My $.02 on the spike in hacking
securityskeptic.typepad.com
securityskeptic.typepad.com
That said, I don't see a rise in hacking incidents. What I do see, is that hacking is currently part of the zeitgeist, so much like when someone tells you about a red car and you start to notice red cars all over the place, the collective focus on security is just bringing more incidents to light.
Quantifying hacker activity is akin to quantifying IP piracy, in that there's really no good way to accurately capture the real numbers. For many years, publicizing breaches was anathema, so the general public were left unaware just how commonplace attacks were. If you want to see remnants of this mindset, just ask a security consultancy for references of other clients they've worked with (It's like asking for a list of someone's sexual partners). We're now at a point where there is more pressure to go public when an incident occurs (as well as things being more difficult to hide).
Even if I remove my cynical security consultant fez (which would make me salivate on the benefits to my livelihood based on the public perception of the state of internet security), I think it's probably a good thing for this stuff to be in the public sphere.
RE: benefits to livelihood. My security consulting didn't suffer while organizations chose not to disclose. The only difference between then and now was a clause in the contract regarding disclosure :-O
Exactly. Everyone in the know has been saying this for a while now.
"States have an inherent right to self-defense that may be
triggered by certain aggressive acts in cyberspace,” says
the policy. Indeed, such aggressive acts might compel a
country like the US to act even when the hacking is
targeted at an allied country.
"Certain hostile acts conducted through cyberspace could
compel actions under the commitments we have with our
military treaty partners,” says the document. “When
warranted, the United States will respond to hostile acts
in cyberspace as we would any other threat to our
country."
United States International Strategy for Cyberspace (PDF) - http://www.whitehouse.gov/sites/default/files/rss_viewer/int...I continue to want to compare this movement with the Yippie movement[2], at least on the handling of media and communications. Having read "Do It!" by Jerry Rubin several times during high school, I really feel similarities between the two movements on this subject. I don't have the book with me but it would really be worth reading it again and try to make some comparisons on actual examples rather than vague ideas (usage of the medias, "for teh lulz" as part of the motivations, relation with the authorities...) like I'm doing here.