iTnews

No room for excessive trust

By Alan Phillips on Jul 27, 2005 4:29PM
No room for excessive trust

Would you let a convicted fraudster look after your financial affairs? Leave your wallet in a room with a known former thief? Give matches to an ex-arsonist? Perhaps feel comfortable knowing that an ex-terrorist hijacker just boarded an aeroplane with you?<

If the answer is yes to any of these questions, you might well want to give an ex-hacker the opportunity to get to know your IT network. I think it shows quite a bit of front to advertise yourself as an ex-hacker, using phrases such as "when I was hacking" and "before I was caught." But the point is that when you take on someone like that, you are taking on risk.

In our profession we have a duty of care to employ people who will do the right thing. In our company, we make sure staff are properly vetted and security cleared for good measure. Penetration testers tend to be intelligent people with an intricate knowledge of IT systems, and during a security assessment a degree of trust is imparted to them. In reality, this trust could easily be abused.

These days, the profession is mature enough that there are plenty of well-qualified, talented pentesters with sound ethics. Indeed, there are now excellent training courses available in the subject, some accredited by universities.

One well-known former hacker who spent time in prison was asked why he did it. He said that back in the days when computers were expensive to get hold of, people like him used to find out about network security by examining the live systems of companies, but with the current comparative affordability of computers, it is possible to set up a testing lab on a shoestring budget. Hopefully, he is going to go straight now, but will we ever really know?

I'd never allow an ex-hacker to work for our company on principle alone. Nor should you.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © SC Magazine, US edition
Tags:
excessivefornoroomsecuritytrust

Partner Content

Matt Tett to lead essential primer session on security by design
Partner Content Matt Tett to lead essential primer session on security by design
"We're seeing some good policy put in place, but that's the exception"
Partner Content "We're seeing some good policy put in place, but that's the exception"
Top 5 Benefits of Managed IT Services
Promoted Content Top 5 Benefits of Managed IT Services
Operationalising net zero to be centre stage at IoT Impact conference
Partner Content Operationalising net zero to be centre stage at IoT Impact conference

Sponsored Whitepapers

Planning before the breach: You can&#8217;t protect what you can&#8217;t see
Planning before the breach: You can’t protect what you can’t see
Beyond FTP: Securing and Managing File Transfers
Beyond FTP: Securing and Managing File Transfers
NextGen Security Operations: A Roadmap for the Future
NextGen Security Operations: A Roadmap for the Future
Video: Watch Juniper talk about its Aston Martin partnership
Video: Watch Juniper talk about its Aston Martin partnership
Don&#8217;t pay the ransom: A three-step guide to ransomware protection
Don’t pay the ransom: A three-step guide to ransomware protection

Events

  • iTnews Benchmark Awards 2022 - Finalist Showcase
  • IoT Impact Conference
  • Cyber Security for Government Summit
By Alan Phillips
Jul 27 2005
4:29PM
0 Comments

Related Articles

  • PEXA buys into AI fintech Elula
  • WA gov creates cyber security uplift team
  • Healthscope CISO heads to KPMG
  • Edtech vendors invaded student privacy: Human Rights Watch
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co sizes up six-figure customer exodus a year to fixed wireless

NBN Co to cut 160 applications under $200m IT simplification

NBN Co to cut 160 applications under $200m IT simplification

What to expect from the incoming Labor government

What to expect from the incoming Labor government

NBN Co's 250Mbps and gigabit growth is finally clear

NBN Co's 250Mbps and gigabit growth is finally clear

Digital Nation

COVER STORY: A Year in the Metaverse
COVER STORY: A Year in the Metaverse
Why do DeFi and DAOs matter to business?
Why do DeFi and DAOs matter to business?
Lendlease launches its own metaverse in Milan
Lendlease launches its own metaverse in Milan
COVER STORY: Data and IoT set digital agriculture on a sustainable future
COVER STORY: Data and IoT set digital agriculture on a sustainable future
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
CTO Juergen Mueller offers a glimpse into SAP's metaverse play
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.