The hacking hobbyist

Published: 17 March 2001 y., Saturday
Baker, a 24-year-old systems programmer, is part of a group of computer experts who spend their free time trying to figure out potential Internet security threats to large networks. Over the last year, Baker's hobby has led him to technology security lapses at E*Trade, the Charles Schwab brokerage concern, Wells Fargo bank and the Critical Path e-mail service. Baker is a member of a clan known as "gray-hat" hackers, who occupy the ethical territory between the malicious "black hats" and the "white hats," hired by companies to check their own systems' security. Gray Hat protocol is to first notify hacked companies of possible network flaws, and then possibly posting the flaw on Web sites where gray hats exchange trade gossip, as Baker did when he discovered the E*Trade network security hole. The company quickly vowed to clean up the matter after reporters called. In a world where hackers are either jailed or earn thousands in consulting fees, Baker's hobby is puzzling. The online gatherings for this community are places like Bugtraq, run by Virginia-based SecurityFocus.com. Five to 10 network vulnerabilities can be posted on Bugtraq in just one day, said chief technology officer Elias Levy, who estimates the gray hat community numbers 10,000 people, ranging from researchers at well-known labs and universities to amateurs. "People make targets of themselves," said Baker, who says he gave E*Trade months to address the issues before posting vulnerabilities. "If there isn't any press, there isn't any action. It is the key to making the whole plan work."
Šaltinis: nandotimes.com
Copying, publishing, announcing any information from the News.lt portal without written permission of News.lt editorial office is prohibited.

Facebook Comments

New comment


Captcha

Associated articles

Could Anthrax Scare Boost E-Mail Use?

All across America, anthrax-leery corporate mailrooms are taking extra care with envelopes and packages more »

India Slates $2Bil Plan For In-School Internet

India's government plans to invest $2 billion to improve Internet access in schools across the country. more »

Afghanistan, on 50 Websites a Day

Since the Sept. 11 attacks, the international spotlight has been trained on Afghanistan, the Central Asian country notorious for housing one of the most repressive regimes on the planet as well as suspected terrorist Osama bin Laden. more »

Swedish Mobile Users To Get Locatable E-911 Services

Hard on the heels of Sprint PCS announcing satellite location-enhanced emergency 911 (E-911) services in the U.S. last week, Europolitan Vodafone has announced plans for a similar set of services for its Swedish cellular users. more »

Digital Island Launches 2Way Web Services

San Francisco-based content delivery network Digital Island Inc. made its first significant move Thursday under the aegis of Cable & Wireless more »

Investment in Voice Technology Increases

Global investment in voice technologies in 2001 is already up by 33 percent, compared to the total investment made in 2000, according to a report by Datamonitor more »

FBI, industry team on computer security

The FBI is teaming with the computer industry to help American companies and regular Internet users prevent the 20 worst computer threats -- from the "Code Red" worm to the "Melissa" virus. more »

New Duron kicks off AMD chip parade

Advanced Micro Devices is getting October off to a start by releasing a series of processors for desktop PCs. more »

New virus "Vote"

Kaspersky Labs Strongly Urges Updating Your Anti-Virus Database more »

Microsoft Passport Still Faces Concerns

Microsoft is still a long way from resolving concerns about interoperability and control of enterprise information in its Passport authentication services more »