Hackers hold key to computer security, conference told

Hackers can help companies improve security and force vendors to acknowledge holes in their software, representatives of the dark IT art said yesterday.

Sylvia Pennington

Hackers can help companies improve security and force vendors to acknowledge holes in their software, representatives of the dark IT art said yesterday.

At the Compsec 99 conference in London, convicted US hacker Kevin Poulsen, who served a five-year prison sentence for his activities, and white hat hacker Sir Dystic, who is best known as the author of the trojan horse program Back Orifice, told a packed house of delegates about how and why they do what they do.

Advertisement

Gaining illegal entry to other people's computer systems, known as hacking, remains one of the more publicly exciting aspects of a profession that is popularly perceived to be short on glamour and long on geek factor.

While curiosity is the prime motivation for most programmers to start hacking, Poulsen explained how he crossed the moral and legal divide when he was on the run from the FBI for some illegal but harmless out of hours hacking he had engaged in, while in the employ of a contractor to the US defence department.

During this period, he supported himself by tapping into radio stations' competition lines to win luxury cars, holidays and other prizes for himself and his friends.

Now a consultant and writer, Poulsen played down the suggestion that hackers were a key weapon in the corporate espionage game.

"I don't think hacking is the best way to gather economic intelligence," he said. "If you want to get specific information from specific companies, you're better off getting a job as a temp or a janitor. "Except for websites, hacking is an engagement - it's relatively rare and it's an ongoing 'dance'."

"I don't think big-time hacking is happening on a corporate level," he added.

For all their paranoia about other companies stealing their secrets, many organisations were not concerned about the prospect of gaining illegal entry to others' systems, provided they could remain undetected, Sir Dystic claimed.

He said he had been asked by many organisations to do so, and had refused.

"Most companies just want the information, they don't care if illegal means are used to get it," Sir Dystic said.

He said white hat hackers could play a legitimate role in raising public awareness of security breaches in commercially available software, which the vendors would prefer to ignore.

Following his release of Back Orifice, which allows users to take control of Windows machines remotely, Microsoft programmers had privately commended his actions, Sir Dystic claimed.

"Companies' marketing departments won't allow them to fix these problems until they become public," he said.

One delegate from Fuji Bank backed up these assertions. Only by showing senior executives some hacker tools and the ease with which they could be used to gain access to corporate systems, had the organisation been persuaded to improve its security policy, he claimed.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

'We're the good guys' claim hackers

Hackers claimed today to be allies of the security industry without whom a vast number of potentially devastating exploits would go unnoticed.

Bank security breaches mostly internal, say experts

Information security breaches at financial institutions, such as banks, are more often than not caused by an internal hacker or staff error, according to security industry experts.

US police flooded with new year virus and hacker threats

US law enforcement and intelligence agencies have so far received more than 30,000 threats from virus writers and hackers planning to turn the millennium celebration into commiseration.

Teen hacker charged with picking lock on NATO site

Man faces five years in prison after home-made hacking program hits politically sensitive US servers.

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

Alcatel-Lucent logo

Summit: Networks swamped by information overload

Alcatel-Lucent's Neal Tilley talks about how enterprises and carriers can...

EU flag

Breach notification laws get green light

Privacy rights strengthened in Europe

Richard Thomas

Summit: Richard Thomas advises on handling the data deluge

Former Information Commissioner speaks out on government databases and data...

oracle sun

War of words escalates between EU and Oracle

Commission comes out fighting after criticism from Oracle and Washington

Primary Navigation