Ask Kevin Mitnick
Okay, Kevin Mitnick is getting back online and can start taking email tomorrow, January 21. We've spoken with Kevin by phone, and he agrees that a Slashdot interview is a fine way to help celebrate his return to the Internet, especially since he has a book to sell and a consulting business to build. (Don't forget: Kevin hasn't been able to make much money for a number of years, and has a lot of lost time to make up for.) One question per post, please. We'll email Kevin 10 of the highest-moderated questions, and post his answers shortly after he gets them to us.
he has a book to sell and a consulting business to build. (Don't forget: Kevin hasn't been able to make much money for a number of years, and has a lot of lost time to make up for.)
Knowing all this as the result of your choice, would you choose this path again? If so, why?
A feeling of having made the same mistake before: Deja Foobar
Seeing that you have taken some responsibility for your actions, do you think your penalty was fair and will a penalty like you received, fair or not, deter others from following in your footsteps?
There has been alot of press, and over the years you have been a hero, and a Martyr to thousands of geeks and hackers, in addition to phone phreaks and anti establishment movements.
In what light and or combination of these types do you see yourself now, is that different from how you were 20 years ago, and do you see yourself as a champion of these things in the future or do you intend to just mix back into society and get a "normal" life back (after your book of course)?
For better or worse, what is the most important thing that you have learned that applies to us all?
Given that you have been quoted as saying your 'hacking' was wrong to do. How do you feel about being perhaps the most notable icon of the hacking community?
"as plurdled gabbleblotchits on a lurgid bee" - Prostetnic Vogon Jeltz. (One man's humorous is another mans flamebait)
Kevin is famous for breaking into systems. In point of fact, he broke the law breaking into systems.
/. get behind him?
When I was 13 I thought that cracking into systems was "kool." Now that I am an adult, I see that once a system has been compromised - even if it's just so that a smart kid can look around - it costs a fortune to be sure that a) the holes are closed, and b) the kid didn't do any damage.
He broke the law. Should we help him "make up for lost time" by helping him profit on his life experiences? I don't think so.
Let me give an example. Let's say that I am pro legalization of prostitution. (I'm not)
Before the legislators became "enlightened" on this issue (while it is still illegal) someone is convicted of being a pimp - should I make that person a poster-boy? Should I work to build a "how to be a pimp" consulting business, or promote a "pimping for dummies" book?
Kevin broke the law, and did his time. Can't he just get a straight job like the rest of us and move on? Why must he be a hero? Why must
I don't get it. Let it go. Kevin, please get a regular job and live like an ordinary citizen.
Respectfully,
Anomaly
But Herr Heisenberg, how does the electron know when I'm looking?
You seem to be held in rather high regard by the nerd community, much like Robin Hood. And just like Robin Hood, there's more myth than truth behind it.
Robin Hood stories are full of daring adventure, inhuman skill with a bow, and the addage of 'robbing the rich to give to the poor'. However, history tells us that if in fact he existed, he was another common thief who mugged women and kept the proceeds for himself.
In much the same way, there are tales of you sitting up all night, technically brilliant, controlling the machines from the inside in. But the truth tells us you sat on the phone like any other con man tricking people into revealing their passwords. And like Robin Hood, you kept the proceeds for yourself. Whether or not you did anything with them is irrelevant.
So why should anyone care who you are, what you think, or give you any more breaks than the next ex-con?
I don't need no instructions to know how to rock!!!!
Programming is largely like riding a bicycle. Once you understand the logic constructs, you rarely tend to forget them. Especially if you are a hacker genius.
However, learning to program in a particular language can take a day or two to learn the new syntax, but the basic programming memes are usually the same (OOP, for-loops, etc.).
Learning how to program in general is different than learning how to program in a particular language.
He who laughs last is stuck in a time dilation bubble.
"player 4 hit player 1 with 0 stroms"
Since this is slashdot and since Open Source and Linux are more our concern here, shouldn't the question be:
"What are the ten worst Linux vulnerabilities to hacking, how would you attack such systems, and what has to be done with Linux to prevent such vulnerabilities?"
Surely you don't actually believe that Linux is unhackable? Wouldn't finding out what Linux's weakest areas are and fixing them before Linux becomes widspread enough on "Dumb User" hardware that it becomes the next great hacking target?
Contrary to popular belief, coding is not all free blow-jobs and beer. Those things cost MONEY!
Would you want kids growing up to want to emulate you? (I don't mean in software)
What do you say to kids who think you're cool?
Get off my launchpad!
You've mentioned in many capacities (your book, interviews on TV) that the law changed during your "big run," outlawing your activities. Yet, you continued to do what you did, and you were aware of the newer laws. If the law had outlawed what you were up to before you started, would you have gone through with what you've done?
The One Rule Of Chess You'll Ever Need: Don't play someone who carries a kit in their bookbag.
Welcome back. Things have changed a lot in the last 8 years. People with your kind of skills are becoming rarer while the number of people that commit on line "crimes" has increased.
The hot issue for many of us concerns the idea of Fair Use, copyright, and copyright enforcment. Government regulations have been changed and are changing in favor of the same kinds of large corporations that claimed huge damages against you during your less than ideal experiance with the Judidical System.
My question is this. What are your thoughts on the continued expansion of corporate copyright enforcement rights, including the legalization of some of the techniques you were convicted of using?
Do you trust corporate america to weild the tools you've used and helped pioneer and what if any regulation do you consider both accecptable and feasable?
Killfile(TGK)
No trees were killed in the creation of this post. However, many electrons were inconvenienced.
I don't have any mod points but I'd like to add my two cents in on this question. What kind of answer exactly do you expect? He has no frame of reference (he's never been on the Internet as we know it) so how can he make a decent comparison?
I think the question, in general, is a good one, but I don't think Mr. Mitnick will be able to give an insightful answer.
If you believe in legalisation, then do promote that guy -- he was doing the right thing (and perhaps breaking the law, the two aren't always the same).
Although the circumstances/topics are different, the logic is akin to Ghandi, Martin Luther King Jr., and many other people who try to do what is right.
Henry David Thoreau talks about this type of stuff in Civil Disobedience (quoted below)
Unjust laws exist: shall we be content to obey them, or shall we endeavor to amend them, and obey them until we have succeeded, or shall we transgress them at once? Men, generally, under such a government as this, think that they ought to wait until they have persuaded the majority to alter them. They think that, if they should resist, the remedy would be worse than the evil. But it is the fault of the government itself that the remedy is worse than the evil. It makes it worse. Why is it not more apt to anticipate and provide for reform? Why does it not cherish its wise minority? Why does it cry and resist before it is hurt? Why does it not encourage its citizens to put out its faults, and do better than it would have them? Why does it always crucify Christ and excommunicate Copernicus and Luther, and pronounce Washington and Franklin rebels?
One would think, that a deliberate and practical denial of its authority was the only offense never contemplated by its government; else, why has it not assigned its definite, its suitable and proportionate, penalty? If a man who has no property refuses but once to earn nine shillings for the State, he is put in prison for a period unlimited by any law that I know, and determined only by the discretion of those who put him there; but if he should steal ninety times nine shillings from the State, he is soon permitted to go at large again.
If the injustice is part of the necessary friction of the machine of government, let it go, let it go: perchance it will wear smooth--certainly the machine will wear out. If the injustice has a spring, or a pulley, or a rope, or a crank, exclusively for itself, then perhaps you may consider whether the remedy will not be worse than the evil; but if it is of such a nature that it requires you to be the agent of injustice to another, then I say, break the law. Let your life be a counter-friction to stop the machine. What I have to do is to see, at any rate, that I do not lend myself to the wrong which I condemn.
there is no thing
what else could you want?
Good at? You've got to be kidding!
I suppose the Rosenberg's were good spys and Dahmer was a good serial killer too huh?
In Mitnick's "line of work" as it were, being good means NOT getting caught.
I honestly don't see why so many people like us lift Mitnick up to some hero-like status. He was dumb. He wasn't a good hacker, and what he did hack he handled really stupidly. And that's what got him caught, plain and simple. He's now going to make a living on his name.
"A terrorist is someone who has a bomb but doesn't have an air force." -William Blum
I don't think that Mitnick has ever suggested that he didn't deserve to be punished or that he didn't break the law in some way. The issue is with the way he was handled by the justice system and those companies. Both wanting to make an example out of him, the handling was disproportionate to the crime.
Mitnick has knowledge and skills that will make him a productive part of society. The area he's promoting himself in is a legitimate legal business so why shouldn't we get behind him and support him. This would constitute a "regular job" - unless you mean flipping burgers or selling clothes at the gap, or maybe insurance salesperson. There are plenty of former criminals in areas of expertise that relate directly to their original crimes. Their knowledge is often very helpful in stopping future crimes and in showing how people can reform and rebuild their lives after having made mistakes.
Mitnick served out the punishment given by the state and now he should be allowed to live his life unencumbered by that "criminal" title. This includes seeking ANY gainful employment he can find.
I feel that society does have an obligation to help people who we've allowed to be mistreated.
The problem with the justice system today is:
1. They bend a little too much to the corporate will.
2. Punishment is never really centered around "correction" even though people are remanded to the "Department of Corrections".
3. There's no procedure for quick and fair correction of mistakes (i.e. false imprisonment, misshandling, etc.) Most compensation has to be gained via lawsuit. False judgements can stay with a person for life, damaging not only their mental health but their future job prospects and personal relationships.
4. Too much stock is put into conviction rates and not enough in to quality of prosecution and/or honesty in prosecution.
5. Justices allow stretching the word and spirit of the law in order to help prosecutions of people not exactly covered under existing laws. I.E. Some people get prosecuted under RICO when their crime has nothing to do with it.
6. Prosecutors withholding charges in order to pursue additional charges should they lose in the first round - an attempt to circumvent double jeopardy rules. (i.e. I murder someone during a robbery - the evidence is fairly thin, so I'm prosecuted for Murder (alone). When I'm acquitted the prosecution charges on attempted robbery, weapons charges or one of the many other charges that they can dig out that might have stronger evidence. The possibility of prosecution might loom for years, along with the stigma of "suspect".)
7. The ability to punish/pursue a suspect through (ab)use of the media. ("person of interest"). Placing pressure on a subject via media "leaks" or press releases that lead the public to believe certain things about a person. While not exactly lies we all know that it's the prosecution using the media to manipulate the public against a SUSPECTED criminal. (defense and prosecution should be barred (ethics) from using the media as a tool against the other side.) Remember INNOCENT UNTIL PROVEN GUILTY.
"Do not be swept up in the momentum of mediocrity." - anon
It's been agreed upon by yourself and others that what you did was wrong but the punishment did not fit the crime.
With more and more people getting caught up in the 'hacker = terrorist' retoric of late, especially those in high places, changing minds is more important than ever. I shudder to think of what would happen if your activities had occured a few years later (that whole 'whistle launch codes into a phone' thing...).
What do you think is the most important thing that the hacker community should do to make sure that cases like yours don't occur again, and that cases involving computer crime are treated fairly and not trumped up to terrorism?
Where are we going, and why are we in this hand cart?
Criminals typically think all the charges laid against them are unfair.
If you can't see the value in jet powered ants you should turn in your nerd card. - Dunbal (464142)
Ahhh, I see. So those that do get punished should not be punished because some others are not???? Shouldn't we be demanding that the others be punished, not demanding ( back in the day) that the US "Free Kevin?"
Similarly, I was wondering if you found any *real* downsides to not being online. Aside from entertainment value and consulting wages, is there anything you found truly crippling about the experience? Could mankind survive in a disconnected world? Do we need to provide internet access for the less fortunate with taxpayer money because it's a basic necessity like a phone?
Of course he couldn't start WW II by whistling into a telephone ... for crying out loud! Please don't send this question to Mitnick, it will only confirm to him the utter ignorance of /.
Kevin, what I've asked myself: after all those years in jail - haven't you thought of leaving the country ?
Just calling it quits an moving somewhere else ?
I've only loosely followed your case (and the related civil liberties problems in the USA) since I first heard of it in c.a. 1997, but judging from todays "status quo", I can say that it hasn't improved at all.
Windows 2000 - from the guys who brought us edlin
The government had access to all the records that Mitnick could have used for his defense, but they arbitrarily withheld the records indefinitely. Each six months Mitnick was given the choice of going to trial with an unprepared defense and some crappy government lawyer with no access to the records necessary to prove his innoccence, or to sign a waiver allowing the government to delay the trial for another 6 months while he stayed in jail. In other words, they were just trying to fuck with him untile he broke, gave in, and pleaded guilty. They never had any intention of giving him a fair trial. It was a total mockery of the legal system and a travesty of justice.
Repeal the DMCA!
My question is:
Does crime pay? Specifically, your crimes.
Seriously, it's people who set up critical system in such a way that their functionality can be influenced from a network designed for research and entertainment that should be charged with manslaughter. If a script kiddie tried to split IRC network and people died because of that, s\he should be just given grief counseling and not charged with anything.
On the other hand, people who purposely break car or air traffic control should of course be responsible. But someone maintaining a critical computer should first make sure that it can not be shut down accidentaly and provide ample warnings to potential tresspassers on why it should be left alone. It wouldn't do to have an obvious, conviniently located self-destruct switch. Or forward any packets from the Internet without strong encryption, if that.
Hmm... I don't remember all the facts. Is there any evidence that Kevin purposly tried to cause serious harm? Or that he even broke into any systems that did critical real-time control? I thought he was just addicted to getting control of a system, stashing away source code and so on. If you get down to basics of human motivation, real hacking is just another kind of science. Like Indiana Jones style of archeology. Risky, annoying, controversial but ultimately an unavoidable consequence of human curiosity.