ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Hacker Mitnick testifies before Senate

Joel Deane ZDNet.co.uk

Published: 03 Mar 2000 10:25 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

In 20 years of hacking, Kevin Mitnick says he only once failed to penetrate a computer system. "It was a computer system run by one individual. And this computer was in his home and it was in the UK, in England, and I was unable to circumvent the security in that system because I didn't have control of BT [British Telecom (quote: BT)]," Mitnick told the Senate Governmental Affairs Committee on Thursday.

During his testimony, Mitnick -- who was only released from a medium security prison in California on 21 January -- offered tantalising insight into his life as a computer intruder, and also took the opportunity to take another swipe at the FBI for "enticing" him back into illegal hacking activities.

Regarding that unsuccessful hacking attempt, Mitnick, who in the past has cracked computer systems belonging to Motorola, Fujitsu and Sun Microsystems, said he targeted the computer because it belonged to an "individual" who had found vulnerabilities in Digital Equipment's VMX operating system. "And my goal was obtaining information on all security vulnerabilities so I'd be effective in compromising any security system that I chose to compromise," he said.

However, the hacker said he found his target "extremely difficult" to crack because "this person was very, very sharp" on computer security. "See," Mitnick said, "the real important point is that the more people that have access to a computer system, the easier it is to penetrate. For social engineering an exploit into government or into large corporations, it's very easy."

Dressed in a jacket and tie, and rocking gently back and forth in his chair as he answered questions, the bespectacled Mitnick, 36, was the star witness at Thursday's Senate hearing. He was convened to discuss online security following last month's spate of Denial of Service attacks against eight major Web sites, including ZDNet.

To thwart computer attacks, Mitnick suggested that each US government agency assess the risk to its systems and do a cost-benefit analysis on protecting them. Mitnick also applauded as a "good first step" a pending bill to beef up federal information security practises. But, he said, the bill should go further to create an audit and oversight program that measures compliance and a numeric "trust ranking" that would quantify its results.

North Carolina Senator John Edwards asked Mitnick whether hacking was a "physical addiction". Mitnick: "I enjoyed it. I would say it was a distinct preoccupation, but I don't think I could label it an addiction, per se."

Edwards: "Did you ever try to stop?"

Mitnick: "I did stop for a while. And then at that time that I wasn't engaging in that behaviour, the Department of Justice, specifically the FBI, sent this informant [hacker Justin Petersen] to target me. And, basically, I got hooked back into computer hacking because of the enticements that this fellow that they sent to target me -- you know -- kind of enticed me back into that arena."

Mitnick went on to say that he didn't encourage "any activity, which maliciously destroys, alters or damages computer information". "Breaking into computer systems is wrong," he added.

Mitnick is not the first hacker to appear before the Governmental Affairs Committee, chaired by Senator Fred Thompson of Tennessee. In May 1998, L0pht, a Boston-based hacker group that recently went corporate, also testified on computer security.

In a statement issued before Thursday's hearing, Thompson said federal agencies continue to "use a band-aid approach to computer security". "Hopefully, the recent breaches of security at the various dotcom companies is the wake-up call needed to focus attention on the security of government computer systems," he said.

Reuters contributed to this report.

What do you think? Tell the Mailroom and read what others have to say.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
60 out of 133 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:























Related Jobs

Security Consultant Ethical Hacking / Penetration Testing - London

Responsibilities: - Deliver security assessment services including network scanning, vulnerability testing, penetration testing, search engine ...

Senior Credit Counterparty Risk, Commodities Products

You will also be responsible for presenting proposals to the credit committee. Leading Investment Bank currently seeks an experienced credit analyst ...

Market Risk Specialist AAA Investment Bank

You will further develop risk methodologies to support the strategic decisions made by the Executive Committee. As a member of the market risk team ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment