News Blog

News Blog


Hackers convene Last HOPE conference in the Big Apple

 

Computer programmers, researchers and students descended on New York City's Hotel Pennsylvania today for the HOPE conference, a forum for all things related to security, including a healthy dose of sessions devoted to breaking security. This year's conference is dubbed the "Last HOPE" because the Hotel Pennsylvania is shutting down. Apparently there aren't any other suitable venues in the whole of Manhattan for dozens of computer whizzes with a penchant for mischief, such as jamming cell phone signals and locking elevator doors. The hotel was a cheap gig for the conference organizers and willing to put up with these high-tech shenanigans.

Turns out, hackers (they don't like to be called "hackers" because it's a cliché and implies they're breaking the law, even though much of what they do is perfectly legal) have lots of questions about how the law applies to their work. This is particularly true when it comes to "botnets," legions of computers that have been turned into obedient zombies and are used by criminals to attack other computers.

Here's how it works: A hacker creates a bot by sending a virus, worm or other so-called "malware" over a network (often through e-mail) and installing it on unsuspecting computers. Once on a computer, the malware allows the hacker to take remote control of the computer, turning that machine into a zombie or robot (hence the name "bot) that can be manipulated into sending spam or large volumes of data to servers run by businesses, schools or other organizations, effectively clogging these servers and often rendering them useless for some period of time.

Some hackers amass large numbers of bots--called botnets--that they can then use to attack other computers, or the hackers can rent their botnets to other criminals. If this sounds farfetched, it's not. Owen Thor Walker, a teen who pleaded guilty earlier this year to six charges of accessing computers for dishonest purposes and without authorization, damaging computer systems, and possession of software for the purposes of committing a computer crime, narrowly avoided going to jail by offering to help police catch other cyber criminals, the Tech Herald reported Thursday.

Even government computers have fallen victim to botnets. In January 2006, Jeanson James Ancheta (20 years old at the time) pleaded guilty to a botnet attack on, among others, the Defense Department and was sentenced to 57 months in prison. Ancheta agreed to pay roughly $15,000 in restitution to the Weapons Division of the United States Naval Air Warfare Center in China Lake, Calif., and the Defense Information Systems Agency, whose national defense networks were intentionally damaged by Ancheta's malicious software.

The botnet threat has created a demand among computer programmers working for businesses, school and government agencies to mount defenses against them.

Of course, a proper defense requires an in-depth study of live botnet armies. So, how do law-abiding programmers find and study botnets without landing themselves behind bars (turns out, it's illegal to intercept and read data traveling across a network without permission)?

If a programmer finds himself or herself mistakenly intercepting legitimate network traffic (such as an online purchase that includes credit card information), they could have some explaining to do, Alexander Muentz, a Philadelphia attorney, cautioned attendees Friday during a session entitled, "Botnet Research, Mitigation and the Law." He added, "Just because you can (intercept and read information) doesn't make it legal."

Muentz warned those attending his presentation to be careful when defending against botnet attacks and discouraged attendees from "the macho response," if they find that their systems have been attacked by a botnet. "The counterattack defense, where you build your own white-hat, botnet army and take it to your attacker, isn't likely to work in court (if you're caught)," he said. On the bright side, if a legit programmer does succeed in attacking his or her attacker, it's unlikely that attacker will go to the police.

Last HOPE runs through July 20 and includes sessions that showcase skills such as lock picking, safecracking and escaping handcuffs. Speakers include Kevin Mitnick, a security consultant who spent five years in prison for computer-related crimes (although not hacking), and Jello Biafra, the former lead singer of the Dead Kennedys. Other activities include a laptop version of the game "capture the flag" and Segway racing.

Tags: Computers, Security, Hacker
More News Blog: Next: NIH official nixes large HIV vaccine trial Previous: Salmonella watch: Tomatoes in the clear, but watch out for hot peppers

1 Comments

Add Comment
View
  1. 1. Technolytics 04:10 PM 7/26/08

    The real issue is that many private sector organizations either do not take this threat seriously or are not willing to spend the time and money to build adequate systems security. Every computer on the network is a potential weapon waiting to be loaded and used and therefore must be protected. Until that is addressed this is an uphill battle that could prove futile!

    Reply | Report Abuse | Link to this
Leave this field empty

Add a Comment

You must sign in or register as a ScientificAmerican.com member to submit a comment.
Click one of the buttons below to register using an existing Social Account.

More from Scientific American

See what we're tweeting about

Scientific American Editors

More »

Free Newsletters


Get the best from Scientific American in your inbox

Solve Innovation Challenges

Powered By: Innocentive

  SA Digital
  SA Digital

Science Jobs of the Week

Email this Article

Hackers convene Last HOPE conference in the Big Apple: Scientific American Blog

X
Scientific American Magazine

Subscribe Today

Save 66% off the cover price and get a free gift!

Learn More >>

X

Please Log In

Forgot: Password

X

Account Linking

Welcome, . Do you have an existing ScientificAmerican.com account?

Yes, please link my existing account with for quick, secure access.



Forgot Password?

No, I would like to create a new account with my profile information.

Create Account
X

Report Abuse

Are you sure?

X

Institutional Access

It has been identified that the institution you are trying to access this article from has institutional site license access to Scientific American on nature.com. To access this article in its entirety through site license access, click below.

Site license access
X

Error

X

Share this Article

X

About the Bering in Mind Blog

In this column presented by Scientific American Mind magazine, research psychologist Jesse Bering of Queen's University Belfast ponders some of the more obscure aspects of everyday human behavior. Ever wonder why yawning is contagious, why we point with our index fingers instead of our thumbs or whether being breastfed as an infant influences your sexual preferences as an adult? Get a closer look at the latest data as "Bering in Mind" tackles these and other quirky questions about human nature. Sign up for the RSS feed or friend Dr. Bering on Facebook and never miss an installment again.

X

About the Cross-check Blog

Every week, John Horgan takes a puckish, provocative look at breaking science. A former staff writer at Scientific American, he is the author of several books—most notably, The End of Science: Facing the Limits of Knowledge in the Twilight of the Scientific Age. He currently directs the Center for Science Writings at Stevens Institute of Technology. He lives in New York State's Hudson Highlands, where he plays ice hockey each winter to hone his cross-checking skills.

X

Expeditions Blog

Ever wonder what it's really like to be working in Antarctica or collecting core samples from the middle of the Pacific Ocean? Get a first-hand feel for scientific exploration by following the blog posts of researchers out in the field.

X

About the Extinction Countdown Blog

Several times a week, John Platt shines a light on endangered species from all over the globe, exploring not just why they are dying out but also what's being done to rescue them from oblivion. From unusual or little-known organisms like the giant spitting earthworm and the stinking hawk's-beard to popular favorites like cheetahs and koalas, Platt, a journalist specializing in environmental issues and technology, does his part to slow the countdown.

X

About the Guest Blog

The editors of Scientific American regularly encounter perspectives on science and technology that we believe our readers would find thought-provoking, fascinating, debatable and challenging. The guest blog is a forum for such opinions. The views expressed belong to the author and are not necessarily shared by Scientific American.

X

About the Solar at Home Blog

Follow Scientific American editor George Musser as he installs--or tries to install--solar photovoltaic panels on the roof of his suburban New Jersey home. You'll learn the literal nuts and bolts of going green with the sun and get energy-saving tips even if you aren't putting up panels.

Write to us with tips or comments at blog@sciam.com and follow us on Twitter: http://twitter.com/sciam.

X