TalkTalk cyber-attack: boy, 15, arrested in Northern Ireland
theguardian.com
theguardian.com
Now we find out the likely candidate is a spotty teenager. I wonder how TalkTalk plan on trashing this kid now.
[0] http://www.standard.co.uk/news/crime/talktalk-hack-by-cyber-... plus many others [1] e.g. http://www.theregister.co.uk/2015/10/26/talktalk_crypto_obli...
Monthly phone has been about £18-22 per month for a few years, whilst broadband has been <£5 per month. Once you have the phone they're in profit, the cost of sending you a router has to be a few quid, paid for in the first month. I don't know what wholesale bandwidth costs but I can't imagine they can lose. They want you on broadband with them so that you don't move to another provider, it locks you in to their phone for 2 years [standard contract period in UK at the moment] securing them a profit.
Once you have the broadband they heavily push their TV packages.
Yes it's a race to the bottom but for POTS with broadband everything beyond your home socket to their servers is the same as with any other standard provider AFAICT.
They don't appear to do that much for their av.package x ~4.3 Million customers per month gross income; there should be considerable competition at the low end for what is essential a commodity.
WRT the review, I wouldn't use an ISP for my email provision but that's based primarily on lock-in; the company have https for their account pages and such (the Thawte cert is dated April 2014 FWIW).
Man, I would hate to get stuck with the carrier that got breached for "bank details and personal information of its four million customers" by a 15 year old kid. That sort of lack of security should in and of itself constitute a severe breach of customer trust and confidence.
[1] http://krebsonsecurity.com/2015/10/talktalk-hackers-demanded...
At that age you have intelligence, lack of considering consequences and importantly lots of time. That's a dangerous combination.
I would think that the 50+ crowd would be far more hampered by their risk assessment of the negative outcomes of these behaviors than by their skillsets alone.
A teen is in it for the lulz, or the glory, or whatever, but a greybeard could lose his retirement, leave his spouse high and dry, lose his ability to see and support his family...
As a colleague developer of mine says: I don't want any of my personal information on the internet because I know how developers think.
Sigh.
And time.
Man, when I think back to the stupid things I did on the internet as a teenager that simply earned me a glare or a stern warning email.... I'm so glad I was a teenager in the 90s, because if I'd done that shit today, I'd be in jail.
this is utterly ridiculous
How "nimble" your mind is really isn't important, and surely you don't think that a 15 year old can be more competent than you in a given stack.
It's just that you're not exposing yourself to the new stacks.
The OP is ridiculous that it cannot be imagined that someone needs to be a child to break into systems.
I'm at University and I run rings around my 20 something cohort.
> because greybeard's IT stack and MO is entrenched, conventional, and defendable-against
this is utterly ridiculous
> this is utterly ridiculous
A vacant comment devoid of insight, by a self-satisfied person oblivious to their predisposition to complacency.
Of course it is now many times more difficult to avoid computers than it was in in the early 1990s.
The kid exposed a major security problem and overall helped everyone, even the company in the long term.
Talk Talk are negligent, I hope a newspaper covers that angle.
http://www.legislation.gov.uk/ukpga/1998/29
75 matches for 'offence' on that page.
Sections 61 and 47 are particularly relevant. European data protection legislation really does have teeth, though the Commissioner has to have the will to use it.
If I paid for a car parking service that had the practice (not a one time incident) of leaving all their clients' cars unlocked, I'd definitively find them despicable.
While at the same time, if someone was hosting their own little personal server and forgot to apply a security patch and someone hacked it and used it for spam or as a botnet, I'd find the attacker despicable.
Perhaps class actions against negligent companies with big payout would push their insurers to breath down their neck and would result in better security.
But make no mistake, the #1 problem is incompetence among developpers. I am sure it's not a direct order from the CEO to code in a way that leaves them exposed to sql injections. It doesn't cost more money to use a parameterized query. It's just that so many people call themselves developpers and simply just don't have a clue.