You understand that legally speaking this is approximately the same thing as telling your boss that the front door isn’t strong and thieves could easily kick it in, and then when they refuse to fix it, the response you’re suggesting is “show up at 3 am and take a sledgehammer to the door, but just dont steal anything from inside” right?
The point is to cover your ass, not pull your pants down.
Yes I understand the intention, but in one of these scenario’s I’ve covered my ass legally and if something happens where the company gets ransomware for example, I likely get paid thousands of dollars in overtime restoring backups and the user ends up updating anyway, and in the other I can go to prison, lose my job, and never be able to use my time at that company as a reference on a resume let alone probably easily get a job again because now I have a criminal record.
I know this because I have lived scenario A probably 6 times in my life.
I know, I live those scenarios too, I said let some 4chan degenerate do the dirty work, get paid for fixing it and get your network in check - if you morally can’t handle that situation because of the data, then do it yourself and you can ensure that your boundaries are not crossed.
Free pro tip: If you do it yourself, you still get paid to fix it ;D
Then compromise the machine yourself without stealing personal data from unrelated people.
You understand that legally speaking this is approximately the same thing as telling your boss that the front door isn’t strong and thieves could easily kick it in, and then when they refuse to fix it, the response you’re suggesting is “show up at 3 am and take a sledgehammer to the door, but just dont steal anything from inside” right?
The point is to cover your ass, not pull your pants down.
The point is to get him to switch so you have peace in your network and don’t have to handle the shit show when someone else does it.
Yes I understand the intention, but in one of these scenario’s I’ve covered my ass legally and if something happens where the company gets ransomware for example, I likely get paid thousands of dollars in overtime restoring backups and the user ends up updating anyway, and in the other I can go to prison, lose my job, and never be able to use my time at that company as a reference on a resume let alone probably easily get a job again because now I have a criminal record.
I know this because I have lived scenario A probably 6 times in my life.
I know, I live those scenarios too, I said let some 4chan degenerate do the dirty work, get paid for fixing it and get your network in check - if you morally can’t handle that situation because of the data, then do it yourself and you can ensure that your boundaries are not crossed.
Free pro tip: If you do it yourself, you still get paid to fix it ;D
Yea I don’t trust the opsec of some random 4chan user to cover their tracks and therefore mine in that scenario.
I’ll just take the option that guarantees I can’t go to jail and ruin my entire fucking life lol.
How is the opsec from some 4chan degenerate having impact on your opsec? Only correct answer is, because you have bad opsec.
Hmmm yes I suppose that is true.
Nonetheless I’ll always opt for the course of action that has the smallest potential negative impact on my personal life.
Well for a security professional, it should not be such a big deal.