I worked at a company that had hired Mitnick as a security consultant.
His report for a client that turned out to have been rife with SQL injection at the time was largely movie plot physical security stuff. Not wrong exactly, but not the center mass of the threat model they needed either.
He seemed to lack systems thinking, producing a report that focused on calling out specific employees as dumb or incompetent. Counterproductive at best. It seemed like his PR exceeded his utility by a great deal.
That trend continues beyond the grave, maybe.
Isn't he famous for social engineering/physical security type things? If you hire an expert in X, you are probably going to get X.
Isn't he famous for getting caught?
Getting caught didn't make him a superstar. Telling his techniques in books and public speeches did.
Yeah I agree, caveat emptor and all that. The blameful framing is bad work product though.
In all fairness, a genuine attacker WILL be abrasive and abusive. They WILL single out employees that are gullible and exploit them. It's not pretty because a genuine attack is not pretty. Of course a simulated attack will be indecent and discourteous in nature, that is how attacks are.
Not necessarily WILL. I've seen awesome attackers who were mostly checkbox spreadsheet clerks. Friendly, methodical, boring, expert.
[deleted][deleted]
Dude I was called out by name in the report either right before you got there or the first one you were there. I was called out in the one where they got B's Audi keys in his office.
Whole thing was so dumb. A floor full of smart monitors that they could have put a keylogger on. A plethora of physical network access and I get called out for leaving my laptop on the lock screen and going downstairs for food.
And they got found out because I ran little snitch I paid for myself and it caught their hijacked chrome making all sorts of weird network calls. But I don't remember being given credit for that.
(Sips mojito)
He mostly used social engineering. Not technical exploits. So that's how he succeeded. Call it crazy, but it worked.
Why hack a password when you can get the employee to just tell you.
Because the employee now knows who might have done it.
"He didn't breach us the way we wanted him to do it so it was dumb." Idk man, sounds like you locked your doors but left the windows open. That's the point of these things.
The point is really after working through remediations, there were pretty massive issues remaining that weren’t hard to find and were relatively vastly easier to exploit if the attacker is a Russian teen and not Bruce Lee. And the budget for such things was blown. Priorities, etc
"a client that turned out to have been rife with SQL injection" sounds more like they left the doors open, but the report focused on the lack of security bars on the windows.
[deleted]
Kevin's security company is also a mess, and the training videos they produce are embarrassing at best.
I understand he probably just lent his name to the company (though he did show up in some of the videos), but still...
This is what happens when the 90's PC community renamed crackers as hackers. Proper hackers would have been the ITS/WAIS ones doing crazy things with computers for its era.
I mean, the landscape changed quite a bit since early days of what Mitnick did as a blackhat. He did his best to adapt and make money, which given his prison term, isn't really that surprising.
He social engineered your company into contracting him, and that adds to the legend, but people don't see how many other companies he failed to social engineer.
The hero worship of him makes me physically ill, always has.
He did cost people their jobs though, so I guess he's a good person.
It's like we don't have any messiah's today that are mediocre professionals at best.
> "He was a hacker-turned-security consultant who, later in life, helped shape the modern white-hat."
They left out convicted criminal.
I have so many stories about his absolutely terrible behavior at conferences. He once refused to pay the entry fee to a charity event and had to be physically ejectedy.
Absolutely better at PR than any actual work, pay careful attention and none of his early stuff was particularly novel, from a technical perspective.
But for whatever reason, we venerate him just because he was victimized by the state. The world is not a dichotomy -- sometimes bad things happen to bad people.
He got all of the "Free Kevin" attention because of how long he was left in jail before trial and then being stuck in solitary confinement after sentencing for months.
If he had been treated fairly by the justice system he wouldn't have gotten nearly as much attention.
He was also autistic, a lot of the behavior can be explained through that lens.
>He got all of the "Free Kevin" attention because of how long he was left in jail before trial and then being stuck in solitary confinement after sentencing for months.
That was uncalled for on the part of DOJ.
>He was also autistic, a lot of the behavior can be explained through that lens.
I'm autistic. Maybe I should go commit a bunch of felonies to increase my chances of a good job and stature in the hacker community, since things like publishing code, publishing peer reviewed papers, and mentoring newbies have not been productive ways of finding gainful employment nor respect of my peers.
I have friends who did things like take a gap year to travel the world or met their spouses on nights I stayed in to study, and some evenings when browsing HN I feel very sad that I wasted my 20s on a society that does not care about me.
Anyways, sorry to wall of text, but what you said really struck a nerve with me -- there are hierarchies in any community, and one thing I've noticed with the hacker scene is one group of people can mess up over and over using the same sets of facts or diagnoses, but others can expect to have worse outcomes with better behavior for reasons that elude me to this day.
> I have friends who did things like take a gap year to travel the world or met their spouses on nights I stayed in to study, and some evenings when browsing HN I feel very sad that I wasted my 20s on a society that does not care about me.
I'm glad you have finally recognized the problem.
Stop living for your idea of others and start living for yourself.
Kevin was famous for being mistreated by the DoJ and writing some books which were perhaps not particularly true in hindsight. After he got out of jail and rejoined the community he lost a lot of respect for being himself, though it's not impossible that years of imprisonment and a long time in solitary had some permanent negative effects. In other words... you shouldn't envy Kevin's life.
For the rest: nothing's stopping you from having fun, regardless of age.
It's good that somewhere the quality of work is rewarded more than the quantity
You act like thats a bad thing given the nature of his crimes.
If more people strived to be like Mitnick today, the tech world would have a lot more power.
For what it's worth, I'm George Hotz, and Kevin Mitnick's books were a big influence on me. I ran into him at a party at DEFCON one year and we talked for 20 minutes before I found out who he was. Gave me a lock pick business card. Cool guy.
I did not realize Mitnick had passed away, very sad. I first learned about him as a kid through the book Takedown, and his exploits definitely fueled my early fascination with computers and hacking. It's heartwarming to see how he later befriended Shawn Nunley, though it's unfortunate that he and Shimomura apparently never buried the hatchet. He undoubtedly influenced an entire generation of hackers, RIP.
Ghost in the Wires is one of all time favorite reads, and I still hope to see it as a dramatized film. It would be a fun “period piece” taking the audience through the 80’s and early 90’s, with some hilarious social engineering scenes (kinda like Catch Me If You Can) and tense moments where the audience roots for Kevin. I really think a film adaptation would help introduce his story to a new generation and be a nice tribute to his legacy.
Except actually real whereas Frank Abagnale fabricated all of his supposed cons (read The Greatest Hoax).
I read the book by Tsutomu Shimomura, who caught Mitnick's hacking and tracked him down. It's a fascinating read. He was able to locate Mitnick in physical world based on his online activities and his cellular phone usage. In those early days, few people understood the cyber landscape and cellular technologies to exploit them.
Yes but AFAIUI Mitnick was upset Shimomura had the full weight of the police on his side, right? He used techniques that shouldn't have been available to him
Interesting fact about Shimomura, he was a student of Feynman's
I think he didn't know cellular well enough and thought a wireless phone was unlocatable because it was mobile and not tied down to a landline. As a physicist, Shimomura would have known all about radio and signal. He just used old WW2 tech of radio triangulation to find the location of the cell phone radio transmitter. It didn't help that cell phones were rare back then and the signal of his cell transmitter frequency was standing out like a sore thumb.
Regarding the full weight of the police, Shimomura did have an easier time to convince the ISP and phone companies to give him access to the logs. He was able to ask the cellular company to locate the cell tower where Mitnick's cell phone connected and traced him to the general area. If Mitnick had been careful, he could have hacked into the ISP/phone companies and erased all his access logs.
> He used techniques that shouldn't have been available to him
Why not? Sometimes it's not what you know, it's who you know.
... All's fair in love and war?
I'm old enough to remember all the "Free Kevin" gifs scattered around the internet.
This helps to fill in some of the details. It's a really nice story showing the humanity that can be found in situations when you look close.
At DEF CON and related events now, you commonly see stickers saying "PUT KEVIN BACK".
Well, he has passed so I don't know if that sticker is relevant anymore.
It's probably not, but still usefully signals particular mindsets to others who might share them.
ok
From what I can tell, defcon is largely law enforcement and companies that sell to them these days, so I'm not surprised at all to hear that.
I keep hearing that cynical, and wrong, dismissal but have zero idea where it comes from. Yes, there are cops. Some .govs even have booths in the info areas. The stated idea is that it's a good thing when cops and hackers can hang out and discuss ideas and opinions outside of interrogation rooms, and I agree with that.
That's miles away from "largely law enforcement" though. I talked to an FBI agent at PyCon but people aren't claiming it's a LEO convention.
Call me nostalgic or whatever, but my laptop to this very day...
>I'm old enough to remember all the "Free Kevin" gifs scattered around the internet.
A generation of hackers (specifically, the vBulletin generation) stayed as far away from the CFAA as possible after that fiasco, which I suspect is exactly the chilling effect that the DOJ intended.
Since we're talking about Kevin Mitnick on Hacker News, I have to mention:
I recently re-read "Cyberpunk: Outlaws and Hackers on the Computer Frontier". It was published in 1991 and the first third of the book provides an early contemporary account of Kevin Mitnick. It's a great book that I first read in my high school library in the 90s and it completely captured my imagination.
However, I had never connected the dots that the subject of the last third of the book was Robert Tappan Morris, creator of the Morris worm, who went on to cofound Y Combinator! Paul Graham is also quoted in the book.
The book has aged pretty great. They added an updated epilogue in 1995 in the early part of the Free Kevin era, but honestly re-listening to the book in 2025, I was wondering where the updated Y Combinator epilogue was!
I'm going to defend Kevin here because I see a lot of comments from people I am sure have no valid reason to be hating on him.
Kevin was particularly annoying because he never failed to penetrate a target. The reason that's annoying is it just takes one slip, one weak point, one inattentive admin and it's over. People will stay mad about that. I get it.
But those who say he had no talent are just ignorant.
His goal was to make the world safer, and making people pay attention to risk didn't make him a lot of friends. All the hate I am reading here is just sad.
If you hate Kevin and did not know Kevin, I feel bad for you. Hate is an expensive emotion, even when you're just being a keyboard warrior. It should be reserved for people who have really wronged you. Kevin is not with us anymore. The hate is hurting you, not him. And he has a son who will read this someday. Have a heart.
This story is itself evidence that Kevin had good parts to him. This 911 GTS is not some shit joke prize.
Yeah, I am shocked a little, because he wasn't a monster or something. Critique is valid, but speaking with obvious resentment and disrespect about someone who died is pretty gross. Again, unless they're, like, a _monster_.
Shawn and I worked together at Novell back when this was going down. It was fascinating at the time and more so in hindsight. FWIW, Shawn's a really good guy.
In case folk don't connect the dots, this appears to be Shawn Nunley from the article.
I would petition all other community members to appreciate the gravity of the parent's comment.
Speaking for myself as someone very early in my journey during the time when Mitnick was still active as a grey hat: he advanced our thinking about security and the nature of trust itself in ways that have never been more timely.
Paradoxically he profited personally far more as a white hat than he ever did in the grey area, his motivations were clearly not extractive. The authorities compelled him to go do lucrative things! (after persecuting him mercilessly).
RIP Kevin. We are ill equipped for the vulns of the AI, but without you we'd be helpless.
I'm old enough to remember Kevin as both hero and villain. People are complex, Kevin seemed to be no exception. His exploits - and the ones of those who caught him - were fascinating to follow in realtime.
But be honest...
How sweet is that 911?
>But those who say he had no talent are just ignorant.
I don't think anyone says he had no talent, what rubs people the wrong way is that the thing he had talent for is the same thing that the people have who try to scam call your grandmother out of her pension money. You can be the world's greatest burglar, you're still a burglar. The whole cringy "social engineering" thing turned media persona and consulting business is to engineering what chiropractics is to medicine.
He leaned pretty heavily into monetizing his own image and for a lot of people what he did became synonymous with the word 'hacking' in a not particularly positive way and critising that isn't hate.
That's just nonsense. First of all, social engineering was a small part of his work, and it's OK that you don't know that. But your totally blatant ignorance of what his career covered is exactly what I'm talking about.
Look, I know that people form their opinions in a bubble. All I am saying here is you should expand your bubble. You know nothing about Kev. Again, that's OK, but it also means you should try to understand what you're hating.
You'd try to make money on your image if you could, I'm betting. Especially if you had been put in prison and left there with no bail hearing, and put in solitary confinement for 'hoarding tuna' in your cell. For 9 months. While your father died. This was not a normal treatment of any person in custody.
Kev was a good person. Full stop. Just as curious as all of us in that era.
His (or other peoples) treatment in the US prison system is another matter and often cruel, but no he didn't conduct himself like a good person in regards to his 'hacking'. He committed wire fraud, he impersonated people, he exfiltrated sensitive credit card information from thousands of people.
That's not just curious, that's not something we all did when we were young, those were legitimate crimes and they still are for good reason. He had a big part in popularizing the image that a hacker, rather than someone who writes software for the public good, is someone who tricks other people and steals personal data.
And no I wouldn't be proud if I ran phishing scams and stole IP from random companies, I wouldn't monetize that, I'd say I'm sorry which from reading his books at least I don't think he ever was.
[deleted]
I heard he can launch nukes by whistling into a pay phone.
Maybe I'm mistaken, but that sounds more like Chuck Norris.
Wait ... no fists involved. My mistake.
Nukes launch Chuck Norris at their enemies.
With Chuck Norris, the nukes whistle at him, just to keep on his good side.
It's in his (Mitnick's) autobiography Ghost in the Wires. In his telling of the story they put him in a more restrictive environment exactly because of the reason given (launching nukes by whistling into a phone)
At least Kevin wasn't a sanctimonious hateful bible thumping religious fanatic homophobic bigot like Chuck Norris.
Wow. Get help.
When I think back to when I was 10 and every boy I knew idolized Norris and I instinctively hated his guts I feel better about myself.
[deleted]
Hah, he social engineered the God of social engineering...
good god how did he get a car into prison?
I also have Kevin Mitnick's business card and it is one of my most prized possessions. A great inspiration and influence on my life.
Too bad he wasn't colorblind.
I don’t need to know an iota of his activities as a hacker to hate him. I hate him because of how many times I had to be put through mind numbing security training with his mug as the opener. “I’m Kevin Mitnick” and KnowBe4 are seared into my brain at a ptsd level for terminal boredom.
> He put himself on the proverbial map in 1979 by dialing into a software company’s server and copying its forthcoming operating system release in its entirety. Imagine convincing a Microsoft server to cough over an early copy of Windows 12 using little more than a phone number.
Windows 12 was in development back in 1979? I think that timeline is a bit off.
I worked at a company that had hired Mitnick as a security consultant.
His report for a client that turned out to have been rife with SQL injection at the time was largely movie plot physical security stuff. Not wrong exactly, but not the center mass of the threat model they needed either.
He seemed to lack systems thinking, producing a report that focused on calling out specific employees as dumb or incompetent. Counterproductive at best. It seemed like his PR exceeded his utility by a great deal.
That trend continues beyond the grave, maybe.
Isn't he famous for social engineering/physical security type things? If you hire an expert in X, you are probably going to get X.
Isn't he famous for getting caught?
Getting caught didn't make him a superstar. Telling his techniques in books and public speeches did.
Yeah I agree, caveat emptor and all that. The blameful framing is bad work product though.
In all fairness, a genuine attacker WILL be abrasive and abusive. They WILL single out employees that are gullible and exploit them. It's not pretty because a genuine attack is not pretty. Of course a simulated attack will be indecent and discourteous in nature, that is how attacks are.
Not necessarily WILL. I've seen awesome attackers who were mostly checkbox spreadsheet clerks. Friendly, methodical, boring, expert.
Dude I was called out by name in the report either right before you got there or the first one you were there. I was called out in the one where they got B's Audi keys in his office.
Whole thing was so dumb. A floor full of smart monitors that they could have put a keylogger on. A plethora of physical network access and I get called out for leaving my laptop on the lock screen and going downstairs for food.
And they got found out because I ran little snitch I paid for myself and it caught their hijacked chrome making all sorts of weird network calls. But I don't remember being given credit for that.
(Sips mojito)
He mostly used social engineering. Not technical exploits. So that's how he succeeded. Call it crazy, but it worked.
Why hack a password when you can get the employee to just tell you.
Because the employee now knows who might have done it.
"He didn't breach us the way we wanted him to do it so it was dumb." Idk man, sounds like you locked your doors but left the windows open. That's the point of these things.
The point is really after working through remediations, there were pretty massive issues remaining that weren’t hard to find and were relatively vastly easier to exploit if the attacker is a Russian teen and not Bruce Lee. And the budget for such things was blown. Priorities, etc
"a client that turned out to have been rife with SQL injection" sounds more like they left the doors open, but the report focused on the lack of security bars on the windows.
Kevin's security company is also a mess, and the training videos they produce are embarrassing at best.
I understand he probably just lent his name to the company (though he did show up in some of the videos), but still...
This is what happens when the 90's PC community renamed crackers as hackers. Proper hackers would have been the ITS/WAIS ones doing crazy things with computers for its era.
I mean, the landscape changed quite a bit since early days of what Mitnick did as a blackhat. He did his best to adapt and make money, which given his prison term, isn't really that surprising.
He social engineered your company into contracting him, and that adds to the legend, but people don't see how many other companies he failed to social engineer.
The hero worship of him makes me physically ill, always has.
He did cost people their jobs though, so I guess he's a good person.
It's like we don't have any messiah's today that are mediocre professionals at best.
> "He was a hacker-turned-security consultant who, later in life, helped shape the modern white-hat."
They left out convicted criminal.
I have so many stories about his absolutely terrible behavior at conferences. He once refused to pay the entry fee to a charity event and had to be physically ejectedy.
Absolutely better at PR than any actual work, pay careful attention and none of his early stuff was particularly novel, from a technical perspective.
But for whatever reason, we venerate him just because he was victimized by the state. The world is not a dichotomy -- sometimes bad things happen to bad people.
He got all of the "Free Kevin" attention because of how long he was left in jail before trial and then being stuck in solitary confinement after sentencing for months.
If he had been treated fairly by the justice system he wouldn't have gotten nearly as much attention.
He was also autistic, a lot of the behavior can be explained through that lens.
>He got all of the "Free Kevin" attention because of how long he was left in jail before trial and then being stuck in solitary confinement after sentencing for months.
That was uncalled for on the part of DOJ.
>He was also autistic, a lot of the behavior can be explained through that lens.
I'm autistic. Maybe I should go commit a bunch of felonies to increase my chances of a good job and stature in the hacker community, since things like publishing code, publishing peer reviewed papers, and mentoring newbies have not been productive ways of finding gainful employment nor respect of my peers.
I have friends who did things like take a gap year to travel the world or met their spouses on nights I stayed in to study, and some evenings when browsing HN I feel very sad that I wasted my 20s on a society that does not care about me.
Anyways, sorry to wall of text, but what you said really struck a nerve with me -- there are hierarchies in any community, and one thing I've noticed with the hacker scene is one group of people can mess up over and over using the same sets of facts or diagnoses, but others can expect to have worse outcomes with better behavior for reasons that elude me to this day.
> I have friends who did things like take a gap year to travel the world or met their spouses on nights I stayed in to study, and some evenings when browsing HN I feel very sad that I wasted my 20s on a society that does not care about me.
I'm glad you have finally recognized the problem.
Stop living for your idea of others and start living for yourself.
Kevin was famous for being mistreated by the DoJ and writing some books which were perhaps not particularly true in hindsight. After he got out of jail and rejoined the community he lost a lot of respect for being himself, though it's not impossible that years of imprisonment and a long time in solitary had some permanent negative effects. In other words... you shouldn't envy Kevin's life.
For the rest: nothing's stopping you from having fun, regardless of age.
It's good that somewhere the quality of work is rewarded more than the quantity
You act like thats a bad thing given the nature of his crimes.
If more people strived to be like Mitnick today, the tech world would have a lot more power.
For what it's worth, I'm George Hotz, and Kevin Mitnick's books were a big influence on me. I ran into him at a party at DEFCON one year and we talked for 20 minutes before I found out who he was. Gave me a lock pick business card. Cool guy.
I did not realize Mitnick had passed away, very sad. I first learned about him as a kid through the book Takedown, and his exploits definitely fueled my early fascination with computers and hacking. It's heartwarming to see how he later befriended Shawn Nunley, though it's unfortunate that he and Shimomura apparently never buried the hatchet. He undoubtedly influenced an entire generation of hackers, RIP.
Ghost in the Wires is one of all time favorite reads, and I still hope to see it as a dramatized film. It would be a fun “period piece” taking the audience through the 80’s and early 90’s, with some hilarious social engineering scenes (kinda like Catch Me If You Can) and tense moments where the audience roots for Kevin. I really think a film adaptation would help introduce his story to a new generation and be a nice tribute to his legacy.
Except actually real whereas Frank Abagnale fabricated all of his supposed cons (read The Greatest Hoax).
I read the book by Tsutomu Shimomura, who caught Mitnick's hacking and tracked him down. It's a fascinating read. He was able to locate Mitnick in physical world based on his online activities and his cellular phone usage. In those early days, few people understood the cyber landscape and cellular technologies to exploit them.
Yes but AFAIUI Mitnick was upset Shimomura had the full weight of the police on his side, right? He used techniques that shouldn't have been available to him
Interesting fact about Shimomura, he was a student of Feynman's
I think he didn't know cellular well enough and thought a wireless phone was unlocatable because it was mobile and not tied down to a landline. As a physicist, Shimomura would have known all about radio and signal. He just used old WW2 tech of radio triangulation to find the location of the cell phone radio transmitter. It didn't help that cell phones were rare back then and the signal of his cell transmitter frequency was standing out like a sore thumb.
Regarding the full weight of the police, Shimomura did have an easier time to convince the ISP and phone companies to give him access to the logs. He was able to ask the cellular company to locate the cell tower where Mitnick's cell phone connected and traced him to the general area. If Mitnick had been careful, he could have hacked into the ISP/phone companies and erased all his access logs.
> He used techniques that shouldn't have been available to him
Why not? Sometimes it's not what you know, it's who you know.
... All's fair in love and war?
I'm old enough to remember all the "Free Kevin" gifs scattered around the internet.
This helps to fill in some of the details. It's a really nice story showing the humanity that can be found in situations when you look close.
At DEF CON and related events now, you commonly see stickers saying "PUT KEVIN BACK".
Well, he has passed so I don't know if that sticker is relevant anymore.
It's probably not, but still usefully signals particular mindsets to others who might share them.
ok
From what I can tell, defcon is largely law enforcement and companies that sell to them these days, so I'm not surprised at all to hear that.
I keep hearing that cynical, and wrong, dismissal but have zero idea where it comes from. Yes, there are cops. Some .govs even have booths in the info areas. The stated idea is that it's a good thing when cops and hackers can hang out and discuss ideas and opinions outside of interrogation rooms, and I agree with that.
That's miles away from "largely law enforcement" though. I talked to an FBI agent at PyCon but people aren't claiming it's a LEO convention.
Call me nostalgic or whatever, but my laptop to this very day...
https://fogbeam.com/free-kevin.jpg
>I'm old enough to remember all the "Free Kevin" gifs scattered around the internet.
A generation of hackers (specifically, the vBulletin generation) stayed as far away from the CFAA as possible after that fiasco, which I suspect is exactly the chilling effect that the DOJ intended.
Since we're talking about Kevin Mitnick on Hacker News, I have to mention:
I recently re-read "Cyberpunk: Outlaws and Hackers on the Computer Frontier". It was published in 1991 and the first third of the book provides an early contemporary account of Kevin Mitnick. It's a great book that I first read in my high school library in the 90s and it completely captured my imagination.
However, I had never connected the dots that the subject of the last third of the book was Robert Tappan Morris, creator of the Morris worm, who went on to cofound Y Combinator! Paul Graham is also quoted in the book.
The book has aged pretty great. They added an updated epilogue in 1995 in the early part of the Free Kevin era, but honestly re-listening to the book in 2025, I was wondering where the updated Y Combinator epilogue was!
His famous metal lock-pick business card - https://imgur.com/a/caareoI
I'm going to defend Kevin here because I see a lot of comments from people I am sure have no valid reason to be hating on him.
Kevin was particularly annoying because he never failed to penetrate a target. The reason that's annoying is it just takes one slip, one weak point, one inattentive admin and it's over. People will stay mad about that. I get it.
But those who say he had no talent are just ignorant.
His goal was to make the world safer, and making people pay attention to risk didn't make him a lot of friends. All the hate I am reading here is just sad.
If you hate Kevin and did not know Kevin, I feel bad for you. Hate is an expensive emotion, even when you're just being a keyboard warrior. It should be reserved for people who have really wronged you. Kevin is not with us anymore. The hate is hurting you, not him. And he has a son who will read this someday. Have a heart.
This story is itself evidence that Kevin had good parts to him. This 911 GTS is not some shit joke prize.
Yeah, I am shocked a little, because he wasn't a monster or something. Critique is valid, but speaking with obvious resentment and disrespect about someone who died is pretty gross. Again, unless they're, like, a _monster_.
Shawn and I worked together at Novell back when this was going down. It was fascinating at the time and more so in hindsight. FWIW, Shawn's a really good guy.
In case folk don't connect the dots, this appears to be Shawn Nunley from the article.
I would petition all other community members to appreciate the gravity of the parent's comment.
Speaking for myself as someone very early in my journey during the time when Mitnick was still active as a grey hat: he advanced our thinking about security and the nature of trust itself in ways that have never been more timely.
Paradoxically he profited personally far more as a white hat than he ever did in the grey area, his motivations were clearly not extractive. The authorities compelled him to go do lucrative things! (after persecuting him mercilessly).
RIP Kevin. We are ill equipped for the vulns of the AI, but without you we'd be helpless.
I'm old enough to remember Kevin as both hero and villain. People are complex, Kevin seemed to be no exception. His exploits - and the ones of those who caught him - were fascinating to follow in realtime.
But be honest...
How sweet is that 911?
>But those who say he had no talent are just ignorant.
I don't think anyone says he had no talent, what rubs people the wrong way is that the thing he had talent for is the same thing that the people have who try to scam call your grandmother out of her pension money. You can be the world's greatest burglar, you're still a burglar. The whole cringy "social engineering" thing turned media persona and consulting business is to engineering what chiropractics is to medicine.
He leaned pretty heavily into monetizing his own image and for a lot of people what he did became synonymous with the word 'hacking' in a not particularly positive way and critising that isn't hate.
That's just nonsense. First of all, social engineering was a small part of his work, and it's OK that you don't know that. But your totally blatant ignorance of what his career covered is exactly what I'm talking about.
Look, I know that people form their opinions in a bubble. All I am saying here is you should expand your bubble. You know nothing about Kev. Again, that's OK, but it also means you should try to understand what you're hating.
You'd try to make money on your image if you could, I'm betting. Especially if you had been put in prison and left there with no bail hearing, and put in solitary confinement for 'hoarding tuna' in your cell. For 9 months. While your father died. This was not a normal treatment of any person in custody.
Kev was a good person. Full stop. Just as curious as all of us in that era.
His (or other peoples) treatment in the US prison system is another matter and often cruel, but no he didn't conduct himself like a good person in regards to his 'hacking'. He committed wire fraud, he impersonated people, he exfiltrated sensitive credit card information from thousands of people.
That's not just curious, that's not something we all did when we were young, those were legitimate crimes and they still are for good reason. He had a big part in popularizing the image that a hacker, rather than someone who writes software for the public good, is someone who tricks other people and steals personal data.
And no I wouldn't be proud if I ran phishing scams and stole IP from random companies, I wouldn't monetize that, I'd say I'm sorry which from reading his books at least I don't think he ever was.
I heard he can launch nukes by whistling into a pay phone.
Maybe I'm mistaken, but that sounds more like Chuck Norris.
Wait ... no fists involved. My mistake.
Nukes launch Chuck Norris at their enemies.
With Chuck Norris, the nukes whistle at him, just to keep on his good side.
It's in his (Mitnick's) autobiography Ghost in the Wires. In his telling of the story they put him in a more restrictive environment exactly because of the reason given (launching nukes by whistling into a phone)
At least Kevin wasn't a sanctimonious hateful bible thumping religious fanatic homophobic bigot like Chuck Norris.
Wow. Get help.
When I think back to when I was 10 and every boy I knew idolized Norris and I instinctively hated his guts I feel better about myself.
Hah, he social engineered the God of social engineering...
good god how did he get a car into prison?
I also have Kevin Mitnick's business card and it is one of my most prized possessions. A great inspiration and influence on my life.
Too bad he wasn't colorblind.
I don’t need to know an iota of his activities as a hacker to hate him. I hate him because of how many times I had to be put through mind numbing security training with his mug as the opener. “I’m Kevin Mitnick” and KnowBe4 are seared into my brain at a ptsd level for terminal boredom.
> He put himself on the proverbial map in 1979 by dialing into a software company’s server and copying its forthcoming operating system release in its entirety. Imagine convincing a Microsoft server to cough over an early copy of Windows 12 using little more than a phone number.
Windows 12 was in development back in 1979? I think that timeline is a bit off.