this post was submitted on 21 Nov 2024
22 points (100.0% liked)

Cybersecurity

5722 readers
141 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] ulterno@programming.dev 2 points 9 hours ago

I'm guessing the ransomware gangs would be giving better payments than regular companies asking for pen-testing.

But with this, comes other concerns:

  • Will the pen-tester be enticed to use the "authorised hacking" as an opportunity to install a backdoor of their own or do they maintain strict borders between both jobs?
    • I'm thinking, not so much, as, if they're already doing something illegal, they might as well just go the extra mile.
  • At the same time, pen-testers working for one company might also be used for industrial espionage efforts, by competitors