About Expert


Key Topics
Consider a recent (2014, 2015 or 2016) security breach popular in the media. Analyze in the context of what you have learned thus far in this course.
The major security breached in 2015
In 2015, Ashley Madison encountered a security breach. A bad MD5 has been implemented in which the data of 37 million customers was compromised, and millions of passwords of the accounts of customers were made vulnerable. It is still unclear that how the security was breached by the hackers or the attackers. The attack was discovered by the company when the ‘Impact Team’ (the name of the hackers) pushed the screen of the computers of the employees on login. It is a major security breach of 2015 because it caused huge damage. The hackers posted the customers personal information who were seeking the extra marital affair. This caused embarrassment and two people committed suicides.
As per the viewpoint of hackers, they consider their acts as illegal, but they do not see themselves as criminals. They assume that they will never be caught and if caught, they can handle the situation as they do not commit any criminal activity. Most of them do not hack because they have an intention of destroying things, but they want to learn in minute details that how they can use things in various manners. In this process, they tend to breach the security of some systems. So, in this way they justify their acts. They see themselves as very intellectual people because they have a drive of continuous learning and they are innovative too. They feel that they what they are capable of doing is very different from most of the people on this planet. When they hack one system, it becomes simple for them to hack the others and their level of confidence as well as the motivation level rises. So, they make this as their practice. Majorly, this is the way they think and act and hence hack.
The 6 dumb ideas in computer securities are: default permit which is obvious that it has the potential to breach the security; enumerating badness because there are there are dozens or hundreds of pieces of malware, worm tests, exploits, or viral code for the legitimate businesses, applications, etc.; penetrating and patch, hacking is cool, educating users and action are better than inaction. We know knowledge is expanding in all areas so why people will not try to hack the system and show their potential to the world that nothing is impossible. If criminals can have such a nice thought to be stubborn and show their credential why cannot our engineers to be stubborn too for making such a powerful software which is not easy to be hacked but next to impossible to be hacked? Also in every organization people should keep a tight security by putting the password on important websites and also limiting the use of important documents to only fewer responsible people. In this way, we can somewhat help each other to be not venerable to be the hack.
Barber, R., 2001. Hacking Techniques: The tools that hackers use, and how they are evolving to become more sophisticated. Computer Fraud & Security, 2001(3), pp.9-12.
Pfleeger, C.P., 2007. Dumb Ideas in Computer Security.