[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: I am a god. You suck!
- Subject: Re: I am a god. You suck!
- From: nathan@visi.com (Nathan Mates)
- Date: 1996/08/05
- Newsgroups: comp.sys.apple2
- Organization: (missing)
- References: <4tums0$ls7@news.wco.com> <4u317h$e7s@news.vanderbilt.edu>
In article <4u317h$e7s@news.vanderbilt.edu>,
Tilghman Lesher <lesherjt@vuse.vanderbilt.edu> wrote:
>Well looks like the #appleiigs boys are at it again. Breaking
>into other people's accounts. Hopefully, this shows just how
>juvenile and untrustworthy these folks are.
Do you have anything to back up your statements, or are you just
trying to flame because that's all you _can_ do? #appleiigs is _NOT_ a
hotbed of people breaking and entering the pentagon's computers before
breakfast-- if it was, it wouldn't be a channel where everyone could
join and listen to what we say at will. [Tip: Remember Matt Carlson?
We were the ones who tracked down his real address, phone number,
etc. Not anyone else.] If someone on #appleiigs did do the dirty job
of hacking Dr. Tom's account, they've shut up about it when I'm
around. (And it wasn't me; let's get that slander over with
immediately.)
Since you seem to be clueless about it, let's give you a free
tip (or few) on unix security...
HOW TO MAKE A SECURE UNIX SYSTEM:
1. Disconnect all cables from machine, especially power
2. Lock in safe or bank vault
3. Throw away the key
4. (optional) Destroy with nuclear weapon
Anything less than this can be considered wide open to people in
the know. Unix security holes are discovered and documented by the
right people (CERT-- Computer Emergency Response Team) on a
frightening basis (usually several per month). Although a large number
of these are due to sendmail (the program used to deliver most
internet mail. In short, a program running with the same privledges
as a system administrator, able to do whatever it wants), there's a
fair number in login and other network programs. And you can bet that
if there are a fair number of _documented_ bugs, then crackers have a
lot more undocumented ones at their fingertips.
Even if your programs are reasonably secure, there's the idiots who
leave guessable passwords. (That scene in _Clear and Present Danger_
where they talk about people who use family birthdays as passwords is
NOT fiction. It happens way too often). The dope who uses a english
word like 'iloveapples '1wswrulz' 'ihateprogrammers' 'sectoreditor' or
'imclueless' is _ASKING_ for their account to be cracked by amateurs.
[Also, it's been calculated that for $10 million, you can buy a
computer(s) (off the shelf from Cray or a network of workstations)
that'll crack _ANY_ password in <10 seconds. If you think that the US
government (let alone those engaging in industrial espionage) doesn't
have a few of those boxes, you're living in a fantasy. If you don't
mind waiting longer than a few minutes, you can do so with a few
pentium boxes or workstations. All you need is one hacked account on a
system to be able to do 2^7 times the damage to the system.]
A few months ago, it was reported that US Military computers were
broken into at the rate of several thousand times last year. Is there
a solution to that? Not easily. Are civilian computers less of a
target? Heck no.
Also, last weekend was DefCon IV. That's a convention of crackers
and other computer miscreants. Even though the government bugged the
heck out of the hotel in Las Vegas where it happened, you can bet that
a lot of information passed hands about cracking systems. I've never
attended one of those, but some guys from work did, and they came back
with T-Shirts showing common computer security holes that aren't
always fixed. The ability to take out systems is NOT a rare art,
despite what the media would like you to believe.
Do _YOU_ feel sure that your account is secure? Get over it, and
fast. Computer security is an oxymoron. WAY too many bugs exist, WAY
too many people know how to fix holes, WAY too many sysadmins are busy
all day answering clueless (l)user's questions to bother to fix what
they're running.
#appleiigs may have a fair number of people who have a clue about
unix systems (because a number of us _RUN_ systems and have to protect
them against crackers), but to think that we are the only Apple II
folks who also know unix, you must have your head up your nether
regions. To think that there aren't others (Matt Carlson? The
anonymous posters?) who aren't #appleiigs folks who dislike people,
you're denying reality to try and flame.
Nathan "Take all measures you know, and _still_ pray that nobody good
attacks your computers" Mates
--
<*> Nathan Mates http://www.visi.com/~nathan/ <*>
# What are the facts? Again and again and again-- what are the _facts_?
# Shun wishful thinking, avoid opinion, care not what the neighbors
# think-- what are the facts, and to how many decimal places? -R.A. Heinlein