A Look Into the Chinese Hacker Underworld
beachels416 writes "The NY Times gained access to a Chinese hacker-for-profit, referred to as 'Majia,' and observed him during one of his nightly 'sessions.' From the article: 'Oddly, Majia said his parents did not know that he was hacking at night [hacking is illegal in China]. But at one point, he explained the intricacies of computer hacking and stealing data while his mother stood nearby, listening silently, while offering a guest oranges and candy.' At another point Majia spoke about the recent Google attacks, and claimed to have particular knowledge of the exact vector used. Nothing too new, but an interesting read nevertheless."
To sum up the article for those too lazy to read it
A chinese guy works a day job, works as a hacker at night. Likes to stay anonymous and take money from people's bank accounts.
I guess the fact that this is a chinese guy is shocking to some new york times readers?
The article highlights two important facts
1. Fun
2. Profitable
It's been a long time since I broke into my grade school's soda/chips/candy closet from a skylight on the roof. Sitting there drinking soda and enjoying chips, I can clearly remember how exciting (breaking in) and rewarding (chips/soda) it was. Later, I learned to respect other people's property.
So what now? ... expect the back doors to be open and the cargo gone. It's very exciting - it's very rewarding. Is it wrong - sure. Are the thieves the ones to blame - no. Not exactly. The thieves are not the ones to blame - the thieves are to be expected. It's an ongoing game where we square off with human nature - make it furn for the security side - keep building better mouse traps. Don't like this perspective? Ok - change human nature then. Good luck.
If you park a trailer in an accessible area
L'esperienza de questa dolce vita (The experience of this sweet life) - Dante Alighieri, The Divine Comedy
cracking is illegal in any civilized country. I am pretty sure that if he spends nights hacking, Chinese authorities won't put him in jail unless he tries to hack something in order to circumvent their controls.
I guess the NYT needs to attach a disclaimer to the story, because whenever a journalist tries to interview a "hacker" I can't decide to laugh or cry. Something like this would do nicely:
It takes a man to suffer ignorance and smile
Be yourself no matter what they say
I didn't see anything in the article about hacking. It all looked like cracking to me.
-- "In order to have power, I must be taken seriously." -Mojo Jojo
I guess plenty of Slashdotters learned a bit about computing from minor cracks - almost everyone has changed a save game file with a text or hex editor. Insecure network shares at your school network. Getting your neighbors' insecure Wifi passwords, someone probably thinks MAC filtering alone is safe. Modifying Flash games to give yourself 2^31 - 1 points on the high score board. Getting root on random poorly secured UNIX terminals in tech expos. Getting into someone else's IIS and read his local files via the canonical path bug many years ago. etc.
Sure it's not healthy if all you do are these minor thing and you keep doing these stuff for years. But it's a good inlet for kids to learn computing nevertheless.
Why is this guy living with his mom if he's such a great and skilled hacker? Where's his money? Where's his grandiose lifestyle? What is he doing with all those computers he's woven into a bot-net? If he's making all that money, why isn't he spending it?
I wonder if we're making the Chinese Dragon out to be far more fearsome than it actually is. Why exactly should I be afraid of him, and all his Chinese brethren? Yes, they can hack, yes they can start and fight a cyber-war. But I am underwhelmed by their power if all they do is sit there day after day, coding, hacking, "making money", and not doing anything with it. And if they do eventually start and fight a cyber war, then they will end up losing the only medium that gives their life meaning. What happens to these guys when we counter-strike (because I refuse to believe that my fellow Western neckbeards would take a cyber-ass-whuppin' from the Chinese lying down)? When their networks go down and their computers are infected or taken out, what then? I can get up and leave my computer. Can they?
I'm a naive bumpkin most likely, I just fail to see how these guys are so formidable. Pathetic is more like it, like a boxer with a glass jaw. Their greatest strength is actually their weakness.
Here's to hot beer, cold women, and Glaswegian kisses for all.
The journalist is only writing to their audience. Just because you do not fit into this audience does not make the article any less valid. The target audience does not want to hear about the technical details of the process, they just want an overview, concentrating on the human side of the issue. (The sense of superiority among some people with technical knowledge is really astounding.)
Oddly, Majia said his parents did not know that he was hacking at night [hacking is illegal in China].
His parents know. If he hacks for money, is up late at night fiddling with computers all the time, and talks about hacking with unusual guests right in front of his mom, she knows what is going on. This is a mother with traditional, conservative beliefs who does not want to be rude and is reluctant to admit that her son is a criminal, so she ignores the entire situation. Not that unusual, and not indicative of some strange counter cultural underworld that is unique to China. Though I'm sure my folks and my friends' parents all thought our blue boxes, black boxes, and mobile (as in, in a car) collections of computers and cordless phones were all for educational purposes back in the day, and the 2600 meetings were just to hang out and drink coffee, since that's what we told them.
This is a hacked account, for which the owner can not be held responsible.