Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

2026-04-10

Ethical hacking

Image from Unsplash

After years, it was time for me to go back to training. I looked for one where the chance would be small that I’d learn very little; something that tends to happen quickly when you’ve been around the block in this field. A course on ethical hacking more than met that requirement.

For more than three decades, I’ve viewed the world from the right side of the line. My work revolves around security policies, risk analyses, and compliance, to name just a few things. I read and hear about what goes on on the wrong side of the line and try to make life as difficult as possible for the folks who hang out there. With this hacking course, I wanted to see the world from their side for once. Because, as Sun Tzu already knew in the fifth century BC: ‘Know your enemy and know yourself, and you will not have to fear the outcome of a hundred battles.’

But what is ethical hacking, exactly? Broadly speaking, there are two kinds of hackers: the good and the bad. The latter usually make the news, for instance through data breaches at the police or at telco Odido, both here in the Netherlands. That’s how hacking is known to the general public: unlawfully breaking into computer systems. The people who do this come in many shapes and sizes. At the bottom of the ladder you find the script kiddies: people who use ready‑made recipes to do things without really understanding how they work. And right at the top you have organized crime and state actors.

But there are also benevolent hackers. Like their malicious counterparts, they look for weaknesses in defenses. The big difference is that they don’t exploit those weaknesses for personal gain; they responsibly report them to the organization where they found the vulnerability. You can hire ethical hackers to test your systems, but some also operate on their own initiative. Quite often, if they play by certain rules, they even receive a reward. That can range from a T‑shirt to (a lot of) money.

Of course, after a five‑day course I am far from a seasoned hacker. Quite the contrary: last week my head was spinning from hacking tools with countless options, the many ports that can be attacked, and lots of other things that any self‑respecting hacker is expected to know by heart. Back in the MS‑DOS era, you also had to do everything from the command line (the C:\ prompt), but by today’s standards that feels rather archaic. And yet that’s still how things work in that world, only now with Linux instead of MS‑DOS.

The most important thing I learned is that hacking involves quite a lot, but that once you’ve mastered the tricks, it can be remarkably easyat least if your opponent doesn’t defend themselves well. In the simple scenario we practiced, you find the IP address of your target, check which ports are open, investigate whether known vulnerabilities exist for the services running there, and boom, you’re in. Obviously, it’s (hopefully!) not always that easy, but the principle is likely the same: the hacker looks for weak spots in the defense. And you’d much rather have those vulnerabilities discovered by an ethical hacker than by a criminal. That only helps, of course, if you then actually act on the findings. Fortunately, everyone understands that. Right?

I’ve always had admiration for colleagues who do this for a living. Now that I better understand what they do, that respect has received a serious upgrade. It’s important, rewarding puzzle work that requires a great deal of knowledge and skill. They make discoveries that sometimes cause quite a stir. And then you see them walking around beaming. A fine sight.

Finally, I’d like to share something entirely different that I learned and that anyone who uses AI chatbots such as Copilot, ChatGPT, and Claude can enjoy. It’s about ELI5. That stands for ‘explain like I’m five’ and ensures that answers are phrased in simple terms and don’t assume prior knowledge. Not baby talk, but often using nice analogies. Just try something like: ‘ELI5: Explain what an IP address is.’

 

And in the big bad world…

 

 

2026-03-13

WhatsApp and Signal hacked? No!

 

Image from Unsplash

Last Monday, Dutch broadcaster NOS ran the headline: ‘Russia hacks WhatsApp and Signal of government employees, intelligence services say.’ Let me explain why I label this as ‘devaluation.’

First, a reassurance: neither WhatsApp nor Signal has been hacked. At least, not if you use the common meaning of hacking: gaining unauthorized access to a computer system (not a formal definition, but the way I see it). In this case, the computer system would be the service as provided by WhatsApp and Signal. Your individual account is not the target.

Let’s pretend for a moment that these chat services really were hacked. That would mean a hacker had broken into their servers and done all sorts of things that many people would not appreciate; allor at least manycustomers would have been affected because their data had been compromised.

But that’s not what happened here at all. The actor (a polite term for perpetrator) targeted individual accounts of specific types of officials. These people received a message that appeared to come from Signal’s chatbot; it looked like an official warning from the service provider about suspicious activity. It also claimed that data might have leaked and that attempts had been detected to access private information. You could prevent this, the message said, by completing the verification process.

So what is actually happening? The actor wants to log in to your Signal account. The app then asks for a code, which is sent by SMS to the phone number Signal knows: yours. The actor needs that code, and your self‑chosen PIN, to log in. Hence the message they send you. The idea is to make you panic so that you quickly complete the ‘verification process’, which really is a trap. If you fall for it, the actor can take over your entire account and even change the linked phone number to their own. They now have access to your contacts and can read new chat messages (both one‑to‑one and in groups). They can even send messages as you. You lose access to your account, but you can create a new one and get your chat history backbecause it is stored on your device. Great, no problem, nice that they helped me so well, you might think.

In another variant, they have you scan a QR code or click a link. They make you believe you are being added to a WhatsApp or Signal group chat, but in reality the attacker’s device becomes linked to your account. The actor can now see all your chats, often including chat history. You notice nothing. In this attack as well, they can read new messages and send messages on your behalf.

Now, back to the term hacking and why I think it is being devalued. From the 1960s onward, a hack was a clever technical trick in the (American) computer and model railway club world, and a hacker was an exceptionally smart programmer. In the 1980s, the term was used for people who conducted in‑depth research into computer systems and networks. If they bypassed security, it was out of curiosity and in order to test things. There were also crackers, their malicious counterparts. From the 1990s onward, the distinction faded and hackers came to be seen as criminals in general. See my personal definition above.

The NOS headline suggests that WhatsApp and Signal have been hacked, while the cyber advisory from Dutch intelligence services explicitly emphasizes that this is not the case. Apparently, NOS was reprimanded, or the editorial team corrected the intern, because later that day the headline changed to: ‘Intelligence services: Russian hackers access WhatsApp and Signal accounts of civil servants.’ And the article gained a paragraph titled: ‘No breach in the messaging service itself.’ In the original version, ‘hacking’ seemed to refer to pretty much all computer‑related trouble coming from the outside. As described above, the term was already significantly devalued, but this was simply misleading.

What actually happened here is called social engineering. In this technique, it is not the computer but the human behind the computer that is attacked. If they succeed in getting you to share a code or scan a QR code, their mission is accomplished. Social engineering is also known as hacking the humanwhich, ironically, is accurate.

 

And in the big bad world…

 

Passport Leak

Image: Unsplash The data behind every passport and ID card has been leaked. No one accepts them as valid ID anymore without question. “You...