Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Beware the Kindness of Strangers: The Case Against Good Samaritan Hackers
Richard Forno, 2002-03-28

The Good Samaritan defence, invoked by hackers like Adrian Lamo, can too easily be distorted by those with less altruistic intentions.

Comments Mode:
Good Samaritan Guidelines 2002-03-29
Anonymous (1 replies)
Good Samaritan Guidelines 2002-04-09
ImNotAHacker@hotmail.com
The first four letters of analogy. . . . 2002-04-01
Ira Wing (2 replies)
The first four letters of analogy. . . .whaaaat? 2002-04-04
Rick Forno (1 replies)
I'm not paid as well as you might think, but I do security consulting. Unlike your statement, I -do- care about the real vulnerabilities, but unfortunately, those making purchasing and policy decisions for our companies and government are still inside-the-box, conventional thinkers, no matter how much objective advice and hard evidence we provide them. The truth about the REAL vulnerabilities means rocking the boat - and these folks rarely want their boats rocked!

You're right - the majority of people think alike, and inside the box. They also use inferior operating systems and applications, coupled with webmin-type interfaces to make it easier for them to have the untrained monkeys do webserver admin work. Coupled with bad security practices, it's a disaster waiting to happen no doubt. But that doesn't give someone carte blanche to go banging around/against a company's networks to try and find a way in for kicks and grins, either.

Script kiddies are not a major security THREAT in my opinion, and I certainly don't go around proclaiming 'billions of dollars' in damage from some lamer's attempt to cause electronic annoyances on the network be it Code Red, Nimda, or Iloveyou..... nor do I put much danger on them in my approach to security. Those figures, from Computer Economics or whoever, IMO, are sensational, first-rate FUD and should be taken with a BIIIIG grain of salt.

Oh, yes.....I'm glad that you're not me either. I'm fine just the way I am. :)


[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/70/11645#11645
The first four letters of analogy. . . . 2002-04-04
Andy Richmond (1 replies)
We're both right. 2002-04-13
Ira Wing
Case Against 2002-04-02
Spade
Beware the Kindness of Strangers: The Case Against Good Samaritan Hackers 2002-04-03
Andy Schmitt (kphrakNO@worldofschmittSPAM.ALLOWEDcom) (1 replies)
"...Good Samaritan Hackers" Bad English. 2002-04-05
Andy Richmond (1 replies)
right.. 2002-04-09
Anonymous
Which law? 2002-04-04
80N
What about the "lurkers"? 2002-04-12
Bob Radvanovsky
Digital Vigilantism? 2002-04-12
Bob Radvanovsky







 

Privacy Statement
Copyright 2009, SecurityFocus