Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

2011: The year hacking goes mainstream

These days, if you're not a hacker, you're probably being hacked

I've said it before and I'll say it again.This will be the year of the hacker --- or rather, the year hacking goes mainstream.

It's been brewing for quite some time. According to McAfee, a team of Chinese hackers has been infiltrating computer networks for the world's largest oil and gas companies. Last week the Wall Street Journal reported that Nasdaq's network was penetrated (though not the Nasdaq market --- as far as we know). And the ongoing battle between Anonymous and the folks who are aiming to take it down is just heating up.

[ Also on InfoWorld, Cringely looks at the AOL-Huffington Post buyout and warns: The mediocre shall inherit the Web. | For a humorous take on the tech industry's shenanigans, subscribe to Robert X. Cringely's Notes from the Underground newsletter. ]

Before you fire up your email program or leap immediately to the comments to correct me: Yes, I know -- "hacker" isn't the right word for this kind of activity. Hackers are not necessarily criminals or even evil-doers. There are white-hat, black-hat, gray-hat, and the occasional houndstooth-hatted hackers.

The appropriate word for people who attack computer systems for their own nefarious criminal purposes is "cracker." But to most people, a cracker is either something you spread cheese on or someone you try to avoid at cocktail parties. These days everybody understands "hacker" --- at least, the Hollywood version. Sorry, but that's just the way it is.

And when hackers get tired of eating Doritos for dinner and have actual bills to pay, they grow up to be highly paid security consultants who are hired to do battle with their younger doppelgangers.

Case in point: The war between HBGary Federal, a security firm hired by the FBI to suss out who was behind the revenge attacks on assorted "enemies" of WikiLeaks and Anonymous.

Last weekend, HBGary CEO Aaron Barr made the fatal mistake of bragging to the Financial Times about how his firm had managed to infiltrate the computers of leading members of Anonymous. Per the FT:

Of a few hundred participants in operations, only about 30 are steadily active, with 10 people who "are the most senior and co-ordinate and manage most of the decisions," Mr. Barr told the Financial Times. That team works together in private internet relay chat sessions, through e-mail and in Facebook groups. Mr. Barr said he had collected information on the core leaders, including many of their real names, and that they could be arrested if law enforcement had the same data.

You'd think he'd know better. But no. Sure enough, HBGary's servers got hacked and Barr's Twitter account got hijacked by, yes, Anonymous. They posted Barr's address, phone number, and Social Security number on his Twitter feed, and sent out numerous taunting tweets on his behalf. They also hacked HBGary's website and replaced it with this message, which reads in part:

You have blindly charged into the Anonymous hive, a hive from which you've tried to steal honey. Did you think the bees would not defend it? Well here we are, You've angered the hive, and now you are being stung.

Writing for CSO online, guest blogger Nick Selby sums up Barr's boneheadedness:

I don't know much about law enforcement, but I do think that, if you're planning, say, to serve a felony warrant, it's a bad idea to phone ahead and let the guy know you'll be by in 15 minutes. ... Criminals generally engage in criminal enterprises for the money (few people have a driving passion to establish, say, an industry-leading counterfeiting ring for the societal benefit), and those who stand between criminals and their goal risk the ire of the criminals. ... Now, stating in a newspaper that you possess the secret identity of a criminal? This falls squarely into the category of "standing between a criminal and his goal." That's a tip, kids. Write it down. To paraphrase Wendy in A Fish Called Wanda, one only briefs the public on an upcoming law enforcement action if one is congenitally insane or irretrievably stupid.

Anonymous also published somewhere between 44,000 and 60,000 emails between HBGary and its corporate/government customers. And what was inside those emails was an eye-opener.

It seems HBGary was working with Bank of America on a plan to take down WikiLeaks -- and, strangely, CNN and Salon commentator Glenn Greenwald, whom it deemed instrumental to WikiLeaks' continued existence, along with a handful of other prominent journalists.

HBGary was one of five firms allegedly involved in the discussion, along with law firm Hunton & Williams, data-gathering firms Palantir and Berico, and consultants Booz Allen Hamilton. Business Insider published the slides this group prepared for BofA. It's pretty chilling. To quote slide 5:

Glenn was critical in the Amazon to OVH [hosting] transition...It is this level of support that needs to be disrupted. These are established professionals that have a liberal bent, but ultimately if pushed most of them choose professional preservation over cause, such is the mentality of most business professionals. Without the support of people like Glenn wikileaks [sic] would fold.

What do you suppose they meant by "pushed"? As in, over a cliff?

That presentation suggests strategies such as sowing dissension within the WikiLeaks org, disinformation (submitting false documents to WikiLeaks in order to discredit it), cyber attacks against WikiLeaks' service providers, a media smear campaign, and "using social media to profile and identify risky behavior of [WikiLeaks] employees."

Does that last one sound like blackmail to you?

HBGary is trying to sell the idea that Anonymous falsified some of the documents, but I doubt anyone's buying it. Palantir has already publicly apologized to Greenwald and severed its ties with HBGary, which suggests the information contained in that leak is accurate.

To recap: A massive U.S. corporation is targeting whistleblowing websites and mainstream American journalists, with the help of several data/security/consulting firms with strong ties to the U.S. government. It sounds like the plot of a Hollywood summer blockbuster. It's not.

So tell me: Who are the white hats and who are the black hats here?

Fasten your seatbelts. It's going to get a lot more bumpy from here on out.

Does all this corporate hacking hack you off too? E-mail me: cringe@infoworld.com.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Amazon, AOL, Booz, CNN, Facebook, FBI, Federal Bureau of Investigation, McAfee, NN, Wall Street, Yahoo
References show all

Comments

1

Chris Bennett

Mon 14/02/2011 - 11:30

I'd like to point out that HBGary Federal were not hired by the FBI to snoop on Anonymous. They did this off their own back in order to garner media appeal.

Unfortunately for them, they stirred up a hornets nest and got their just deserts. The interesting thing to note is that in the course of the hack they were exposed as being one of three security firms who where hired to potentially discredit WikiLeaks. As there is no evidence that they have even attempted to do this, though, the whole point is moot.

2

Ron Willison

Mon 14/02/2011 - 13:54

Sorry Chris I have to disagree some. This is a big deal. And what it demonstrates is to what ends people of power will go to in order to defend their statue quo. It does matter that we the people have been systematically robbed on a grand scale by those we have placed in power since the enactment of the federal reserve Act of 1913. It does matter that those same people are perfectly comfortable with turning our Constitution and bill of rights into toilet paper. And if you think The Patriot act and Joe Lieberman's pending Kill The Internet Button Cyber Security Bill are moots points. I really hope you are in the minority. Here in the US. Our Govt. are supposed to represent us. "WE THE PEOPLE" When they take us to war. Every person on all sides that are killed or maimed sits on our, WE THE PEOPLES" shoulders. WE have to carry that weight around. And frankly my friend that don't sit well with me.

3

Chris Bennett

Mon 14/02/2011 - 15:56

Hi Ron, I agree that they should be working for the people. I was taking issue with the facts of the story. The FBI *DID NOT* hire HBGary Federal to spy on Anonymous. It was wrong for them (HBGary Fedreral) to snoop, but they did it for their own ends with the hope of SELLING the data to the FBI AFTER THE FACT.

I was merely hoping to resolve the confusion with the facts of the case. I do not live in the USA, and I do see the erosion of rights happening in your country. These same rights are being eroded in my country too (Australia).

What is the most INTERESTING thing from the whole saga is that the BoA wanted to use questionable tactics against WikiLeaks. As somebody who is somewhat sympathetic to WikiLeaks cause, I have an issue with the tactics discussed - however less of an issue because they were not actually employed.

4

Jas Angre

Tue 15/02/2011 - 01:20

You are kidding aren't you?

"I have an issue with the tactics discussed - however less of an issue because they were not actually employed."

What do you think has been and is going on if these tactics are not now being employed?

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: mcafee, security
Latest Blog Posts
Whitepapers
  • Fixing Your Dropbox Problem - How the Right Data Protection Strategy Can Help
    It’s estimated that more than 50 million people have used public cloud storage services such as Dropbox to share and exchange files. Public cloud services are so easy to use that their openness can undermine existing IT policies regarding the transmission of confidential data. With data volumes threatening to overwhelm onsite storage, IT managers are looking to find a solution that’s affordable and secure. This paper details a simple three-step approach to helping users manage access to the public cloud without placing your data or your business at risk. Read on.
    Learn more »
  • HP ePrint Enterprise mobile printing solution
    The merger of mobile devices and cloud services has become one of the most significant enablers of business productivity and innovation in the past decade. We now hold the power of communicating and computing in the palms of our hands, nearly anywhere business or life takes us. However, one key business process has eluded the mobility movement: printing. Even the most technically enabled business travelers find themselves hunting down print services while on the road and interrupting IT managers when visiting a branch office simply to print a document. But finally, a truly mobile print experience is available—helping enterprises to drive business productivity further. Read more.
    Learn more »
  • Customer Case Study: Yarra Valley Water Turns to Enterprise Software to Improve Information Flow
    “We don’t need to wait till month-end for management reports—they’re now available whenever we need them. We have much more efficient management, as everyone across the organization is looking at the same set of figures. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments