SabunMacTavish

security against real adversaries, not ceremony

Hacking Will Outlive the Job Description

In 1903, an audience at London’s Royal Institution gathered to watch a demonstration of Marconi’s wireless telegraphy. The technology promised communication over great distances, with claims of security to match.

Before the intended message arrived, someone else’s message came through.

Nevil Maskelyne, a magician and inventor, had interfered with the demonstration. Commercial rivalry helped motivate him, but the underlying question was familiar: does this technology actually work the way its makers say it does? The Royal Institution documents the incident.

This happened before modern computers, before penetration testing became a service, and before anyone could put “cybersecurity professional” on a business card.

That is where I start when I hear that cybersecurity is dying.

I think we need to be clearer about what, exactly, is supposed to die.

A job can disappear. A service can become cheap enough to automate. A company can lose its reason to exist. None of those outcomes necessarily means people will stop being curious about technology - or stop trying to break it.

Hacking is bigger than its job descriptions.

Pentesting, red teaming, reporting, and assurance all serve a purpose. They give discoveries a route toward fixing things. But my interest in hacking does not begin with a deliverable. It begins with wanting to understand something.

How does it work? How do people actually use it? What does it trust? What happens if I challenge that trust?

Sometimes the result is a vulnerability. Sometimes it is an unexpected use, a failed experiment, or a better understanding of why the system holds together. The investigation itself is part of the appeal.

There is some evidence that this motivation extends beyond personal experience. HackerOne’s 2018 survey of 1,698 ethical hackers found that 37% hacked as a spare-time hobby, while monetary gain ranked fourth among motivations. That is one community’s survey, not a universal explanation of hackers, but it shows that the paycheck is not the whole story. HackerOne’s survey findings.

Technology keeps giving that curiosity somewhere to go.

Selected hacking milestones: wireless interference in 1903, telephone blue boxes in the 1970s, machine learning security research in 2006, and indirect prompt injection in 2023. Dates are not to scale.

Telephone enthusiasts explored networks through their signaling systems. Wozniak built a blue box that generated tones to make free calls. Decades later, smartphones brought different hardware, operating systems, permissions, and exploit chains to investigate. Computer History Museum, Citizen Lab’s iPhone investigation.

Machine learning became another subject of security research. In 2006, researchers were already examining how adversaries could manipulate learning systems. By 2023, researchers were demonstrating how instructions hidden in retrieved content could influence LLM applications through indirect prompt injection. Can Machine Learning Be Secure?, Greshake and colleagues’ research.

The knowledge required changes. So do the tools. The habit of questioning a system’s assumptions remains useful.

AI is also changing who - or what - can perform that investigation. We should take that seriously.

At DARPA’s 2025 AI Cyber Challenge, competing automated systems collectively found 54 of 63 deliberately introduced vulnerabilities and patched 43. They also discovered 18 real vulnerabilities that had not been planted for the competition. These are meaningful results, even within a bounded competition environment. DARPA’s results.

DARPA AI Cyber Challenge 2025 combined results across competing systems: of 63 deliberately introduced vulnerabilities, 54 were found and 43 patched. An additional 18 real vulnerabilities were discovered outside that total.

AI can help us secure systems. It does not give an adversary a reason to stop trying. Better defenses change the problem they have to solve, but do not necessarily remove their motivation to solve it.

If we keep learning, so can they. Security cannot depend on us being the only ones who adapt.

I have no interest in defending my future with a claim that machines will never find the bugs I can find. Some security work will become faster and cheaper. Some skills will lose their scarcity.

At the same time, AI is becoming something people investigate. Google launched a dedicated AI vulnerability reward program in 2025. Its first dedicated AI bugSWAT event generated more than 70 reports and over $400,000 in rewards. New technology is already creating new research work. Google’s 2025 review.

None of this guarantees my job, or yours. Enjoying something does not protect its economics.

But it does explain why I expect hacking to persist - and why I think the people who stop learning are the ones who risk getting left behind.

That applies to me too. Experience matters, but it cannot be the end of my education. If the systems change, I have to be willing to become a beginner again: read, build, experiment, misunderstand something, and try again.

It also means questioning how we deliver security work. That is central to what we’re building at 4rthur.ai: in the age of AI, how should offensive security services change?

If parts of the work can be automated, what should an engagement look like? What should people spend their time investigating, and how should we demonstrate value to the people relying on our findings? Working through those questions means being willing to rethink familiar ways of delivering security, including our own.

That same willingness to learn is something we practise together at u9up, the AI security community I co-founded in Malaysia. We research how AI systems can fail and how they can be defended, then share what we learn through research, writeups, and talks.

Our description is simple: “We break it, we fix it, we write about it.”

Each part matters to me. Breaking something tests whether I understand it. Working on a fix makes me confront how it is supposed to function in practice. Writing about it forces me to explain what I found clearly enough for someone else to examine, challenge, or build on.

Learning together also means we do not all have to figure everything out alone. Someone else’s experiment can expose a gap in my understanding. My failed approach might save another person some time. A question from a beginner can make us revisit an assumption we stopped noticing.

That is the kind of community I want to help build. At u9up, there is room for people already deep into AI security and people just starting to get curious.

I cannot promise what cybersecurity careers will look like in ten years.

I can say what still interests me: someone builds something new, people start using it, and I want to understand it well enough to ask what they have missed.

That is why I keep hacking.