this post was submitted on 21 Nov 2024
23 points (100.0% liked)

Cybersecurity

5722 readers
104 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS
top 2 comments
sorted by: hot top controversial new old
[โ€“] ulterno@programming.dev 3 points 14 hours ago

I'm guessing the ransomware gangs would be giving better payments than regular companies asking for pen-testing.

But with this, comes other concerns:

  • Will the pen-tester be enticed to use the "authorised hacking" as an opportunity to install a backdoor of their own or do they maintain strict borders between both jobs?
    • I'm thinking, not so much, as, if they're already doing something illegal, they might as well just go the extra mile.
  • At the same time, pen-testers working for one company might also be used for industrial espionage efforts, by competitors

Wait, they weren't already? I guess I already assumed that many (most?) black hats were white hats in the daytime. You gotta get that knowledge from somewhere...