Kevin Mitnick Looks Back in Forbes Interview
Kevin MitnickAndy Greenberg
writes on
Forbes.com:
There was a time when the name Kevin Mitnick represented everything that the world's chief security officers feared most: a reckless geek with the power to break any network in the world.
Prosecutors and journalists, including the New York Times' John Markoff, further aggrandized his cybercrime exploits, claiming he was a criminal hacker mastermind who had wiretapped the FBI to stay ahead of his pursuers, hacked into Pentagon computers and could launch nuclear weapons simply by whistling tones into a pay phone.
Mitnick wound up serving five years in prison--four before his conviction and eight months in solitary confinement. He got out in 2000. Now Mitnick, 45, has reinvented himself as a security consultant. In his second career, he performs the same cyber-intrusions he once used to steal data to suss out flaws in companies' defenses. That means Mitnick has to convince major corporations and even government agencies that he's a trustworthy professional--rather than a cyberpunk.
But Mitnick isn't hiding his hacker background. In fact, he says the notoriety of his criminal past has only boosted his business. And last month, at the HOPE hacker conference in New York, Mitnick announced that a lapsed statute of limitations will allow him to publish a book detailing his exploits as a cybercriminal and a fugitive. The book won't be ready for about a year but Forbes.com talked with Mitnick about telling all, the state of cybersecurity and why true hackers make the best security professionals.
More
here.
Kevin Mitnick Websites Vandalized by Pakastani Crackers
Via zone-h.
Kevin Mitnick, the infamous cracker specialized in social engineering techniques whose life made the Hollywood screens is known as a person who is building his professional reputation (not without obstacles though) by offering a variety of services in the IT Security field and holding well-paid conferences and appearances all over the world.
A group of Pakistani crackers vandalized today the websites of 4 different Kevin Mitnick's ventures, in what it looks like to be a focused personal attack. The sites defensivethinking.com, mitsec.com, kevinmitnick.com and mitnicksecurity.com have been defaced with offensive messages against his person.
But Kevin Mitnick is not new to this kind of attentions from the defacer's world...
More
here.
Kevin Mitnick Detained, Released After Colombia Trip
Kevin MitnickElinor Mills
writes on
C|Net News:
Since being released from prison eight years ago, Kevin Mitnick's brushes with the law have consisted of a few parking tickets and a citation for driving without a front license plate--that is, until he returned from a trip to Colombia two weeks ago.
After landing at the Atlanta airport for a security conference, Mitnick was detained for four hours for reasons still not fully explained. To make matters worse, while customs officials in Atlanta were busy inspecting his cell phone, laptop, and luggage, police in Bogota were ripping open a package he had mailed to his U.S. address on suspicion that it contained cocaine.
The simultaneous incidents gave Mitnick deja vu of his days as a fugitive pursued by the FBI for breaking into computer networks, only this time, he hadn't broken any laws.
"There was uncertainty, fear, and panic because I didn't know what was going on, and I didn't do anything wrong," he said in a recent telephone interview with CNET News. "In my mind, I thought I was being set up for something."
More
here.
C|Net Interview: Kevin Mitnick on hacking's evolution
Joris Evers writes in C|Net News:
To many, the name Kevin Mitnick is synonymous with "notorious hacker." He was caught by the FBI in 1995 after a well-publicized pursuit. Mitnick pled guilty to charges of wire and computer fraud and served five years behind bars.
Today, Mitnick is a computer security consultant and has written two books, including one on social engineering, his forte. He is a celebrity, especially at events such as the annual Defcon gathering of hackers in Las Vegas, where attendees ask him to sign their badges.
Mitnick spends much of his time on the road at speaking engagements. CNET News.com caught up with Mitnick after a gig at a San Francisco user event for SupportSoft, a maker of call center software, and talked to him about software security, the evolution of hacking and social engineering, and law enforcement's action against hacking.
Kevin Mitnick debunks myths
Via CNN.
To many, the name Kevin Mitnick is synonymous with hacking, the cinematic sort where a snot-nosed kid thumbs his nose at authority. But, Mitnick says, the characterization is a bit overdone and the legend untrue, if not libelous.
It is true, he says, that he broke into corporate computer systems and stole source code to satisfy his curiosity, but he denies the stories that he hacked into NORAD -- North American Aerospace Defense Command -- or that he wiretapped the FBI.
After a well-publicized pursuit that made him notorious, the FBI arrested Mitnick in 1995. He served five years in prison after pleading guilty to charges of wire and computer fraud. He was released in 2000 and today runs a computer security firm. In a telephone interview with CNN's Manav Tanneeru, Mitnick talks about his past, the state of online security today, and how he handles what his name has come to mean.
Unable to Attend HOPE: Famed Hacker, Kevin Mitnick, Felled by Flu
An AP newswire article by Frank Bajak, via ABC Technology News, reports that:
This Andean highlands capital [Bogota, Columbia] has twice felled famed hacker and security consultant Kevin Mitnick.
"I'm looking forward to getting on the first plane to the United States," Mitnick said Wednesday from his hospital room.
Mitnick, 42, said he has been laid up for some three days with a nasty flu, with a fever reaching 104 degrees.
On a separate visit back in May, the author of "The Art of Intrusion" and "The Art of Deception" said, he had spent a day in the hospital for tests after experiencing chest pains and elevated blood pressure.
More
here.
Kevin Mitnick Teaching Network Security
Image source: CNN / Mitnick Security Consulting
Rebecca Harrison
writes for
Reuters:
"Computer terrorist" Kevin Mitnick is one of the world's most famous computer hackers and became a cause celebre after breaking into networks and stealing software at companies including Sun Microsystems and Motorola.
Now Mitnick, from the United States, travels the world teaching companies how to guard against people just like him.
He argues that while sophisticated technology can help keep networks clean from viruses, it is useless if hackers can con a company's employees into handing over passwords by posing, for example, as colleagues.
More
here.
New Google VP Busted Kevin Mitnick Back in the Day
Kevin Poulsen writes on 27B Stroke 6:
Google's new vice president and general counsel is no stranger to search. As a federal prosecutor in 1995, he oversaw the manhunt that tracked down then-fugitive hacker Kevin Mitnick.
Kent Walker has served as deputy general counsel of eBay, and associate general counsel at Netscape, among other Silicon Valley posts.
But if you set the way-back machine for 1995, you'll find him an assistant U.S. attorney in San Francisco specializing in cybercrime. He issued the subpoenas that helped federal agents, and Tsutomu Shimomura, trail Mitnick to his North Carolina hideout.
More
here.
Kevin Mitnick to Write Autobiography
Via The Sydney Morning Herald.
After a seven-year wait, reformed hacker Kevin Mitnick will finally begin work on his autobiography following the expiration of a court order that prevented him from profiting from his crimes.
Mitnick spent more than five years in jail for his exploits, which included hacking into Motorola, Novell, Fujitsu, Sun Microsystems and Nokia to steal software code. He was arrested in 1995 after spending two years on the run from the FBI living under assumed names.
Since his release in 2000, he has worked as a security consultant and written two books, The Art of Deception and The Art of Intrusion. The court order preventing his profiting from his crimes expired on January 29.
"I couldn't really write my autobiography or do a movie based on my life because the Government didn't want me to profit from my story," he says. "Now I'm free to write my side of the story."
More
here.
Mitnick preaches social engineering awareness
Rodney Gedda of Computerworld Today (Australia) writes in InforWorld:
Properly trained staff, not technology, is the best protection against social engineering attacks on sensitive information, according to security consultant and celebrity hacker Kevin Mitnick.
"People are used to having a technology solution [but] social engineering bypasses all technologies, including firewalls," Mitnick said. "Technology is critical but we have to look at people and processes. Social engineering is a form of hacking that uses influence tactics."
During his keynote address at this year's Citrix iForum conference in Sydney Thursday, Mitnick said hackers are analyzing the "bigger picture" and are looking for the weakest link, which is "people like you and me".
Social Engineering 101: Mitnick And Other Hackers Show How It's Done
Elinor Mills writes on C|Net News:
Kevin Mitnick knows that the weakest link in any security system is the person holding the information.
As a young fugitive hacker, he went to jail for breaking into computer networks, mostly by using his cunning and persuasion than his tech skills. He was an early master of the science of social engineering--manipulating people into doing what you want, such as giving out passwords and other information that unlocks sensitive information on networks.
Mitnick and a panel of other hackers discussed their social engineering pranks and gave live demonstrations at the Live HOPE (Hackers on Planet Earth) conference late on Saturday.
More
here.
FOIA Docs Show Feds Can Lojack Mobiles Without Telco Help
Julian Sanchez writes on ARS Technica:
Courts in recent years have been raising the evidentiary bar law enforcement agents must meet in order to obtain historical cell phone records that reveal information about a target's location. But documents obtained by civil liberties groups under a Freedom of Information Act request suggest that "triggerfish" technology can be used to pinpoint cell phones without involving cell phone providers at all.
Triggerfish, also known as cell-site simulators or digital analyzers, are nothing new: the technology was used in the 1990s to hunt down renowned hacker Kevin Mitnick. By posing as a cell tower, triggerfish trick nearby cell phones into transmitting their serial numbers, phone numbers, and other data to law enforcement. Most previous descriptions of the technology, however, suggested that because of range limitations, triggerfish were only useful for zeroing in on a phone's precise location once cooperative cell providers had given a general location.
This summer, however, the American Civil Liberties Union and Electronic Frontier Foundation sued the Justice Department, seeking documents related to the FBI's cell-phone tracking practices. Since August, they've received a stream of documents—the most recent batch on November 6—that were posted on the Internet last week. In a post on the progressive blog Daily Kos, ACLU spokesperson Rachel Myers drew attention to language in several of those documents implying that triggerfish have broader application than previously believed.
More
here.