Home > Security Tips > Guest Commentary > Of hackers and Hannibal Lechter
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

GUEST COMMENTARY

Of hackers and Hannibal Lechter


Ira Winkler, CISSP
01.25.2004
Rating: -3.47- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


I believe that most people in the industry know in their gut that hiring a hacker, specifically someone who breaks into systems and commits other computer related crimes, is wrong. Unfortunately, many others don't really understand the nature of computer crimes and think it's OK to hire a felon or would be felon.

The basic issue is that most people believe that hackers have some specialized knowledge unique to criminals. If you don't understand computers, surely someone who can compromise them must be a computer genius. Clearly, just because you can stab a person, it doesn't mean you're qualified to be a surgeon.

Can surgeons more efficiently kill people? Probably so. But they don't, because they are generally good, talented people who don't commit crimes. There could be a genius, psychotic doctor out there like a Hannibal Lechter, but they are very few and far between -- if they exist at all.

Computers are the same way. Just because you can stab (a.k.a. hack) a computer, it doesn't mean you know how to repair it. An expert social engineer has no clue as to how to implement an organization-wide awareness program. A person who can download an IIS exploit usually has no clue how to patch that problem or fix a SQL vulnerability.

For some reason though, the general public, and even some people in information security, buy into the myth that hackers are computer geniuses because someone leaves default passwords on critical servers or something similar. They can kill computers so they must make a brilliant computer security specialist. That just isn't so.

The mere act of breaking into a computer without permission is a crime. It creates risk of damage. Even if the hacker tells you everything he did, you still have to assume the worst and reinstall all systems from scratch. Also, under California's SB 1386 regulation, enterprises must inform California residents if certain personally identifiable information is compromised while in an unencrypted form. That and the resulting effects can cost millions of dollars.

Now for the biggest crock of garbage out there; the concept of self-proclaimed "reformed" hackers. Reformation is a state of mind, not a proclamation. That a person hasn't been arrested for a crime since his release doesn't mean he's reformed. Does he consistently take full responsibility for his crimes and avoid further temptation? Does he admit what he did was a crime in the first place or call it a teenage hobby? Does he blame others for his arrest or say he shouldn't have been arrested?

There is a difference between a teenager who is scared straight, and a repeat, career criminal. However you have to be very careful, as criminals tend to hide their complete records, and most of their crimes don't even make it to their record.

I want to reiterate though that ethical considerations are secondary to the fact that they don't have the basic skills of trained professionals. Hire resumes and experience, not criminal records and felonies. The Hannibal Lechters of computers are few and far between. Show me a felon and I can show you 30 professionals who are as good, if not better. Admittedly there are some professionals who are criminals or incompetent, however it doesn't mean you accept proven criminals.

Would you want Hannibal Lechter to operate on you? He's probably a great surgeon, but he might be tempted to grab a kidney for a quick snack.

About the author
Ira Winkler, CISSP, CISM is chief security architect at Hewlett-Packard. He is also author of the forthcoming book, Spies Among Us (McGraw-Hill).


FOR MORE INFORMATION:
  • SearchSecurity editors Mia Shopis and Crystal Ferraro face-off on the topic of hiring hackers.
  • Ira Winkler further dispels the hacker myth in this Guest Commentary Q&A.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Information Security Laws, Investigations and Ethics
Do BlackBerrys and other mobile devices put sensitive data at risk when used overseas?
Anti-cybercrime legislation sent to president
DHS should lose cybersecurity authority, experts say
Google amends log retention rules, privacy advocates respond
Security Certifications' Ethics Programs Merely Window-Dressing
MIT case shows folly of suing security researchers
What vendors would you recommend for software write-blockers?
TJX hacking ring charged in federal indictment
IBM X-Force report critical of independent security researchers
Valuable lesson emerges from DNS flaw handling

Penetration Testing and Ethical Hacking
Screencast: Collecting metadata with Metagoofil
Penetration tester explains secrets to accessing corporate systems
Screencast: How to use Wikto for Web server assessment
Security Services: QualysGuard Security and Compliance Suite
What are the pros and cons of zero-knowledge penetration tests?
Information security book excerpts and reviews
Screencast: Penetration testing with Metasploit
IBM's Watchfire halts network research, focuses on Web apps
Google hacking exposes a world of security flaws
Core Security selects former Sophos exec as new CEO

Organized Cybercrime
Symantec values market for stolen data at $276 million
McColo shutdown won't stop spam, malware, warn security experts
Express Scripts offers reward in hacker extortion case
Programmer charged for sniffer used in TJX breach
Anti-cybercrime legislation sent to president
Web security threats gaining attention at many companies
EV SSL certificates won't stop phishers, researchers say
Stolen data ending up in Google cache, say researchers
Built-in Windows commands to determine if a system has been hacked
Exploit research: Keeping tabs on the hacker underground

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
cypherpunk  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
More Security Resources for Resellers, VARs and OEMs
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts