Latest
What an AI Detector Score on Your Manuscript Is WorthThe One-Hour Call Before I Quote Your BookWhen a Client Thinks the Ghostwriter Used AIMonthly or Milestone: How Ghostwriting Gets BilledWhen Your Memoir Should Be a NovelWhat It Costs to Fix an AI-Written ManuscriptThe Clients Who Pay and VanishThe Quotation Marks That Get Authors SuedThe Work You Would Never Have StartedWhen Your Own Memoir Sounds Like BraggingWhat Belongs on a Copyright PageThe Hugging Face AI Agent Attack: An Operations ReadingBehind the Book: The Mysterious Island, Neb’s SideHow to Organize Decades of Memories Into a MemoirWhy Rotten Tomatoes Sucks: The Score Does Not Mean What You ThinkWhy Amazon KDP Sucks: They Terminated My Account OvernightIngramSpark: How I Publish Now and WhyWhy Fiverr Sucks for Ghostwriting: The Buyer’s SideWhy eBay Sucks Now: A Seller’s Numbers and a Buyer’s WarningThe Ghost Story TraditionThe Gothic TraditionThe Christmas Ghost Story TraditionResurrection as a Narrative StructureBooks to Give a WriterThe Beach Read ArgumentWhy It’s a Wonderful Life Failed on ReleaseWhat to Read in SpringWhat to Read in SummerWhat to Read in OctoberHow Warner Bros. Dismantled a $17 Billion Cartoon EmpireThe Imaginary Scarcity TrapThe Graph That Goes Vertical Is Usually Somebody Else’sSubstack Is Not Collapsing. The Promise Was.The Disasters That Happen to Ordinary PeopleToba: The Winter That Almost Ended UsJay Stifflemire: Nothing Ever Gets Written DownGeorgie-Ann Getton: I Forgot I Had Free WillAI Detection Cannot Be Evidence, and Publishing Is Using It That WayAI Consciousness Left Philosophy and Entered the LaboratoryThe Office Block Where the Bedrooms AreThe Web Got Fenced: What AI Search Costs Small SitesBlack Tuesday: The Web Ring War Nobody Outside It NoticedWhat the AI Visibility Industry Sells, and What the Evidence SaysBlack Tuesday: The Original ring-master.net Page, 2000Behind the Book: Peacekeeper, The Dissolution WarsBehind the Book: Real World SurvivalBehind the Book: Publish Your BookBehind the Book: ReincarnationBehind the Book: Sell Your BooksBehind the Book: Show Don’t Tell
The Writing King Your Ethical Ghostwriter. Your Story, Done Right.

I Got Caught Hacking in 1981. The Professor Made Me Head of Security.

This entry is part 16 of 39 in the series Technology
TL;DR: Home security does not fail at the technical seam. It fails at the human one. A company with card readers, cameras and alarms lost everything to a brick propping a door open for smoke breaks. Your house has somewhere between 25 and 60 connected devices you bought one at a time, and the defenses that work are the dull ones you can keep doing.

In 1981 a college professor caught me trying to break into the school’s computer system. He didn’t suspend me. He said, since you hacked our computer, you’re now in charge of system security, and handed me the job.

That was the most useful thing anyone has ever done for my career, and not because it taught me about computers. It taught me that the only reliable way to protect a system is to look at it the way somebody trying to get in would look at it. Not the way the person who built it sees it, and definitely not the way the brochure describes it.

Thirty-three years in enterprise technology later, twenty of them running computer operations at Trader Joe’s, that habit has never stopped paying. It’s also the reason I find most home security advice close to useless. It describes products. It doesn’t describe how anybody gets in.

How does a company with cameras and card readers still get breached?

The company had spent thousands on card readers, security cameras and alarm systems. Every door logged every entry. Every corridor was covered. On paper it was excellent.

An employee got tired of digging his badge out every time he stepped outside for a smoke break, so he propped the door open with a brick. That was the whole breach. Everything upstream of that door became decoration.

I’ve thought about that brick for years, because it’s the shape of nearly every failure I’ve seen since. The technical controls were fine. The seam was a person doing something reasonable to make his day slightly easier.

Criminals know this better than most security professionals do. They don’t build attacks around beating your antivirus. They build attacks around what you already know and keep postponing. You know you should install that update. You keep clicking remind me later, because you’re busy and it’ll restart your machine and you have things to do.

What does an ordinary neighborhood look like from the attacker’s side?

Some years ago I drove through a suburban neighborhood with a laptop running network scanning software. Not doing anything, just looking, the way somebody who wanted in would look.

In twenty minutes I found 127 home networks still using their default passwords and 43 with no password at all. Dozens of routers hadn’t been updated in years. Any teenager with ordinary computer skills could have been inside most of those houses’ internet connections that afternoon.

None of those families thought of themselves as targets. That’s precisely why they were easy ones.

I ran a version of the same test at a cybersecurity conference, a room full of people who do this for a living. I set up a wireless network called Free Conference WiFi and left it running. Within an hour I’d captured login credentials from seventeen different smart devices, because their owners’ phones had connected automatically and the devices had followed. Most of those people had no idea their gear hands over credentials to anything that looks familiar enough.

How many connected devices are in your house right now?

I counted the devices using my own internet connection once, expecting maybe fifteen. There were 47. Phones, tablets, computers, smart speakers, security cameras, thermostats, the refrigerator.

I’d bought every one of them separately, over several years, each for its own reason. At no point did I sit down and design a network. It assembled itself out of individual purchases that each made sense on their own.

Most families are somewhere between 25 and 60 devices without ever having counted. Each one contains a computer more capable than the systems that ran entire corporations in the 1980s. Each one talks to servers belonging to companies you have never heard of.

The strangest one I’ve found belonged to a family who called me about mysterious activity on their router. We checked every computer, every phone, every obvious smart device, and found nothing. It turned out to be their two-year-old microwave. It had never been set up for internet access, so it had quietly attached itself to a neighbor’s unsecured network and was phoning the manufacturer every night.

You cannot protect an inventory you have never taken. That’s the first real step, and almost nobody does it.

The book on this: Family Cybersecurity is 231 pages on protecting a household instead of a company: the devices, the habits, the backups, and the conversations with the people you live with.

Does paid security software protect you better than the free one?

I ran a comparison of Windows Defender against four commercial antivirus products. Defender detected 99.2 percent of the malware samples, had the lowest false positive rate of anything tested, and used less memory and processor than most of the paid alternatives. The free thing already on the machine outperformed the subscriptions.

It’s an argument that the money is usually going to the wrong place. The spend feels like protection. The dull maintenance is the protection.

A small business owner I know of postponed his updates for three months because restarting interrupted his work. Criminals eventually exploited a vulnerability Microsoft had patched two months earlier. The attack encrypted everything and the ransom demand was fifty thousand dollars. He paid it and never received working decryption keys. Three years of customer records, gone, and the business rebuilt from nothing.

Ten minutes of restart, spread across three months, against the whole company. That’s the real exchange rate, and it never feels like that in the moment.

Why do so many breaches start with somebody being helpful?

Why breaches start with somebody being helpfulA family donated an old computer to a charity, having deleted their files first and believing it was clean. Deleting is not erasing, and whoever bought that machine from the charity recovered five years of tax returns, bank statements and personal photographs. The identity theft that followed cost fifteen thousand dollars and two years of credit repair. Nothing technical failed. They did a generous thing without knowing that the delete key is a suggestion instead of an instruction. The same lesson turned up on a home network, where a gaming console connecting at three in the morning every night turned out to be a neighbour teenager who had guessed the WiFi password and consumed nearly half a month of data before anybody looked.Why the breach started with a kindnessNothing technical failed. Delete is a suggestion, not an instruction.1A generous actAn old computer donated to charityFiles deleted first, believed clean2Deleting is not erasingThe data was still on the driveand the drive was sold on3Five years recoveredTax returns. Bank statements.Personal photographs.4The cost$15,000 and two years of credit repairfrom doing something kindNothing technical failed here. The failure was in what nobody had been told.
Why breaches start with somebody being helpfulA family donated an old computer to a charity, having deleted their files first and believing it was clean. Deleting is not erasing, and whoever bought that machine from the charity recovered five years of tax returns, bank statements and personal photographs. The identity theft that followed cost fifteen thousand dollars and two years of credit repair. Nothing technical failed. They did a generous thing without knowing that the delete key is a suggestion instead of an instruction. The same lesson turned up on a home network, where a gaming console connecting at three in the morning every night turned out to be a neighbour teenager who had guessed the WiFi password and consumed nearly half a month of data before anybody looked.Why the breach started with akindnessNothing technical failed. Delete is a suggestion,not an instruction.1A generous actAn old computer donated to charityFiles deleted first, believed clean2Deleting is not erasingThe data was still on the driveand the drive was sold on3Five years recoveredTax returns. Bank statements.Personal photographs.4The cost$15,000 and two years of credit repairfrom doing something kindNothing technical failed here. The failure was inwhat nobody had been told.

A family I helped donated an old computer to a charity. They’d deleted their files first and believed it was clean. Deleting isn’t erasing, and whoever bought that machine from the charity recovered five years of tax returns, bank statements and personal photographs. The identity theft that followed cost them fifteen thousand dollars and two years of credit repair.

Nothing technical failed there. They did a generous thing and didn’t know that the delete key is a suggestion instead of an instruction.

Even my own network taught me this one. I noticed a gaming console connecting at three in the morning, every night. It was my neighbor’s teenager, who had guessed my WiFi password and had been downloading games for months. He’d consumed nearly half my monthly data before I looked.

What should you do first, and in what order?

If you take one thing from this, take the order. Most people start with the most visible step instead of the most effective one.

Count your devices. Open your router’s admin page and look at the list. You’ll find things you forgot about and probably something you don’t recognize. That list is what you’re protecting.

Change the router’s default password. Then check when it was last updated. This is the front door and it’s the one people skip.

Turn on automatic updates and stop postponing them. The restart is the price. It’s a low price.

Back up the things you cannot replace, and keep one copy somewhere that’s not attached to your network. Ransomware encrypts what it can reach.

Talk to the people you live with. Every technical control in your house runs through somebody’s judgment at some point. The brick is always a person, and the fix is a conversation instead of a purchase.

None of that is exciting and none of it costs much. That’s rather the point. The professor who caught me in 1981 was right about the method: look at your house the way somebody trying to get in would look at it. What you find will be duller and more fixable than you expect.

Frequently Asked Questions

What is the first thing I should do to secure my home network?
Take an inventory. Open your router’s administration page and look at what is connected. Most households have between 25 and 60 devices and have never counted them. You cannot protect a list you don’t have, and the list usually contains at least one surprise.
Is free antivirus good enough?
For most households, yes. In a comparison against four commercial products, Windows Defender detected 99.2 percent of malware samples, had the lowest false positive rate, and used less memory and processor than the paid alternatives. The bigger gains come from updates and backups instead of from a subscription.
Why do security updates matter so much?
Because most successful attacks use vulnerabilities that were patched weeks or months earlier. One small business owner postponed updates for three months, lost everything to ransomware, paid a fifty thousand dollar ransom and never received working keys. The patch had been available for two months.
Is deleting files enough before I give away a computer?
No. Deleting removes the pointer, not the data. A family who donated a computer after deleting their files had five years of tax returns, bank statements and photographs recovered from it, leading to fifteen thousand dollars of identity theft. Use secure erasure software, or physically destroy the drive.
Do smart home devices really pose a risk?
They do, and often quietly. At a conference I set up a network called Free Conference WiFi and captured credentials from seventeen smart devices within an hour. One family’s two-year-old microwave had attached itself to a neighbor’s unsecured network and was contacting the manufacturer nightly.

📝 Disclaimer

The views and opinions expressed in this blog post are solely those of Richard Lowe and are based on personal experience and research. This content is for informational purposes only and should not be construed as professional legal, financial, accounting, or business advice. Always consult with qualified professionals before making important business or legal decisions. Richard Lowe is not a lawyer, accountant, or licensed professional advisor, and this content does not establish any professional relationship.

0 comments

No comments yet. Yours can be the first.

Was this useful?

Leave a comment