Security Dojo

Where information should stop

agosto 3rd, 2010 por Enrique Alfonso Sanchez Montellano

I often stay away from political and economical sources, why? well due to my job and research I believe I should not be involved in any of them, is my job not to be bias against nobody that could potentially be my client, so I just shut up, even with close relatives, friends and relationships.

As the release of trapper was getting closer I started thinking what good would the complete release of the software will do, and I came up with this answers:
- Nothing, nobody would use it
- Some people would use it for kicks, mostly to hack their own networks or hack work
- It could be used to crack something large and big
- Other people would use it on their audits, call me I’m finished and keep on using my research and work.
- Man in black would seize my server (since it’s on the US) and force the app to be erased after magically appearing with a copy of it.

While the last one appears definitely far fetched the third one got me thinking seriously, not only because of the nature of my research has gone definitely into Hydras and AI / Neural Networks / Expert Systems but because potentially sooner or later it could be pushed into the light and someone will do something that would compromise the years I’ve work on the security field.

I’m not calling that a reporter, as the ones I know they have been always fair to me in developing at story, but today as I unleashed the third rewrite of trapper (yes I had to rewrite 2 times already due to redesign of the objects) someone at the starbucks checked their email via pop, in less than 5 minutes all his email was parsed, loged into facebook, found, friends found, had his avatar picture and was searching who he was talking to in MSN. At that second I realized I stupidly left the domain into * and not localhost, definitely my mistake but … it suddenly hit me, am I making stuff secure or insecure releasing this?

The answer was “You are making stuff completely insecure, people won’t understand what is going on, it will be just pure blood and your point across will be lost” so my decision is to open trapper only to a few people without hard modules and keep it for Yaguarete as part of the internal tools, not because I don’t want to, believe me with the design I made a proficient coder will have no trouble to create it’s own little hydra, but it won’t me mine, it won’t be code breaking hard into stuff I seriously do not want to even ping.

YES I’ve become soft, YES I’m not the guy who used to rampage like 10 years ago in G-Con, but then again who would be? are you really a sane person holding into something that happened or said 10 years ago? is your life THAT pathetic?

I’ve seen people come from total “n00bs” into amazing hackers, like HKM I remember him messaging me saying he got hist first overflow after reading a paper then all the sudden he is destroying 2Wire with amazing research, people evolve, everything evolves, why wouldn’t I just evolve?

As I was reading the leaks that might break spies and complete networks of the CIA on Afganistan because of a leak I said “well sure government did stuff they shouldn’t have done? most probably but then again should documents leak THAT harshly?” I’m not condemning or applauding the act I just wondered “what if code I wrote ever is used for that?”

You might not have met me in my “worst” years, when I tough I was invincible, when nobody was smarter than me, more connected than me, etc. but I realize that those years I did more damage than help, I turn around and I smile when people tell me they look up to me and they have shaped cons in the sense of G-Con or stuff like that (I have to say that having someone name his kid after you felt great, thank you Pedro Navarro -byteStriker-)

Anyway I’m still alive, am I the same? no, is my research the same? probably is it still agressive? As much as I need to, because at the end, my research is only for me now, I don’t want any more fame, I don’t want the spotlight anymore, I’ve had my 15 minutes of fame, I want to do what I like, what I want and just be happy (breaking stuff sure why not)

Will trapper ever be public? to be honest it might, just not right now I’d like to keep the advantage before other companies use it and call my company inferior, anyway it will have a mixed license so too bad for ppl that will use it for commercial.

If you are interested in a copy of it, contact me and we can chat but I don’t promise anything.

Tags:   · · · 3 Comentarios

Dejar un comentario

3 respuestas hasta ahora ↓

  • 1 Pedro Navarro *byteStriker ago 3, 2010 at 10:32 pm

    You so fucking great and i’m so proud that my little son to have the same name of my master: You. Thanks for all nahual, you ever be invencible, you ever be the master.
    My dear little boy has a mission, to be a great man, just like you.

  • 2 Isaac Aldana ago 11, 2010 at 10:46 am

    Que tal Nahual, estuve en tu presentacion del CP Mexico, muy fregona, la verdad esperemos que ese nuevo programa en ruby lo puedas distribuir, independientemente si es para cosas malas es una buena aportacion al mundo.
    Cuidate y yo si te iba a disparar la chela pero te fuiste saludos!!

  • 3 Nathan_Chud nov 22, 2010 at 3:29 pm

    Trapper needs to be release it 0oo0 , la vida moderna de un nahual xD !!! enjoy California … by the way nice fucking Car xD