3 ms·
It’s weird how there’s been a massive uptick in security “threat researchers” blogging about hello world style malware in the past few years. On the plus side,
by rhexs 4y ago
It’s weird how there’s been a massive uptick in security “threat researchers” blogging about hello world style malware in the past few years. On the plus side, malware reverse engineering is a tough job that traditionally didn’t pay that well, so hopefully they’re doing better now with the rise of all these startups doing blog posts about LD_PRELOAD.
- ewuhic 4y agoTo me all of the sec research still seems like some kind of secret wisdom bound only to the best hackers out there, am I wrong here?
- rhexs 4y agoThat's just the culture of defcon/blackhat/"if you get any certs you're dumb". If you can program, you can learn almost any concept in security with self study and a handful of good books. Marketing posts, such as these, often aren't very useful but sure look neat with all the basic blocks...
- TechBro8615 4y agoThere’s a wide gap between the majority of infosec bloggers and the top echelon of experts. I don’t see a problem with that, personally, and it’s not much different than the distribution of expertise in most other software domains. Surely the more the merrier, since at least some of those new entrants will grow into experts. Also, there’s a reason the “hello world” malware posts are popular - the techniques they’re describing might have been known for years, but they’re practical and they work. Often their longevity is only due to their unfixable nature in exploiting a design flaw. So they’re useful not only from a practical standpoint but also an academic one of demonstrating a class of attack so pernicious that it can only be eliminated with a ground up redesign.