Hackers vs. crackers, security, & fun at Defcon
XLawyer writes "In an article about Defcon, a reporter from the New York Times tried reasonably hard to explain and observe the difference between hackers, who like to figure out how things work, and crackers, who like to get into other people's things and sometimes stop them from working. An interesting item in the article shows how crackers make reporters' jobs harder by calling themselves "hackers." " The article itself is well written, and lucid with some telling interviews; (NYT requires free login, BTW)
.
Earlier this year, I was on irc (sorry, but we all do it sometimes) and a 13yr old Turkish kid proclaimed himself as a "hacker" - refusing to admit that he was wrong and actually wanted to be a "cracker". He said "it's up to me what I call myself". On this basis, I'm a Nuclear Brain Engineer.
The term "hacker" probably has a lot to do with the term "hack", a "hack" being a particularly dedicated journalist, or member of newsroom staff who slaves away to beat the deadline etc...
The point? In my experience, people who wrongly call themselves "hackers" are either;
or
None the less, ill-informity is nothing new, and nothing to get too heated about.
Mong.
* Paul Madley
*...Slacker, Artist, Techie - Geek *
Remember: Nothing is Cool.
First was the announcement by the Hack-Sec Klahn of their joint venture with IEC to put together an incedent response database based on profiling attackers. This is some pretty cool stuff..
Also at Defcon was a group of cognitive psychologists that were interviewing DC attendees. They were looking for insight into hacker and cracker mentalities. I was a test subject (I hung up my black hat years ago..), and I saw several of my fellow hackers, as well as some crackers being interviewed. We talked about when I got started hacking (20 years ago on a VIC-20!), when I was the cool kid in town because I had the 1200 baud modem, motivations behind my work with clients (in general, not specifics, of course) in helping to lock down networks.
I think that profiling efforts like this will be a great service to the infosec community for determining proper incident response techniques.
The cDc guys were their typical loud, light-show assisted selves, and bo2k may or may not be the hacking tool of choice for owning Windoze boxes, but it is at the very least useful in the context of remote administration of Windoze boxen. As for the ISS commentary about it being "child's play", I'm reserving judgement until I have a look at the source and play with it in my lab. The ISS guys are typically straight shooters, but recall that they are also a publicly held company, thus have a serious PR group to consider. The ISS announcement is definitely PR driven, we just need to know if it's accurate.
The l0pht guys announced "AntiSniffer", software to detect the presence of a sniffer (ie someone with a NIC in promiscuous mode, thus collecting every frame that passes over the wire) on a LAN. Cool stuff.
The unsig!