Women make up only 24% of the information security workforce, which is a troubling number in an age when equal representation is needed more than ever.
Ethical hacker, bug hunter, and hacker advocate Chloé Messdaghi wants to change that by advocating for more women and underrepresented genders in the hacker field. Bug hunting in particular is a hot topic, since more businesses are offering payouts for hackers who find and report vulnerabilities in their networks and sites.
Messdaghi is the founder and CEO of women’s hacker advocacy group WeAreHackerz, leader of the San Francisco Bay Area chapter of Women of Security, and an advocate for hacking as a more acceptable way to protect enterprises from malware. Here are her thoughts on security, representation, and hacking for the forces of good.
What’s your hacking background like?
I’ve been in the field for three years now; before I came in, I was a management consultant for a cyber security company. I kind of learned it by accident. When I started working at a company called Bugcrowd, which is in the bug bounty space. I had a manager named Jason Haddix, who is pretty well known in the bug bounty space, and he started teaching me the basics in Burp Suite.
I still promote bug bounty. I think it is one of those things that we don't really talk about how much it has impacted the infosec community, especially the hacker community, because it's the first time that companies or organizations are communicating with the hackers. That's kind of a game-changing moment, because it's slowly changing the stereotypes of hackers and starting to bring more of a bilateral trust amongst organizations and hackers. Hackers are scared to report vulnerabilities — 60% of them that find vulnerabilities don't report it — because of the fear of being prosecuted by an organization.
Now one of the things I work on is social engineering. So I will test people in companies, if they are on their toes when it comes to being phished or hacked.
So when I do it for training purposes, usually where the person doesn't know they’re being tested, what I'll do is I'll send an email from maybe like a spoof personal email for the manager saying, for example, “Hey Jen, you've done such a fantastic job on the past few months, and I've recognized it and I just wanted to give you this Amazon gift card,” with a [malicious link] in the email.
That's one way to do it. The other way is if I'm trying to get a hold of an assistant, I’ll usually write, for example, “Hi, Tom I need to have this PDF printed out immediately. Put it on this person’s desk, if you can do that within the next hour or two, that'd be fantastic. This is an urgent matter.” And usually the assistant downloads the PDF.
It's fun sometimes, but also it lets you know that you have to be on your toes. I always tell people to not check your emails unless they've had their caffeine intake. Attackers are aware that on the weekends and evenings you're probably under some sort of influence, or you're not fully awake yet. And so that is the perfect time to launch an attack.
And there's definitely a need for that, especially now because everyone's emotions are all over the place, we're dealing with burnout, and we're also in the big unknown. Because of all this stuff happening, it makes you a victim right away.
What are your favorite aspects of ethical hacking?
One of my favorite aspects of it is that a hacker has made a conscious decision to do it on the good side, which makes me really happy because there are a lot of malicious actors out there. We need as many ethical hackers as malicious actors to try to prevent these situations from occurring.
The thing that I love about the hacker community, in general, is that everyone supports each other and they hold each other accountable. If you were to go out of scope and you exploit something and you shared it online, the bug bounty community will call you out on it. Hackers are already on a fragile line as it is when it comes to recording things and the way that the public perceives us. When one person acts out in the way they're not supposed to, it removes trust that has taken a very, very long time for an organization to have when coming to work with hackers.
What are some of the most valuable skill sets that you've found that you need to rely on?
Curiosity. No matter if you're technical or not technical, curiosity is something you need to have, because infosec is such a big field of its own, and it's very different from most other tech sectors. New things are happening all the time, new tools get out all the time, new vulnerabilities to exploit happen all the time. If you have that constant curiosity, and you ask yourself how can I outsmart this and that, and how can I do whatever I can to serve and make sure that I'm protecting people, then you’re set. Many of us came in here because of the curiosity, and many of us came in here because we want to prevent attacks from occurring.
I would [also] say the ability to keep up with the news. Infosec Twitter is definitely one of those things you have to be part of to understand what's going on. Follow people, ask questions, reach out to people. The thing that I really love about this industry is that you can write to a complete stranger, and most likely they’re gonna respond to you.
Why are you an advocate for ethical hacking? Why is ethical hacking so important?
For me, it’s hearing people's stories of what it's like when you want to report something that you found, and you just can't because you're worried that you're going to be prosecuted if you even give them just a small mention.
It's sad to see all these incredible people that are trying to do something good, but the laws themselves are so out of date. I mean, we're still dealing with anti-hacking laws from 1984. We have anti-circumvention laws around from 1998. And when you think about it, that was a whole different world than how we are today. That was before Y2K.
It's really sad to see that this is still an ongoing thing. And then when you see the press reporting how hackers are these terrible people, they're doing these terrible things, you have to remind them there's a difference between a hacker and a cyber criminal. Even still today, when I tell people I work with that in the hacker community, they take a step back, or their jaw drops, because they're afraid. Sometimes hackers do report it, but companies don't fix it in time, like what we saw on Equifax. You need a lot more ethical hackers than cyber criminals in this world.
What kind of challenges have you come across as a woman in infosec?
There are many. In my first year of work in infosec, I actually almost left. It got to a point where it was just so bad — I could not believe that people are putting up with this BS.
In the first two weeks of joining infosec, the first cybersecurity company I worked for, I looked around the offices, and thought, where are the women? I remember researching and finding out that like, only 11% of people in infosec are women. That scared me, and it really sunk in when I went to RSA in 2018 and I was in a room for a talk, and I saw that there were only a couple other women in this room that had hundreds of men.
I had guys call me baby, or they turn around and tell you, “Oh, can you give me a water?” “Hey, aren't you supposed to be taking down notes?” I would make a comment in the boardroom meeting, and no one would hear me. It would just be like crickets. And then a guy would say the same thing I did, and everyone went to applaud him. And it just kept occurring.
After all that, I basically was looking for jobs outside of infosec. I was like, that's it, I'm out. But then I went to a conference called Data Security and I walked in this room, there's like 200 women in there. It was the first time ever I saw women in infosec, like a whole group of women in infosec and I didn’t feel isolated anymore. It made me realize: I need to fight for this. We need to fight for this.
Since I've been in infosec, I have been assaulted twice at conferences. I've had men try to get into my hotel room a few times as well. As you can imagine, it gets pretty scary. So now I don't stay in conference hotels, I usually have someone with me at all times when I'm in public, to try to protect myself when I go to conferences. And I still continue to do that to keep myself safe.
What advice do you have for both women and young professionals breaking into the hacking space?
Have a support group. I also really recommend that also to never, ever, ever be silent about anything that has happened to you. That is bad. Because chances are there are other people out there that have gone through something just like you have, and they need to hear your story so they can come out too. When it comes to if you have been assaulted or sexually harassed at work, make a police record. Don't go to HR. HR is not there to help you. They're there to protect the company. And so by filing a police report, it prevents that person from ever doing it again.
As well, I always recommend reading into the people who are known in the field. There's this great book series called Tribe of Hackers, with different editions for different career paths. That is so important, because I think that when you're starting to see if this is a field for you, you need to read about it and research it. It’s one of my favorite books in this industry because it really touches on all the different elements in hacking that play a role.
Any final thoughts?
In terms of gender representation in the industry: It’s not changing fast enough. We need to fix what is happening internally before we recruit more women because, if anything happens to these people, you feel that guilt with it. We need to fix it.
This interview with an ethical hacker has been edited for brevity and clarity.
Update: August 17, 2020 at 11:33 AM MT
After publication Messdaghi reached out to SDxCentral asking to clarify some comments stated in her interview. She said, "For further context, I’d like to offer these points to the SDX article about me to provide better clarity to the story. I’m not just a leader of the San Francisco Bay Area chapter of Women of Security, I am the co-founder and president. I was never a management consultant for a cybersecurity company, but was one prior to entering infosec. My first job in the infosec industry was a marketing manager. The 200+ women attended conference is called Day of Security. If a woman has been assaulted or sexually harassed at work, I encourage them to contact their local police and file a report – it’s not about creating a police record. It’s about reporting a crime.
To clarify, I am not a 'bug hunter' today. I’m an ethical hacker and ethical hacking advocate. I represent marginalized genders in infosec, not 'women and underrepresented genders in the hacker field.' WeAreHackerz is a private virtual hacker community of marginalized genders, it's not just for women and wasn't set up to be an advocacy group, instead it's a supportive community to empower each other. I don’t advocate hacking as a means of protecting enterprises from malware, but instead advocate for changing public perception of what a hacker does and seeking legislation to benefit ethical hackers. I always have permission from companies before testing company employees to see if they are on their toes when it comes to phishing or being hacked. Lastly, we need more ethical hackers than malicious actors to prevent situations from occurring."
Comments