I want to be a hacker

You wouldn’t believe how many times a student in a class or course tells me the ‘I want to be a hacker‘ thing. Some don’t even skip that first step and tell me they want to study CyberSecurity or ask what reading material I’d recommend to learn and dig a bit deeper into CyberSecurity (we’ll talk about that in another post, noted). I tell everyone the same thing: the first thing you have to do is read a lot, then specialize in something you’re truly PASSIONATE ABOUT, and finally keep reading, but now focused on the topic you like.
What do I need to study?
In other words, there’s no manual for learning CyberSecurity, just as there’s no single topic to it. CyberSecurity covers many different branches and nobody is an expert in all of them. Personally I believe you can get into the Security field from two different starting points: the developer who’s learning how to improve their code and make it more secure and optimized, and the systems administrator who wants to make sure the systems they manage are secure in every aspect. Neither path is better than the other, they simply complement each other. In my case, I made the jump to the Security side after spending several years as a Systems Administrator. During those years I learned a lot about Linux and Windows, services, networks… and also about Security, since once I installed a system I had to check it was secure before putting it into production—it wasn’t enough to just install it and apply the latest updates, I had to verify it was actually secure. Those years gave me the chance to set up a small lab with decommissioned machines and install different operating systems to see which one did what the company needed in the most efficient and secure way, so I installed many different versions of Windows Workstation, Windows Server, Linux, Unix, *BSD… and spent thousands of hours reading about secure configurations, service installation, firewalls… In fact, there were days when a coworker would ask me ‘why don’t you go home? your shift ended a while ago’ and I’d answer ‘because at home I’d just do the same thing, and here I’ve got more bandwidth‘.
But I also have friends currently working in Security who came from the Development side. They also bring a different complementary perspective to mine. Many of them couldn’t care less about knowing what a Fortigate or a ping flood is, but they know how to control memory allocations to prevent a buffer overflow and how to craft a complex blind SQL query to exploit a Blind SQL Injection vulnerability, things I can only do at a basic level.
At the company where I currently work there aren’t just these two profiles, I also have coworkers who are really good with networks. These people don’t care which OS version is running on the server, because they know exactly which segments of the network carry information ‘traveling’ unencrypted and therefore susceptible to being captured. And of course they know how to fix it, what hardware should be installed to encrypt all those communications, or what firewall configuration needs to change so that network users can’t access that confidential information.
‘You can’t do it alone, but with friends you can’
That’s why I said earlier that you should specialize in something you’re truly PASSIONATE ABOUT, because we can’t know everything and we’ll need to work as a team with other people who complement us. The typical image of the evil hooded hacker sitting in a dark room browsing three-dimensional databases only exists in movies. And bad movies at that. Luckily, nowadays it seems screenwriters do a bit more research than they did when they wrote the movie ‘Hackers‘ (the only good thing about that movie is Angelina Jolie on rollerblades), and we now have shows like Mr. Robot, where some real exploits are shown being used to access a system:
By this point, things should be a little clearer for you. What did you like most out of everything we’ve talked about so far? Do you enjoy developing in Java? Are you one of those people who spend their lives formatting and installing a new OS version just to try things out? Or have you been administering Oracle for a while and feel really comfortable in that environment? Well then, focus on that and keep reading and researching about vulnerabilities, secure code, optimization, go to events where these topics are discussed, listen to different points of view, start a blog to document your progress, even prepare a talk yourself! There’s no course out there that teaches you to be a hacker, but you can study and practice the thing you love enough to reach a level where you can test and question things about a specific technology that nobody had ever questioned before. And that’s what being a hacker is.






Tienes razón, Angelina Jolie patinando mola mucho!
Jajajajaja, ¡es lo mejor de la película sin duda! Eso de navegar entre bases de datos tridimensionales… no lo termino de ver.