A hacker's mom broke into a prison and the warden's computer
wired.com
wired.com
Cell phones are a particular problem because it has been shown that some in prison continue to engage in criminal activities with those outside including witness intimidation or worse.
[0] https://allongeorgia.com/georgia-state-news/ga-dept-of-corre...
Reference: https://hackaday.com/2017/05/11/tearing-down-the-boss-phone/
(it is actually "B.O.S.S.")
How do we expect people to join back to society when they can't use literally the number one most important thing?
Maybe give them phones with no cameras and monitoring of use, but just nothing seems very inhumane.
It is whether the US is looking at the results achieved by other countries and whether the US is trying to emulate successful strategies.
As a sweeping generalisation, I see that the US says "that doesn't apply to us", always finding some weird excuse. Your invalid response is kind of an example.
It's a fairly common sentiment that the U.S. penal system is heavily skewed toward retribution than reformation.[1] But identifying a problem on the one hand, and quantifying and addressing it on the other, are two entirely separate tasks. The latter is typically much more difficult.[2]
[1] Justice Anton Scalia admitted as much in court, "Well, I thought that modern penology has abandoned that rehabilitation thing, and they--they no longer call prisons reformatories or--or whatever, and punishment is the--is the criterion now. Deserved punishment for crime." Oral argument, Miller v. Alabama, 2012.
[2] Thus the quip, "Everybody complains about the weather, but nobody does anything about it." A reformulation of a Charles Dudley Warner quote, who, interestingly, also seems to have been an advocate for prison reform in his time, among many other civic and political reforms. See https://en.wikipedia.org/wiki/Charles_Dudley_Warner and https://books.google.com/books?id=ktwRAAAAYAAJ&q=+%22little+....
If you look at this recent paper[1] by the lancet on "The psychological impact of quarantine and how to reduce it: rapid review of the evidence" (coincidentally it's about the corona virus) then you might notice that the effects of isolation are exactly what prisons are designed to do[2]. For quarantines it's a huge dilemma ofc.
[1] https://www.thelancet.com/journals/lancet/article/PIIS0140-6...
I’d love to find corroborating evidence for this, because I find it completely facinating.
I also think they should be allowed to grow their own weed.
Maybe require only open source software and no crypto except for authentication but confiscating phones is stupid and lazy.
Counter-argument: seeing the world pass you by is a good way to become suicidal, and the state (at least here in the US) has an obligation to protect those in their custody.
Receiving broadcasts e.g. radio signals etc. is fairly low risk (exceptions include coded one-way transmissions), but bidirectional communication is a good way to increase the risk that a prison may face a life-critical challenge at some point.
Instead of Prisons: https://www.prisonpolicy.org/scans/instead_of_prisons/chapte...
Anyone looking for some Netflix/Chill which is also edutainment about prisons and that doesn't paint the problem as binary (good vs evil) I highly recommend Oz https://www.imdb.com/title/tt0118421/ or (a more recent show about the streets and problems in LE) The Wire https://www.imdb.com/title/tt0306414/ <-- needs at least 2 or 3 times watching because it's incredibly dense!
Edit: this is also an incredibly good read https://mises.org/library/defending-undefendable
The courthouse was owned by who? The sherriffs? I thought the ownership was okay, but it was the over-eager law enforcement that refused to budge because they weren't informed.
And yes, stipulated, the sheriff is an asshole, but even he would have honored a contract between Coalfire and Dallas County, Iowa.
> Don’t blindly assume.
I know I would be way more willing to allow a pleasant lady of mature mothering age and demeanor than a middle aged guy.
Its the stereotypes we subconsciously build up unfortunately.
It’s not young thugs that come in to medical centers trying to score painkillers; it’s middle-aged suburban moms.
The former know where to buy on the street. It’s the latter that think of trying to lie to their doc.
But in practice we tend to be more suspicious of the former.
So you have classified the greatest threat as female, suburban, and adult, but the statistics seem to indicate male, rural, and young adult. You are in danger of being pen tested.
It's also worth noting that "who dies from opioid overdose" and "who is more likely to use a doctor to get their fix" are two different discussions, not least of all because "who dies from opiate overdose" is unrelated to "source of opioid." In the period 2005 to 2015, the likelihood of a prescription drug being the initiating drug dropped in half, while the likelihood of it being heroin went up about four-fold (Cicero, Ellis, Kasper 2017).
As to women being the ones who walk into the medical center, note that the CDC's Drug Abuse Warning Network shows that the leading age groups to walk into an ED are women 25-34, 45-54, and 35-44 in that order (though the downward bump for 35-44 isn't really that big - it really is the center of the bell curve).
The big increase in "rural" areas is messy. The actual data shows "non-major urban", and lumps together "small urban" and "rural". Given how medically underserved rural areas are in the US, however, I'd say the anecdata that it's suburban is more consistent with "non-urban growth favoring the non-urban areas that actually have prescription-writers in them." (Cicero et al 2014)
The shift went from very-young inner city males getting heroin as their first drug to white middle-aged currently-as-many-women-as-men (but the velocity of growth is much higher in women) using scripts to, now, going back to heroin as scripts are harder to come by.
Lastly, the previous comment compared "young thugs" (15 yo inner-city males were the predominant opioid abusers in the 80s and 90s, and are traditionally the stereotype for opioid abuse) to the unsuspected-but-common addict that walks in the door today, analogous to the Mom PenTester in the original article. And, indeed, the opioid abuser of yester-year was not prescription-based: they weren't hitting up their physician. It seems like they were saying "the old stereotype that we suspect leads us to ignore this common and inconspicuous thing that is actually the risk." Which you've taken to mean "this common thing we don't adequately suspect is the defining description of what opioid abusers look like."
After reading the rest of the story, that was a gut punch!
[1]: https://en.wikipedia.org/wiki/Women_are_wonderful_effect
I worked at a fortune small-cap where the IT department was absolutely insidious. They would undermine anyone who they didn't like, or who opposed their nonsense. I wrote a lot of backend stuff, and they would spend far more effort and money denying us servers and resources than it would have taken to simply get those things for us. They'd tell us developers we couldn't use the OS's our products targeted, and yet they'd be using them.
They undermined their own CIO time after time; most lasted about 18 months.
Then, the company hired a sociable, intelligent, woman as CIO.
Within six months, she'd (rightly) fired the ENTIRE department. They just didn't see it coming.
It's not the pentester's job to fix social policy, merely to point out that threats can come from a variety of vectors that people don't expect.
Despite the need for people, you'll still encounter a lot of barriers to getting a job.
It doesn't make sense to have a bunch of hoops to jump through when the demand is there, you can train people easily, and there are people willing to learn.
You can disregard 99% of calls-to-action regarding security hiring and talent demand.
It's not clear that you're describing that kind of situation. Taking someone with essentially zero relevant experience and training them up to be someone that can deliver a skilled service to a client is a much different ask. There are companies that are willing to make that bet, I work for one now that is hiring pure developers in a security role, but they have the resources to play the long game. Little infosec consulting firms can't do that.
This comes across as me disagreeing with you. I'm not, I agree security is easy to get into and there is way too much black box bullshit surrounding it. I just have been involved with companies along the full spectrum of services and capabilities and feel that not everyone is in the position to make the bet you're laying out as a sure thing.
I don't think the industry is tripping over themselves to get talent in any aspect. It just isn't what I've encountered. None of my prior domain knowledge counted (what little there is). Only certs and recent activity.
Depending on what experience you do have you might find good luck in hiring on at larger firms like insurance, financial, healthcare where they are going to need in-house staff and can make use of other skills that you might bring while they train you up on the security side.
I know there's smart people doing good work, but it could not deliver for me within a reasonable time despite putting in the work, and that was enough to realize most of the call-to-action was bullshit. If anyone asks me for career advice (no one should), I just tell them to learn to code and do code reviews in their spare time. Don't even bother with the pentesting side of it.
Pen tests and red teaming are about both skills and decision making, both of which have very high potential for significant damages if carried out incorrectly. For me personally, getting the OCSP would just tell me you have very basic skills and have demonstrated some interest. I would then have to fold you into the engagement pipeline, which would involve some thumb-warming, as basically a water person until i get feedback from the rest of the team that you are asking the right questions and are making good decisions. You would then get progressively more responsibilities and operate under scrutiny for a couple of years before you would be asked to lead anything. The fact that you did nothing for three months just tells me they were too busy to figure out how to get you started on that ramp...or they were idiots. Who knows.
Again, it's a communication issue and your expectations were set too high, but that definitely doesn't mean the industry is secretly flush with talent.
This is another thing: people value those certs really differently and it's almost worth not doing them at all, again going back to: just learn to code. And to your point: more communicating badly.
There's not a single more valuable qualifier than experience and yet that's the hardest thing to get when it really shouldn't be. Med students assist with surgeries but they aren't put in charge, I don't see why pentesting can't be the same.
I think you've taken the rare, good, working parts of the industry and believe that to be a baseline, and I don't think it's realistic.
Here's another one from yesterday - RSA Conference: https://www.youtube.com/watch?v=yqOGuXcLdOA
Screenshot here. Safari on the left. Firefox on the right. https://i.imgur.com/Qgqiywc.png
Submitters: please don't rewrite titles unless they are misleading or linkbait. This is in the site guidelines: https://news.ycombinator.com/newsguidelines.html.
(Submitted title was "Pen testers mom breaks into a state prison and infects wardens computer")
Just to choose an example: There's a program called Retroactive which patches Aperture, iPhoto, and iTunes to work again on macOS Catalina. The project's github links to a medium article the author wrote, which is titled:
> Technical Deep Dive: How does Retroactive work?
If you arrive at this article from RetroActive's github, it's a fine title. But if you just see it on Hacker News and don't know what Retroactive does, the title is 100% useless noise. So when I submitted the article to HN[0], I tried to make the title more descriptive while also changing as little as possible. All I did was replace "work" with what Retroactive actually does:
> Technical Deep Dive: How Does Retroactive Patch Aperture for macOS Catalina?
Even though I did my best to change as little as possible, I felt quite guilty about the title change. But in hindsight, by trying to "compromise", I ended up with a title that's still really bad! The first 6 words of my 11-word title give the reader absolutely zero information.
This article didn't get much attention, and I can't help wondering if the title is why (not to imply that this or any article somehow deserves attention). The title really should have been:
> How Retroactive makes Aperture, iPhoto, and iTunes work again on macOS Catalina
The only thing I'd add is that it makes a huge difference to use language, where possible, from the article itself, rather than come up with words that aren't in the article. There's nearly always a subtitle or representative phrase that is suitable. A title that consists of the article's own language makes for a much better title than one that the submitter made up. We stick to that principle when editing titles. It's not always doable, but 90% of the time it is.
In the case of 22229101, though, I'd go for the subtitle: "The technical backstory of Retroactive". It's true that it doesn't explain what Retroactive is. But it explains what the article is, and it implies that readers will find out what Retroactive is. Indeed, the very first thing you see if you click on it is "If you need to run Aperture, iPhoto, or iTunes on macOS Catalina". It's a great HN submission, so I've changed the title to that and emailed you a repost invite.
p.s. I don't mind having these conversation on the site from time to time, but it's random whether we end up seeing a post like yours or not, so if you want to be sure to get a response, hn@ycombinator.com is better.
I will say: my concern with not defining Retroactive is that the people who'd likely be most interested in such an story (say, macOS programmers) won't be any more likely to read it than, say, SQL programmers. But maybe that's less big a deal than I think it is?