Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Bugtraq
[Top] [All Lists]

Re: Vulnerabilites in new laws on computer hacking

Subject: Re: Vulnerabilites in new laws on computer hacking
Date: Fri, 17 Feb 2006 14:28:29 +0300
nuqneH,

I'd even say, if you hire someone whose security knowledge is based solely
on breaking into systems, this guy will not able to produce valuable reports
for customers because his viewpoint is likely to be flawed; his knowledge on
protecting system usually falls into "patch-this-hole" pattern, not risk
assessment and secure design. 

Not always (well, i myself was a very bad guy years ago), but i think it
is the main reason of big IT security companies policy "we do not hire hackers" 
-
not because they you cannot trust them - that is not true, they often have
a kind of own ethics strong enough - but just because they are almost useless.

There are exceptions, sure.

On Thu, Feb 16, 2006 at 08:54:51AM +1100, Craig Wright wrote:

"If you hire someone that has never broken into a system, this guy will
not be able to produce valuable reports for customers because he will
not be able to find vulnerabilities that can't be found running a
scanner."

The quote above is wrong. Empirically and categorically wrong. This is a
case of blind assertion with no proof let alone evidence. Lets look at
things a little scientifically. For all you hope to demonstrate with
this style of pen. test you are only as effective at best as a poorly
run hands on vulnerability based risk assessment. 

<Prev in Thread] Current Thread [Next in Thread>