Welcome | Sign In
ECommerceTimes.com
Tech Buzz

Alien-Hunting UK Hacker Coming to America

Print Version
E-Mail Article
Reprints
Alien-Hunting UK Hacker Coming to America

A UK hacker of modest abilities who allegedly broke into secure U.S. government computer systems in search of UFO conspiracy-theory evidence has lost his fight against extradition. The British House of Lords was unmoved by Gary McKinnon's argument that he would be subject to U.S. terrorist sentencing guidelines, but McKinnon still has one avenue of appeal: the European Court of Human Rights.


The British House of Lords has decided to extradite Gary McKinnon, a British citizen who hacked his way into several U.S. military, defense and NASA computers, to the United States to stand trial. McKinnon has been fighting extradition since the discovery in 2002 that he was the one who broke into the U.S. government's most sensitive networks -- reportedly from a friend's aunt's house -- between 2001 and 2002. He allegedly caused US$900,000 in damages to computers located in 14 states.

What is remarkable about McKinnon's case is that he managed this feat with little high-level hacker expertise -- and that his quest was not for military secrets or sensitive design plans, but for secret documents that would reveal the existence of alien life. In interviews with news media, McKinnon claims his search was successful, uncovering photographs of alien spacecraft and the names and ranks of "non-terrestrial officers."

Terrorist Charges

The U.S. government does not place much weight on McKinnon's odd motives. McKinnon reportedly left a note on an Army computer criticizing U.S. foreign policy as government-sponsored terrorism.

In the indictment against him, the U.S. government accuses McKinnon of handicapping it in the aftermath of September 11.

"The entire network of 300 computers at NWS Earle, located in Colts Neck, N.J., was effectively shut down for an entire week. ... [F]or another three weeks afterward, military personnel and government civilian employees at NWSE were only able to send and receive internal e-mail. It was only approximately a month after McKinnon's last intrusion into the network that NWS Earle was able to automatically route Naval message traffic and access the Internet," according to the indictment.

In fighting extradition, McKinnon maintained that a trial in the U.S. could subject him to terrorist sentencing guidelines. With the House of Lords rejecting that argument, he has just one other option: appealing to the European Court of Human Rights.

Patchy Security

That McKinnon was able to access secure government information using basic hacking software is not all that remarkable, said Matt Shanahan, SVP of marketing and strategy for AdmitOne Security.

"In most cases, when people hack into a system -- the vast majority of the time -- they are able to get in because reasonable controls were not in place," he told TechNewsWorld. "In the case of McKinnon, there were a number of devices the systems administrator had not set."

A highly fragmented systems administration environment, together with the fact that a lot of controls are manual, usually results in some vulnerability, Shanahan said.

"People usually forget to set something, or they are using a virtual machine that might not have been set up correctly and then copies the same mistake 100 times," he explained. "McKinnon was able to find, and then take advantage of, these vulnerabilities."

The answer is reducing fragmentation as much as possible, Shanahan suggested, and automating the process instead of relying on individuals to make necessary adjustments.

No doubt, a red-faced U.S. administration has patched the vulnerabilities that McKinnon was able to exploit.

Still Vulnerable

What is worrisome is that high-level professional hackers still have ways to access these systems if they want to, said Bill Johnson, CEO of TDI.

"We have become a big proponent of securing the computer baseboard manager controller, or BMC," he told TechNewsWorld.

The BMC is network-accessible once a hacker can get past the firewall, and it allows command and control of the main motherboard, he said.

"Even systems in NASA would be vulnerable to this method of attack," noted Johnson.


Print Version E-Mail Article Reprints More by Erika Morphy


More by Erika Morphy

Will the iPad Bookshelves Be Sparsely Stocked?
March 12, 2010
Whether the iPad will enjoy success anything like that of the iPod or the iPhone is the topic of a fair amount of speculation as launch date draws nearer. That may depend on what users really want to do with the device and how much content is available for them to do it. Read e-books? Use iPhone-type apps? Play games? All of the above? One thing that seems certain is that it will be less than iPhone fans are used to.
FTC May Put Kibosh on Google's AdMob Deal
March 11, 2010
Despite the fact that the mobile advertising market is still young and fragmented, U.S. regulators apparently are concerned that Google's proposed acquisition of AdMob could give it an unfair competitive advantage. The FTC reportedly is seeking input from the search giant's competitors and advertisors, and its probe could turn into a long and drawn-out process that might ultimately kill the deal.
Valve Opens Pipeline for Mac Gaming
March 09, 2010
Mac owners who are gamers tend to play on a console rather than on their computers, largely because offerings for the Mac have been few and far between. Online game distributor Valve intends to change that with the release of Steamworks for the Mac. "It will create a market for games for the Mac, where there wasn't a significant one before," said Parks Associates analyst Pietro Macchiarella.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network