Explaining this sentiment, Andy Kemshall - CTO and co-founder of SecurEnvoy, said, “I firmly believe that the media attention LulzSec’s DDoS attack has recently received is deserving. It’s thanks to these guys, who’re exposing the blasé attitudes of government and businesses without any personal financial gain, that will make a difference in the long term to the security being put in place to protect our own personal data!”
Andy continues, “While many are claiming the attack is a bad thing what they’re forgetting is, at the end of the day, it comes down to a fundamental failing on the part of the organization that allows these criminals in. If they didn’t leave their networks unlocked there wouldn’t be a problem. For example, we visited a local authority last week offering to secure data access while it’s waiting for its SecurID tokens to be replaced by RSA. We were astounded to find that the organization was actually pretty blasé and said they didn’t feel there was a huge risk. This is naïve as, not only is there proof that the tokens are insecure as another organization has been hacked, but why else would RSA go to the expense of replacing them if there wasn’t a problem?”
While some believe time and effort should be spent deactivating hacker groups, like LulzSec and Anonymous, Andy believes there is much to be learnt from their expertise and raw talent.
Andy clarifies, “These techies are up to speed and are useful to the industry – we need them! What people choose to ignore is many of today’s experts are ex-hackers themselves so Anonymous and LulzSec are actually tomorrow’s authority. They offer fresh ideas and they’re exposing new vulnerabilities that the ‘good guys’ may not yet have seen or even considered. The simple truth is that we’re going to need their expertise if we’re to defend ourselves against other countries and those malicious hackers who are out for financial gain. Instead of persecuting them, we need to recognize their talent, embrace their expertise and encourage them across from the dark side to turn their expertise into something constructive rather than destructive.”
At present it would appear that LulzSec and Anonymous are working on their own initiatives. Andy speculates on the power that could be harnessed by getting these organizations to actually work together, “At the moment, you’ve got these ‘gangs’, for want of a better term, getting massive exposure with what would appear to be very little financial backing or leadership – it goes against the norm as they are doing it for the common course."
"I think these guys are extremely clever to be able to operate with zero budgets and get the huge amount of coverage they’ve achieved to date in comparison to the vast PR machines of the FTSE 100 companies. By combining their services you’d create a considerably formidable force whose strength could be used for good, for example to bring down terrorism and the ill-forces operating with the confines of the Internet. We should be nurturing this IT talent and growing it for the good of the general public."
Andy concludes, “Organizations are still too blasé about security. These are people we trust to look after our details, but they don’t seem to be taking this honor too seriously. We need people like LulzSec and Anonymous, and I personally am standing up and saying thank you to these guys, as they are making businesses and government sit up and take action or naming and shaming them so at least I can have an informed opinion of who I can trust.”
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.