• 2 Posts
  • 63 Comments
Joined 1 year ago
cake
Cake day: June 23rd, 2023

help-circle












    1. running unauthorised pentests does indeed get people fired. Along with getting their managers in hot water for letting their pentesters be loose cannons. And if they’re attacking someone else while on company time, the company can be in serious legal trouble too.

    2. it is rather customary for heads to roll when critical data is leaked as part of an insider attack, especially when said attack was enabled by negligent practices.

    Just incase you’ve forgotten that randomly attacking people and leaking data is this kid’s MO.



  • Yea, but the nerds that the suits put in charge of security will absolutely recognize this kids skills.

    They will also recognise how much of a potential threat he is.

    The suits don’t run the security teams at most corpos.

    The suits absolutely do run the security teams. Very indirectly, but they do. The suits are the ones security teams have to persuade to get any sort of funding and they can and will veto a hiring decision like this.

    You are correct that in most places, the suits do not usually directly intervene. Usually there is a lead guy in the security team that handles the conversations with the suits.

    In a well functioning security unit, there is some trust there but not nearly enough to hire a kid like this. A veto is seen as a politically risky manoeuvre for a suit but it would absolutely be pulled for the prospect of hiring this kid, with some frankly compelling justification that any team lead would find nearly impossible to get around.

    I’ve worked in several corporations in several security teams in the past, some amazing, some god-awful with insane suit meddling.