HomeSecurityIn the depths of "cyberwar"

In the sanctuaries of "cyberwar"

hacking2Who are today's hackers and what are the threats on the internet?

Competition has been a natural attraction for humans since the beginning of time. And the challenges surrounding the perfection of a creation make many who are passionate about similar activities want to test its endurance.

Report: Niki Papazoglou

At the same time, they compete with the capabilities of the manufacturer of a machine, a fabric, a painting, and in recent decades, a computer system. The latest attempt at competition, that of the computer system, is called "hacking".

From ransoms to decrypt files to the theft of bank account passwords, cyberattacks are increasingly a concern for businesses, internet users, the media and cybercrime prosecution..

A recent Greek example is that of the 27-year-old and 31-year-old who were arrested a short time ago for stealing Facebook user passwords. Another, on a global scale, was the announcement by Ebay through which it urged users to change passwords, since the security of the system had been breached. Neither of the two cases "cost a lot", but both terrified public opinion, regarding security in the age of broadband.

Teenagers passing the time, professionals ensuring the integrity of a system, or instruments of coordinated digital activism in response to state initiatives, who are hackers after all, and how different is the alarmism that accompanies them from the reality of cybersecurity?

The black hats and white hats of the hacker

Among the many things that have been written, the "cinematic" view wants hackers to wear hats, depending on their purposes, to meet anonymously in hackforums, IRC channels and newsgroups from where they organize their attacks. They are divided into blackhats and whitehats, without missing from the "internet scene" the power of balance, whose exponents move in the space of the gray hat (greyhat). The hat represents the purpose of the attack, benevolent or malicious attacks for one's own benefit, without of course missing the undecided who, moving in the intermediate space, operate on a case-by-case basis. And as in every war, so too in this one there are ranks, which some admit and others do not, which want white to side with good and black to bear, as usual, the seal of evil..
The aforementioned meeting places are easy to locate. However, in order to become a member of such a community, one must, according to the ritual, “prove one’s worth,” as George, the head of electronic systems for a large company, informs us. Once one has been rated, one can be used in attacks. Like every secret community, this one has its own ritual, after which, depending on the points you have received, you are used where the superiors estimate that you can help. “The leader is always the one who has the most qualifications. The one who has proven to have done the most hacking, that is, breaking the security software that every digital system carries,” says George.

"Blackhats" are those who carry out an attack for personal gain, for example, those who extract credit card details and at the same time money from their owners, malicious hackers.

On the other hand, "whitehats" aim for the joy of conquest, they do not carry out attacks with selfish purposes, they do not aim for money. Those of them who are also inclined to activism, form groups like "Anonymous" and the whole action from hacking turns into hactivism.

hacking5
The time of the attack

As for the time of the attack, George says: "The truth is that it looks like a war. While you are being attacked to take down your page, you are being hit by targeted computers from all over the world. Imagine having a tunnel that can accommodate a certain number of cars and suddenly more and more enter. Well, no matter how much you try to secure the entrances and normalize the flow, it is expected that at some point the tunnel will become blocked." After all, according to George, when a war begins, anything can happen. Especially in a world characterized by the phrase "what comes up, stays up" - in a free translation.

And somewhere here the cinematic version ends, which includes truths colored accordingly, of course, for the pleasure of the film-loving audience.

In the eyes of the average user, hacking can be defined as the ultimate war, a show of force or an easy way to get rich, but that's not exactly the case. Although Alexandros, an information systems security officer, identifies security gaps in companies' electronic systems by "hacking" them, few would call him a hacker.

"My company is approached by businesses to test the security of their networks, with penetration tests. Essentially, when someone comes to us, we try, within 15 days, to break the security of their system. By doing so, we identify the gaps that make them vulnerable to unpaid attacks, and by communicating the results to them, we provide the solution for a more secure network." These professional hackers, although they exist in Greece, are not used as much as abroad.

"Hacking, as a misunderstood concept, has been associated with something punishable. However, for me and many other employees it remains a job. Essentially it denotes someone who knows something very well. If I need to find the weakness of a system, I will have to hack into a code to identify its vulnerability. Essentially, I am committing a punishable act but with the approval of the website owner," adds Alexandros.

In general, in other European countries and in America, securing networks is a primary concern for a company. In our country's small market, however, businesses do not have the room for such services or the risk posed by a potential attack is not assessed as high enough to proceed with such a procedure. "If the cost of the service we offer exceeds what an attack on their website will cost someone, then they are definitely not concerned with the security of their network.".

Tackling hacking in Greece and other countries

In Greece, of course, as Alexandros informs us, there is no coordinating body responsible for informing users about the identified risks, except for the Cybercrime Prosecution, which deals only with criminal acts. In America, Cert informs the public about the risks of the Internet, about security, about the investigations carried out in the field of security, and even about some of the attacks that are organized, but not about all of them. At the international cybersecurity conference, Black Hat, which is organized every year in Las Vegas, the last time experts questioned whether companies should be required to publicize the attacks they receive, given that many shortcomings in protection mechanisms are observed.

hacking8
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS