Slashdot Mirror


Author Says It's Time To Stop Glorifying Hackers

First time accepted submitter Geste writes "Diane McWhorter pleads in this NYT Op-Ed piece that it's time to stop glorifying hackers. Among other things she rails against providers' tendencies to 'blame the victim' with advice on improved password discipline. Interesting, but what lesson are we to learn from someone who emails lists of passwords to herself?"

69 of 479 comments (clear)

  1. Also time to stop by Anonymous Coward · · Score: 5, Insightful

    glorifying actors, sports figures, politicians, generals, soldiers, writers, artists, architects, Canadians, cooks, race car drivers, the old, children, dogs, accountants, spies, computer programmers, cowboys, drug smugglers, and the disabled.

    1. Re:Also time to stop by i+kan+reed · · Score: 4, Funny

      Goddammit, you stole the thunder out of so many potentially good posts, fast-acting AC.

    2. Re:Also time to stop by NotDrWho · · Score: 5, Funny

      Come on now, no one glorifies clowns.

      --
      SJW's don't eliminate discrimination. They just expropriate it for themselves.
    3. Re:Also time to stop by jellomizer · · Score: 2, Insightful

      Well there is a difference between glorifying people who somewhat try to do positive things with their life, and achieved something from it.

      But Hackers, drug smugglers and much of the other black market activity really shouldn't be glorified. Because for every 1 person who does this for some noble deed there are a thousand stupid kids who do this because they think it is easy money.

      --
      If something is so important that you feel the need to post it on the internet... It probably isn't that important.
    4. Re:Also time to stop by NotDrWho · · Score: 5, Funny

      That's because they think outside the box.

      --
      SJW's don't eliminate discrimination. They just expropriate it for themselves.
    5. Re:Also time to stop by ackthpt · · Score: 4, Funny

      glorifying actors, sports figures, politicians, generals, soldiers, writers, artists, architects, Canadians, cooks, race car drivers, the old, children, dogs, accountants, spies, computer programmers, cowboys, drug smugglers, and the disabled.

      So long as we still glorify the Hypnotoad, I'm cool with that.

      --

      A feeling of having made the same mistake before: Deja Foobar
    6. Re:Also time to stop by nucrash · · Score: 2

      scientists never get respect.

      --
      Place something witty here
    7. Re:Also time to stop by Anrego · · Score: 2

      As a fellow Canadian, I'd like to point out that you forgot to say sorry.

      Sorry :(

    8. Re: Also time to stop by Zero__Kelvin · · Score: 3, Insightful

      It took me a while to notice, but your post is what made me realize that most of the people posting here up until now have no idea what a hacker is.

      --
      Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
    9. Re:Also time to stop by Ardyvee · · Score: 4, Interesting

      The thing is, there is the general public definition of hacker (ie a criminal), and then there is the definition of hacker by other people that is something along the lines of: somebody who likes to take things apart, exploring the system's limits; an expert on the field. The later definition includes people like the Elf Lord you mentioned, Abby (from the same show), most security consultants, criminals, etc.

      Therefore, his comment is valid for a certain definition of hacker (and most hackers don't reach the news because they are security consultants, or work in IT in a company, or report the issues to the companies who don't go "YOU HACKED INTO MY SYSTEM NEED TO SUE"). And thus: the biggest problem IT people have when communicating with the rest is that neither side really talks the same language. How are we going to communicate effectively and solve issues if we don't really share the same language?

      --
      I don't care if I'm wrong. I only care about everyone obtaining something from the discussion.
    10. Re:Also time to stop by UnknownSoldier · · Score: 2, Interesting

      > In most cases a hacker is nothing more than a thief and criminal, the article is correct, they should not be glorified.

      Originally, grasshopper, hacker meant someone who was curious about a system and/or learning -- non-destructive probing, or one produces elegant code.

      1. A person who enjoys learning the details of programming systems and how to stretch their capabilities, as opposed to most users who prefer to learn only the minimum necessary. 2. One who programs enthusiastically, or who enjoys programming rather than just theorizing about programming. 3. A person capable of appreciating hack value (q.v.). 4. A person who is good at programming quickly. Not everything a hacker produces is a hack. 5. An expert at a particular program, or one who frequently does work using it or on it; example: "A SAIL hacker". (Definitions 1 to 5 are correlated, and people who fit them congregate.) 6. A malicious or inquisitive meddler who tries to discover information by poking around. Hence "password hacker", "network hacker".

      * The Original Hacker's Dictionary, http://www.hackersdictionary.c...

      Then the media hijacked the term and labeled all the white hats with the black hats.

    11. Re:Also time to stop by RabidReindeer · · Score: 2

      The term "hacker" gets applied in the general public usage to:

      1. Social Engineers, regardless of tech skills
      2. ignorant script kiddies
      3. malicious invaders ("crackers")
      4. people who bang on systems with blunt objects ("hack jobs" in the pre-computer sense)
      5. people who actually know what they are doing and do it for constructive purposes

      It's mostly our own fault that we haven't managed to make the distinctions clearer. The first 3 on the list are basically criminals unless they're working for authorized purposes. The fourth may or may not be, but even when they are on the side of "good", sloppy is a menace in and of itself. The fifth is not only all too rare, but in my experience is sometimes actively discouraged, because it takes too long to do a truly competent job.

      Criminals do get glorified, when they're "Robin Hood", Thoreau, or the Founding Fathers. Sometimes their crimes are attempts to remediate even worse crimes.

    12. Re:Also time to stop by saider · · Score: 2

      "Timothy McGee" (NCIS), that occasionally needs to hack something to save a life

      The fact that a law enforcement agent breaks the law during the course of their duties should be cause for concern. We have the 4th amendment for a reason. You cannot make an action permissible for one person, while making it illegal for another. That sets up all kinds of trouble.

      Besides, he is rarely saving lives with his actions. The hacking is usually done to catch the perpetrator after the fact as a deus ex machina to move the plot along.

      --


      Remember, You are unique...just like everyone else.
    13. Re:Also time to stop by wagnerrp · · Score: 2, Informative

      Alignment has nothing to do with anything. "Hacking" is a constructive operation. You hack together a piece of code. You hack together a server. You hack together physical objects that have nothing at all to do with computers. "Hacking" is the process of building something new and useful without the full blown structure and overhead of a traditional engineering. Or, it could be violent coughing. Or, it could be chopping down a tree. Hacking has been around long before computer security was even a thing. Suddenly (well, over the past 20 years), hacking has become something evil, and all those old meanings are forgotten.

  2. You keep using that word by Overzeetop · · Score: 5, Insightful

    Note to the press: "Hackers" doesn't mean what you think is means.

    --
    Is it just my observation, or are there way too many stupid people in the world?
    1. Re:You keep using that word by mwvdlee · · Score: 5, Insightful

      Indeed.

      There's a difference between somebody who takes a list of passwords and abuses it and somebody who finds security issues and reports them responsibly.
      There's also a difference between somebody who it a victim and somebody who gmails list of passwords to herself.

      Oblig. car analogy: The person stealing your car is a "criminal", the owner of that car is a "victim". The person bypassing the lock on his own car and then reporting the issue to the car manufacturer is a "hacker". The person keeping a keychain in her unattended car, with keys of all her properties, conveniently labelled what each key is for and where it can be found, is called an "Idiot".

      One does not preclude the other.

      --
      Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
    2. Re:You keep using that word by nomadic · · Score: 4, Insightful

      The commonly-accepted usage of words is determined by the majority. Whatever "hacker" used to mean, it now means someone who bypasses computer security systems to commit crimes.

    3. Re:You keep using that word by lgw · · Score: 4, Insightful

      The difference between "idiot" and "at fault" is huge.

      Users will be idiots. Does any IT admin deny this fact? If your system only protects users who aren't idiots, you're a sorry excuse for an admin.

      Make your system robust against weak passwords. This is not rocket science. If it's something important, use two-factor auth. If not, make account recovery easy - put real thought and effort into it! And for goodness sake, make sure your DB of password hashes doesn't become public - that's all in your hands, and it's completely your fault if that happens, weak passwords or strong.

      --
      Socialism: a lie told by totalitarians and believed by fools.
    4. Re:You keep using that word by fisted · · Score: 3, Insightful

      Since the "majority" has not a faint idea what hacking is, or was, i refuse letting them assign new meaning to words they dojn't understand.
      IOW your argument is stupid.

    5. Re:You keep using that word by Anonymous Coward · · Score: 3, Insightful

      Exactly. This ship sailed a long time ago. Time to give it up. The original meaning of "hacker" is dead. If you use it in that sense, you will only be miscommunicating with the vast majority that uses it in the new sense.

      Seriously people. Let it go. Words change. Many of the words you use now meant something else entirely a hundred years ago.

    6. Re:You keep using that word by Aighearach · · Score: 4, Insightful

      Your system cannot protect the idiots from themselves. That is a trap you fell into somewhere. Most likely you simply agreed it would be nice if it was so. "Yeah, why can't we protect all our users?!"

      This isn't brain science or rocket surgery. The idiots have to have a way to access the system. They will NOT remember strong passwords, they will write them in a stupid place or keep them in gmail with public information as the account recovery. And guess what, you can't control gmail. Put some real thought into it, your idiot users will hand their access away to the first thief, and you can't do much to protect them.

      All you can do is protect your system and try to make anything important difficult enough to access that the idiots can't get in.

    7. Re:You keep using that word by Aighearach · · Score: 3, Informative

      "Hackers" are called Makers now. We lost that language war, but we have a new term now.

    8. Re:You keep using that word by Aighearach · · Score: 3, Insightful

      The commonly-accepted usage of words is determined by the majority.

      While I do agree that whatever "hacker" used to mean is called a "maker" now, you're way off on how word meanings are determined.

      It turns out, each word can have multiple meanings, and all the meanings with common published examples are the real meanings! Wow! Blows your mind, right?

      How can nerds expect the world to believe in our vocabulary if we can't even read dictionaries?

    9. Re:You keep using that word by Rinikusu · · Score: 5, Informative

      I currently have over a dozen passwords I have to keep memorized for accessing various systems (each with their own unique login IDs and passwords), many of which are changed every 3-6 weeks and do stringent checks on previously used passwords. That's just for work, and not including the dozen or so username/passwords I use online in my personal time. Seriously, it's time to rethink passwords because if you don't like that I write all this shit down in a spreadsheet that I print out and stuff in a binder, well, it beats the other guys post-its on their monitors.

      --
      If you were me, you'd be good lookin'. - six string samurai
    10. Re:You keep using that word by houghi · · Score: 2

      Make your system robust against weak passwords. This is not rocket science

      It is for a LOT of situations more complicated then what you believe.
      Suere you have the standard measurements you talk about, like pasword hashes not bevoming public.

      The problem is that security is a social problem that is being solved by technical solutions. On the social part is also that people are not able to remember 174 logins and seperate passwords and remember the new passwords every month. That 174 is a total ransom number. I am sure if I look at how many websites I have a login and password, that number is easily reached.

      So people will look for a way to still be able to reach that website or do their work. They will find easier passwords. Write them down. Use the same login and password for different systems.

      A password reminder program is not a solution, as I am not allowed to install programs on my work PC. I will also not have access to it all the time.

      --
      Don't fight for your country, if your country does not fight for you.
    11. Re:You keep using that word by Princeofcups · · Score: 2

      "Hackers" are called Makers now. We lost that language war, but we have a new term now.

      Because "maker" isn't a completely generic term, that wouldn't get confused with ANYONE WHO MAKES THINGS. Sorry to yell. Some people are hard of hearing.

      --
      The only thing worse than a Democrat is a Republican.
    12. Re:You keep using that word by DaveV1.0 · · Score: 2

      The definition of a word is defined by usage. You have stated that you don't care what popular usage is, therefore you are stating that you don't care what the actual definition of a word is, you are going to use it how you think it should be used.

      Now, who is stupid: the person who is using the word as most of the human race uses it; or you, who is insisting on using the word according to the preference of a small group of people?



      P.S. if you say "him and everyone else", you should see a psychologist about your narcissistic delusions.

      --
      There is no "-1 offended" or "-1 you don't agree with me" mod options for a reason.
    13. Re:You keep using that word by RabidReindeer · · Score: 3, Insightful

      You could use a password manager like KeePass, LastPass, PasswordSafe, etc. Is there some reason you don't?

      And even if there is, reconsider it. You can keep a password safe database(s) on a thumb drive handcuffed to your wrist if you want to be really paranoid. The databases are encrypted, but if they're physically tethered to you, you'll have to take them with you instead of possibly leaving them unguarded on your desk.

      The idea of making different apps all have different passwords (as opposed to single signon or a password safe/PIN vault under a master password) may sound secure, but nobody's memory is that good, and the resulting post-its, unencrypted spreadshhets, Windows Notepad files or whatever means that in reality, you may be less secure, rather than more secure.

    14. Re:You keep using that word by UnknownSoldier · · Score: 2

      Why the fuck aren't you using a password manager like KeePass / KeePassX ???

      Memorize one long master passphrase, copy/paste every other password.

    15. Re:You keep using that word by DaveV1.0 · · Score: 2

      No offense, but not only are the cows out of the barn on this one, but the barn has pretty much burned down. I remember the attempts to get people to call them crackers, worms, etc. It didn't work. I do agree with your observation on the hat distinction. But, complaining about the use of "hacker" or saying it shouldn't be this way is irrelevant, and refusing to accept the popular convention is just, well, stupid.

      --
      There is no "-1 offended" or "-1 you don't agree with me" mod options for a reason.
    16. Re:You keep using that word by Jaysyn · · Score: 2

      We need people to build things far more than we need people to break them. Building things is cool. Breaking them isn't.

      Gandalf isn't always right. Sometimes, you *do* have to break things in order to know how to build them better.

      --
      There is a war going on for your mind.
    17. Re:You keep using that word by real+gumby · · Score: 2

      Note to the press: "Hackers" doesn't mean what you think is means.

      So true.

      Interestingly House of Cards which includes a character who is a cracker and hacker (appears to have good hacking skills which he uses to break into systems). It appeared that the writers had actually made an effort to learn about the culture(s). For example there was a well done attack that combined social engineering and sleight of hand to defeat two factor authentication.

      Unfortunately his lines still made it clear that the writers didn’t really understand what those words really meant (sorta like when the marketing department uses the word “cloud”). And the set department still made the usual nonsensical computer displays. As for the character himself. well he was hardly glorified. In fact if I ever met a person like that my overshelming desire would be to smite him with a copy of the V7 manual. Twice, if he kept moving.

    18. Re:You keep using that word by lgw · · Score: 2

      Sure you can protect the idiots. Like my post said, you can use 2-factor auth, or if it's not that important, you can make account recovery easy. Debit cards work fine with a 4-digit PIN, because both "it's 2-factor auth" and "fraud prevention and recovery is well thought out".

      --
      Socialism: a lie told by totalitarians and believed by fools.
    19. Re:You keep using that word by geekoid · · Score: 2

      You can train people to sue strong but easy to remember passwords.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
  3. Time to stop glorifying the NYT Op-Ed by coldsalmon · · Score: 5, Insightful

    Stop falling for the clickbait, Slashdot.

    1. Re:Time to stop glorifying the NYT Op-Ed by Bacon+Bits · · Score: 2

      Joke's on them. Nobody at Slashdot actually reads the articles.

      --
      The road to tyranny has always been paved with claims of necessity.
  4. Hackers get no RSPECT by Anonymous Coward · · Score: 3, Funny

    And yea, that's spelled right. In all 57 states.

  5. Blaming the victim? by Anonymous Coward · · Score: 4, Insightful

    Next thing you know we'll stop teaching kids to look both ways before crossing the street because we're teaching people not to drive drunk. But this just isn't how the world works.

    1. Re:Blaming the victim? by Just+Some+Guy · · Score: 2

      Yeah, I don't know what sane person could get "blame the victim" out of that. Is it "blaming the victim" if my wife takes a self-defense class, or is it acknowledging that there are bad people in the world and it's prudent to learn how to deal with their presence?

      --
      Dewey, what part of this looks like authorities should be involved?
  6. Victim blaming by LocalH · · Score: 5, Insightful

    Why the hell is there a trend nowadays to call it "victim blaming" to give people advice on protecting themselves? Is it really such a bad idea for people to do things to protect their passwords?

    I guess telling people to run antivirus is now "victim blaming", too.

    --
    FC Closer
    1. Re:Victim blaming by lagomorpha2 · · Score: 4, Funny

      Don't teach users not to run mysterious .exe files from suspicious people without antivirus software! Teach scammers not to scam!

    2. Re:Victim blaming by gIobaljustin · · Score: 2

      If there is a reasonable and effective method that women can use to protect themselves from getting raped, why would they not use it? Sadly, there is no such reasonable or effective method. Becoming a shut-in is not reasonable, and unlikely to be effective. Rapists don't rape because of someone's choice of clothes, so telling them to not wear certain clothing is just idiotic.

      Your comparison is bad and you should feel bad. In fact, just think about what you're saying; you're essentially saying that people shouldn't mention to other people that there are ways to protect themselves from bad things. It's just absurd.

      It all depends on how the advice is given. If you're blaming a victim for someone else's actions (say, someone breaking into their home), then I could see that as "victim blaming." However, if you merely fault them for not taking reasonable and effective steps to mitigate the chances that they will be harmed, that is entirely different than blaming them for the actions of another. This "victim blaming" nonsense needs to be put to rest.

      --
      Thank you Dave Raggett
    3. Re: Victim blaming by N1AK · · Score: 3, Insightful

      Careful, I'm not sure you can see over the top of all that hyperbolic. It isn't impossible for most people to hold the view that crime is bad an should be discouraged and that taking moderate steps to moderate your risk of being a victim is sensible; if you haven't already tried it then I'd strongly suggest giving it a go.

  7. US blame culture. by JustNiz · · Score: 4, Insightful

    So she emailed a list of passwords to herself, didn't bother encrypting it, and kept it in her on-line email account for 9 months, then she's actually surprised when she gets hacked?

    I look forward to the day when America gets back to the point where people start taking responsibility for their own actions again, instead of always looking for someone else to blame (and sue) for their own stupidity.

  8. Author is s twat by scorp1us · · Score: 3, Informative

    He *emailed* himself his own password list then whines when his account gets hacked.
    NO SURPRISE HERE.

    --
    Slashdot's rate-of-post filter: Preventing you from posting too many great ideas at once.
  9. "Victim Blaming" by gurps_npc · · Score: 2
    It's not "Victim Blaming" unless someone attempts to punish the victim. Yelling at an idiot to stop throwing his mone the ground while closing his eyes is not victim blaming.

    See Adrienne Brown, who really was victim blamed.

    Or the poor woman in the Steubenville Rape case.

    --
    excitingthingstodo.blogspot.com
  10. In other news... by slapout · · Score: 2

    Author Diane McWhorter identity was stolen 6 times today

    --
    Coder's Stone: The programming language quick ref for iPad
  11. disconnect by Tom · · Score: 2

    but what lesson are we to learn from someone who emails lists of passwords to herself?

    That real-world security is very disconnected from the clean and nice scenarios in your books and head, because real users think differently than geeks and do different things for different reasons. Some of them we gloat over and call them Lusers and other deragatory terms, but that's mostly to cover up our own insecurity because most of the Lusers out there have had ten times as many and twice as beautiful women and don't live in their mothers basements anymore.

    Yes, I know that's also untrue. The point is that different people have different skills and while many of the non-techie people do stuff that we techies consider stupid, they could laugh just as much about us in other areas of expertise. Maybe not women, maybe for them it's sports or marketing or making friends.

    So stop gloating and calling people stupid and look at what they can, in fact, teach you. In this case, there's quite a bit to be learned, not the least of which is that passwords are a moronic concept and need to die.

    --
    Assorted stuff I do sometimes: Lemuria.org
  12. Victim Response by Jharish · · Score: 2

    Hacker says it's time to stop listening to authors. Especially if they think hacker=computer criminal. It's got as much integrity as saying white people=bankers.

  13. My takeaway.. by Anonymous Coward · · Score: 3, Funny

    Things I learned in reading that blabbering op-ed.

    Earthlink is still alive. (shocking, but meh...)
    Author likely uses same password for multiple publically known email accounts. (lacks even the least amount of personal information security training)
    Seems to think Gawker is a respected, um, network. (HAHAHA!)
    Thinks pepole hacking celebrity accounts or high-profile public figures is equivalent to what Snowden and similar whistleblowers do, at least as popularity is concerned. (Err...)
    Mentions term 'white hat' like it's a mythical unicorn. (turtles all the way down....)

    This is like a nail beutician, commenting on the security of a cars CAN bus. I want my 5 minutes back!

  14. Maybe it's time to take away her soapbox by Akratist · · Score: 3, Informative

    There seems to be no end to pinheads like this who run around and pontificate about crap they know nothing about. And, oh, hey, nice try impressing us with how sophisticated you are..."Oooh, look at me! I was at the museum of modern art! I'm ever so much better than you!" And, of course, she is part of the media class which spends a considerable amount of time glorifying violence to bring in entertainment dollars. The reality is that dumbshits like her owe most of their modern existence to "hackers" such as the Royal Society and others who refused to accept what they were told as conventional wisdom of the day and began "hacking" science and the natural world, producing great advances and inventions, and so on. I'll stop the rant now, and just say that useless flapjaws like her are the reason I ignore the major media...reading virtual fish wrappers like her column just wastes time I could spend doing more productive stuff which will actually help improve the lives of people instead of just making me look stupid in front of a national audience.

  15. Why is this on slashdot? by TranceThrust · · Score: 2

    A badly written rant containing ill-informed opinions, even when accounting for the author being no `geek', as she puts it.

    The problem is not the `glorification' of hackers (seriously?). The problem is that laws remain outdated to cope with this digital age. The problem is that governments rely on badly protected and badly regulated technologies.

    The problem is not having enough hackers.

  16. Hire an expert by seyfarth · · Score: 2

    Anyone with a lot of money and little computer security knowledge needs to hire someone to set up their computers and teach them safe practices. It would be worth several thousand dollars to a milliionaire to avoid the sort of problems Ms. McWhorter encountered. Perhaps she is not rich, but she has won a Pulitzer prize for writing. I think she could afford to try harder to be safe. Ideally an operating system should protect the user, but it is practically impossible to write complex software with no errors. People should be suspicious when their operating system comes with a time trial of anti-virus software. The fact that such software exists, makes it pretty obvious that the system is fragile. Ms. McWhorter writes well, but is clearly not a computer security expert. She needs help with her computer and on-line affairs.

    --
    Ray Seyfarth, ray.seyfarth@gmail.com, http://rayseyfarth.blogspot.com
  17. Dear Diane... by stox · · Score: 3, Interesting

    If you want to see what real hackers are about, come on down to H.O.P.E. this year, http://www.hope.net./ We're just a short walk away from the New York Times at the Hotel Pennsylvania.

    See you there!

    --
    "To those who are overly cautious, everything is impossible. "
  18. Idiots... by Jawnn · · Score: 2

    ...should not pontificate about "hackers". OK, I'll spot her the inept use of the term, but aside from that, when it comes to cyber security, Diane McWhorter is clearly an idiot. She uses a public mail server to send her passwords to herself, across the Internet, unecrypted, and it's somebody else's fault when such idiotic stunts result in compromised security?
    Ms. McWhorter, It has nothing to do with "glorification". Criminals and miscreants will steal your shit if they can, often just because they can. The motivation doesn't matter. What matters is that they will. What matters even more is that one can, with a few simple steps, drive the likelihood of such a theft down to near zero. So when you fail to take those steps, you are being stupid. Its like never locking your house or your car and then crying foul when someone points out your negligence to you.

  19. Author also wants... by JestersGrind · · Score: 2

    everyone to get off her lawn.

  20. The Song of Their People by Sponge+Bath · · Score: 4, Funny

    I'm a hacker,
    I'm a snacker,
    I'm a mid-night wacker.
    I get my lovin' on the net.
    Ooh, ooh, ooh, ooh

  21. Victims often at "fault", but not their fault by Dutch+Gun · · Score: 3, Interesting

    Ok, we're going to snicker at someone e-mailing password lists, because we all probably understand that e-mail, by default, is sent in the clear, and is therefore not secure. It's hard for tech geeks to properly empathize with "normals" who just want to get some work done, or surf around on the net and not worry about getting their computer taken over by some malware.

    Honestly, though, it's hard to blame normal users for this. Should a user have to be a computer expert in order to actually use a computer? Some might argue yes, but that doesn't seem too realistic. The fault lies with software developers who blindly rushed features out the door without giving proper thought to the security implications. Microsoft had a really bad habit of this until they made security a significant corporate priority - it's time for Apple to catch up now, as proven by the recent "goto fail" fiasco. The focus has since shifted to softer targets, first Javascript and browser exploits, and then third party plugins as those closed up, such as Adobe products or browser-based Java exploits, and the good time for hackers (no, I'm not going to call them "crackers") is still rolling on.

    Honestly, I'm not sure what the answer is: Probably most casual users should actually move away from fully-powered computers and move toward safer, more locked-down systems like tablets and phones (like they have been). For people not doing serious work or creating actual content, these are more than capable, and are certain safer systems in general. Alternatively, getting set up as a limited account in an operating system with a smaller attack surface like Linux would be fine too. BTW, I don't buy the notion that Linux is inherently safer than Windows (granted, that definitely used to be true) - it's a combination of fewer threats (because it's a less rich target) and configuration options - Windows is also very safe as a limited user account). We've seen plenty of serious security holes in very popular FOSS software, even recently. But people buy computers because they actually want to do computer-like things with them, including running popular software. Limited accounts / locked-down systems are not always feasible.

    One thing I'd love to see is the death of standard login-password mechanisms. It's too much of a burden for both a normal user to both create and remember a secure password, and for the website to keep that valuable user information secret. We've demonstrated again and again and again that eventually a crack will be found and the info will leak. That's why I'm hoping that something like SQRL will eventually see widespread adoption. It's biggest strength is that it doesn't require trusting ANY second or third party with secrets of any sort in order to keep your identify secure (granted, associated data can still be compromised, but your identify can't be stolen at least). It's a very promising system, but we'll see if it catches on - it's sort of a long shot. But for the time being, something like LastPass is the next best thing. Someone needs to tell the author of this article about it so she can stop e-mailing herself password lists.

    --
    Irony: Agile development has too much intertia to be abandoned now.
    1. Re:Victims often at "fault", but not their fault by Dutch+Gun · · Score: 2

      Should a user have to be a computer expert in order to actually use a computer?

      They don't need to be experts; they just need to not be absolutely retarded. You learn to drive (maybe) before you get your license. Learning a few basic facts before you go off and do a bunch of stupid shit with a computer is something everyone should be able to do, though I don't think there should be a license.

      Modern computers essentially have the equivalent of a big red light switch placed out in the open which, if flipped, may accidentally burn your office down. No one would find that acceptable design anywhere outside the computer world. If a user accidentally double-clicks an attachment, it can bring down a corporate network. I don't consider that acceptable or sustainable, and I don't think that someone double-clicking an attachment is retarded, because that's a FEATURE that's been added. Why the hell can't we make it safe to double-click and view an attachment? That's OUR fault, not theirs!

      This lady knew enough not to re-use passwords among different services and sites. Short of using a third-party password management system, and without the inherent understanding that e-mail isn't secure (which service providers don't exactly communicate openly), e-mailing password lists doesn't seem retarded to me. It sounds like someone trying their best to stay secure within a very complex environment they don't completely understand, and probably never will.

      Computer-literate folks like us tend to set the bar too high without realizing how difficult we're making things for others who would just like to use computers to get work done, and not have to spend have their time just in training how not to get hacked. Calling non-experts "retarded" is not going to help anything.

      --
      Irony: Agile development has too much intertia to be abandoned now.
    2. Re:Victims often at "fault", but not their fault by gIobaljustin · · Score: 2

      Computer-literate folks like us tend to set the bar too high without realizing how difficult we're making things for others who would just like to use computers to get work done, and not have to spend have their time just in training how not to get hacked.

      Strange how people treat cars so differently. Going onto the road with no understanding of how to operate a vehicle or what the rules of the road are would be seen as unacceptable, but if you do something similar (though I think less extreme) with a computer, it's just normal.

      Calling non-experts "retarded" is not going to help anything.

      I'm not saying that non-experts are retarded. One doesn't have to be an expert to not be retarded; they just have to be a tiny bit competent and learn some *basic facts*.

      --
      Thank you Dave Raggett
  22. I have a problem with that. by khasim · · Score: 2

    Seriously, it's time to rethink passwords because if you don't like that I write all this shit down in a spreadsheet that I print out and stuff in a binder, well, it beats the other guys post-its on their monitors.

    NOT ON THE COMPUTER!

    For work passwords, WRITE them down (pen) on a piece of paper and keep that piece of paper in your wallet.

    For home passwords, WRITE them down and then that piece of paper like any other important piece of paper for your home.

    If you do it on the computer you do not know that the system has not saved it to a temp file or something that a cracker will find.

    People who will physically break into your house and steal your computer are a different threat than people who will break into your computer via the Internet. Protections against one will not help against the other.

  23. Comments prove the McWhorter's point by DaveV1.0 · · Score: 3, Insightful

    I don't think I have seen one comment that "Guccifier" did was wrong. But, there are plenty of posts calling McWhorter an idiot, a pinhead, a shithead, etc. and telling her to shut up and that it is her own fault she was hacked.

    Most comments on here are verbally abusing the victim while completely ignoring the person who compromised her account and posted her personal details on line. And, I am willing to bet that if that happened to any of those posting said comments, the victim would want to kill the perpetrator.

    --
    There is no "-1 offended" or "-1 you don't agree with me" mod options for a reason.
    1. Re:Comments prove the McWhorter's point by DaveV1.0 · · Score: 2

      That is a false analogy. They are not "leaving the car running". A more appropriate one would be having a cheap lock on their back door, and in this case having a bowl with copies of all her of keys in the house.

      Saying "That car thief was AWSOME! You deserved to get your car stolen, you fucking shithead! Next time turn off your car and lock the door, n00b!" Isn't "suggesting that they not leave their car running and walking away".

      Please go read the comments where they are not suggesting she "take reasonable security precautions" but rather are simply insulting her. Also, read her article where people are praising "Guccifier" and wanting to start defense funds, etc.

      The end result is abuse of the victim and praise/support of the perpetrator.

      --
      There is no "-1 offended" or "-1 you don't agree with me" mod options for a reason.
  24. Agree with headline... by meustrus · · Score: 2

    Disclaimer: I didn't RTFA, and while I agree with the headline and summary, it's not for the same reasons and I actually have a lot of respect for real hacking.

    I agree that it's time to stop glorifying hackers. Not real hackers that find SSL vulnerabilities, or who hack the mainframe, or who embed assembly in their compiled programs. No, those people deserve all the glory they get (which is very, very little). No, I'm talking about the "hackers" that are always stealing peoples' passwords.

    A figurative 99% of security breaches happen because a password got stolen. That is not hacking. That is stealing a password. It requires no more technical competence than the average user possesses. If you write your password down and throw it away, the garbage man can find it and log into your email. Does that make him a hacker? No, it makes him an unethical, opportunistic garbage man.

    Password security is not equal to computer security. Real hackers compromise computer security, possibly resulting in a stolen password, or possibly resulting in access that renders the stolen password irrelevant. And if someone steals a banker's password and uses it to do things the banker is allowed to do, then there wasn't anything wrong with the computer security.

    That's not to say the user is automatically at fault for the password security. I mean, sure, the user could have handled the password better, but if that user understood that in the first place then there never would have been a problem. Password security is a policy detail. That's probably why it's usually the weakest link. Only the geeks understand enough to design an effective policy, but the geeks don't usually design good policies for non-geeks.

    --
    I sometimes ask revealing, often ignorant-seeming questions. Maybe they're harder to answer than you think.
  25. That battle is long over by sjbe · · Score: 2

    So you would stand idly by and allow misinformation by a group who clearly and chronically has absolutely no grasp of the field they are discussing ruin your language?

    It's not my language. I didn't invent it. I don't own it. I also am not so arrogant as to think other people are stupid and do not grasp the meaning of the word. And even if I have an opinion about it my opinion doesn't mean much. The word hacker, for better or worse, now means someone who breaks into computer systems. Intent doesn't play into it although usually the term isn't used with positive connotations. You may not like this but that is the way it is. Get used to it. That battle was lost a LONG time ago.

  26. Re:Note to codemonkeys. by gIobaljustin · · Score: 2

    Protip: Words can have multiple meanings.

    --
    Thank you Dave Raggett
  27. Let's get this straight, Diane... by macraig · · Score: 2

    ... we don't glorify hackers, we glorify good people doing good things that benefit the common good. It just so happens that some of those people accomplish that goal by hacking.

  28. Re:Need to stop trying to market brand "hackers" by geekoid · · Score: 2

    I would rather they say 'A criminal hacked into...

    --
    The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
  29. So says the NY Times. by davydagger · · Score: 5, Insightful

    We glorify much worse in society.

    Our top artist, Jay-Z is a man who made a career spanning over a decade rapping about being a criminal(gangsta rapper), and glorying a life soaked in drugs, loose women, and crime.

    On the other hand, we have movies like zero dark thirty which glorify torture.

    We glorify politicians who lie, cheat, and steal, and we encourage eachother to lie cheat and steal for them.

    When a kid is bullied in school they are generally blamed for being weak, socially unfit, or making themselves a target.

    Most celebrities, the people who we all mimick, do drugs, drive under the influence, sleep around, and act without a care for the rest of us. If we admit we don't like them, something is wrong with us. We re-adjust our social values around them.

    We glorify the press and the news, and when they get caught lying to us, often to assassinate someones character for either social or political reasons, strut around as if their position makes them nobility, and violate each and every rule they tell us they abide by with enough regularity its safe to say they don't exist, we extoll them as the saviors of democracy.

    But yes, its hackers. Hackers are making society a terrible place. If computer break ins where any other field besides computers, it would be socially accetable. If you get take advantage of financially, or make a silly mistake, well its proof the capitalists are smarter than you. If the bank takes advantage of your lack of time to fight them, its because they deserve to prey on the weak. If you break into the bank computers because the same smarty pants bankers are to daft to learn your field, your a terrorist.

    Somehow hackers are glorified? Another shitty op-ed from the NY Times, a fine publication with a long history of clueless op-ed writers, and hideously snobbish double standards.

    I've said this before, and I'll say it again, the NYT is a fine publication, but the opinion editorials are run by a bunch of smarmy yuppie shitheads without any real vantage point in society.