4 ms·
I assume that if you're freelance you're at more risk of finding yourself on the receiving end of a CFAA violation. What I wonder is that if security researcher
by TerminalJunkie 9y ago
I assume that if you're freelance you're at more risk of finding yourself on the receiving end of a CFAA violation. What I wonder is that if security researchers who work for domestic companies face the same degree of scrutiny that these freelance researchers do.
I guess that if you work for a company you're probably not looking at anyone's website that's not explicitly paying you/your company and under some contract.
- SubiculumCode 9y agoTrue.
- jerf 9y agoWhile what you posted makes sense with the right definitions, I think you might understand better if you're careful with your definitions of "security specialist" (what SubiculumCode said), "security researcher" (what you said), and the other classifications. Not all specialists or researchers are doing penetration testing. Of those, not all of them are penetration testing third party stuff, and of those, not all of them are doing it without permission. That's the only one that will get you into trouble. I'm not, technically, a "security specialist" of any stripe, but I take a very careful interest in the defensive side of security, and am currently in the middle of implementing a fairly security-sensitive system. I don't worry that the FBI is going to bust down my door at 2am because I've tweaked the API of my code to make it harder to write cross-site scripting attacks, or because I fixed the architecture so that authentication is done very early in the request cycle instead of ad-hoc and inconsistently very late in the request cycle in a way that requires every developer of every individual web page to have to enforce all authentication. Most security work is going to involve internal matters and the fixing thereto, and, yeah, the job isn't going anywhere any time soon. (Though it does have the eternal challenge of convincing people they need to pay for it, and the problem that even in companies where programming is the major product like Facebook and Google, you're still going to be a cost center.)
- bigiain 9y agoWorking for Intel didn't stop Intel getting a conviction against Randal Schwartz (which was eventually quashed, but he ended up being " felon" for over 10 years...) https://en.wikipedia.org/wiki/Randal_L._Schwartz https://en.wikipedia.org/wiki/Randal_L._Schwartz