and they might not be mine.
  21. Just as in all areas of life there are constraints by BoomerSooner · · Score: 1

    Just because someone chooses to ignore the law (or claim ignorance) does not make what they are doing legal. However, there is a large divide between what is "legal" what is "moral" and what constraints should really exist.

    For example, doing drugs is illegal but in reality is it immoral? or wrong? What if that drug were aspirin? caffienne? alcohol (remember we tried that once)? The laws should exist there to protect us from each other not to protect us from ourselves, in my opinion of course.

    Personally I hate hackers because my f'ing Windows Box would get hacked regularly since I didn't have 2 hours a day to check on patches. I switched to Linux on the server side and haven't looked back. So my result was beneficial as a result of being hacked. However, if I could get my hands around the throat of the mofo's (1 in taiwan and one in italy) after working all weekend to repair the damage, believe me you couldn't get a drop of water down their throats because I'd be squeezing so hard.

    In short, if you don't like the rules of your society either work to change the laws, ignore the laws (at your own risk), or move. Either way no matter where you go, stupid laws will follow (except Sealand, but they won't let you immigrate).

  22. it makes more sense.. by Suppafly · · Score: 2, Interesting

    The whole conversation makes a lot more sense if you drop the hat references.. sure its easy to lump people into categorys of white, black, gray, etc hat. But in reality there are crooks, good guys and crooks who play good guys. It used to just be a hax0r description to use the hat verbage.. its unfortunate that its passed into mainstream security usage.. I personally have a hard time taking anyone seriously that describes themselves by the figurative color of their hat..

    1. Re:it makes more sense.. by natefaerber · · Score: 1

      But how does "Red Hat" fit in?

      --
      -- My HARDWARE, My CHOICE.
    2. Re:it makes more sense.. by Anonymous Coward · · Score: 0
      The whole conversation makes a lot more sense if you drop the hat references

      It seems to make the same amount of sense to me, except it is lacking the imagery of the hats which makes it more interesting.
      It used to just be a hax0r description to use the hat verbage.. its unfortunate that its passed into mainstream security usage.. I personally have a hard time taking anyone seriously that describes themselves by the figurative color of their hat..

      Hmmm, that's odd. I mean, there's nothing wrong with having that opinion. I just don't see what the big deal is. I think it could have easily been just portrayed with black, white, and gray as you say... but the "hat" aspect is much more interesting.

      Why would you not be able to take this seriously? Imagery occurs all over the place. It's very natural.
    3. Re:it makes more sense.. by Anonymous Coward · · Score: 0

      "But how does "Red Hat" fit in?"

      They're one of the crooks who play at being the good guy.

  23. Disclosure of information by jalilv · · Score: 1

    Disclosure of information should be protected by law. There are cases in which hackers find bugs in softwares they are using on their own systems. Like in this particular case, the professionals probably found bugs in the OS that was running on their own machine. Such information should be allowed to be disclosed publicly. Whether to contact the vendor before telling rest of the world is a matter of choice and let the hacker decide about it. Smarter vendors will keep an eye on Bugtraq and other such lists. Even more smarter vendors will test their products before selling but thats a different story altogether. Some vendors are arrogant enough to either take a long time to look into the issue or don't provide a patch at all. Public disclosure might put some pressure on them. It might also make the user of the software products aware of the problem and take necessary precautions if possible. Instead of suing the hackers who are doing a service to vendors for free, the vendors should be sued by the clients (but the EULA doesn't allow it in most cases). Its sad that efforts are made to stop the disclosure of information instead of securing the right to freedom of speech.

    - Jalil Vaidya

  24. Who uses these terms? by Captain+Rotundo · · Score: 1

    Who runs around calling themselves "white hat" or "grey hat" or "black het" its just plain stupid to me. I suspect these terms were created for the purpose of so called "white hat" types differentiating themselves from "black hat" types.
    Basically a ruse so they can be 'hip' (being hackers and all...) but still be acceptable to the corporate system.

    The simply concept that legallity has ANYTHING to do with morality in the hacker world is absurd. I could list many things that are illegal, but of at least debtable moral stature, and possibly vice versa.

  25. security VS fame by phorm · · Score: 3, Insightful
    I think one of the big questions when accusing somebody of "hacking" should be intent. While this is of course one of the hardest ground to judge, hackers tend to fall along lines the lines of.
    • Fame: Doing something for popularity or fame
    • Profit: Doing something for profit
    • Personal gain: Doing something to gain personally or to lessen a personal expense, either by not paying for software/services or otherwise.
    • Entertainment: Simply because the hacker has nothing better to do with his/her time
    • Security: Doing something for the purpose of forwarding the intent of security etc
    • Revenge/attack: Self explanitory
    • Script kiddies or typical hack-it-cause-I-can types would tend to fall into "Fame" or "Entertainment".

    • If you have somebody who's informed a company of their problem, waited for them to do something, and then finally anonymously or semi-anonymously posted the problem, then we have the "security" types that are looking out for all of us. Somebody who posts it as "hey look at me, I hacked XXX/YYY and somebody should fix it" is just looking for fame or possibly profit.

      I think that if you can hack a system and then offer a viable fix/solution without the indicated repercussion of telling everyone in the world what the problem is, then you shouldn't be blacklisted as a "black hacker".

      However, if you go off and tell everyone that so-and-so's software/network is insecure because they didn't pay you, then you're no better than an extortionist or a crook.

      If you've bypassed security on a product that was hindering legitimate users, we have another really hard area to define. Anything that gets done to a company's product generally should be done with the grace of the producing company.

      Perhaps one of the biggest problems is those who just jump out and post something on the internet without thinking of the ramifications to the owner/users of the product. If you post a security vulnerability and fix, you may be allowing a certain amount of people to fix the problem, but you're also letting all the hackers out there know where there's easy prey in those that don't see the fix soon enough.

      In the same hand, if companies legally lambaste anyone who hacks and then offers a solution to their woes, it only makes things worse.

      Corporations with insecure products/networks need to recognise that running for the lawyers isn't always the best solution, while those doing the hacking need to recognise that extortionist/fame mongering/otherwise damaging tactics aren't helping either.

      If more companies can work with legitimate hackers in a productive way (as stated in the article, many have internal hackers), without inviting dozens of script-kiddies to poke at their servers, then perhaps one day the important people (we, the end-users) will find a day when we can legitimately use the products we pay for, in a meaninful manner, and without security woes.

      It's not what you can do, it's how you do it that counts - phorm
  26. If servers were Fords by wytcld · · Score: 5, Insightful
    Let's say you notice that my Ford Pinto is likely to explode. But there's a law in place that says that Ford can sue you if you tell me, because that violates their crash security, which consists in not letting people who might be malicious know that the rear end of a Pinto could be a tempting target.

    Now let's say you notice that my HP server is likely to be compromised. But there's a law in place that says HP can sue you if you tell me, because that violates their cracker security, which consists in not letting people who might be malicious know that the rear door of an HP could be a tempting target.

    Exactly why should HP deserve a legal protection that no sane person would give to Ford, when in both cases the customers are far better off with the knowledge?

    --
    "with their freedom lost all virtue lose" - Milton
    1. Re:If servers were Fords by jbolden · · Score: 2

      I think the better analogy would be knowledge that if you use ABC tool the Ford Pinto's door comes right open and thus its easy to get inside. The law is kinda iffy about this sort of information, in general the prosecution needs to prove intent to harm.

      The problem with /. is people confusing getting sued with losing a suit, and getting prosecuted with getting convicted.

    2. Re:If servers were Fords by pyrrho · · Score: 1

      um, because I want my corvair, dammit, and I don't care what speeds it's safe at!

      just a little joke at Nader's expense... your example is flawless.

      --

      -pyrrho

  27. I thought there were only black-hats left? by Kjella · · Score: 2

    I would have thought most of the white hats would give up, seeing how most people seem to wear dark black sunglasses when determining how white/gray/black a hat is....

    Kjella

    --
    Live today, because you never know what tomorrow brings
  28. Re:Do we really need a hat? No- just truth. by Lumpy · · Score: 3, Informative

    really? ok.. so do you investigate hardware designs and modify equipment that YOU PURCHASED as a hobby? if so then you are a Black hat and need to go to jail by your definition.

    Security means nothing with the term hacker unless you are an un-educated manager. What you are referring to is a cracker and a completely different individual....

    Please, get a clue as to what term is what. I dont care what the illeterate media calls them or how they use the term... a HACKER is not a criminal but a software and hardware genius...

    A CRACKER tries to break into systems or bypass security. Why is this so hard for people to understand? The drivel that spews forth from the anchorwoman/man's mouth does NOT make it truth.

    --
    Do not look at laser with remaining good eye.
  29. No traditional whitehats anymore by Florian+Weimer · · Score: 2

    Almost all major players in the security field nowadays sell early access to information on unpublished vulnerablities (or let others sell it). Therefore, "responsible disclosure" is important: not only have vendors a comfortable time frame for dealing with problems, but the information is also more valuable if its distribution is limited for a longer period of time.

    Of course, this hasn't got to do much with security anymore, it's all about making profit and a feeling of security. After all, when you learn about a new, critical defect in Windows or some component of the GNU/Linux system, there's already a patch (at least in most cases, and the other ones are so obscure that you don't understand what's going on, so you really can't be bothered by them). So it's not that bad if you run software which is poorly designed and sluggishly implemented, isn't it? The whitehats will keep everything in control, and thanks to the new DMCA law, we can safely tell them from the blackhats!

    sigh

    (And BTW, the "responsible disclosure" document is referenced quite a lot for a withdrawn Internet Draft.)

  30. There are no white-hat hackers by russotto · · Score: 1

    A self-proclaimed white-hat hacker is someone who decries as a 'cracker' those who perform now what used to be perfectly acceptable hacks, and accepts the current state of the law as a fair arbiter for hacker ethics. But the DMCA has made hacking security systems not just on others' computers, but on those completely owned (not oWn3d) by you, into a criminal act.

    You can still be a hacker and not hack security systems. But then you're not a "white hat" -- you're just out of the "hat" picture entirely. If you're a hacker with a hat, like it or not, it's black. The DMCA didn't get rid of just the greys, it took out the whites as well.

  31. Damn Right! by Anonymous Coward · · Score: 0

    Linux will be a small nitch of hobbiest for macs and nothing else.

    Not hobby, not hobbier, but hobbiest!

  32. Hacker != Lawbreaker by Gerry+Gleason · · Score: 5, Insightful
    We don't give the media permission to denegrate the basic goodness that is "the hacker ethic". In spite of all the crap the major media puts out about this, there is almost no connection between hacking and breaking the law. The real origin of the urge to hack is the same as they urge any artist feels to create.

    I fully support the use of the alternate term "cracker" to refer to people who use hacker-like skills (or often, no skill just downloaded cracker kits) to vandalise whatever system they can manage to crack. Yes, some hackers get sucked into these activities at some point in their development, but that doesn't mean it is condoned by the hacker ethic.

    How about some analogies. When you check the door of the business down the street and find it unlocked, is it legal so wander around inside and see what you find? No, but if you didn't do any damage, it shouldn't be more than a legal slap on the wrist. If when you tried the door, you triggered the alarm, or some damage was done just by trying it, you can expect someone to be pissed off, and maybe prosecute you when you try it again on another business.

    If a responsible third party closely inspects and tests the security perimiter around your nuclear, chemical or biological plant, and finds vulnerabilities, what should be done? Right, first they tell you and the relevent government authorities, and if there is no real response for a reasonable period of time, tell someone else (press, other trusted third party, etc.).

    What is going on now is a typical corporate response, and it is exactly the same as using SLAPP lawsuits to silence critics. It is evil and anyone getting hit by such tactics should get help from advocacy groups. Of course, staying away from controversy is one approach, but it doesn't give you good hacker-karma.

  33. Shades of Graey by Anonymous Coward · · Score: 0
    The issue becomes contentious in the middle. It's not terribly difficult to determine ethical behaviour, or egregious unethical behaviour. But all the stuff in between is up for grabs. This is what scares the pants off of Felton, et al.


    Is security research ethical? When does it become unethical, and criminal, and who decides? As a security professional, I'm seriously thinking of hanging up my "hat" and going to law school.

  34. DMCA isn't the big gun against hackers. by werdna · · Score: 4, Informative

    While the ethics of cracking have always been interesting, the legality has never been an issue. It is, and for years has been, a crime, essentially, merely to knowingly obtain unauthorized access or to exceed authorized access to a computer owned by another. [Alas, many companies have injudiciously asserted these criminal charges against former consultants, merely to beat a bill with a nasty counterclaim.]

    However popular it is to join the bandwagon railing against the DMCA anti-circumvention provisions (people seem to forget that the DMCA is itself an omnibus of technical and non-technical issues, good, bad and indifferent, and ranging from boat-hull designs to ISP immunities), the article's focus on DMCA is misplaced -- almost irresponsibly so.

    The big guns against cracking conduct have been in place for years, and well before DMCA: The Computer Fraud and Abuse Act, the ECPA and countless state computer crime and regular theft statutes. All of these tend to be much broader in scope and reach, and far easier to prove and enforce. After the enhancements (from a prosecutor's point of view) made in the USA-PATRIOT Act, CFAA has become an even more powerful tool. The FBI didn't need a DMCA to get Kevin.

    At the end of the day, the HP nonsense was just that: nonsense. The reason the HP DMCA threat was never pressed was simple -- it was a no-play claim, and everybody knew it. However, there are and have for years been a kazillion laws to beat up on anybody who engages in unauthorized access or exceeding authorized access of any kind, and regardless whether the conduct amounts to any circumvention of an effective copyright protection scheme.

    I'm not arguing cracker ethics, or defending DMCA. I'm simply saying that the focus of the article is wildly misplaced. DMCA is just barely an interesting curiousity in the enforcement quiver -- so far as real cracking goes, it isn't even a fourth-string defense except in the oddest cases.

    1. Re:DMCA isn't the big gun against hackers. by BitterOak · · Score: 3
      The reason the DMCA is particularly pernicious, however, is that it criminalizes the dissemination of "hacking tools", not just the act of hacking itself.

      True, the DMCA is narrower than some of the other laws you cite because it is specific to security systems designed to protect copyright, and not security systems in general.

      The article unfortunately confuses two gray hat actions: breaking into a system to report to the owner about its vulnerabilities without permission (which should be illegal in my opinion), and releasing exploit scripts to the public when vulnerabilities are found in commonly used operating systems or servers. I think the latter should definitely NOT be illegal for First Ammendment reasons if no other.

      The DMCA stands apart from the other laws you cite, in that it criminalizes the latter activity (if the security system is primarily used to protect copyright.) The other laws only criminalize the former activity.

      --
      If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
    2. Re:DMCA isn't the big gun against hackers. by werdna · · Score: 2

      The reason the DMCA is particularly pernicious, however, is that it criminalizes the dissemination of "hacking tools", not just the act of hacking itself.

      You will search in vain to find "hacking tools" among the proscribed devices set forth in DMCA. Only particularized devices are involved there, and very few of them have ANYTHING to do with cracking.

      I don't disagree that the DMCA is pernicious, only that the conflation of it with these practices is bad karma for those who would like to criticize DMCA -- its technically weak as an argument, and generally associates violators of DMCA with an image not favorably taken in the public at large. If you want to beat down the DMCA, don't blame everything on it, like some technological "el nino."

      There is simply no reason to think that releasing an exploit script directed to a technical vulnerability would be a DMCA violation -- and the HP backtracking that immediately followed their ludicrous overreaching is more evidence that DMCA is not implicated than that it is.

    3. Re:DMCA isn't the big gun against hackers. by BitterOak · · Score: 2
      You will search in vain to find "hacking tools" among the proscribed devices set forth in DMCA.

      Explain that to Dmitri Sklyarov, who spent more than a month in jail for releasing a hacking tool, which unlocks Adobe e-books.

      --
      If I can be modded down for being a troll, can I be modded up for being an orc, or a balrog?
    4. Re:DMCA isn't the big gun against hackers. by Reziac · · Score: 2

      Or in fewer words:

      The DMCA criminalizes free speech and thereby nullifies the First Amendment.

      And there were already laws aplenty against nefarious hacking; for what did we need another one??

      --
      ~REZ~ #43301. Who'd fake being me anyway?
    5. Re:DMCA isn't the big gun against hackers. by werdna · · Score: 2

      Explain that to Dmitri Sklyarov, who spent more than a month in jail for releasing a hacking tool, which unlocks Adobe e-books.

      That's just silly. This is some new use of the word "hacking tools." Certainly, Elcomsoft doesn't think so -- the words "hacking tools" do not appear on their web site.

      Sure, you can try to define yourself out of this argument by treating the word "hacking" to mean whatever you like. But that's the same logical error -- you are still conflating the same concepts. If you define "hacking" to include the activity of trafficking in software for "unlocking Adobe e-books," congratulations! You won the argument. But so what? My point is that DMCA is not directed toward the conduct traditionally known as hacking by most of us (clever machination of technical systems) nor the conduct currently known as hacking (cracking). The DCMCA anti-circumvention proscriptions may overlap with some cracking conduct, just as any number of other laws -- that doesn't make it anti-cracking legislation, for the reasons stated earlier.

  35. Gray hats.... by WickedLogic · · Score: 1

    reguardless of that article, which was VERY biased. I'd like to point out that those who see the world, computer hacking especially, as either black hat or white hat, only see it that way due to the limitations on the dunce hat they already wear.

  36. Justice or Law? by Anonymous Coward · · Score: 0

    >Never and I mean never underestimate Microsoft! Everyone who has, has been stomped on or crushed. Their bussiness model couldn't compete with oss so they are now using a legal model to squash us. Its perfect agaisnt individuals who do not have the finiancial power to defend themselves in court.

    The law is SO far away from justice now, it's not even funny.

    You can buy the law and make your ennemies criminals. But that doesn't mean it's right, and it's surely not justice.

    USSR, land of the Free!

  37. "Code of Ethics"? by exhilaration · · Score: 1
    Though having and following a code of ethics is nice, it doesn't shield you from the law.

    If a company feels like it, it can go right ahead and sue regardless of how "ethical" the hacker might be.

  38. Ethics by mrcparker · · Score: 2, Insightful

    Since when is giving out information unethical? I find a flaw in something - anything - and somebody asks me about it, I am going to tell that person what the flaw is. If my wife buys a car that she will be travelling around with my little girl in and my wife asks if there are any problems with the car the salesman has to tell my wife about any flaws. If I find a problem with the tires that causes the car to flip I anm going to tell people about it. This is the nature of information.

    1. Re:Ethics by PigleT · · Score: 2

      "Since when is giving out information unethical?"

      Ever since you subscribed to a utilitarian view of ethics and there was a better option, I should think.

      "If I find a problem with the tires that causes the car to flip I anm going to tell people about it."

      Before or after it's flipped? And who exactly are you going to tell?

      --
      ~Tim
      --
      .|` Clouds cross the black moonlight,
      Rushing on down to the circle of the turn
  39. Rainbow Hats by nurb432 · · Score: 1

    Ethics are relative to each person anyway.

    And besides, they are for loosers..

    --
    ---- Booth was a patriot ----
    1. Re:Rainbow Hats by Anonymous Coward · · Score: 0

      Morals are relative, ethics are not.

      And it's spelled "losers," not loosers.

    2. Re:Rainbow Hats by nurb432 · · Score: 1

      No shit its spelled that way, it was intentionally misspelled..

      And both are relative.. Nothing is absolute.

      --
      ---- Booth was a patriot ----
    3. Re:Rainbow Hats by Anonymous Coward · · Score: 0

      Morals vary from person to person while ethics are defined and written. There most certainly are absolutes. ...and 'its' should be 'it's'.

    4. Re:Rainbow Hats by nurb432 · · Score: 1

      Yes Mister Typo Checker.. I'm so impressed.

      Though I still don't agree, they are not absolute.

      --
      ---- Booth was a patriot ----
  40. You take the credit -- would you take the blame? by GuyMannDude · · Score: 3, Insightful

    While I'm not familiar with Kevin's case, I've been in a similar situation before. Bank A would not patch their holes in their banking websites. I notified them again and again. After months waiting, I went public. Problem was solved the NEXT DAY! It was simply a matter of getting the right people to make it a priority. I feel that this is completely morally justified and I don't think that the bug was exploited, and I don't think that USERS were harmed just because it was public.

    Congrats on getting the bank to do something. And your sentence makes it clear that you feel that you deserve the credit for getting the bank to fix this.

    Now I am wondering: what if the bank did not fix this problem the next day? And what if some cracker/con-artist used your publically-disclosed exploit to cause significant damage to the accounts of one or more bank's customers? Would you be willing to take the blame for this? Yes, the bank should have fixed the problem and you gave them ample opportunity to solve the problem themselves. But I would argue that, yes, you do bear some responsibility in this case. But that's just my opinion. I am curious what yours is.

    You are very eager to take the credit for a case when a public exploit resulted in something beneficial. Would you also be willing to take the blame if your actions had had disasterous consequences? If so, then I salute you as a fair man/woman/slashkitty. If not, I wish I could smack you upside the head.

    GMD

  41. Re:OT: shades of grey by MindStalker · · Score: 1

    I'd have to look up the law, but I'm pretty sure most all of them were legal before the legalisation of abortion. All the legalisation did was make it a right, so you didn't need a doctors recommendation or any good reason whatsoever.

  42. Crackers are hackers by ACNeal · · Score: 2, Interesting

    There is no real distinction between hacker and cracker.

    The tools, tricks, and procedures used by one are used by the other. The original hackers were the original crackers. It was fun to break into things (be it your radio, your telephone, your telephone network, or someones computer system). Well whats the fun in just being there if no one knows you were there. This is where data stealing, or defacing came in. All the way back when the hack/crack was as simple as making a score board say MIT, when they didn't have a sports team, let alone being involved in the specific contest.

    To you and me, it is obvious where a prank ends, and malicious intent begins. To the person that has to clean up the prank, it is all malicious. So to you an me, there is a distinction between hacker and cracker, but to the laymen, they are the same. Not because they don't know any better, but because to them the outcome is the same. And now with the DMCA and the like, the line is clearer.

    And before someone says kernel hacker, the prankster hacker is where the term originated. So if anyone is using the term incorrectly, they are probably the ones that should get the chastising. Kernel hacking is such a small and specific subset of the word, it isn't what the term was created for, nor does it truly represent the standard.

  43. Hacking into "your own" servers is a crime now! by Anonymous Coward · · Score: 0

    You do realize that if you hack into another computer you own on a public network, that is technically against the law. If the ISP finds out, you will be in jail for a few days.

    What about a sys admin testing "his own servers" (company servers he/she is responsible for) for vulnerabilities? If the PHBs find out the "hacker" tools he is using to test his own server's vulnerabilities, they will fire the poor sap and try to get the Feds to charge him/her with FELONY HACKING!!!! Punishable with many, many years in prison in solatary confinement plus 10 years parole with virtually no way to generate income.

    Therefore, the moral of this story is: Don't own any "hacker" tools for ANY REASON. Add the vendor's upgrades when they come out and NEVER test your servers for vulnerabilities. Then when the network is compromised, explain this little scenario and say "I did the best I can, given the current legal climate of said vulnerability testing". It won't save your job, but it will save your career and keep you outta jail.

    1. Re:Hacking into "your own" servers is a crime now! by Anonymous Coward · · Score: 0

      I have a plan for this exact scenario whenever it comes up. My home network is on a commodity ISP, and my work network is far away both physically and logically. Some day some luser at the ISP will try to be clever, and it'll go like this:

      [ISP] you've been attacking (such and such address)
      [me] ok, do this - whois (address)
      [ISP] uh, what about it?
      [me] you see the contact there?
      [ISP] ok, it says (name)
      [me] and just who do you think I am?
      [ISP] uhh...
      [me] it's MY network, so go bother someone else.

      Simple, unless you're not in the ARIN/RIPE/etc records, of course.

  44. Fading of the grey hat by Zelet · · Score: 1

    If there is no longer a grey hat because of dumb-ass laws, what do you think the distribution is going to be from grey to black or grey to white? I personally believe, since there aren't that many jobs available, many more people will switch to black hat instead of white.

    Either way, "black" or "grey" doesn't matter as long as they continue to push the industry into security. In my opinion both are doing good to the industry. What happens if we get into an information war and we never had to deal with security before? Black and grey hatters - you are patriots to me, no matter what the government says.

    Good job.

    --
    ...And when they came for me, there was no one left to speak out for me." - Martin Niemoeller (1892-1984)
  45. Nearly everyone's a grey-hat by xeno · · Score: 5, Interesting

    Bull. There's plenty of room in the grey-hat region, and plenty of population in it. The wiggle room for those who crack systems/software and then publicly announce the results is getting tighter. However there are an awful lot of people whose main concern is simply sharing results of bug/flaw discovery or other necessary activities that aren't good for vendor busines models. The fact that the DMCA seeks to redefine discovery and community notification as reverse-engineering and criminal collusion doesn't do a thing to shrink the number of people (admins, architects, programmers, dbas, etc) who simply need to do these things to do their jobs. The grey hat is still a thinking person's hat -- one abides by the letter of the law as best one can, and find ways around the obtuse or wrong-headed sections to accomplish primary goals of systems operation, data protection, and other work processes. Some prefer to skirt the line with black-hat-dom, while others simply protest bad law. Ain't nobody a white hat unless they utter phrases like "He was arrested so he must be guilty" or "The law is always right."

    Not too long ago, I sent a note to several of my friends about a conflict I saw between the DMCA-esque proposed Microsoft security certification -- requiring software bug hiding and notification of the software vendor before notification of the affected client -- and the codes of ethics binding those with CISA and CISSP certifications -- both of which require protection or notification of the potential target/victim. (My personal favorite part of the ISC2/CISSP code is "Tell the truth" which is anathma to the DMCA/bug-hiding camp.)

    Of course, since DMCA enforcement tends towards the corporate view of things (property, ownership, patents, royalties) rather than the societal view (ethics, trust, truth, community), if I follow the vendor-independent (societal) path, I get labelled as a grey-hat or a black-hat right out of the starting gate. Have I personally cracked and distributed software? No. But do I swear to uphold the right of the consumer to know of flaws in their software or implementation? Of course I do -- it's the core of my job as a consultant. But doing so may label me as a criminal, and not doing so is unethical and unprofessional. As the article point out, all you can do is try to do the right thing. Currently that may be illegal.

    Maybe some of us will go to jail for it, but that's what it'll take to change or repeal ill-formed laws such as the DMCA. Nothing induces judicial scrutiny like a situation where a judge is embarassed to enforce a bad law against a just person. But for anyone contemplating the notion of a "test case", keep in mind that the ACLU only picks up your legal fees if you keep your nose clean while you're doing the (illegal) right thing.

    J

    --
    I think not...(*poof*)
  46. real world analogies by markwusinich · · Score: 1

    In Philadelphia there is a resturant attached to the Spectrum (venue for conerts, circus, minor league hockey). There is a stair way leading up to the inside arena at which point you have to show your ticket. There is also a door that leads to a hallway that leads to the interior stadium. There is no guard at the door, you do not have to show your ticket. If I use that door, I think it is clear that I am stealing. Just as if I crashed the gate.
    But is telling someone else about the door stealing.
    Many of the agruements about no real property being lost apply.

    What if there is a 'Do not enter' sign on the door?

    What if the door is locked, but pushing opens the door anyway?

  47. Article demonizes disclosure by Anonymous Coward · · Score: 0

    Apparently you're now a bad guy if you do an independent security audit of a product and publish the results.

  48. For me to poop on. by FallLine · · Score: 3, Interesting
    Suits are scared of the public knowing about holes in their product, because that could erode trust in the product. That's the short term vision that motivates suit fear, and causes them to lash out with threats of lawsuits.

    Unfortunately, this fear overwhelms the suit's intelligence, which would tell the suit that in the long term
    I'm not a suit, I'm well aware of the arguments on all sides and I was once involved in the hacking community, but I don't agree that the the instant disclosure of new vulnerabilities (and especially the all too common practice of releasing corresponding exploit code with it) is good policy. Regardless of the speed of the vendor or development team to release an appropriate patch, the person that publishes a new vulnerability gives those that wish to hack (yes, I know and I don't care) into systems a huge advantage on the administrators of the world. With the publication of a new exploit to bugtraq or what have you, you instantly arm thousands of script kiddies with an attack that cannot be defended against (in the majority of cases anyways). Even in the best of situations, there is going to be some delay in the development team's response. Even in the best of situations, the sysadmin can only patch so many systems so quickly. Even in the best of situations, only so many admins are going to be available to update their systems in the first place. This is simply a totally unnecessary situation in the vast majority of cases. If the so-called hacker were a little more reasonable and a little less self-centered, then they would give the vendor at least a day or two to come out with a patch before announcing it to the world.

    The argument that you need to publish to the whole world instantly is absurd. Sure, a couple vendors may not be responsive, but most are. Even in the cases where the vendor's response is not entirely adequate, the "harm" posed by waiting is negligable because it's rather unlikely that some unknown hacker will discover the same bug and start exploiting it before then. Few would argue that the developers of Linux and a couple other leading open source packages are slow to respond, yet we see this same instant disclosure of code, often without a patch (even in the cases where a patch is provided, it's not necessarily one that is suitable).

    The reason for this publication in the majority of cases is pretty simple. The publisher wants some recognition for his discovery. While this is understandable, there are other ways to gain recognition. For instance, he could disclose the fundamental details of the exploit to the public and/or a trusted 3rd party on discovery and maybe attach a checksum or PGP signature of his official advisory that he sent to the vendor (in case someone else tries to take credit for the particulars, the corresponding document could be revealed and proven to be known by the discoverer at least when the first advisory was sent out). It may not bring him quite the same fame, but it would be something.

    a climate where disclosing holes is discouraged merely limits access to the information to the so- called "black hats".
    Even if the so-called "white" or "grey" hats cease to disclose these vulnerabilities to anyone, it would be virtually impossible for a large number of black hats to keep the exploit to themselves without it getting back to the security community. It's human nature to brag and to leak. What's more, I would argue that very few blackhats have the sophistication to come up with original exploits themselves. They pretty much depend upon the more knowledgable people that disclose the vulnerabilities to the public. In other words, the community of people having exploits over vulnerable machines would be far smaller.
    1. Re:For me to poop on. by markwusinich · · Score: 1

      What if an ATM had the option of dishing out bills in either $20 or $5, and a radio station annouced that the ATM at 34th and Lancaster had $20's in the tray that should have $5's. There would be a line of people taking out $15.

      Certainly you could see that this would not be responsible, and those responsible should be punished.

  49. What about.. by Brandeissansoo · · Score: 0, Redundant

    What about the ...RED...hats .. (laugh/snort/laugh)

  50. what's that quote from the Chronicles of Amber? by shren · · Score: 2

    "Narrow them down to a simple choice. Make them think it's their own." - Luke, on salesmanship

    --
    Maybe the state's highest function is to grind out insoluble problems. (Zelazny, Hall of Mirrors)
  51. If I bought a truck.... by Satan's+Librarian · · Score: 2, Interesting

    If I bought a truck, and the seatbelt linkage into the truck's frame was faulty and likely to fail in a crash, then I suspect I'd write a letter to Consumer Reports reporting it. I'd probably also write a letter to the company. The fact that I would have had to take apart a portion of the truck to find the fault would make NO difference. No one would say it was illegal, no one would complain that I was 'gray hat' or 'black hat'. I bought the truck, the truck had a problem, I told people. Big deal.

    If I took apart someone else's truck without asking for permission, I suspect I'd just get my ass kicked. But, charges could of course be filed by the owner of the truck as well.

    Why is it different with computers? Why are there people here saying that someone who looks at something they've legally purchased and find flaws with it are ethically in the wrong? And why should they not be able to speak up about it? The article is about a guy who reverse-engineered something on his own system. He didn't hack anyone else's system. What is wrong with that? I'm seeing tons of posts saying that all gray hats are black hats, or that ethically gray hat hacking is wrong although they do it anyway, and lots of garbage like that. What is gray at all about experimenting on your own machine when you've purchased the software?!? The whole gray/black/white hat stuff to me only applies (in any way, even if it is all b.s.) when you're poking into *other* people's computers.

    Yes, if you find a hole, it's polite to everyone to give the company a chance to fix it before going public. But - that's a polite social thing to do. I see nothing wrong with telling an emporer or anyone else that they are butt naked. And if I feel like it, I should be able to tell everyone that the emporer is butt naked without asking his permission. That's called freedom of speech.

  52. Re:You take the credit -- would you take the blame by swillden · · Score: 2

    Now I am wondering: what if the bank did not fix this problem the next day? And what if some cracker/con-artist used your publically-disclosed exploit to cause significant damage to the accounts of one or more bank's customers? Would you be willing to take the blame for this?

    The fact that an attack is performed shortly after the weakness is disclosed does not mean that (a) the attack would not have been performed had the weakness not been disclosed or (b) that the disclosure had any relationship whatsoever with the attack.

    What's very clear, however, is that the correction of the defect has a direct, causal relationship with the public disclosure.

    Certainly, public disclosure increases the odds of an attack, but it does not increase them from from zero, and disclosure which results in the correction of the defect reduces them from the previously-unknown value to zero.

    In most cases, the bank's customers are better served by public disclosure. For one thing, it lets them know that their bank behaves irresponsibly with their money, and gives them a good hint that they should take their business elsewhere.

    I would agree that it's irresponsible to publish software that automates an exploit, and that doing so might place the author at fault, to some degree. Publishing the vulnerability on a secret crackers-only forum would be thoroughly reprehensible. And it's both polite and good for the bank's customers to give the bank a chance to fix the problem themselves before going public. But if the bank isn't willing to protect its customers unless its nose is publically rubbed in the problem, then the responsible thing to do is to go public.

    You are very eager to take the credit for a case when a public exploit resulted in something beneficial. Would you also be willing to take the blame if your actions had had disasterous consequences?

    You have it backwards. The poster would be at fault if he had continued to keep it quiet until the customers' accounts had been emptied. The only difference is that there would be no one trying to apportion blame to him, so that is an /easier/ approach. But a much less moral one.

    --
    Note to ACs: I usually delete AC replies without reading them. If you want to talk to me, log in.
  53. Motive defines the line... by g_bit · · Score: 1

    ...not the means to an end. The difference between me killing someone to save the world or to make myself a million dollars is huge.

  54. Re:You take the credit -- would you take the blame by slashkitty · · Score: 2
    I do see your point, however, I will throw it back to you like this: In the same situation where you knew of a hole and did not disclose it to the public, would you feel guilty if it was found by someone else and exploited anyway? Your LACK OF ACTION can have consequences as well. Would you take the blame of not informing the public?

    It's unfortunate that the legal system tends to look more at actions instead of inactions. Did you ever see the final episode of "Seinfeld"?

    I feel that there is less RISK to users if they know which company / product / website is more risky to use, and know which companies keep up to date on fixing things.

    In the end, in my case, the type of bug in the bank's site had been listed in CERT for 2 years, along with how to fix it. I think that it's clearly the company's fault for not building a safe website.

    --
    -- these are only opinions and they might not be mine.
  55. Blacklist the DMCA by Uzmo · · Score: 1
    White hat / Black hat -- does it really matter?

    To an extent, I would say it is fair to give an organization a set amount of time to respond with a patch, but if the organization does not respond, then who is benefitted by staying silent? It is better to get the word out and inform those that care for their systems rather than entrusting that security to an unresponsive organization.

    If an organization uses the DMCA to coerce an individual to stop disclosing information that pertains to the security of the organization's software or OS, then perhaps it is time to consider foregoing the 30-day notice period. In the end, we (generally) are just trying to build more secure systems. If the organizations who write/sponsor the code cannot support maintaining the security of the product, then screw them!

    Uzmo

    1. Re:Blacklist the DMCA by Grab · · Score: 2

      Hell yes, it matters. If you fuck up a company's data, or possibly worse, take a company's data and sell it to their competitor, then that's a crime. The same as if I happened to leave my front door unlocked, it's still a crime for someone to come in and steal my TV. That's the difference between white and black hats.

      And then there's the ultimate "black-hat" attack - the DDOS. Requires little or no skill, just the ability to use some scripts off the web. Doesn't teach you anything. Just fucks up everything for the ppl attacked and for anyone trying to use their systems, without any gains for anyone except the immature little wanker sat giggling in his bedroom.

      I'm 100% anti-DMCA for its restrictions on reverse-engineering. But I'm 100% *for* fucking over the script kiddies.

      The "gray hat" thing is harder. RFPolicy is a good start towards this - get a standard code of conduct and everyone knows where they are. If you're genuinely not interested in hurting the affected people, give them a chance to respond and fix it, and then take the kudos. Hell, anyone who's ever worked in software knows that you never find all the bugs - even NASA can't manage that, for all its budget and procedures! - so this in-depth testing helps everyone. And this also provides a stick with the carrot - the software company *does* have to respond in a timely manner to alerts, bcos otherwise their product will get cracked.

      "Then screw them" is one argument, but it assumes you're not affected. Suppose you happen to have one of those servers? Remember, it's not really the software companies affected, it's anyone who uses that company's products. So if someone finds a vulnerability in the Apache software and then cracks your server wide open, wiping all your data in the process, it's *you* that's suffered, not the Apache team who were slow in responding to the alert.

      Grab.

  56. White / Gray / Black defined by Slur · · Score: 2

    WHITE
    Hacks systems at the request of the system owner to find vulnerabilities. Helps system administrator eliminate obvious holes first. Gets a paycheck and free lunches from the IT manager.

    GRAY
    Inconsiderately hacks systems without the knowledge of the system owner, blinded by his good intentions. Notifies system administrator about holes in the system. Receives suspicion and a subpoena, gets free representation.

    BLACK
    Cracks systems in search of personal booty and root exploits. His back-door scripts leave no traces. Notifies the world by rerouting all requests for the public site to goatse.cx. Never gets caught, gets all the chicks.

    --
    -- thinkyhead software and media
    1. Re:White / Gray / Black defined by Anonymous Coward · · Score: 0

      Stop your fucking F.U.D.! You Suit!
      Look at @Stake! You probably weren't around when they were the L0pht. They had their *own* network, they cracked their own system, and *then* posted vulnerabilities.
      Now, everybody's going to go "under"!
      Watch out now, STUPID! You won't even know where it's coming from...!

  57. My black hat has a big `EFF' on the front... by Dr.+Zowie · · Score: 2

    ... and so should yours, if you're worried about this stuff. Go here and send them a hundred dollars. You'll be glad you did.

  58. Keep All Hacks Secret. by SphynxSR · · Score: 2, Interesting

    If the community keeps all the hacks secret all software will be secure. No one will need to patch their systems. Personal firewalls will no longer be needed. Anti-Virus will a thing of the past. I think this is what the white house and other insecurity, are really trying to tell all of you. Don't share and don't hack. That way no one know about a hole. ie, China will be the only place that can hack into your system. Well including the government, MPAA, RIAA. Remember if you don't know they are doing it. It's not illegal. So IF are smart enough to find a hole, don't tell and OWN THE SYSTEM. At this rate it won't be patched and they most likely won't even know your there. This is how our government is going to protect us.

    --

    I don't suffer from insanity, I enjoy every minute of it.
  59. I agree.... by raehl · · Score: 1

    I was really aiming at the legal arsenal wielded to discourage even attempting to find and disclose bugs - not saying that bugs should be immediately publically disclosed. Or at least not trying to say that.

    1. Re:I agree.... by FallLine · · Score: 2
      I was really aiming at the legal arsenal wielded to discourage even attempting to find and disclose bugs - not saying that bugs should be immediately publically disclosed. Or at least not trying to say that.
      I apologize for jumping the gun. I read into your post what many others were saying. I pretty much agree that corporations should not have the legal means to prevent disclosure since auditing the security of the software is a legitimate right of the consumer...as long as that publication is made to further the security and not to defeat the security (e.g., DRM) That said, I think that few companies are going to be willing to pursue a researcher that makes a sincere effort to notify the company in an appropriate amount of time since it is not in their best interest. Even if a few companies do decide to attack conscientious discoverers, they are unlikely to succeed in court.
  60. Re:Do we really need a hat? X0X by Anonymous Coward · · Score: 0

    ...Even if know damage is done, if you're in my system...

    and that system would be your elementary school network, where you're just lerning how two speel?

  61. Gray is Black.. I AGREE by thedarkstorm · · Score: 2, Insightful
    I'll probably be modded down for this, but that's okay.
    I agree that if your Gray then your black. You might be Black with good intentions.. but your still black.

    It's like breaking into a store; simply to warn the store owner that you could break into a store.. no different. Or to use a popular theme in other postings regarding a house with an Open sign on it. NO! It's more like going up to a house, trying all the doors and windows till you find one that is open.

    Unless you are specifically asked by a company owner or software maker to exploit security holes, you shouldn't be doing it. If your concerned about security of the source, then choose a OpenSource alternative or write your own. If your using a COTS, then ask the publisher for permission to test the software for security holes, most will allow you as long as your a paying customer. If they don't, you probably don't want to be using that software vendor's appliction anyways.

    It's all about property people and respecting peoples privacy. Yes, it would be a utopian society if everybody could be online without fears of your network being compromised, and that's not reality obviously. But we don't need vigilanties running around exploiting everybodies software or network just because they can. It's not research its criminal; you've breached somebodies privacy even if you didn't do damage. If you want to practice, setup your own private network with software that allow's you to do as such. An no, I don't agree at all with the penalties associated with violations of the DMCA. They are outrageous and should be removed and educated individuals should re-establish new ones.
    --
    ... hey ... I had a .sig, bu then MicroSo$$ embraced it...
  62. I'm not wearing a hat by Anonymous Coward · · Score: 0

    This article, and the climate that it has arisen out of (the recent White House cyber-security report, and the new penalties introduced by the USA PATRIOT Act) make me quite glad that I've gotten out of the Information Security business altogether.

    This conflict between the ex-hackers and the ex-military/police within the information security community has been building for quite awhile, and it was only a matter of time before something tipped the balance. The crashing economy was already starting to weed the more rebellious of us out, as we just looked plain untrustworthy, and being the rebellious and out-of-the-box thinking geeks that made us good security people in the first place, many were unwilling to undergo the image transformation that was being required of us, to become security "professionals".

    9/11, however, was all the excuse needed to tip the balance all the way back to the suited "professionals". Now the shifty-looking security guys weren't just an eyesore, they were downright untrustworthy, possible cyber-terrorists (ala ex-Soviet chemical/biological/nuclear scientists), that could destroy your company if you look at them the wrong way.

    I don't remember who first said "Image is everything" but there's a reason it has become cliche. Real security is a scary, complicated, painfully obtuse thing, that rubs users the wrong way, and makes them want to use the system as little as possible. The more secure you need it, the more downright annoying and obtuse it HAS to be. Otherwise it isn't good security. For that very reason, good security doesn't sell awfully well. All the computer companies need to sell to suits, who equate security with increased cost and no benefit. A lot of computer companies can't afford to scare off a single client, so they will do their utmost to prevent their image being tarnished, especially in such hard times.

    So, being one of those people who calls a spade a damn shovel, I'm glad to be out of the business of covering up problems. I like fixing them which I will continue to be able to do for myself and my various consulting clients, but my country has apparently come to a consensus that doing so, for free, is immoral. Who am I to question my country? If I find something, that knowledge will stay comfortably in my head. I don't need a company suing me because I tried to help. I don't need to be a martyr for some cause that no one but a handful of people pay more than lip service to. The United States and the corporations that keep it running have chosen bad security, and they'll pay the piper eventually. I'll just sit back and watch the show.

  63. I don't mind wearing a black hat by alexjohns · · Score: 4, Interesting
    You can call me white, gray, black, puce, ochre, whatever. I already break the law, every day. I speed; roll through stop signs; jaywalk; litter; drive after having a beer or two with dinner; try to get every conceivable deduction on my taxes; copy software and music CDs. In the past, I experimented with illegal drugs; shared prescription drugs; bought alcohol for minors; participated in sodomy in at least one state that outlaws it. Shit, the list's just too freakin' long.

    I'm already a criminal. I imagine most people on here are. Who the hell hasn't broken a law today. We're in a drought here in Maryland. Water a plant today, did ya? Broke the law. have you let a teenager bum a cigarette? Criminal.

    Why should anyone care what color hat they supposedly wear. It's an arbitrary label. I call myself a hacker. I don't break things. I don't steal things. I try not to hurt people I like. In my opinion, that makes me an OK guy. Of course, opinions vary.

    Oh, and you... yeah you. Stop looking over your shoulder. I'm running crack against your password file right now. Might want to go change a few of 'em. Especially root. You know, the one that's your girlfriend's name. (And we both know she's not really your girlfriend. All you really have to do is ask her out, but you're scared. Pussy.) I'm only telling you all this because I like you. Now go ask her out, wimp.

  64. I got yer hat by Anonymous Coward · · Score: 0

    Who needs whitehats or greyhats?

  65. Let them suffer! by Glanz · · Score: 1

    I say then, let them suffer the consequences of their own karma. No help from me, that is sure! Let them eat cake, in other words, and the fully digested and expunged cake too!

    --
    Rien n'est plus beau que le creux du 0.
  66. The greater harm. by InnovATIONS · · Score: 1
    Your analogy is interesting, but flawed. Instead imagine that your discovery about the Ford Pinto did not involve rear-end collisions but something that could be induced by making a few modifications to a garage door remote control.

    You publish your findings and some incredibly malajusted person actually builds the device and uses it to blow up every occupied and unoccupied car that he can find. Now the chances of his being able to do this without your having published your discovery are essentially nil. Leaving aside legal responsibility for the moment are you ethically responsible for the harm that has been done?

    This goes right to the heart of the Black/Gray/White Hat issue. Knowing that there are Script Kiddies and other malicious forces that will IMMEDIATELY act to turn your published discovery into harmfull results and that there is no way the company could both create a fix and fully distribute it fast enough is it EVER the lesser harm to publish it?

    You might say that you are encouraging them to release a fix. But even if they had a fix already created and tested (unlikely) how much harm would occur to machines that did not get a chance to install it fast enough? No, your act of publishing will allways create the greater harm.

    1. Re:The greater harm. by Nonesuch · · Score: 3, Interesting
      InnovATIONS writes:
      Your analogy is interesting, but flawed. Instead imagine that your discovery about the Ford Pinto did not involve rear-end collisions but something that could be induced by making a few modifications to a garage door remote control.

      You publish your findings and some incredibly malajusted person actually builds the device and uses it to blow up every occupied and unoccupied car that he can find. Now the chances of his being able to do this without your having published your discovery are essentially nil. Leaving aside legal responsibility for the moment are you ethically responsible for the harm that has been done?

      It's not just black and white, and (most) software exploits do not result in human deaths.

      The "spotless white" hat notifies Ford, but the company ignores the warning and goes on making the Pinto without any changes. The CIA, Mafia, and Mossad learn of the weakness (through leaks or by discovering the issue independently) and build selective exploits, using them against their enemies for several years before the weakness becomes widely known. (This scenario has played out in both physical security and remote software exploits more than once.)

      The "light gray" hat tells Ford and his circle of 'leet buddies, and when Ford does not respond, some or all of his research notes are published to a "Full-Disclosure" list. Ford rushes out a fix in record time.

      The "pitch black" hat builds selective exploit tools and sells them to the highest bidder.

      This goes right to the heart of the Black/Gray/White Hat issue. Knowing that there are Script Kiddies and other malicious forces that will IMMEDIATELY act to turn your published discovery into harmfull results and that there is no way the company could both create a fix and fully distribute it fast enough is it EVER the lesser harm to publish it?
      Yes, it can be "the lesser harm" to publish.

      I've learned the hard way on more than one occasion that if you don't publish, most vendors will almost certainly not respond in a timely manner. They may create a fix and quietly distribute it in their next scheduled release, or they may just ignore the warning.

      Meanwhile, other researchers (including some truly morally bankrupt black hats) are almost certainly looking at the same areas you are, and will eventually discover the same vulnerability independently, and begin to exploit it.

      You might say that you are encouraging them to release a fix. But even if they had a fix already created and tested (unlikely) how much harm would occur to machines that did not get a chance to install it fast enough? No, your act of publishing will allways create the greater harm.
      In case after case it has been demonstrated that for most vendors, nothing short of full disclosure is sufficient for them to take the problem seriously.
  67. The exploiter is to blame, not the revealer by Theatetus · · Score: 2, Insightful
    Now I am wondering: what if the bank did not fix this problem the next day? And what if some cracker/con-artist used your publically-disclosed exploit to cause significant damage to the accounts of one or more bank's customers?

    If I went to my bank and noticed the door to the vault was open, I would tell the manager about it.

    If I came back the next day and it was still open, I would close my account. I would also feel ethically obliged to tell all the other customers at that bank that their money isn't secure.

    A: Do you agree with that, in the terms of the analogy? (physical bank; physical door)
    B: Does the analogy become any different when a computer is involved?

    One person, and one person only, is responsible for a malicious exploit: the person who performed the exploit.

    Networking protocols were designed for sharing information. There are (relatively) easy ways to ensure that only authorized recipients get information through these protocols. If a security system allows me access to parts of an internetwork, I have no reason to think I'm an unauthorized recipient of the information on that network.

    --
    All's true that is mistrusted
  68. At least by PaddyM · · Score: 1

    We still have Red Hat.

  69. A house is not a computer by dtabraha · · Score: 2, Insightful

    Can we at least get away from the terrible analogy of:
    "Ok, say you someone breaks into your house/car/business but doesn't steal anything" to mirror the actions of "hacking"?

    Yes, it really sounds like it might be a good analogy, but computers are absolutely none of the above.
    There is no such thing as a nice citizen who comes around to your house and checks to make sure your door is locked and your jewelry is secured in your house. There never has been, there never will be, and there never will need to be, because the Internet is a way different medium than the real world.
    Analogies are great for helping geeks explain computer terms to non-computer people, but no matter how you slice it an apple will never be an orange.

    A prime example of how it doesn't work is in software "hacking". If a major gaping security hole in someone's software exists, it is something that desperately needs to be fixed immediately and brought to people's attention.

    Imagine something simple like an IIS bug (no way!) that allows people to download the source code for some script on your server that includes things like database and system passwords. Some well meaning (gray) hacker tells Microsoft about this, and gets tossed in jail. Meanwhile the same exploit is found at the same time by a malicious (black) cracker, who tells all his l337 script kiddie friends and before you know it some poor startup companies have just given out credit card numbers and secure corporate information to exactly the wrong kind of people.

    Where is the white hat in all this?
    Oh, he thought about the exploit, but didn't look into it because that sort of thing is naughty and he might get his pretty little white hat dirty.

    Testing security measures and breaking software is absolutely necessary if we want to keep robust efficient systems across the country.
    Do you really think other countries prosecute their L337 cR4X0rs when they break into our untested unsecured networks?

    There have been hackers ever since there have been computers, and it needs to stay that way or we will all find ourselves up that silicon creek without a paddle.

  70. ACLU by Binome · · Score: 1

    What makes the American Civil Liberties Union "diametrically opposed" to God? The ACLU doesn't oppose anything. It's merely that they support the rights of the extremists. Yes, some extremists are "diametrically opposed" to the idea of the Judeo-Christian deity. But some aren't.

    Any other nonsense you'd like to spout forth in order to get me modded down by going further offtopic at the prodding of a troll?

    --
    In Soviet Russia, Beowulf cluster imagines you!
  71. Who Cares by Anonymous Coward · · Score: 0

    Wanna know what color my 'hat' is? You may as well as me what kind of mood I am in, the answer is very relevant. Besides, there is *no* security and anyone who thinks otherwise is in for a rude awakening one day. Either a system is completely secure and trusted, or it is not. Now guess which category 99.99% of the world's systems fall into? You are only 'secure' until someone better than you comes along. Better, or more motivated, or sadly enough just luckier also means you just got owned.

  72. Re:Gray is Black.. I AGREE by Trepalium · · Score: 1
    So, in summary:
    Ignorance is bliss, and therefore, what you don't know won't hurt you. Let sleeping dogs lie, and never look a gift horse in the mouth.

    Now, I'm sure every software vendor would love nothing more than to prevent security holes from being found in their products, but they're likely to try to accomplish this goal using the wrong method -- adding terms to the license that prohibit such activities. Instead we have to rely on those people who ignore the unenforcable restrictions on reverse engineering to find the holes, and keep these companies honest.

    The problem with your logic is that you seem to be implying that only those who are publishing vulnerability reports are those who are capable of finding them. There are likely many that go unreported for ages until either the exploit gets widely distributed enough, or someone else finds it. Personally, I would find no moral problem with violating a license that dared to tell me what I can and cannot do with it, after I purchased it. After all, I may be violating the law, but am I Right or Wrong?

    There is no absolute right, and absolute wrong. The law can't legislate right and wrong, and can't make us good people. All the law can do is provide punishment for those who harm others. Trying to get the law to distinguish between Right and Wrong is a recipe for disaster.

    --
    I used up all my sick days, so I'm calling in dead.
  73. Full Disclosure != Black Hat by Anonymous Coward · · Score: 0

    I don't understand the statement in the article that white hats only disclose vulnerabilities to the owner and trusted third parties. Isn't there still room for white hats to do full or responsible disclosure?

  74. Once you go black... by Anonymous Coward · · Score: 0
    ...you never go back!

    Fsck the man!

  75. Re:Gray is Black.. I AGREE by dubious9 · · Score: 1

    That's what grey is. It's white with some black. Or black with some white. By the same logic, if you are grey you are white, because of you're intentions. Grey do things blacks would never do, like doing the Right Thing (tm). Greys also do things whites would not do, i.e. disclosing information.

    "Unless you are specifically asked by a company owner or software maker to exploit security holes, you shouldn't be doing it. "

    I totally disagree. Then the only unauthorized people that find holes will use it against you. What happens if you are a company that can't afford to hire White Hats? What happens when you are a mega corporation and don't want your shoddy security reputation shot any further? You can't make security updates without saying that you made a mistake in the first place.

    For every grey hat that discloses information there is probably at least one black hat that also finds it. If you are smart enough to find a hole, then somebody else is too.

    If my company hires me to do network security and I happen to find a gapping hole in the 3rd party firewall software, you'd better bet that I'd tell my company. I'd also tell my collegues that consult for other companies. The best way to diseminate information is to make it public. I am more loyal to the company that pays me than I am to Microsoft.

    How can you prevent black hat break ins? Find the holes first. Notify the software maker. Patch the holes if you can. If the software maker chooses to not budget the fix until next year, I'll go public. I'm also more loyal to security professionals whose jobs rely on software than to Microsoft et al. whose profits depend on software.

    --
    Why, o why must the sky fall when I've learned to fly?
  76. How white is "white"? by Nonesuch · · Score: 2
    thedarkstorm writes:
    I agree that if your Gray then your black. You might be Black with good intentions.. but your still black.
    I strongly disagree. The law may define more and more actions as being unlawful (see the DMCA), yet those actions may still be ethically/morally right, and socially acceptable. The US has many such rules, where the law says one thing and society at large says another.

    Unless you are specifically asked by a company owner or software maker to exploit security holes, you shouldn't be doing it.
    I'm not exactly a "white hat" by most definitions.
    My job (and my hobbies) involves legally acquiring software and hardware and testing it, tearing it apart, looking for weak spots.

    That includes purchasing items like a Cisco PIX or a software firewall, testing for security holes, and often extends to writing and executing working exploits for these holes, on legally acquired copies running in my test lab.

    These actions may violate the vendor's EULA. But they do not ever involving penatration of the network, host, or data belonging to an innocent third-party. Do these acts make me a black hat?
    If my customer agrees, I report issues to the vendor. If they not respond, and if my customer agrees, I will post some or all information to a full-disclosure list. What color is my hat now?

    If your concerned about security of the source, then choose a OpenSource alternative or write your own. If your using a COTS, then ask the publisher for permission to test the software for security holes, most will allow you as long as your a paying customer. If they don't, you probably don't want to be using that software vendor's appliction anyways.
    Neither I personally nor my employers trust the publisher to do their own testing and report honestly on the results.

    While it may be in violation of the law or a civil transgression to "test" software after purchasing a legally licensed copy, I do not agree that such testing turns a grey hat to black.

    But we don't need vigilanties running around exploiting everybodies software or network just because they can. It's not research its criminal; you've breached somebodies privacy even if you didn't do damage.

    I've breached whose privacy? That of the vendor who wrote the software or designed the hardware?
    If I legally acquire software and hardware, install it on my private testbed, then exploit the software (locally, in my "sandbox"), it most certainly is research. It may also be criminal. If I take the results of my tests and publish them, that too is research, and under the DMCA or certain EULAs, may be unlawful.

    Regardless of how the laws are contorted to depict my actions, I will not accept the label of "black hat" on this basis.

    1. Re:How white is "white"? by thedarkstorm · · Score: 1

      I've breached whose privacy? That of the vendor who wrote the software or designed the hardware?
      If I legally acquire software and hardware, install it on my private testbed, then exploit the software (locally, in my "sandbox"), it most certainly is research. It may also be criminal. If I take the results of my tests and publish them, that too is research, and under the DMCA or certain EULAs, may be unlawful

      But you stated yourself that you are violating the EULA, that is damaging to the publisher of the software and is not research. It would be defined as 'research' if you had sought the publishers permission which I doubt you ever did. Your comment states your an OPENBSD fan, OPENBSD gladly allows you to perform research. In that case, use the OpenSource for your research and if your concerned about the security of COTS then DON'T USE IT!

      --
      ... hey ... I had a .sig, bu then MicroSo$$ embraced it...
  77. Whitehats can break the law too. by thogard · · Score: 2

    The only effective way to get many compaines to fix problems is blackmail which is technicaly illegal just about everywhere. There is something wrong when you have to break the law to get your vendor to fix something.

    The page says a black hat will not disclose their hacks and use them for their own gain. That sounds like me. I run unix boxes and I think Windows in most cases is trash. When a client says they are as secure, I've been known to show them why they aren't. I've had one client get all upset since I wouldn't explain to MS how I took down their secure box. MS isn't paying me and they have done enough boneheaded things to make my life hell at times. I'm not going to do anything else that helps gates and his evil minions make my job harder.

  78. Can we now have a "Simpson's Law"?? by SoSueMe · · Score: 1

    Maybe it should go like this:
    When the discussion in a threat starts to invoke the voice of Homer Simpson, the thread is deemed to be ended.
    Winner NOBODY!

  79. Americans only see Black and White these days by Anonymous Coward · · Score: 0

    Hi --
    I used to admire America, the Great. A nation full of ideals, dynamic, and fast-paced. But what the hell's going on nowadays? Everything is oversimplified: "the axis of Evil", "White hats/Black hats", DMCA, etc. Like someone said in the article, it used to be a script kiddie cracked your server, because you were to dumb to keep it patched up. Now, it's "terror" against "a mission critical server." Get fucking real!
    It seems America's capacity for creative thinking, analysis, and the criticism that's intrinsic is withering away amidst lawsuits, stringent patent laws, simpleminded thinking (Bush) and overregulation...
    I'm sure as hell glad that I don't have to live there, and can just look at it from the outside, sucking up the info...Too bad...
    America is on the way to dying from lack of oxygen.
    (And now, let's all watch the whole shit go down on CNN as oil prices go up, as George W. Bush throws the whole world in a crisis so deep we're going to start missing Ronald Reagan and want to crawl into our assholes.)

    A reader from another continent (wouldn't matter where, Americans flunk Geography at school).

  80. my hat color? by Anonymous Coward · · Score: 0

    sexually frustrated purple

  81. Exploits 'held by the dark side' for _years_. by Nonesuch · · Score: 2
    Even if the so-called "white" or "grey" hats cease to disclose these vulnerabilities to anyone, it would be virtually impossible for a large number of black hats to keep the exploit to themselves without it getting back to the security community.
    It's human nature to brag and to leak.
    There are several real-life examples of remote root exploits being held by a (relatively large) group of "black hat" hackers for several years before leaking out to the community at large. For example, there was a Solaris statd exploit that circulated for, IIRC, three years before it "leaked", resulting in a functional patch from Sun.

    What's more, I would argue that very few blackhats have the sophistication to come up with original exploits themselves.
    It only takes one.
    There are some very intelligent people coding for black hats. Many of the brightest people on the legitimate side of network security honed their skills as a black hat, then had a change of heart in the past few years as the threat of criminal charges grew larger, or after suddenly realizing that having a house, a wife, and kids changes your priorities.

    They pretty much depend upon the more knowledgable people that disclose the vulnerabilities to the public. In other words, the community of people having exploits over vulnerable machines would be far smaller.
    However, the pool of exploitable machines would be much much larger.

    Restricting public exposure of holes has been tried, and found wanting. Limited distribution of the details of holes was the unwritten law in the 1980's and early 1990s (anybody remember the 'core' list?). This is why the creation of Bugtraq in 1993 was such a big deal. Prior to that, vulnerability information was carefully controlled, distributed to a limited pool of "trusted" admins... including the "daytime personas" of a number of black hats.

    This approach did little to keep the black hats from learning about new vulnerabilities and writing exploits, and put little pressure on vendors to patch their software or pro-actively work to limit security holes.

    Full-disclosure may not be ideal, but it is better than the alternatives.

    1. Re:Exploits 'held by the dark side' for _years_. by FallLine · · Score: 2
      There are several real-life examples of remote root exploits being held by a (relatively large) group of "black hat" hackers for several years before leaking out to the community at large. For example, there was a Solaris statd exploit that circulated for, IIRC, three years before it "leaked", resulting in a functional patch from Sun.
      Sorry, but I think you're wrong. I knew of statd exploits many years ago. The statd exploits were publically known vulnerabilities for a long time, most admins were just too lazy to patch their systems. Please be more specific if you wish to use this example. Which group? How many people? When did they have it? Which versions of solaris were affected? When was the vulnerability (not necessarily the exploit) made public?

      It only takes one.
      Sure, and it only takes one person to leak. You can hardly have a group of 30 people or more and not have a leak after a week or two. So the question is something like this: Would you rather have 30 hackers attacking the same number of vulnerable targets for a slightly longer period of time or 20000 script kiddies (plus assorted people that have more skills) of them for slightly less? You do the math. I'd certainly take the 30 and that's assuming that the vendors are significantly less responsive (a premise that I disagree)...by the mere fact that you give them, say, a 2 day lead time.

      There are some very intelligent people coding for black hats. Many of the brightest people on the legitimate side of network security honed their skills as a black hat, then had a change of heart in the past few years as the threat of criminal charges grew larger, or after suddenly realizing that having a house, a wife, and kids changes your priorities.
      Well this can quickly unravel into a semantic argument, but I disagree. Very few people that are not disclosing to the public or to the vendors have the ability to write their own exploits. What ever hat you wish to put on them is an entirely different argument that I'm not interested in. I won't debate that many sophisticated people had their start in hacking, but the more sophisticated people quickly outgrow hacking into other people's servers for the sake of it as their skills develop. What fun is it to hack a bunch of servers with already known exploits (even if you created them) when you can you do something that is actually intellectually challenging (e.g., discovering your own) and do it mostly above board while you're at it, not to mention profit from your legitimate fame. (Sure, someone on the fringes may engage in the occassional hack, but not en masse) Yes, there are some undeniable blackhat codes, but they're generally lacking in originality.

      Restricting public exposure of holes has been tried, and found wanting. Limited distribution of the details of holes was the unwritten law in the 1980's and early 1990s (anybody remember the 'core' list?). This is why the creation of Bugtraq in 1993 was such a big deal. Prior to that, vulnerability information was carefully controlled, distributed to a limited pool of "trusted" admins... including the "daytime personas" of a number of black hats.

      This approach did little to keep the black hats from learning about new vulnerabilities and writing exploits, and put little pressure on vendors to patch their software or pro-actively work to limit security holes.
      In much the same way (as you and others argue this point) "democracy" was tried by, and subsequently failed for, the Greeks (and others), so therefore it could have been (and was) argued that it was the wrong path and should have been avoided in favor of monarchy, dictatorship, or the other extremes. Of course, we all know the United States and other democracies have since succeed magnificently. The reason? Subtle and important differences in the governence and a different situation (class, geography, economics, etc). You can't neglect these important differences:

      Firstly, what I'm asking for is not the same as the policy with CERT and other bodies. These people pretty much gave CERT the information and then walked away from it. Instead, I'm giving the vendor a reasonable period of time to respond. If they fail to respond in that alloted time, then the hacker always has the option of making the same disclosure that they do today, only a day or two later. The vendor has every incentive to respond before the hacker does this. Secondly, you can hardly compare the situation today with the growth of the internet (and lists devoted to distributing this sort of information to the public) and the increased interests in security with that of 10+ years ago. It's an apples and oranges comparison. Thirdly, I've yet to see any objective evidence that full disclosure has been any more effective in practice (and yes, I was around and quite aware then). Maybe you can argue that the sysadmins and/or users are a little better armed today with knowledge, but the script kiddies are also armed in that same stroke... The difference is that the script kiddies are armed first, with real weapons (well code at least) when the users only have knowledge that's of questionable value (even with this full disclosure and if the vendor tries as hard as they can, it may take more than a day to come out with a patch or an acceptable workaround).
  82. Re:People only see Americans in Black and White by dtabraha · · Score: 1

    Unfortunately, America has always had problems like this that seem to clutter up the media, and then eventually people's everyday lives.

    Things like the Vietnam war that caused an entire generation to dress funny and smoke a lot of pot. McCarthyism caused us to put a whole lot of innocent people in horrible concentration camps just because we were looking for a communist ghost. Less than 200 years ago we kept other people in chains, beat them, killed them and forced them to do our manual labor.

    You won't always find the strength or spirit of America on CNN, just Connie Chung and Larry King yapping away about what a tragedy it is that a few CEOs scammed some money. Meanwhile thousands of people are dying in countries that wept for us on 9/11, but we can't afford the airtime to cover that news.

    It's been the norm for the government and the media to blow things out of proportion and to dig up the wrong dirt on the right issues. But it's also been the norm for the citizens of the US to fight against the government for what we believe in. That's why we all turned into hippies, fought against communist concentration camps, and had a civil war over slavery.

    That's also the reason that we have big discussions like these on Slashdot about the ethics, definitions and social implications of hacking. What we need to do is focus less on what's being said, and focus more on who it's being said to. A bunch of geeks on a web site writing inflammatory comments about the government really only affects a bunch of geeks that come to that website and read those comments. It would be more effective if we could somehow get a real geek in Washington. Unfortunately for politicians to pay attention to you, you have to waft money in front of their nose. (Here boy! Nice senator want a campaign donation? Good senator!)

    Therein lies the problem. Those with the money are bringing wheelbarrows of it to their congressman to shut us geeks up, while we piss and moan about it in our forums.

    White, gray, black, purple... it doesn't matter what hat you're wearing now.
    If those in control now (Hollywood, Washington) have their way you'll eventually end up with a pair of matching handcuffs and a free ride to Alcatraz.

  83. Re:Hacking/Cracking ambiguity will soon be resolve by ites · · Score: 1

    TCP = Trusted Computing Platform.
    Hacker = any person writing illegal code.
    Legal code = code that observes legal requirements for security and traceability.
    Requirements: a bloody huge set of rules that only very large companies will be able to observe.
    Consequence: in five years' time, 'independent' software developers will go the way of independent car manufacturers.
    Captain, I predict that this scenario has a 45% chance of occuring.

    --
    Sig for sale or rent. One previous user. Inquire within.
  84. So you're saying Consumer Reports is illegitimate? by Nonesuch · · Score: 2
    thedarkstorm writes:
    But you stated yourself that you are violating the EULA, that is damaging to the publisher of the software and is not research. It would be defined as 'research' if you had sought the publishers permission which I doubt you ever did.
    Being "research" and being "illegal" are not mutally exclusive. My claim is that I am doing legitimate research on security, even though I may be violating a civil contract between myself (or my employer) and the vendor.

    The fact that I did not obtain the publisher's permission does not magically redefine my activity to be "not research".

    I bought a sports car. I don't think it goes fast enough. I swap out the intake system, have a machine shop rebore the engine, and I extract the manufacturer's ROM, edit the ROM image to tune the pre-computed fuel curve table, and burn a new ROM for myself.

    All of this activity I define as "research". The car manufacturer might not agree, and will void my warranty. But the fact that I do not have permission from them to "hack" my car does not change the definition of my research to something else, it only changes my relationship with the vendor, and precludes me from obtaining future "tech support" from the vendor.

    Your comment states your an OPENBSD fan, OPENBSD gladly allows you to perform research. In that case, use the OpenSource for your research and if your concerned about the security of COTS then DON'T USE IT!
    My clients choose to use non-open-source products. They choose to pay me to perform "research" on these products and supply my results either exclusively to my client, or to Bugtraq. I accept my client's conditions, and perform research for them.

    The fact that the company that sold them the hardware or software did not agree to this "research" does not change the definition of my activity.

    If my client was "Consumer Reports", would you still have a problem with my research?

    Consumer Reports buys all the items they test from retail outlets, and does not ask the manufacturer for permission to perform their "research": http://www.consumerreports.org/static/popup/didyou know.html

  85. A.C. by Slur · · Score: 2

    You are a humorless moron.

    --
    -- thinkyhead software and media
  86. Re:Do we really need a hat? No- just truth. by duren686 · · Score: 2

    a HACKER is not a criminal but a software and hardware genius...

    A CRACKER tries to break into systems or bypass security.


    That's true, but would you be more scared of a guy waving his axe around hacking things, or a salty biscuit that you crush up and put into your chicken soup?

    That's why mainstream media says "hacker"

    --
    Y2K Compliant since the late 1890s
  87. Last Post! by alpg · · Score: 1

    Real programmers disdain structured programming. Structured programming is
    for compulsive neurotics who were prematurely toilet- trained. They wear
    neckties and carefully line up pencils on otherwise clear desks.

    - this post brought to you by the Automated Last Post Generator...