91av

Access granted

To most computer users, hackers are worse than second-hand-car salesmen. Virus-infected e-mails are their stock in trade and that's when they're not trying to bring down Microsoft, stock markets and the Pentagon. But according to Oxblood Ru

To most computer users, hackers are worse than second-hand-car salesmen. Virus-infected e-mails are their stock in trade and that’s when they’re not trying to bring down Microsoft, stock markets and the Pentagon. But according to Oxblood Ruffin, such a caricature is just plain wrong. Ruffin is “foreign minister” of the Cult of the Dead Cow, one of the oldest hacker groups. He says most hackers work within the law and use their skills to help governments and businesses defend computer systems from real criminals and faulty software. So why did Ruffin’s group release “Back Orifice”, a free software tool that allows people to access anyone’s Windows operating system remotely? Duncan Graham-Rowe was curious…

Why do you call yourself Oxblood Ruffin?

The few strongest influences I have in my life are Brit culture and black culture. Oxblood is sort of a nod to ox-blood shoes, which to me has always been a very British thing. And Ruffin is the surname of one of my favourite singers, David Ruffin. It ends up sounding very Dickensian though.

How old are you?

Old enough to appreciate Shirley MacLaine; young enough to like Natalie Portman.

What do you do for a living?

I work for a distributive software development firm. I tend to be involved with recruitment and corporate strategy. I bring in companies to do computer security for us.

You’ve got a background in hacking yet you get other companies in to do your security? Why don’t you do it yourself?

I’m not one of the sharper knives in the drawer when it comes to hacking and the Cult of the Dead Cow (CDC).

Do your employers know of this alter ego of yours?

Actually I was hired because I was in the CDC. My boss is very enlightened. Everybody round here grew up with the CDC and nobody could quite believe there was somebody in Toronto who was part of it.

You don’t hide it in any way then?

Not at work.

What do you tell people at dinner parties?

Only my friends know. I’m totally proud of it, though. If I were gay, I’d be totally out of the closet. The thing is we’re not doing anything illegal. Probably none of us has hacked into the NASA supercomputer since they were 13.

But as teenagers you did that?

Yeah, but there was nothing malicious about that. It was like playing catch. It was a challenge. Can you get in? What’s there? Okay, now I’ll try to leave without getting caught. It’s not like, “Oh, I want to go in and erase the archives.”

Is it standard for large corporations to hire ex-hackers for their security needs? Is there an industry of poachers-turned-gamekeepers?

No, it’s not like that at all. I’m in an exceptional position. My boss is a very enlightened person and understands how these things work. But most people rely on stereotypes. Being a hacker, it’s as if you’re branded as a liar. You’re always suspect. Once you’re identified as a hacker, it’s very difficult to shake that image in a corporate environment.

Still, doesn’t that create some sort of conflict of interest when people like you get hired in the computer security industry?

I think it would create a conflict of interest if I were actually doing that kind of thing. But even then the people we hire only hack into our own machines. It’s much easier when you’re working in a controlled environment. For most people “hacker” equals “criminal”, whereas in the hacker community where I come from it means something different. The term itself is considered a very honourable one. It’s maybe something that people outside of the geek community don’t quite understand. As far as we’re concerned the people they are talking about aren’t hackers, they are “crackers”.

Don’t criminal hackers-crackers-and other hackers spring from the same fountain?

I don’t like the whole criminal side of things. I know obviously that it goes on and that there are all these idiots who write malicious worms and very destructive programs. They’re criminals and have zero respect in the crowd I mix in. There’s nothing but ridicule and contempt, and this is a very commonly-held opinion. We’re divided on quite a few issues but there’s absolute agreement that malicious programmers are absolute morons and they deserve anything they get.

How was the Cult of the Dead Cow formed, and what does it do?

It originally started in 1984 as a group using early networked computers long before the Web. You published whatever you wanted, pushing the free speech envelope. The name actually came from the two guys who started this, Grandmaster Ratte’ and Franken Gibe. They were 14-year-old kids hanging out in Texas at this abandoned abattoir, one of these big ruined buildings where kids smoke cigarettes, talk about girls and create mayhem and bust Coke bottles. Grandmaster is now a hip-hop music producer living in Harlem. And Franken ended up going to Harvard. The people in the CDC are tremendously diverse in their backgrounds. Some are security consultants, graphic designers, another is a lawyer. There’s even a professional soccer player.

You talk about the work the CDC does as never being malicious, but with the kind of knowledge you have as a group, where do you draw the line?

I think that it sort of comes with experience and time, that younger knives really don’t have the same kind of balance maybe, and are a little more ambanxious to do all kinds of things. I don’t know anybody in the CDC that I wouldn’t trust.

How did you get to join the CDC?

When I was recruited I was kind of stalked. I didn’t know anybody else in the CDC. They found out about me when I was having an online correspondence with one of them for a while. So they checked me out I suppose. Unknown to me, I was sort of being recruited and considered for membership of the CDC. If anybody ever asks to become a member they’re immediately taken off the list. They figure, if you need to be a member, you’re not cool enough.

Typically, from a kind of lay-person’s perspective, a hacker’s profile would be of some antisocial teenager with too much time on their hands. Is that accurate?

It’s a very common and in some ways quite inappropriate stereotype. Often it is a very, very smart kid, working alone or with a small pack of friends. But they tend to be less antisocial these days. Ten or 15 years ago geeks were more outsiders than anything. Now it’s incredibly cool if you’re a hacker.

What happens when a hacker grows up?

Some of them go into parliament. Seriously though I think that kids have a lot of time when they’re younger and they can spend time fooling around with video games and computers. Later on these same people are probably going to work in technology-simply because they spend so much time on computers.

If the division is one of age, are there “two cultures” within “hacktivism”?

There’s hacktivism and there’s activism. Activists use computer technology primarily as a communications tool, organising online sit-ins, like organising a street protest online, sending out newsletters, advertising things for web sites. Hackers are looking much more directly at programs and technology.

To most people, there’s people in the know, like yourself, and people who haven’t the faintest idea how you’d even begin to go about doing something like breaking into NASA computers. How is it done?

Well, generally speaking, you would have to have a high level understanding of how networks operate and then you would have a high level understanding of programming and vulnerability of computer systems. There are all kinds of back doors you can use to get in, depending on what the administrators of computer networks leave open. A lot of hacking, or network intrusion, is just bad management of the network. It’s like having a house and forgetting to go around and lock the back door and close the windows and make sure that the windows going into the basement are shut. Back door is a common term.

So what could one do then?

It depends where you get in. You could “own” the computer, meaning that you would get group privileges, in which one person-usually the administrator-has higher levels of access to a computer network than other users. Alternatively you could work your way up the security chain. Or you could take over a system. Usually what a lot of people want to do is just get in there and leave by a back door so that they can get in and out whenever they want. What others want is a stepping stone to another computer, so that they can hack into one system without revealing their tracks. You can do anything, is the short answer.

What about damage?

You can crash a network. You can erase the contents of a network. You can use it as a launching pad to attack other computers or e-mail systems. A very common technique is to look for passwords.

So what’s the worst thing you ever did?

I’ll tell you the thing that made me feel the most uncomfortable. I once impersonated a priest to make three long-distance calls. I’ve done far worse things, but that’s what I feel the worst about.

What about hacking?

I think I’d like to take a pass on that one.

CDC is best known for Back Orifice. This is a program available on the Web that allows anyone to gain entry to any Windows operating system remotely. Isn’t that putting a loaded gun in people’s hands?

Oh, yeah. But when used legitimately it’s one of the best network administration tools for Windows. It is very robust. It has very strong encryption. I know all kinds of system administrators who threw out all of their tools and they just rely on this now. It’s a very elegant program that’s very powerful. You can organise the network any which way you please.

But it can also be used to remotely take hold of another computer.

Yes, that’s what a network administrator would do. For example, if someone wanted to install a new program on your computer without interrupting your work during business hours.

Wasn’t Back Orifice originally developed to highlight potential security flaws in Windows?

Exactly, but also to publicise the issue of Trojans, which before simply wasn’t a word in common speech. A Trojan is essentially an application or a feature that’s running on a computer without somebody’s knowledge, like the “I love you” virus.

Okay, but despite the advantages couldn’t Back Orifice still be used for malicious purposes?

Yeah, if someone was trying to make malicious use of Back Orifice, someone could go in there and remove files, hard drives and literally do anything. Most often it would be sent to somebody as an attachment like the recent “I love you” virus. It’s the same kind of thing. You get an e-mail attachment and that’s most often how it’s deployed. When they click, it opens a small program that seamlessly ferrets into the computer and lies down at the bottom, unnoticed.

Okay. Given what Back Orifice is capable of doing, shouldn’t CDC bear some of the responsibility?

It’s sort of a double-edged sword. I think the upside of it is that hardware and software engineers are really going to be forced to develop better applications. The application will not do anything the machine does not allow it to do and this is really one of the problems we wished to highlight. Microsoft took a machine that was never designed to be a network machine and put it online. It’s like putting a sledge on the motorway.

What’s the future of hacking? Will it become more prolific? As you say, it’s become a lot trendier, sexier.

I think that you’re going to see a lot more of it. It’s become very easy to hack because there is this proliferation of “scriptkiddies”. They’ve no idea what they’re doing. They download programs or scripts and hack by pointing and clicking. We usually call it Windows hacking. It just doesn’t take the same kind of skill as it used to. I mean, before you actually had to hack. You had to be considered a bit of a genius to do anything. Now it’s just like any moron can run a script, and the next thing you know they’re taking down the Pentagon.

More from 91av

Explore the latest news, articles and features