‘We Got to Be Cool About This‘: An Oral History of the LØpht, Part 1
duo.com
duo.com
I honestly feel that in the current day and age, if anyone tried the same stuff many of us got away with in the early 2000s (or 90s), then the punishment would be much much stricter. Not sure how that gets in the way of people learning by "banging things together till they work", which was a major source of learning for me.
Damn, I feel old now!
From poring over stuff from this milieu, I figured out how I could change grade records at my school. I never did it, so I don't know what would've happened if I got busted.
Some kid in the Bay Area just got busted for the same and is facing 14 felony charges.
Anyway. This was my first encounter with hacker culture, and it was so brain expanding even though I understood practically none of it. Now, I could barely recount more than the few sentences I just did, but that logo brings up waves of nostalgia.
> We wrote numerous search warrants to get the IP addresses of the possible phishing site email. We got it and we did good old fashioned police detective work and we narrowed it down to an address
Good old fashioned police detective work indeed.
[1] http://www.ktvu.com/news/concord-student-accused-of-hacking-...
It always amazes me that the person who effectively opens an unlocked door gets the book thrown at them while the people who left it unlocked get off scot-free.
Plus, negligence can be a crime, too.
But it's natural that someone who commits a crime receives a harsher punishment than someone who neglects to put all relevant deterrents in place.
I never used it for anything evil per se, but I did unblock the football site we were told would be unblocked, and other sites that teachers were told would be unblocked but weren't. Problem was, when you signed in there was a nice box that said "Users Online" and showed their names. One day the DTC signed in as I was online and promptly the phone rang and I was told to take my hands away from the computer and walk to the office. I had to show her what I had done, and ended up being suspended from school computers for two weeks. I couldn't imagine the things I would be accused of if it happened today. Thank god I was a straight A student and favored by everyone in the community. I also had my Starcraft 2 collectors edition USB confiscated because I had the portable onion browser on it, and my friends called it the 'stick of freedom.' Imagine if the term darkweb was as highly villainized then as it is today.
I was lucky enough to start working with the school when I was 16 (now 20.) I remember the description of the look on the regional contact from the state when the DTC told him that the district had given me a key to the school and the equivalent of domain admin in our environment. Rightfully so, but I proved myself and my worth.
Bit long of a response for something so simple, and full of nostalgia as well. It's just a shame to see that curiosity and investigation is so heavily frowned upon.
There are still resources for this CTF365 comes to mind and the Offensive Security lab for their certs. There are also awesome people putting up networks you are invited to attack for free, there was one that was part of a workshop at HOPE XI but I can't recall the site. And running even multiple VMs to practice with is something a lot of people can do today.
The 90's in the school's computer lab may have felt differently if you escaped any sort of punishment for exploration, but the CFAA was first enacted in 1986 and the punishment for computer crimes have been disproportional since before then, owing to societal lack of understanding of how computers actually work.
I still have the sticker somewhere.
However the front page hasn't been updated since 2015.
The one thing everyone involved with the L0pht and cDc has that you probably don't is age; they were doing this stuff in the 1990s and had time to make a name for themselves. But things move so much faster now than they did in the 1990s, that differentiator gets less and less forbidding every day.
It has, though basically every one of the now-respectable-looking professional security outfits you could point to has one or more of these late 80s early 90s "mystique era" hackers working for it (and I can probably tell you what their old bbs handle and/or irc nick was).
When I was still discovering the computer and internet world, they were already "giants" in the space, so of course they would seem like the epitome of what I wanted to achieve.
"I want to be like them and be able to do the stuff they do", i.e your standard role model feeling.
Which of course sounds silly once you grow older and realize you can be like them if you study and put the hours on it, but at the time, being so much younger, it just seemed magical.
I compare them to what the movie "Hackers" made me feel. I knew it was a completely fantastical representation of what hackers actually were (and you could even argue it was a bad-ish movie), but the fact that I could imagine myself being able to break into a TV network and putting the show of my choosing felt like magic. I guess it's the analogue to what Dungeons and Dragons was for a lot of people, imagining being a wizard and killing dragons.
So while I agree with you that they were just a group of people that got together to share knowledge and explore this new frontier, it was so ahead of what I could achieve at the time that it was hard not to look up to them.
Kind of how I (and I would guess, a lot of other HNers) look up to what you (and e.g. Project Zero engineers) can do with security and cryptography stuff :)
It's not that I think I'm not capable or competent enough to do it, just that I haven't walked the thousand miles you have. But of course, I'm now an adult that can rationalize these things, instead of an impressionable kid with dreams of grandeur :).
they got acquired by Symantec. Mudge went on to work with the DoD to development a cyber fasttrack program, Weld started and recently sold Veracode, Katie started the bug bounty at Microsoft, Joe Grand is still doing his thing w/ HW etc...
these folks really are self-made titans of the industry and a true testament to meritocracy and the hacker ethos. They legitamized security research as we know it.