Unfortunately it came to a sudden end after I got a little too cocky and persistently took and re-took control of a smallish US telecom companies network, and the RCMP came knocking on my door for the FBI. That was largely unrelated to Warez but the advice given to me was that I should probably stop that as well. Thankfully I was too young to be charged with any of it at that time.
I do regret the massive headaches I must have caused the system administrators at the telecom company. Sorry guys. I have repaid my bad karma many times.
If those RCMP folks came knocking on your door around January 22nd 1999. Hi there. Long time. It was fun chasing you, but I didn't enjoy the rm -rf.
It was definitely a game but I wasn't trying to cause any damage. No doubt I caused more than a few headaches though, which I do truly regret, having been on the other side of the same many times over the past 30 years.
I switched to linux in 2004 or so. All those old use cases kind of vanished or changed. Perhaps the subset of software is more limited on linux, since Microsoft also builds - and exploits - a platform for commercial success, but I see more and more linux-specific applications too, typically using qt5 or qt6. Which is interesting considering linux does not have a huge share here. I guess there does exist some market value here.
I just can not really see myself using or needing "warez" on linux - the use cases are sooooo different now. For multimedia there are very few use cases not covered by ffmpeg and mpv. The only thing I'd like is something like avisynth, but more like a domain specific language that is even shorter. I remember back in early 2004 or late 2003 I was still writing avisynth scripts to modify video data on windows. Linux pipes never really went into an object-oriented approach and view onto data.
I remember switching to Linux around 94 and at the time one of the things that annoyed me was that there was very little commercial software to patch registration checks out of!
There were a couple of image-viewers, and similar things, but I fell out of the habit of decompiling random binaries, and stopped keeping up with the newere techqniques for a good few years. My reversing skills came back, later, but swithching to Linux where everything was "free" and source was mostly available really did change a lot of my computer-related hobbies.
Seeing this sent me down a rabbit hole through the old Net Monkey Weekly Reports. I found interviews, arguments, and stories I had completely forgotten about. My memory of that period is pretty hazy now, but competing at that level was a lot of fun. I never really did it for the software.
I eventually had to quit so I could finish school, and unfortunately I lost touch with almost everyone.
[dee]
.sS$ tHE $$Ss.
$$$$ $Ss,`$$$$
$$$$ $$$$ $$$$
,$$$$ $$$$ $$$$.
.sS$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$: $$$$.""""²$$$$$$$$$$$$$$$$$$$$$Ss.
$$$$' `²$²'.,sSSSSS$s`$',ss#SSS#ss.`$$$""""' $²"",ss#SSSSs`$$$²"S$$$$
$$$$ $s._ `$$$$ |$$$$$ $$$$$ |$$$$ $$$ $ _.s$ $$$$ $$$$$|'.s$`$$$$
$$$',$$$$',$$$| :$$$$ $#$szsmzs$$$$ $$$ $ `$$$$ $$$$ |$$$$ $$$$.`$$$
$$',$$$$' $$$$: $$$$ $$$$$ $$$$ $$$ $Ss`$$$$.`$$ :$$$$ `$$$$.`$$
$$ $$$$; `╙S$$S²'$$$ |$$$$ :$$$$ $$$ $$$ l$$$$ $`²S$$²' :$$$$ $$
$$.`$$$$ |S$$ $$$$$ |$$$$ $$$ `²' $$$$',$ $$$S',$$
$$$s.²╙S$S#$s$#S$S╜²' S$$$$#s#S$S²',$$$S#$S$S╜²'`²╙S$S#$s#S$S╜²'.s$$$
$$$$$ $$$$$
$$$$$ P R E M i E R E $$$$$
$$$$$ A T O M i C X U S H Q $$$$$
$$$$$ P A R A D i G M R E L E A S E H Q $$$$$
$$$$$ $$$$$
`²S$$$SSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSSS$$$S²'
`$'
| SiteOps: X, Dee, Hazzy, Phiber
: Staff: Dream, BasecW, Sting, Tinywulf, Gal
,$s Special Thanks: ADDiCTiON
`²'I recall thinking it was a cool and novel way to tell a story at the time it was released, but admittedly I haven't revisitted it in a couple decades so it may seem tame by todays standards.
https://en.wikipedia.org/wiki/The_Scene_(miniseries)
Episode one: https://youtu.be/ImLy5mqj8WI
Warez: The Infrastructure and Aesthetics of Piracy - https://news.ycombinator.com/item?id=29633143 - Dec 2021 (13 comments)
So phone phreaking was also part of the early warez scene. I built a box that could generate 64 tones that could put the phone line into all kinds of states to allow various kinds of mayhem on the phone lines. This led to me being on the radar of some interesting individuals in the warez/phreak scene. In the late 80's/early 90's I once received a phone call from a "party line" with dozens of hacker types from all over the world just being obnoxious, it was kind of hilarious. I stayed on it for like 10 minutes and hung up, it was just a lot of noise. A couple months later my mother was visited by the FBI (I had just turned 18 and had already moved out), and she told me I needed to call them. Well it turns out that party-line call was started from a PBX at a top secret military facility. Apparently someone who had my contact info had hacked around the phone system and stumbled upon this PBX, not knowing where it was located. After telling me this the FBI agents wanted me to teach them all about "the underground" and they asked me about "warez" and "phone phreaks". I just had to say I didn't know what any of that was about, I was just a kid and I picked up the phone when it rang one day. That's the last I heard about it.
The warez group FBR was legendary. I was somewhat involved with them in the late 80's. I remember hearing a story where they social engineered a secretary at a video game company. Someone mailed a modem to her (at her work) and instructed how to set it up as if they were working an IT job for the games company. They were able to transfer an upcoming game release over that modem, before the game was out. I don't remember all the details, but it was something along those lines, probably a lot more hilarious than I can remember now.
When people had their own internet connected machine other protocols were much better choices.
One day I realised bittorrent is a part of the warez scene
Yeah! I was a bit connected in that we'd write "intro" for a BBS and in return we had unlimited download (whereas on many BBSes there were seeder / "leecher" ratio and unless you were providing stuff, you'd be hindered by your leecher ratio).
> The “Scene,” as it is known, is highly illegal in almost every aspect of its operations.
But the "intro" pirates would put in front of cracked games (or sometimes on BBSes to advertize the BBS), later renamed "cracktros" (for that term wasn't used at first) eventually did spawn full-on "demos" and "musicdisk" / diskzines etc. and those weren't illegal.
In my Commodore Amiga days about half of my 5"1/4 floppies (because we were hacking 5"1/4 external drives to our Amiga and pretend to the computer they were the internal 3"1/2 disk so that we could buy shitload of much cheaper 5"1/4 floppies [1]) were demos (from Sanity, Scoopex, State of the Art, Lemon, Razor 1911, etc.).
Piracy definitely had aesthetics to it and I'd say the fully legal demos were, weirdly enough, the biggest manifestation of the aesthetics of piracy.
[1] in the early days I remember that after having something ridiculous like 3 boxes of 10 5"1/4 floppies, compared to 3 boxes of 3"1/2 floppies, you had already fully paid the 5"1/4 external floppy drive reader. I still have that external 5"1/4 drive for the Commodore Amiga just as I still have my chinese pirate SNES copying device. These two are prized possessions of mine ; )
I've seen that people (probably reddit teens) still install those "Windows Black Version" warezed Windows that come full of crap. I wonder how fruitful those have been for getting peoples data/money.
Teen me was never stupid enough to install a not only cracked but probably malware/virus packed OS thankfully.
Windows XP BlacK! < Pirateshipskull_wallpaper.png >
The big Sims cracker I believe is still that womans name, ladyfit or something? I forget. I tried to dig into who/what that was a decade ago out of curiosity if she/they were someone whose software you would want to install and could find nothing, but every person playing a cracked version uses it..
Also, I wish I could remember the intricacies but there was some way to visit other chatrooms and request files (progz, mp3, etc.) from a manifest which would then be emailed to you.
I call them more like Freedom Fighters. Like Mel Gibson in the movie Braveheart.
My first software purchase was I think after 2015, and it still felt weird compared to the usual process of finding a keygen somewhere.
what is it then?
specifically: what is the medium in which IRC exists, or operates in? are the people using IRC networking with each other, perhaps socializing?
Piracy sites are easy to track and obviously break the law. US ISPs should easily be able to null route their IP and CDNs should be able to easily block the domain from being served.
Their shelf life is more than 5 minutes. If we can't even get public sites under control there is no hope for more private ones.
The .nfo files alone, distributed with most releases, carrying the most elaborate of ASCII art. I distinctly remember the aesthetics you mention.
See their 40 year retrospective demo for a lot more of that: https://www.youtube.com/watch?v=dybkLM-1eQo :)
Frankly .tk domain is as much of a nostalgia hit as the music, weren't aware it is still around.
aesthetics is an umbrella term for the "[…] norms and rules of participation, […] forms of sociality, and […] artistic outputs." — think: sociology, culture, customs, and less visuals. reading chapter five (aesthetics), perhaps unsurprisingly the chapter where the author dives deeper into the topic, is certainly advised.
I spent the next month tracking him down. He was fond of DoSing a Canadian ISP. He also, for some reason, fond of DoSing a computer lab at NASA. I tracked him through servers he had broken in at 13 different american universities, a couple of machines at NASA, one machine at fbi.gov, and a variety of others.
Coordinated with a guy at NASA, everyone but FBI was eagerly sending me logs from their servers, and the FBI+NASA looped in RCMP who got thousands of pages of logs from me. Both from servers he had broken into, and from the various IRC channels I monitored his activity from. The Canadian ISP he was fond of DoSing was also quite eager.
Around January 22nd 1999 (might have been a day before or after) the RCMP came knocking on his door. A few hours later (after being released after being interrogated) he got online and told me he would knock my servers offline permanently. At this point I had a phone number directly to the RCMP - and they paid him another visit.
ISPs already have policies that you can't use them for piracy and it is trivial for an ISP to see that a site is being used for piracy. A manual check can be done within 30 minutes.
>This resulted in them taking down things like Cloudflare, Google Drive, and the Italian government.
This sounds more like Cloudflare and Google Drive are harboring pirates. There should be similar takedown processes and having suspicious accounts separated onto distinct IPs from higher trusted ones to avoid actions like this affecting non pirates.
What an absurd world view.
It is like a bank that has sloppy security and exposes you to the whole world, including adversaries from Russia china NK etc.
Things like Telco cloud banks should absolutely be thrashed for having bad security. Responsible disclosure should also be a thing but we all know these companies sue people for that too.
Is it about a perceived lack of consequences of the one vs the other? What if the hack caused real damage and suffering? For example, people's medical histories get stolen and exposed? Ransomware encrypts hospital systems, disrupting medical care?
Or, the inverse: while you're away, somebody breaks into your home non-destructively, takes some photos, sleeps on your couch, and leaves. Should that be forbidden? Your fault for allowing it? It is easier to pull something like this in the digital world, is that why it seems different to you?
Making burglaries illegal is a real way of preventing many burglaries from happening, because it puts people committing them in prison and deters some from doing it in the first place. This only works because the burglar is in the same place as the burglary, and so they can be arrested.
People with little to no computer experience apply the same standard to cybersecurity and treat foreign hackers the same way as burglars. Then they get surprised when the Russians hack them and the FBI does nothing.
I really don’t understand the urge or need to compare software security with physical security.
There is no door, that cannot be opened with enough effort. Part of what stops people trying, is the fear of consequences.
You don't need a wiretap to know that 123moviesclone.su is hosting pirated content. You can simply visit it and tell in 2 seconds.
We're in a thread that starts from the notion that it should not be illegal to "hack a telecom network and take control of it", because "the people running it did not do a good job configuring and securing it." That's essentially the free-for-all position, and defending it by claiming that the opposite extreme is the only other option is a false choice. Nuance and compromise exist, and our world is made of them.
Also, your argument about burglars can be applied to "hackers", too. Police can find and arrest people domestically and beyond. Consequences deter people from all sorts of illegal activity. On the other hand, nation states are not necessarily deterred by laws from kidnapping and killing people inside the territory of other countries. You've probably seen the news.
What's different is the ease of access to digitical, internet-connected systems, and the scale of abuse that affords. That's a reason to think differently about _how_ to shape the rules and laws around "hacking", but not a reason to have no rules or laws at all.
My issue is that software security is not taken seriously most of the time because features are more important than spending a little more time on code quality.
The hacker is not the one writing buggy software.
Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.
I also notice that you haven't really answered my questions around that.
> if you get hacked, it is on you. The attacker was smarter than you, simple as that.
From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?
I think physical and "cyber" security are not so dissimilar in the need to back them up with rules and laws at some point. Still, there are differences, so I don't think the rules and laws need to be the same. You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.
Yes, it would suck if the hospital got hacked while I underwent a surgery for example, and the ventilator stopped working. But if that happens, whoever is doing it is not stronger, just smarter than the people administering the hospital network.
> From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?
I gave an analogy with chess. You don't have to be strong in the physical sense to win a chess match, just smarter than your opponent. This is how I see the difference.
> You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.
For software, the playing field is level: you use a computer, your opponent uses a computer. But the difference is the other person's capabilities. You can be smarter and you don't get hacked, or your opponent is smarter and hacks you.
You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.
You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength, or any other advantage, to cause such adverse outcomes in other ways; it is not clear to me if you would also regard that as okay and think we should not have the laws that sanction such things; or if and why you think this anarchy should only exist in some sort of "digital computer space", crossing which would serve to make actual, real world consequences not matter that much anymore. It's almost like, by putting a computer between actions and consequences, one passes through a waterfall that washes away responsibility and "sin", in the ethical sense. But that depends on whether you think those were there to begin with, and is only an interesting metaphor for me; please don't get distracted by it.
In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?
(Edit: Please disregard "what you gain", it comes across completely wrong and takes it in an unintended direction. "Where does it come from" is what I mean.)
For instance, I’m pretty sure I’m better at computer security than Terence Tao but no way would I say I’m smarter than him.
How do you compensate someone who's dead?
This isn't hypothetical: https://www.politico.com/news/2022/12/28/cyberattacks-u-s-ho...
Anything network connected that can be reached by an adversary. And, I did not say it shoukd be legal or illegal, just that the fault lies with who administers/secures those systems, not with whoever breaches them.
> How do you compensate someone who's dead?
In some countries where I lived, there were pricelists based on nationality that insurance would pay out in case of accidental death. If you live in a more homogenous country, you can use other factors to determine what the payout should be.
I said the fault lies with the administrators of those systems, not with attackers. I really think I never said it should be legal or illegal. I don’t really care if it is illegal or not, hackers are not dettered by the legality of it. Do you think someone in The Gambia cares that hacking is illegal in Canada?
> You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength
For me being smart and being strong are two wildly different things. It is like asking me why I don’t compare apples to oranges. I can’t.
> In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?
I am not trolling. I see this, hacking and securing something against hacking, as an “intellectual fight”.
Let’s say you are a 50 year old security admin that gets owned by a 14 year old with a computer. You were beat because the 14 year old one was smarter than you, not that he had more experience or was physically stronger than you. Just smarter.
Now imagine you’re part of a security team and you still get owned. What does that say about you?
I am at a loss on how to explain that when it comes to computer security the fault, in my book, does not lie with the hacker.
Just like when a flaw is found and exploited I do not blame the one who found it, but whoever made it possible in the first place. And in the case that the flaw was patched and a software update was made available, but it was not installed promptly, then the fault lies with whoever did not update the system.
Regarding arguing: I made a statement expressing my position and got mobbed for it. Now I am defending my position.
We can agree to disagree and keep enjoying what is left of our weekends.
I think I do get it now, and it seems to be pretty much to what I described before. While I think that there is responsibility for the outcomes of one's actions no matter through which ways and means they are accomplished, for you, it seems to depend: making it about smarts or intellect or whatever, and putting a computer in between, causes it to transcend legality and morality. Adverse consequences are not on the actor anymore, and purely on the "defender".
That's not how a lot of people (including myself) see this issue. They would not agree that responsibility and outcomes should get disconnected or redistributed by changing the ways and means in between. (Edit, just to make this extra clear: The idea is that it should not matter if one uses their brain and a computer to effect damage, or some other means. Computers are a different tool, not a different game.) Even more, people find it hard to follow both the ethics and the logic of your argument, because you've not been able to express WHY an exception should be made for "smarts" and "computers" and not in other cases. Whenever I've asked you to explain, you've either misunderstood or evaded the question and responded with re-iterating that "smart" is different from "strong", as if that explains anything. (It boils down to being asked: "Why should the difference between red and blue matter here?" and answering with "Because they are different.")
So, you're taking an position that people find ethically problematic and logically inconsistent, and that's the reason why you receive this pushback: people feel motivated to counter what they see as an uncontested "ethical divergence", and you gave them an obvious logical chink to pry a lever into.
What I'm taking away is that you truly believe this, which is so foreign to me that I'm completely mystified. It makes me curious, and also uncomfortable, and for both reasons I wonder: How? Why? However, you're simply re-iterating your position, and I've come no closer to finding out, nor do I think I actually will, because I can't find a way to phrase my questions in a way that would bridge a barrier of understanding between us and make you respond to what I'm asking.
I'm still curious. But in any case, please do enjoy the rest of your weekend.