Hackers Not Afraid of Being Caught
An anonymous reader wrote in to point us to an interview with Honeynet Founder Lance Spitzner where he says "Years ago it was hackers who were doing it for the bragging rights, now it's the criminals. The motivation has changed, hacking is now profitable and there's so much money to be made with very little risk to the actual hackers."
Of course hacking is profitable -- the laws of supply and demand cover this as any service or product. The laws making hacking illegal only add more gold to the pot. For acts considered criminal, the value to the service provider will still meet what the market dictates. In this case, the chance of getting caught is low, so hacking might not be as profitable as selling pot, but it also depends on the demand. If hackers are making money, that means there is a demand for their service. If only a few hackers are willing to take the risk, a high demand and low supply of service providers means a high cost/profit. That's the nature of the free market.
Yet I don't think this profit will necessarily last forever -- even if laws change to make it easier to catch a hacker and even if the penalties are raised. The Internet is global, not local. With more third party countries gaining Internet access and more people willing to invest the time to learn to hack, I believe hackers will find their jobs outsourced as quickly as call centers and web developers have. So what?
The State will write laws to defend against hacking, but the reality is that the free market will provide better defense. There are laws against breaking and entering, but do they work? No, locks do. In situations where locks don't work, alarms work. In situations where alarms aren't enough, a Colt 45 used once usually fixes that situation. The law has almost no effect on crime other than raising the profit for those willing to take the risk. Hackers make a profit only means that anti-hackers have a new business opportunity -- and if you're good with security, you should make a windfall NOW before the law interferes with YOUR ability to secure your clients. Regulations against hacking might harm you more than they harm the "criminals."
Take advantage of this business opportunity today -- on either side of the "battle."
Hackers can think whatever they want. The real problem right now is that the governments of the countries they live in don't care and don't do anything about it. Perhaps that's understandable since many of those countries have enough non-tech issues to deal with already. But I think that if that's the case, they just shouldn't be allowed on the internet yet. There really needs to be a bar for entry. I can't tell you how many applications we get for people using stolen credit card numbers and coming from IPs in Africa, Indonesia, etc. Fortunately, we check applications by hand and weed those out. But many hosting companies probably just accept them and create accounts, opening their systems to escalated privlige attacks.
I'm surprised we haven't started seeing vigilantes tracking down hackers and spammers. When governments can't handle things, the mob takes over.
Being a hacker is not a punishable offense. If criminals are using so-called "hacker" skills in criminal pursuits, they're still criminals. Call them criminals.
I'd expect the OMG SCARY word "hacker" to be misused like this in Hollywood films and mainstream news, but not on Slashdot of all places.
Slashdot Burying Stories About Slashdot Media Owned
I'd have to say I share the same philosophy as you. While I have 'hacker' roots and a 'hacker' mindset, that doesn't mean I break into things that aren't mine and break laws. Not to say I couldn't, I just don't care to. Even when I was younger and some of the things I did to learn and experiement may have been questionable, I would have never done it for anyone else, it was all for my personal desire to learn, not a financial motivation.
In a world of acronyms, the words are the real victims.
unfortunately, that desire to simply LEARN is what has slipped away and given rise to the new definition of the term hacker.
A true hacker desires KNOWLEDGE. Not power, not finances, KNOWLEDGE. That is the hacker's reward.
Not retarded WinNuke attacks (showing my age slightly), not stealing identities, not peeking at your hard drive...knowledge. The knowledge of how things work, why they work, what DOESN'T work, and what can be done to make them work BETTER.
Living With a Nerd
When it comes to (criminal) hacking, or any other illegal activity, the smart perp will consider the risk-reward of his behavior. Unless the potential payoff of a crime is significant, it simply does not make good economic sense to do it.
This is a common perspective, but there is another motivation that comes into play. Most people are bound mostly by moral reasons to not commit crimes. What is interesting with computer crimes is they could easily have been a predicted consequence of globalization. Crime correlates strongly with wealth disparity. This speaks to both the risk/reward you mention and the ability of criminals to justify their behavior to themselves. Opening up the global market brings people with vast wealth disparity into the same arena. It would be surprising if a hacker in some poor country did not turn to crime which can pay him a year's salary in a day for a low risk crime and at the same time be robbing those fat Americans and Europeans born into extreme luxury while they have had to work long hours just to feed themselves.
Quite frankly, I don't understand why there is almost no active lobbying for harsh laws towards hacking. Just think about it - When launching an online server, be it an an application server , gaming or communication server , a hosting service or a website - what is your most major concern after the development is over(even if the development was done with it in mind )?
Security. The FEAR of getting your server hacked pretty much doubles the development cycle, and is around 70% of the patches and fixes issued after it is launched. It's retarded that not having enough security = invitation for being hacked. Sleeping with the windows (no pun intended) open and getting a "I walked around your house and took a shower, don't forget to close your windows tomorrow night" letter on the next morning in case of a white hat or "I stole your stereo and PS2, why the fuck you left the windows open" in case of a black hat, is how the internet works these days, and it needs a major fix.
My Starcraft 2 Blog
Welcome to the real world: words change meanings continuously. "Thing" once meant a council meeting (waay back in the norse times), now it mean, well, "thing". "Gay" once meant cheerful/happy, then it meant "homosexual", and now it's in the middle of becoming just "uncool". Etc.
That's how we ended up with so many languages. As a species we have a sort of a "Babel tower" mechanism built in. Get two communities isolated for long enough, and even starting from the same language you end up with two new languages or dialects. Each of the two changed words independently, and eventually you end up with the whole language of each not even resembling the language of the other. (Don't believe me? English and Greek both evolved from the same Indo-European roots.)
People hear some cool new word, or a new way to use an existing word, or some wisecrack and latch to it. And if it gets enough followers, there you go, you have a new word or a new meaning for a word.
Some cool kid uses, say, "twink" in a MMO once for someone buffed or equipped beyond the means of a normal player that level. Some people hear it, like it, and start using it too. Repeat a few iterations, and next thing you know it becomes the new primary meaning of that word in relation to MMOs.
And so it was with "hacker" too. Except this time it was also boosted by a whole generation of clueless journalists, who promptly bombarded everyone with their new meaning. Everyone has had it hammered into their heads that "hacker" doesn't mean the old-style "guy who really likes computers and doing amazingly hard/low-level stuff", but, yes, basically "high tech criminal".
As early as the end of the 90's I've had the surprise to hear even computer engineers using it that way. Yes, literally. I was for example at some training back then and the guy teaching goes, "anyone knows what a 'hacker' is?" Me: "Someone who really loves computers and programming?" Him: "Nope, a criminal breaking into other people's computers." Go figure.
So, way I figure it, we might as well let go. That battle is lost, and we don't even have the means to fight it. For every time you tell someone "no, no, no, 'hacker' was never supposed to mean 'criminal'", they'll promptly have a dozen TV show hosts, pseudo-tech journos, etc, hammering the opposite right back into them. That word is lost. By now it's not just "mis-used", it simply _is_ the new meaning of the word.
Give up, move on, find another one.
A polar bear is a cartesian bear after a coordinate transform.