L0pht hacker group returns from the dead

Symantec didn't crush us.

The news report begins with shots of a tense space shuttle launch. Engineers hunch over computer banks and techno music pounds in the background. There is a countdown, a lift-off, and then you see a young man in a black T-shirt and sunglasses, apparently reporting from space.

This is the Hacker News Network, and after a decade offline it is lifting off again, this time with a quirky brand of video reports about security.

Hacker News Network is one of the side projects of the Boston-based hacker collective known as L0pht Heavy Industries. They're the guys who famously told the US Congress that they could take down the Internet in about 30 minutes, and who helped invent the way that security bugs are reported to computer companies.

The L0pht's eight members were hacker gods back in the '90s, but most of them have faded from the limelight, even as they've watched a cottage industry of security research firms sprout up based on many of the disclosure techniques they pioneered.

The L0pht disbanded after it sold out to consultancy @stake in 2000, and its members gradually watched their dream of being paid to do cutting-edge hacking and security research wither and die.

But over the past few months, the L0pht has been getting back together, kind of.

Six of the eight members reunited last year at a Boston security conference, and in May 2009, members of the group released the first update to their L0phtCrack password audit tool since 2005. They say it took a few years of negotiations with Symantec - which bought @stake in 2004 - to get back control of L0phtCrack and several other L0pht properties.

Last month the L0pht website went back online, and the demo version of Hacker News Network is set for an official launch on Jan. 11, 2010. (Chosen because the date 01-11-10 works as a binary number.)

The L0pht website will give members a single place to link to their current projects. Peiter Zatko, aka Mudge, says he'd like to use it as an archive of the group's historic security advisories.

More projects may evolve. The group acquired the rights to its AntiSniff network monitoring tool from Symantec and is toying with the idea of reviving that as well.

"We're still trying to figure out what the ultimate goals are," said Joe Grand, aka Kingpin. "But I'm just happy that we can be in touch on a personal level and not have to deal with business, not have to deal with politics, and just have a place to do stuff."

Business and company politics pretty much killed the L0pht, according to some members. The core members sold their business to @stake in the hopes that with a deep-pocketed corporate sponsor, they would be free to do hacking projects that really interested them, such as drawing attention to important security problems that were being ignored by software vendors.

But in the end, corporate pressures trumped idealism. Within six months, Space Rogue, the only member who remains anonymous, was fired from his job in the company's PR department ("I didn't fit in at all; they were a bunch of clueless idiots," Space Rogue remembers), and gradually other members drifted away, often in disillusionment.

"We went there to become researchers," said Christien Rioux, aka DilDog. "Unfortunately the research part didn't generate enough money to fund the consulting part."

"It stopped being fun," said Joe Grand, who said he left after being pressured to do consulting work instead of the research he loved. Today Grand runs his own electronics design company, Grand Idea Studio.

Some members stopped talking to each other, angry with the way things had gone. The only L0phter with Symantec today is Paul Nash (aka Silicosis).

But bad feelings between the members have softened with time. Though many of them live in different cities now, they still get together whenever they can, at conferences or when they happen to be passing through the same city.

"I don't think we could ever recapture the magic of what the L0pht was," said Space Rogue, who is now an IT staffer in Massachusetts. "But I think we're at the point now where we can rekindle the friendship."

"It's L0pht again, but different," he said.


What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Related Security news

Hacker attacks on US military jump sharply in 2009

China source of most attacks, says report

Microsoft denies building security 'backdoor' in Windows 7

Privacy organisations shouldn't read too much into NSA involvement it says

Pentagon expands exclusive deal with McAfee

Department of Defense uses McAfee products

Police arrest pair over global banking web scam

Man and woman arrested in Manchester for using notorious Zeus Trojan



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Service-oriented security

SOA has become an integral part of enterprise software by providing a framework to efficiently develop software as services that is easily sharable, reusable, and integrated. No where is the need more apparent than in the Identity Management space. Welcome to the age of Service-Oriented Security (SOS).

Download Whitepaper

Data protection prospective vendor checklist

Organisations need a way to map business needs against all these challenges in procuring a technical solution. To help, SANS has developed the following Prospective Vendor Checklist.

Download Whitepaper

Unlock the power of the mainframe

This whitepaper presents the notion of CICS as an integration hub based on a component-based, service-oriented architecture supporting Web services. Highlights will review the challenges and contrasted support for Web services natively in CICS.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
BMC

Ride the express lane in the journey to speed ITIL adoption

Explore the challenges in making the journey to ITIL and the criteria for selecting consulting services
By following ITIL practices, your IT organisation will become more closely integrated with the business. We recommend making the journey to ITIL in a sequence of six incremental steps, the phases of which are driven through execution of a strategic transformational roadmap.

Download white paper

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *