Sinisterly
Hacker Jailed For Selling Customers' Data On Dark Web - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: General (https://sinister.ly/Forum-General)
+--- Forum: World News (https://sinister.ly/Forum-World-News)
+--- Thread: Hacker Jailed For Selling Customers' Data On Dark Web (/Thread-Hacker-Jailed-For-Selling-Customers-Data-On-Dark-Web)

Pages: 1 2 3


RE: Hacker Jailed For Selling Customers' Data On Dark Web - Double06 - 05-27-2018

I really enjoy these reads related to cyber-criminology and get me thinking..

"You have a deep and impressive knowledge of computers and if you had decided to use your abilities lawfully I have no doubt at all that you would have had a very successful career." - I'm not justifying this individual's actions in any way, however if such companies picked up the pace on such necessary security departments this individual might have worked and nourished his way for the ethical side. Instead of the company focusing example on their marketing department which would be to pump & dump ads to hook such customers (which I get from a business perspective), you also need to cover the the customer's you hook.

Followed by,

"Unfortunately you saw the potential of using your skills to make a great deal of money not lawfully but by crime, blatant crime and your crimes were highly sophisticated." - indeed his ways could be classified to 'sophisticated', however their nothing more than mass-botting emails with poor phishing attempts at clients information. As mentioned above security can never be fully covered and insured, but you can't expect to build a house with doors, and not install locks. The world is full of different individual with different morals who will persist, ethically or not.


RE: Hacker Jailed For Selling Customers' Data On Dark Web - mothered - 05-27-2018

(05-27-2018, 12:33 PM)Zajbu Wrote: As mentioned above security can never be fully covered and insured

Precisely.

From a security standpoint, you need to cover every angle and exhaust all channels but from an attacker's perspective, all you need Is one single gateway and you're In. A given flaw Is easily missed by a security analyst, and just as easily exploited by someone with malicious Intent.


RE: Hacker Jailed For Selling Customers' Data On Dark Web - Jiggly - 05-27-2018

(05-27-2018, 11:24 AM)mothered Wrote:
(05-27-2018, 11:09 AM)Jiggly Wrote: There may be no such thing as "completely secure", but don't make it easy for people.

Agree.

Going on personal experience, It's either the cost factor In why better security Is neglected, lack of knowledge or complacency.

Or possibly a mix of all three. If nothing happens to your company, you don't have excess funds allocated for security and you/your employees don't know much about security, it's likely to take a breach to teach you how important it is.


RE: Hacker Jailed For Selling Customers' Data On Dark Web - mothered - 05-28-2018

(05-27-2018, 10:12 PM)Jiggly Wrote:
(05-27-2018, 11:24 AM)mothered Wrote:
(05-27-2018, 11:09 AM)Jiggly Wrote: There may be no such thing as "completely secure", but don't make it easy for people.

Agree.

Going on personal experience, It's either the cost factor In why better security Is neglected, lack of knowledge or complacency.

Or possibly a mix of all three. If nothing happens to your company, you don't have excess funds allocated for security and you/your employees don't know much about security, it's likely to take a breach to teach you how important it is.

Agree. A company on a large scale, must look at all contributing factors when securing their organization.

When I perform a penetration test for a firm, "every" avenue must be exhausted- software, hardware, networking, social engineering and physical tests. The latter (physical) Is extremely demanding. It begins at the exterior of the building and finishes at the very same point on completion.

Everything from security cameras, building entry codes, visitor and employee authentication (via buzzing In), alarm systems, printers (wireless and/or fixed), scanners, photocopiers, faxes, modems, routers, fixed phone lines, call barring and caller ID spoofing (Incoming & outgoing) sensitive document disposal, removable device policies, company confidentiality, pre-employee screening & background checks, device disposal (eg: secure wipe on HDDs, printer HDDs etc), account authentication and complexity requirements Implemented, servers, IDS/IPS (security rules & traffic filtering), database configuration and authentication, device firmware and hardware component manufacturers, checkpoints In place when locking up at close of business, the effectiveness of checkpoints, the nature of all locks (can they be lock picked or opened with dedicated manufacturer bump keys), smart lock biometric authentication and recovery and the list goes on.

This covers around 15% of what's Involved. I'll be here most of the day If I document the lot. A lot of pen testers look at the technological/computing side of It alone. As you can see, that barely touches the surface.


RE: Hacker Jailed For Selling Customers' Data On Dark Web - Jiggly - 05-28-2018

(05-28-2018, 04:49 AM)mothered Wrote:
(05-27-2018, 10:12 PM)Jiggly Wrote:
(05-27-2018, 11:24 AM)mothered Wrote: Agree.

Going on personal experience, It's either the cost factor In why better security Is neglected, lack of knowledge or complacency.

Or possibly a mix of all three. If nothing happens to your company, you don't have excess funds allocated for security and you/your employees don't know much about security, it's likely to take a breach to teach you how important it is.

Agree. A company on a large scale, must look at all contributing factors when securing their organization.

When I perform a penetration test for a firm, "every" avenue must be exhausted- software, hardware, networking, social engineering and physical tests. The latter (physical) Is extremely demanding. It begins at the exterior of the building and finishes at the very same point on completion.

Everything from security cameras, building entry codes, visitor and employee authentication (via buzzing In), alarm systems, printers (wireless and/or fixed), scanners, photocopiers, faxes, modems, routers, fixed phone lines, call barring and caller ID spoofing (Incoming & outgoing) sensitive document disposal, removable device policies, company confidentiality, pre-employee screening & background checks, device disposal (eg: secure wipe on HDDs, printer HDDs etc), account authentication and complexity requirements Implemented, servers, IDS/IPS (security rules & traffic filtering), database configuration and authentication, device firmware and hardware component manufacturers, checkpoints In place when locking up at close of business, the effectiveness of checkpoints, the nature of all locks (can they be lock picked or opened with dedicated manufacturer bump keys), smart lock biometric authentication and recovery and the list goes on.

This covers around 15% of what's Involved. I'll be here most of the day If I document the lot. A lot of pen testers look at the technological/computing side of It alone. As you can see, that barely touches the surface.

I think that's a great way to explain it. I couldn't hope to know how to cover all those aspects, but I'm glad to be somewhat aware of them. During my courses for higher education (aka a course for working at universities), they kept coming back to security and privacy for students, parents, investors, industry partners and other stakeholders. I also had the opportunity to meet with some of the directors working on security in relation to facilities management (cameras, entry systems, alarms etc). Very insightful. I don't think I could ever know "enough" about it.


RE: Hacker Jailed For Selling Customers' Data On Dark Web - mothered - 05-28-2018

(05-28-2018, 10:24 AM)Jiggly Wrote:
(05-28-2018, 04:49 AM)mothered Wrote:
(05-27-2018, 10:12 PM)Jiggly Wrote: Or possibly a mix of all three. If nothing happens to your company, you don't have excess funds allocated for security and you/your employees don't know much about security, it's likely to take a breach to teach you how important it is.

Agree. A company on a large scale, must look at all contributing factors when securing their organization.

When I perform a penetration test for a firm, "every" avenue must be exhausted- software, hardware, networking, social engineering and physical tests. The latter (physical) Is extremely demanding. It begins at the exterior of the building and finishes at the very same point on completion.

Everything from security cameras, building entry codes, visitor and employee authentication (via buzzing In), alarm systems, printers (wireless and/or fixed), scanners, photocopiers, faxes, modems, routers, fixed phone lines, call barring and caller ID spoofing (Incoming & outgoing) sensitive document disposal, removable device policies, company confidentiality, pre-employee screening & background checks, device disposal (eg: secure wipe on HDDs, printer HDDs etc), account authentication and complexity requirements Implemented, servers, IDS/IPS (security rules & traffic filtering), database configuration and authentication, device firmware and hardware component manufacturers, checkpoints In place when locking up at close of business, the effectiveness of checkpoints, the nature of all locks (can they be lock picked or opened with dedicated manufacturer bump keys), smart lock biometric authentication and recovery and the list goes on.

This covers around 15% of what's Involved. I'll be here most of the day If I document the lot. A lot of pen testers look at the technological/computing side of It alone. As you can see, that barely touches the surface.

I think that's a great way to explain it. I couldn't hope to know how to cover all those aspects, but I'm glad to be somewhat aware of them. During my courses for higher education (aka a course for working at universities), they kept coming back to security and privacy for students, parents, investors, industry partners and other stakeholders. I also had the opportunity to meet with some of the directors working on security in relation to facilities management (cameras, entry systems, alarms etc). Very insightful. I don't think I could ever know "enough" about it.

That would've been a great experience meeting with the security directors. I wish I had the opportunity.

You've would have learned quite a bit from your courses.


RE: Hacker Jailed For Selling Customers' Data On Dark Web - Dexdeniro - 06-04-2018

I still think that is a little to harsh for the crime . 10 years is alot he didnt kill no one.


RE: Hacker Jailed For Selling Customers' Data On Dark Web - mothered - 06-05-2018

(06-04-2018, 07:58 PM)Dexdeniro Wrote: I still think that is a little to harsh for the crime . 10 years is alot he didnt kill no one.

Agree, particularly with your latter comment.

I've come across reports of crimes In my country, where murders have served half the time. Sentences are reduced based on various factors such as guilty pleas, but It still doesn't change the fact that they've killed someone.


RE: Hacker Jailed For Selling Customers' Data On Dark Web - xyzo - 06-07-2018

"£1.6m worth of cryptocurrency that is unaccounted for."

I hope he does not lose his keys to his crypto wallets.
Also - Knowing that you will get out of prison with over $ 2M USD waiting for you will make the prison time a bit easier.
The value of his crypto-portoflio could ofcourse crash down to 0, or grow to a extend where he does not have to work for the rest of his life anymore.


RE: Hacker Jailed For Selling Customers' Data On Dark Web - mothered - 06-07-2018

(06-07-2018, 12:16 AM)xyzo Wrote: Also - Knowing that you will get out of prison with over $ 2M USD waiting for you will make the prison time a bit easier.
anymore.

That's If he still has his sanity Intact.

10+ years In prison can have a significant negative Impact on one's mental state.