Remix.run Logo
Buttons840 an hour ago

White-hat and grey-hat hackers need to be able to perform penetration testing without permission. Nobody is able to build secure systems. The best we can hope for is that the good guys find the vulnerabilities first and report them responsibly.

This would be a huge inconvenience for companies and government organizations, so it probably won't happen. We will chose to sacrifice national security for the convenience of companies--what else is new?

Companies will say "it is our system, we are responsible for our own system", then, after a breach, they will say "our bad, we are not responsible". Same old story; half the nation's personal information is leaked twice a month and nobody cares.

pixl97 an hour ago | parent [-]

At the end of the day you will be hacked. The question is are the attackers going to be nice and tell you.

Buttons840 19 minutes ago | parent [-]

Since I'm getting some positive feedback, I'll go even further and say that there should be security bounties established by law:

If a certified red-team of security researches breaches a company's system and discloses appropriately, the law should require the company to pay a security bounty.

The bounty doesn't have to be crippling to the company, but it should be large enough that the security researchers will be paid well and can live on collecting security bounties. We want an entire industry of good guys testing the security of everything.

There can be some regulation to. Like, it's not okay to run a massive DDoS to test systems. We want the red-teams doing constructive things, not just breaking everything. It should be legal for the red-teams to be annoying, but not purposely destructive.