ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Mitnick on hacking

Joris Evers CNET News.com

Published: 04 Nov 2005 18:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

To many, the name Kevin Mitnick is synonymous with "notorious hacker". He was caught by the FBI in 1995 after a well-publicised pursuit. Mitnick pleaded guilty to charges of wire and computer fraud and served five years behind bars.

Today, Mitnick is a computer security consultant and has written two books, including one on his forte — social engineering. He is a celebrity, especially at events such as the annual Defcon gathering of hackers in Las Vegas, where attendees ask him to sign their badges.

Mitnick spends much of his time on the road at speaking engagements. ZDNet UK's sister site, CNET News.com, caught up with Mitnick after a gig at a San Francisco user event for SupportSoft, a maker of call centre software, and talked to him about software security, the evolution of hacking and social engineering and law enforcement's action against hacking.

Q: What do you think of the state of software security these days? Is it getting better?
A:
Software is always going to have bugs because there are human beings behind it doing the development. Hopefully, universities teach secure coding practices. When I went to school, there were many programming classes, but nothing that taught secure coding practices. So, hopefully, there will be an educational process and companies will actually do source code audits before they release their software and also train their people in secure coding practices if they are already employed and not in school. That will reduce the amount of problems, but there will always be problems.

Do you believe that the state of software security is better today than five or 10 years ago?
No, though it depends on what software you are talking about and what the company has done. I can't make one statement for the whole industry. Take Microsoft, for example. I think their current code base is more secure than Windows NT was.

Would you say Microsoft is a leader and the rest of the industry is still catching up to that?
It is whatever the market demands — and Microsoft is up there, front and centre, because they have such a broad user base. Maybe you can call them a leader, but I am sure there are other companies who are taking security seriously. I am waiting for a case where a software maker gets sued for releasing buggy code, but they will probably cover their ass with the long license agreements that nobody ever reads.

We've been talking about weaknesses in technology, not weaknesses in humans, which can also be a threat. You're one of the social engineering gurus. Do you see it evolving?
They are always coming up with new scams. A year ago it was Nigerian scams. Now callers purport to be from the MasterCard or Visa fraud department, calling you to try to trick you into revealing your CVV (Cardholder Verification Value) number...

For more, click here... 

Next

Previous

1 2 3


  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
188 out of 430 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Network / Security Manager, West Yorkshire, 25k-30k

Network and data security is of paramount importance to the company - you will have a proven track record in network and data security, an ...

Fraud Analytics Manager

Well renowned large Retail Bank require a Fraud Manager. The role will be focused on the Bank's Fraud Analytics team. The person who assumes this ...

Clinicial Coding - NHS - London and Home Counties

If you have Clinical Coding experience and would be interested in contract work please send in an up to date CV and contact Steve. We have an ongoing ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Speed Demon: Wireless Surpasses...

Mobile Speed Demon: Wireless Surpasses Landline Author: Eric Everson, Founder MyMobiSafe.com As I look around my house and throughout my network of friends, I instantly realize... More

Post a comment

Why do you need Portable password mana...

There are much more than 5, but I will start with these main points: 1. You are human... never mind, no one is perfect. 2. We live in modern world with its cons and pros 3. We... More

Post a comment

The GoDaddy saga continues...

I've been trying to sort out an incident with registrar GoDaddy since last week. I blogged on Tuesday and Thursday about the situation, but in a nutshell I found out that I was registered... More

1 comment