Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Interview with Marcus Ranum
Federico Biancuzzi, 2005-06-21

Comments Mode:
Good! 2005-06-21
Anonymous
Interview with Marcus Ranum 2005-06-21
Steve Lodin
Interview with Marcus Ranum 2005-06-22
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum
If the CTOs of 10 FORTUNE 500 firms .... 2005-06-22
Andrew Yeomans
Interview with Marcus Ranum 2005-06-22
some guy in Central PA (1 replies)
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum (1 replies)
Interview with Marcus Ranum 2005-06-22
Anonymous
Interview with Marcus Ranum 2005-06-22
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum (2 replies)
Re: Re: Interview with Marcus Ranum 2005-06-22
Anonymous (1 replies)
Re: Re: Re: Interview with Marcus Ranum 2005-06-23
Marcus Ranum (1 replies)
Blame 2005-06-22
Anonymous (1 replies)
Re: Blame 2005-06-22
Marcus Ranum
Interview with Marcus Ranum 2005-06-22
Anonymous
What a genius! 2005-06-22
Pete (4 replies)
Re: What a genius! 2005-06-22
Anonymous (1 replies)
Re: Re: What a genius! 2005-06-27
Anonymous
Re: What a genius! 2005-06-22
Marcus Ranum
Re: What a genius! 2005-06-23
Anonymous
Re: What a genius! 2005-06-23
Anonymous
Interview with Marcus Ranum 2005-06-22
B Maurice
Interview with Marcus Ranum 2005-06-22
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum
Interview with Marcus Ranum 2005-06-22
Anonymous
Interview with Marcus Ranum 2005-06-22
Anonymous
Interview with Marcus Ranum 2005-06-22
Anonymous
Interview with Marcus Ranum 2005-06-22
Tails (2 replies)
Re: Interview with Marcus Ranum 2005-06-22
Anonymous
Re: Interview with Marcus Ranum 2005-06-22
Marcus Ranum (7 replies)
Re: Re: Interview with Marcus Ranum 2005-06-23
Kevin Fink
I'm not sure how useful a statement that is, though. Without users none of the security threats would matter, either. So what?

To move towards solutions, you have to understand the issues, to understand the issues you have to understand the people, and to understand the people you have to understand their motivations.

That means you have to separate the whitehats from the blackhats - their motivations are completely different. I think that most people would agree that whitehats are primarily motivated by a combination of curiousity, thrill-seeking, and need for notoriety. Blackhats are primarily motivated by some combination of political aims, emotional issues, and financial needs. Those are very different drivers, and need to be addressed completely differently.

By the way, your interview did strongly imply that you were talking specifically about whitehats, not the larger class of hackers:

They're the ones who place their desire for fun ahead of everyone on earth's desire for peace and [the] right to privacy.

As discussed above, I don't think the blackhats are doing this for fun. I think they're doing it because they're angry at someone, want to make money, are trying to make a socio-political point of some sort, etc. Computer crime is just a tool to them - not fundamentally any different than extortion, bank robbery, or car bombing.

So you're not going to stop exploitation of security threats by convincing "hackers" that building web applications is more rewarding than finding and demonstrating a hole in someone's security.

That's probably enough for a comment board posting ...

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/334/32062#32062
Re: Re: Interview with Marcus Ranum 2005-06-23
Anonymous (1 replies)
Re: Re: Interview with Marcus Ranum 2005-06-25
rabidpacketmonkey
Re: Re: Interview with Marcus Ranum 2005-06-28
Norman Yarvin
Interview with Marcus Ranum 2005-06-22
trip (1 replies)
Re: Interview with Marcus Ranum 2005-06-23
Marcus Ranum
Good Article 2005-06-22
JC
What A Total Jackass 2005-06-22
Anonymous (1 replies)
Re: What A Total Jackass 2005-06-23
Marcus Ranum (1 replies)
Re: Re: What A Total Jackass 2005-06-29
Anonymous
Marcus Ranum blaming hackers???? 2005-06-22
pw (2 replies)
Re: Marcus Ranum blaming hackers???? 2005-06-23
Marcus Ranum
no, blame the victims 2005-06-24
Anonymous
SE/Linux 2005-06-22
Luke Kenneth Casson Leighton (1 replies)
Re: SE/Linux 2005-06-29
Anonymous
Interview with Marcus Ranum 2005-06-23
Rastor5
Interview with Marcus Ranum 2005-06-23
Anonymous
distribution of responsability is well put 2005-06-23
Martin-Éric Racine
Interview with Marcus Ranum 2005-06-23
Anonymous
Blame the Hackers? 2005-06-23
Bob (1 replies)
Re: Blame the Hackers? 2005-06-29
Marcus Ranum
Interview with Marcus Ranum 2005-06-24
Phil Agcaoili
his comments about the RFC process 2005-06-24
Reinier Post
Interview with Marcus Ranum 2005-06-24
Anonymous (2 replies)
Re: Interview with Marcus Ranum 2005-06-27
M. Andrew Molitor
Re: Interview with Marcus Ranum 2005-06-28
Anonymous (1 replies)
Interview with Marcus Ranum 2005-06-27
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-07-11
Anonymous
80% spyware & 15% keyloggers? 2005-06-28
Anonymous
Interview with Marcus Ranum 2005-06-28
Anonymous (1 replies)
Re: Interview with Marcus Ranum 2005-06-29
Marcus Ranum
Interview with Marcus Ranum 2005-06-29
David
Agressive network configuration 2005-07-05
Stephen T
Interview with Marcus Ranum 2005-07-06
Anonymous
Think about it... 2005-07-16
Johann van Duyn
Interview with Marcus Ranum 2007-07-11
John Cowan
Interview with Marcus Ranum 2007-11-27
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus