Foxes in the Henhouse: Can Hackers Be Trusted to Defend Computer Systems?

Foxes in the Henhouse: Can Hackers Be Trusted to Defend Computer Systems?

San Francisco, Calif.?The RSA Conference this week hosted a panel discussion titled “Foxes in the Henhouse” about the contentious issue of hiring reformed hackers as computer security professionals. The expectant audience didn’t have to wait long for the sparks to start flying among the four panelists. The most heated exchanges came between Kevin Mitnick, the reformed hacker who served five years in prison after a highly publicized computer crime conviction and became an icon in the hacker community, and Ira Winkler, Hewlett Packard’s Chief Security Strategist and a former National Security Agency employee.

Mitnick condemned Winkler as a hypocrite for speaking against using hackers in such posts, saying Winkler himself had hired members of a group called the Ghetto Hackers for an information security group in the past, while Winkler reminded the audience that Mitnick was a convicted felon who’d been arrested five times in the past 20 years and as a hacker was adept at rationalizing his computer crimes.

The other two panelists, Jennifer Granick and Christopher Painter, provided the legal view, as they have been on opposite sides of many computer crime cases, Granick as a defense attorney and Painter as a prosecutor. The motley mix of backgrounds and opinions made for a volatile, yet informative, discussion.

Here are the panel’s notable quips about specific issues raised during the lively hour-long event:

The skills hackers bring to the computer security profession
Mitnick: Hackers who have reformed have something to bring to the table. They’re not doing simulated-type penetration testing. For example, do I want a pilot who has 1,000 hours on a flight simulator or 1,000 hours of real-time flight experience? I think there’s a value proposition there.

Granick: Computer security requires a talent [which hackers have] at being able to understand how something can be made to do something that it’s not supposed to do?how it can be used in an unauthorized or unexpected or novel way. You have to be able to anticipate those types of uses in order to guard against them.

Winkler: The best penetration testers I’ve ever met have been fully cleared people working for the U.S. government… What do hackers offer that legitimate security professionals don’t? They don’t bring any specific way or any unique tool that might be used… If you show me somebody with a criminal record and say ‘here’s his skill set’, I can find you 30 people with the same skill set?if not better?who have no criminal record.

How does it look when you bring in someone with a questionable background and give them the keys to the castle?
The risks companies considering a hacker for a computer security position face
Painter: For a computer security person, you want [him or her] to look at the other people on the system not just as bits and bytes but as individuals who have privacy and other interests. Hackers at one time in their lives weren’t able to make that distinction and put their interests first. If past is prologue, you have to look at that.

Mitnick: The trust has to be evaluated on a case-by-case basis. Once trust is violated, it’s extremely difficult to get back. The trust requires the person that’s hiring to do their due diligence and really look at the risk.

Winkler: There are well-established, legitimate firms that you can hire and you don’t have to worry about what happens when a hacker you’ve hired does something wrong?and you’ve provided him with the tools to do it. How does it look when you bring in someone with a questionable background and give them the keys to the castle? How do you explain to your shareholders that level of risk?

Can hackers really reform?
Mitnick: My position now is any type of unauthorized access is completely wrong, and it’s illegal and unethical.

Painter: One of the things that hackers have demonstrated is not justas defense attorneys like to put itintellectual curiosity, but a disregard for other people’s rights and property and a way to minimize that conduct and say ‘this is not that illegal, this is not that problematic.’

Winkler: Why not use people [with no criminal past] instead of hiring someone with a criminal record and putting yourself and your customers at risk? There’s the issue of recidivism. There’s a high rate of recidivism in just about all crimes.

Granick: It’s incredibly presumptuous to say every person who has a criminal record cannot be rehabilitated, cannot change, is immoral, is untrustworthy and is not worth the risk.

It’s incredibly presumptuous to say every person who has a criminal record cannot be rehabilitated.
What about the careers of reformed hackers who never got caught?
Granick: I’m the only one up here who’s qualified to say what hackers think, because I’ve defended so many of them. Hackers think ‘I will not get caught.’ Period.

Mitnick: I can think of several individuals who’ve started very successful computer companies who were hackers, crossing the line into unauthorized access. A lot of respected people in the industry who’ve started companies that many people use as vendors were actually hacking before. I was actually trading vulnerabilities with a lot of these people.

Winkler: My definition of what he’s saying is ‘you can’t trust anybody, so you might as well trust the crooks.’

So should companies hire them or not?
Mitnick: The truth is in the industry hackers are used. A lot of companies?to save their brand or save their image?don’t like to admit it but that’s what’s really going on. My clients are happy with the skill set I bring despite my criminal background.

Painter: People can be rehabilitated, but it’s a risk factor. Look at other industries. If someone gets convicted of bank fraud or embezzlement, they don’t get rehired in the banking industry. People convicted of insurance fraud don’t get hired in the insurance industry.

devx-admin

devx-admin

Share the Post:
Development Project

Thrilling East Windsor Mixed-Use Development

Real estate developer James Cormier, in collaboration with a partnership, has purchased 137 acres of land in Connecticut for $1.15 million with the intention of

USA Companies

Top Software Development Companies in USA

Navigating the tech landscape to find the right partner is crucial yet challenging. This article offers a comparative glimpse into the top software development companies

Software Development

Top Software Development Companies

Looking for the best in software development? Our list of Top Software Development Companies is your gateway to finding the right tech partner. Dive in

India Web Development

Top Web Development Companies in India

In the digital race, the right web development partner is your winning edge. Dive into our curated list of top web development companies in India,

USA Web Development

Top Web Development Companies in USA

Looking for the best web development companies in the USA? We’ve got you covered! Check out our top 10 picks to find the right partner

Renesas Tech Revolution

Revolutionizing India’s Tech Sector with Renesas

Tushar Sharma, a semiconductor engineer at Renesas Electronics, met with Indian Prime Minister Narendra Modi to discuss the company’s support for India’s “Make in India” initiative. This initiative focuses on

Development Project

Thrilling East Windsor Mixed-Use Development

Real estate developer James Cormier, in collaboration with a partnership, has purchased 137 acres of land in Connecticut for $1.15 million with the intention of constructing residential and commercial buildings.

USA Companies

Top Software Development Companies in USA

Navigating the tech landscape to find the right partner is crucial yet challenging. This article offers a comparative glimpse into the top software development companies in the USA. Through a

Software Development

Top Software Development Companies

Looking for the best in software development? Our list of Top Software Development Companies is your gateway to finding the right tech partner. Dive in and explore the leaders in

India Web Development

Top Web Development Companies in India

In the digital race, the right web development partner is your winning edge. Dive into our curated list of top web development companies in India, and kickstart your journey to

USA Web Development

Top Web Development Companies in USA

Looking for the best web development companies in the USA? We’ve got you covered! Check out our top 10 picks to find the right partner for your online project. Your

Clean Energy Adoption

Inside Michigan’s Clean Energy Revolution

Democratic state legislators in Michigan continue to discuss and debate clean energy legislation in the hopes of establishing a comprehensive clean energy strategy for the state. A Senate committee meeting

Chips Act Revolution

European Chips Act: What is it?

In response to the intensifying worldwide technology competition, Europe has unveiled the long-awaited European Chips Act. This daring legislative proposal aims to fortify Europe’s semiconductor supply chain and enhance its

Revolutionized Low-Code

You Should Use Low-Code Platforms for Apps

As the demand for rapid software development increases, low-code platforms have emerged as a popular choice among developers for their ability to build applications with minimal coding. These platforms not

Cybersecurity Strategy

Five Powerful Strategies to Bolster Your Cybersecurity

In today’s increasingly digital landscape, businesses of all sizes must prioritize cyber security measures to defend against potential dangers. Cyber security professionals suggest five simple technological strategies to help companies

Global Layoffs

Tech Layoffs Are Getting Worse Globally

Since the start of 2023, the global technology sector has experienced a significant rise in layoffs, with over 236,000 workers being let go by 1,019 tech firms, as per data

Huawei Electric Dazzle

Huawei Dazzles with Electric Vehicles and Wireless Earbuds

During a prominent unveiling event, Huawei, the Chinese telecommunications powerhouse, kept quiet about its enigmatic new 5G phone and alleged cutting-edge chip development. Instead, Huawei astounded the audience by presenting

Cybersecurity Banking Revolution

Digital Banking Needs Cybersecurity

The banking, financial, and insurance (BFSI) sectors are pioneers in digital transformation, using web applications and application programming interfaces (APIs) to provide seamless services to customers around the world. Rising

FinTech Leadership

Terry Clune’s Fintech Empire

Over the past 30 years, Terry Clune has built a remarkable business empire, with CluneTech at the helm. The CEO and Founder has successfully created eight fintech firms, attracting renowned

The Role Of AI Within A Web Design Agency?

In the digital age, the role of Artificial Intelligence (AI) in web design is rapidly evolving, transitioning from a futuristic concept to practical tools used in design, coding, content writing

Generative AI Revolution

Is Generative AI the Next Internet?

The increasing demand for Generative AI models has led to a surge in its adoption across diverse sectors, with healthcare, automotive, and financial services being among the top beneficiaries. These

Microsoft Laptop

The New Surface Laptop Studio 2 Is Nuts

The Surface Laptop Studio 2 is a dynamic and robust all-in-one laptop designed for creators and professionals alike. It features a 14.4″ touchscreen and a cutting-edge design that is over

5G Innovations

GPU-Accelerated 5G in Japan

NTT DOCOMO, a global telecommunications giant, is set to break new ground in the industry as it prepares to launch a GPU-accelerated 5G network in Japan. This innovative approach will

AI Ethics

AI Journalism: Balancing Integrity and Innovation

An op-ed, produced using Microsoft’s Bing Chat AI software, recently appeared in the St. Louis Post-Dispatch, discussing the potential concerns surrounding the employment of artificial intelligence (AI) in journalism. These

Savings Extravaganza

Big Deal Days Extravaganza

The highly awaited Big Deal Days event for October 2023 is nearly here, scheduled for the 10th and 11th. Similar to the previous year, this autumn sale has already created

Cisco Splunk Deal

Cisco Splunk Deal Sparks Tech Acquisition Frenzy

Cisco’s recent massive purchase of Splunk, an AI-powered cybersecurity firm, for $28 billion signals a potential boost in tech deals after a year of subdued mergers and acquisitions in the

Iran Drone Expansion

Iran’s Jet-Propelled Drone Reshapes Power Balance

Iran has recently unveiled a jet-propelled variant of its Shahed series drone, marking a significant advancement in the nation’s drone technology. The new drone is poised to reshape the regional

Solar Geoengineering

Did the Overshoot Commission Shoot Down Geoengineering?

The Overshoot Commission has recently released a comprehensive report that discusses the controversial topic of Solar Geoengineering, also known as Solar Radiation Modification (SRM). The Commission’s primary objective is to

Remote Learning

Revolutionizing Remote Learning for Success

School districts are preparing to reveal a substantial technological upgrade designed to significantly improve remote learning experiences for both educators and students amid the ongoing pandemic. This major investment, which