SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Hacking and Viruses

This hacker wears white

This hacker wears white

By:  Mari-Len De Guzman  On: 20 Jul 2006 For: ComputerWorld Canada Creator

The so called “white hat” hackers of the IT world, like the Metropolis Man of Steel, could have turned bad and joined the havoc wreaking dominion of IT’s dark side; instead, they use their technical flair helping companies strengthen their defenses against malicious attacks.

He could have conquered the world with his superhuman powers, but Clark Kent chose to be on the good side, beckoning his Superman alter ego to defend the weak.

The so called “white hat” hackers of the IT world, like the Metropolis Man of Steel, could also have turned bad and joined the havoc wreaking dominion of IT’s dark side; instead, they use their technical flair helping companies strengthen their defenses against malicious attacks.

Twenty-three-year-old Paul Haas’s job title is “security engineer” but simply put, he is a hacker by profession. He hacks into corporate systems and seeks out vulnerabilities that can be exploited. But he does it as a service and with the knowledge and permission of the subject company.

“Using the knowledge I gained through research and vulnerability gathering, I prepare a report that itemizes the risks of each of those vulnerabilities and the priorities in terms of what should be fixed first,” explains Haas, who works at Redspin, a security consulting firm in Carpinteria, Calif.

Haas has only been with Redspin less than a year, but he’s no stranger to IT security. During his undergraduate studies at the University of California Santa Barbara (UCSB), Haas got involved and worked at the university’s computer security research lab, alongside various post-graduate researchers.

At 22, he was one of the youngest and the only undergraduate among a team of IT researchers that won at last year’s Def Con Capture the Flag contest.

Capture the Flag is a hacking competition where each team is given a set of computer systems with built in security. The object is to break into as many of these computers as possible within a prescribed time period.

Haas says winning Def Con was one of the best things that happened to him. “Once you compete with a really good team, you can actually say that in an instant…that’s the highlight of my career.”

Shortly after winning Def Con, Haas earned his Bachelor’s Degree in Computer Science and worked for Redspin. His accomplishment at the hacking event may have helped put Haas on the radar of potential employers like Redspin, but it was his research background that added trustworthiness to his credentials, says Redspin’s president John Abraham.

Abraham admits Def Con is not typically the place where his company would look for candidates, but when he heard about Haas’s work at the university research lab he knew Haas was working on the good side.

“The whole hacker community isn’t always the community that can structure itself in a way that could benefit the clients. We had to vet out [Haas] because we needed to make sure that he came out of the research (community) and not out of the hacker community,” Abraham says.

Haas also gives Def Con credit for the opportunities it opened up for him, especially the “credibility” it added to his Bachelor’s Degree credentials. “I know what vulnerabilities look like, I know how to exploit and research them as the need arises,” says Haas, whose interest in computers started in his teens, the day he got his first PC.


Sign up for our Newsletters












Print |  Views: 1233   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Mari-Len De Guzman Mari-Len De Guzman is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

MS announces security programs
MS announces security programsMAPP will give vendors vulnerability information while the Exploitability Index will give guidance on the likelihood of a breach
Inside the black market 'bug trade'
Inside the black market 'bug trade'We’ve all heard about the war on drugs, but what about the war on software vulnerabilities? David Rice, author of Geekonomics: The Real Cost of Insecure Software, explains
Putting a PAL to work
Putting a PAL to workVoice over IP - VoIP - is inevitable in government. It is the hottest area, and many government departments are exploring how they can take advantage of its benefits - like greater flexibility in service and features and possibly lower costs. This rating is reserved for the most critical problems.
Why hack a Mac?
by joaquim p. menezes - remember charlie miller? 

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.