Hacker News new | ask | show | jobs
by dobbsbob 4798 days ago
Internet cred applies to pen cred surprisingly. If you go down for hacking and do not become an informant, you will find job offers inside the pen for teaching other criminals comsec so they can run their outside drug operations. If they can read about you then it applies to your standings in the pen hierarchy.

That's why prison is never rehab for hackers. They just network with the street criminals and come out super criminals with full cred like Max Vision or the software developer kid here where I live that did a bid for bank fraud, met some gangsters in prison, paroled as a ranking member in their violent dial a dope crew and police have been unable to break up the gang since he joined and took over the comsec and allegedly money laundering for them. They accused him of being able to leak the whereabouts of rivals to his own gang too by social engineering the media and police, plus hacking their blackberries. Strong security knowledge + violent criminal pact with bikers = not good

1 comments

How do you know stuff like this? Can you recommend a good book that covers recent history?
You might find this book interesting. http://www.amazon.com/Kingpin-Hacker-Billion-Dollar-Cybercri...

I've read it and can confirm its a good read. I think this guy was arrested in 2005 or 2007 but that's going on memory from over a year ago.

Good, entertaining read. I get the impression it was sanitized a great deal, because I was sorely disappointed with the lack of technical meat-n-potatoes.

For instance, the author totally glossed over how they recovered the data from his encrypted storage at the end. Was the PC left on and the screen not locked? Cold boot attack? Brute force? Hell, they didn't even specify exactly which crypto software was used.

He fell asleep while he left his servers on. So they simply siphoned the keys from memory. He used some proprietary Israeli made encryption software and FreeBSD, but it didn't matter because everything including Truecrypt keeps your keys in memory when mounted.

Even if his server was off, they could have broken into his safehouse and sabotaged the unencrypted bootloader. Only defense against this is use OpenBSD 5.3 which allows booting from fully encrypted drives, or keep your unencrypted boot partition on a usb stick you carry around.