Cybersecurity as a socially conscious career choice for young hackers
forbes.com
forbes.com
The lesson: most kids who crack systems as a self-declared white hat will be punished, some will get lucky with job offers (that they never seem to accept at the end of the day - humm).
Like the elders were advising 10-20 years ago: don't bother with trying to play by the rules. Start your own consulting firm or just keep it to yourself.
Young Hamad shouldn't have done that, and would be fired from any job in cybersecurity for doing the same thing against a client's network without authorization.
When I was younger I tried to break into that world and it was pretty much impossible. Companies I contacted to notify them about their security flaws seldom replied (and when they did, it was never to thank me)
On the other hand, I could always find buyers for exploits in alternative markets, or credit card numbers, or rooted servers.
My moral compass prevented me from going too deep into that stuff, but I know people who ended up setting DDoS -for-cash services, etc. (and they/we were just kids !)
I get it that you're trying to sell courses here, but come on...
Certifications are often frowned upon by some of the better pen testers.
Programming skill will get you most of the way there. It is by no means impossible.
Now, this is only my experience, but I've never really seen all-rounded security people being valued in companies, apart from maybe small consultancies where getting a job is probably mostly governed by luck and being in the right place, at the right time :)
Certs can be important for contract/services work, so if you're looking at a company that bills people out to clients, and that would be your role, you'll probably needs certs, as some clients (e.g. government) require them.
If you're looking at joining an internal security team at a company -- even a big one like Visa or Intel -- the certs tend to be less important. Plenty of people, as you move up the management chain, have certs, but usually because the employer footed the bill.
My evidence is anecdotal, obviously, but everyone I know who's joined an internal security team got the gig based on skills and experience. None of them had certs. (And the offers I've received myself weren't based on certs, since I don't have any!)
Not quite true. Many massive sites offer rewards for finding vulnerabilities. Be sure you comply with their terms of service while doing so.
But don't hack other people. Bad things lay that way.
The high-schoolers are more hungry for information and more interested than the College CCDC team I work with (a very top team).
With that being said, there are so many outlets for these younger hackers to practice. CTFs everywhere on the internet, cyber challenges are all over the internet, and there is always something completely new to learn (Oh...you learned WebSec pretty well...but what do you know about exploit development).
The problem is we need more people who know what they are doing to work closely with the high school students and keep them focused and keep them exploring the discipline.
A bored student without Allen Pallers thing here will usually be a bored student with it. The CyberAces weekend in my state is in March. What are my high schoolers supposed to do until then if they are truly bored?
Want a socially conscious job that helps people? Don't pick a career where you track down holes in the dyke and report back their location to your corporate or government master. Pick a career where you build a better dyke (and don't hold people for ransom to use it)
Aside: i'd love to see these blatant advertisements-as-news-articles banished from the front page for good.