Attacks/Breaches

4/20/2017
04:30 PM
Kelly Sheridan
Kelly Sheridan
Slideshows
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
100%
0%

6 Times Hollywood Got Security Right

Hollywood has struggled to portray cybersecurity in a realistic and engaging way. Here are films and TV shows where it succeeded.
Previous
1 of 7
Next

(Image: NiP Photography via Shutterstock)

(Image: NiP Photography via Shutterstock)

Films and TV series have famously blundered their depictions of cybersecurity. NCIS, Scorpion, and CSI: Cyber, are a few examples that made tech pros scratch their heads.

Directors' challenge: security -- and tech plotlines overall -- aren't visually interesting. What's so glamorous about someone sitting at a computer, or a seemingly endless pile of code?

"Historically, Hollywood has struggled with the fact that the nuts and bolts of computing are not very photogenic," says ESET senior security researcher Stephen Cobb. It's tough to create a "rich visual environment" while offering a realistic portrayal of security and hacking.

The classic depiction of Hollywood hacking looks like someone at a computer with amazing graphics dancing across the screen. It's a conversation between two characters that sounds like this:

"I need someone to hack into the CIA."

"Oh, why didn't you just ask? I can do that."

While some of the fundamental concepts behind security-focused productions have been correct, the tech community has generally disliked how their profession is portrayed because each film or series skews in a different direction.

"Filmmakers say they want to portray hacking as being sexy and cool, but a lot of the time, sitting at a terminal isn't very cool," says Matthew Devost, managing director at Accenture Security and special advisor for the film Blackhat.

Not all films fail to get it right. Here, Cobb and Devost share the films and TV series where security is the focus and there are real takeaways for both security pros and general audiences. These productions may have some overdramatic moments, but they are more realistic than most:

 

Kelly Sheridan is the Staff Editor at Dark Reading, where she focuses on cybersecurity news and analysis. She is a business technology journalist who previously reported for InformationWeek, where she covered Microsoft, and Insurance & Technology, where she covered financial ... View Full Bio

Previous
1 of 7
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JulietteRizkallah
50%
50%
JulietteRizkallah,
User Rank: Ninja
4/26/2017 | 7:05:29 PM
Re: You missed one.
I agree!! The Millenium series has the best representation of the hacking techniques!  But maybe it was not included in this article as not initially created by Hollywood...
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
4/25/2017 | 1:30:29 PM
Sneakers, Hackers
It's been quite some time since I've seen Sneakers, but I definitely remember it as being among the less sensationalized and more "accurate" depictions of hacking.

Incidentally, I seem to recall the movie Hackers having some ridiculousness in it -- but it did offer one cool trick: That you can turn any (landline) phone into a rotary phone -- if, for some reason, dialing directly isn't a feasible or desirable option -- by simply tapping the hang-up clicker X number of times for each number.
SecretSquirrel96
50%
50%
SecretSquirrel96,
User Rank: Apprentice
4/24/2017 | 12:54:37 PM
Enemy of the State
Going to have to disagree on enemy of the State having anything realistic about it at all, let alone anything to do with Cyber Security. The only thing close to getting it right in that movie, was the fact the NSA exists.

Beyond that it was a typical Hollywood version of reality.

When you start of the movie with the murder of a politician by an NSA director, you lose all credibility in the realism category.

NSA doesn't, task or control imagery satelittes, nor are they re-tasked in real time or streaming live video, that's just completely ridiculous

 

 
Shantaram
50%
50%
Shantaram,
User Rank: Ninja
4/24/2017 | 2:56:32 AM
Re: 192.168.0.1
Excatly! Nice post, i really enjoyed to rea it. THanks
ANON1248385514336
100%
0%
ANON1248385514336,
User Rank: Strategist
4/21/2017 | 11:29:49 AM
You missed one.

This article for me was kind of a "Duh" moment. There's no major epiphanies here. What about "Girl with the Dragon Tattoo". For me, the brief glimpse of a SQL injection attack elevated the proficiency of the character way more than any portrayed hacker before that movie.

WebAuthn, FIDO2 Infuse Browsers, Platforms with Strong Authentication
John Fontana, Standards & Identity Analyst, Yubico,  9/19/2018
Turn the NIST Cybersecurity Framework into Reality: 5 Steps
Mukul Kumar & Anupam Sahai, CISO & VP of Cyber Practice and VP Product Management, Cavirin Systems,  9/20/2018
NSS Labs Files Antitrust Suit Against Symantec, CrowdStrike, ESET, AMTSO
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
Flash Poll
The Risk Management Struggle
The Risk Management Struggle
The majority of organizations are struggling to implement a risk-based approach to security even though risk reduction has become the primary metric for measuring the effectiveness of enterprise security strategies. Read the report and get more details today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-1664
PUBLISHED: 2018-09-25
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 echoing of AMP management interface authorization headers exposes login credentials in browser cache. ...
CVE-2018-1669
PUBLISHED: 2018-09-25
IBM DataPower Gateway 7.1.0.0 - 7.1.0.23, 7.2.0.0 - 7.2.0.21, 7.5.0.0 - 7.5.0.16, 7.5.1.0 - 7.5.1.15, 7.5.2.0 - 7.5.2.15, and 7.6.0.0 - 7.6.0.8 as well as IBM DataPower Gateway CD 7.7.0.0 - 7.7.1.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote atta...
CVE-2018-1539
PUBLISHED: 2018-09-25
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.
CVE-2018-1560
PUBLISHED: 2018-09-25
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tr...
CVE-2018-1588
PUBLISHED: 2018-09-25
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6) is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resourc...