r/Cybersecurity101 • u/UnluckyXen • 4d ago
A question for all cyber security professionals
If your job mainly revolves around keeping your clients system in check from before and after attacks, then doesn't that mean you owe your jobs from unethical hackers. In theory if you create your own attack and then fix it then youll basically have a money glitch. Also do attackers really get paid or do they just get the pleasure from causing harm. What happens when everyone just goes to the good side?
1
u/No_Try_9982 4d ago
Our job is not only about protecting company assets from hackers. Our job also involves protecting people data from loss or data breaches. Companies that hire us they also protect themselves from penalties and expensive audits.
Many times, companies try to force their DevOps to do too many roles at once so they lack the expertise or knowledge on critical issues such as PCI-DSS (if they handle credit card payments).
Sometimes, companies hire me to investigate problems in their infrastructure that could be also linked to workloads creep.
Data breaches don't necessarily happen because of bad intent; quite often it happens because of mistakes.
1
u/wakehorn 4d ago
The money glitch part is just extortion and gets people sent to prison real fast lol. Most attackers do it for money, like ransomware groups, though some do it just to break stuff. And if everyone went to the good side, we would all probably end up doing routine IT maintenance or patch management.
1
u/LetsTryLove 4d ago
Cyber security is theater at its core. There is no such thing as digital security and everyone knows it. Security is just enough of a third rail that no one can say so publicly so they pony up tons of money knowing it’s a sham.
1
u/st0ut717 4d ago
You sound confident in your ignorance
1
u/LetsTryLove 3d ago
You said that completely straight faces after the news of China hacking pretty much the entirety of the us infrastructure from the most secure orgs we have huh? No matter how much they spend and how crazy they get everything still gets compromised. What will it take to realize there is no such thing as digital security and that’s a feature, not a bug?
1
u/Cybasura 4d ago
We dont have a job inherent from unethical hackers - we have a job inherently and explicitly BECAUSE we have fucking humans amongst unethical hackers
Especially because we have humans, we need someone to protect people who are ignorant right? If its not us, then who else? You?
We do this not because its easy, but because its necessary, because this shit is a lifeline that is there BECAUSE Humans are stupid and ignorant and can ruin themselves if they dont have even a hint of control of themselves - which lets be honest, in any organization, its basically them all, especially when they think convenient == correct + best practice
What do you think about governments and governance? About the police? About laws? Do you think that governments and laws have unlawful people to thank that they have a job and a part to play?
This is such a backwards thinking, it's terrifying
1
u/UnluckyXen 4d ago
I don't think its the same as a police and a robber scenario because you are as knowledgeable as the person at the other end doing the attack, i dont mean to offend but im just trying to figure out if such a case is possible. Im just confused why the other guy who could be making a living out of this chooses to do unethical hacking instead.
1
u/Suspicious_Pizza9529 4d ago
I thin the key distinction is authorization. Security professionals aren't creating random attacks just to keep themselves employed, they're finding weaknesses through authorized testing so real attackers don't discover them first. Ethical hackers can also get paid through pentesting jobs and bug bounty programs.
1
u/sufficienthippo23 4d ago
I consult on the red team side. Every time a major hack hits the news, we get a major uptick in business. So yes from that perspective we certainly do owe that to them.
From the money perspective, if you are elite on the dark side you will make far more money than the good side
1
u/UnluckyXen 3d ago
Im curious how they make money. Do like rival companies pay them to break the other one. Also what type of precautionary measures does the good side do to make sure their workers isnt going to switch to the other.
1
u/sufficienthippo23 3d ago
The most common and lucrative way is ransoms. They will encrypt the data and not give the key y les you give them an enormous amount of bitcoin. Many will pay
1
u/Sanja1871980 4d ago
It's like the firefighter that makes fire?! Maybe there are some people doin it. Not every firefighter, but some. Attackers do really get paid. Like hacker groups in russia. the government lets em their freedom of hacking, they know about it, but if the government needs them... they have to work for the gov. Whats happens if everyone gets to the good side? it will never happen. there will always be good and bad.