Meet the hackers

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

SPECIAL REPORT
Meet the Hackers
Meet the hackers
Patrick Gray, ZDNet Australia
Raven Alder: Girl power
The first woman to deliver a technical presentation at the famed DefCon hacker conference, talks about "gender wars" in the hacking realm.

Name: Raven Alder
Handle(s): Raven
Age: 28
Place of birth: Mississippi, USA
Marital status: Single
Current residence: Maryland, USA
Job: Security consultant, True North Solutions
First computer: Home-built 8088 machine in 1988
Best known for: Tracing spoofed distributed denial of service attacks
Area(s) of expertise: ISP backbone networking, protocol decoding and design, Linux/BSD security, and cryptography

What's the difference between male and female hackers?

If you ask Raven Alder, she might let out a string of expletives because gender is a non-issue.

Alder was the first woman to deliver a technical presentation at the famed DefCon hacker conference in Las Vegas. But don't harp on it. If there's one thing she hates, it's being type-cast as a "chick hacker".

"If I never read another 'she's going to save the Internet' article or have a reporter wanting me to pose by the pool at DefCon with a life preserver, it will be too soon.

"One popular magazine's 'do you think girl hackers should date boy hackers?' left a bad taste in my mouth, too. Nobody asks the guys this stuff, and finding myself a 'boy hacker' is not really tops on my list of things to do this weekend," Alder said.

Born into a fairly well-to-do family, it was clear that Alder was a brainiac from a young age.

"I skipped three grades and was taking college classes at 12, graduated high school at fourteen and college at eighteen," she said. "My parents very much encouraged my sister, brother and me to be academic achievers."

Alder has the markings of an uber geek, but her lifestyle is far from sedentary.

"Mom put all three of us through martial arts [Shorin Ryu Matsumura discipline] for at least a year. She wanted us to be able to defend ourselves. After that, it was our decision whether or not to continue," she explained. "My kid sister quit and did gymnastics instead, making it almost all the way to being an Olympic-class gymnast before quitting to become the captain of her high school cheerleading squad ... [but] I continued."

Alder first dabbled with computers in 1985, fiddling with her school's Apple II, but didn't get serious until after graduate school.

"I went to Virginia Tech in an entirely unrelated discipline, but you can't attend that school without becoming at least basically technically competent," she explains.

Despite becoming quite involved with geekish pursuits, Alder says her social life hasn't suffered at all.

"If anything, it's made it more to my tastes. I like geeks," she confessed. "I'm far more likely to enjoy the company of the folks I see at dc-securitygeeks meetings than I am of the people I'd see at my neighbourhood bar. I've met a variety of fascinating people through hacking, and some of them are now close friends."

Alder hasn't taken a holiday "that didn't involve computer security" for around five years. "Most of my vacations are something like, 'Oh, I'll go to Ottawa Linux Symposium, that will be fun!'," she said.

While her parents have been supportive, Alder's father is sometimes rattled by the idea of his child hanging around with "hacker types". When she called to tell him she'd be presenting at a computer security conference "he went to brag to his security officer friends". But the thrill didn't last too long.

"DEFCON? Do you know what that is? It's full of HACKERS!" her father said.

It took her 30 minutes to deliver the "hackers-are-not-bad" speech.

But it's not all smiles and sunshine in the security business for Alder -- she once found a serious vulnerability in a "very popular security product".

"I wrote up some proof of concept exploit code, and took it to my boss," she explained. The makers of the product didn't really seem to care about the issue nor want to fix it.

"I carefully explained the importance of the problem, and the possible ramifications of exploiting it. People are trusting this product with their security data, and if the product itself is [insecure], it's un-trustable and you can't have faith in the veracity of that data," she said. Still, the vendor was unmoved, claiming no one would ever find the glitch.

Alder was by this point annoyed. She had found the problem, so others could too. But the vendor simply refused to fix the problem.

"Now, if I had been doing this as an independent researcher, I would have posted [it] to Full Disclosure (a security mailing list) at that point. However, since I was working for a company, disclosure was in their hands and not mine, and they chose not to say anything. So the vulnerable product is still out there.

"I was explicitly told that I would be sued to the tune of several million dollars if I ever violated my NDA [non-disclosure agreement] and revealed the vulnerability. This is why closed source security is bad. Lesson learnt ... any vulnerability research I do from here on out is my own, and I will be answerable to nobody but myself for disclosure," she said.

It could be this experience which has dimmed her view of the industry as a whole. There are good people in the security space, she says, but there are also some bad eggs.

"The root problem that the security industry has is ... unscrupulous people selling to an uninformed market. The managers buying security products don't understand security at all, and so they trust the vendors to tell them what is best," Alder argued. "And somehow, conveniently, what is best has a great overlap with whatever that particular vendor happens to be selling."

However, it's not just the vendors who are to blame. To a certain extent, Alder said, end-users engage in an "ignorance is bliss" management philosophy.

"Many companies just want to be able to throw money at a product and feel secure. They're uninterested in understanding security or changing their habits and environment.

Unfortunately, that's not the way that a successful security program works. People who understand security are necessary, and in chronically short supply," she said.

"[Companies] have the latest and greatest firewall that nobody has ever bothered to configure, or a very expensive intrusion detection system (IDS) that nobody has the understanding to tune."

Alder monitors the nessus.org IDS. Nessus is an open-source vulnerability scanner, so one might expect some sophisticated attacks against that domain but this is not always the case.

"Sadly, most of the attacks that people threw at it were pretty stupid -- 'Oooh, I downloaded Nessus! Hey, I'll run Nessus against Nessus!'. I did see some exploit attempts that were fairly similar to the successful attacks against Debian and Gentoo at about the same time, though, so that was neat. And they didn't get in!," she recalled.

It seems Alder genuinely enjoys her work, and gets some thrills through some unlikely pursuits. "Hiking, rock climbing, camping. I'm also an avid reader -- I have a taste for science fiction and fantasy, but I'm also fond of archaeology, linguistics, history, particle physics, and biology," she said.

In her spare time, she downs chai while arguing philosophy with friends.

To aspiring hackers, Alder has this piece of advice: "Learn TCP/IP or the internals of your operating system of choice. Ideally, learn both. Don't just be a script-kiddie who downloads an attack program off the Internet and think that's cool.

"Understanding what you're doing is more cool. Having the know-how to develop a new and innovative attack or to develop a creative defence is a lot more impressive than 'dude, I sniffed your Hotmail password'."

ZDNet Australia's Patrick Gray reported from Sydney. For more coverage from ZDNet Australia, click here.

Raven Alder: Girl power Brian 'Jericho' Martin
Adrian Lamo: The baby-faced cracker Kevin Mitnick: The mal-ware master
Peiter Mudge Zatko: Renaissance man?

Adrenalin pumping through their veins as lines of code are crunched to perfection. Well, that's how it is in the movies anyway. As usual the reality is slightly different: Welcome to the real world of hackers.
ZDNet UK's Australian cousins have tracked down some of the world's most prominent (and notorious) hackers. In this five-part series, we delve into the lives of five prominent hackers and give you a unique chance to know your enemy. Forwarned is forarmed.
Raven Alder: Hacking is a feminist issue
Brian 'Jericho' Martin: From architect to demolition man
The Attrition.org co-founder, who dropped out of college during his second year at architecture school, shares his silliest hacks.
Adrian Lamo: The baby-faced cracker
For the so-called "homeless hacker", there was no turning back after discovering how to make both sides of a 5.25in floppy disk writable at the tender age of eight.
Kevin Mitnick: The mal-ware master
The man who claims to have been treated like "Osama bin Mitnick" shares his experience of being behind bars.
Peiter Mudge Zatko: Renaissance man?
The individual better known simply as Mudge, talks about the origins of L0pht Crack -- a password cracker for Windows-based systems which he wrote to "prove a point and not for commercial purposes."
Related News
Security breaches drive customers away
Net crimes should be recorded, says MP
MPs start review of Computer Misuse Act
MPs ponder whether 'benign' hacking should be legal
UK firms failing security challenge
Related Insight
Does publishing virus source codes help security?
Preventing hack attacks: The must-reads
What can you learn from a hacker site?
Cyberterror: Clear and present danger or phantom menace?
Steering Microsoft clear of hackers

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Jack Strain

Just gimme a map to the fridge. :D

19 minutes ago by Jack Strain via Facebook on Indoor navigation coming to a mobile near you soon
dede0202

Hello ALL USERS OF THE PIRATE BAY I WOULD PUT AN EXPLANATION ON PIRACY Story Idea ILLIGALE AND SHARING THOSE THAT NET Dissent NOT WELL BUT TO CA...

9 hours ago by dede0202 on The Pirate Bay infringes copyright, High Court decides
Sungwoo

do You know that? it can install 4G Ram. So i buy 4g and install It work! I can run call of duty 4,6,7 [Modern war... 1,2,3] Call of duty 1 was...

10 hours ago by Sungwoo on Loose Ends - Upgrading the Aspire One 522
itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

15 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

19 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

21 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

1 day ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

1 day ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

1 day ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

2 days ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

2 days ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

2 days ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

2 days ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

2 days ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

2 days ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

2 days ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

3 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

3 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

3 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

3 days ago by Moley on Windows 8 start-up speed forces USB boot workaround