Attacks/Breaches
8/6/2011
07:35 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Building A Better 'Anonymous'?

DefCon 19 panel debates how the hacktivist collective could more effectively channel its energies for its own causes as well as for security

DEFCON 19 -- Las Vegas -- Aaron Barr was camouflaged in the audience here today rather than on the podium as the scheduled star panelist on the "Whoever Fights Monsters" session, while self-professed members of Anonymous later chimed in during a heated question-and-answer session.

The panel generated a provocative debate over whether the Anonymous hacktivist collective would be more effective if it retooled and focused its efforts -- as well as whether its very public hacks have actually prompted organizations to better secure their systems.

Barr, the former CEO of HBGary Federal who was targeted by Anonymous' LulzSec branch after promising to unmask some of its main members, at the eleventh hour had to pass on his slot on the panel due to the threat of a lawsuit from his former employer. But Barr's firsthand experience with being hacked, "doxed," and personally attacked by the hacktivist group served as a backdrop to the lively panel discussion, as well as the question-and-answer session at the DefCon 19 hacker convention.

The panel, moderated by Paul Roberts, editor of Threat Post, included Joshua Corman, director of security intelligence for Akamai; "Jericho" of Attrition.org; and "Krypt3ia," a security expert and blogger who began the session with his face masked ninja-style in a black scarf, identifying himself with the tongue-in-cheek pseudonym "Baron Von Aaarrrr." He later removed the mask after an audience member questioned the credibility of someone who would not show his face. "I'm overt, not covert," he said.

Akamai's Corman said Anonymous is more about chaos than white hats or black hats. "Anonymous isn't good or evil -- they're chaotic," Corman said. And the group and its brand of hacktivism and doxing isn't going away, he said.

But Anonymous' hacking, doxing, and exposing holes in organizations' security have not resulted in better security, he said. "My personal disappointment is if you think it makes security better by showing failure," that's not the case, he said.

Corman suggested that LulzSec would do better to channel its efforts on bad actors, such as child exploitation sites, for example, and cause "directed chaos."

"I'm not advocating vigilantism," however, he said. "But let's have a more intelligent discussion" rather than the seemingly random and chaotic attacks, he said.

Krypt3ia said calling out organizations for their weak or lax security wasn't the original purpose of Anonymous' attacks, anyway. "It was just an excuse made after the fact ... to [lend] it some legitimacy," he said.

And the mass-doxing strategy dilutes the impact Anonymous was going for, he said.

"You want to 'out' people for doing bad things? Well, cool, but do it right. Stop this crap of SQL injectioning and [leaking] unimportant data. The last dump on Mantech had one SBU [sensitive but unclassfiied] doc," he said. "So learn your target and know what you are doing. The real dirt comes out of insiders."

And it's possible the hacktivists could be getting misled by disinformation: "How do you know you have the real dirt? How do you know you are not getting disinformation?" Krypt3ia said. "I've seen companies already doing disinformation campaigns. Have Anonymous and LulzSec fallen into those traps?"

Jericho concurred that dumping massive amounts of uncensored data is ultimately relatively ineffective. "Releasing 250,000 cables is really cool, but it's hurting your cause. There's so much noise there and pointless documents. You could handpick them, or put them out one a day," for example, he said.

An audience member who said he works in Anonymous' LulzSec school responded to the discussion over the group's seemingly random and sometimes disparate activity. There are "eight different subcrews [in Anonymous] that each handle things differently," he said.

The panel basically agreed that protesting and calling out perceived injustices is a relatively positive goal of the group. But they also pointed to the lack of attribution. Dave Marcus, director of McAfee Labs security research communications who attended the session, says it's time for Anonymous to take ownership of its hacks and actions. "Do it openly and take credit for it," he said.

Gregg Housch, a member of Anonymous who participates in its chat rooms and protests but not in any hacking, says Anonymous should not have a particular focus. He says anyone can use the Anonymous "brand" in their hacktivist activities. "I'm not Anon, and I don't speak for Anonymous," he says.

He notes that some members left Anonymous after LulzSec's hack of HBGary and other organizations.

"If you leave Anonymous because you don't agree with something it did, then you don't belong in Anonymous," Housch says.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2886
Published: 2014-09-18
GKSu 2.0.2, when sudo-mode is not enabled, uses " (double quote) characters in a gksu-run-helper argument, which allows attackers to execute arbitrary commands in certain situations involving an untrusted substring within this argument, as demonstrated by an untrusted filename encountered during ins...

CVE-2014-4352
Published: 2014-09-18
Address Book in Apple iOS before 8 relies on the hardware UID for its encryption key, which makes it easier for physically proximate attackers to obtain sensitive information by obtaining this UID.

CVE-2014-4353
Published: 2014-09-18
Race condition in iMessage in Apple iOS before 8 allows attackers to obtain sensitive information by leveraging the presence of an attachment after the deletion of its parent (1) iMessage or (2) MMS.

CVE-2014-4354
Published: 2014-09-18
Apple iOS before 8 enables Bluetooth during all upgrade actions, which makes it easier for remote attackers to bypass intended access restrictions via a Bluetooth session.

CVE-2014-4356
Published: 2014-09-18
Apple iOS before 8 does not follow the intended configuration setting for text-message preview on the lock screen, which allows physically proximate attackers to obtain sensitive information by reading this screen.

Best of the Web
Dark Reading Radio