The Fall of Hacker Groups
phrack.com
phrack.com
Initially he brushes against the notion that hacking may have grown, as an activity, due to the geometric (?) progression of connectivity, and that the phenomena he is describing is the demise of the 'collective', as a species, rather than the demise of hacking itself. This is sort of a bizarre moment in the essay, because he immediately forgets the notion and plunges into an ideopathological rumination of the decline of creativity and the destruction of collective will by a search for unique individual identity under the oppressive circumstance of the capitalist/existential philosophical apparatus.
I describe it thusly to give the click-to-comments-first reader a flavour of the essay, and also because I am making fun of him. I am making fun of him with serious purpose, as he has made the fatal, arrogant error of conflating ideas with facts; an error that has literally killed millions of people.
It is interesting that the hacker collectives have declined, and this could have been an interesting essay. It does not seem to me that the raw incidence of hacking has declined. I have no idea why this person believes such a thing. Hacking of all kinds and intentions are reported in a flurry these days. What has declined (I accept his assertion) is the phenomena of the group social identity of hackers. My first hypothesis about this is that anyone who studies graphs and networks could explain it to me without a second's hesitation, and perhaps someone will.
My (largely uninformed: I welcome correction) expectation is that the explanation will be directly related to the progression of connectivity: information is no longer rare or exclusive, and so social representation and status-seeking are no longer necessary parts of the driving activity, which is the hacking. This precludes the fetishization (in a pseudo-Marxist sense) of small networks such as the hacking groups. Small networks doubtlessly continue to exist and function quite well with only a fraction of the awareness of their collective identity.
I would recommend the Adventure Time episode "Thanks for the Crabapples, Giuseppe" as good contextual background material.
I like your use of colon rather than semicolon. Was that deliberate?
With the exception of LoD and MoD, these "groups" (brands, really) have nothing in common with each other. And none of them had any common purpose.
The article talks about uniqueness, but being in a group does not affect uniqueness. You could almost compare it to all the Hacker News advice to not do a startup solo, as you need companions to talk to on the long slog. A hacker in a group can brag to them about his achievements (he could tell the whole world, but then he'd be arrested). He can also brag to other hackers about being in an elite group. It socially enhances them as an individual, it doesn't take away from their individuality.
They say the French revolution was formed in the salons of Paris. What were the salons of this bygone hacker scene? The BBS's running on the Apple ]['s and Commodore 64's that were sitting in the bedrooms of teenage boys. That the means of communication were completely controlled by teenage boys (through a mostly oblivious Bell) affected things in a whole host of ways. Any kid with a phone line in his room and $200 for a Commodore 64 could host a node on this communication network in the mid-1980s.
Two forces destroyed the scene - the carrot and the stick. The stick was the government beginning to notice their existence. The 414's were busted in 1983. There were a series of raids in 1987. In 1990 MoD was busted and Operation Sun Devil happened. This didn't really kill the scene though. A complete free-for-all changed into more careful hackers, not making calls from their house but using acoustic couplers on payphones or (modded) cell phones. They also were quieter about laws they may be breaking. They also became more sophisticated, really understanding the phone system, how Internet hosts and security worked etc. In some ways, attacks by law enforcement made them more dangerous.
The real death knell of the groups was the carrot. The Internet became more widespread, and these people began to get jobs. They formed companies, which they sold for millions of dollars to billions of dollars. Which is not hyperbole. When the guy you knew, who was not all that smarter than you, creates a billion dollar company, wardialing or sniffing the traffic of some host seems less important. Idle hands are the devil's workshop. The closed off world of mainframes on x.25 networks run by Computer Science Phds from top universities, counterposed to another network of working class mischievous teenage boys with their Commodore 64 BBSs in their bedrooms - this is a ripe ground for a hacker scene. A network where you hear stories of teenagers making millions on the hit app they wrote - opportunities like this put a damper on hacker scenes.
I guess I agree with your last graf.
(L0pht obviously had a side in the full disclosure "debate", but they didn't have much to do with the outcome of the debate. I don't recall anyone serious taking the opposing side on full disclosure, by the way; that outcome was a foregone conclusion.)
Can you expand on this? I'd say the outcome has been the opposite of the foregone conclusion, unless I've misinterpreted you. FD seemed like the "of course it's this way" option (unless I misremember), but that's not where we are today.
What I'd say is that today, few people bat an eyelash if a researcher does a detailed writeup of how a vulnerability and its exploit work (for instance, look at the Google security blog). That wasn't true in the 1990s: if a company of Google's stature had published something like that, it would have been controversial and newsworthy.
I'd suggest FD prevailed because it's relatively safe to publish vulnerabilities today; in fact, it's a career booster.
During the FD debate, there were "important" people suggesting that all vulnerabilities be routed to organizations like CERT, which had as a charter the concealment of vulnerability details.
They might have ./smurf.c'd each other constantly but they all pretty much came out of the same environment.
How seriously do you take cDc and the L0pht? We should probably make sure we're not talking past each other before we try to debate.
Not saying all groups by any means, but even with being a few years late getting started in the infosec world of Atlanta there were still a lot of old guard hackers hanging around when I got out of school and people still felt comfortable sharing stories from time to time.
They all got old, and new groups didn't form to join them because what was a lark in the 90's is now considered cyberterrorism.
Umm, what? I'm hardly a fan of Anonymous, but I think that's a pretty ridiculous statement on its face. The only reason I've even heard of CCC and the like are because I was a huge nerd who read way too many hacker books as a kid. About the only one of the classic groups I recall even getting any mainstream attention was cDc, meanwhile Anonymous routinely make international news.
I know that might reek of pedantry, but it's an important distinction because we don't want to contribute to the misconception that everyone associated with Anonymous is a a sooper geenus power user. Large components of the group agree with its goals but don't have special knowledge.
That tells me that you are certainly not German and probably also not European.
Since the 80s the CCC was regularly in national German news as well as European. Some of the hacks made worldwide news, I guess (I'm thinking especially of the NASA-Hack and the GSM-Hack).
At least in Germany, one of the reasons we don't see other hacker groups appearing is that the various local CCC groups are the obvious place to go for people who would otherwise found own hacker groups.
* CCC[1] was not a 'crew'. The CCC IMHO has still a big impact, mostly due to the (extremely?) high technical skill-set of its members.
* The OP writes about cultural impact NOT mainstream attention. In order to get mainstream attention you have to do something trivial like DDOS Yahoo! which was way below the average technical ability of these 'crews' to cause havoc (if they'd like to do so) back in the day.
"Notice this does not concern _collaboration_ as much as it does _collectiveness_."
Also anonymous actions are kin to those of femen, designed to grab media coverage for free publicity while the media themselves have become more about sensationalism and at the same time more aware of the digital world.
Or, I was a hacker before it was cool
|=-----------------------------------------------------------------------=|
|=--------------------=[ The Fall of Hacker Groups ]=--------------------=|
|=-----------------------------------------------------------------------=|
|=--------------=[ Strauss <strauss@REMOVEME.phrack.org> ]=--------------=|
|=-----------------------------------------------------------------------=|
Hard formatting for 80 character terminals is just annoying because the computing world has moved on to working in paragraphs. If you want to draw boxes then do it properly instead of wasting time doing it in ASCII.Computer networks increasingly made it possible to transmit unlimited and uncensored information across their geographical extent with little effort, with little costs, and in virtually no time. From the communication development standpoint, one would expect that the events that followed the 80s to our days would lead to a geometric progression in the number of hacker communities. In effect, hacking has arguably grown. Hacker communities, definitely not. So what went wrong?
The answer is in the first sentence. It's so easy to get information now that you can do it alone in many cases. You don't need a secret society of hackers to curate and distribute it once you have developed good search engine and research skills (which many younger hackers learn in school). Also, if you're in a tech hotspot or even a major metro, it's easy to meet up with other people for casual hackathons, and there are conferences for everything. things like Defcon are large commercial enterprises these days. I bet within 5 years there'll be a 'leakyworld' for people who follow Wikileaks. It's easy to join or abandon forums, whether on the open web or on the deep web via Tor (which feels a lot like the early days of the WWW to me).
So if the creators of Subseven, Back Orifice are reading this, I just want to say thanks.
Gray hat -> Snowden, most of Anonymous's antics, CCC, Schwartz, etc.
Black Hat -> Using vulnerabilities to break into other people's computers.
Gray Hat -> Using information gleaned from breakins to other people's computers to find new vulnerabilities.
or
Gray Hat -> Finding vulnerabilities and supplying them to people who break into other people's computers while retaining deniability about the actual breakins; ie, supplying your friends without wanting to know what they're doing with the exploits.
The 1990s "gray hat" would be the guy using leaked SunOS 4.1.3 source to find vulnerabilities.
Your distinction isn't invalid; these "hat colors" have always been confusing.
As a, fairly well read, outsider, Black Hat, to me, always implied actualy damage, financial or otherwise.
Gray Hats, on the other hand, still might break in and exploit vulnerabilities, but made certain not to cause any damage.
I suppose this partitioned people based on primary motivation. Black Hat's were in it for personal gain or evil, White Hat's for protection, and Gray Hat's for intellectual pursuit. Much easier to categorize and rationalize the romanticism associated with the culture when your "team" is the Gray Hat's.
Leaking documents like snowden is an actual moral gray area.
Deleted comment
NewHackCity was about as much a "group" as the cDc "NSF" was: it was a bunch of people who happened to hang out together (or, in NHC's case, live together). I suppose NHC got to look more like a group when they all left the east coast and set up a hackerspace.
I guess my point is: if you pick apart just the Boston scene, yes, it's going to look like everyone's interrelated. But that scene has, for instance, little to nothing in common with LoD (a bona fide "competitive" hacking group) or Haggis or whatever.
1 - The role of government. Once the laws caught up to the hackers, and the CFAA was passed in 1986, it gave the government a lot more teeth to federal laws targeting computer crime. Shortly thereafter, you have what some refer to as the "Hacker Crackdown" from 87-90 which went after LOD, MOD and smaller groups. Some went to prison, others went or tried to go legit. I think hackers realized groups tend to have more visibility with the feds and you're more vulnerable to getting caught compared to just working by yourself.
2 - Size and structure. Since most of the groups are pretty closed by nature, when a group is disbanded or law enforcement breaks them up, there's never enough "new recruits" to take the flame and continue on. Look at LulzSec. They had a huge run, but once Sabu flipped and turned most of his crew into the feds, there wasn't anybody else left would/could carry torch any further. So even when you have a high profile group, once it takes a hit, it's rare for them to bounce back. Anonymous is the exception to this rule, but it seems they like the decentralization approach their structure since it assures the group can carry on if/when the feds start to arrest its members.
3 - Knowledge transfer. Not only does size affect the lack the groups today, but also the lack of knowledge transfer. Back in the late 90's I knew a bunch of college guys who were hackers. You could ask them anything and most of the time, they'd let you in on how they hacked email, how they found open servers, etc. Nowadays, somewhat because of law enforcement, somewhat because people now see their hacking techniques as trade knowledge, they're much less open about how they ply their trade. This means every kid who wants to learn how to hack is on his own. There is no MOD or LOD or LulzSec to prove yourself to, to get entry into the club and get higher levels of knowledge. Hackers, are now, left to their own means to seek out and find their own knowledge. As such, the cycle perpetuates itself because now instead of wanting to share this knowledge, they have the attitude, "I found this by myself, go find it on your own." which makes people less likely to form a group to share knowledge.