4 ms·
> Secure Thoughts collaborated with Security Expert Jeremiah Fowler to expose a massive leak Seems to level up in the hacking world, you do whitehat stuff like
by blindm 6y ago
> Secure Thoughts collaborated with Security Expert Jeremiah Fowler to expose a massive leak
Seems to level up in the hacking world, you do whitehat stuff like this, but it could be that 90% of your work is blackhat. Why do 'researchers' risk exposing themselves like this (if the bulk of what you do is blackhat?). I'm not saying Mr Fowler is secretly a blackhat, but many people in the hacking scene are obviously blackhat judging by what they post on social media. You can infer that they like to get up to some sketchy stuff (again - risking exposing themselves to LE).
- dec0dedab0de 6y agoI think that they think its fun and neat to know how to do it, but most don't actually do it. Kind of like how most people training in martial arts, or tactical shooting aren't actually going around attacking people
- ender341341 6y agoI also imagine that being whitehat can fill a lot of the thrill side of things that you might get from blackhatting with significantly less risk.
- jnosCo 6y agoNo matter the color of your hat, if you're a security researcher, you're likely already on a watch list. Having publicly attributed white hat activity is a good cover.
- sdiq 6y ago>As a security researcher, I never circumvent or bypass password protected assets. These records were publically accessible and no hacking necessary to see 63.7 million records. From the article.
- MaximumYComb 6y agoIn Australia, our cyber security laws are very strong. There is no way I'd attempt to access services on random IP's to test if they use no password with common usernames for those services. Any semi compotent prosecutor could argue I accessed a computer without permission and they'd be 100% correct. The only way I can see myself accessing a computer and not breaking a law is through a genuine mistake i.e. mistyping an IP/url and somehow having the right username + password. I prefer to stay 100% on the legal side. The only way I'll touch a computer is with a signed document from the owner giving me permission and with clear instruction on what I can and cannot do.