Sure, culture has become more sensitive to these things overall and criminal prosecution of credit card fraud and computer crimes has become a lot more effective but there's a tangible difference between generating fake credit card numbers and masking your identity to defraud ISPs and hacking the Pentagon to access government secrets (namely, the latter fits into the hacker ethos of "liberating information" and rejecting authority whereas the former just provides personal gain). Changing your school records as a student is a childish version of the latter (as the intent is not to create false credentials for monetary gain but to defy the authority of teachers by subverting their means of "punishment").
Um no, definitely not.
> Sure, culture has become more sensitive to these things overall
Decades of fearmongering in media, omnipresent surveillance and the buying off of all competent hackers did a good job of that.
this could not possibly be further from the truth -- the early hacking/phreaking scene was quite possibly one of the most diverse in tech history, mostly because it was actually meritocratic
even the population of kids that hung out on IRC during early web2.0 DDoSing each other and trading 0days had a disproportionate amount of minority individuals, and large portions of them graduated to today's cybsec industry
The weird thing is we have had the CFAA hanging over us as some kind of Sword of Damocles for decades and we just collectively ignored it. Honestly everyone was even pretty cavalier about this stuff during and after the Mitnick prosecution...
In the 2000s when I talked to people who do urban exploration there was at least an understanding that you should not be taking photos in sensitive locations -- "please don't make a felony diary".
The 90s were cavalier. We're talking over 20 years ago, different time.
The big difference was that people were... for lack of a better designation, intensely naive back then. There just wasn't a lot of understanding around consequences.
to be fair that movie follows a group of teenagers showcasing illegal activities that finally culminate into their federal arrest.
yeah, they're later exonerated because 'Movie-FBI' has a heart and a sense of justice, but that's probably not the best movie to try to pull criminality psych from.
my guess : Eric Corley injected a lot of his own personal ethos into that movie. He was apparently an unpaid consultant.
I'm purely speaking retrospectively here
I am pretty sure kids today are also doing some different mildly illegal stuff with technology, but we'll have to wait 20 years to find out about it.
Also scamming product returns, food delivery refunds, stuff like this.
Curious what other things people have run across.
Orherwise ISPs are the poster child of monopoly giants that had to be broken down kicking and screaming, but kept screwing the customer over and over because there is litteraly nothing that we can do about it (voting won't help). They can burn in hell I wouldn't care.
These days isn't it a lot easier to deal with that? You basically just get on the phone with equifax/transunion and upload some documents.
Guess that trial and error had to start somewhere.
Also I really wonder what the mathematical chances are that the card actually matched with someone back then. Like obviously a collision risk here but how large?
Even if it's still a pretty huge space.
[0] https://medium.com/@ma.juber/mathematics-behind-credit-debit...
So if you have fourteen digits, one of which is a check digit and up to six of which are non-random, that leaves only seven truly random digits per issuer, i.e. a pool of 10'000'000 (10^7) numbers rather than the 1'000'000'000'000 (10^12) possible numbers claimed elsewhere.
Of course the actual pool is different as the number of fixed digits seems to vary per issuer and for some it seems to be only one.
ISPs were also pretty liberal with free trials (AOL CDs galore) since it was mostly customer acquisition cost (it wasn't yet established that you had to have an Internet connection like you did a landline and Cable TV) and the marginal cost was low (ideally, the cost of peering -- the ISP basically had some routers and modem banks between an internet exchange and a phone exchange; and the user paid any applicable long distance charges to call the ISP). Whereas now you'd preauthorize the card at signup time to catch this sort of fraud beforehand.
Also, not every valid number will be used (e.g. all 0s won’t be an option), and every number don’t need to be valid at the same time. If I renew 25 cards, their numbers are burned with no reuse.
That’s a long way to say, I’m not a fan in general of throwing in naive probability calculations and calling it a day.
The BIN/IIN is traditionally the first 6 digits. Extended BINs can be 8-11 digits, which is like subnetting -- the BIN sponsor can delegate assignment control of an extended BIN range to another entity. So in some cases, there can be as few as 4 "random" digits in the full card number (PAN).
E.g.:
BIN "random" Check
411111 111111111 1
ExtendedBIN "random" Check
41111111111 1111 1
If you were sweeping a PAN range for live numbers, you'd start with a known-valid BIN, probably 6 or 8 digits. Then randomly choose the next 9 (or 7) digits, and then calculate the check digit.We can't know the likelihood of hitting a valid number without knowing the count of assigned PANs in that BIN, but clearly the capacity would be 1 billion (or 10 million) possibilities.
There were a pretty good number of nationwide ISPs to choose from too, if you wanted something less fly by night. A whole heck of a lot of consolidation happened since then of course. But even the winners of dial-up pretty much lost to cable and baby bells. It was easy to setup a dial-up ISP, but it's darn hard to setup a broadband ISP, so we're stuck unless you can convince the FCC that the 1996 Telecom Act applies (might need some court work as well) and we can get mandatory line sharing back.
You have to remember how expensive this stuff was in the 80's and 90's, how low risk this type of fraud was, and how us teens didn't really think about it. ISPs billed by the hour, something a teen could not afford.
Check out any history of phreaking [0]