Inside the Billion-Dollar Hacker Club
techcrunch.com
techcrunch.com
We're discussing here a group of people who started their careers dead smack in the middle of the dot-com bubble, practically all of them in software/network security, a field that has stayed valuable since its inception. Of course they've done well for themselves.
This would be interesting if the denizens of #w00w00 had, say, invested in each other's companies. But as I understand it (I was a #!r00t person; our biggest win was ISSX) that's not at all what happened.
Sorry to sound pissy. I'm just hoping to forestall another goofy HN conspiracy theory; the idea that w00w00 is, like, the Internet's "Skull & Bones". No.
Also, I suspect the stories about w00w00 as a "hacking group" that broke into people's machines: total BS.
This doesn't mean that list or whatever caused the success. This is the same problem epidemiologists face when trying to explain cancer clusters.
See also http://en.wikipedia.org/wiki/Texas_sharpshooter_fallacy
Also, back in the late 90s defcon days, w00w00, CdC, New Hack City, each had an entrepreneurial spirit. w00w00 perhaps more than most. I remember when CdC launched BackOriface, it was just as much a startup launch as anything.
Note: I don't claim to be a member of any.
We were all of us entrepreneurial, but being in w00w00 didn't get any any support from, say, d0b.
I'll do you one better: #!r00t'ers started a bunch of companies together. Other than WhatsApp (WHICH I ADMIT BLOWS THE CURVE), were there a lot of multiple-w00-person companies?
"Gotta disagree with you on this one. Lots of folks in w00w00 worked together. In that sense, they did invest in each other (with time and effort, if not cash)." -- that's correct and a good way of putting it.
All is a strong word. I was more #hack, but also spent time in #!r00t and the two communities overlapped a bit (tim(al), etc). I was terribly non-entrepreneurial back then. I ported the original iss.c to SunOS and Solaris but distinctly remember telling kewpie that a business around this would never fly. This is one example (of a few quite notable ones) of why people should not take business advice from me.
All that aside, yeah, this smacks of mostly post-hoc fallacy to me as well.
"And surprise surprise, people who used one of the more technical communications medium back in the 90s end up being technical people when they grew up."
I think that's your actual point: Smart technical young people became smart technical adults, and the hindsight of whats app could have been any number of channels, just as many of the members were parts of many "crews" or channels. Unlike most channels though, as you point out, they met up in real life, generally in august in vegas. :-)
That's true. The Internet's "Skull & Bones" of black hat, darkside hackers is l0ck.
Apparently their leader made a fortune preparing for the coming deflation: http://www.youtube.com/watch?v=RTTFuOEOhEE
This reminds of the Indian IT scene. Where today's so called managers/execs/leaders were just lucky to be in the path of immense inertia in the 90's.
Most of them probably have no experience at all, some of them as little as working in testing projects for a few months. They just had to be promoted because companies were growing 100% year on year, and the only way to get new managers were to promote existing people. People with as little as an year of experience from college became senior managers.
Now we have these people come and repeatedly lecture us 'We are so awesome, they had to make us VP's without doing any work at all'.
Before WhatsApp's purchase, the "napster on irc" byline was, #winprog taught him all he knew about winsock programming and without #winprog napster would never have been made.
Now suddenly it's "without #w00w00, napster would never have been made" because this combined with WhatsApp's purchase lets someone write some 1500+ word article about nothing.
I wonder what would have happened if TetriNET ended up selling for millions back in the day, would that have suddenly become the irc hackers made bajillions byline?
And surprise surprise, people who used one of the more technical communications medium back in the 90s end up being technical people when they grew up.
Haven't really used IRC since the mid-90s, but perhaps it's a good way to connect to other developers? Is there a representative YC channel?
As for YC, there's the ##startups channel on Freenode, unofficially.
There is no better way to coordinate. Clients for every platform are available. You can have new tickets, bugs, announcements piped into the channel. Discuss everything instantly and in real time, while leaving a log for those who are offline, highlighting them when necessary.
Running your own server is perfectly feasible. And if you connect to a known ircd with SSL forced, it's reasonably secure. There are even OTR plugins for many popular clients (♥irssi♥). There's also FiSH but that's on the inconvenient end of the paranoid spectrum.
It is perfect if people you're going to communicate with are proficient computer users.
I have a client, spend some hours per week on IRC. Yes, there's great support, extremely skilled developers in various areas can be reached online.
I use weechat (text-based) or Textual (OSX GUI).
Most, if not all, of the big open source projects have channels on Freenode. They are excellent places to connect with other developers (people). Not only are they just great places to get involved with other developers, they're also great places to talk to professionals using the technologies every day. You can learn best practices and industry standards by idling in the channels and watching questions get answered.
In terms of a "representative YC channel," there's not an official Hacker News or YC channel I'm aware of. However, there is #startups on Freenode that some have considered a sort of unofficial Hacker News IRC channel. We're a pretty active and lively bunch and the topics range from startups, funding, and entrepreneurship to programming, good beer, and current events. Just like all decent IRC channels, and you're welcome to come hang out any time.
For me the big advantage is that it "just works" (web interface + mobile app) for everyone in the company whereas there is overhead to getting IRC setup. We had tried IRC previously and it didn't take. It also doesn't hurt that Slack looks sexy.
I think that IRC has really stuck around because it somehow really captures asynchronous group discussion, but also simultaneously keeps the barrier to participation really low. It makes total sense to me that the IRC community is still so strong.
IRC is awesome.
I've found my closest friends through irc and we are partnering regularly on business related subjects. Best medium to stay connected. The WhatsApp Groups are what kids these days use from what i hear.
I also try to sit in freenode channels that intersect my interests, but I'm not anywhere near as active in them as I was back in the day. But that's where all the good developer-related channels are now.
I was in two 'crews' as they used to call them in the early 00s. I'm not sure if you would really want join them. I think I prefer my current networking (twitter, github, blogposting, hacker news, stack overflow, etc.)
Back at the time, there was no StartUp culture (where I lived, not talking about Silicon Valley), everything was closed and there was a huge debate over full disclosure (I'm not even sure how it ended... I remember tf8, antisecurity.is and the rest...).
There were a few skilled people around and almost everybody knew them. WEB 2.0 didn't exist (twitter, facebook, etc.) the web was a totally different place...
I'm not sure it was better though, it seemed way more exotic IIRC. But the general behaviors of the communities (linux communities, hacker communities, etc.) was awful: You were getting your fair share of curses every day. Some IRC networks were wild, with DOSSes (flood, nuke and other shit which could disconnect a 56k easily) flying around. Exploits were flying around, some private some not-so-private.
Security was not an industry and the required skillset was not so extreme as it is today. I mean, you could do quite some damage without being very technical. Things changed after 2002-3 (you can see this in the Phrack articles, turning suddenly extremely technical).
Then the web-based internet came out, everything start requiring PHP+SQL and XSS was born. Then Java and after that JavaScript... Which created a new, less sophisticated attack vectors.
Then the era were officially sponsored cyberwars came into play arise. Stuxnet was the most prominent example of this era, with the NSA revelations and China's cyber-army giving a clear view of how the security industry is shaped nowadays.
Today there are no crews like Team TESO (I'd like to read about the story of their members...), ADM, etc. I still remember 's0ftproject[1]' back in the days in Italy. Some members can still be found involved in the Tor project.
Anyway, things have changed for the better or worst. Better keep up with the times...
ps. Today's world should be considered a kinder-garden for a security professional. Way more attacking vectors (so more protection needed) and a huge amount of companies which understand the importance of computer security. Back in the 2001 telnet was still widely used...
But you probably know better, since you're on the field.
What does that mean? Tim Berners-Lee might like to have a word with you about when the "web-based" internet came out.
Oh, and you used telnet to get to these things, not ssh. SSH didn't become de rigeur until the very late 90s.
This is not to say that the web didn't exist at the time; it did. Webcrawler was useful back in the days of Webrings.
- Groucho Marx
After all a lot of members of this community have already gone to build big companies.
I think at a certain age/time, you tend to spend more time with friends rather than family and that's when it begins to happen. For non-hackers it's when they develop lifelong friends in work or school, for hackers/internet-people that's when you start thinking of your ICQ/IRC/fandom/LJ/pick your ancient platform as your true friends even if you've never met in person.
Security should be about planning for failure and not about trusting a marketing blurb that says "100% secure". Just look at the Apple gotofail bug, the RSA/NSA fiasco, the Debian fuck up, the ssh crc32 bug...
I'll finish by quoting Theo de Raadt : "You are absolutely deluded, if not stupid, if you think that a worldwide collection of software engineers who can't write operating systems or applications without security holes, can then turn around and suddenly write virtualization layers without security holes." *
* You can replace 'virtualization layers 'with 'secure messaging protocol' or any other piece of code.
I was 17 and managing servers during the first dotcom boom when you needed more than just smarts to create a startup. You needed a boatload of VC money.
If w00w00 was formed in present day, half of us would have been funded by YC. We were just smart and young people at the start of this internet thing. Not surprising we went on to make internet companies.
This article does leave out a lot of people and includes someone that shouldn't be included.
Great editing standards.
It's not mandatory but it surely helps.
Ahhhh, the memories!