Q&A

Why Johnny Long Hacks Stuff

The Christian hacker talks about how he wrote No Tech Hacking, why he thinks social engineering is easier than hacking software, and how hes trying to get the hacking community to do charity work

By Katherine Walsh

Page 2

CSO: What was the writing process like? Did you find that you learned new things as you went along?

Long: This was slow in coming. Many projects I work on are three to six months from beginning to end. The writing process for “No Tech” was very similar to that in duration, but the research, stories and photos behind it are years in the making. I got to the point where I saw so many things in public that I started carrying a camera with me all the time. I started pulling together years worth of pictures and war stories, and then came to the realization that it was practical stuff that a wide audience could understand. “No Tech” gets to the heart and soul of what we’re up against, not just for corporations trying to protect their data, but for individuals trying to protect their privacy.

CSO: Talk about your relationship with your work partner Vince, who you describe in the beginning pages of the book. What’s the most valuable lesson about no-tech hacking that you learned from him?

Long: Vince was instrumental. He was a mentor in many different ways. He didn’t just give me practical advice; he literally shifted my perspective to focus on things most people wouldn’t think about. In our working relationship, I was always considered the hacker because I broke into the systems and the networks, but Vince really personified what it is that makes hackers special. It’s that mentality of seeing life from a different perspective. Even though Vince isn’t highly technicalhe’s excellent with things like communications and physical securityhis skills plunge right into the heart of the technical world. He could find a way into a building and walk out with an arm-full of sensitive documents, a process would have taken us months from a purely technical angle. It was incredibly eye opening.

CSO: What is the most important aspect of no-tech hacking?

Long: It’s definitely awareness. No-tech hackers are definitely more aware than the standard person. They notice details; they’re very perceptive. It’s definitely something that can be learned, but it comes much easier if you have an instinct for it. The awareness associated with no-tech hacking goes along way for preventing it as well. If you’re walking into work and you notice there is a bag full of un-shredded paper sitting outside the dumpster, or you notice a door that is supposed to be locked and isn’tit’s noticing that and being willing to do something about it. There is a fine line. I don’t want to create a society of completely paranoid people. But at the same time, I have been able to walk around airports, past the security gates, taking pictures of people’s baggage or taking video footage of pilots pushing the combination into a door lock. In this day and age, in that environment, someone should be noticing. In my experience, right now, they are not.

Johnny Long

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors