Technology Review - Published By MIT
Advertisement

March 2005

The Talented Mr. Mitnick

A notorious hacker turns security guru.

By Gregory T. Huang

smaller text tool iconmedium text tool iconlarger text tool icon

From hijacked PCs that spew spam to denial-of-service attacks that crash Web servers, cyber-crime means billions of dollars a year in lost revenues and productivity. And no computer user is safe. "It's not if," says Kevin Mitnick, "it's when are you going to get hacked."

Mitnick should know. The former hacker perpetrated a series of high-profile corporate break-ins in the 1990s -- and served five years in federal prison for it. Once the FBI's most-wanted cyber-criminal, Mitnick is now one of the world's most sought-after tech security consultants. "A few years back, companies spent more on coffee than on security," he says. Now, they make security their top priority, hiring Mitnick to break into their systems, expose their weaknesses, and teach them how to protect themselves.

Hacking has been Mitnick's priority ever since his teenage years in southern California. First telephone networks, then the Pentagon -- then Nokia, Novell, and seemingly every other big company. Today's laws on cyber-crime were practically invented because of Mitnick. His pranks earned him the respect of hackers as well as numerous arrests, culminating in his five-year prison stint. Mitnick spent eight months of that time in solitary confinement, he says, because the judge was told that Mitnick could start a nuclear war by calling up NORAD on a payphone and whistling modem tones into the receiver. His radio was seized for fear that he would turn it into a cell phone. Even using an electric typewriter in the prison library got him handcuffed and whisked away. "These guys were watching too much MacGyver," he quips.

That was the turning point in his career. Since his release from prison in 2000, Mitnick has chosen to use his considerable skills to improve network security. Now 41 and sporting a decidedly buttoned-down look, Mitnick has made a guest appearance on the TV show Alias and earned honorable mentions in many other media outlets. Though he is often recognized as "that hacker guy" in airports and hotels, he says he registers under a fake name only at hacker conventions. But he doesn't give out his private e-mail address or his city of residence; one can't be too careful.

Indeed, the current pace of cyber-crime amazes even Mitnick. Last fall, he and Avantgarde, a tech marketing and design firm in San Francisco, hooked up six  computer platforms to the Internet via broadband DSL and recorded the cyber-attacks that occurred over a two-week period. It took less than four minutes for an automated attack to successfully break through the security defenses of one newly connected PC; most machines without an active firewall (a filter that screens suspicious code) faced more than 300 attacks per hour, while those with firewall protection faced fewer than four per hour. But  firewalls don't protect against "social engineering," a fancy term for conning users out of such sensitive information as passwords and PINs. The  idea that humans are the weak link in any security system was famously exploited by Mitnick in his glory days; he comes across as personable and authoritative, so it's easy to see why people would give him information.

Mitnick's case highlights a point that's increasingly critical as more and more sensitive information and money change hands over the Internet: in his words, "Hacking is a skill set -- how you use it is up to your ethics and morals." And the arms race between malicious hackers and security experts will only escalate. "Computer systems are complex," Mitnick says. "There will always be ways to break in." Which means that no matter which side he is on -- let's hope it's ours -- Mitnick will always be in demand.

March 2005

Would you like to read more articles from the March 2005 issue?

This article is from the March 2005 Issue of Technology Review. To read other articles from this issue simply register for My.TechnologyReview.com. It's free.

Subscribe today and save up to 41% »

Comments

  • fy
    Guest (f##ker) on 12/23/2005 at 8:31 PM
    Posts:
    1
    f##k off
    Rate this comment: 12345
    • Icon
      Guest (shinobi) on 04/29/2006 at 12:00 AM
      Posts:
      1
      Mr.Mitnik .. i wish u to visit U.A.E-Dubai and give some conference
      i would like to meet u
      Rate this comment: 12345
    • the best
      Guest (hex) on 05/19/2006 at 12:00 AM
      Posts:
      1
      wish i know you mr Micknic
      Rate this comment: 12345
  • fy
    Guest (f##ker) on 12/23/2005 at 8:31 PM
    Posts:
    1
    f##k off
    Rate this comment: 12345
Advertisement

Current Issue

Technology Review November/December 2008
Sun + Water = Fuel
An MIT chemist has opened the way to making hydrogen fuel from water using sunlight.
•  Subscribe
Save 41%
•  Table of Contents
•  MIT News

Magazine Services

Career Resources

MIT Technology Insider

Stories and breaking news from inside MIT about the latest research, innovations, and startups--in a convenient monthly e-newsletter. Subscribe today
Advertisement

Follow us on Twitter

Twitter

Get Technology Review updates via the web, cellphone, or Instant Messager – Follow techreview on Twitter!

Advertisement

More Technology News from Forbes

Advertisement
Advertisement
TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology