Hacker News new | ask | show | jobs
by dathinab 85 days ago
The problem is to hack something you need to know the what, where, who.

Companies have a very visible what, where, who in most cases.

Hacker don't, and take extra steps to obscure it (e.g. jump hosts, bot nets etc.).

Now if it's idk. a spear phishing campaign or similar "hacking back" by giving them trapped data or reverse social engineering attacks might work.

But if it's a technical security vulnerability some one found by scanning and sneaked into using multi-country jump hosts and cleaned up behind them. Then you have little chances to find them and to do so likely requires getting information from telcoms which require judge orders to be handed over, and from multiple countries, too.

1 comments

Sure though I would view that as a separate problem with the idea of asking anyone to target attackers.. Everyone is an equally good psychic some believe they are better than others.