logoalt Hacker News

mcfunleytoday at 12:22 AM7 repliesview on HN

I worked at a company that had hired Mitnick as a security consultant.

His report for a client that turned out to have been rife with SQL injection at the time was largely movie plot physical security stuff. Not wrong exactly, but not the center mass of the threat model they needed either.

He seemed to lack systems thinking, producing a report that focused on calling out specific employees as dumb or incompetent. Counterproductive at best. It seemed like his PR exceeded his utility by a great deal.

That trend continues beyond the grave, maybe.


Replies

leetrouttoday at 1:06 AM

Dude I was called out by name in the report either right before you got there or the first one you were there. I was called out in the one where they got B's Audi keys in his office.

Whole thing was so dumb. A floor full of smart monitors that they could have put a keylogger on. A plethora of physical network access and I get called out for leaving my laptop on the lock screen and going downstairs for food.

And they got found out because I ran little snitch I paid for myself and it caught their hijacked chrome making all sorts of weird network calls. But I don't remember being given credit for that.

(Sips mojito)

tophamtoday at 12:31 AM

The hero worship of him makes me physically ill, always has.

He did cost people their jobs though, so I guess he's a good person.

lern_too_speltoday at 12:28 AM

He social engineered your company into contracting him, and that adds to the legend, but people don't see how many other companies he failed to social engineer.

the_aftoday at 12:45 AM

Kevin's security company is also a mess, and the training videos they produce are embarrassing at best.

I understand he probably just lent his name to the company (though he did show up in some of the videos), but still...

show 1 reply
kingforadaytoday at 12:35 AM

> "He was a hacker-turned-security consultant who, later in life, helped shape the modern white-hat."

They left out convicted criminal.

show 1 reply
skeakertoday at 1:12 AM

In all fairness, a genuine attacker WILL be abrasive and abusive. They WILL single out employees that are gullible and exploit them. It's not pretty because a genuine attack is not pretty. Of course a simulated attack will be indecent and discourteous in nature, that is how attacks are.

show 1 reply