Hacker breaks into Daum’s system
By Jin Hyun-jung
The nation’s second-largest internet portal Daum was attacked by a professional hacker in July, the police said yesterday, revealing loopholes in the firm’s security system.
The hacker, who was only identified by his surname Shin, broke into the portal’s customer consulting system which allegedly contains personal information of customers such as their names and citizen registration numbers.
The internet firm subsequently asked 7,000 members to change their id and password without informing them of the incident.
Daum said in a statement that it kept the incident under wraps for eight months due to concerns that the suspect will disclose the information that he obtained. The company said it found no evidence that the suspect gained access to its server and customer database.
It also enhanced its security system to fill the hacking loopholes.
Shin threatened to sell the personal information, demanding tens of millions of won. The police are still seeking Shin’s whereabouts.
(The Korea Herald/ Thursday March 27, 2008)
——————————————————————————————
When I first read this article about 3 days ago, I thought this could be a good material for our class. I found two things to think about in this article – one is what the hacker did after hacking and the other is what company did when they knew about hacking. I guess it’s rather different from what we’ve learned.
First, hacker threatened a firm and demanded money, which looks a little different from other hackers that we’ve covered in class. “Hacker Crackdown” said that the purposes of hacking are to learn something, to show off, to warn or for fun. For that reason, I reached the conclusion that the objectives of hackers are changing as time goes by and technology develops. This idea can be supported by many other hackers who ask for money after they hack individual homepages of famous celebrities.
Second, a company didn’t publicize the fact their portal site had been hacked. It could have been dangerous because many people didn’t care the notice that a firm posted including me. Even though the company worried about customers’ information which would be opened to the general public if they let people know, they definitely should’ve told us.
In my opinion, we need to talk about both the definition and purpose of hackers and what company should do related to publicity and secrecy. What do you think?
This is REALLY interesting, and ties directly to some questions I’ll be asking soon.
As for now, I think Daum needs to REALLY invest in some security. Or maybe it’s time Korean internet users started insisting portal sites invest in better security. Giving up on ActiveX and other protocols that the rest of the world doesn’t use would be a start, since it’s always easier to use global-standard software!
But there are much bigger questions involved in this. We’ll be talking about them this week!