2658 8:44 Throwback Thursday

TBT: Ethical Hacker Earns Big “Bug Bounties”

In this week’s “Throwback Thursday / Where are they now?” segment, we hear from an ethical hacker who carved out a niche in cybersecurity by safeguarding small businesses. Today, we're updating you on his pivot to earning through bug bounties.

8:44

Subscribe Now For A Free Five Step Tutorial

Get a free five-part email course that shows you how to find, validate, and launch your side hustle idea — no experience required.

Episode 2658

Welcome to Throwback Thursday / “Where are they now?” where we take an in-depth look at someone who’s story has evolved considerably since we first featured them.

Last week, we heard from a statistician turned fantasy sports strategist, who leveraged his knack for numbers to launch a fantasy sports analytics business.

Today, in our latest feature, we’ll hear from an ethical hacker who carved out a niche in cybersecurity by safeguarding small businesses. Today, we're updating you on his pivot to earning through bug bounties.

What’s happened since? Let’s hear directly from them. I’ll be back at the end to wrap us up.

Listen to today's episode to hear more...

Yours in the revolution,

cg-sig-newsletter

Read the full transcript

This transcript was generated from the episode audio and may contain minor errors.

[Music]

Ethical Hacker earns big bug bounties. We're gonna talk about bug bounties today. I haven't talked about those in a long time, several years, I think. Bug bounties, if you don't know what that is, I'm gonna explain it and you're actually gonna hear a listener story from an Ethical Hacker, a guy who's like a programmer, a coder, and he's not trying to break into stuff. Well, he actually is trying to break into companies, but not really to steal from them, more like to discover a vulnerability so he can report it and then get paid.

So it's an interesting little world, an interesting niche in the world of cybersecurity where people actually are earning some significant bounties. The companies basically pay people to find these exploits and then instead of exploiting them to actually report them so they can fix them. So we're gonna update you on his pivot to earning through bug bounties. He initially was focused more on safeguarding small businesses. You'll hear more about the update from him.

Let's see, last week we heard from a statistician turned fantasy sports strategist who leveraged his knack for numbers to launch a fantasy sports analytics business. And of course, today we're gonna go to hear from this Ethical Hacker and see what he learned, how his business has evolved along the way. Sometimes when we highlight a business that we've featured in the past, we hear what's gone well, what's been challenging, or just like, what is the next iteration? I wanna encourage you also, as you are developing ideas, don't be afraid to evolve and move on to something else. Iteration is actually, I think, an understudied secret of entrepreneurial success.

Most of the time, most people who are running a business, whether a side business or something that they grow into a full-time thing, it's going to have different stages and that's normal. So the way you progress through the stages, your willingness to do so and your curiosity about what might come next is actually pretty important or a good predictor of success, let's say. And without further ado, let's hear from Kai. He's gonna tell us about those bug bounties. I'll be back at the end with a couple of brief comments.

[Music]

My adventure into the realm of ethical hacking began with the focus on protecting small businesses from the myriad of threats lurking in the digital shadows. However, as my skills sharpened and the cybersecurity landscape evolved, I found myself drawn to the challenge and potential of bug bounties. This shift wasn't just a new direction for my career. It was a leap into a global arena where security experts and hackers converge to fortify the web's infrastructure. Bug bounties appealed to me as they offered a way to not only test my skills against some of the most secure systems in the world, but also to contribute to a safer internet.

My first significant bounty came from identifying a vulnerability in a major social media platform's photo sharing feature. The bug, if exploited, could allow an attacker to access private images without permission. The thrill of discovery was matched only by the reward, a five-figure sum that far exceeded what I typically earned in a month through traditional consulting. As you might guess, I started paying a lot more attention to bug bounties from then on. The transition required a shifted mindset, from a service provider to a competitor in a global contest.

Platforms like HackerOne and Bugcrowd became my new go-to websites to visit, where companies post rewards for hackers who can identify and report security flaws. Learning to navigate these platforms, understanding their reporting requirements, and honing my skills to uncover high-impact vulnerabilities was a daily routine. One of the biggest challenges in bug bounty hunting is the sheer volume of researchers vying for the same prizes. To stand out, I specialized in a particular type of vulnerability, focusing on cross-site scripting attacks, which soon became my niche. This specialization, coupled with a methodical approach to research and reporting, increased my success rate.

Earning my first $10,000 through bug bounties was a milestone, but it was just the beginning. As I accumulated more bounties, my earnings grew, allowing me to invest in better tools and dedicate more time to hunting. The financial rewards have been significant, but the real satisfaction comes from seeing my work contribute to more secure online experiences for millions of users. The landscape of cybersecurity is ever-changing, and it keeps me on my toes. Thanks so much to Kai for sharing those updates with us.

Let me know what you think, who you'd like to see featured from our archives of more than 2,600 episodes, more than 1,000 stories and case studies. It's all completely free. You can access all of those at sidehustleschool.com or wherever you get your podcasts. Sometimes on Spotify and Apple Music, they don't actually contain the entire library just 'cause it goes back so far. So if you want to get the whole library, you can go to the website, again, completely free.

We've got notes for every episode. We've got new episodes coming out every day. I hope you will continue to listen. It's all free. Did I mention that?

I think I did. So I'll sign off for now. My name's Chris Guillebeau. This is Side Hustle School.

Find your side hustle

Search 450 real case studies by income, difficulty, and business model. The Side Hustle Finder helps you skip the browsing and find ideas that actually match your situation.

Explore the Finder →
Side Hustle book
From the Host

Side Hustle: From Idea to Income in 27 Days

The step-by-step guide behind many of the stories on this show. Find your idea, validate it, and start earning — no experience required.

See all books →

Keep in Touch

Chris Guillebeau speaking to a packed crowd

There's a new story every single day on Side Hustle School. Episodes are produced to be short and to the point — I know you're busy. Be sure you subscribe to get a weekly recap of each episode!

Email hello@chrisguillebeau.com
Say Hi From your favorite airport

To infinity and beyond,
Chris Guillebeau