HomeinetMore ethical hackers are being hired to find bugs

More ethical hackers are being hired to find bugs

ethical

A while ago, an ethical hacker named Mark Litchfield received an email that led him to acquire $1.5 million to date, all of it legally.

The email came from Yahoo, which is now owned by Verizon Media, and offered Mr. Litchfield several thousand dollars as a reward for finding a bug in its website code some time ago.

Yahoo , like many other tech companies, pays people well to find holes in their websites that could be exploited by a malicious hacker. Yahoo in particular learned this the hard way when it suffered two massive security breaches in 2013-2014. After that, it turned to ethical hackers for help .

Litchfield even states that anyone could do it.

Detecting errors

Litchfield has decades of experience in this field, which can be daunting for someone just starting out in debugging. The gap between experts and novices can seem overwhelming.

For a long time, only those lucky enough to land a job in cybersecurity would find bugs, even if they weren't paid to do so. According to James Lyne, head of research at the Sans Institute, most of them did so either by chance or with the help of a mentor.

There was a growing need to change this random selection process, Mr Lyne said, given the huge skills shortage in the cybersecurity industry.

Many governments, including the United States, have created training programs that try to give ethical hacker students a taste of cybersecurity to see if they like it.

Mr Lyne helped set up a similar UK scheme, Cyber ​​Discovery, which in its first year had more than 25,000 entries.

The Cyber ​​Discovery program simulates the daily work of professionals. It discovers security vulnerabilities, identifies hackers, analyzes documents for clues and other essential skills in games. It also familiarizes children with the tools that many cyber professionals use every day.

Participants earn points when they complete a section. And top performers take part in courses that help them further improve their skills.

But those involved in bug discovery should realize that the job of a cybersecurity worker requires much more in terms of skills and expertise.

And companies should have a number of other defenses in place long before they consider turning to an ethical hacker to audit their systems.

Alongside the defenses built into networks and threat analysis teams, they must proceed with penetration testing that does a more in-depth job of ensuring that a system is broadly protected from an attack.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS