Man Hacks 911 System, Sends SWAT on Bogus Raid
An anonymous reader writes "The Orange County Register reports that a 19 year old from Washington state broke into the Orange County California 911 emergency system. He randomly selected the name and address of a Lake Forest, California couple and electronically transferred false information into the 911 system. The Orange County California Sheriff's Department's Special Weapons and Tactics Team was immediately sent to the home of a couple with two sleeping toddlers. The SWAT team handcuffed the husband and wife before deciding it was a prank. Says the article, 'Other law enforcement agencies have seen similar breaches into their 911 systems as part of a trend picked up by computer hackers in the nation called "SWATting"'"
I'm really naive about security, so I can't understand how these security breaches happen time and time again. If these systems were web based, or offering some kind of web or internet service which necessitated having open TCP ports I'd find this easier to understand. Why is it that ordinary office systems (and bespoke Command and Control Systems), and documents sitting on file servers behind corporate firewalls, with no direct connection to the outside world are always so vulnerable? Surely it's possible to run an internal network (ethernet or whatever) in such a way as to make it completely inaccessible from the outside world, while running an email and web gateway?
"It's a pretty harrowing experience for the innocent victim but at least it was just a prank."
It's all fun and games until someone gets shot for resisting arrest?
"Sure, SWAT is trained not to shoot first and ask questions later, "
I'm afraid that I'd have to disagree with this. At least compared with normal officers, SWAT is indeed trained to shoot first.
This can be considered acceptable if SWAT usage is restricted to high risk situations, where not using these tactics is likely to result in more deaths, but some areas have them serving most of the warrents - even on unarmed, non-violent dentists moonlighting as bookies.
I don't read AC A human right
I think if we are going to talk about ultimate responsibility it is with the developers and vendor of the software. They failed to write secure software for a mission critical system. Their failure was a lack of foresight, testing or both. Personally I am surprised that on slashdot where ripping vedors security seems to be a hobby that the fingers weren't pointed in this direction first post. It was the brains at the start of the process that failed, not the brawn at the end of it.
Users... the only thing keeping 1st level support from being the bottom feeders.
I think this guy said it well:
The libertarian solution to the failures of capitalism is to apply more capitalism til the failures are fixed.