Slashdot Mirror


The Hacker Who Found the Secrets of the Next Xbox and PlayStation

An anonymous reader writes "Stephen Totilo at Kotaku has a long article detailing the exploits of an Australian hacker who calls himself SuperDaE. He managed to break into networks at Microsoft, Sony, and Epic Games, from which he retrieved information about the PS4 and next-gen Xbox 'Durango' (which turned out to be correct), and he even secured developer hardware for Durango itself. He uncovered security holes at Epic, but notified the company rather than exploiting them. He claims to have done the same with Microsoft. He hasn't done any damage or facilitated piracy with the access he's had, but simply breaching the security of those companies was enough to get the U.S. FBI to convince Australian authorities to raid his house and confiscate his belongings. In an age where many tech-related 'sources' are just empty claims, a lot of this guy's information has checked out. The article describes both SuperDaE's activities and a journalist's efforts to verify his claims."

214 comments

  1. Sort of interesting, but... by Frosty+Piss · · Score: 5, Insightful

    In an age where many tech-related 'sources' are just empty claims, a lot of this guy's information has checked out.

    And he still broke into other people's networks without permission. But I suppose that's OK here since the private info that he released was of interest to Slashdotters and was "accurate"? It was OK because the victims where Microsoft and Sony? Or, shall we see another case of the famous Slashdot Double Standard?

    --
    If you want news from today, you have to come back tomorrow.
    1. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      There seems to be an implied whiny he's-a-hero-not-a-criminal, but it is not explicit. I choose to pretend that the OP is not a brainless moron, and that the implications were unintended.

    2. Re:Sort of interesting, but... by Mitreya · · Score: 5, Interesting

      And he still broke into other people's networks without permission. But I suppose that's OK here since the private info that he released was of interest to Slashdotters and was "accurate"?

      It may be ok to a degree for the cases where he broke in and then notified the company of a breach (without doing any damage or requesting a payment)
      Companies should be required by law not to pursue anyone who notified them of security holes in good faith. Instead they choose to harass such people, scaring them off and making MY data less secure.

    3. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      He's acting moral in one sense and expecting that to shield him against his other immoral actions. He is in the wrong.

      I'm no apologist for the police. I know they often have disproportional responses. But it's not clear to me that his home was "raided". Executing a search warrant is not a raid per se.

    4. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      I am sorry if you cannot understand the fallible beliefs of slashdot, maybe you should venture to a place where LOGIC and VERIFICATION are the norm as we have no need for either here.

    5. Re:Sort of interesting, but... by Frosty+Piss · · Score: 5, Insightful

      It may be ok to a degree for the cases where he broke in and then notified the company of a breach...

      Hi, I broke into your house and ran may fingers through your dainty underthings and fondled your tooth brush.

      Don't you think you should buy a better lock and maybe an alarm system?

      Don't bother thanking me, it's what I do...

      --
      If you want news from today, you have to come back tomorrow.
    6. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      How do you prove good faith?
      You can't. And because of that, it makes them a target, anyone trying to attack them, would say, we're not trying to break in and steal your data, we're just trying to improve your security.

      You know the funny bit? If he had access to the financial side of those companies, they'd be paying through the nose and begging him to keep things quiet, keeping the authorities away themselves.

    7. Re:Sort of interesting, but... by K.+S.+Kyosuke · · Score: 1

      And he still broke into other people's networks without permission.

      That's really scary. And that's just a rather neutral individual. Imagine what would happen if large institutions with agenda like FBI or CIA started doing the same thing! Oh, wait...

      --
      Ezekiel 23:20
    8. Re:Sort of interesting, but... by daremonai · · Score: 4, Funny

      Hi, I broke into your house and ran [my] fingers through your dainty underthings

      Then you've been punished enough already.

    9. Re:Sort of interesting, but... by Mashiki · · Score: 1

      If you broke into my house to stop someone from stealing my things and in turn ran your fingers through my dainty things while in the progress of stopping the commission of a crime, well we have something completely different right? In turn, someone who finds a security hole and not profiting, and disclosing privately that the issue exists should be lauded. Those that do disclose shouldn't be.

      --
      Om, nomnomnom...
    10. Re:Sort of interesting, but... by craigminah · · Score: 0

      That's kind of like me trying to rob a bank but I have a note in my pocket saying "I was just trying to verify your security was adequate" in case I get caught. WTF? Hacking is illegal no matter what the intent.

    11. Re:Sort of interesting, but... by Anonymous Coward · · Score: 1

      In an age where many tech-related 'sources' are just empty claims, a lot of this guy's information has checked out.

      And he still broke into other people's networks without permission. But I suppose that's OK here since the private info that he released was of interest to Slashdotters and was "accurate"? It was OK because the victims where Microsoft and Sony? Or, shall we see another case of the famous Slashdot Double Standard?

      Generally I'm in favour of being cautious about rewarding tossers who release malware on the net, hack and wreck systems, or in some other way wreak merry havoc and then expect fat job offers. They should not be rewarded but rather should be put in fuck-you-in-the-ass jail. But In this case I'd be wiling to compromise. If that guy really did no damage, and If I was MS, I'd compensate him for the damages done by the FBI and the Aussie cops, make him a job offer and put him to work in my security department doing destructive security testing. The CIA used to hire safe-breakers, burglars forgers and con artists to teach their agents trade-craft and probably still does so why not do something similar as long as you are not rewarding people for being complete assholes?

    12. Re:Sort of interesting, but... by Mitreya · · Score: 1

      Hi, I broke into your house and ran may fingers through your dainty underthings and fondled your tooth brush.

      Don't you think you should buy a better lock and maybe an alarm system?

      While creepy (particularly the toothbrush fondling part :), it is still preferable to waiting for an even less scrupulous person to break into your house

      I see it more as "Hi, I was passing by the street and pushing on everyone's door (for fun, it is what I do). Your door had opened when I pushed it -- you may want to fix your lock".

      This may be a tad creepy, but these people are not the problem. The ones who would quietly use this information are the problem.

    13. Re:Sort of interesting, but... by Frosty+Piss · · Score: 1

      Your scenario has little or nothing to do with the story. This guy broke into some networks and reviled business information to the public.

      --
      If you want news from today, you have to come back tomorrow.
    14. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      If a stranger broke into my house because he heard my wife screaming rape and he stopped the rapist, I'd be okay with him going into my house. He better be damn sure about what he heard, though.

      If a stranger broke into my house because he saw someone stealing my television, I wouldn't be okay with it at all. It's just a television. Stay out of my house.

      But those are really crappy analogies for what this guy did.

      This guy checked all the doors and windows, found one open, went inside, and then let the owner know about it after the fact. The only crimes being committed were being committed by him.

    15. Re:Sort of interesting, but... by cultiv8 · · Score: 1

      another case of the famous Slashdot Double Standard?

      Citation please. ;)

      --
      sysadmins and parents of newborns get the same amount of sleep.
    16. Re:Sort of interesting, but... by Anonymous Coward · · Score: 2, Insightful

      If I'm in charge of millions of people's credit card information, THANKS! You're better than dealing with hackers who would rather take that credit card information, sell it on the black market and have to deal with legal charges for failure to properly secure financial information!

    17. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      So it's ok for anybody, private individuals, commercial organizations, government agencies, to spy on everybody looking for people who plan to commit crimes. And if they can prevent a single crime through their actions they should be lauded, right?

    18. Re:Sort of interesting, but... by xstonedogx · · Score: 1, Insightful

      If you truly believe such behavior is merely "a tad creepy" and that it isn't a problem, seek professional help. I'm serious. What this guy did to these networks is way less of a problem than your disturbing analogy.

      The last time I saw someone "helpfully" checking doors in my neighborhood I called the cops. There is never a good reason to test the security of a stranger's house, or even a friend's house, unless they want you to do so. If you really care, write a damn pamphlet about home security and hand it out or mail it.

      Getting back to the network... You only have the word of someone unscrupulous that they didn't commit further unscrupulous activities.

    19. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      And he still broke into other people's networks without permission. But I suppose that's OK here since the private info that he released was of interest to Slashdotters and was "accurate"?

      It may be ok to a degree for the cases where he broke in and then notified the company of a breach (without doing any damage or requesting a payment)
        Companies should be required by law not to pursue anyone who notified them of security holes in good faith. Instead they choose to harass such people, scaring them off and making MY data less secure.

      So you want to make loopholes for criminals correct? Because thats what your short sighted and incredibly dumb "idea" would do.

      Besides. If someone kicked in your front door and rummaged through your home and when he got arrested he told you "Hey man the lock on your front door is substandard" you think the cops should just let him go free with no recourse because he tested your home security?

      I really hope you arent this damned stupid all the time.

    20. Re:Sort of interesting, but... by Stan92057 · · Score: 1

      What agenda is that ? Oh wait the catch criminals its there job.

      --
      Jack of all trades,master of none
    21. Re:Sort of interesting, but... by sycodon · · Score: 0

      Why do people cling to the perception that committing a clearly illegal act is somehow/sometimes justified for some reason?

      --
      When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
    22. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      still broke into other people's networks without permission. But I suppose that's OK here since the private info that he released was of interest to Slashdotters and was "accurate"?

      I wouldn't exactly use the word "OK" here, but I will say I don't give a shit about someone who breaks into a company just for some joyriding. It's the digital equivalent of taking a car with the keys in it for a spin around the block and then returning it. Not really criminal behaviour, but also not something that's really legal or OK.

      But then I wouldn't expect much of Slashdot to understand, since the culture around here is one of a binary right and wrong rather than any form of nuance. Bloody engineers and linear, categorical thinking. Especially when it comes to silly shit that doesn't matter, like "oh knows... someone hacked our server and didn't do anything with the data".

    23. Re:Sort of interesting, but... by Runaway1956 · · Score: 4, Insightful

      Less secure than what, exactly?

      Let's use a real world analogy. I have my house locked up tight. My neighbor says that I have cruddy, worthless locks on my door. He proceeds to show me how easy it is to break into my own house. He suggests that I invest in the same type of locks that he uses.

      So, what should I do? Call the law, and have the neighbor locked up for showing me that my security is shit?
      Or, should I purchase and install the locks that he has shown me to be effective?

      In actuality, the neighbor has helped me to be MORE secure, not less secure.

      Derp, derp, derp.

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
    24. Re:Sort of interesting, but... by Runaway1956 · · Score: 2

      I also revile business information. Revilers Unite!

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
    25. Re:Sort of interesting, but... by Luckyo · · Score: 5, Insightful

      Depends. Did he ask for your permission beforehand? If he did and you gave him OK, that's fine.

      If he didn't, he's committing a crime for obvious reasons. Else this would become a perfect excuse to burglars who didn't manage to steal YET. "But I was just showing the residents how weak their lock was!".

    26. Re:Sort of interesting, but... by Cali+Thalen · · Score: 1

      I suspect that any network admins worth their pay would be able to tell 1) if the exploit / entry method the guy was talking about was true, and 2) what he did when he got in there. If not, they have bigger problems.

      I sympathize with the views here, on both sides. Yes, this guy did something wrong, and at least in some cases seems to have been genuinely grey (if not white) hat about it. But if a system as a flaw big enough, how do you want the company to find out about it, this guy or Anonymous/Lulzsec?

      Honestly, he's in a no-win situation, and he put himself there, so it's hard to feel too sorry. But I'd hope that there would be a way for people like this to constructively use their skills, since there seems to be no end of backdoors and holes that need to be fixed. Aside from companies understanding the situation, you're taking your freedom into your own hand when you poke around like this.

      --
      Chaos, panic, disorder...my work here is done.
    27. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Information wants to be free!

    28. Re:Sort of interesting, but... by Mitreya · · Score: 1

      The last time I saw someone "helpfully" checking doors in my neighborhood I called the cops. There is never a good reason to test the security of a stranger's house, or even a friend's house, unless they want you to do so.

      I am not saying that I would encourage such behavior. But once a problem is found, I'd prefer to be notified about it (and I want the companies in question to be notified about it). There has to be a mechanism to allow this.

      Getting back to the network... You only have the word of someone unscrupulous that they didn't commit further unscrupulous activities.

      If they are not requesting anything in exchange then they are not benefiting from notifying you about the breach. You, however, DO benefit from being notified of a security breach.

      I also assume you do not take their word for it and perhaps verify that they haven't done anything untoward on your system.

    29. Re:Sort of interesting, but... by Ogive17 · · Score: 4, Insightful

      He also told you ahead of time.

      Let's say you came home and your neighbor was sitting on your couch watching tv while drinking one of your beers. Then he says "your locks suck, you should try the ones I use".

      How would you like that?

      Derp, derp, derp.

      --
      "Action without philosophy is a lethal weapon; philosophy without action is worthless."
    30. Re:Sort of interesting, but... by Truekaiser · · Score: 2

      Actually you got it half right. Right now it's okay for Companies and the government to look into your life and control it in a way he did to them, getting all your private information to make sure you're not a 'terrorist'* or to sell that information to others. It's though a high crime to do it to companies, even if they had the digital equivalent of an in plain sight open and unlocked second story window.

      *exact definition of the word will be determined by the political climate, but will always be scapegoats for real problems.

    31. Re:Sort of interesting, but... by Anonymous Coward · · Score: 1

      He wasn't just some gray-hat poking around people's networks and offering security consulting. He leaked proprietary info to the press, and fraudulently acquired an xbox dev kit in order to resell it on ebay.

    32. Re:Sort of interesting, but... by spire3661 · · Score: 1

      NO. Simply put, dont break into other people's networks, regardless of intent. It is never ok to trespass in the name of self-righteousness. Also, its not YOUR data, it is data about you.

      --
      Good-bye
    33. Re:Sort of interesting, but... by spire3661 · · Score: 1

      You have a strange perspective. IF someone random person is going around pen-testing the neighborhood, im going to have him arrested. THe problem is self-appointed idiots like this who thinks its ok to pen-test shit that does not belong to them.

      --
      Good-bye
    34. Re:Sort of interesting, but... by Runaway1956 · · Score: 1

      You're describing one of my shipmates, not my neighbors.

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
    35. Re:Sort of interesting, but... by Ardyvee · · Score: 2

      The real issue here is why we, as a society, couldn't put his skills to good, lawful use. (There is also unlawful good, but I won't go there, since what matters is the lawfulness) He seems like somebody with the skills. Why isn't he working for a security firm? Why isn't he making software more secure through lawful methods?

      To follow the physical lock analogy, instead of him going around your neighborhood checking locks/doors, why wasn't he a locksmith? A locksmith should be able to obtain access through any/most locks. He should also be able to tell the flaws of each lock and help build a more secure lock. Thus, why wasn't this guy working as a security specialist? It seems to me that not only did he fail in finding a good, lawful use to his skills, but we as a society failed to point him to those areas.

      So yes, he's probably going to get a harsh sentence. According to law, he deserves it. Instead of simply saying "it's illegal, so he gets punished", let's go a bit further: how can we turn the next guy like him that seem like a grey hat into a full fledged white hat? There is a reason ethics exist, and we use them.

      --
      I don't care if I'm wrong. I only care about everyone obtaining something from the discussion.
    36. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      In an age where many tech-related 'sources' are just empty claims, a lot of this guy's information has checked out.

      And he still broke into other people's networks without permission. But I suppose that's OK here since the private info that he released was of interest to Slashdotters and was "accurate"? It was OK because the victims where Microsoft and Sony? Or, shall we see another case of the famous Slashdot Double Standard?

      Slashdot Double Standard (colloq.), is when one visits a web site with thousands of different people all voicing their opinion, and expecting them to share one single opinion,.yet at the same time expect them to be different individuahls. Something like that.

    37. Re:Sort of interesting, but... by tlambert · · Score: 1

      Your scenario has little or nothing to do with the story. This guy broke into some networks and reviled business information to the public.

      Uh... where exactly did he criticize business information in an abusive or angrily insulting manner?

    38. Re:Sort of interesting, but... by Cassini2 · · Score: 2

      Actually, it is like having a house on a busy street with the door standing open, only you don't know it. Would you rather:
      a) Your neighbour pop in, check if you are still alive, and remind you to close the door?
      b) or just wander in and out like everyone else does on the street.

      The problem isn't that people are breaking into your house. It's that people are breaking into your house, sleeping over, and you don't know it.

      Physical property has definite levels of trespass. Walking through an open door is not trespassing in many jurisdictions. Things are way more nebulous on-line. If I can pull data from your webserver without a password, where was the closed door exactly? (People have been charged with pulling open-access data from a webserver, and it really shouldn't have been as easy as knowing which web page to call up.)

    39. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      It's entirely ok to break into Sony, what goes round, comes around.

    40. Re:Sort of interesting, but... by Maxx169 · · Score: 1

      I prefer chaotic neutral, personally.

    41. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      SuperDaE doesn't give a shit.

    42. Re:Sort of interesting, but... by Anonymous Coward · · Score: 1

      Because the world isn't black and white. Because laws are made by fallible humans. And because sometimes the ends justify the means.

    43. Re:Sort of interesting, but... by Joe_Dragon · · Score: 1

      Why isn't he working for a security firm?

      what is doing is kind of in the trade school / hands on area and HR does not like them even when people who to them know more then people in college.

    44. Re:Sort of interesting, but... by Bert64 · · Score: 1

      They harass such people because they acted in good faith and informed them.
      Malicious hackers will try to be stealthy, so they will NEVER invite dialog with their victims unless it's for purposes of extortion, and they will generally go to extreme lengths to disguise their identities, keep access to whatever systems they breached and use them to gain further access if possible.

      Someone who tries to help them by identifying a hole and helping to fix it makes themselves an easy target. Someone who is stealthy, doesn't enter into dialog and is probably located in a far away country is very difficult to prosecute if you can even find them at all.

      Of course this guy may be on questionable legal ground, but the fact is vulnerabilities were there... Is it not preferable that someone like this found them, rather than someone more malicious?

      So don't do it. Don't run the risk, instead leave any exploitable holes for real malicious criminals to find.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    45. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      That's my point. If we say that it's OK for individuals to break into computer systems, even as a white hat, we can't ask governments and companies to stop spying us. What you describe may be what's happening now, but it's not the right thing. We must stop that as well, but we won't do it by setting our own counter examples.

    46. Re:Sort of interesting, but... by sycodon · · Score: 2

      The ends rarely justifies the means.

      And while the world isn't black and white, we have processes that are set up to mitigate that fact.

      Viewing the breaking into a system, and then notifying the owners, as some kind altruistic act is at best misguided and more likely a sorry excuse for illegal behavior.

      --
      When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
    47. Re:Sort of interesting, but... by Bert64 · · Score: 4, Insightful

      The closest analogy is the spirit of the law vs the letter of the law...

      Hackers generally obey the letter of the law, that is they are only making a computer do what it was programmed to do. Wether that programming was intentional, or the result of a bug comes down to the spirit in which the program was written.

      A similar scenario is the law... There are many loopholes (ie bugs) in the law which allow people to legally perform acts which were never intended by the people who wrote those laws.

      So why then is it legal for a lawyer to exploit loopholes in the law, but not legal for a hacker to exploit loopholes in program code?

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    48. Re:Sort of interesting, but... by Bert64 · · Score: 1

      Well, if the police see someone stealing your television it's likely they too would gain access to your house in order to arrest the thief.

      Also it's unlikely a stranger would need to do any additional damage to "break" in, they could gain entry via the same means as the original thief.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    49. Re:Sort of interesting, but... by rastoboy29 · · Score: 1

      What double standard?  Good technicians are encouraged to explore the network.

      Or do we just want to let the Chinese develop good security knowledge?

      He didn't destroy anything, that's the point.

      What is wrong with you?

    50. Re:Sort of interesting, but... by Bert64 · · Score: 2

      The problem in many countries, is that while this guy has skills he may not necessarily have the paperwork to prove his skills.
      As such, companies simply won't hire him, and will never give him the chance to prove what skills he has.

      Also, if he gets convicted he will have a criminal record, which will be yet another reason why companies won't hire him.

      So the end result is that once all the dust settles, his only way of earning a living will be to use his skills for illegal purposes. And if he goes to jail, he will meet all manner of people who can introduce him to organised crime gangs who may want his services.

      --
      http://spamdecoy.net - free throwaway anonymous email - avoid spam!
    51. Re:Sort of interesting, but... by PopeRatzo · · Score: 0

      And he still broke into other people's networks without permission.

      You mean somebody broke into Sony's computers without their permission?

      Oh noes!

      It was OK because the victims where Microsoft and Sony?

      Yes.

      --
      You are welcome on my lawn.
    52. Re:Sort of interesting, but... by stevew · · Score: 1

      No - simply no. He broke in to a private network without permission That is equivalent to "Entering" of a Breaking and Entering charge in the US in a brick/mortar situation. There is not ethical difference between the two. What he did with his ill-gotten gains aren't relevant to the discussion. That is the same thing as killing someone today, then joining Amnesty International the next day?!?

      --
      Have you compiled your kernel today??
    53. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Sony and Microsoft being victims... oh poor corporations! Why doesn't anyone say that every human is a f...... victim of those or other corporations? Oh that's ok though...we are used to it!

    54. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      I think you should enjoy, just for a few years, the fun of the Cheka. Because that is exactly your mindset. And, don't bore me with the irrelevant details of economics of your American Cheka your advocate and the Russian Cheka.

      http://en.wikipedia.org/wiki/Felix_Dzerzhinsky

    55. Re:Sort of interesting, but... by VGPowerlord · · Score: 1

      Actually, it is like having a house on a busy street with the door standing open, only you don't know it. Would you rather:
      a) Your neighbour pop in, check if you are still alive, and remind you to close the door?
      b) or just wander in and out like everyone else does on the street.

      Well, we could make this a bit more like the actual scenario.

      Actually, it's like having a house at the end of a largely unused alley with the door standing open, only you don't know it. Would you rather:
      a) A random person pops in, make copies of all your private mail and computer files, then maybe tells you about it.
      b) You take the chance that someone randomly finds your open door.

      --
      GLaDOS for President 2016! "Well here we are again. It's always such a pleasure." -- GLaDOS, 2011
    56. Re:Sort of interesting, but... by Luckyo · · Score: 1

      It is not. Draw a legal comparison:

      Is it okay to lockpick all company office locks, evade security cameras using various hiding techniques, crack the safe combination using a high tech listening device with a lot of trade secrets, take photographs as evidence and then mail all of the evidence of break-in? Because that is exactly what you're doing, but through computers and networks instead of doors and corridors.

      Many people use "but it's okay for my to pick my neighbour's lock just to show him that it's weak" comparison. First of all, it's not. Second, company is NOT your neighbour. The only way to test its defences legally is to ASK PERMISSION BEFORE TESTING AND GET APPROVAL, just like a locksmith testing the above scenario would need to to be legal. Otherwise you're committing a crime. There is no grey ground here.

    57. Re:Sort of interesting, but... by TapeCutter · · Score: 4, Interesting

      Why do they feel the need for a battering ram to serve a warrant on a kid stealing plans for a toy? Why did they take his credit and bank cards and leave him without access to his own accounts? What he did was wrong but it does not warrant a jackboot response from the authorities.

      --
      And did you exchange a walk on part in the war for a lead role in a cage? - Pink Floyd.
    58. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      More likely they would surround the house and wait for the guy to come out.

    59. Re:Sort of interesting, but... by Anonymous Coward · · Score: 1

      Load of bull from you. I have been working on some VERY important piece of corporate security for a multi-billion dollar revenue corporation, which is also related to the general security of the country it operates in. It was just the "money" side of business, though. No background checks whatsoever. At least no official ones. I could have sneaked in something which would have opened the entire money palace of a dozens-of-billions enterprise. Even worse, I might have been able to compromise security of some relevant people, because their details were processed in the enterprise.

      Actually, I did this kind of thing TWICE and the biggest effort on the side of authorities was that one guy talked of "hole in the wall with a machine gun behind in TelAviv airport" to scare me a little into not doing fishy stuff. My ID card and corporate employment was sufficient to get access to crown jewels, though.

      In another function they did a secret background check on me with some interesting results, as it transpired A DECADE later. So maybe they do this all the time and just don't tell too many people. So they can also be "flexible" in their judgement. "He was a bad guy ten years ago, but we turned him. No problem".

      So, this guy will never get a legit job because he did some micro-crime ? Hilarious. In some countries you have former "terrorists"/"terror supporters" become presidents or ministers. Just check Brazil for starters.

      Guy needs to let some time go past and do open-source projects without anything fishy. Then land a highly paid job in banking, insurance IT or the like. He will only be stopped by his own smelly T-shirt or something like that.

    60. Re:Sort of interesting, but... by Max+Littlemore · · Score: 3, Insightful

      That's my concern in this. Seizing his bank access seems punitive to me and he hasn't been found guilty of anything. The alleged offenses don't even seem to warrant that action.

      I really hope his legal team can set some kind of precedent to keep a tighter leash on prosecution agencies.

      --
      I don't therefore I'm not.
    61. Re:Sort of interesting, but... by drinkypoo · · Score: 0

      It was OK because the victims where Microsoft and Sony?

      Well, yes, yes it is. Microsoft and Sony have demonstrated repeated willingness to access customers' information without their consent. Why should customers not access their information without their consent? It seems fair to me.

      Note: I'm not dumb enough to try to actually do it, but I do feel entitled.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    62. Re:Sort of interesting, but... by c0lo · · Score: 1

      Or, shall we see another case of the famous Slashdot Double Standard?

      Why not, is it forbidden? I'm looking to Washington DC and I don't see a Single Standard, even if US may benefit from having one (e.g. consider the Constitution, how many "standard" interpretation it does have?).

      --
      Questions raise, answers kill. Raise questions to stay alive.
    63. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Microsoft and Sony are not people, and they dont think about their alarmsystems - and even if they had "underthings" they could not have any feelings about someone touching those.
      Closest analogy one could bring is if someone broke into your workplace and left a note that your alarm system sucks.

    64. Re:Sort of interesting, but... by rtb61 · · Score: 1

      You are a shit head. A direct personal invasion is not the same as an internet hack of a business account. One relates to escalation which can result in bodily harm and death and the other of course is largely meaningless. M$ in this case has used it's corporate US power to escalate this beyond all reason, to a risky how invasion with some douche FBI agent threatening a minor with extradition (zip, zero, nil, nul chance, just some douche being true dick). How was the hack possible, obviously some truly piss poor security by M$.

      Now consider this was a family home and M$ and the FBI led an attack against the whole family and their technology (there you go a direct personal attack, where the attack is the punsihment the US government via the FBI intended) which they knew in majority would have nothing to do with the poorly secured information M$ lost. I am sick of psycho idiots and the pathetic mod cheerleaders comparing internet hacks to direct personal attacks. Especially where it is blatant that the direct personal attack and collective punishment against the whole family, occurred as a result of some pumped up fuckwits at M$.

      --
      Chaos - everything, everywhere, everywhen
    65. Re:Sort of interesting, but... by Dogtanian · · Score: 1

      But those are really crappy analogies

      Er, you must be new here. Stupid analogies are the lifeblood of Slashdot arguments. :-)

      --
      "Slashdot - News and Chat Sites Deviant". (Click "homepage" link above for details).
    66. Re: Sort of interesting, but... by Anonymous Coward · · Score: 0

      Just my opinion, but information shouldn't be held to the same level as physical property. I love the hacking scene. Freedom of information and disclosire is at least one thing the people have a chance at fighting for.

    67. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      It was OK because the victims where Microsoft and Sony?

      Not OK for Microsoft, but for Sony it is definitely OK.

      Sony has publicly stated breaking into anyone's computer or network is perfectly acceptable, so they have less than zero room to complain about people breaking into their network.
      You can't even say he broke into Sony's network without permission. They granted that permission when they claimed breaking into computers and networks was perfectly permissible.

      Just because the law says it is illegal does not mean it isn't OK to do, especially when the "victim" states publicly that it is OK to do so.
      If they wish to claim it is wrong, they need to finally admit THEY were wrong and issue an apology.

      However Microsoft has done no such thing, so one can only assume Microsoft agrees with the law as-is and does not want others breaking into their network. It's safe to say that was wrong.

    68. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      In the past reporters that did this kind of investigative journalism were lauded.

      Today, the FBI's corporate overlords frown upon anything remotely similar to the age old practice.

      They didn't secure their borders, he got in, got some info, exposed the non dangerous info, enlightened the corporations as to their vulnerabilities while giving the corporations free publicity.

      Win-Win-Win!! So why were the FBI involved? Oh yeah, cuz they're owned by the corporations and must investigate when corporations are too lazy to properly secure their networks.

      Nothing was stolen, no real laws were broken and the companies got free technical support... WTF?

      FBI - get your mits off this guy, he didn't do anything wrong.

    69. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Corporations aren't people, they are supposed to have the best locks already.

      When the corporations are lax / lazy, then yes, by all means this should be shoved in their faces in as public a manner as possible.

      Preferably with proof that is incontrovertible that the hack occurred. Hence the info on the next gen platforms.

      It's called white hat hacking, and is not illegal. Not by any means. This craptastic law that the AG likes to use needs to be removed from the books and the AG and staff sent to gitmo for murdering and criminally harassing people who did nothing wrong.

    70. Re:Sort of interesting, but... by Gadget_Guy · · Score: 0

      I don't see the problem with that. For all the authorities know, he stole the information to sell to the highest bidder. It doesn't seem like an unusual measure to take in hacking cases. You might try to play down the hacking offense by calling him a "kid" and saying that it was just "plans for a toy", but this is a billion dollar business here. And who knows what other offenses could be uncoverred during the course of the investigation.

      It should be up to the courts to decide whether this deserves just a slap on the wrist. Until that time, it should be treated seriously.

    71. Re:Sort of interesting, but... by bogie · · Score: 2

      "It should be up to the courts to decide whether this deserves just a slap on the wrist. Until that time, it should be treated seriously."

      No, he should be treated innocent UNTIL proven guilty in a court. That mean bail unless he is a flight risk or danger to the public at large. Also it does not mean freezing his bank accounts.

      --
      If you wanna get rich, you know that payback is a bitch
    72. Re:Sort of interesting, but... by Mashiki · · Score: 2

      Why do people cling to the perception that committing a clearly illegal act is somehow/sometimes justified for some reason?

      Short answer? Sometimes a single person committing a single illegal act, and 'saving face' for someone else. Is better in the long run than an issue existing and 300 people using the same breach a few months down the road. There are reasonable expectation in case law at least in my country on such things. Both in things relating to physical property, and to computer crime.

      --
      Om, nomnomnom...
    73. Re: Sort of interesting, but... by Anonymous Coward · · Score: 0

      This. I guarantee that the action taken by the FBI and the austrailian authorities was not of their own volition.

    74. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Where's the bit in your analogy that is analogous to where he obtained documents relating to Orbis and Durango which he then disseminated (at least to a reporter and apparently to several other 'hacker friends')? Or where he gained access to pre-release hardware and then tried to sell it?

    75. Re:Sort of interesting, but... by sycodon · · Score: 0

      The analogy to the "open house door" is that these people would be going door to door, checking the locks for any house the is unlocked.

      Someone doing that is not being altruistic. They are deliberately trying to break in and when they can, they take pictures and sometimes steal stuff and then claim they were only protecting you.

      Better that people caught breaking into homes be shot by the owners.

      --
      When Fascism comes to America, it will call itself Anti-Fascism, and tell you to give up your guns.
    76. Re:Sort of interesting, but... by Gadget_Guy · · Score: 1

      No, he should be treated innocent UNTIL proven guilty in a court. That mean bail unless he is a flight risk or danger to the public at large. Also it does not mean freezing his bank accounts.

      You might think that it means freezing bank accounts is not allowed, but the law does not agree. Considering that he was apparently in cahoots with at least one other person overseas, they really don't want to allow him to transfer any proceeds of crime offshore.

    77. Re:Sort of interesting, but... by kelemvor4 · · Score: 1

      What double standard? Good technicians are encouraged to explore the network. Or do we just want to let the Chinese develop good security knowledge? He didn't destroy anything, that's the point. What is wrong with you?

      Good technicians who are employed to explore a network are encouraged to do it. That's about as far as it goes in reality.

    78. Re:Sort of interesting, but... by shentino · · Score: 1

      Civil forfeiture is wonderful isn't it?

    79. Re:Sort of interesting, but... by shentino · · Score: 2

      Trespassing online is whatever a big corporation with an army of lawyers says it is.

    80. Re:Sort of interesting, but... by wallsg · · Score: 1

      The closest analogy is the spirit of the law vs the letter of the law...

      Hackers generally obey the letter of the law, that is they are only making a computer do what it was programmed to do. Wether that programming was intentional, or the result of a bug comes down to the spirit in which the program was written.

      A similar scenario is the law... There are many loopholes (ie bugs) in the law which allow people to legally perform acts which were never intended by the people who wrote those laws.

      No, the hacker isn't obeying either the spirit or the letter of a law that prohibits unauthorized access to a computer system or network. He's exploiting weakness in systems to, at the very least trespass. If he breaks in, does no damage (and yes, copying business data to sell or release publicly is damage), and notifies the company then it's questionable that he should be prosecuted.

      Instead of your lawyer analogy though, a much better one is a burglar who, using the weaknesses inherent in a mechanical lock, picks said lock and then enters your house, makes copies of all of your credit cards and papers/data (and destroys them if he wants to be malicious), posts hidden cameras throughout your house, and sabotages the lock on the back door or window so that he has easier access in the future.

    81. Re:Sort of interesting, but... by wallsg · · Score: 1

      Well, we could make this a bit more like the actual scenario.

      Actually, it's like having a house at the end of a largely unused alley with the door standing open, only you don't know it. Would you rather:
      a) A random person pops in, make copies of all your private mail and computer files, then maybe tells you about it.
      b) You take the chance that someone randomly finds your open door.

      How about making it really realistic?

      You have a door on the house secured with a faulty lock. The lock looks like it's secure but if you know what you're doing it's trivial to open.

      BTW, I have told my neighbor about his open garage door after dark. I went to his front door and rang his door bell. I didn't go into his house through his garage.

    82. Re:Sort of interesting, but... by Anonymous Coward · · Score: 1

      I don't think you understand the meaning of the word "analogy".
      If something is analogous to breaking the law, it is not necessarily illegal. It's just analogous to breaking the law.

    83. Re:Sort of interesting, but... by TemperedAlchemist · · Score: 1

      So if I notice that the gate around an industrial complex has a security flaw, sneak in, sneak back out and tell you about it, then I should have my bank account seized and have my house raided?

    84. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      I hope he makes the argument in any appearance, that he stands unequal at law, and demands the same amount of cash returned as the other side has spent , including what the FBI spent to date. And that no evidence is illegally exported (megaupload).

    85. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Yes, because everything should be just divided evenly, even when the conditions aren't even, right? What an idiot.

    86. Re:Sort of interesting, but... by DKlineburg · · Score: 1

      I am not saying that I would encourage such behavior. But once a problem is found, I'd prefer to be notified about it (and I want the companies in question to be notified about it). There has to be a mechanism to allow this.

      I think this stands out to me most. I have to agree that yeah, you are being dishonest for doing it. But telling someone should be ok. IF however, when your admin does his check finds you did steal the kitchen sink, it isn't as ok. I will say however, he only REALLY did that with epic, and only when drunk. He only talked to MSFT when they found him. There is a lot of things he did like leak specs would be doing what is wrong. So sadly, he did enough to deserve some of this. The degree is debatable IMHO.

      --
      Memory is deceptive because it is colored by today's events. - Albert Einstein
    87. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Most likely because the real people who do this aren't noticed. Well at least in the US it seems. I don't have skills near him I'm sure, but I don't have a BS so I might as well be a rock. According to US companies that is.

    88. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      allow people to legally perform acts which were never intended by the people who wrote those laws.

      I hope you mean "allow people to legally perform acts which were intended to be outlawed by the people who wrote those laws. Hopefully we all engage in acts every day which were not explicitly foreseen by lawmakers - for instance, I'm working on a video game.

      So why then is it legal for a lawyer to exploit loopholes in the law, but not legal for a hacker to exploit loopholes in program code?

      Seriously? Of course it's legal to exploit "loopholes" in the law. The law a priori cannot make it illegal to exploit loopholes, otherwise the loopholes would not de facto exist. The law formally cannot define what a "loophole" is. It's Godellian in nature, but only because you're applying the self-reflexivity yourself by applying the word "legal" and the word "law" in the same sentence. The very concept of "loopholes in the law" is meta to the concept of "the law" itself.

      There is a clear equivalent for programs, but it certainly does not have anything to say about legality.

      So you're saying that because the law doesn't perfectly reflect intention, therefore any other system that doesn't perfectly reflect intention should a priori be legal to exploit. That's a ridiculous argument.

    89. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Yeah, poor kid, knew perfectly well he was breaking the law but went ahead and did it anyway; released confidential information regarding a highly competitive multi-billion dollar business just because he thought it would make him cool, and then those damned agents of law enforcement did what agents of law enforcement do when the law has been broken.

      Well sorry but if this kid "just can't help" his curiosity maybe the police "just can't help" doing their thing too?

    90. Re:Sort of interesting, but... by arnodf · · Score: 1

      That's more like the neighbour breaking into your house, standing there creepily in your bedroom, only to notify you that your locks suck.

      A better analogy would be if he was looking for you to return your drill he borrowed and tried the front door which was locked so he tries the back door which isn't locked and leaves a note to tell you he was looking for you, leaves the drill on the kitchen table and that the back door was unlocked.

    91. Re:Sort of interesting, but... by Bengie · · Score: 0

      It's more like you were on vacation and gone for two weeks when your concerned neighbor called to let you know that they noticed you were gone for a while, went to check-in to make sure you were all-right, and noticed you left your door unlocked, so you called the police on them.

    92. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Innocent people don't have their property and freedom taken away.

      lol, ignorance is bliss

    93. Re:Sort of interesting, but... by Anonymous Coward · · Score: 1

      Just for fun, lets rework the GP story to fit the root story.

      I have my house locked up tight. My neighbor says that I have cruddy, worthless locks on my door. He demonstrated this by taping an advertisement for the type of lock he prefers to my left buttock while I slept last night. However, he didn't break anything and even locked the door again on his way out, so I should be thanking him.

    94. Re: Sort of interesting, but... by Anonymous Coward · · Score: 0

      IP crime is the FBI's domain.

    95. Re: Sort of interesting, but... by Anonymous Coward · · Score: 0

      And you told him to stay off your property already, derplord.

    96. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      You mean the double standard where the tards here SCREAM for net neutrality but then exclaim that botnetted Windows PCs should be identified by the ISP and cutoff the internet until the user gets the malware removed.

      Real classy, slashdot.

    97. Re: Sort of interesting, but... by Phasma+Felis · · Score: 1

      Did you also steal confidential documents in the process? You seem to be ignoring that little detail.

    98. Re:Sort of interesting, but... by Gravatron · · Score: 1

      Keep in mind, he was trying to sell secrets and dev kits to the highest bidder it seems. Freezing his accounts could be a standard response to stopping ill gotten gains from being laundered once he was found out.

    99. Re:Sort of interesting, but... by Eugriped3z · · Score: 1

      Just HOW is this INSIGHTFUL when it wasn't Slashdot that made the assessment being characterized as such?

    100. Re:Sort of interesting, but... by IndustrialComplex · · Score: 1

      I suspect that any network admins worth their pay would be able to tell 1) if the exploit / entry method the guy was talking about was true, and 2) what he did when he got in there. If not, they have bigger problems.

      The problem is that it doesn't stop at 2)

      2. Verify what he did when he got there. If he tells you what he did, then yes, you should be able to check that.

      Now comes the fun part:
      3. Prove that he didn't do anything else. This isn't easy, in fact, you are trying to prove a negative. You assume that their systems are perfectly designed to log/alert/block/etc anything additional, and that this is possible for a network admin 'worth their pay'. Let me tell you, no network admin worth their pay should assume that this is possible.

      Why would you ever assume that you would be good enough to know that addition intrusion did not occur if you know for a fact that he was already capable of defeating your public-facing security?

      This is a problem because you cannot know for certain that he did only what he claimed he did, and thus you now have to incur a cost to verify to a sufficient level of confidence that further intrusion did not occur. That is not free, and should never be assumed on the word of someone who already violated your trust.

      --
      Out of modpoints but really liked a post? 1BDkF6TtmmeZ3yqXbz9yhdYVqRYnwFoXDj
    101. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      A flaw in the design or implementation of a security measure doesn't somehow make your actions legal, or ethical. Many locks can be opened with a 'bump' key, but that won't protect you against a charge of trespassing. "Well, officer, since their lock can be bumped, I assumed that it was OK with the owners to be in here if you knew how to bump a lock!"

    102. Re: Sort of interesting, but... by cixtian · · Score: 0

      He's admitted that he committed the CRIME... He should be prepared to suffer the consequences. And innocent till proven guilty is a tenant if the American judicial. Such a concept may not have Jurisprudence inAusteailia( I don't pretend to know ). In any case he hacked the places for what ever reasons but he knew it was a crime so let him deal.

    103. Re: Sort of interesting, but... by cixtian · · Score: 1

      Yes!!! Breaking and entering is a crime and if the precident is that your accounts are seized then so be it.

    104. Re: Sort of interesting, but... by cixtian · · Score: 1

      Difference is he didn't tell you and ask if he could show you, but instead you come home and are getting naught with the wife and he's sitting on your couch, eating popcorn. He committed a crime

    105. Re: Sort of interesting, but... by Runaway1956 · · Score: 1

      That sumBITCH! I TOLD him to stay out of my popcorn!

      --
      "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
    106. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      Better that people caught breaking into homes be shot by the owners.

      Yeah because that is not an extreme overreaction at all. *rolls eyes*

    107. Re:Sort of interesting, but... by Anonymous Coward · · Score: 0

      In an age where many tech-related 'sources' are just empty claims, a lot of this guy's information has checked out.

      And he still broke into other people's networks without permission. But I suppose that's OK here since the private info that he released was of interest to Slashdotters and was "accurate"? It was OK because the victims where Microsoft and Sony? Or, shall we see another case of the famous Slashdot Double Standard?

      Mod this down. There is no double standard because you don't see Slashdotter's ever calling for the FBI to raid someone's house for anything at all. In other words, if you want to call this a double standard, show me one story where the FBI raided a corrupt developer's house, a banker's house, etc. and *then* show me the /. commenters shouting for joy.

      The only double standard here is the one held by the authorities and which crimes they choose to prosecute.

      Scumbag.

    108. Re:Sort of interesting, but... by rastoboy29 · · Score: 1

      Yes, and that may be why we end up on the ass end of history.

  2. Need to nip it in the bud by Anonymous Coward · · Score: 5, Funny

    It starts out like this, a hacker looking for the latest games, then it leads to Global Thermonuclear War.

    1. Re:Need to nip it in the bud by Anonymous Coward · · Score: 0

      Greetings, Professor Falken.

    2. Re:Need to nip it in the bud by hcs_$reboot · · Score: 1

      Shall - we - play - a - game?

      --
      Slashdot, fix the reply notifications... You won't get away with it...
  3. Exploit by Anonymous Coward · · Score: 0

    Man, if you're going to get fucked by the authorities anyway, you might as well exploit everything you can to make some money and GTFO.

    1. Re:Exploit by Anonymous Coward · · Score: 0

      Yeah, totally Bro! The government should, like, not prosecute anyone unless they murder like 5 people!

    2. Re:Exploit by Anonymous Coward · · Score: 0

      More like he should have known he was going to get prosecuted, so why hold out and white hat it?

  4. No damage? by l00sr · · Score: 1, Informative

    There seems to be this common misconception that a network can be broken into without causing any damage. Tell that to the IT department that has to re-flash and re-image every damn machine on the network to make sure no backdoors were left behind.

    1. Re:No damage? by Anonymous Coward · · Score: 0

      There seems to be this common misconception that a network can be broken into without causing any damage. Tell that to the IT department that has to re-flash and re-image every damn machine on the network to make sure no backdoors were left behind.

      Outside of some 3-letter agency, find me an IT department who actually executes said scenario, and manages to convince every single employee (including all executives) that a complete wipe and re-image of their machine is necessary within the next 12 hours. Sure this is a proper response. It's also a ludicrous one.

      Come to think of it, even 3-letter agencies don't do this shit. If they actually did, then their security audits wouldn't be so fucking piss-poor.

    2. Re:No damage? by Anonymous Coward · · Score: 1

      So, you're saying that IT shouldn't fix backdoors on their network as long as no one ever breaks in using them (that they know about)?

    3. Re:No damage? by K.+S.+Kyosuke · · Score: 5, Insightful

      There seems to be this common misconception that a network can be broken into without causing any damage. Tell that to the IT department that has to re-flash and re-image every damn machine on the network to make sure no backdoors were left behind.

      There seems to be this common misconception that having to fix a network to remove holes and backdoors is somehow worse than having lived with it for some time without knowing it Not to mention the fact that your second sentence does not substantiate the first, also known as the non sequitur fallacy: not having caused any damage and being under suspicion for having caused some are two completely independent things.

      --
      Ezekiel 23:20
    4. Re:No damage? by Anonymous Coward · · Score: 0

      by that logic, you would leave your doors unlocked because of the time it would take to ensure that each is closed and locked?

    5. Re:No damage? by Jah-Wren+Ryel · · Score: 4, Insightful

      There seems to be this common misconception that a network can be broken into without causing any damage. Tell that to the IT department that has to re-flash and re-image every damn machine on the network to make sure no backdoors were left behind.

      Those actions and associated costs are not the result of having your network broken into. They are the result of being told your network is vulnerable - even if you have no knowledge that the network was actually broken into.

      --
      When information is power, privacy is freedom.
    6. Re:No damage? by Anonymous Coward · · Score: 0

      Or the IT department can live on ignorantly after having their network hacked with countless backdoors left behind and deal with the incalculable cost of corporate espionage/sabotage for months/years/decades.

      I'll gladly take the hacker who humiliates me over the hacker that subversively drives my company into bankruptcy.

    7. Re:No damage? by lkangaroo · · Score: 1

      Guess there is a difference between your definition of "damage" and the GP's. In a business setting, any time, effort, or money that you spent, and would not have to spend if there were no breach is considered "damage".

    8. Re:No damage? by 93+Escort+Wagon · · Score: 1, Informative

      Having been through such a situation in the past - while the GP contained some hyperbole, I can tell you our guys spent a couple days checking and cleaning up after an intrusion. If you don't think there's a (necessary) significant investment of time that goes into dealing with an intrusion, you've likely never actually worked in IT.

      --
      #DeleteChrome
    9. Re:No damage? by houghi · · Score: 0

      If I am able to break into your system, you have a problem with your security.

      In Belgium there was a 'hacker' that hacked into a banking system by using the password 'pswrd'. As he just did trial and error, many did not want to call him a hacker.
      Some people thought that it was better that it was not a real hacker. For me it was worse.

      Look at it in another way:
      1) I hack your system and tell you what I have found. I might or might not have left backdoors behind.
      2) I hack your system and do NOT tell anybody. I might or might not have left backdoors behind.

      --
      Don't fight for your country, if your country does not fight for you.
    10. Re:No damage? by Anonymous Coward · · Score: 0

      The backdoors are assumed to have been installed by the hacker, they never existed had the hacker not existed.

    11. Re:No damage? by K.+S.+Kyosuke · · Score: 1

      Guess there is a difference between your definition of "damage" and the GP's. In a business setting, any time, effort, or money that you spent, and would not have to spend if there were no breach is considered "damage".

      And as long as you can make things up, any word can mean anything you want. So, to continue your line of reasoning: my dictionary tells me that "breach" can mean the same thing as "crack" or "fissure", and the hole was there before the guy got in there, so logically, they'd have to spend effort anyway.

      --
      Ezekiel 23:20
    12. Re:No damage? by Namarrgon · · Score: 2

      Your front door lock is broken, but you didn't realise it. A passer-by tells you that is broken. Do you blame him for the "damage" to your wallet that comes from fixing it?

      Or how about this: You're understandably unhappy that he pushed your door open and poked his head in. He claims he didn't take anything (and given how he volunteered the information about your door, there's no reason to disbelieve him), but are you angry at him that you now feel the need to double-check everything you own, just in case he (or someone else) took something?

      --
      Why would anyone engrave "Elbereth"?
    13. Re:No damage? by Anonymous Coward · · Score: 0

      You are looking the wrong way.
      The security guy will have to put in some hours after a security breach, that is true but that is because the security of that system was not good enough.
      So being lazy or making bad decisions has a price tag to it.

      Looking back the job was not good enough so it had to be done properly plus some extra checks for backdoors, looking forwards that mistake will not happen again. Lucky they were told. Checking for backdoor still needs to be done not because the guy who went public might have leave one behind (very improbably) but because someone else could have got in and plant one.

      If a guy figures out a way to break into my house, does it without stealing anything and tells me how he did it I will not complain I have to spend time and money replacing a lock.

    14. Re:No damage? by spire3661 · · Score: 1

      Its not ludicrous. We could and should be able to do it, but we dont design our networks to a handle that kind of thing. IMHO, every machine in the building should have a hot spare HDD ready to go and a full user profile stored on the network/backups. We dont have this functionality because its more important to slap a cheap vendor workstation on a desk then it is to build a a proper machine with extra hardware.

      --
      Good-bye
    15. Re:No damage? by tlambert · · Score: 1

      Guess there is a difference between your definition of "damage" and the GP's.

      In a business setting, any time, effort, or money that you spent, and would not have to spend if there were no breach is considered "damage".

      Excuse me...

      Why is it that you think that a breach that is committed by someone who reports it to you and potentially faces repercussions for their having a Bushido-style sense of honor about things causes less damage than a breach committed by someone who then proceeds to profit from said breach without disclosing it to you, up to and including selling the details of how to repeat it to third parties?

      Do you somehow think that the people who open themselves up to the repercussions are smarter than the ones who keep quiet and face less risk?

      From your "business perspective", I'd call the people who kept their mouth shut "smarter". Why is it you think a "smarter" person would be unable to get into your system -- or hasn't already -- than one you would, by your own lights, class as "less smart"?

    16. Re:No damage? by bwcbwc · · Score: 1

      No, you're conflating two different types of security vulnerabilities:
      1) The gap the guy originally used to get in, plus any other pre-existing vulns.
      2) the gaps the guy may have introduced into the network while he had access, via new malware, etc.

      The re-flashing and stuff mentioned on the GGP is primarily to mitigate #2.

      #1 is definitely not the guys fault, but any precautions required to mitigate #2 definitely are.

      And whether you agree with the law or not, breaking into secured networks is still illegal regardless of the harm. Even if you throw out the remediation costs, the argument that "no damage was done" isn't necessarily true: from a business POV, breaking into their corporate network and leaking game console specs ahead of announcement qualifies as industrial espionage. What if the leaked XBox specs inspired Sony to upgrade the CPU or the graphics on the PS4 to improve their performance? The leak takes away a competitive advantage that MS had due to their trade secrets.

      --
      We are the 198 proof..
    17. Re:No damage? by Em+Adespoton · · Score: 1

      Its not ludicrous. We could and should be able to do it, but we dont design our networks to a handle that kind of thing. IMHO, every machine in the building should have a hot spare HDD ready to go and a full user profile stored on the network/backups. We dont have this functionality because its more important to slap a cheap vendor workstation on a desk then it is to build a a proper machine with extra hardware.

      The other problem is that you need to deal with when the intrusion was detected when dealing with cleanup and mitigation. If there was an undetected intrusion, followed by backups cycling, user profiles getting backed up to hot spares, etc. and THEN someone notices the intrusion... well, you have to first figure out when the intrusion took place and what systems were possibly touched -- after which you need to follow the cascade of tainted systems until you reach the end.

      There's nothing worse than losing a week of work to restore to a tainted snapshot -- other than maybe being unable to audit and verify whether you've cleaned everything up in the first place.

    18. Re:No damage? by Anonymous Coward · · Score: 0

      If you were not an IT Whore, you would not comply with the demands to run Acrobat Reader and Flash Player. You would have no intrusions. You simply deserve what you get.

    19. Re:No damage? by Anonymous Coward · · Score: 0

      Shertainly. Flash, Acrobat Reader, MS Office would never have any flaws if there were no criminal hackers who exploited them. China would never fuck the west via the Internet if there were no hackers who told about it. If nobody tells about something, it does not exist !!

    20. Re:No damage? by Anonymous Coward · · Score: 0

      Businessmen are spineless whores with lots of money and they keep themselves an obedient Zoo Of Spineless Half-Assed "IT" Whores. Do you really think whores have any consistent system of morals ?

    21. Re:No damage? by Xugumad · · Score: 1

      I do that for systems I maintain.

      I've nuked systems just for looking suspicious, despite not being able to prove someone cracked them (half the binaries in /bin stopped working, I figure that's fairly damn suspicious).

      Anyone who doesn't re-image a cracked system is unbelievably naive, and it will come back to bite them hard one day. Like hell am I going to take the word of someone who broke into my systems that they didn't leave a rootkit.

    22. Re:No damage? by Anonymous Coward · · Score: 0

      There seems to be this common misconception that a network can be broken into without causing any damage. Tell that to the IT department that has to re-flash and re-image every damn machine on the network to make sure no backdoors were left behind.

      There seems to be this common misconception that having to fix a network to remove holes and backdoors is somehow worse than having lived with it for some time without knowing it Not to mention the fact that your second sentence does not substantiate the first, also known as the non sequitur fallacy: not having caused any damage and being under suspicion for having caused some are two completely independent things.

      If all you assume are fixing the existing exploit that the hacker used, then you are right. However, the problem is you don't know WHAT they may have done. There is definitely a cost involved in doing even basic forensics to see what machines the hacker may have broken into, what he may have had access to, etc. This may also require other actions such as reimaging/reinstalling/recovering from pre-hack backups/etc certain machines (an earlier post about reimaging EVERY machine is rather overkill that no one's going to do, of course). You could argue either way on the cost of all the meetings, presentations, explainations to management and requiring resetting everyone's password that will occur. Then, depending on the company, there's the possibility of PR issues to deal with and/or dealing with customers or vendors who may be affected in some way (or new prospectice customers who you may lose due to the event). And in some cases, such as this one, one could argue that stealing trade secrets has a cost (as in information leaking to competitors).

      So no, there is no such thing as a "no damage" break in. I will certainly grant you that monetary awards in certain previous cases has been too high and that not all break ins should be treated as equal crimes- but even the simplest break in is going to have a cost associated with it and damage done in some form or another that is above and beyond the fixes that SHOULD have been done prior to it (of course, even the "should have" depends on the actual method of break in- if the vendor is a day late on fixing a zero day exploit, you can still end up hacked even if you apply security patches regularly as you should).

    23. Re:No damage? by Xugumad · · Score: 1

      My network is vulnerable. I know this, because it exists.

      The question is how vulnerable.

      I run Linux, not OpenBSD, so there's a greater chance that I'll get a zero-day attack sprung on my network. However we make that compromise because it's considered reasonable.

      I run services we need, but each is a risk.

      There is no such thing as a secure network, there is only a secure-enough network.

    24. Re:No damage? by Anonymous Coward · · Score: 0

      Well, this dilhole leaked trade secrets . Realize, that information on unreleased, undisclosed products are protected trade secrets. While it is all noble and all to say, "I broke into your network using x,y,z", when you have also downloaded and leaked their information - you are in no way a white hat.

    25. Re:No damage? by Anonymous Coward · · Score: 0

      If we discover a security hole ourselves and find no subsequent evidence of a breach, we can be reasonably (but not absolutely) confident that our security auditing is functioning correctly and we repaired the hole before any breach occurred.

      If we do find evidence of a breach, the attacker will of course be held responsible for the damage.

      If the attacker says, "I have attacked your network, but don't worry (wink wink) I didn't do anything," he has done us the favor of letting us know there has been an attack, but he is still responsible for the attack. You can't absolve him of this by pointing out that we benefit from knowing about the hole. That's absurd.

    26. Re:No damage? by Anonymous Coward · · Score: 0

      This guy and 99% of Anonymous are Attention Whores. This Attention Whore used an international phone line to brag about his exploits. If he had a non-Attention mission he would have had much better security. He talked like a parrot kept in isolation for two weeks, apparently.

      Same with Anonymous - get a single important guy, threaten him with 124 years of revenge (after all he didn't kill (that would be just 20 years) but threaten the nice scam of War-Profiteers, Jewistan and Wall Street) and what they he does is basically destroying the entire org by a nice, detailed song. If the Anon muppets had proper security in place, they could have waterboarded the guy until he died and they would not have seriously damaged the org.

      Here's something proper:

      http://sourceforge.net/projects/didipus

      Now, I have been an Attention Whore in the past, and I can tell you it is entirely ineffective for your other objectives if you can be identified. You either "blend in to established, licensed memes" or your are "shut down". Free speech means they (the state, the banksters, all sorts of professional shit) are free to intimidate you. So you better go Full Anonymous, which means your corrupt ISP can't rat you out to the $hit.

    27. Re:No damage? by Anonymous Coward · · Score: 0

      I can tell you bu$ine$$men actually DO leave the virtual doors wide open, as a modicum of proper security (such as unguessable passwords), would reduce profit by 0.1%. I can also tell you that some of he largest technology corporations consciously run that kind of crap security. It is actually a big fat, obese wonder they have not yet been completely infiltrated, manipulated and destroyed by China. Their actions YEARN for that.

    28. Re:No damage? by Anonymous Coward · · Score: 0

      I'll retract that. I think they stuffed Nortel and got the blueprints of RR and Lockmart.

    29. Re:No damage? by Anonymous Coward · · Score: 0

      Breaking into Western Networks is the prerogative of the Spooks. Of America and basically everywhere else. He is clearly a Dangerous Criminal and Threat To Society !

    30. Re:No damage? by bloodhawk · · Score: 1

      There seems to be this common misconception that a network can be broken into without causing any damage. Tell that to the IT department that has to re-flash and re-image every damn machine on the network to make sure no backdoors were left behind.

      Those actions and associated costs are not the result of having your network broken into. They are the result of being told your network is vulnerable - even if you have no knowledge that the network was actually broken into.

      That is not completely correct. Once you know your network has been broken into you can no longer trust any device that has potentially been intruded upon and more often then not a full rebuild is required, simply finding a vulnerability means you have to patch it not rebuild. There will always be vulnerabilities, maintaining and monitoring is key to that, however once a vulnerability is exploited the cost skyrockets.

    31. Re:No damage? by thePowerOfGrayskull · · Score: 1

      A couple of weeks ago, one of our deployment SSH keys was compromised. After the hole was plugged, every employee had to re-key, re-upload keys, etc - even though we knew only one key was obtained .

      What kind of org do you work in where they don't take security importantly enough to do this?

    32. Re:No damage? by Jah-Wren+Ryel · · Score: 1

      I'm pretty sure you missed the point. If you had a gap, you don't know who has been through it. If you only look for introduced malware when you know somebody has been through the gap, then you are only half-assing your security.

      --
      When information is power, privacy is freedom.
    33. Re:No damage? by dissy · · Score: 1

      So what you're saying is, if you say to me in conversation you are running a server with such and such software, and I reply also in conversion that the latest version of software such and such is exploitable, then give you the URL to the security announcement... I now somehow owe you money despite not even knowing where your network is let alone haven't touched the thing? Simply because you need to check for backdoors and reimage potentially backdoored machines?

      I think you don't understand how this "fault" thing actually works.

    34. Re:No damage? by kelemvor4 · · Score: 1

      Your front door lock is broken, but you didn't realise it. A passer-by tells you that is broken. Do you blame him for the "damage" to your wallet that comes from fixing it?

      Or how about this: You're understandably unhappy that he pushed your door open and poked his head in. He claims he didn't take anything (and given how he volunteered the information about your door, there's no reason to disbelieve him), but are you angry at him that you now feel the need to double-check everything you own, just in case he (or someone else) took something?

      If the lock was "broken" because he was able to devise a method to pick it necessitating that I replace the lock then YES. Imperfect security is reality everywhere all the time. If you think your systems are completely secure all it means is that you are mistaken.

    35. Re:No damage? by Anonymous Coward · · Score: 0

      Who is responsible for the attack? The attacker. It doesn't matter whether he says "I didn't do anything" because he can't be trusted.

      If you have a vulnerability and you discover the vulnerability, you close it. You check for evidence of a breach. Finding none, you don't make an extra effort to look for malware (besides what you would normally be doing). If you find evidence of a breach, you do put in extra effort.

      In this special case, your idiot attacker is telling you he has breached your systems. This doesn't absolve him of the responsibility of breaching your systems. And you have to put forth the special effort.

    36. Re:No damage? by Namarrgon · · Score: 1

      Your argument is that his actions opened their systems wider, than if he hadn't done anything? Is there any evidence of that being the case here?

      If that's not the case, then he still did them a favour by pointing out a hole in their security. Sure there may be others, but now they know about this one. The responsible action would be to close the hole (and thank him), but they could always ignore it and do nothing; they'd be no worse off.

      --
      Why would anyone engrave "Elbereth"?
    37. Re:No damage? by Anonymous Coward · · Score: 0

      There seems to be this common misconception that having to fix a network to remove holes and backdoors is somehow worse than having lived with it for some time without knowing it

      Speaking in house analogies (as that seems to be the flavor of this discussion): you don't just have to fix the door he used to gain access to your house - you also have to gut any room he might have accessed while in your house because you have no way of knowing whether he is completely honest with you when talking about his exploits or if he used his access to your home to leave some bugs behind (and counts on having built enough rep with you by informing you of the faulty door that you won't take that possibility seriously).

      Fixing the door is necessary and an improvement to the house - having to trash your perfectly fine living room just because he might have accessed it (and you can't prove that he has not) is real damage that was dealt through his intrusion.

    38. Re:No damage? by kelemvor4 · · Score: 1

      Your argument is that his actions opened their systems wider, than if he hadn't done anything? Is there any evidence of that being the case here?

      If that's not the case, then he still did them a favor by pointing out a hole in their security. Sure there may be others, but now they know about this one. The responsible action would be to close the hole (and thank him), but they could always ignore it and do nothing; they'd be no worse off.

      No, my point is that a system that is not perfectly secure is not an invitation for anyone who wants to access the system. Just as you will go to jail if I leave my front door closed but unlocked and you walk in and rifle through my wife's underwear drawer. Maybe you take a photo of it, while you're there but leave the actual items. Unlocked (or insecure in computers) does not equate to do whatever you want. If the company had no security other than a telnet uid/pwd, he still isn't allowed to crack that and access the server. This guy broke into a computer system and should be punished for it. If he wanted to do some white hat hacking, he should have obtained consent before he accessed the systems. Really, I don't think there's even any gray area here. He accessed systems without first obtaining permission. The security of those systems is not relevant.

    39. Re:No damage? by Eugriped3z · · Score: 1

      There seems to be this common misconception that a network can be broken into without causing any damage. Tell that to the IT department that has to re-flash and re-image every damn machine on the network to make sure no backdoors were left behind.

      There seems to be this common misconception that having to fix a network to remove holes and backdoors is somehow worse than having lived with it for some time without knowing it Not to mention the fact that your second sentence does not substantiate the first, also known as the non sequitur fallacy: not having caused any damage and being under suspicion for having caused some are two completely independent things.

      It IS sort of funny to think that re-imaging an insecure system in order to bring it back to it's former state of brokenness constitutes repair or implies that damage was done. Perhaps the perpetrator should should have been tracked down and awarded a consulting fee or offered a job.

    40. Re:No damage? by Namarrgon · · Score: 1

      Pretty hard line to take on a guy who was a) a kid, b) merely curious, not malicious, c) did no damage, and d) did them (and their customers) a favour by alerting them to a security hole that could be maliciously exploited by the next hacker to drop by.

      Some companies (e.g. Epic) actually appreciated the heads-up, and sent him a signed poster in thanks. Your position that he be punished instead, while defensible under a strict interpretation of the law, looks more like a dick move to me. I'd expect a judge would be rather more nuanced.

      --
      Why would anyone engrave "Elbereth"?
  5. Durango hasn't been revealed by Anonymous Coward · · Score: 1, Insightful

    > he retrieved information about the PS4 and next-gen Xbox 'Durango' (which turned out to be correct)

    "Durango" hasn't been revealed yet. How do we know his info is correct?

    1. Re:Durango hasn't been revealed by Sir_Sri · · Score: 1

      They might mean he had info on early development kits, a lot of that info has leaked out (there are after all lots of companies that have said kits).

      Early development kits aren't final hardware though, so they don't mean much to consumers or people on the outside.

  6. But officer, I just broke in! by Anonymous Coward · · Score: 0

    "simply breaching the security of those companies was enough to get the U.S. FBI to convince Australian authorities to raid his house"

    Simply? Yes, simply breaking the law will get you the attention of the police... This must be the first /. post by a 8yr old... (a stupid 8yr old)

    1. Re:But officer, I just broke in! by Osgeld · · Score: 1

      yes, breaking in and taking information

      people would oppose someone breaking into their house and stealing all their financial documents, but its apparently harmless to break in and commit industrial espionage

  7. Chinese Army by the+eric+conspiracy · · Score: 4, Insightful

    Ugh.

    If some surfer dude from Oz can do this imagine what the Chinese Army and the TLAs have gotten into.

    I don't know is this is good or bad, Mutually Assured Destruction can be a good thing, as well as can be the dissemination of information.

    However it sure should give people pause when they put a server online. Or make their bank accounts available on the web.

    It might be a case of not if but when.

    1. Re:Chinese Army by Anonymous Coward · · Score: 0

      Go China! At this point, they're our best hope of saving the world from the Americans.

    2. Re:Chinese Army by the+eric+conspiracy · · Score: 1

      > Go China! At this point, they're our best hope of saving the world from the Americans.

      Be careful what you wish for. You might get it.

    3. Re:Chinese Army by Lumpy · · Score: 1

      You are late for your labor camp job comrade... Please send video of you being beaten by your neighbor to the Ministers email address by 3am or you will be punished by the overseers.

      --
      Do not look at laser with remaining good eye.
    4. Re:Chinese Army by Anonymous Coward · · Score: 0

      Uhh.. his mugshot was all over the news here in Oz, I can tell ya one thing, he ain't no surfer dude

    5. Re:Chinese Army by Anonymous Coward · · Score: 0

      Pheew ! I am so glad there is Gitmo plus Waterboarding and 124-year sentences for hackers in America. So much more civil than 10 years of Chinese labour camp. And the best is that I stand much better chances to enjoy jail in America than in China.

      I also find it so civilized Banksters like the Lehman CEO can fuck America through all openings and aren't even investigated for anything which could lead to jail time. Destroying millions of jobs is of course a lesser crime than hanging out dirty laundry of the rich&powerful to dry.

      With Idiots like you, America is on a safe path to share the destiny of England. They don't even have the money to fix their teeth, these days.

    6. Re:Chinese Army by Anonymous Coward · · Score: 0

      see! to prevent this we need the Chinese!

    7. Re:Chinese Army by Anonymous Coward · · Score: 0

      Ugh.

      If some surfer dude from Oz can do this imagine what the Chinese Army and the TLAs have gotten into.

      I don't know is this is good or bad, Mutually Assured Destruction can be a good thing, as well as can be the dissemination of information.

      However it sure should give people pause when they put a server online. Or make their bank accounts available on the web.

      It might be a case of not if but when.

      The FBI should raid housing Unit 61398 in Shangha.
      http://www.guardian.co.uk/technology/2013/feb/23/mandiant-unit-61398-china-hacking

    8. Re:Chinese Army by Anonymous Coward · · Score: 0

      This would of course assume that Australians are genetically inferior to other nations. When will people learn the grass isn't always greener on the other side, the most brilliant thoughts can still be had by those in socially unacceptable conditions, those without a voice and even those who pronounce air conditioner as egg-nishna.
      Good day.

  8. Don't get caught by Anonymous Coward · · Score: 0

    Kids. KIDS. Don't do stuff like this through an identifiable Internet connection.

  9. You don't get it. by excelsior_gr · · Score: 0

    I think that obtaining the info on the Xbox and the PS just served as a proof of his feat. He infiltrated the networks of two mega-corps that spend millions on security and employ hundreds of experts using his skills and knowledge. Maybe he didn't even care about the specs of the consoles. He just wanted the kind of information that would prove that he had actually gained access.

    The one with the twisted perspective on the subject is you in this case. You completely ignore the black/gray/white-hat categorization and try to make us believe that this guy should be treated like a common criminal. Well, he should not. Depending on the way he gained access, MS and Sony should probably consider hiring him.

    1. Re:You don't get it. by dreamchaser · · Score: 1, Redundant

      He broke the law, if his story is true, plain and simple. You're the one with twisted perspective on it. He had no right to access their networks or proprietary information. I hope they don't go TOO hard on him as he did seem to have relatively benign intentions, but he hacked into systems without permission. The companies in question did not contract him to do penetration testing or an overall security assessment.

    2. Re:You don't get it. by Anonymous Coward · · Score: 0

      I think that obtaining the info on the Xbox and the PS just served as a proof of his feat. He infiltrated the networks of two mega-corps that spend millions on security and employ hundreds of experts using his skills and knowledge. Maybe he didn't even care about the specs of the consoles. He just wanted the kind of information that would prove that he had actually gained access.

      The one with the twisted perspective on the subject is you in this case. You completely ignore the black/gray/white-hat categorization and try to make us believe that this guy should be treated like a common criminal. Well, he should not. Depending on the way he gained access, MS and Sony should probably consider hiring him.

      It isnt hard to break into anyones security. All it takes is the will to do it. Breaking into a companys, no matter how big it is, isnt that difficult. It happens every single day. All it requires is the will to do so. Because nothing is fool proof, for every lock ever created no matter how complex it is there are a thousand guys that can open it.

      And he is a common criminal. You justify his methods and acts simply because he didnt steal, but he still commited a criminal act. Thats like if you say a guy broke into a bank vault that he shouldnt be considered a criminal simply because he didnt take the money and that the bank should praise him and thank him for breaking into their vault. He justify his acts because your on his side. Even robin hood is still a common criminal regardless of what he did with what he stole he still broke the very basic and common laws. By your logic if the guy broke your window in your home and came in and went through all of your stuff but didnt take anything you would be happy because he proved your window was a weak entry point. Youre a complete and utter moron.

      And why should someone hire him? "Oh you broke into our security and made us look bad? Hell work here please and have unfettered access to us from the inside". You want to reward criminals for criminal activity? And I hate to break it to you, but just because he broke in doesnt make him a good security person because anything he can put in place can be defeated by a thousand other people because like I said, nothing is secure.

    3. Re:You don't get it. by Sir_Sri · · Score: 1

      You realize there are firms that sell that sort of security right? And academic programs on how to do so etc.

      There are legit was to enter the business he simply chose a different route.

    4. Re:You don't get it. by DKlineburg · · Score: 1

      I guess that is akin to saying a padlock only keeps honest people honest?

      --
      Memory is deceptive because it is colored by today's events. - Albert Einstein
  10. who cares by Vince6791 · · Score: 2

    So, it's okay for the u.s government and even corporations to spy on our communications(facebook, phone calls, chats), emails, and whatever we upload to the cloud without a court warrant but when somebody does it to a corporation or government it's time for the feudal u.s system to go bat shit crazy on his/her ass. If u.s does not follow the constitution why should we, remember by the people for the people. Hah, who cares it's a feudal system. People just stop hacking it's not worth losing your life over.

    1. Re:who cares by bwcbwc · · Score: 1

      No it's not OK for the government to do that. But just because the government screws you over doesn't mean you can go screwing over 3rd parties. The problem isn't that the law against cracking networks is necessarily bad (although I'll agree it's not perfect and overreaches), it's that the government and corporations aren't held to the same standard as individuals, which is a completely separate issue.

      --
      We are the 198 proof..
  11. Its funny... by Anonymous Coward · · Score: 1

    Because no one seems to be blaming the companies like usual, no one is blindly angry for no reason and no one seems pissed off. Why? Because he stole information that users here find interesting.

    I mean he did the same thing that hackers have done to companies before and you people lined up to spout the same comments and blame the companies for being hacked many many many times but now all the sudden you change your tune simply because he wasnt trying to steal personal information about you. He commited the same crime. Its like saying someone who breaks in your home to steal your wallet is bad, but if he breaks in and steals nothing then youre perfectly fine with it.

    1. Re:Its funny... by Anonymous Coward · · Score: 0

      Judging from the posts above, that's actually what some of these people believe. And they also believe him when he says he didn't do anything (else) wrong.

  12. It is called the Geohot effect by argee · · Score: 1

    You would think that after Geohot showed the way (not!), that people would leave
    Sony alone to wither on the vine.

    Friends don't let friends buy Sony Products.

    1. Re:It is called the Geohot effect by spire3661 · · Score: 1

      You mean the guy that completely capitulated, tucked his tail between his legs and ran? Yeah Geohot sure showed the way........

      --
      Good-bye
    2. Re:It is called the Geohot effect by Anonymous Coward · · Score: 0

      He was an Attention Whore, Too. Why didn't he post his exploit entirely anonymous or at least strongly pseudonymous. There was once a guy posting the reverse-engineered code for RC4 on USENET and they never got him. Almost infinitely more important and smarter than these Attention Whores Without A Real Beard.

    3. Re:It is called the Geohot effect by westlake · · Score: 1

      You would think that after Geohot showed the way (not!), that people would leave Sony alone to wither on the vine.

      At any odds you would care to name, I would bet that 99.8% of users upgraded their PS3 firmware (currently at rev. 4.31) without giving a second's thought to Geohot or Linux on the console.

    4. Re:It is called the Geohot effect by Gravatron · · Score: 1

      No one cared about linux on the ps3 outside a few small circles, so no one really cared about losing it. Hard to sympathize with a cause no one honestly cares about.

  13. Really? by Anonymous Coward · · Score: 2, Insightful

    Summary: Kid breaks in networks of corporate entities, accesses trade secrets, purchases development hardware using fraudulent information, brags about it on the internet and then cries about being "ruined".

    There is nothing "ethical" about any of this kid's shenanigans. He cried about them taking his toys away, and doesn't even realize he's going to pound-me-in-the-ass prison yet.

    Moral of the story: Common sense eludes hacker.

    1. Re:Really? by Anonymous Coward · · Score: 0

      I find it quite interesting that everybody perpetuates the "get raped in jail meme". Did police really do this ? If yes, I do think they deserve many more cyber operations against themselves. If not, who posted the disinformation and what are the objectives ?

      If you find out why raping is being used as a threat, please think hard, devise a proper plan and then damage the interests of those who spout that nasty shit. There are lots of ways, from free counter-propaganda to fact-checking to hacking (but with proper security, please) to writing a virus targeting the source of the nasty shit.

    2. Re:Really? by Anonymous Coward · · Score: 0

      Prison is generally not a nice place. It's not the police doing the raping (generally) but the other prisoners. The type of people who are hackers tend to be the less likely to defend themselves against physical intimidation.

  14. Shall we Play a Game? by RiscIt · · Score: 1

    Haven't we seen this movie before?

  15. Inevitable lesson by Anonymous Coward · · Score: 0

    Be a pirate. Exploit every hole ye shall find. Gives nothing back!

    Arrrr.

  16. if you have to cheat... by glitch23 · · Score: 1

    to gather information to 'one-up' your competition or to make yourself look good to your friends then you aren't very good. And in this case, breaking the law by breaking into companies is cheating.

    --
    this nation, under God, shall have a new birth of freedom. -- Lincoln, Gettysburg Address
  17. banking fraud can get you time in a FPMITA by Joe_Dragon · · Score: 1

    banking fraud can get you time in a FPMITA and he did it on the International level.

  18. I think what you're looking for is... by Anonymous Coward · · Score: 0

    "May your wishes come true, and may you live in interesting times."

  19. default passwords + open IP is a big issue. by Joe_Dragon · · Score: 1

    default passwords + open IP is a big issue and you don't even need to be a be good hack to pull that off.

  20. Seriously? by Seumas · · Score: 1

    Slashdot is linking to Kotaku content? Why not just link directly to blogspam (which, frankly, would be better quality than the link-bait drivel on Kotaku)?

  21. at least have whistleblower protection and eula by Joe_Dragon · · Score: 1

    at least have whistleblower protection and other stuff like company who use eula's to make you at fault for bugs or even website typo's that let you get pass security with out even trying to hack.

    whistleblower protection is needed to cover stuff like what happened to Stephen Heller and others like him.

    http://en.wikipedia.org/wiki/Premier_Election_Solutions

  22. infiltrated or used some ones log on and password by Joe_Dragon · · Score: 1

    infiltrated or used some ones log on and password that maybe been in a other system that did not have millions sent on security

  23. In the USA..... by Lumpy · · Score: 1

    WE make sure that no good deed goes unpunished. no matter where you are in the world, do something good and we will find you and punish you.

    --
    Do not look at laser with remaining good eye.
  24. Whats the first rule of braking the law? by Anonymous Coward · · Score: 0

    Its don't talk about it.

    Guess what the second rule is?

    Anyhow this guy has learned that no good deed goes unpunished.

  25. Accidental Mistakes by Anonymous Coward · · Score: 0

    In other less safer times, mistakes would have been easily solved by hiring this guy. And so, knowing not only how to solve the mistakes but also how he hacked their sites.

    But, today seems that these companies, not only don't need to solve anything. But are also interested in showing the world who rules. And how we should all obey them...

  26. it's more about the shop fraud by Anonymous Coward · · Score: 0

    you are all talking about the network intrusion. in the article, they say he (or his "friends") got at least 2 free development devices that would have cost 7500 each, by entering fake addresses and intercepting the delivery. he also tried to sell these on ebay. the search warrant was related to ebay.

  27. Let me get this straight... by fullback · · Score: 1

    Your computers and other electronic devices can be confiscated without warrants or your "permission" within 100 miles of the U.S. border without cause or suspicion because you have no right to privacy, and the contents of your phone can be examined by a police officer during a traffic stop, but their computers are private and protected by people with guns?

    Right. Got it.

    In the past, people would never have tolerated this. They'd have risen up against it and the evil bastards who propagated it.

    Now, we're just weak little serfs in the new feudalism.

    1. Re:Let me get this straight... by Anonymous Coward · · Score: 0

      The Supreme Court doesn't agree with the 100 mile rule. Not that that will make you feel better after 10 wasted years of costly legal battles and a completely destroyed life.

    2. Re:Let me get this straight... by Anonymous Coward · · Score: 0

      You are surprised that law enforcement has privileges that the common citizen does not? Further, you think this is wrong? Ha! Even your operating system disagrees with you.

      People have tolerated a great many regimes far more oppressive than a government that dares to read your email. That you can even put this in the same bracket with the gulags and various secret police forces disappearing people - which went on for years in multiple countries with no uprising - shows how out of touch with reality you are ... ... and how lazy. You expect "people" not to tolerate this, but your sole action in objection is to post a comment on a site where most people will agree with you anyway?

      And the worst part is that when something happens that actually matters this will continue to be your default response. Weak little serfs, indeed. The internet is the opiate of the masses.

  28. "He hasn't done any damage" by Memroid · · Score: 2

    I would argue that he may have done a great deal of damage. Releasing plans for future products can tip off competitors. Information regarding future products can also result in a customer not purchasing what is currently available in anticipation for a future product. Both of these can mean millions of dollars in losses for a company.

  29. Never leak to the companies! by Anonymous Coward · · Score: 0

    Never, ever leak to the companies! They will in incredibly quick order, become rat bastards! Sony, microsoft, pick your company. If you gain access to their system, you are a criminal! If you find a security hole, dig, find out all you can, then report all the stuff, and the security hole, anonymously. If they find out who you are, they will make your life a living hell. If you tell them in confidence about a potential security hole, they will have the cops on speed dial breaking down your door! Its far better to publish as widely and broadly as possible how to break into their site! Only after 100,000 skript-kiddies pave the path should you describe (also anonymously) potential fixes (if you dare). They don't know about 'good guys' and 'bad guys'. To them, you are a bad guy. Your intentions are unimportant. Look at Julian Assange! Look at Bradley Manning! They *all* shoot the messenger. If they have a problem, demonstrate the problem! Remember anonymity is your only friend. They will assume Chinese hackers broke in, especially if you lay some Chinese characters onto the site! The companies have lawyers who are assholes! The companies have bosses who are assholes! They don't like someone from outside telling them problems. Its better to break a companies entire site and bring all their data to utter ruin, rather than tell them about a security vulnerability. Is everyone out there dumb? Look at geohot! Sony made his life shit. Likewise Manning and Assange! How is anonymously breaking a site utterly worse for the hacker when they can go out for pizza and beer later without looking over their shoulder, than being an upright and ethical computing professional with the fucking FBI kicking down your door and threating your life, liberty and pursuit of happiness for doing the right thing? THINK!

  30. by Anonymous Coward == LOL by Anonymous Coward · · Score: 0

    WOW !! GREAT !! you hear that h4x0r from around the world !! this will teach you to stay true to your manifesto !! never inform anyone !! stay low do your magic and live/die by your codename !!

  31. Beware by Anonymous Coward · · Score: 0

    Let this be a lesson to you boys and girls. If you discover an exploit, release it to the community covertly and make sure you remain ANONYMOUS.

    Remember. Good hackers are known by many.
    Great hackers are known by everyone.
    But the best hackers, are known by noone.

  32. Overkill by Anonymous Coward · · Score: 0

    The kid was dumb to hack these companies in the first place, and even more stupid to openly keep on doing it after companies and authorities were aware of him (not to mention the boasting), but their response here is still pretty overkill; the US in general has a tendency to far too heavily come down on anyone remotely associated with hacking in any form.

    Microsoft aught to have offered the guy a job, not sent the FBI after him; good to see Epic were nice enough about it though, sending him off a signed poster as thanks.

  33. Most neigbours are bad by Anonymous Coward · · Score: 0

    You know for sure that there are some very bad neighbours in your neigbourhood that want to break into your house and steal your stuff. You protect yourself with locks. A neigbour breaks into your house and touches your stuff and drinks you beer but doesn't steal anything. He shows you how bad are you locks.
    1) You are gonna punish him and in doing so scaring other neighbours from showing you how bad your locks are.
    2)You are gonna thank him and secretly swear that he's a bastard, but follow his advice and secure you locks to further prevent break-ins (from "good" or "bad" neighbours).

    Do 1.
    You're a moron. Youre house will surely be attacked again by bad guys.Wouldn't be nice if you knew your weak spots.

    Do 2.
    You're a moron because your locks suck. But you're willing to improve them and become less moron.