Three tips for a better Anonymous

Security experts offer advice for how the hacker group can grow up

Has the Anonymous movement reached a midlife crisis?

There's no question that the loosely confederated collective has gained members and attention over the past year, for computer attacks on PayPal, Sony, and government contractor HB Gary Federal, and for the erratic cyber-rampage carried out by its sister group, LulzSec. But maybe the group needs to grow up a bit in order to get its message across.

At the Defcon hacking conference in Las Vegas Saturday, cyber experts had some tips for building a better Anonymous.

1. Look out for your new members.

Following a December, 2010, denial of service attack on the PayPal website, the company handed the U.S. Federal Bureau of Investigation about 1,000 IP addresses linked to the attack. Those people may have thought they were downloading software -- Anonymous uses a program called the LOIC, (Low Orbit Ion Cannon) in its attacks -- and joining a movement, not committing a federal crime.

"Anonymous has this idea moving forward that anyone can join us and take up arms, but they're not educating the people who are using these tools," said Jericho, the pseudonymous security expert who founded Attrition.org, a Web site that compiles information on the computer security industry. "Anonymous needs to educate their people as much as the public on their goals."

According to Gregg Housh, an Anonymous spokesman, he was overwhelmed with emails during the December attacks from neophytes looking to join in. "The emails were all, 'I don't know what you guys are doing, but I'd like to help'," he said Saturday. "I was getting anywhere from 100 to 150 of those an hour for a week-and-a-half period." He couldn't respond to the emails, he said, because that would have meant participating in criminal activity.

Housh noted that there is an IRC (Internet relay chat) room channel called "New Blood" where Anonymous members will help.

2. Vet what you release.

Anonymous exposed HB Gary Federal's proposed disinformation campaigns against organizations such as Wikileaks, but the disgraced security firm is far from the only company involved in such operations, according to Krypt3ia, anonther pseudonymous security blogger. "It's been going on for a very long time in the private sector," he said. "It's nothing new. It's just somebody got... caught."

That means that there's a pretty good chance that Anonymous could be the target of such a campaign. There's nothing to stop any hacker from leaving a file with Anonymous's tagline, "We are legion" on a hacked computer to direct blame toward the group.

"How do you know that you're getting the real dirt? How do you know you're not getting disinformation?" Krypt3ia said.

3. Look out for collateral damage.

When LulzSec published thousands of usernames and passwords two months ago, it didn't take long for some innocent bystanders to get hurt. People had their Web mail accounts compromised and fraudulent Amazon orders placed from their accounts. Anonymous says it wants to take on hypocritical corporations and corrupt governments. Exposing the personal information of regular people doesn't help that cause.

Anonymous brought the HB Gary emails to light, but historically the best information has come from insiders such as Watergate's Deep Throat (FBI agent Mark Felt) and a member of the military, Bradley Manning, who supplied documents to Wikileaks -- not hackers, Krypt3ia said. "The real dirt has only come from insiders."

Jericho and Krypt3ia were speaking at a Defcon discussion that was supposed to include the former Federal CEO of HB Gary, Aaron Barr, but legal threats from Barr's former employer kept him offstage, hidden somewhere in the audience. HB Gary has tried to distance itself from Barr, but moving to prevent him from speaking about this experience is probably not going to sit well with the hackers who support Anonymous, said Joshua Corman, a security researcher who was also on the panel.

HB Gary "just put a big target on themselves," he said.

Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

Tags cybercrimeAnonymouslegalHB Gary Federal

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Robert McMillan

IDG News Service
Show Comments

Father’s Day Gift Guide

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?