Hiring Hackers: Why it Might Not Be Such a Good Idea
Hiring hackers to test your security seems like a good idea--but what exactly is their security expertise, and what are the risks associated with allow them access to your systems?
There has been a long, ongoing debate about this issue, and recently it has resurfaced in public. Should companies hire hackers convicted of computer crimes? The general theory is that these "hackers" are elite commando style computer security experts that can tighten up your network in a weekend marathon of pizza and pop. Nothing could be further from the truth.
Securing a network takes a lot more then plugging a few technical holes. Even if I were to walk into your network and fix every single existing problem, it would not make your network secure. Security is a procedure with many steps, assessment, definition of needs, planning, implementation, review, and so forth, which amounts to a never ending cycle. Even if you hire a brilliant hacker that secures you against all known attacks, new problems will crop up. Even if your hacker has these qualities, their ethics are extremely questionable. There is a famous saying among lawyers: "never put a perjurer on the stand", which boils down to "if you know he's lied before, chances are, he might do it again". How can you trust your newly hired hacker not to slip backdoors into the system that they might later exploit. While it is true that any trusted employee might try to do something like this it certainly seems silly to put yourself in a higher risk category.
A company has a fiduciary responsibility to stockholders. They are entrusted with their stockholders' money and are expected to make decisions that will increase it without unnecessary risk. Engaging in high risk behavior means legal liability. For example, would it be reasonable to sue the corporation for not taking proper care and responsibility in hiring someone they know to have offended before? Considering the position of trust most security administrators are placed in (they have administrative access to servers, monitor users' network usage, read incoming and outgoing e-mail and so on) is it really wise to hire these people? A person with administrative access to a server, or physical access to the network can break into systems and leave backdoors with nary a trace. Would you expect a bank to hire criminals convicted of armed robbery to transport money on the grounds they know what to look out for? Would you hire a burglar to install the alarm system for your house?
While it would be nice if all criminals that got caught were rehabilitated, used their skills for good rather than evil, and never offended again, this is not a perfect world. By breaking the law, for whatever reason (curiosity, maliciousness, etc.) they have chosen to violate rules generally accepted in most countries and societies. They have (at a bare minimum) shown poor decision making, and while they may not specifically want to re-offend, they may be tempted by a short term gain and take a chance (as they have in past).
While it is possible to find a convicted hacker with the skills you want, it is exceedingly rare. Even if they possess the required skills their decision making and morality must be questioned. Even if they are reformed and never commit a crime again, would clients feel comfortable with the person? In general the negatives associated with hiring a convicted hacker far outweigh any benefits.
To quote a recent online article:
"Nolan Waithe Grant was hired Aug. 16 to work at the university computer system's help desk at a salary of $21,626. Three years ago he pleaded guilty to hacking into the school's Unix computer network."
I'm not sure, but being paid 22k a year to work on a helpdesk sounds more like punishment than a career. I know I'd rather be dealing with new software and security technology then helping users change passwords they forgot.
About the Author
Kurt Seifried is a security analyst, and author of the Linux Administrators' Security Guide.
SecurityPortal is the world's foremost on-line resource and services provider for companies and individuals concerned about protecting their information systems and networks.
The Focal Point for Security on the Net (tm)