Interview with a Blackhat (Part 3/3)
blog.whitehatsec.com
blog.whitehatsec.com
http://blog.whitehatsec.com/interview-with-a-blackhat-part-1...
(pastebin if it goes down: http://pastebin.com/jiUM0AFr)
http://blog.whitehatsec.com/interview-with-a-blackhat-part-2...
(pastebin if it goes down: http://pastebin.com/SAKS2CTW)
Idea for a site: A pastebin that uses nice typography, instead of monospace... Perfect for this sort of thing.
Is there a good one already os shall I make one?
I personally use readability for this (though I don't use it for mobile or any other purpose other than "make this pretty now"), and tried it now on pastebin and it seems to work fine.
I find it really useful since I can just type out my docs in dropbox, create the rendered link, then pass that around. It's super easy.
The black hat is putting in hard work and making tools while getting an unreasonable amount of funds. (Of course illicit professions have that tendency with risk factor and all.)
We're talking about a profession learned strictly from the community that developed extremely specific and effective skills.
Anyone able to do that and succeed is obviously talented and it is telling that they were never interested in cashing that talent in a legitimate career with a major tech firm.
Companies don’t purchase DDoS protection. Cloudflare for example offers incredibly strong DDoS protection for 200 dollars a month (also its harder to jack a cloudflare domain). If I extort you for 200-1000 dollars for 1 day why not make yourself immune for the minimal fee?
https://blog.whitehatsec.com/interview-with-a-blackhat-part-...
> A: Erm, depends.
Well, I have no scientific evidence to back up my claims (deadly sin, I know...) it's mostly the personal experience of my friends who lived in multiple countries, which closely matched this documentary:
I'm also interested in this question. Is there existing research on this topic? Earlier in the piece he also claims this:
The thing you have to remember is the black hat world is 10 steps ahead of what’s commercially available. When a 0-day is released blackhats have used it for months.
Is this statement true? Are the top level blackhats more talented, driven, or greater in number than the top level whitehats? Obviously there is money to be made as a blackhat but not everyone has criminal inclinations. Script kiddies aside, intuition tells me that the intersection of people who have the skill to write an 0-day and the inclination to be a blackhat is smaller than the intersection of skilled/honest people. Not to mention that you can make a perfectly legal fortune (ethics aside) selling exploits to security firms which on-sell them to governments. [1]
I'm also interested in his statement about virus scanners - are they really useless? I use Chrome, MS Security Essentials, dont click on devious looking links...and I've had 1 infection flagged in the last 3 years (thanks Adobe). Are there stats on how many infections dont get noticed by anti-virus software, even if you keep the definitions up to date?
[1] http://www.forbes.com/sites/andygreenberg/2012/03/23/shoppin...
"There really isn’t a hatred of whitehats from the blackhats. In fact, quite the opposite. If we stayed with viruses from 2000 because we were never challenged we’d be so out-dated and not capable of making a tenth of the amount of money we make currently. Most blackhats love whitehats for that reason."
This type of activity isn't really representative of either side of the traditional security world. Blackhats have generally shunned "carders", and the for-profit crime groups usually use "script-kiddie" like tools. Every once in a while there is an exception, but it's mostly been the case for at least the last 20+ years that blackhat skills/status in the community is negatively correlated with theft/extortion/fraud.
[1]http://www.wired.com/culture/lifestyle/news/2002/08/54400?cu...
I wouldn't call this guy Blackhat though, if he's stealing credit cards then that's straight up fraud.
Usually when people use the term 'blackhat', they are referring to someone who breaks companies terms of service but just below actually breaking the law.
Blackhat is outright stealing/espionage/manipulation of other devices for your own gain.
There are whitehat folks who do the same...the difference being blackhat don't tell the company whose server they broke into how they did it.
Doing it for bragging rights is not accurate either. Plenty of them brag, sure, but they hack because they like to hack. People always want to make that more than it is.
EDIT: To be clear, that doesn't mean that whatever community she's in doesn't disapprove of that behaviour, but douchebag and blackhat are not mutually exclusive.