Are there any resources you could recommend to those (like me) who want to learn more?
Ask HN: Where did you learn about security/attacks?
1–6 of 6 posts
Re: Ask HN: Where did you learn about security/attacks?
#2Re: Ask HN: Where did you learn about security/attacks?
#3It's unclear what exactly you want to concentrate on. Do you want to learn about encryption algorithm details and want to understand the design decisions behind them or do you just want to effectively use them? Do you want to learn about proper architecture and general principles?
edit: feel free to contact me if you have any specific questions, I'll try my best to weigh in on specific issues.
Re: Ask HN: Where did you learn about security/attacks?
#4Pentesting/security analysis has been my hobby in high school/early college and I ended up getting BS and MS degrees in CS, with concentration in security. It's also my day job. It's unclear what exactly you want to concentrate on. Do you want to learn about encryption algorithm details and want to understand the design decisions behind them or do you just want to effectively use them? Do you want to learn about prop…
Re: Ask HN: Where did you learn about security/attacks?
#5Pentesting/security analysis has been my hobby in high school/early college and I ended up getting BS and MS degrees in CS, with concentration in security. It's also my day job. It's unclear what exactly you want to concentrate on. Do you want to learn about encryption algorithm details and want to understand the design decisions behind them or do you just want to effectively use them? Do you want to learn about prop…
Certainly more the former, but I think that the latter will come as a natural result. I would love to learn both the algorithm details/design as you mentioned and at the same time, some of the attacks available on them (my assumption here is of course that there are a set number of attacks that people would try on a new algorithm; it's entirely possible that is not the case :) ).
If it's not too technical, try finding some articles in phrack(.org) magazine. They usually outline the details of attacks and will let you see what vulnerabilities attackers take advantage of. If you want to stay technical, I'd look for exploits online and try to understand how they work. If you start at the defensive end, it might not be exactly clear why some counter-measures are in place and might be more dry than playing with something you can actually break.
Get a very old Linux install, disable ASLR, PaX, W^R and anything that might stand in your way and create write your first buffer overflow attack. Then try a a heap exploit. Then move on to more interesting things. Try to follow security conferences and the papers presented there. Attend security-related meet ups in your area. Idle in irc channels, etc.