Home > Security Tips > Guest Commentary > Of hackers and Hannibal Lechter
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

GUEST COMMENTARY

Of hackers and Hannibal Lechter


Ira Winkler, CISSP
01.25.2004
Rating: -3.47- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


I believe that most people in the industry know in their gut that hiring a hacker, specifically someone who breaks into systems and commits other computer related crimes, is wrong. Unfortunately, many others don't really understand the nature of computer crimes and think it's OK to hire a felon or would be felon.

The basic issue is that most people believe that hackers have some specialized knowledge unique to criminals. If you don't understand computers, surely someone who can compromise them must be a computer genius. Clearly, just because you can stab a person, it doesn't mean you're qualified to be a surgeon.

Can surgeons more efficiently kill people? Probably so. But they don't, because they are generally good, talented people who don't commit crimes. There could be a genius, psychotic doctor out there like a Hannibal Lechter, but they are very few and far between -- if they exist at all.

Computers are the same way. Just because you can stab (a.k.a. hack) a computer, it doesn't mean you know how to repair it. An expert social engineer has no clue as to how to implement an organization-wide awareness program. A person who can download an IIS exploit usually has no clue how to patch that problem or fix a SQL vulnerability.

For some reason though, the general public, and even some people in information security, buy into the myth that hackers are computer geniuses because someone leaves default passwords on critical servers or something similar. They can kill computers so they must make a brilliant computer security specialist. That just isn't so.

The mere act of breaking into a computer without permission is a crime. It creates risk of damage. Even if the hacker tells you everything he did, you still have to assume the worst and reinstall all systems from scratch. Also, under California's SB 1386 regulation, enterprises must inform California residents if certain personally identifiable information is compromised while in an unencrypted form. That and the resulting effects can cost millions of dollars.

Now for the biggest crock of garbage out there; the concept of self-proclaimed "reformed" hackers. Reformation is a state of mind, not a proclamation. That a person hasn't been arrested for a crime since his release doesn't mean he's reformed. Does he consistently take full responsibility for his crimes and avoid further temptation? Does he admit what he did was a crime in the first place or call it a teenage hobby? Does he blame others for his arrest or say he shouldn't have been arrested?

There is a difference between a teenager who is scared straight, and a repeat, career criminal. However you have to be very careful, as criminals tend to hide their complete records, and most of their crimes don't even make it to their record.

I want to reiterate though that ethical considerations are secondary to the fact that they don't have the basic skills of trained professionals. Hire resumes and experience, not criminal records and felonies. The Hannibal Lechters of computers are few and far between. Show me a felon and I can show you 30 professionals who are as good, if not better. Admittedly there are some professionals who are criminals or incompetent, however it doesn't mean you accept proven criminals.

Would you want Hannibal Lechter to operate on you? He's probably a great surgeon, but he might be tempted to grab a kidney for a quick snack.

About the author
Ira Winkler, CISSP, CISM is chief security architect at Hewlett-Packard. He is also author of the forthcoming book, Spies Among Us (McGraw-Hill).


FOR MORE INFORMATION:
  • SearchSecurity editors Mia Shopis and Crystal Ferraro face-off on the topic of hiring hackers.
  • Ira Winkler further dispels the hacker myth in this Guest Commentary Q&A.

Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Information Security Laws, Investigations and Ethics,   Information Security Management,   Application and Platform Security,   Enterprise Vulnerability Management,   Security Testing and Ethical Hacking,   Security Basics,   Editorials and Opinion,   Security Management,   General Information and Discussion,   Human Resource Issues,   Guest Commentary,   Hacker Tools and Techniques: Underground Sites and Hacking Groups,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Information Security Laws, Investigations and Ethics
Melissa Hathaway urges more cooperation, government attention to cybersecurity
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity

Security Testing and Ethical Hacking
Could Metasploit popularity erode?
Metasploit Project acquired by vulnerability management firm Rapid7
Should management processes change based on a patch release schedule?
Does an EULA make it truly illegal to decompile software?
Screencast: BackTrack 4 offers an arsenal of penetration testing tools
Security testing firm uncovers XML vulnerabilities
Screencast: Samurai offers pen-testing nirvana
The requirements needed to make an external penetration test legal
McAfee to acquire Solidcore Systems for whitelisting
The Pipe Dream of No More Free Bugs

Editorials and Opinion
The best of SearchSecurity.com
Getting back to basics
Best of SearchSecurity in January 2004
Fighting the hacker myth
Security in 2004: More of the same
Inconsistent terminology is a security hobgoblin
June 2003: The Month in Review
A feasible plan for a central virus-naming body

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
FERPA  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts