5 ms·
There is a case to be made that you only need to be good enough to get in. I myself am not nearly at the level where I could write a hypervisor exploit even tho
by the_cyber_pass 10y ago
There is a case to be made that you only need to be good enough to get in. I myself am not nearly at the level where I could write a hypervisor exploit even though I have been in the industry for a while. However I feel pretty confident in my ability to break into almost any company if I set my mind to it. Fancy exploits are just things that take time to create and if your super great payload gets flagged by fireeye down the line you might have just wasted a ton of time for no other reason than showing off if powershell would suffice. So I guess I am torn on this because I don't want to flame the sysadmin's turned security people for not being a top speaker at blackhat or CCC because I myself come from that background, but on the other hand I think I should expect more quality work out of the CIA than what comes out of infosecinstitute. If this is the average of the CIA I really think NCC group might have more capability than the intelligence agency of the US government which is kind of crazy to think about. I am sure they have some really great zero days that they save for very important projects, but I doubt we will get to see the same level of capability that we saw out of the NSA leaks.