Ex-prosecutor: Politician's plea for UFO hacker lacks facts

A former prosecutor says the Mayor of London was ignoring the facts this week when he publicly threw his support behind the man who has admitted hacking into US military computers in 2001.

Scott Christie, an assistant U.S. attorney in New Jersey in 2002 when Gary McKinnon of London was indicted in the case, told Computerworld that London Mayor Boris Johnson 's emotional defense of the hacker is obscuring the facts and circumstances surrounding the crime. McKinnonhas acknowledged that he hacked into U.S. government and military computer systems simply to look for information on unidentified flying objects (UFOs).

But while the US government alleges McKinnon caused US$900,000 in damages to computers in 14 states, and that he caused the shutdown of critical military networks shortly after the Sept. 11, 2001 terrorist attacks, the mayor of London offered a very different take on it in a column that he wrote for London's Telegraph newspaper. The column was a public plea for US President Barack Obama to drop the case against McKinnon.

Johnson called US efforts to prosecute McKinnon a "legal nightmare." And saying that McKinnon is not a threat to the US, Johnson also referred to the Department of Justice's ongoing efforts to extradite McKinnon to the US for prosecution as "American bullying."

Christie, who now leads the information technology group at law firm McCarter & English LLP, said it's clear that Johnson doesn't have all the information about the case.

"[McKinnon] has created this cause celebre status in order to appeal to folks who will beat the drum on his behalf and they conveniently ignore the facts of the situation and the entire nature of his conduct," said Christie. "I think that, unfortunately, it lends some credence to the individuals who are painting McKinnon as a victim, to have the mayor of London weigh in as part of that team ... people are resorting to a distortion of the facts in order to further his celebrity status as a victim. It's troubling."

In his column, Johnson asserts that McKinnon is not a "proper hacker", adding, "He was so innocent and un-furtive in his investigations, that he left his own email address, and messages such as 'Your security is crap'."

Christie, though, says that's not true, noting that McKinnon had worked as a system administrator in the UK. He also said that McKinnon was able to surreptitiously enter US Department of Defense computers and cause a significant denial-of-service within weeks of the 9/11 terrorist attacks.

He added that McKinnon also did not leave his email address behind.

"That's not true. Mr. McKinnon took great pains to obscure ... where he was coming from and who he actually was," said Christie. "He certainly did not leave his email address. He was able to be identified only through the hard work and diligent investigation by the Naval and Defense Department criminal investigators. It's unfortunate that that Mr. Johnson doesn't have a full understanding of the facts in his rant in favor of Mr. McKinnon."

He also said he was surprised that any plea to a national leader would be made so publicly and not through normal political channels.

Late last week, it was announced that McKinnon was getting yet another chance to avoid extradition when The High Court in London ruled that the case can be reviewed by Keir Starmer, director of public prosecutions for England and Wales.

McKinnon, who was an unemployed system administrator in the UK at the time of the 2001 hack, has been using a series of legal maneuvers and appeals over the past seven years to fight extradition to the United States. McKinnon, now 43, was indicted in November 2002 in the US District Court for the Eastern District of Virginia. He has said he broke into U.S. military computers hoping to uncover evidence of UFOs.

McKinnon has admitted to hacking the computers and described how he did it in detail at computer security conferences in London.

Tags: hackers, ufo

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CSO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
CSO Corporate Partners
  • FirEye
  • Clear Swift
  • Trend Micro
  • Sophos
  • NetIQ
rhs_login_lockGet exclusive access to CSO, invitation only events, reports & analysis.
CSO Directory

Splunk for Security (Enterprise)

Splunk collects, indexes and harnesses all the fast moving machine data generated by your applications, servers and devices - physical, virtual and in the cloud.

Security Awareness Tip
Clearswift tips: Guidelines for introducing and policing an effective IT Policy

1. Make it clear that the policy is not about playing ‘Big Brother’ but to ensure the security of employees, company information and data and to safeguard the company’s reputation.
2. Invest time to get buy-in from managers and their teams.
3. Convey the message of flexibility – with regard to social media, it is not about blocking staff usage but working in everyone’s interests to ensure that threats are contained.
4. Introduce a regular company-wide training programme that everyone attends at regular intervals throughout the year, not merely as part of an induction programme.
5. Within the training programme make sure that there are specific examples to demonstrate each rule or regulation, and that there is a clear explanation of the dangers of casual or careless talk on social networking sites. Again use examples, employees need to understand the consequences of raising a throwaway comment that has negative connotations for the business, as much as they need to be aware of dangers of making a more direct but ill-considered attack on a competitor, regulator or even a fellow colleague. They need to be clearly advised on any impact on the company and/or legal action or inquires that may be raised as a result.
6. Alert employees to any changes in policy through regular clear communication.
7. Reinforce the operational policy guidelines regularly, cover everything from blogging to Facebook, LinkedIn and Twitter.
8. Ensure that the rules are fair and that they apply throughout the business.
9. Enforce the rules – if there is a deliberate or malicious contravening, disciplinary action needs to be taken. A policy isn’t worth having if it is seen to be lax and unenforced.
10. Review the policy regularly to ensure you keep up to date with new systems and technology.

Phil Vasic is Regional Director, APAC, at Clearswift, the software security company www.clearswift.com
Security ABC Guides

7 Ways to Protect Your Business Printers

Can a hacker burn down your business by remotely setting one of your printers on fire? Researchers at Columbia University have recently proposed such a scenario, although HP quickly denied that it's possible. However, even if your printers can't be used as remote firestarters, there are many risks involved in networking a printer.