Hackers hold key to computer security, conference told

Hackers can help companies improve security and force vendors to acknowledge holes in their software, representatives of the dark IT art said yesterday.

Sylvia Pennington

Hackers can help companies improve security and force vendors to acknowledge holes in their software, representatives of the dark IT art said yesterday.

At the Compsec 99 conference in London, convicted US hacker Kevin Poulsen, who served a five-year prison sentence for his activities, and white hat hacker Sir Dystic, who is best known as the author of the trojan horse program Back Orifice, told a packed house of delegates about how and why they do what they do.

Advertisement

Gaining illegal entry to other people's computer systems, known as hacking, remains one of the more publicly exciting aspects of a profession that is popularly perceived to be short on glamour and long on geek factor.

While curiosity is the prime motivation for most programmers to start hacking, Poulsen explained how he crossed the moral and legal divide when he was on the run from the FBI for some illegal but harmless out of hours hacking he had engaged in, while in the employ of a contractor to the US defence department.

During this period, he supported himself by tapping into radio stations' competition lines to win luxury cars, holidays and other prizes for himself and his friends.

Now a consultant and writer, Poulsen played down the suggestion that hackers were a key weapon in the corporate espionage game.

"I don't think hacking is the best way to gather economic intelligence," he said. "If you want to get specific information from specific companies, you're better off getting a job as a temp or a janitor. "Except for websites, hacking is an engagement - it's relatively rare and it's an ongoing 'dance'."

"I don't think big-time hacking is happening on a corporate level," he added.

For all their paranoia about other companies stealing their secrets, many organisations were not concerned about the prospect of gaining illegal entry to others' systems, provided they could remain undetected, Sir Dystic claimed.

He said he had been asked by many organisations to do so, and had refused.

"Most companies just want the information, they don't care if illegal means are used to get it," Sir Dystic said.

He said white hat hackers could play a legitimate role in raising public awareness of security breaches in commercially available software, which the vendors would prefer to ignore.

Following his release of Back Orifice, which allows users to take control of Windows machines remotely, Microsoft programmers had privately commended his actions, Sir Dystic claimed.

"Companies' marketing departments won't allow them to fix these problems until they become public," he said.

One delegate from Fuji Bank backed up these assertions. Only by showing senior executives some hacker tools and the ease with which they could be used to gain access to corporate systems, had the organisation been persuaded to improve its security policy, he claimed.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

'We're the good guys' claim hackers

Hackers claimed today to be allies of the security industry without whom a vast number of potentially devastating exploits would go unnoticed.

Bank security breaches mostly internal, say experts

Information security breaches at financial institutions, such as banks, are more often than not caused by an internal hacker or staff error, according to security industry experts.

US police flooded with new year virus and hacker threats

US law enforcement and intelligence agencies have so far received more than 30,000 threats from virus writers and hackers planning to turn the millennium celebration into commiseration.

Teen hacker charged with picking lock on NATO site

Man faces five years in prison after home-made hacking program hits politically sensitive US servers.

Related whitepapers

Related jobs

Most watched

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

a padlock

Microsoft to plug security holes

Microsoft has given advance warning of a number of security...

Nokia handset

Top 10 articles, 10 July 09

No Nokia Android phone, ActiveX attacks and Google enters into...

Can Google beat Microsoft at its own game?

Google's announcement this week that it plans to step into...

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

Primary Navigation