Hiring hackers to improve security, good or bad?

The vast growth of Internet has brought many good things like electronic commerce, email, easy access to vast stores of reference material etc. As, with most technological advances, there is also other side: criminal hackers who will secretly steal the organization’s information and transmit it to the open internet. These types of hackers are called black hat hackers. So, to overcome from these major issues, another category of hackers came into existence and these hackers are termed as ethical hackers or white hat hackers.

This white hat hackers are usually hired by companies with the purpose of enhancing the security of their network, but not many people are in favor of this situation, and this become one of the most debated topic and often meetings for systems securities faces these kinds of debates where they consider the pros and cons of hiring former hackers, which is probably a better terminology. Why is former hackers a better terminology? Probably because they will use vulnerabilities to their own gain, that is the nature of hackers.

So, it is hiring former hackers a good idea? Those in favor of this idea think it would be a great idea because there are certain things hackers know that the common computer engineer does not know. These hackers are considered even as security experts who specialize in penetration testing to make sure a system is truly secure.

Is interesting to know that some companies are using these ethical hackers to do penetration testing, both internally and externally. Why companies think this is a good practice? when launching a new system, for example they think that beyond their best testing efforts, penetration testing can seek out hidden vulnerabilities that have been overlooked.

But coming back to the concept of hackers, who is, as mentioned before, a person that look for vulnerabilities in programs or network for their own gain, this can be categorized as a criminal behavior. With this background, how trustful a person like that could be? What if this person wants to dip into the company’s confidential files and take a look around, just because he can? Can you trust him not to illegally download copy protected music and movies or install pirate software on computers on the company’s network in his spare time?

Hiring a reformed former hacker may look a good idea but when you do that you put your whole security system on hands of someone that is not totally trustful for his background. Once hired, and working for the company they have no problem in accessing the security system and make changes that you probably never know, and you will be dependent on them to fix it.

Source:

http://content.wisestep.com/top-pros-cons-hiring-hackers-enhance-security/

 

Leave a comment