The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

I Got Caught Hacking in 1981. The Professor Made Me Head of Security.

This entry is part 16 of 21 in the series Technology
TL;DR: Home security does not fail at the technical seam. It fails at the human one. A company with card readers, cameras and alarms lost everything to a brick propping a door open for smoke breaks. Your house has somewhere between 25 and 60 connected devices you bought one at a time, and the defenses that work are the dull ones you can keep doing.

In 1981 a college professor caught me trying to break into the school’s computer system. He did not suspend me. He said, since you hacked our computer, you are now in charge of system security, and handed me the job.

That was the most useful thing anyone has ever done for my career, and not because it taught me about computers. It taught me that the only reliable way to protect a system is to look at it the way somebody trying to get in would look at it. Not the way the person who built it sees it, and definitely not the way the brochure describes it.

Thirty-three years in enterprise technology later, twenty of them running computer operations at Trader Joe’s, that habit has never stopped paying. It is also the reason I find most home security advice close to useless. It describes products. It does not describe how anybody gets in.

How does a company with cameras and card readers still get breached?

The company had spent thousands on card readers, security cameras and alarm systems. Every door logged every entry. Every corridor was covered. On paper it was excellent.

An employee got tired of digging his badge out every time he stepped outside for a smoke break, so he propped the door open with a brick. That was the whole breach. Everything upstream of that door became decoration.

I have thought about that brick for years, because it is the shape of nearly every failure I have seen since. The technical controls were fine. The seam was a person doing something reasonable to make his day slightly easier.

Criminals know this better than most security professionals do. They do not build attacks around beating your antivirus. They build attacks around what you already know and keep postponing. You know you should install that update. You keep clicking remind me later, because you are busy and it will restart your machine and you have things to do.

What does an ordinary neighborhood look like from the attacker’s side?

Some years ago I drove through a suburban neighborhood with a laptop running network scanning software. Not doing anything, just looking, the way somebody who wanted in would look.

In twenty minutes I found 127 home networks still using their default passwords and 43 with no password at all. Dozens of routers had not been updated in years. Any teenager with ordinary computer skills could have been inside most of those houses’ internet connections that afternoon.

None of those families thought of themselves as targets. That is precisely why they were easy ones.

I ran a version of the same test at a cybersecurity conference, a room full of people who do this for a living. I set up a wireless network called Free Conference WiFi and left it running. Within an hour I had captured login credentials from seventeen different smart devices, because their owners’ phones had connected automatically and the devices had followed. Most of those people had no idea their gear hands over credentials to anything that looks familiar enough.

How many connected devices are in your house right now?

I counted the devices using my own internet connection once, expecting maybe fifteen. There were 47. Phones, tablets, computers, smart speakers, security cameras, thermostats, the refrigerator.

I had bought every one of them separately, over several years, each for its own reason. At no point did I sit down and design a network. It assembled itself out of individual purchases that each made sense on their own.

Most families are somewhere between 25 and 60 devices without ever having counted. Each one contains a computer more capable than the systems that ran entire corporations in the 1980s. Each one talks to servers belonging to companies you have never heard of.

The strangest one I have found belonged to a family who called me about mysterious activity on their router. We checked every computer, every phone, every obvious smart device, and found nothing. It turned out to be their two-year-old microwave. It had never been set up for internet access, so it had quietly attached itself to a neighbor’s unsecured network and was phoning the manufacturer every night.

You cannot protect an inventory you have never taken. That is the first real step, and almost nobody does it.

The book on this: Family Cybersecurity is 231 pages on protecting a household instead of a company: the devices, the habits, the backups, and the conversations with the people you live with.

Does paid security software protect you better than the free one?

I ran a comparison of Windows Defender against four commercial antivirus products. Defender detected 99.2 percent of the malware samples, had the lowest false positive rate of anything tested, and used less memory and processor than most of the paid alternatives. The free thing already on the machine outperformed the subscriptions.

That is not an argument against paying for security. It is an argument that the money is usually going to the wrong place. The spend feels like protection. The dull maintenance is the protection.

A small business owner I know of postponed his updates for three months because restarting interrupted his work. Criminals eventually exploited a vulnerability Microsoft had patched two months earlier. The attack encrypted everything and the ransom demand was fifty thousand dollars. He paid it and never received working decryption keys. Three years of customer records, gone, and the business rebuilt from nothing.

Ten minutes of restart, spread across three months, against the whole company. That is the real exchange rate, and it never feels like that in the moment.

Why do so many breaches start with somebody being helpful?

A family I helped donated an old computer to a charity. They had deleted their files first and believed it was clean. Deleting is not erasing, and whoever bought that machine from the charity recovered five years of tax returns, bank statements and personal photographs. The identity theft that followed cost them fifteen thousand dollars and two years of credit repair.

Nothing technical failed there. They did a generous thing and did not know that the delete key is a suggestion instead of a instruction.

Even my own network taught me this one. I noticed a gaming console connecting at three in the morning, every night. It was my neighbor’s teenager, who had guessed my WiFi password and had been downloading games for months. He had consumed nearly half my monthly data before I looked.

What should you do first, and in what order?

If you take one thing from this, take the order. Most people start with the most visible step instead of the most effective one.

Count your devices. Open your router’s admin page and look at the list. You will find things you forgot about and probably something you do not recognize. That list is what you are protecting.

Change the router’s default password. Then check when it was last updated. This is the front door and it is the one people skip.

Turn on automatic updates and stop postponing them. The restart is the price. It is a low price.

Back up the things you cannot replace, and keep one copy somewhere that is not attached to your network. Ransomware encrypts what it can reach.

Talk to the people you live with. Every technical control in your house runs through somebody’s judgment at some point. The brick is always a person, and the fix is a conversation instead of a purchase.

None of that is exciting and none of it costs much. That is rather the point. The professor who caught me in 1981 was right about the method: look at your house the way somebody trying to get in would look at it. What you find will be duller and more fixable than you expect.

The Guides That Get Your Book Written, Published, and Sold

Four short, practical guides on writing, publishing, and selling your book, plus the occasional note when there's something worth your time. No fluff, no daily inbox clutter. Drop your email and they're yours.

We use MailerLite to manage our list and send these emails. Your address is used only to send you what you signed up for. We will not sell it, share it, or use it for anything else, and you can unsubscribe anytime.

Frequently Asked Questions

What is the first thing I should do to secure my home network?
Take an inventory. Open your router’s administration page and look at what is connected. Most households have between 25 and 60 devices and have never counted them. You cannot protect a list you do not have, and the list usually contains at least one surprise.
Is free antivirus good enough?
For most households, yes. In a comparison against four commercial products, Windows Defender detected 99.2 percent of malware samples, had the lowest false positive rate, and used less memory and processor than the paid alternatives. The bigger gains come from updates and backups instead of from a subscription.
Why do security updates matter so much?
Because most successful attacks use vulnerabilities that were patched weeks or months earlier. One small business owner postponed updates for three months, lost everything to ransomware, paid a fifty thousand dollar ransom and never received working keys. The patch had been available for two months.
Is deleting files enough before I give away a computer?
No. Deleting removes the pointer, not the data. A family who donated a computer after deleting their files had five years of tax returns, bank statements and photographs recovered from it, leading to fifteen thousand dollars of identity theft. Use secure erasure software, or physically destroy the drive.
Do smart home devices really pose a risk?
They do, and often quietly. At a conference I set up a network called Free Conference WiFi and captured credentials from seventeen smart devices within an hour. One family’s two-year-old microwave had attached itself to a neighbor’s unsecured network and was contacting the manufacturer nightly.

📁︎ Behind the Book📁︎ Cybersecurity📁︎ Security📁︎ Technology

🏷︎ Family🏷︎ Home Security🏷︎ Passwords

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

Leave a Reply

Your email address will not be published. Required fields are marked *