Hacking is often associated with bad behavior, but there are some good guys out there who help to ensure products aren’t exploited by ill-intentioned parties. This is part of the offensive security research (OSR) process. On this episode of What That Means, Camille speaks with Jason M. Fung, Director, Offensive Security Research & Academic Research Engagement at Intel, who breaks down why offensive security research is such a crucial practice.
They cover:
The definition of offensive security research, aka hacking
Why thinking like a hacker is essential for effective offensive security research, and how not all hackers are bad
The various reasons hackers might enjoy offensive security research in the first place
What skills and traits the ideal hacker possesses
Why it’s important to include different perspectives, including those from outside organizations, when it comes to offensive security research
The various kinds of researchers involved
The development of Capture the Flag events
... And more. Tune in, you don’t want to miss it!
The views and opinions expressed are those of the guests and author and do not necessarily reflect the official policy or position of Intel Corporation.
Here are some key take-aways:
Offensive security research is almost like an industry euphemism - when we think about hacking, there’s often a negative connotation, but some hackers actually use their skills for good and help to uncover product weaknesses before they can be exploited.
Having outside perspectives from people like well-intentioned hackers can help development teams fill in blind spots and anticipate threats they might not have otherwise considered.
There should also be a holistic approach to offensive security research to ensure well-rounded solutions.
Several kinds of researchers are involved in offensive security research, including academics eager to find new innovations, those who come from the industry side and are employed by companies, as well as freelance bug bounty hunters.
Oftentimes the academic researchers are motivated by the hope that they’ll be the first to publish new findings; this can require a disclosure agreement to prevent certain information from going public too soon, so there is a level of patience required on academics’ part.
Regardless of why the various researchers get involved, their work provides excellent insight and opportunities for improvement when it comes to product development.
Some interesting quotes from today’s episode:
“We want to put ourselves into the shoes of the hackers and ask the question, what would they do?”
“We don’t want to be playing by the rules. We are going for the weakest link. And this is what offensive security research is about.”
“By having more people coming from different perspectives, it helps to kind of round out the blind spots.”
“I’m hacking my own product. I’ve been paid by the company to do fun things that I like, and I’m hiring the best professionals outside into my team to do the work.”
“You can be the bad guy that may be selling your learnings to the black market, but also, you can be doing all these fun things as a good guy.”
“I really enjoy the benefit of working with folks coming from different backgrounds and perspectives and helping one another to continue to learn.”
“One thing I really care about is not just about the skill set of the individual, but also their mentality. The mentality about being passionate, being curious, and also ready to learn more new stuff and collaborate well with one another”