Security teams used to focus on firewalls and endpoints and many security professionals cut their teeth as system and network administrators. Nowadays infrastructure is defined by code, breaches are increasingly caused by weak applications and automation is essential for under-staffed teams. This is changing the skillset required by security pros. We now also need to have a deep understanding of applications and an ability to build automation into our tools and processes.
Everyone relies a huge amount nowadays on Open-source libraries that are often maintained very informally by loose-knit communities that are easy to infiltrate. This used to be the domain of nation states but the criminals are getting in on the action.
We are getting better at protecting Endpoints and attackers are shifting their focus. Legacy applications will continue to be a fertile hunting ground!
Bit of a cliché but ML will no longer be something that you just buy. Tools & techniques that were previously the domain of data science experts are getting easier to use. Won’t be long before larger SOC teams are using the tools directly rather than via models that are embedded in products.
The tools, knowledge and technologies for achieving a true Zero-trust architecture are rapidly maturing. Maybe like nuclear fusion – 15 years away and always will be but 14 years after the Jericho forum declared the end of the network perimeter we are getting close the point where many enterprises have a realistic chance of keeping their clients off “trusted” networks, particularly non-technical employees.
Let me guess. From a young age, you were attracted to spy movies. You are someone who wasn’t necessarily interested in school subjects, but probably did okay regardless. You learn concepts easily and quickly compared to others. You had a natural affinity for computers at a young age. Something about you is excited by the subversive blackhat hacking community, but actually, you’re a good person who doesn’t like the idea of ruining people’s lives or spending your life doing chin-ups with your morally questionable mate “Steve” in a high security prison.
So what’s the solution? Become an ethical hacker, so that you can do these illegal things without risk of jailtime, and get paid for it!
I should start with a disclaimer — I’m not an expert. I’ve only ever landed one hacking job, which is my current one — and I haven’t even been here long! But I did spend a lot of time in other sectors of IT wishing I was in security. As a result, I’ve read a lot of stuff and spoken to a lot of people. Basically, it all boils down to this:
There is no one-size-fits-all approach to getting your first infosec role. There was a recent Twitter hashtag that did the rounds, #MyWeirdPathToInfosec, where a whole bunch of infosec professionals revealed the paths they took to an eventual infosec role. They varied widely, some spent time in federal prison (not recommended), some were musicians, some scored an infosec role straight out of college, some were offered jobs after illegally hacking a company and then telling the company how they did it (also not recommended). This technique may have worked for some people in the 90s, now it will probably land you in jail.
The point is, don’t have tunnel-vision. Career opportunities often arise where you least expect.
I remember my first experience with “hacking.” I was about 10 years old, and I discovered the ability to save webpages locally. I headed straight to Google, downloaded the home page, and edited my local copy in notepad.exe to contain the words “Luke was ‘ere!”. When I opened up the edited page, my stomach dropped. I thought I had defaced Google. How long until the FBI kick in my door? Should I tell my parents before they find out?
Back in myyy daaaay, there were no hacking challenge sites. In fact, there was barely any information out there, at least that I could find. My first resource was a website by Carolyn Meinel, titled “The Guides to (mostly) Harmless Hacking.” The guides were written in Comic Sans, the token font of that bad design genre that can only be found in the 90s and early 00s. These guides included such classics as “Telnet: the Number One Hacking Tool” and “How to Hack with Windows XP part I: The Magic of DOS.” They can still be found here.
Upon finishing school I scored my first job in IT and started a computer science degree, almost finished, dropped out, got made redundant, moved out of home, acquired Bachelor of Music, became a full-time musician, spent a couple of years performing on cruise ships, met my wife, lived in the UK, got married, moved back to Australia, and started working as a full-time web developer.
Throughout all this, my passion for hacking never really subsided, and development was never something I loved. I had a wonderful job with great people, but the actual tasks of my job weren’t sparking me. As it turns out, I was on a project which involved e-commerce and sensitive data, so my boss offered for me to take a security related course. I emailed the CEO of a local penetration testing firm and asked what the best security course was, and he recommended OSCP. So I did it!
Completing my OSCP was a turning point for me. I spent every spare moment of those 60 days learning as much as possible about the art of hacking. Even when I was exhausted, I had trouble sleeping because my brain wouldn’t stop thinking about the challenge boxes in the labs. That’s how I knew it should probably be my job, instead of development, which I had grown tired of. (I wrote a three-part blog series about the OSCP too, if you’re into that.)
Only a month or two after completing OSCP, I landed my first penetration testing job through a great infosec recruiter after solving a hacking challenge they posted online. You can read more about that story here.
Enough about me! Finally, we are at the bit you all came here to read. Some actionable tips on how to get your first job as a hacker:
Contribute to open source tools, write your own, blog, start a podcast, go to hacker cons, connect with people on Twitter. You will learn a lot and it will introduce you to a whole network of lovely people who can help you. The infosec community on the whole are a friendly, tight-knit pack of smart, passionate people. If you’re reading this, there’s a good chance you will feel at home.
Are there people out there in your dream role? Email them and ask about your career path. The worst that will happen is that they don’t reply, the best that can happen is that you gain a mentor and some life-changing advice.
You can have every hacking certification under the sun, but if you walk into the interview gloating about some illegal stunt you pulled, nobody will risk hiring you. The white hat community often deal with highly sensitive data — your employer and your clients need to be able to trust you.
On that note, when you’re in an interview and you don’t know the answer to a technical question, it’s better to say “sorry, I don’t know, but I will be sure to research that later!” than to try to bluff your way through an answer. The person interviewing you will be able to tell, and they are probably more interested in you being honest and genuine than correct. At this point in time, experienced security professionals are rare, so many companies are hiring less experienced staff with the right mindset and attitude, then putting them through training to learn the technical skills.
Frankly, many certifications in this field aren’t a good indicator of someone’s technical ability. Having said that — you’re more likely to get a job if you have them. It shows that you’re invested in the craft, you have spent time/money skilling up, and you are interested. There are a few great certifications out there, and some that aren’t so good. If you’re not sure which ones are good, ask someone who knows!
Have you been in a HackerOne/BugCrowd hall of fame? Found a RCE in a bug bounty? Did you do well in a CTF at a hacking conference? Are you highly ranked on hackthebox.eu? Put it on your CV! These things might seem like games, but they’re also proof that you’re passionate about the craft, and have some skills.
Recruiters get a bad name for relentlessly calling you and using dodgy tactics to get the right contacts, but they’re not all like that. Finding a quality recruiter with good connections can make all the difference. When you are looking for a recruiter for a hacking gig, find one that specialises in infosec. A standard IT recruiter probably won’t know the right people.
Are you a developer? Find a bug in the application you develop, show it to your boss, ask permission to conduct more in depth security testing. Are you a sysadmin? Find a security hole in your network (you probably already know where to look), communicate the risk to your boss and ask for permission to conduct further testing. Whatever role you’re in — there’s a good chance you can make a name for yourself as the in-house security expert.
Now in your infosec interview/CV, you can say you were the in-house security expert, even though your official title was just “developer.” You can also fill out the “responsibilities” section of your role with some security related tasks.
It’s time. We’ve rounded up all our best games of 2018, then followed that up with another bunch of games you might’ve missed. We’ve done plenty of retrospective to close out the year. Now it’s our chance to look ahead at a packed spring schedule (and beyond), rounding up all the games we’re most excited about for 2019.
That part is key: Most excited about. That means you’ll find some obvious picks here, like Metro Exodus. You’ll also find some smaller, more niche picks like Disco Elysium, Heaven’s Vault, and The Occupation. And it means this is not a comprehensive list. It’s just our favorites.
Sorry in advance if we cut your favorite game from the list.
The first major PC release of 2019 is Capcom’s Resident Evil 2 remake ($60 preorder on Humble), due to release at the end of January. It’s probably the safest possible bet Capcom could make after the bold first-person pivot of Resident Evil VII. The Resident Evil 2 remake brings back all the fans’ old favorites. Leon’s here! And Claire! And Ada Wong! And Raccoon City! Also, it’s been redone to use the over-the-shoulder camera from Resident Evil IV!
It’s like a mashup of everyone’s favorite Resident Evils. That’s less exciting (to me at least) than a proper Resident Evil VII follow-up, but it’ll be great to have this classic story playable on modern machines, and with mechanics befitting a 2019 video game. So long, fixed camera angles. Adios, tank controls. We can do better now.
The Occupation was supposed to release in October. Now it’s supposed to release in February. I don’t think anyone even announced a delay—it just slipped into the future as if the original date never existed, the perfect way to delay a game that’s about a corrupt government cracking down on civil liberties to keep citizens safe.
Delay or no, The Occupation‘s still one of my most anticipated games for 2019. The game takes place over four real-time hours, with characters and events sticking to a strict schedule. You play a journalist, trying to uncover the facts behind a deadly crime—but you need to make decisions about what leads to pursue and how to follow them. Do you meet with the government official you have an appointment with? Or perhaps blow them off and root through a colleague’s empty office?
I’ve played a lot of so-called “immersive sims” over the years, but none as ambitious as The Occupation. I hope the delay gave the team enough time to fine-tune the details.
Usually these lists become outdated because of delays, but not this time. The day after we recorded our 2019 preview video, Metro Exodus ($60 preorder on Humble) announced it was moving its release date up a week, from February 22 to February 15. That takes it out of competition with Anthem and puts it back up against Crackdown 3, as well as Far Cry: New Dawn.
Metro is the one I’m looking forward to most though. I loved the cramped corridor shooting of Metro 2033 and Last Light, and while I’m a bit less enamored with the idea of a pseudo-open-world Metro game I’m curious to see whether it works, guiding Artyom on some grand journey through the Russian countryside.
Metro Exodus ’s strongest competition, Far Cry: New Dawn ($40 preorder on Humble) releases the same day with a brighter and goofier take on the post-apocalypse. And you know what? I’m kind of looking forward to it. I think Far Cry’s serious numbered entries are mostly mediocre (especially Far Cry 5) but the gimmicky spin-offs like Blood Dragon and Primal are interesting experiments—even when they don’t quite work out.
So a post-apocalyptic Far Cry? One that’s set on the same map as Far Cry 5, but without all the political and religious overtones? It probably won’t break new ground for the series or for games as a whole, but it at least sounds like a decently fun time. And hey, Fallout 76 set the bar pretty low, so…
Once upon a time February 22 was supposed to be the crowded day, but first Crackdown 3 dipped to February 15 and then Metro followed suit. Now only Anthem ($60 preorder on Origin) remains, BioWare’s take on a Destiny-style shooter—except maybe with a better story? That’s a pretty thin maybe, based on what I’ve seen so far, but I’m still holding out some hope. It is BioWare, after all.
We really don’t know though. BioWare’s been reticent about showing off Anthem’s story, instead focusing on how it plays. And I can say: It plays great. At our E3 demo I claimed Anthem plays “even smoother than Destiny,” which is high praise coming from me. Rocketing around in my little mech, strafing waterfalls and diving underwater, then exploding back out of a pool to shoot some nearby foes—it’s effortless.
But I loved the shooting in Mass Effect: Andromeda and not much else, so…well, I hope the story’s decent. Fingers crossed.
Frogwares’s Sherlock Holmes series is the closest I’ve come to a gaming guilty pleasure. They’re low budget, often buggy, the cases you solve hit-or-miss, and the mechanics for finding a solution even more inconsistent. And yet they often rise above their station, delivering excellent character moments for Holmes and Watson, or seizing on a neat detective game gimmick (like Crimes and Punishments with its red herring endings).
Point being: I’m always interested in what Frogwares is up to, even if the results aren’t perfect. And with Cyanide’s 2018 Call of Cthulhu game a mess, that makes Frogwares’s Sinking City our best hope for a truly unsettling mythos experience. The cinematic trailer below gives me no idea whether this is mostly an action game or a detective game, but I’m at least excited to find out.
Dark Souls is dead. Long live Dark Souls. If you believe From Software, the Dark Souls series is finished forever. That doesn’t mean From Software is done making that style of game though.
Enter Sekiro: Shadows Die Twice ($60 preorder on Steam). It’s not a Souls game, but Sekiro takes those ideas—deliberate combat, pattern recognition, grand boss battles, impenetrable lore—and transposes them to Japan’s Sengoku period. It is, in so many ways, recognizable as a From Software game.
And yet it’s not afraid to deviate from Dark Souls as well. Exploration is more active, as your character has a grappling hook-arm that allows him to leap to rooftops and branches or swing across gaps. That, in turn, makes stealth a viable option—either bypassing enemies entirely or leaping down on them unawares for a quick kill.
We don’t know much about Mortal Kombat XI yet. Announced in December at The Game Awards, all we’ve seen is a single CGI trailer of Dark Raiden fighting two Scorpions. That means uh…well, Dark Raiden and Scorpion are in the game. It also seems like the character customization elements of Injustice 2 will make it over to this latest Mortal Kombat.
But what will the campaign look like? That’s what I’m most curious to see. The seamless cinematic-driven campaigns of Mortal Kombat IX andX were great, but after four games (including the Injustices) it seems like it might be time for a shakeup. Rumors claim Mortal Kombat XI will include a full-on adventure mode with a map to explore, a la 2005’s Shaolin Monks, but we’ll see.
I still find it hard to believe Bethesda’s funding Rage 2 ($60 on Amazon), a sequel to one of the all-time blandest games, but…well, Prey was great. Maybe another of Bethesda’s weird bets will pay off. After all, Rage 2 mashes up id’s shooting with Avalanche’s Mad Max driving, which certainly sounds like a winning combination.
The question is whether the story can pull its weight as well. Lest we forget, the first Rage played pretty well. It was just boring as hell. Rage 2 seems to be shifting towards a quirkier Borderlands-lite style of humor, which might help propel the action along…or might get old quick. It’s hard to tell.
Either way, I’m looking forward to Rage 2—and that’s a sentence I never thought I’d write a year ago.
Source: IT News