Re: [ISN] Oracle Chief Challenges Hackers

From: InfoSec News (isnat_private)
Date: Wed Nov 21 2001 - 02:25:30 PST

    Forwarded from: "Michael J. Reeves, AA, ASc" <mjreevesat_private>
    I find the comments made by J. D. Dyson interesting. I recognize he is
    one of the more knowledgable and visible persons of this forum.
    However, I cannot totally agree with his views in this matter.
    Having studied the history of cryptoanalysis, it is apparent that most
    cryptoanalysis is supported by the government. Secondly, though the
    URL link is highly critical of contests, it does not offer many
    concrete facts to support the position of the writer.
    For example, the contest mentioned, and the alleged fact that the
    algorithm was broken by various means. Nowhere is it indicated whether
    the TEXT was in fact RECOVERED???
    Fact: IF you have NOT recovered the text, you have NOT broken the
    Fact: Babbage was an academic who worked for the government. So are
    many other academics.
    In the present instance, the game is to break into/through a security
    system on a computer network. For a lot of hackers who take this as a
    PERSONAL affront to their skills, they will increase their attacks on
    the system.
    This will of course generate a great deal of information for the
    developer/publisher of the software in question. It should be obvious
    that the developer will use this information to enhance and fix
    security breaches in thier program.
    COOPERATION!!! LOW SELF-ESTEEM is SO-OO manipulatable!!!
    IF I was going to play the role of a "BLACK HAT HACKER" (IF!!!), I
    would keep my mouth shut, and WAIT until the software has been
    disseminated into the network system. I would attack the USER's
    system, and leave the developer alone. THIS is the strategy that HURTS
    the developer's credibility!!!
    IF the developer wants to test their system through a contest, let
    them put up some SERIOUS money. Consider they are attempting to hire
    for FREE the combined skills of numerous hackers of various abilities
    that may total hundreds of hacking experiemce years.
    An appropriate amount of money would be several ANNUAL salaries that
    could be shared among those who successfully breach the system.
    Consider this a CONSULTING FEE for contributing to the further
    development of the security features!!!
    InfoSec News wrote:
    > Forwarded from: Jay D. Dyson <jdysonat_private>
    > On Thu, 15 Nov 2001, InfoSec News wrote:
    > <SNIP>
    >         If stupidity is dangerous, then Mr. Ellison's statement is
    > accurate.
    >         For clear and concise refutation on why the challenge is bogus, I
    > need only point to Bruce Schneier's December 1998 remarks on the matter:
    >         Mr. Ellison would do well to read it and recognize his folly.
    >         And for the record, nothing, but *nothing* is perpetually secure.
    > Time is the greatest reducer of perceived absolutes.  And when (not if)
    > the time comes when Oracle is breached, I will personally laugh...
    >         ...and point.
    > - -Jay
    > <SNIP>
