One of those kids was wondering around the exact floor where my desk was. I got a job and career out of it, these kids got jail time and one suicide. Geez.
One of those kids was wondering around the exact floor where my desk was. I got a job and career out of it, these kids got jail time and one suicide. Geez.
I personally doubt whether one wants to be a productive member of a society that put one into jail.
I agree with the mind of this statement. The problem is: For lots of such skills, it is hard to find jobs where these are needed (for example reverse engineering). Based on my personal observation, to stay in the example, there exist much more skilled reverse engineers than jobs where these skills are useful/needed.
I know lots of examples where this is the case (I am talking about Germany, where the situation might be a little different, but I do not believe that the difference is too large).
I know some really great reverse engineers who have difficulties to find a decent job (they get through with some badly paid jobs that are far below their skills).
I can assure that I have hardly ever seen a job ad where reverse engineering (as in software) skills are even mentioned. And I openly admit that I (who also have some knowledge in reverse engineering) would not even know where to ask/look for a job that gratifies such skills. Be assured that I would have passed on such job hints if I knew of any.
In my observation the whole "IT security" scene (I am aware this is a somewhat different area than reverse engineering) is a close-knit circle that is hard to get into. If you are able to get into, I have strong evidence that the salary is actually rather good. But I have no idea how to get into the inner circle where the job offers await.
Seriously: I have some colleagues who even asked me with my knowledge about security why I do not get into this the field of activity of IT security. I tell them to give me hints how to get into this inner circle where the interesting job offers await. None of these loudmouths could tell me. Of course...
EDIT: I could go on and on. The statements stay the mostly the same all the time: Where can such a person find job offers?
I will not disagree. But I am explicitly talking about reverse engineering as in the original article (i.e. mostly software and to a lesser (but not less important) sense electronics).
I do not know enough details about the other segments that you mention to make deep statements about them. But I am pretty confident in my opinion that the kind of skills that you require for them are really different from those that you need for software/electronics reverse engineering. What I want to say with this: The skills that you need for hacking an XBox (as in the article) do hardly ever transfer to any of your examples (bomb squad detectives, Root cause analysis experts, market/competition research, Prototyping, NTSB agent).
In my opinion/experience, finding loopholes/security bugs in an existing system and designing systems that are unprone to security bugs are two very distinct skills. It is quite imaginable that many people that people who work in the branch become good at both, but being good at one of them does not make you good at the other.
EDIT: The only kind of knowledge that comes spontanously to my mind that transfers well between both areas is having an immense amount of obscure knowledge about weaknesses in lots of protocol designs.
See, its a progression not a dichotomy. A hacker possesses only a subset of a truly skilled security programmer. And the security programmer always has home field advantage. As a hacker becomes more seasoned, they learn more and more about the system until they reach the level of the security programmer or the person implementing all the locks and keys
Indeed. For this one loves to build mathematical models, formulate security properties, make proofs, think deeply about the limits of the formulated models (e.g. tempest attacks, cache timings etc. which might introduce side channels) etc.
Finding exploits is quite a different job: Here you very often have lots of legacy systems which have an architecture that is hard to make secure. To give an example: A parser for a very complicated and ill-specified file format where mistakes can easily lead to catastrophes (for example because the format allows to embed "executable scripts" that are run in a JIT-based virtual machine). So you look for loopholes in an often badly designed or at least complex and thus error-prone system and think about how you can exploit these mistakes in a clever way.
I am very sure that both can be very exciting jobs, but they are in my opinion quite different in nature.
> If I am an expert an building impenetrable servers, then I must know how to penetrate servers since I've added patches to block all known attacks. How could I do that without first being a hacker?
I think the essential difference is that if you are an expert in building impenetrable servers, you simply avoid lots of design decisions that are prone to security problems (to stay in my explanation above: these also typically have the property that they can be specified rather well formally). On the other hand, if you want to penetrate servers, you need creativity to turn "suspicious looking design decisions/oversights" into working exploits.
So being an expert in building impenetrable servers will not make you good in penetrating servers: Knowing what design decisions are hard to keep in control security-wise does not (necessarily) give you the knowledge about how to concretely exploit them. On the other hand: Having a strong creativity for how one can in practice exploit oversights does not (necessarily) make you a good engineer for systems that are hard to exploit.
The coder oversights wont be there because that seasoned expert once exploited someone else like that and knows where to defend. There is such a thing as 100% secure code. Although instances of it are very small. My point is, you get to be so good at building defenses because youve seen so many offenses and know what to expect and how to counter.
> Of course, they do! Reverse engineering is the skill of being able to see how things are put together without having the whole picture.
I disagree and have done quite some reverse engineering out of private interest. To me it was mostly about learning and applying an excessive amount of knowledge about obscure trivia that can hardly be applied anywhere else (except perhaps for some really rare embedded developing stuff), such as knowledge about some obscure flags in the linker format, knowledge about aracane details of the call convention and instruction encoding, arcane features of the respective CPU/chipset that probably only OS developers are even aware of, etc.
This is what > 90% of reverse engineering consist of for me: Learning/having/applying an immense knowledge of a giant amount of arcane details that are hardly useful anywhere else.
> It's having an intuition of where to find the clues to solve the bigger puzzle.
I am not aware that I have used a lot of intuition. It is rather a lot about documenting everything well, documenting how each subsystem/function relates to others, ... lots of long, monotonous (but not boring) documentation. The reasons is that if you do not document a lot, you will soon be struck by the immense amount of details. A little bit like how you would document the inner workings of a space ship that landed on earth exhaustively in terms of lots engineering diagrams.
If someone were looking to join the easiest way would be find a conference near you. In the US pretty much any major city has these, but in other countries I'm sure they are just as common. Some are very professional, some are less so. If there is copious amounts of drinking you're at the right place. Generally the smaller the conference the better, so that also means less advertising and harder to find
Lots of different InfoSec groups go to meetups so at that point just talk to as many people as you can, it might seem difficult to break into a group without anyone to vouch for you but most of the time everyone is open to newcomers
When you say "IT security" do you mean pentesting? Access management? Network security? ISO 27001 auditing? Working with any of the many security-related software suites around?
If you really were not doing any real harm (where I believe you), why didn't you become an activist to abolish/change the laws on which you were cease and desisted?
Also I was 17 and I imagine I was more easily intimidated.
My old watering hole used to get them from Archie Comics and ended up changing their name to avoid the (legal) usage of a trademarked name, mostly because they didn't want to spend the money to prove they were in the right.
They did not attempt to let the targeted companies know so they could improve their security. They were hacking for profit.
See: https://en.wikipedia.org/wiki/Copyright_and_Related_Rights_R...
In my observation, this is a branch of industry that is very hard to get into.
> You could essentially be paid by companies to hack their own product entirely legally for the purpose of better securing it against potentially malicious hackers.
For this purpose, one uses quite different techniques than for blackhat hacking. E.g. in the whitehat case, the source code is often available etc.. So brutal code reviews, which require rather different skills (e.g. knowing all the subtle details of the language standard (e.g. C/C++)), are much more effective to secure applications than using the typical "blackhat techniques" (reverse engineering, knowing subtle details of CPU behaviour etc.).
There are some who work in reverse engineering, CPU interactions or static analysis but those are often more senior positions within a company, are more research focused or specifically marketed as such; my role as a pentester is focused on dynamic testing from a blackbox perspective. Sometimes we are lucky to have architecture diagrams, API docs, or source code but they only serve to benefit the test from an external perspective. I don't analyze the code and report vulnerabilities there, I report findings from a perspective of breaking the application in runtime; the code only makes that easier.
Anyone here wishing to break into security to "be a hacker" might find web app pentesting to be the most familiar for developers (it's not far from skills used for UAT, QA and debugging) and provides a pathway down the OSI model. There are companies that will take strongly motivated and technical people to train into pentesters, as the field is vastly understaffed and it's easier to train someone on your methodology from day 1. However, this normally starts as Web App (it's where the money and clients are) and one can move into other areas over time.
I'm more than happy to provide more details or resources to those interested. My knowledge is more in the attacker area, but its possible to start in either side and pivot into the other. Time, patience, and a willingness to learn.
I know some people (myself included) who would work as consultant but have no idea how to even get hold of consulting jobs. Yes, I often ask people who are much much successful in getting those, how they got them. These successful consultants eventually admit that they themselves have no real idea. People just approached them etc. I (and lots of other people) are not the kind of people "that are simply approached".
TLDR: I would not even know how to start to get consulting jobs (and lots of people have a similar problem).
Disclaimer: I am talking about the situation in Germany. In the USA, it might be different.
First of all, forget about the "situation in Germany". Work is everywhere, so be willing to accept work anywhere. There's definitely a pecking order in consulting firms and you can get projects because the company gets a one off engagement with a new client who wants the work done on site. The company has some really awesome full time employees who could do it in their sleep, but they're busy on long term contracts with key clients. Be willing to go, as a subcontractor, to some unglamorous location for a week long project to pentest some shitty internal application that nobody has ever heard of. Get a few of those under your belt and you'll know how it works.
Second, understand that there's more to it than your technical skills. Make friends who work in the industry. Talk with them about what they're working on. Find any interesting bugs or behavior in what you're working on? Chat with them about that. Doesn't really matter if it's security related or not. The people who do the work in the industry are all generally interested in the details of software. If you're into that, then you belong.
Keep reminding your friends that you're hungry for work. Keeping in touch will keep you in mind when they need an extra guy to help out.
Once you start getting work be sure you contribute well. Everyone wants to have the most high severity findings, and obviously you will need to produce those if you wanna keep getting work, but also be that guy who goes the extra mile to help put the report together, write up extra recommendations that would be helpful.
Keep in touch with the people you work with. Be cool to the sales/project management/accounting people. It's simple things like getting your expenses/timesheets/invoices filed in a timely manner. There's more to the business than finding vulnerabilities. Everyone wants to close out the job, get paid, and move on. Show everyone that you know how to behave like a professional. Remember that the people responsible for staffing are asking themselves: Who do we know that we can send in there to take care of this work, so that we can bill them and collect this revenue, who will get the job done and be easy to work with?
Be that guy, and you will be approached too, and you can find full time work in the industry if you want.
I used to work at a company that did pentests (although I never did any myself). This was never the case. Every single one was approached in the same way an unprivileged attacker would approach it, apart from, when testing a production instance of an application:
- dummy accounts are set up, so that if user data must be extracted it doesn't come from real users
- you're not allowed to do anything that risks taking the application offline, destroying data, etc.
brandonjm wrote above (emphasis by me): "You could essentially be paid by companies to hack their own product entirely legally".
It would be a massive waste of time and ressources not to give the internal whitehead team any internal information possible to secure the application. For this I stand by my point that the methods that I stated are usually much more effective.
Pentesting is typically applied in very different scenarios (not a company hacking their own product as in brandonjm's scenario).
You are absolutely right about the massive waste of resources that holding back info causes. It's way better to give consultants complete control of a working test system with the full build environment. And they might as well just let you do it remotely. But many companies don't do that. Instead they would rather eat your travel and accommodation costs, and then when you show up you're being paid to sit around for a week because they don't even have things ready, so you sit around reading bullshit documentation so you look busy and your contact doesn't look bad. And when you finally do get something you spend lots of billable hours figuring out how to get it up and running, which provides absolutely no value to them and wasted valuable time you could have been finding bugs. But that's just how it goes.
That's not really an industry.
Pen. tester is, security researcher or implementer or auditor is, crime committer isn't.
The days of getting a career from unauthorized hacking into systems are over. That road leads to prison/death, as it should.
As it should?
English isn't my first language and I really hope you aren't suggesting that the one who does unauthorized hacking should die.
EDIT: I assumed good faith, according to the Hacker News guidelines. Apparently in this case I was wrong. I just read the GP's second, more in-depth, comment further down: he's absolutely in favour of prison and thinks that in some cases death may be warranted.
But I still don't understand how hacking is such a serious crime to be punished by death sentence.
In fact, there are very very few crimes which deserve death penalty.
The language was clear, its America that's at fault.