you have to care when nobody is paying

i don’t think you can become exceptionally good at cybersecurity if cybersecurity only exists between 9 and 5 for you.

you can become competent. you can get the certifications, learn the methodology, memorize attack paths, use the right tools and have a completely successful career in security.

but there is a level beyond competence that i don’t think you can reach unless you actually love the craft.

the hackers i’ve always admired are a little fucked in the head about computers. they’ll open devtools on a website they weren’t even testing because one request looked strange. they’ll read some horrible rfc because one field doesn’t make sense. they’ll reverse a random binary because a string bothered them. they’ll notice one permission check behaving differently and suddenly four hours are gone.

nobody assigned this work. there is no jira ticket. most of the time nobody even knows they’re doing it.

they just need to know.

that has basically been my relationship with security too.

this year alone i’ve reported more than 200 vulnerabilities to cert-in across companies and public systems. a lot of that work had no bounty, no guarantee of a cve and sometimes barely anything beyond an acknowledgement. at one point i told hindustan times that less than 1% of what i’d reported had even been confirmed fixed1.

i kept hacking anyway.

some of those bugs later got cves. cert-in eventually credited me for three vulnerabilities in one erp system, including unauthenticated rce, idor and source-code disclosure2. cool. but none of that is why i originally opened the application.

i genuinely just enjoy finding out how things break.

a lot of this for me is probably autismmaxxing. if a system behaves slightly differently from how i think it should, my brain has an extremely difficult time leaving it alone. one weird response becomes another request, then another endpoint, then reading some javascript bundle, then suddenly it’s 4am.

sometimes there is a critical vulnerability at the end.

sometimes there is absolutely nothing.

i still enjoyed looking.

and i think that distinction matters a lot in modern cybersecurity because security has become a very normal career now. there are roadmaps, bootcamps, salary guides, certifications, linkedin influencers and thousands of people asking which sequence of certificates will get them a six-figure security job.

there’s nothing inherently wrong with that.

but having a cybersecurity job and being a hacker are not automatically the same thing.

i’ve met plenty of people who got into security because it pays well. from my own experience, most of them eventually hit a wall. once the checklist stops, they stop. once burp doesn’t immediately show something interesting, they’re done. once the methodology says there are no more steps, there are no more steps.

the really good people tend to keep poking.

money can pay someone very well for their time. it can buy better hardware, better tooling, training, compute and access to extremely talented people.

what it can’t do is make someone care.

you can’t salarymaxx somebody into wondering about a protocol while they’re trying to sleep. you can’t give somebody another certification and suddenly make them spend sunday afternoon understanding some useless implementation detail because not understanding it is annoying them.

that kind of obsession has to already be there.

old hacker culture understood this better than modern corporate security does. so much of it came from weird people on irc, mailing lists, forums and tiny internet communities spending ridiculous amounts of time learning things with basically no obvious career value. people built tools because the existing ones pissed them off. people published obscure technical writeups because something was interesting. people broke things simply because they were told those things couldn’t be broken.

a huge amount of hacker knowledge came from people fucking around.

hackerone’s own surveys reflect this pretty well. in its 2021 hacker report, 85% of respondents said learning was a motivation for hacking compared with 76% who cited money. 47% participated in vulnerability disclosure programs that offered no monetary reward at all and among those hackers, 79% said learning was one of the reasons they did it3.

an earlier hackerone survey found that nearly 58% of hackers described themselves as self-taught and fewer than 5% said they learned hacking skills in a classroom. learning was the number one motivation in that survey too while money had fallen to fourth4.

none of this means certifications are useless or that getting paid somehow makes you less of a hacker. that’s stupid.

it means the certificate isn’t the source of the ability.

a course can teach you what ssrf is. obsession is what makes you encounter some completely unrelated feature six months later and immediately think, “wait, can i make this thing request itself?”

you develop that instinct by touching systems constantly. by breaking your own shit. by reading things nobody asked you to read. by writing unnecessary tools. by chasing stupid ideas. by spending years accumulating tiny pieces of context that eventually become intuition.

ai is probably going to make this difference much more obvious.

basic competence is becoming cheap. models can write the code, explain the protocol, suggest attack paths, generate payloads and increasingly do substantial parts of security research themselves.

we’re going to have programmers who don’t really like programming, security people who aren’t particularly interested in computers and ai researchers who aren’t especially curious about intelligence. they’ll still be able to produce decent work because the tools will carry more and more of the execution.

but ai can’t make you obsessed with something.

and when execution becomes cheap, i think obsession becomes more valuable, not less.

the person who asks the strange question still matters. the person who doesn’t trust the obvious answer still matters. the person who keeps looking after every tool says there’s nothing interesting still matters.

“do what you love, love what you do” is painfully corny advice.

i hate that i believe it.

but security has made it very difficult for me not to.

if you don’t actually like hacking, there eventually comes a point where you’ve done enough.

if you do, “enough” is a surprisingly difficult concept.

Footnotes

  1. hindustan times, cert-in asks teen researcher to hold off public vulnerability disclosures, august 2026.

  2. cert-in, civn-2026-0430: multiple vulnerabilities in manacle technologies erp system, september 2026. cve-2026-84147, cve-2026-84148 and cve-2026-84149.

  3. hackerone, the 2021 hacker report, 2021.

  4. hackerone, the 2018 hacker report, 2018.