The year was 1999, I had befriended a strange group of friends from an IRC support channel. We all lived within 250 miles of each other and one day decided to have a gathering with about 6-7 randoms from the channel. Hilarity ensued as we played games of command and conquer, Starcraft, and Serious Sam. I was yelled at for saturating the 1.5mbps SDSL line with my webcam, streaming views to our friends who were too far to drive in. Someone else was eating aluminum soda cans. At one point one guy happened to login and said “wait you guys are having a LAN party? I’ll hop on the PATH and be right there”. Then my life changed in front of my eyes.
In walks this dude that looked like he came straight out of Hackers. We all dap up and continue talking about random nerd things. The conversation goes to cell phones and how the fcc passed this law which OP talks about. Surprise someone has a grandfathered scanner that could scan 800-900mhz. Dude that showed up starts talking about how he knows a guy that knows a guy that took his code and runs an elaborate carding net. Dude then whips out a demodulator app that he wrote that takes beeper signals from the scanner audio and decodes it to text. He tells us we can pull livery and taxi beeper codes because they text headquarters with the credit card numbers on pickups. Then his app does it. One guy holding the scanner at an angle to one of those bend/squiggly microphones that were ubiquitous in the AOL era. Modem like beeping screeching through the air. Then messages and credit card numbers start streaming through this dudes app. The entire room does a collective holy s#%^ mainly because we can’t believe this would be streaming in “broad daylight” across the Hudson.
He went on to explain how he got into hacking almost just like in the movie Hackers. Dude was brilliant and got recruited into hacking groups as a programmer when he was 13. He was writing stuff like this for 5 years. We think we had crossed paths at some point because I was deep in the demo scene and wrote patches for hacking groups.. but that day blew my mind about how security through obscurity worked and led me down a black hat path that switched to white hat in the early 2000s
Huh?
I miss the 90s. I was 12 years old in 1999, but I started disassembling code when I was 8, so as you can imagine, people online thought I was an adult with all of illegal things I did. I even broke into PayPal and bragged about it. lol embarrassing today.
That being said, I feel like back then a most vulnerabilities were so simple due to lack of foresight/security that quite a few 12-year olds with a decent understanding of computing could perform them:
I fondly remember an IIS bug which allowed you to basically 'cd' into any directory on the host machine and execute cmd.exe remotely. I believe it was as simple as the server not sanitising '..\' when written using unicode escape characters...
All the way through the thousands there was a backdoor on OSX' remote desktop. As long as they were not behind a firewall and had not manually setup remote desktop, you could get full access as well.
And all the way through the 90s and the thousands, there was a backdoor on Motorola and Buffalo cable models, so you could remotely inject your own firmware and remotely reboot the router if you wanted. Everyone online was soldering those things to get hacked internet back then and I was just scratching my head as to why they were not using the backdoor instead.
I can go on. I haven't done anything infosec in a very long time. When I was 18 I got interested in certificate decryption and my passions took a more math heavy direction, eventually leading to quantitative finance.
edit: Oh, and to keep more on topic, regarding listening to cell phone chatter, the cell tower where I lived didn't change to digital until 2006, so in the thousands I knew you could listen in, but frankly I wasn't interested. I was more interested in making cantennas and injecting an 802.11 signal 2 miles away, decrypting their WPA. Surprisingly I did not find a single router that had a different admin password than its WPA password.
In the 90s all the way into the early thousands, to get online I had to get hacked internet, as my parents didn't really understand the internet and thought it was a fad. This may be what inspired some of the black hat stuff I did.
The answer to "How did you hear about our company?" would not have gone well. :-)
The call was a professor at the local state university talking to a woman whose identity I was not able to determine. Almost the entire conversation was about how much he hated Palestinians. That they were subhuman and should be wiped out. I grew up in the South and had heard hateful things before but this was the first time I heard someone advocate for genocide so openly. That conversation has stuck with me ever since, making me wonder what's going on in people's minds that they keep hidden from the public.
At one point in the conversation the woman asked if he was on a cell phone and if anyone could overhear them. Despite there being no way of them knowing we were listening, it still caused my hair to stand on end. He said it was unlikely. The quality of the signal didn't waver during the call and was strong the entire time was he probably was stationary nearby. So very odd that he didn't call using a landline given the cost of such a cell call.
They routinely kill and maim palestinian teenagers with 0 consequences, so there must be a huge part of society that agrees with such ideas that they are able to do so with impunity.