{"id":2296,"date":"2021-05-27T19:38:12","date_gmt":"2021-05-27T18:38:12","guid":{"rendered":"https:\/\/wp-uk.mindquest.io\/?p=2296"},"modified":"2022-10-10T15:41:13","modified_gmt":"2022-10-10T14:41:13","slug":"hacking-rickey-gevers","status":"publish","type":"post","link":"https:\/\/wp-uk.mindquest.io\/?p=2296","title":{"rendered":"From Hacking NASA to Protecting Your Online Accounts: A Chat with Rickey Gevers"},"content":{"rendered":"<p><em>Ethical hacking\u00a0can be\u00a0the solution to\u00a0some of\u00a0our\u00a0most serious cybersecurity\u00a0issues. We\u00a0interview\u00a0Rickey Gevers,\u00a0<a href=\"https:\/\/mindquest.io\/en\/blog\/news\/1255\/cybersecurity-careers-overview\" target=\"_blank\">cybersecurity<\/a> expert and\u00a0founder of\u00a0<a href=\"https:\/\/scatteredsecrets.com\/\" target=\"_blank\">Scattered Secrets<\/a>, a\u00a0password\u00a0breach notification and prevention service\u00a0that is helping\u00a0businesses and individuals protect their online accounts.\u00a0\u00a0<\/em><\/p>\n<p><em>Here is how\u00a0this\u00a0Dutch security pro\u00a0got into hacking, was\u00a0arrested\u00a0by the\u00a0authorities,\u00a0and\u00a0went on to show how\u00a0that\u00a0his talents could also be a force for good.\u00a0\u00a0<\/em><\/p>\n<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<p>?  <a class=\"has-text-color\" href=\"https:\/\/visit.mindquest.io\/mission-control-center-podcast?utm_source=medium&#038;utm_medium=b_post&#038;utm_campaign=Podcast_lp\" target=\"_blank\">Subscribe to the podcast<\/a><\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<h2><strong>How did you get into hacking?<\/strong>\u00a0<\/h2>\n<p>My dad\u00a0was\u00a0really\u00a0the one who\u00a0introduced me to tech. I&#8217;m not a typical technical person. I like to play outside\u00a0and\u00a0those kinds of things.\u00a0So,\u00a0not necessarily\u00a0being\u00a0behind\u00a0a computer. But my dad bought\u00a0a computer\u00a0when I was young, so I started playing with it at a young age\u00a0too.\u00a0I liked\u00a0the Internet a lot\u00a0because you could search for anything you wanted.\u00a0I am a very curious person,\u00a0so I was\u00a0looking\u00a0things\u00a0up all the time.<\/p>\n<p>But\u00a0an\u00a0Internet connection was very expensive back then,\u00a0and at one point\u00a0my parents\u00a0had to pay a lot of money\u00a0because of me.\u00a0So,\u00a0they used a Windows password.\u00a0But I managed to break into the Windows user account and started using the Internet again.\u00a0They got mad again, and then my dad used a BIOS\u00a0password, which was a proper measure to keep me out for a month or so.\u00a0<\/p>\n<p>\u00a0Then I\u00a0managed to take out the whole modem, put it in my own computer, install\u00a0all of\u00a0the drivers and use the phone connection from the moment they left the house.\u00a0\u00a0And I put my computer in such a position that if they came home, I could see them entering\u00a0and\u00a0remove\u00a0the cable, remove the modem,\u00a0and\u00a0put them back in\u00a0my dad\u2019s\u00a0computer just in time before they entered the house.\u00a0That\u2019s how I\u00a0sort of started hacking, in a\u00a0pretty natural\u00a0way.\u00a0I\u00a0wasn&#8217;t\u00a0really busy\u00a0with hacking or anything. I just wanted to get the things done.\u00a0<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<h2>Then, at the age of 13, you created Waarneming.nl, a leading community-driven platform where users collect and share data for nature conservation, research or education. How did you go from there to the major leagues of hacking?<\/h2>\n<p>Usually, when I talk about the things that I have achieved, I\u00a0see\u00a0<a href=\"https:\/\/waarneming.nl\/\" target=\"_blank\">Waarneming.nl<\/a> as\u00a0the brightest thing that I&#8217;ve done. I didn&#8217;t make any money\u00a0from it, but it contributes a lot to society.\u00a0And at one point the website got hacked, which I will never forget. One\u00a0guy\u00a0just took it offline and put some defacement posters on it.\u00a0I\u00a0put the website back online\u00a0but, after\u00a0half an hour, the guy defaced the website again. It\u00a0a\u00a0lot of fun for\u00a0him\u00a0but,\u00a0of course,\u00a0it\u00a0was not\u00a0for me.\u00a0\u00a0<\/p>\n<p>I decided\u00a0I didn\u2019t\u00a0want this to happen anymore in the future. And the only way to stop it\u00a0was\u00a0to understand how hackers work.\u00a0So,\u00a0I started to learn\u00a0to hack and,\u00a0pretty quickly,\u00a0I hacked my first computer.\u00a0I kept on challenging myself.\u00a0Back in the day, nobody got arrested for it.\u00a0I didn&#8217;t break any computers ; didn&#8217;t delete any files or whatever you can imagine ; I just hacked the computer and that&#8217;s all I did.\u00a0So\u00a0I started\u00a0aiming for\u00a0higher targets. I went from one computer to a computer network. I went to universities\u00a0because they had\u00a0fast Internet connections. And I moved\u00a0up\u00a0the ladder\u00a0and eventually was able to basically hack any network, move laterally\u00a0within the network\u00a0and\u00a0become the main admin. And that&#8217;s\u00a0sort of\u00a0where\u00a0my story ended.\u00a0<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<p><a class=\"has-text-color\" href=\"https:\/\/mindquest.io\/en\/signup?type=consultant\" target=\"_blank\">Join our community and find your next job or expert in IT<\/a><\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<h2><strong>Then you got caught.<\/strong>\u00a0<\/h2>\n<p>For some reason, the University of Michigan\u00a0did\u00a0a\u00a0forensic investigation, found me and arrested me. As I said, this was back in the day, so not a lot of hackers got arrested. I had also hacked NASA, to just give\u00a0you\u00a0an example.\u00a0And I\u00a0remember\u00a0one\u00a0guy got\u00a0arrested for hacking NASA,\u00a0but\u00a0at that\u00a0time,\u00a0it was very normal to hack computers at NASA.\u00a0<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<h2><strong>What exactly happened with the\u00a0whole\u00a0University of Michigan\u00a0incident?<\/strong><\/h2>\n<p>Well, the University of Michigan was sort of my playground,\u00a0because the Internet connection there was very slow.\u00a0So,\u00a0if I wanted\u00a0to try some new tools that I\u00a0had\u00a0found,\u00a0I usually tried\u00a0to do\u00a0it\u00a0on a network there, which is probably one of the reasons they\u00a0caught\u00a0me. But they did a proper forensic investigation and they determined that I was in the network, that I had full control of\u00a0the network, but\u00a0that I didn&#8217;t do anything else. So that&#8217;s why the FBI basically\u00a0did not chase me.\u00a0\u00a0<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<p><a href=\"https:\/\/visit.mindquest.io\/subscription-newsletter\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"367\" alt=\"Connect by Mindquest Newsletter\" class=\"wp-image-6772\" src=\"https:\/\/wp.club-freelance.co.uk\/wp-content\/uploads\/2022\/07\/Test_MQ-New-Blog-CTA-Banner-2-23-1024x367.jpg\" srcset=\"https:\/\/wp-uk.mindquest.io\/wp-content\/uploads\/2022\/07\/Test_MQ-New-Blog-CTA-Banner-2-23-1024x367.jpg 1024w, https:\/\/wp-uk.mindquest.io\/wp-content\/uploads\/2022\/07\/Test_MQ-New-Blog-CTA-Banner-2-23-300x108.jpg 300w, https:\/\/wp-uk.mindquest.io\/wp-content\/uploads\/2022\/07\/Test_MQ-New-Blog-CTA-Banner-2-23-768x276.jpg 768w, https:\/\/wp-uk.mindquest.io\/wp-content\/uploads\/2022\/07\/Test_MQ-New-Blog-CTA-Banner-2-23-1536x551.jpg 1536w, https:\/\/wp-uk.mindquest.io\/wp-content\/uploads\/2022\/07\/Test_MQ-New-Blog-CTA-Banner-2-23-1200x431.jpg 1200w, https:\/\/wp-uk.mindquest.io\/wp-content\/uploads\/2022\/07\/Test_MQ-New-Blog-CTA-Banner-2-23.jpg 1700w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/a><\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<p>Then the\u00a0high-tech\u00a0crime unit here in the Netherlands was established and they contacted the FBI and asked them if they had anything they could do for them. So that&#8217;s when the FBI said, well, we have a file here.\u00a0We know its name,\u00a0we know where he lives,\u00a0so maybe you can pick up the\u00a0case. And that&#8217;s basically what they did.\u00a0I got arrested by the\u00a0high-tech\u00a0crime unit\u00a0as one of the first hackers they arrested, I believe. They\u00a0thought I was a\u00a0really big\u00a0hacker, which I wasn&#8217;t,\u00a0of course.\u00a0I did hack a lot of computers, but I never did anything with it.\u00a0So,\u00a0I\u00a0was basically a huge disappointment.\u00a0<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<h2><strong>Then, after some years under trial,\u00a0and a suspended sentence, you went back to hacking, but with a different approach.\u00a0You went on to create Scattered Secrets.\u00a0What was your thinking?<\/strong><\/h2>\n<p>At first, when I went on trial, I wondered\u00a0\u201cshould I continue this?\u201d\u00a0But after two years, I was like\u00a0\u201cwell, I&#8217;m only good at one thing, so let&#8217;s just fight back and show everybody that I&#8217;m on the good side and that I don&#8217;t have anything to do with criminals or whatever.\u201d\u00a0And I started\u00a0hacking again.\u00a0\u00a0<\/p>\n<p>I did a lot of penetration testing, and at one point I noticed that you can easily hack any company and you usually do\u00a0it with\u00a0the same trick.\u00a0That&#8217;s\u00a0when I started building\u00a0<a href=\"https:\/\/scatteredsecrets.com\/\" target=\"_blank\">Scattered\u00a0Secrets<\/a>, because I believe\u00a0you can\u00a0hack any\u00a0company\u00a0by\u00a0simply looking at the passwords that\u00a0have been\u00a0leaked.\u00a0So that&#8217;s what we&#8217;re trying\u00a0to fight against\u00a0right now. We&#8217;re basically doing the low hanging fruit for most hackers. It&#8217;s not that interesting. It&#8217;s not that advanced. But,\u00a0in our opinion, it&#8217;s the most dangerous and easiest way to hack any company\u00a0right now.\u00a0\u00a0<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<h2><strong>So,\u00a0you basically monitor for passwords that have been hacked and leaked.\u00a0Where do hackers get these passwords?<\/strong><\/h2>\n<p>The funny thing is that most passwords are leaked through only a few databases. We have a few enormous leaks. One of them is\u00a0MyHeritage. The other one is\u00a0MySpace. And the third one is LinkedIn. That&#8217;s where most passwords come from.\u00a0It&#8217;s often\u00a0the small databases people are in, but\u00a0once every two\u00a0years, you have an enormous breach.\u00a0\u00a0<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<h2><strong>Given\u00a0these\u00a0ongoing\u00a0data leaks\u00a0and recent headline-grabbing\u00a0global\u00a0breaches, how do you think we are doing in terms of\u00a0cybersecurity?<\/strong>\u00a0<\/h2>\n<p>Often, if you talk to security experts, they say we&#8217;re not getting better.\u00a0But in my opinion, there won&#8217;t be a single day without\u00a0hacks.\u00a0That&#8217;s simply because you have the human\u00a0factor,\u00a0and the human factor is always vulnerable.\u00a0We can build secure systems, but there&#8217;s still a human using them, so it will always be vulnerable.\u00a0So, we\u00a0have to\u00a0deal with the fact that there will always be hacks.\u00a0<\/p>\n<p>At the same time,\u00a0when it comes to\u00a0multinationals\u00a0\u2013\u00a0back in the day,\u00a0in 2014 or\u00a0prior to that, we had these flat\u00a0networks,\u00a0and you could easily\u00a0become the\u00a0administrator.\u00a0It was\u00a0pretty easy\u00a0to hack\u00a0large companies. I think most multinationals now have a certain base level. And,\u00a0sure, in the news we see the ones that don&#8217;t have that base level.\u00a0But we&#8217;re getting more and more mature. I think that&#8217;s the most valuable lesson.\u00a0\u00a0\u00a0<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<h2><strong>To you, what\u2019s the most challenging aspect of cybersecurity?<\/strong>\u00a0<\/h2>\n<p>As a security researcher, I think the most challenging part is that\u00a0you\u00a0have to\u00a0keep up with your knowledge,\u00a0you\u00a0have to\u00a0continue learning and working.\u00a0If you stop doing certain things, your knowledge starts to\u00a0lag behind.\u00a0It&#8217;s a constant battle\u00a0to keep\u00a0your knowledge\u00a0at\u00a0a certain level.\u00a0\u00a0<\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<h2><strong>And what are your go-to cybersecurity education resources to stay at that level?<\/strong><\/h2>\n<p>Without a doubt, the <a href=\"https:\/\/www.sans.org\/meta\" target=\"_blank\">SANS Institute<\/a>. In my opinion, they&#8217;re the only real experts. It\u2019s very expensive, between six and eight thousand euros, but it&#8217;s absolutely worth the money. I try to do a course every year, but it\u2019s not always easy to find the time.  <\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<p><a class=\"has-text-color\" href=\"https:\/\/mindquest.io\/en\/blog\" target=\"_blank\">Check out more of our interviews from our podcast episodes.<\/a><\/p>\n<div class=\"wp-block-spacer\"><\/div>\n<p>You can follow Rickey on <a href=\"https:\/\/x.com\/UID_\" target=\"_blank\">Twitter<\/a> and <a href=\"https:\/\/www.linkedin.com\/in\/rickey-gevers-aa862b15\/\" target=\"_blank\">LinkedIn<\/a>. <\/p>\n<div class=\"wp-block-spacer\"><\/div><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We interview Rickey Gevers, cybersecurity expert and founder of Scattered Secrets to discuss his career and ethical hacking.<\/p>\n","protected":false},"author":6,"featured_media":2297,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[754,9,773],"tags":[525,47,568,565,566,441,579,567],"class_list":["post-2296","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-about-us","category-featured","category-podcast-interviews","tag-behind-the-screens","tag-cybersecurity","tag-cybersecurity-careers","tag-ethical-hacking","tag-hacking","tag-interview","tag-podcast","tag-rickey-gevers"],"acf":[],"_links":{"self":[{"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=\/wp\/v2\/posts\/2296","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2296"}],"version-history":[{"count":9,"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=\/wp\/v2\/posts\/2296\/revisions"}],"predecessor-version":[{"id":6773,"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=\/wp\/v2\/posts\/2296\/revisions\/6773"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=\/wp\/v2\/media\/2297"}],"wp:attachment":[{"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2296"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2296"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp-uk.mindquest.io\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2296"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}