This transcript was generated from the episode audio and may contain minor errors.
[Music]
Ethical Hacker earns big bug bounties. We're gonna talk about bug bounties today. I haven't talked about those in a long time, several years, I think. Bug bounties, if you don't know what that is, I'm gonna explain it and you're actually gonna hear a listener story from an Ethical Hacker, a guy who's like a programmer, a coder, and he's not trying to break into stuff. Well, he actually is trying to break into companies, but not really to steal from them, more like to discover a vulnerability so he can report it and then get paid.
So it's an interesting little world, an interesting niche in the world of cybersecurity where people actually are earning some significant bounties. The companies basically pay people to find these exploits and then instead of exploiting them to actually report them so they can fix them. So we're gonna update you on his pivot to earning through bug bounties. He initially was focused more on safeguarding small businesses. You'll hear more about the update from him.
Let's see, last week we heard from a statistician turned fantasy sports strategist who leveraged his knack for numbers to launch a fantasy sports analytics business. And of course, today we're gonna go to hear from this Ethical Hacker and see what he learned, how his business has evolved along the way. Sometimes when we highlight a business that we've featured in the past, we hear what's gone well, what's been challenging, or just like, what is the next iteration? I wanna encourage you also, as you are developing ideas, don't be afraid to evolve and move on to something else. Iteration is actually, I think, an understudied secret of entrepreneurial success.
Most of the time, most people who are running a business, whether a side business or something that they grow into a full-time thing, it's going to have different stages and that's normal. So the way you progress through the stages, your willingness to do so and your curiosity about what might come next is actually pretty important or a good predictor of success, let's say. And without further ado, let's hear from Kai. He's gonna tell us about those bug bounties. I'll be back at the end with a couple of brief comments.
[Music]
My adventure into the realm of ethical hacking began with the focus on protecting small businesses from the myriad of threats lurking in the digital shadows. However, as my skills sharpened and the cybersecurity landscape evolved, I found myself drawn to the challenge and potential of bug bounties. This shift wasn't just a new direction for my career. It was a leap into a global arena where security experts and hackers converge to fortify the web's infrastructure. Bug bounties appealed to me as they offered a way to not only test my skills against some of the most secure systems in the world, but also to contribute to a safer internet.
My first significant bounty came from identifying a vulnerability in a major social media platform's photo sharing feature. The bug, if exploited, could allow an attacker to access private images without permission. The thrill of discovery was matched only by the reward, a five-figure sum that far exceeded what I typically earned in a month through traditional consulting. As you might guess, I started paying a lot more attention to bug bounties from then on. The transition required a shifted mindset, from a service provider to a competitor in a global contest.
Platforms like HackerOne and Bugcrowd became my new go-to websites to visit, where companies post rewards for hackers who can identify and report security flaws. Learning to navigate these platforms, understanding their reporting requirements, and honing my skills to uncover high-impact vulnerabilities was a daily routine. One of the biggest challenges in bug bounty hunting is the sheer volume of researchers vying for the same prizes. To stand out, I specialized in a particular type of vulnerability, focusing on cross-site scripting attacks, which soon became my niche. This specialization, coupled with a methodical approach to research and reporting, increased my success rate.
Earning my first $10,000 through bug bounties was a milestone, but it was just the beginning. As I accumulated more bounties, my earnings grew, allowing me to invest in better tools and dedicate more time to hunting. The financial rewards have been significant, but the real satisfaction comes from seeing my work contribute to more secure online experiences for millions of users. The landscape of cybersecurity is ever-changing, and it keeps me on my toes. Thanks so much to Kai for sharing those updates with us.
Let me know what you think, who you'd like to see featured from our archives of more than 2,600 episodes, more than 1,000 stories and case studies. It's all completely free. You can access all of those at sidehustleschool.com or wherever you get your podcasts. Sometimes on Spotify and Apple Music, they don't actually contain the entire library just 'cause it goes back so far. So if you want to get the whole library, you can go to the website, again, completely free.
We've got notes for every episode. We've got new episodes coming out every day. I hope you will continue to listen. It's all free. Did I mention that?
I think I did. So I'll sign off for now. My name's Chris Guillebeau. This is Side Hustle School.