Comment Bring 8+ laptops (Score 1) 384
Comment hacker behavior (Score 1) 37
The article lists a number of actions that the hacker shall not do. Most are to be expected, such as not modifying the system, not bringing it down, not exposing private information. The first and last points in the list are strange though:
- Not using social engineering to gain access
- Not using brute forcing to gain access
Eh? Why are these not valid attack vectors?
Hacking Nuclear Command and Control 256
Secrets of Schizophrenia and Depression "Unlocked" 334
NASA Wants to Take the Blast Out of Sonic Booms 187
Crashing an In-Flight Entertainment System 322
Dead Musicians Signing Media Rights Petitions 357
The Case for OpenID 229
Why Upper Management Doesn't "Get" IT Security 126
How Many Windows? 327
Throwable Game Controllers 92
Comment Teach (Score 1) 737
I'm sure most of the crackers (script kiddies) don't have the faintest idea of the consequences of their actions. To them, the remote system is just another system, another command processor that they can control.
Also, the idea that what they're doing is illegal doesn't sink in; it's only recognised superficially.
I'd say, find alternative sentences that shows the consequences of breaking in. Four weeks of miscellaneous chores in a backup tape factory, reinstalling systems that were broken in to, or something.
Also, make sure beforehand that everyone knows that cracking a system means downtime, a lot of work to reinstall, and consequential damages. All that, even if nothing was broken, because the sysadmin has to reinstall anyway just to be safe.
That being said, I think some responsible cracking should be permissible under some strict conditions (don't break anything, report the security hole, inform the victim), maybe to prove that there actually is a hole. My ISP (XS4ALL) have some rules (Dutch, sorry) on this.