arent hackers just punks who are also nerds?
@KitRedgrave allow me to attest to this.
Basically, yes.
@thegibson @KitRedgrave If the first question you ask about rules is, "So what would I have to do to wreck this?"…
@KitRedgrave @thegibson We had a vendor in for a thing at work that we'd be interacting programmatically with. I asked, "How does billing work? Like if billing is O(n) what's n? In other words, what would I have to do to astronomically blow up our bill?"
I was asking with the idea that then I'd know to avoid doing that thing and understand what might drive costs up or down, but apparently they'd never been walked that in that way. I was somewhat surprised.
That is a hacker's mind at work.
The first conversation I have when I am onsite is that "I am here for you to blame if things go wrong, but please let me know if that's what you need so I don't get mean about it."
Generally they'll tell you what the real deal is after that talk.
Sadly it is part of our role.
@benhamill @KitRedgrave it's usually at least the first thought... I don't usually say it out loud, but it's also why I am good at blue team security... i find the weak points that need some reinforcement and build on that.
Actually... at this point, I usually point at where it's weak and say something like "somebody should fix that".
They usually listen.