back to article Hacking Team havoc shows even 'security experts' suck at security

Over the weekend, 400GB of highly sensitive files belonging to Italian malware spyware software house Hacking Team were spread over the internet for everyone to see. The leaked source code and documents look legit, and match what is already known about the secretive firm, which specializes in selling software for monitoring …

  1. Anonymous Coward
    Anonymous Coward

    Everybody likes toast.

    Can't we say they are Marmite, some may like it, some may not.

    But fuck them and all they stand for.

  2. Steve Aubrey

    Live by the sword,

    die by the sword. If you're going to play in this arena, you have to plan on the attacks coming. Not if, but when.

    Probably wouldn't hurt to have a full-time, completely independent pen test team. With hefty rewards for successful attacks.

    1. Roq D. Kasba

      Re: Live by the sword,

      If you're going to pick fights, learn how to fight (or at least how to defend yourself!)

    2. Ole Juul

      Re: Live by the sword,

      Backups are also important. For example, having another job lined up would be prudent.

      1. Anonymous Coward
        Anonymous Coward

        Re: Live by the sword,

        Just start up the backup company...

    3. John Brown (no body) Silver badge

      Re: Live by the sword,

      "Not if, but when."

      I'm surprised it's taken this long. I'd have thought Calling your business "The Hacking Team" was a little like a red rag to a bull in hacking circles.

  3. Mephistro

    Defining Hacking Team and HBgary...

    ... as 'security firms' is a little bit of a stretch, in my opinion. They seem to be doing just the opposite thing, making the Internet a less secure place and, by extension, making the world less secure also.

    I'd like all these (in)security firms -and they governmental customers- to FOAD, preferably in flames. I'll keep on dreaming. Sigh...

    1. This post has been deleted by its author

      1. Mark 85

        Re: Defining Hacking Team and HBgary...

        Nice sentiments and I agree. These types of firms will keep popping up as long as someone waves cash in their face and as long as there are repressive governments, there will cash.

        *Had to withdraw and edit.. stupid typos.. Bad keyboard! Bad! Go to the corner!"

        1. Michael Wojcik Silver badge

          Re: Defining Hacking Team and HBgary...

          These types of firms will keep popping up as long as someone waves cash in their face and as long as there are repressive governments, there will cash. there are computers.

          FTFY.

          Information Technology creates the market for its abuse. Governments seek to accrue power, and so does the private sector, and often enough so do individuals. We're not going to achieve some sort of utopia where everyone agrees not to read each other's mail, to paraphrase Stimson.

          Certainly we can cheer (and work for) particular successes: rolling back government powers here, applauding when a bad actor is caught there. The systemic problem will never go away, though.

    2. Anonymous Coward
      Anonymous Coward

      Re: Defining Hacking Team and HBgary...

      Internet is already a not secure place - and this kind of software can be used in a bad or a good way - like any weapon. Today perfectly legal, good and needed nvestigations cannot ignore electronic data - physical surveillance devices or phone taps are no longer enough.

      There were and are a lot of companies around making physical surveillance devices, why nobody complains about them? Even a lot of high-end cameras and telephoto lenses are used for that purpose - but Canon, Nikon and the like don't care to whom they sell too...

      I perfectly understand the need to control who has and how can use this kind of technology - and ensure it is used to protect people from criminals, not viceversa (otherwise criminals will have it, and you won't).

      Unluickily, greed is a powerful incentive to sell to anybody - yet some states are still "allies" even if they don't match ethical standards, and I guess some contracts were obtained through governments - for example USA are known to deliver to some "allies" (not fully trusted) technology bought abroad to avoid to deliver and disclose their own.

      I wonder how many people ethical standards will change easily when many $$$$$$$$$$$ will materialize in front of their faces, like some artists one day demonstrating for human rights, the next ready to perform privately in front of known dictators, as long as the check is big enough.... are you all sure you will be coherent and bold enough to say "NO!"? Throw the first stone...

    3. Anonymous Coward
      Anonymous Coward

      Re: Defining Hacking Team and HBgary...

      Reading this article has sent me all misty eyed and nostalgic for the halcyon days of the HBGary fiasco.

      That was an absolute hoot.

      Having said that, having another look over some of the IRC logs from the time is a little depressing, given the subsequent fates of those involved.

  4. Anonymous Coward
    1. Anonymous Coward
      Anonymous Coward

      Re: Bangladesh

      You don't need such sophitication to find a blogger, and your accusation without any proof are very much alike what such a government would do.

  5. FozzyBear
    Happy

    I admit to

    Reading about the attack and subsquent fallout over the attack with great glee.

    I will sign off with a head nod to the articles picture

    HACK THE PLANET

  6. oneeye

    This story is the gift that will keep on giving. The arrogant security (so called) experts should have a check list if they can't remember the basics that they continually warn Us about.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like