This session is for members.

Subscribe or log in to watch every GoSec session.

Subscribe Log in

This recording is not available yet.

Ethical Hackers and the Amygdala

Download resources

About this session

Chloé Messdaghi, VP of strategy at Point3 Security and an ethical-hacker advocate, opens her keynote with Equifax and Capital One, both warned by researchers before their breaches, and the figure that sixty percent of hackers do not report vulnerabilities for fear of prosecution. She recounts the DJI bug bounty case, where a researcher who confirmed scope by email was still threatened under the Computer Fraud and Abuse Act, and the Coalfire testers jailed overnight in Iowa despite a signed engagement. She then turns to the brain: the amygdala flags anyone unfamiliar as a threat, and because the public rarely meets a hacker, hoodie-and-ski-mask imagery and press language that says 'hacker' when it means 'attacker' go unchallenged. Her survey of legislation covers the CFAA and its stackable charges, the DMCA, terms of service, Aaron Swartz, Aaron's Law and the pending Van Buren case. Change, she argues, needs three levers at once: press, organisations adopting vulnerability disclosure programs, and legislators. She closes with five actions, from signing the Hacking Is Not a Crime petition and fact-checking journalists to lobbying representatives and supporting groups such as disclose.io and I Am The Cavalry.

Sixty percent of hackers don’t submit vulnerabilities due to the fear of out-of-date legislation, press coverage, and companies misdirected policies. This fear is based on socially constructed beliefs that the amygdala processes. This talk focuses on how to increase public awareness in order to change legislation to support ethical hackers, ending black hoodie and ski mask imagery, and encourage organizations to support bilateral trust within their policies. 

Key takeaways

  • Publish a vulnerability disclosure program with a clear contact and scope; most large companies still have none, and researchers give up when they cannot find whom to tell.
  • Keep a paper trail when testing: confirm scope in writing before touching anything, and stay in scope and do not exploit, because that is what separates a hacker from an attacker.
  • Correct the press when it writes 'hacker' for 'attacker'; the locksmith-versus-burglar analogy lands with people outside infosec.
  • Treat anti-hacking, anti-circumvention and acceptable-use rules as three separate legal exposures; a signed engagement did not stop the Coalfire testers from being arrested.
  • Follow the Van Buren case and contact your representatives; if violating terms of service becomes a crime, companies decide who goes to prison.

Speakers

Chloé Messdaghi
Chloé Messdaghi
Tech Changemaker & Cofounder HINAC;WOT · Stand Out In Tech
Chloé Messdaghi is the Vice-President of Strategy at Point3 Security. She is an ethical hacker advocate who strongly believes that information security is a humanitarian issue. Besides her passion to keep people safe and empower online & offline… Read moreRead less

Chloé Messdaghi is the Vice-President of Strategy at Point3 Security. She is an ethical hacker advocate who strongly believes that information security is a humanitarian issue. Besides her passion to keep people safe and empower online & offline, she is driven to fight for hacker rights. She is the founder of WeAreHackerz (formerly known as WomenHackerz), president and co-founder of Women of Security (WoSEC), podcaster for ITSP Magazine's The Uncommon Journey, and runs the Hacker Book Club. She will be presenting her latest talk titled “Ethical Hackers and the Amygdala”.

Resources

Tags

More from GoSec 2020

Also from Chloé Messdaghi

On the same topic

This site is registered on wpml.org as a development site. Switch to a production site key to remove this banner.