Big Data. Big Decisions
InformationWeek
Special Coverage Series

Commentary

Mathew J. Schwartz

Mathew J. Schwartz



When Hackers Meet Girlfriends: Readers Judge Our Theory

My modest proposal to deter law-breaking hackers by helping them get girlfriends sparked condemnation, support, and even marriage advice.

Do hackers have an image problem? As far as many self-professed hackers are concerned, the hacking underground is doing just fine, thank you very much. Now move along.

Discussions about hacking (taking things apart and putting them back together again) and cracking (breaking into systems or software, typically for illegal purposes) can be challenging. Many non-hackers see cracking as synonymous with hacking. Many self-professed hackers shout down outside analysis of their activities or motives. Then, of course, there are those limelight-stealing amateur upstarts--in the eyes of many hackers--known as hacktivists who have the temerity to crack poorly secured databases, claim the hacker mantle, and then brag about it.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Judging by the quantity and range of responses to my recent column, "One Secret That Stops Hackers: Girlfriends," many hacking supporters have strong feelings about research showing that many young crackers simply "age out" once they get a girlfriend or other life responsibilities. "Someone who does not understand," tweeted more than one reader. But others supported the findings: "The story is completely true, tho. Happened to me and many of my friends. Exactly as late teens, and then we got girlfriends," read one post to Slashdot.

[ Cyber-vandals created an Android app store that stocks nothing but malware. Read about it at Android Attackers Launch Fake App Market. ]

Anecdotal insights and opinions about hackers--never mind the relationship proclivities of the hacking-inclined--abound. So here are some thoughts in response to the comments on my column asking how we might better help young hacking aficionados steer clear of jail:

1. What do serial hackers look like? Why do people hack? Are they young or old? How many hackers break the law? Are there more hackers than bank robbers? Is the majority of online crime today perpetrated by international identity theft syndicates? If an information security expert illegally accesses an online server but no one ever finds out, did it really happen?

Discussing computer crime can quickly verge on the existential, which just goes to show how little we know about it. While the FBI tracks bank-robbery statistics, it doesn't do the same for online crime. Accordingly, part of the usefulness of the research cited in my column from online psychology expert Grainne Kirwan, who lectures at Ireland's Dun Laoghaire Institute of Art, Design and Technology, is that she's taken the time to speak with numerous hackers, thus providing some answers to the preceding questions. Furthermore, what she found is that most--not all--hackers are young, and that many stop hacking when they get jobs and more life responsibilities. But she also spoke to older hackers who have kept it up.

2. Real hackers don't get caught. On that note, might the best hackers simply never get caught? "Real hackers go undetected. I'm 29. I'm a hacker. I have a job. I have a relationship. I have children. I just stand up for what's right, not just what makes money," said "KoE" in a comment to my column.

But how likely is it that all "real hackers" don't get detected? Isn't it also possible, in part, that law enforcement agencies know about a great many more indiscretions than they publicly acknowledge or pursue, and that--given finite resources--they simply focus on the more egregious cases of law breaking?

3. High-tech crime: Too much jail time? Should we as a society go easier on high-tech criminals who do get caught, especially if they evince a social conscience? To help answer that question, consider that admitted LulzSec participant Ryan Cleary, now 20, faces 25 years in prison in the United States if he's extradited--on top of any jail time he might serve in the United Kingdom. That's thanks to LulzSec's 50-day spree that mixed hacking websites from Sony to the U.S. Senate, before the group's leader, Sabu--by then an FBI informant--called it quits and launched a collaboration with Anonymous called AntiSec. Given the list of Cleary's crimes, does the potential jail time seem appropriate?

4. Businesses: Be accountable for data security. If part of the function of jail time is to warn other people away from certain types of crimes, then the stiff sentences associated with high-tech crime might stand. All potential rehabilitation aside, "the problem with the 'aging out' theory is that there is always a steady supply of younger hackers who take the helm--and build on the work of their predecessors," commented "Cryptodd" on my column.

That speaks to a bigger issue: if your databases are getting owned by a 16-year old, then your business isn't trying hard enough to protect its data. Better security practices, in other words, would make the youthful high-tech offender situation largely academic. In Cryptodd's words, "If data is encrypted and protected well, hacker satisfaction decreases to zero."

5. Getting hackers girlfriends would be expensive. Want to fix the hacking problem? Then get hackers girlfriends, I joked in my column. "This guy has come up with the solution to stop hackers. The FBI can start a matchmaking division to stop cybercrime," tweeted ex-hacker Kevin Mitnick.

While the concept sounds absurd, it's apparently been tried before, and it worked. As one reader emailed, linking to an Atlantic article: "The basic premise--have relationships with women to neuter dangerous men--has been tried, apparently with success. The year is 1972, after the Olympic massacre of Israelis by the Palestinian Black September terrorists. The PLO brass needed--if only for PR reasons--to shut down this group. The solution? Recruit the most beautiful daughters of Palestine, offer the terrorists a job, apartment, a wife to get them to retire." The catch, aside from finding interested female participants, is that the strategy was apparently quite expensive.

6. Revenge of the girlfriend theory. Government-promoted hacker resettlement program or dating service aside, numerous responses to my column--not least via an amusing marriage and dating sub-discussion on Slashdot--highlighted the fact that many young adults do quit hacking simply because they got a girlfriend. "In my case, she didn't do anything specific to stop my hacking, beyond existing. We have only a finite amount of time," said one Slashdot poster.

7. Hack this: Ethical encouragement. To the overriding question posed in my column--"How might young hackers who break the law be encouraged not to do so?"--the award for best response goes not to a hacker, but from someone who lives with one. "AutumnL78" says the answer isn't "throwing girls at them," but rather encouraging them to use their skills for better purposes.

"The key issue is not discouraging, but encouraging in a positive and educated way. Instead of trying to stop kids from hacking, we need to be focusing on what can be done to encourage them to become ethical hackers," she wrote.

"How do I know this??? Eight years ago I married the guy who got busted for hacking the schools' dial-up system from home in middle school, who would take leave to go to hacker cons, and owned a small library of 2600 magazines," she said. "I encouraged this hacker to change rates in the Navy so that he could use his interest in hacking and all the skills he had for good. I supported his desire to get not one, but two master's in Internet security. I have gone to many hacker cons just to learn and understand what my husband is passionate about."

The best solution? To help keep more young rule-breaking hackers from doing jail time, let's encourage them to put their skills to ethical use. Anyone want to argue with that?

Distributed denial-of-service attacks can do serious damage. Get ready before you're hit. Also in the new, all-digital Save Your Assets issue of Dark Reading: Next-gen attackers aren't out to steal your money, and your old style of defense isn't going to stop them. (Free registration required.)



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.

Follow InformationWeek

By The Numbers

What Are Your Primary Concerns About Using Big Data Software?

Base: 417 respondents at organizations using or planning to deploy data analytics, BI or statistical analysis software
Data: InformationWeek 2013 Analytics, Business Intelligence and Information Management Survey of 541 business technology professionals, October 2012

What Do You Think?

What's your attitude about SQL analysis on top of Hadoop?
We want fast, standard SQL analysis capabilities on Hadoop ASAP
Hadoop is for unstructured data; SQL is for relational databases
We'll give SQL on Hadoop a try, but relational DBs will remain the mainstay
Given strong SQL support on Hadoop, we'd nix the data warehouse
We're not interested in Hadoop
No opinion



Related Content

From Our Sponsor

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Five Big Data Challenges and How to Overcome Them with Visual Analytics

Business leaders often need a visual snapshot of data to quickly grasp and use it. This paper identifies five challenges in presenting data and how visual analytics can resolve them. Solutions are suggested to overcome the challenges of: speed, data clarity, data quality, displaying meaningful results, and dealing with outliers.

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Game-Changing Analytics: How IT Executives Can Use Analytics to Create Innovation and Business Success

Today's competitive advantage requires a deeper understanding of your business, your market and your customers. As an IT executive, you can drive that knowledge transformation. In this white paper, learn how to make decisions as a strategic business leader and three steps to begin an analytics initiative within your enterprise.

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

Data Visualization Techniques: From Basics to Big Data with SAS Visual Analytics

High-performance data visualization turns sophisticated analyses into meaningful graphics, leading to faster and smarter decision making. In this white paper, learn how visual analytics can transform big data, with additional features such as real-time functionality, mobile compatibility, robust applications for technical groups and accessibility for nontechnical users.

Big Data: Lessons from the Leaders

Big Data: Lessons from the Leaders

Financial performance, competitive advantage, operational efficiency, strategic decision making - every business goal can extract value from big data, and the time for doubt or inaction has long passed. In this Economist Intelligence Unit report, in-depth interviews with data pioneers reveal the link between the effective use of big data and the bottom line among other results.

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Decision-Driven Data Management: A Strategy for Better Decisions with Better Data

Which came first, the data or the decision? This white paper makes the case for having a decision in mind, then tailoring big data's volume, variety and velocity to achieve business results such as overcoming customer dissatisfaction or creating well-informed strategies in real time.

Informationweek Reports

Research: The Big Data Management Challenge

Research: The Big Data Management Challenge

The challenge of big data is real, but most organizations don't differentiate 'big data' from traditional data, and nearly 90% of respondents to our survey use conventional databases as the primary means of handling data. We'll help you understand what constitutes big data (it's not just size) and the numerous management challenges it poses.