Not only are they making a point about how terrible security is ("Do you think every hacker announces everything they've hacked?"), but they've also called out the internet on its generally abysmal attention span. I wouldn't be surprised if they'd had this written on day zero.
Neither of these are novel concepts: we've heard about abysmal internet security (FireSheep) and low attention spans (Nicholas Carr[0, 1] and Jonah Lehrer[2]) repeatedly over the last couple of years.
This release may seem profound to you, but LulzSec proposes no solutions to the problems they're creating. They're too nihilistic to put on white hats, and they deserve none of your praise as a result.
The difference is that LulzSec managed to get their word on every tech blog in the world. They also managed to get their basic message - nothing is safe, and here's proof - onto nearly every single major news site in existence, and they made their message immediately and personally important to millions of people. That's why I'm praising them. They don't need to propose a solution; that's already been done. They don't need to have a new message; extant messages are good enough. What they bring to the party is visibility.
Do published books and articles in The Atlantic, Wired, and NYT not work for you? Those are a few of the news sites that have covered declining attention spans.
As for internet security--anyone who can do something about it already knew there was a problem. On the consumer end, what are users supposed to do? Add symbols to their passwords? That would delay GPU- or SSD-based brute force techniques by, what, 10 seconds?
An article on Wired gets read and forgotten. An article about passwords in the NYT gets dismissed as "newfangled kids". Ten million credit cards stolen - one of which is yours - gets remembered. Having your FB account manually and maliciously defaced changes your life. That's visibility that no article or book can sell.
Consumers are supposed to start using tools like KeePass or LastPass. Adding symbols to a simple 6-character password doesn't help. Adding symbols to a high-entropy 20-character password and never using a password twice makes you basically immune to this kind of thing.
On the consumer end - what needs to be done is a massive education campaign, kept reasonably simple. It was done in 2000-2003 for anti-virus and it (roughly) worked for the 80% or so of the Windows world that did what they were told (by the mainstream press).
The mainstream press has (so far) done a terrible job on password education. You see long lists of rules that nobody but a security professional or hacker would follow. It needs to be boiled down to something simple, like:
Use a password manager to assign unique, random 15 character passwords for all accounts, protecting them with a strong master password.
I put together a guide based on this concept here:
Neither of these are novel concepts: we've heard about abysmal internet security (FireSheep) and low attention spans (Nicholas Carr[0, 1] and Jonah Lehrer[2]) repeatedly over the last couple of years.
This release may seem profound to you, but LulzSec proposes no solutions to the problems they're creating. They're too nihilistic to put on white hats, and they deserve none of your praise as a result.
[0] http://www.theatlantic.com/magazine/archive/2008/07/is-googl...
[1] http://www.amazon.com/Shallows-What-Internet-Doing-Brains/dp...
[2] http://scienceblogs.com/cortex/2010/04/attention_and_intelli...