April 21, 2007
On the security industry
A particularly insightful comment on Slashdot today:no such thing as a white hat is there? I mean - I can only assume this was a 'white hat' hackers conference, given there was actual publicity given and a public bounty and such. But then things like these pop up? "'Shane can have the laptop, I want the money,' Dai Zovi said in a telephone interview from New York"
"Conference attendees were underwhelmed, reasoning a Mac exploit that required no end-user interaction could be sold for upwards of $20,000." Makes me think.. black hat, white hat.. what's the difference these days? I thought a white hat hacker was the 'good guy' (albeit still a hacker).. the kind of person who hacks for fun / curiosity.. the kind of person who notifies the developer of the bug or, at least, just makes the bug known to the world at no charge. Not the kind of person who hacks, then scours the 'security conferences' for a bounty, and when that bounty is lower than what they could get off of actual 'bad guys', complain that the bounty is too low. To me, that just sounds like the person is a black hat, but dons a white hat on top in an attempt to fool us into thinking they're white hat.
Posted by Jeffrey at April 21, 2007 11:30 AM
What is a TrackBack? Learn more here. TrackBack URL for this entry:
http://www.geekable.com/cgi-bin/mt-tb.cgi/1389
Listed below are links to the 0 weblogs that reference 'On the security industry' from Geekable.com.
http://www.geekable.com/cgi-bin/mt-tb.cgi/1389
Listed below are links to the 0 weblogs that reference 'On the security industry' from Geekable.com.

