iPhone app iPad app Android phone app Android tablet app More

LulzSec, Sony, And The Rise Of A New Breed Of Hacker

Sony Hack

First Posted: 06/07/11 07:05 PM ET Updated: 08/07/11 06:12 AM ET

NEW YORK -- When a new hacking entity calling itself LulzSec claimed credit for a barrage of recent attacks on Sony and several other companies, many cyber-security experts found themselves grasping for a term to describe the attackers.

Hackers often divide themselves into two groups -- the "black hat" hackers, who exploit the vulnerabilities of their victims for profit, and the "white hat" hackers, who point out those weaknesses so that the vulnerable can take the proper measures to protect themselves. Yet as several experts pointed out recently, LulzSec doesn’t really fit into either of those categories, and that slipperiness, combined with the group’s sudden prominence, speaks to how hacker culture is changing.

In the wake of the April attack that exposed the records of more than 100 million customers of the Sony PlayStation Network, a crime whose perpetrators remain unknown, LulzSec has claimed responsibility for additional attacks on Sony, as well as hacks against PBS, Nintendo and InfraGard, an organization affiliated with the FBI.

In a press statement released last week, the group wrote, "We recently broke into SonyPictures.com and compromised over 1,000,000 users' personal information, including passwords, email addresses, home addresses, dates of birth, and all Sony opt-in data associated with their accounts." LulzSec also claimed to have gotten hold of "3.5 million 'music coupons,'" which the group then invited the public to "plunder."

Their motivation, it seemed, was something other than monetary gain. But what? An introduction on their website offers a clue: "We have now taken it upon ourselves to spread fun, fun, fun… "

Jeff Moss, the founder of Defcon, the world’s largest hacking conference, told HuffPost, "We’re struggling with labels to describe what they're doing." He brought up the term "gray hats," which has been around at least since the late 1990s and is about as ambiguous as it sounds.

"You could call them 'gray hats' in the sense that they're breaking laws," he said, "but they're not, as far as I can tell, stealing secrets and trying to sell them, like corporate espionage, and as far as I can tell they're not blackmailing anybody or holding anybody ransom."

Moss drew a connection to George Hotz, also known as geohot, a 21-year-old hacker who was sued by Sony earlier this year and whose conflict with the company sparked a retaliation against Sony in early April by the hacker collective Anonymous.

In 2010 Hotz figured out a way to break into his Sony PlayStation 3 console and use it to run a third-party application. Sony then issued an update for the gaming console that shored up its hardware defenses.

"This angered all these tinkerers and all these people who’d been doing things with the PS3," said Moss. "Something that was previously fine and that they’d paid for was no longer fine. They felt totally abused by this corporate giant."

Hotz found a way get past Sony's hardware security yet again, and many in the hacker community hailed him as a hero. LulzSec’s battle against Sony, Moss suggested, may be related to Hotz's cause.

"It sounds like it’s a protest," Moss said. "I don't want to use the term 'hactivist' -- it seems like half of it is, they have these goals and these lofty ideals, and then the other half is, they want to pile it on, like vandals having fun."

Jeremiah Grossman, the chief technology officer at the firm WhiteHat Security, Inc., rejected the term "gray hat" as a classification for LulzSec. Yet, like Moss, he suggested that the Sony attacks may have been motivated by Hotz's lawsuit. (The suit was settled out of court earlier this year.)

"These are people who were not too pleased with Sony going after one of their own," he said.

Grossman defined a "gray hat" attack as one in which the hacker uses illegal means to harm a government or institution deemed unethical. In contrast, he said, "What they're going for is not politically-motivated or anything like that. I guess you'd call it revenge."

Regardless of how these attacks are classified, said Grossman, they underscore a point that cyber-security researchers are always trying to hammer home: as the Internet grows, companies are growing more and more vulnerable to attacks of all kinds and should take precautions that they might not have considered necessary in the past.

"Back in the old days," he said, "if you wanted to rob a bank you had to drive to it and take out the money. Now you can be anywhere in the world. When you're conducting legal actions against one person, like geohot, all the people who liked his work and enjoyed his cause can go after you directly, no matter where in the world they are."

"Sony made a good legal case against geohot," Grossman added. Yet because of hackers like LulzSec, he said, not to mention the massive attacks in April, "It might not have been the best choice for them to go after him the way they did."

FOLLOW HUFFPOST TECH

NEW YORK -- When a new hacking entity calling itself LulzSec claimed credit for a barrage of recent attacks on Sony and several other companies, many cyber-security experts found themselves grasping f...
NEW YORK -- When a new hacking entity calling itself LulzSec claimed credit for a barrage of recent attacks on Sony and several other companies, many cyber-security experts found themselves grasping f...
 
 
  • Comments
  • 201
  • Pending Comments
  • 0
  • View FAQ
Comments are closed for this entry
View All
Favorites
Recency  | 
Popularity
Page: 1 2 3  Next ›  Last »  (3 total)
photo
oneyippie
Leaning far to your left
02:24 PM on 06/12/2011
Power to the People, baby!
05:39 PM on 06/08/2011
Its called research people -> http://en.wikipedia.org/wiki/Grey_hat

The term Grey Hat was coined by a hacker group called L0pht in 1998.
04:07 PM on 06/08/2011
they're bored - it's not complicated. there's not like a hacker playground to hang out at and ride the seesaw. and i know what you're gonna say - why don't they use it for good and go work for corporate america or the government - and if you can't intuit my response i'm not sure what it'd mean to convince you otherwise.
12:03 PM on 06/08/2011
Businesses react in response to government intervention or market pressure. Business has convinced the world they don't need any oversight. The market is clueless; 99.99% of customers won't care about how a company deals with the security of their information until they are declaring bankruptcy because some identity theif racked up a mountain of debt under their name.

Businesses are gathering more and more of your personal information and they are doing less and less to protect it. These are the people you should be getting mad at.

If Lulzsec wasn't doing this eventually it would be actual cyberthieves and this would be a much bigger story.
photo
HUFFPOST SUPER USER
ResearchtheFacts
Alert, awake & paying attention to the details.
11:58 AM on 06/08/2011
They are anti-capitalism hackers. Already define in Europe as such. There main beef is capitalism.
photo
HUFFPOST SUPER USER
ResearchtheFacts
Alert, awake & paying attention to the details.
11:59 AM on 06/08/2011
edit: defined...
photo
HUFFPOST SUPER USER
Joe3245
Now thinking outside of THE BOX.
12:36 AM on 06/09/2011
Thats probably a large part of the community. The group is probably almost as diverse as anonymous, and likely largely inspired by anons and former anons.
11:50 AM on 06/08/2011
Has anyone brought up the EVE connection? LulzSec - NullSec Their behavior matches a pirate in EVE as well, robbing and pillaging, but offering a hearty "nice try" afterward.
This user has chosen to opt out of the Badges program
photo
09:12 AM on 06/08/2011
Their name says it all. They are doing it for laughs...what is so hard to understand about this?
photo
djnealb
Texan. Liberal. Nerd. Awesome.
11:39 AM on 06/08/2011
It doesn't make what they're doing any less illegal. Your argument is like me saying "I'm going to shoot you in the kneecap, but don't worry because it just for the lulz."
This user has chosen to opt out of the Badges program
photo
03:33 PM on 06/08/2011
I never said it made their actions legal, I said it wasn't hard to figure out WHY they were doing it...which is what the article is about...authorities trying to find the motivation behind the hacks...the name is LulzSec...

So if I shoot you in the kneecap, and the police try to find a MOTIVE, it would be for the lulz...not because I wanted to rob you...
07:16 AM on 06/08/2011
Brat hats... they can make action figures for them
photo
European1919
I am the Pigmâ’¶n
05:02 AM on 06/08/2011
You bet the American secret services and other US state-organised crime is already in on this game:
http://www.guardian.co.uk/technology/2011/jun/06/us-hackers-fbi-informer?INTCMP=SRCH
05:47 AM on 06/08/2011
if this is true than why isnt there one in my group. and why is there still thousands of others???
photo
European1919
I am the Pigmâ’¶n
05:52 AM on 06/08/2011
How do you know there isn't one in your group?

Ahh ... clever try, but not good enough ... YOU are the one in your group.
03:53 AM on 06/08/2011
They have an almost French arrogance - beret hackers? :-)
10:48 AM on 06/08/2011
As opposed to the standard "I'm a stupid American tourist, look at me" arrogance?
11:39 AM on 06/08/2011
Old and used up....Try again Duane
photo
flossophy
the unfamous anti-establishment classical liberal
12:50 AM on 06/08/2011
The ha.ckers need to start thinking more entrepreneurial instead of just being digital street hoodIums. For instance, I'd consider paying them to disrupt !ran's nukuIar facilities or China's n Russia's authoritarian regimes or perhaps even my traffic ticket records. I'm not sure why they choose to go after Nintendo or Playstation networks... there seems to be many more nefar!ous institutions out there that could use their intervention. Going after western corporations only empowers the illiberal regimes around the globe. The ha.ckers are remarkably shortsighted in this respect.
photo
flossophy
the unfamous anti-establishment classical liberal
01:06 AM on 06/08/2011
He.ck, why aren't they going after Saud! Arab!a's regime... or Syria's? 

I mean really... what a missed opportunity.
photo
HUFFPOST SUPER USER
Bill Cumming
Tech guy. Ubuntu user, Scottish ^_^
07:47 AM on 06/08/2011
Probably because Syria's internet connections are too erratic for any attack to be worth it. The Government has a tendency to simply cut the internet connection for the entire nation when it sees something iffy.. (either going in or out of the country)

Leaders in those types of countries tend to be the paranoid type so very little information is ever on machines connected to the internet so they Western government can't attack and steal information...
This user has chosen to opt out of the Badges program
photo
Eris23
Justice is in indefinite detention.
01:14 AM on 06/08/2011
You haven't been paying attention.
photo
flossophy
the unfamous anti-establishment classical liberal
02:17 AM on 06/08/2011
To what.
04:57 AM on 06/08/2011
To what?
11:29 PM on 06/07/2011
Pay the hackers to counter protect. These guys love money and toys.
This user has chosen to opt out of the Badges program
photo
Eris23
Justice is in indefinite detention.
12:30 AM on 06/08/2011
Money doesn't but everything.
photo
flossophy
the unfamous anti-establishment classical liberal
01:04 AM on 06/08/2011
Do they have more flossophical or ideological goals? 
12:37 PM on 06/08/2011
Only food, clothing, and shelter.
photo
HUFFPOST SUPER USER
Bill Cumming
Tech guy. Ubuntu user, Scottish ^_^
07:54 AM on 06/08/2011
But don't be surprised that the one you pay to protect are the ones that are attacking,
Or turn around and help...

Oddly enough Some hackers have ethics (strange I know!) and if they see a Government /Corporate state using propaganda of any sort they tend not to like that sort of thing and are more inclined to exploit flaws in the system to release the info...
11:24 PM on 06/07/2011
Hello Sony...Wake up! Just ppost a large reward for information as towho is behing the hacks and you will have your answer in about...I would say...10 minutes. No brainer but then, you'd need a brain to figure that out.
This user has chosen to opt out of the Badges program
photo
Eris23
Justice is in indefinite detention.
12:30 AM on 06/08/2011
Nope. If the crew is remotely disciplined, nobody knows who they are. Not even each other.
01:38 AM on 06/08/2011
Winner, winner, chicken dinner.
photo
HUFFPOST SUPER USER
5SpdSolara
All your base...
11:15 PM on 06/07/2011
"All your base are belong to LulzSec."
This user has chosen to opt out of the Badges program
photo
09:14 AM on 06/08/2011
All your database are belong to LulzSec

fixed
03:35 PM on 06/08/2011
OMG! The evil cassette and crossbones. We are the doom ed.
10:16 PM on 06/08/2011
Word! strong fan for the Zero wing reference! Fan #56!
photo
HUFFPOST SUPER USER
apathyman
Let them hate, so long as they fear
11:14 PM on 06/07/2011
What exactly gives Sony the right to tell a person how to use the product they bought? After it's paid for what he does with his own property is not Sony's business
photo
HUFFPOST SUPER USER
vibroluxor
11:41 PM on 06/07/2011
You know that legal agreement we all click yes to without reading? It'd be in there.
10:56 AM on 06/08/2011
are you aware that those don't completely hold up right? because it's not like you have a choice to enter those contracts or not. I mean, it's not like you have the right to negotiate those contracts.
11:47 AM on 06/08/2011
You know that little agreement is not a legal document right?
HUFFPOST SUPER USER
gorash
07:43 AM on 06/08/2011
You want people to start pirating games? Because this is what it's all about.
photo
HUFFPOST SUPER USER
apathyman
Let them hate, so long as they fear
01:17 AM on 06/10/2011
It's not about pirating games, I'll assume you've never modded your system or you'd know that. It's about a company tell a person what they can or can't do with their own property