Who can I hire to hack me?
shkspr.mobi
shkspr.mobi
His goal was to make himself relatively anonymous in the real world and scrub his (actual) personal info from public/for-sale databases. And while he didn't hire anyone to pentest his digital identity, he did hire a PI to try and find him.
To make sure he didn’t make any mistakes, Mr. Lopp paid private investigators to try to find him. It was an investigator who helped him figure out that his D.M.V. registration was making him vulnerable, which led him to getting a decoy address.
Maybe ir differs state to state?
The niche market of folks with enough security-savvy to know they need the services of a pen tester is pretty small. That said it's also a pretty wealthy niche, so a boutique "personal security coach" business could probably thrive.
I already know of a company that was hacked due to an email exploit. So they cleaned things up and gave employees specific training. Then six months later they launched their own email attack, something like ten percent of their employees failed that test!
(Seems like tallpoppy is focused on harassment)
Shouldn't we have the right to know or be able to check how secure our data and identity is on these services?
It's not a crime that is routinely prosecuted (at least not in the US; there are horror stories from the UK). But that doesn't mean it's safe to build a business around that activity.
(To be clear: I'm saying this about general security testing, not taking over someone's account who's paid you to do so. That's not criminal, just sort of unethical.)
> you do not
I don't think this answers the question. Of course unsolicited pen testing is already illegal; that's not an interesting question imo. What I'm more curious about is security industry opinions about whether or not the current law is a good idea.
Are there any changes you would make to the law if you had the ability to do so, or do you see a more general danger in allowing customers to attack their own accounts?
Apart from an obvious black list you are looking at a world of pain both by the bank's lawyers AND the authorities. It may be YOUR money but tampering with a bank's systems is very much criminal activity in most countries.
Judge: who gave you the right to invite someone to hack a company's e-banking security process or Facebook's security processes?
You: it is my data
Judge: it is THEIR system, see you and your friend in 5-to-10 (or whatever the penalty is in whichever country)
If they don't, I feel there's a rather lopsided situation.
I was talking to a guy who provides online security services for financial institutions. I asked him what happens when someone loses money due to a hack. I found his response amusing and horrifying.
“When someone breaches your online account and steals money, if the amount is $50, the bank will restore it at their expense to keep you happy as a customer. If the amount is $50,000... well, the bank doesn’t care about having you as a customer that much.”
The bank will seek to see who/what was at fault. If you handed someone your passwords etc, they carry no responsibility and kiss that 50k goodbye. Your pin/passwords are yours and yours alone. You should protect them. At least in the UK there have been plenty of cases were people were tricked to hand in their passwords. They never got anything back from the banks.
If someone breaks in physically and steals the contents of your safety deposit box they will hunt-them-down. If you come forth and you say "I know who it was, I helped him/her as part of a pen-test" then you are going down with them.
Two factor using something like Google Authenticator? Nope.
Two factor using a less-secure text messsge? Rarely.
An email asking for secondary confirmation when logging in from a new device or IP address? Forget it.
A history within my account that shows all logins and login attempts, along with the request IP address and location? I wish.
I’m sure banks do stuff behind the scenes to secure my account. But it seems they could do a lot more to empower me to help in the process. I understand that it’s difficult to pin the blame on a bank for a password stolen by a virus a customer picks up that had nothing to do with them. But it seems they’d do a whole lot more to help me protect my account.
I’m generalizing, I know, but I find it comical (and frustrating) at how often I see banks attempt to do things in the name of security that don’t help at all, but go a long way to destroy UX, or even decrease security.
- Prevent paste on the password field.
- Security questions, often with ridiculous questions.
- “Security” phrase and image.
- Shocking password restrictions.
For Firefox users, I use "don't f... with paste" addon. It works like a charm.
Those are the services for "ordinary people". The thing is, they advertise to celebrities & CEOs because there aren't many people willing to pay for pentesting. That will always be an expensive service, since it by definition requires highly-skilled employees. A service that advertises to celebrities would almost certainly be willing to work with an ordinary individual, but how many people are willing to pay for the service? Certainly not enough for this to be a million-dollar idea.
The tester would be taking on legal risk for performing any kind of account takeover.
Consequently, I don’t see this as a viable service offering.
This is not actually the best way. For some services eventually you get to a person in a call center who can actually check those security questions to perform a password reset (when all else fails). Having a random string opens the door for someone to claim "oh I think I put something random in there, I really forgot what" and it's likely they'll pull it off. Especially if the hacker knows (somehow[0]) that you put a random string there and it's exactly 32 characters long.
Just go with a plausible name that's still not straightforward to guess.
[0] You may blog about it... Or discuss it loudly and is overheard.
I go another step and do not keep that recovery answer once put into the form. Does wonders to make sure everything else does not fail.
In your scenario the service is already broken and the door is wide open no matter what you choose as the recovery answer.
You'd be safer with this assumption anyway. But again, after telling the whole internet you're using random 32 character strings for that it's likely that you just lowered the bar a little for social engineering. It is easier than you think to call a call center and convince someone to perform a password reset or a SIM porting (for hijacking). At least don't give them another plausible avenue.
One thing to consider is the password manager generated security questions. Half the customer service agents out there will accept "it is just a bunch of random characters i typed". Security questions should go the "correct horse battery staple" route.
While some services are secure, without testing it isn't safe to assume that any particular service is. And even with testing, it can vary depending on the particular CSA. So in general, I don't think this is a good idea, since there is no way of knowing if any particular service will be secure.
Here in the UK, it seems that most reputable organisations are GDPR conscious. I've deliberately got my birthday slightly wrong to see what they do - 100% of the time they refuse to proceed.
Perhaps I'm just lucky.
Is this service available to public figures like:
* John Podesta (of the US Democratic National Committee, phishing target)
* John Brennan (former CIA director, whose AOL account was pwnd by teenagers while he held that job)
Of course it is. But these sorts of powerful people always think somebody else is the target.
Mr. Eden's proposal is a good one. Too bad such a business would need more lawyers than pentesters.
You’re aware that Mr Podesta flagged the email as being suspicious, sent it to their security person, and was given the all clear before following it?
It's amazing how those people don't really have much clue about it all. Imagine who's not in the tech field.
I had the same idea at the time. I am not sure if people would pay for such service, but they definitely need it.
For the average person, the main threats are various forms of social engineering, mostly the kind that is really obvious to anyone who has a rough idea how security works ("This is a secure document, please click yes when it asks you to allow this document to execute arbitrary code"), and software so far out of date that common exploit kits have pre-packaged exploits.
But I think in most countries you would still be liable to Google/FB etc if the attack gets detected and linked to you.
You could also hide a bounty somewhere (e.g. in an email, in a private Github repo, etc.).
You don't even need to mention this is your account, e.g. "I want the email password of X for Y bitcoins".
Both solutions comes with its own issues, but I don't think there is a legal way to do a full pentest.
I'm sorry to be harsh on this person but this is quite a dumb post. What is the difference between hacking a celebrity vs an ordinary person? None.
Any penetration testing / security consultancy will be able to do what you're asking for, provided you can pay their rate.
> Does this service exist? If not, is this a million-dollar start-up idea?
No it is definitely not a million-dollar startup idea. It also wouldn't be a startup it would be a consultancy. Penetration testing firms can easily charge clients up to around $1000 / day. How many individuals are going to pay multiples of $1000 to see how secure their online data is?
If you're a company and the SaaS provider is of similar or small scale you might be able to work with them if you have special security concerns that exceed their regular customer base. You could maybe even get them to hire a consultancy to check or recheck their services but in no case would you ever just go out and do that of your own volition.
Independent of that, even in a personal context, people use SaaS providers because they trust their ability to do a certain job better and/or cheaper than you could do yourself. That usually includes the factor of securing their data, if only because it's in their best interest not to have PR disasters and lose customers.
So any company claiming to provide such service is either not doing so legally or (more likely) limiting their activities to various passive approaches and not attempting to actually pentest/social engineer access to your accounts in ways like an actual attacker would; so they're implying that they provide a better, more serious service than they actually do.
https://aws.amazon.com/security/penetration-testing/
https://www.microsoft.com/en-us/msrc/pentest-rules-of-engage...