mnemonic security podcast
Hosted by Robby Peralta from mnemonic, one of Europe’s leading cybersecurity companies, the show features conversations with researchers, founders, operators, and security leaders working across the cybersecurity landscape.
Each episode explores a specific topic within cybersecurity: from incident response, threat intelligence, AI, and geopolitics, to leadership, resilience, and the changing role of security leaders.
The podcast is tailored to cybersecurity practitioners and decision-makers who want grounded conversations about where cybersecurity is going, what organisations should prepare for, and what experienced people are seeing.
mnemonic security podcast
Pentesting these days - Crowdsourcing
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
In this episode we chat with a hacker for hire aka pentester for mnemonic - Harrison Sand.
We start out with an update on how it is to work as a pentester these days, where Mr. Sand explains how he works with his customers and what his typical engagements entail. We then move into the concept of crowdsourcing security testing, and Harrison shares his opinions on when an organization should consider using such services, and the differences they should expect when crowdsourcing as opposed to using a "traditional" security consultant.
Technical level: 3/5
Host: Robby Peralta
Producer: Paul Jæger
From our headquarters in Oslo, Norway.
SPEAKER_01Welcome to the mnemonic security podcast. Today I have the pleasure of speaking with somebody that we all know very well. The infamous hacker and the black coat. Instead of hacker has a master's degree in computer networking and security from the University of Maryland. He's hacked his way into hundreds of organizations around the world, in a legal way, of course. And he's currently a penetration tester working for mnemonic in Norway. Harrison Stan, welcome to the podcast.
SPEAKER_00Thank you for having me.
SPEAKER_01So, Mr. Stan, how did you get brought into the world of hacking?
SPEAKER_00Personally, I think it's actually kind of maybe not the most exciting story. I think I've always been interested in IT and computers since I can remember. Um when I was in university, uh my first two years were kind of a generic IT track. Uh then I I landed an internship at in uh in the security department for a large international hotel chain. Uh and I I was I thought it was so much fun. Uh I was building like intrusion or uh filters for intrusion detection systems and uh working with like some really smart people and I thought it was something I really wanted to pursue.
SPEAKER_01Uh so yeah, you started off on the blue team.
SPEAKER_00Yeah, so I started off on uh I started off in the I guess defense side. Defense side. Yeah. Um and I I finished my degree uh specializing in security. Worked for about a year as a security analyst uh at another company and found out about mnemonic and started to get focused more on pen testing, and that's worrying.
SPEAKER_01That is the fun stuff. Okay, cool. Today I wanted to talk to you about crowdsourcing penetration testing and the whole concept behind it. And uh I figured you're the perfect man for the job because you are working as a you know professional pen tester, but you've also uh told me that you've done some uh some side work uh in the in the in the afternoons.
SPEAKER_00Yeah, so I mean yeah, full time I work as uh as a you know penetration tester for mnemonic. Um but then I I wouldn't say I've uh uh worked a huge amount of time with it, but I I have actually you know submitted some uh some vulnerabilities uh to you know crowdsourced uh bug money programs. So I have uh some experience with someone.
SPEAKER_01Quick money, yeah, cool. So um before we dive into that, uh I thought we would uh go through what it's like to be a pen tester. And just for the people that are listening to this that aren't a pen tester, how does how does that sort of go? How does the process go?
SPEAKER_00Yeah, so it's it's a bit well, it's a bit open-ended, but I mean a lot of the times we'll get uh you know, a customer is releasing a new application, or you know, they have some security concerns for something, or yeah, basically there's a million and a half reasons, compliance, etc. Um, they'll come out and reach out to us, say that you know, we have an application that wants to get tested. We'll sit down, we'll have a scoping meeting, we'll talk about you know what their concerns are, how the application looks, uh, you know, the back ends and also the you know business, uh, you know, what kind of business functions it fulfills um so that we have a better understanding. And then we make a contract, uh I'll sit down. You know, I I work a lot with web application testing. Um so you know, I'll a lot of the times it entails just uh you know, you set up a uh some kind of proxy so you can look at the traffic moving between the the browser and the server and just kinda mess with stuff, see where it goes, and make a report, send it off, and you know, some customers follow up and uh we'll work with them to help get stuff remediated. Sometimes they put it in put it in a file cabinet, and that's how things go. But yeah, that's basically basically the majority of projects that I get.
SPEAKER_01And then you're basically going in there and just trying to what are the like uh the rules they give you?
SPEAKER_00Yeah, I mean uh a lot of the times i of course it depends, but a lot of the times we'll you know test in uh we'll like to test in a non-production environment. Uh so if anything gets messed up or if the server goes down. Exactly. So it's not like uh super critical, you know, if if everyone's uh if the if the platform goes down, we're not actually affecting you know real money. Um yeah, but they'll give us access to like a uh development environment, um, some test users, and you know, we'll just start playing around like can I like a really basic use case would be, you know, if I'm user A, could I transfer money on behalf of user B? So like could I move money from your account to my account and and those kind of scenarios? So a lot of like application logic flaws uh we're starting to see uh we see more and more of issues or uh like that um because people are moving to using more standardized frameworks, so a lot of the traditional vulnerabilities like you know, SQL injection and cross-site scripting and we still see them, but uh fewer. A bit fewer as people move to more standardized frameworks.
SPEAKER_01But you you mentioned uh use cases, uh as in user A doing something for user B. How detailed are the customers in saying we want to test these use cases, or is that just sitting in your head?
SPEAKER_00Yeah, I mean, yeah, a lot of the some I would say most customers uh some people have gone out and like made a list of, you know, these are the things that we're concerned about, these are the use cases I want you to test. But a lot of the times it just comes down to, you know, what I think uh What do you think is best? Yeah, what I think like would be something to look into.
SPEAKER_01I guess that's uh has a lot to do with the maturity of the customer as well. It does. And their and their team.
SPEAKER_00Yeah. So like we we have we have some customers that reach out reach out to us and have never done a pen test. Um then they kind of leave it to us to guide them into what direction to go. Uh sometimes you know they have a lot of experience with pen testing, they've been doing it for years, and they'll have you know very strict guidelines on, you know, this is what we want and this is how we want it. But I think it's generally it's it's kind of nice to have somewhat uh an open-ended freedom to kind of look into things because as a pen tester, if I start looking into an application and I start seeing flags or indications that something is a little bit fishy, like I want the freedom to look down that path instead of being, you know, strictly have to follow a book. Have to follow a book, exactly. I think you get better results.
SPEAKER_01Yeah, because haptors don't follow a book. Exactly. So um the the customers that you're working with, do they pen test stuff before you come in and you're like, okay, they they uh maybe they do like some sort of uh software sort of test and then you take the results, try to do something like that, and then once they've done everything they can possibly do, they hand the ball over to you, which are like the the big boys when it comes to hacking or yeah, in in my experience, I mean some customers do some degree of testing uh on their applications, like it could be could be part of their um development lifecycle.
SPEAKER_00Like m I've seen customers that'll uh you know maybe they'll run a vulnerability scan on the you know infrastructure before they go into production, or or they'll have uh some kind of web application scanner. Um generally I don't get to see the results of those. Uh sometimes you do, sometimes you don't.
SPEAKER_01So how easy is it for you to hack into a you know an average company?
SPEAKER_00Yeah, so I guess like a lot of my other answers, uh highly dependent, but uh if you just took an average company, small company off the street, as a general rule, if you have enough time and if you have enough resources, I don't think anybody's safe. Like, I mean, not even the NSA. Nobody's safe. But it's all it's all a balance of uh you know how much will how much time somebody's willing to spend. I mean, if you're selling cupcakes, probably don't have many people after you willing to spend the time to uh Exactly. But um, you know, if you're the NSA, obviously you have some uh dedicated adversaries who are interested in getting what you have. Exactly. Um so probably not too hard necessarily. Um but it's more who's actually interested in doing it, which is probably actually I mean, in my personal opinion, that's probably saving most of us. Uh is just or not yeah, basically the lack of hackers is saving us. No, but it's it's more just the yeah, it it's more just the the balance of uh the amount of yeah, the amount of time somebody's willing to spend to what you have to for them to take.
SPEAKER_01Yep. Alright, so now let's get into the uh the main topic of today. And uh that goes around crowdsourcing pen testing. Because uh, I mean, I'm not working with this from day to day, but uh from my side, the way I look at it is uh you get a customer, they call you and say, Okay, now we're planning on releasing a new update or releasing a new product, and uh for compliance reasons or for because we have a security guy that we actually listen to, we gotta test this stuff before we put it out there for people to actually use. Right. And there's a lot of companies that put stuff out there before testing it properly, and we've read about that in the newspapers. Yes, unfortunately, for them. So pen testing today is that company will call mnemonic or call uh uh KPMG, EY, whatever, some some company uh and get some of their uh some of their hackers to come test the application for security vulnerabilities. And that process, I'm imagining, takes a while. They have to first, you know, on the customer side, they have to determine the scope, they have to figure out what you can and can't do. Um they have to have uh they have to have a budget for this because you guys are not cheap and you're actually not very easy to find either. Um every company's hackers is sold out, it seems like, which is uh so it's good business. But now they have this new concept where uh you can just crowdsource it. So instead of having to uh go after or you know go through this whole process of finding the right hackers and finding the right company, you could just go online, put your pro uh document your project, tell them what you want to know, tell them what you want to look for, uh, and then all the hackers in the world can just hack your application.
SPEAKER_00Yeah. Um so I think I think the two can complement each other, um, but I don't think either one can replace. So I think uh in I think they both have a I think they both have value, um, but they fulfill different roles. Uh so if you have you know a dedicated penetration tester, of course, like as you mentioned, expensive, hard to get, uh a lot of time getting things set up. Um but I think it also provides uh a certain value that you're not gonna get out of a crowdsourced pen test. Also, on the other hand, I think that uh having a um you know having a bug bounty program and and being on a crowdsourced uh you know pen testing platform, I think can also provide benefits that you're not necessarily gonna get from a dedicated penetration tester. Um so it uh I I would like to see a world where where both are used. I think you know the more eyes on security, uh I think we're all off for the Yeah.
SPEAKER_01And in this world of yours that you just mentioned, this perfect little uh this perfect little world. Yes. How would you do it if you're a company?
SPEAKER_00Honestly, I I would probably do both um from the from the crowdsource pen testing perspective. I mean, I think it provides a really good outlet for um you know maybe otherwise malicious uh hackers. Uh, you know, if if if somebody finds a vulnerability in your product. Uh traditionally, you know, well, if somebody found a vulnerability in your product and wanted to make money off of it, traditionally, you know, they could go to the black market or the quote unquote gray market and and sell it to somebody for who knows what. Um but now if you if you're on a crowdsourced pen testing platform, uh they have a you know legitimate way to uh notify you, um, get a financial reward, and I know it's a good incentive to uh you know disclose vulnerabilities to the to the vendor. Um so I think uh I think you know it's important to have for that reason so that you're you're kind of directing uh you're directing hacking activities in a in a positive uh in a positive way. Um and not to say, you know, of course, uh you know, there's just one aspect. There are a lot of people who make a living uh on these uh crowdsourced uh platforms as well. Um but also on the on the other hand, I think that uh you don't get ness you don't get the same kind of depth and you don't get the same insured quality uh from a crowd crowdsourced platform. I mean when you when you hire a pen tester, you're uh for example, as part of before you release something into production, you'll have an application, it's internal uh because it's or it should be internal because it's still in development. And before you release it to anybody, you want to be sure that it's it's safe. You know, in that kind of instance, uh you have somebody that really focuses on the application. You know, they work with the development team, they know about the application, you know, it's uh you basically have a dedicated security person on your team for a dedicated amount of time. And I think the value is, you know, they they learn more about the application. Um they can uh for example, like if you have a if you have two weeks to do a test and um uh the security guy is interested in, you know, sees some indications of something being a bit fishy, you know, they can sit down with the uh uh development team and and maybe it wasn't a full uh exploiter or like exploitable uh security issue, but maybe okay, maybe best practice would be to like rethink how we do this. Do this another way, yeah. So it's it's uh a lot more intimate and uh involved method of security testing that I and and when you crowdsource uh it's kind of you know it's it's a bit more removed. So they don't uh I don't think you're gonna have as as uh generally I don't think you're gonna have as you know in-depth and tailored results.
SPEAKER_01So in your perfect world, you would you would hire in an external you know uh you would hire a mnemonic, for example, uh for testing or uh you know uh hacking wh while you're developing the application. And once it's m once you've maybe released that, then you can open it up to uh crowdsourcing.
SPEAKER_00I mean I think I I think that's a valid way to go, but I would also say that you know you should conduct penetration testing for you know sensitive applications on some kind of routine schedule as well. So sure, if you wanna if you wanna do a a test with mnemonic um before you release something into production, you know, open it up to a crowdsourced uh platform. But then I think also the I mean you still only have with crowdsourcing, you only have that kind of surface level uh yeah, that uh surface level uh testing.
SPEAKER_01Um which is what the hackers have.
SPEAKER_00It's what the hackers have, but I mean but you so generally when when I do security testing, uh uh my preferred uh method would be it's kind of like a white box security test. Um because you're even though it may not simulate a true hacker on the internet, um it uh it allows you to learn more about the application, you work with the developers, and like I mentioned, like it allows you to uh find those security best practices that you might be missing and kind of just overall build a more secure application. So because so let's say you have you have some crown jewels uh you know uh inside your infrastructure and you have a web application on the internet and there's let's just say hypothetically three layers of security in between. Uh if you hired a crowdsourced uh pen tester or did some kind of like black box testing where you just said here's an endpoint, go at it. Uh maybe they would only find something if all three security mechanisms were broken. But if you hire somebody and do a white box test, um we might find that two of those security layers are broken and report on that, and then you can you know have a have more security in depth.
SPEAKER_01Because the way you tested it.
SPEAKER_00Yeah, basically like yeah, it allows us to know more and allows us to see the missing gaps that might not be visible to somebody from an external perspective.
SPEAKER_01How easy is it to uh sell an exploit on the the black market?
SPEAKER_00Depends on your depends on what the exploit does and what kind of product it is. Uh generally I would say probably not too hard. I mean uh a really valuable exploit. Uh let's say you found something in uh you know the latest version of iOS or Android, you know, it would be taken up in minutes and you'd probably be able to buy a nice house.
SPEAKER_01Well where do you go with that?
SPEAKER_00Like uh you can't just go on Google or Finn and just say uh actually if you Google like where I would like if you Google like where to sell iPhone exploit, uh there's some uh there's some you know legitimate uh exploit brokers uh who will go on and like sell that to uh well China or Russia or Yeah, it depends on which one you choose, but basically, yeah. People with deep pockets. Uh yeah. Um so you I mean, yeah, so you have you know what basically if uh if I find a vulnerability, like one route is to you know go on the the black market and sell it, I can go through one of these brokers who's kind of like a gray area sending or selling to the NSA or whoever. Um or you can uh disclose it to you know Apple. So prefer I mean in terms of uh you know bettering security for everybody, the preferably I would disclose it to the mother would want you to give it to Apple. Yes. Like in a yeah, in a perfect world, then uh we'd all be giving it to Apple, and that's why I think it's important to have you know these kind of crowdsourced uh pen testing platforms and and bug bounty programs, because then you they have a reason to do that, right?
SPEAKER_01Yeah, and we looked uh I won't say who we looked at, but we looked at uh a couple of different Norwegian companies, big lot also big for Norway at least, and we just tried to uh imagine, okay, say we did find an exploit, uh let's go to their website, let's see who we talked to. And we did not find a single none of those companies had a website or that was easily you know findable saying, hey, if you found a vulnerability, let us know here.
SPEAKER_00Yeah, like at least they may have had something, but we didn't find it. Oh, yeah. I I mean, yeah, I was not able to find it. Yeah. Um, so and I think it speaks a lot to the security maturity for a lot of these organizations. And um, you know, if you're really dedicated and you know have good intentions, you probably could go on LinkedIn and find somebody with security in their title and try and send them an email. But uh generally I think that process should be easier um to to incentivize you know disclosing these types of uh findings.
SPEAKER_01And uh I mean we we sat down together and looked at uh stuff like Hacker One and there's a bunch of you know cool new platforms out there that uh that offer these sort of uh that offer you help. But what is that help? Like uh you mentioned bug bounty programs, we also looked into disclosure policies. How does that hang together?
SPEAKER_00Right. So they'll I mean if you if you're a company and you wanna, you know, jump on the bandwagon and and and get crowdsourced pen testing and have a bug bounty program, it's kind of a one-stop shop for that. Um so they have templates for setting up disclosure policies. Um you know, they know what's common in the industry and they'll help you uh they it depends on what you want, but you could they can help you start uh you know filtering the reports that you have for vulnerabilities, so you know they can kind of filter out the noise and only send to your experts uh what they think is stuff they want to know, need to know. Exactly. So they'll you know they'll they'll have they'll set you up with a policy, they'll provide a platform for disclosing vulnerabilities, um and communicating with the with the hackers. The hacker or the researcher or whoever. Uh and they also uh can facilitate uh payouts for for bounties as well.
SPEAKER_01Well that sounds like a good idea, because I mean those companies we like that should definitely look into uh how how does um Okay, I don't wanna I don't wanna say defend your job, but okay, in five years from now, say that everybody starts uh, you know, going this way, which I really do believe they will. What is going to be the role of where are you gonna be in five years?
SPEAKER_00Honestly, I mean I don't think I don't think things will change too much. Uh the I I would I mean I work as a full-time penetration tester, and I would be very happy if more companies joined these kind of crowdsource platforms. But I also know that they you at the same time, like you can't uh assume that uh one of these platforms replaces a real uh dedicated penetration test. They might advertise that they help you become compliant, and and I'm not saying that they won't, but I'm but uh I don't even if you're compliant, you may not be actually bettering security to the best that you could. Uh so I guess in that sense, then uh I disagree a bit with how those compliance.
SPEAKER_01So do you think that maybe it should be that uh maybe uh a professional company um they actually help cust their customers to set up these sort of platforms so they're doing the right things and Yeah, I think that I mean uh a lot of companies could benefit from something like that.
SPEAKER_00Uh in my experience, you know, when I've I've submitted a few findings uh uh on on these platforms before. And I have had good experiences and I've I've talked with knowledgeable people, but I've also had the opposite happen as well, and it's really discouraging, and it kind of if if you have a finding or or uh see something wrong with their software and and you want to disclose it to them, but then you reach somebody who's obviously not very knowledgeable in security and kind of blows you off, and then you like you don't really want to work for them again.
SPEAKER_01Yeah, because that just means you wasted your time. Exactly. And that and you showed me like you made five hundred dollars in that in an afternoon just by just by I mean, I can never do that, but uh you made five hundred dollars in Afternoon, right? And um that was to a company that actually understood what you got on the other on the other side. It took maybe how was the process?
SPEAKER_00How long did it take them to so I I uh was looking into just in my spare time, I was looking into uh uh a product that I was using personally. Um saw something that was kind of interesting, uh, and then I I looked them up uh looked them up online, uh found that they were part of this program, uh submitted my finding. It depends on the company, um, but in in this instance, I think from the date that I submitted my finding until the payout for the uh bounty. Uh it was about two weeks altogether. So not two weeks. Not too bad.
SPEAKER_01Okay. Yeah. Yeah. And uh what do you think they did with uh the stuff that you gave them? Because they was this on some sort of this was on a bug bounty uh program thing, right?
SPEAKER_00Yeah, exactly, exactly. So no, they actually um no, it was it was really good. I I submitted my finding. Um I we had communication, we walked uh we talked back and forth. Uh they patched the vulnerability. Um they sent me a link to this uh updated uh version that they were planning to send out into production, I verified that the vulnerability was no longer present and they sent out the payments.
SPEAKER_01So that was a very that's very professional sort of uh Exactly but I company.
SPEAKER_00Exactly. And I think in the cases where um maybe a company's not necessarily mature in security, and if uh a researcher or a hacker, whoever who's you know very knowledgeable on the subject is submitting their findings to a company and they don't necessarily know how to handle them, uh you know it's it yeah, like I mentioned, it can be very discouraging. So I think it's important to have somebody there who knows how to handle these issues, um, so that hackers are, you know, uh you have a good relationship with the the hacker community. And so I think if if if you don't necessarily have those resources internally, I think it could you could really benefit from you know bringing somebody in from the outside.
SPEAKER_01Yeah, exactly. That's where these uh that's where you know a company you work for or other you know other of your competitors can come in, I guess. Yeah. And I think that that that to me sounds like that's gonna be what's gonna happen.
SPEAKER_00Yeah, I I think that uh that could definitely be something in the future. Or if not already today.
SPEAKER_01Is it really expensive for companies to set up the I mean I didn't look at any of the price lists for any of these uh platforms, but do you think it's expensive for a company to use that platform for to set up that policy and stuff?
SPEAKER_00Or is it like honestly, I I don't I I would assume I haven't looked at the numbers, uh, but I I think it is generally cheaper than if you were to quote unquote get a pen test from a dedicated uh uh security professional. Um but I also think you're getting a different product. Yeah, exactly. So um yeah, just in my mind, kinda two different things.
SPEAKER_02Yeah.
SPEAKER_01I was gonna comment on that. I was uh looking forward to making a joke in the opening saying that you're actually sitting in uh in the studio with a a button-down shirt. Yeah. And uh you're a good looking guy, you have gel in your hair, you don't stink. Um Yeah, I mean, I I guess I was kind of mean to say that you would stink, yeah.
SPEAKER_00I'm gonna get hacked. If you've been to some of the hacker conventions, I don't think it's uh too far off. Okay. Um no, but I guess I have to be presentable for customers. So there's a there's a fine line I have to walk.
SPEAKER_01Yeah. For so for Paul in the room that's our producer, he um should he be more inclined to choose a company that has a bug bounty program than one that doesn't? I mean why why should the guy in the street care?
SPEAKER_00Yeah, I mean if so if if I'm looking for a product or if I'm trying to buy something or or want to get an impression on how the security for a company is, uh I absolutely like if they have a bug bounty program, uh Plus two points in your book. Yeah, I mean absolutely. I mean it's it's it it says that you have at least thought about security. And and if you're aware that security is an issue and you want to spend time on it, and you know, I I think that it goes a long way to say who you are. Um so I mean uh from that aspect, I think people should care.
SPEAKER_01Yeah, and just to put that in context, you were the lead investigator for the the watch out uh uh program that uh the Norwegian um what do they call it?
SPEAKER_00Norwegian consumer counselors.
SPEAKER_01The Norwegian consumer counselor had a project called Watch Out, which basically uh they looked at all the watches, the smart watches. Uh and long story short, uh after I'm sure which is hundreds of hours of pen testing, uh, they found out that a lot of these watches uh were used, you know, they these were child's child's watches. My sister's son has one of those child's watches and they can he was able to figure out where those kids were. Um they could even hack into their microphones and stuff like that. So if you're yeah, so that that's why somebody on the streets you care, right? If your son or your daughter's running around with one of these smart watches.
SPEAKER_00Right, exactly. So I mean I yeah, uh I mean you get what you pay for. A lot of these were weren't necessarily the most expensive things on the market. Um but yeah, like if if if there was a company out there uh who you know if you if you were in the market for one of these devices uh and you wanted to find the one that was uh secure or made by a company who cared about security, you know, everybody everybody says quote unquote it's secure in marketing material and uh but what does it actually mean? But if you actually looked behind the scenes and like, okay, uh are they part of the hacker community? Like do they want to do they incentivize people disclosing to them? Like how uh get a sense for how uh security aware or mature they are? You know, if if they had a bug bounty program, I would definitely take them more seriously.
SPEAKER_01Is there any place that um normal people like uh Paul can uh can go to check out like these sort of things, or do they have to sort of go through the whole process of do they have a boundary program?
SPEAKER_00Well, it's not it doesn't have to be terribly hard. I mean, for example, uh you know, if you any any big company, if to Apple, Microsoft, uh whoever, if you just say, you know, just Google report security vulnerability, Apple. And in the probably the first result or two, it'll it'll redirect you to their page and you know how they handle and it'll probably talk about their disclosure policy and you know uh things along that line.
SPEAKER_01So what is the difference between a good uh pen tester and uh not as good pen tester?
SPEAKER_00Yeah. So I I guess that's a tough question. I mean a lot of the starting out, I if I'm just looking at myself and like starting out like what I think uh has really I've what I think I've gotten better at and what I think has really like made myself as a a better penetration tester is um really understanding and trying so instead of just running if I see it if I see some kind of application and if I'm just throwing tools at it and hoping to get some output, you know, that's where everybody starts. Um but it's not necessarily gonna give you that a good penetration test. I think if you if you really work to kind of understand how the application works, if you try and think like a developer and and think about like you know, this is why the application was built the way it is, um and you start looking into application logic and you use uh you you still use these tools and you use uh you know automated scanners and and everything, but it's uh it's more of an assistance rather than the test itself. So if I run an automated scan, uh maybe it finds uh it gives me like a small indication of something, and then now I have a route to follow uh to dig deeper and to you know see if I can and find something there. Yeah, exactly. So I think like being able to know understand the application, know where to look, and like know and have a sense for like when to dig down into something.
SPEAKER_01Uh understand what you're testing testing. Exactly. And I guess that's the difference between uh, you know, hiring in a company like like or hiring you than hiring in uh a crowdsource sort of thing. I mean you actually sit there and understand.
SPEAKER_00Exactly. And I I think there are um there's definitely really good uh people who who work on these platforms and these like crowdsource platforms. But you, for example. Uh but I mean the yeah, you don't you don't st you still don't get that benefit of you know dedicated time sitting with the developers, understanding the application. Uh it's just a level of of depth that you don't get.
SPEAKER_01I guess the in summary the difference is that you you uh versus these uh crowdsourced pen testers, you're the same person. But those you're sitting in the room with the customer and with the people that have built it and can and speak to them, and these other people aren't.
SPEAKER_00Yeah. And I mean just just being able to, just on like a s like on a personal level, just sitting with the team, bouncing ideas off of each other, working together, uh, I think it's much more productive than kind of you know if you're working isolated uh on two separate, just I think uh I think it goes for anything, really. I mean we need to work together.
SPEAKER_01Yeah. So uh my last question for you. Does everybody that's working in pen testing have a black hoodie?
SPEAKER_00Some of us do. Uh uh maybe 50%.
SPEAKER_0150%. 50%.
SPEAKER_00That's my rough estimate.
SPEAKER_01All right. Well, Mr. Tan, thank you very much for sharing your uh your competency with us. And thank you for having. And uh, I'm gonna come back to you in five years and we're gonna see uh how the market has changed. Sounds like a plan. All right. Thank you. Thank you. Well, that's all, folks. Thank you for tuning in to the mnemonic security podcast. If you have any questions or any concepts that you would like us to discuss on future shows, please feel free to send us an email to podcast at mnemonic.nl. Thank you for listening.