Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> or Mitnick Security

Please no. Not Mitnick.

I'd rather funnel clients towards my competitors than Kevin Mitnick.

He's a skilled social engineer, and his greatest social engineering success was manipulating the media into believing he speaks for hackers in general.

He is not a programmer, his opinions on cryptography aren't insighful, etc. His only skill is deception.



A nice example is when I used to point out OpenVMS security benefits. Better architecture, higher quality focus, and few things running by default led to fewer vulnerabilities and more containment than competing systems. At least one person always had a recurring counterpoint: "but didnt Mitnick hack all kinds of VMS systems?"

If by hack, you mean use conned or password-guessed credentials to get in... Not my definition of the word.


Regardless of your opinion of The Man Himself, the company employees people that are good at things beyond social engineering. I've seen two separate engagements with them (one as a 3rd party and one as technical contact), and both found significant non-trivial vulnerabilities that needed to be patched.


I can't speak towards the efficacy of his staff, but that testimonial is generally true of any engagement with most security teams.


To be fair, are we assuming op's server wasn't compromised through deception? Smart play is usually the easiest path to a goal...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: