Think like a hacker: Ethical hacking
One of the best ways to secure your source code is to try to hack it yourself. DAST is an automated form of this, but there’s no substitute for having clever people try to outsmart your software.
What makes ethical hacking “ethical"?
In GitGuardian’s Security Repo podcast,10 Mackenzie Jackson interviewed Snyk’s Sonya Moisset about ethical hacking. According to Sonya, ethical hacking is “identifying and exploiting vulnerabilities in computer systems or networks in a responsible and lawful manner.” It’s been around for quite a while. In the late 1990s, journalist and security researcher Carolyn Meinel published a book on it called The Happy Hacker.
Sonya described four main tenets that ethical hackers are supposed to follow:
- Only hack with permission...