<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Watch out for your White Hats in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Watch-out-for-your-White-Hats/m-p/13951#M1497</link>
    <description>&lt;P&gt;Would you hire an electrician who was unaware of local building codes and electrical safety standards?&lt;/P&gt;&lt;P&gt;That&amp;nbsp;looks like&amp;nbsp;what happened in this situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It appears that the Michigan Democrats engaged with a group of politically organized amateur hackers who think they are security testing professionals. Passion and good intentions are not enough.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my extended thoughts, with added linked reporting beyond the NPR article see&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://cragins.blogspot.com/2018/08/good-intentions-passion-professional.html" target="_blank"&gt;Good Intentions &amp;amp; Passion /=/ Professional Expertise&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Aug 2018 13:45:38 GMT</pubDate>
    <dc:creator>CraginS</dc:creator>
    <dc:date>2018-08-24T13:45:38Z</dc:date>
    <item>
      <title>Watch out for your White Hats</title>
      <link>https://community.isc2.org/t5/Industry-News/Watch-out-for-your-White-Hats/m-p/13925#M1490</link>
      <description>&lt;P&gt;Within my own company, we have had discussions about how often/wide pen testing should be announced.&amp;nbsp; One extreme believes that there needs to be widespread knowledge so that the hounds can be called off if production were to be impacted.&amp;nbsp; The other extreme believes that op-sec is required to maintain the integrity of the test. The best answer is probably somewhere in the middle.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The DRC recently became a great example of not getting this balance correct.&amp;nbsp; Yesterday, they &lt;A href="https://www.nytimes.com/2018/08/22/technology/democratic-party-says-it-has-thwarted-attempted-hack-of-voter-database.html" target="_self"&gt;publicly announced an attack&lt;/A&gt;, which got wide-spread media attention. Today, they&amp;nbsp;&lt;A href="https://www.npr.org/2018/08/23/641189337/dnc-says-attempted-cyberattack-wasnt-russia-it-was-a-test-from-michigan" target="_self"&gt;ended up walking it back.&lt;/A&gt;&amp;nbsp; Apparently, their white hats and their IR team were not on the same page.&amp;nbsp; It also appears that the white hats may not have been engaged&amp;nbsp;by the organization that owns the servers, which does create a legal risk (&lt;A href="https://en.wikipedia.org/wiki/Computer_Fraud_and_Abuse_Act" target="_self"&gt;CFAA&lt;/A&gt;) for&amp;nbsp;the white hats.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Aug 2018 19:07:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Watch-out-for-your-White-Hats/m-p/13925#M1490</guid>
      <dc:creator>denbesten</dc:creator>
      <dc:date>2018-08-23T19:07:43Z</dc:date>
    </item>
    <item>
      <title>Re: Watch out for your White Hats</title>
      <link>https://community.isc2.org/t5/Industry-News/Watch-out-for-your-White-Hats/m-p/13951#M1497</link>
      <description>&lt;P&gt;Would you hire an electrician who was unaware of local building codes and electrical safety standards?&lt;/P&gt;&lt;P&gt;That&amp;nbsp;looks like&amp;nbsp;what happened in this situation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It appears that the Michigan Democrats engaged with a group of politically organized amateur hackers who think they are security testing professionals. Passion and good intentions are not enough.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For my extended thoughts, with added linked reporting beyond the NPR article see&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;A href="https://cragins.blogspot.com/2018/08/good-intentions-passion-professional.html" target="_blank"&gt;Good Intentions &amp;amp; Passion /=/ Professional Expertise&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Aug 2018 13:45:38 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Watch-out-for-your-White-Hats/m-p/13951#M1497</guid>
      <dc:creator>CraginS</dc:creator>
      <dc:date>2018-08-24T13:45:38Z</dc:date>
    </item>
  </channel>
</rss>

