In Depth

LOpht in Transition

Most of the '90s hacking group the L0pht - Mudge, Space Rogue, Weld Pond and others - have emerged in legitimate roles. Was their work ultimately boon or bane for security?

By Michael Fitzgerald

April 17, 2007CSO

Brian Oblivion. Kingpin. Mudge. Space Rogue. Stefan von Neumann. Tan. Weld Pond. That’s how the hacker group called the L0pht appeared before the Senate Subcommittee on Government Cybersecurity on May 19, 1998. They said, among other things, that they could take down the Internet in 30 minutes. The senators listened closely and afterward praised them effusively.

It was a landmark moment for hackers, shunned, derided and loathed by the technology industry. And it was a landmark for the L0pht too. Though the group was already known for its vulnerability disclosures, for the Hacker News Network, for tools like the hash cracking tool L0phtCrack, now “everybody [in the hacking community] wanted to be the L0pht,” remembers Jeff Moss, founder of the Black Hat and Defcon security conferences.

Not bad for a group that got its start when someone’s wife said it was time to get his computers out of the bathtub.

The L0pht shaped the way disclosures are handled and helped force vendors like Microsoft to change the way they address software security flaws. There’s no question, either, that by raising the visibility of security problems, the group spurred companies to begin paying more attention to security. “You knew you’d better rattle your own doorknobs before the hackers did,” says John Pescatore, a longtime information security analyst at Gartner.

Some think, though, that visibility has hurt software security. “They were the Led Zeppelin of gray hat hacking,” says Marcus Ranum, who is credited with creating the first commercial firewall product and is now CSO at Tenable Network Security. “By releasing gray hat tools and techniques they were able to get a tremendous amount of attention. And they opened the floodgates for all the bottom feeders that followed them.”

Ironically, it was Ranum himself who helped give the L0pht credibility. As CEO of NFR, which made software to find intruders on corporate networks, Ranum used the L0pht’s vulnerability research to strengthen his product, and hired the L0pht both to do a code review and to write modules for his product, giving the group a legitimate corporate client to tout. He says he considers the L0pht members his friends and says they are “great guys.” But he thinks those who have followed them find vulnerabilities almost as a way to blackmail corporations. He blames the L0pht, saying, “They have changed the industry for the worse.”

Nothing in the L0pht’s emergence from Boston’s bulletin board community in 1992 suggested it would achieve any more notoriety than other hacker collectives of the day. Brian Oblivion, a hacker with strong interests in radio communications, founded the group. Oblivion declined to be interviewed for this article, saying via Space Rogue that he was too busy. Chris Wysopal, who joined the L0pht in late 1992 as Weld Pond (a handle chosen by pointing at random at a map of the Boston area, because the bulletin board The Works forbade members to use real names), says that Oblivion “had so many computers in the bathroom that his wife couldn’t use it anymore.” She gave the group space in the South End artist’s loft where she made hats. And for several years, the L0pht was just a place for Oblivion and his friends to hang out after work and store their growing collection of computing equipment.

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WHITE PAPER
Maximizing Site Visitor Trust Using Extended Validation SSL

VeriSignNow with Extended Validation (EV) SSL available from VeriSign, you can show your customers that they can trust your site. Learn about EV SSL benefits in the free VeriSign white paper.

» Read the Paper

Featured Sponsors
Sponsored Links

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Managing SSL Security in Multi-Server Environments

CA's IT Security centralizes your identity management to turn security into a proactive, business-building tool

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

When Customer Relationship is Everything, Businesses Bank on SSL Solutions

Maximizing Site Visitor Trust Using Extended Validation SSL

Solving Online Credit Fraud Using Device Reputation

Understanding Data Location is Imperative for Data Loss Prevention

Secure your virtual and physical environments with the same software

Manage your IT more effectively

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

The Case for Business Software Assurance ~ Securing Your Applications

Efficient - Flexible - Compliant

Digital Identity Protection and Data Security Get Personal

Simplify your data center with Juniper Networks. View the webcast

The Latest Advancements in SSL Technology

How to Offer the Strongest SSL Encryption

Forrester Total Economic Impact (TEI) report: Save Millions in Fraud Losses.

Get in Compliance With Government Data Regulations

Taking the Botnet Threat Seriously

Any company can promise identity protection. Only Debix can prove it

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage

5 Steps to Secure Outsourced Application Development