Episode Summary
Executive Summary: Jason Haddocks recounts how curiosity drew him from teenage computer tinkering and fake-ID forums into professional penetration testing. The episode highlights practical hacking methods—physical intrusion, app reverse engineering, recon, and web exploits—and shows how weak security decisions like open cloud storage, hard-coded credentials, and lax password resets can expose sensitive data at scale.
Main Topics: From curiosity to cybercrime to professional security (Priority: 5/5): Jason describes early computer interest, making fake IDs after joining Shadow Crew, and how law-enforcement pressure pushed him out of that scene and into legitimate penetration testing. Physical penetration testing tactics (Priority: 5/5): Stories include defeating parking-gate sensors with a shoe, using a blow-up doll to trigger a magnetic door, tailgating into a building, and crawling through ceiling space into a server room. Reconnaissance as a core hacking skill (Priority: 4/5): Jason explains how finding public-facing assets, subdomains, and exposed services is foundational for web and mobile app testing, especially for large organizations like banks. Major mobile banking app and cloud-storage exposure (Priority: 5/5): A banking app’s check-deposit feature stored check images in an open AWS S3 bucket, exposing names, addresses, account numbers, and transaction history for millions of checks. Weak authentication and admin compromise on a porn site (Priority: 5/5): Jason demonstrates account takeover via a flawed password-reset flow that always generated five-character passwords, then escalates to admin access and broader backend compromise. Security tradeoffs in user-facing platforms (Priority: 4/5): The transcript discusses why some sites intentionally keep passwords easy for convenience, and how that choice can create serious downstream risk when combined with other bugs. Professional reward and mindset of pentesting (Priority: 3/5): Jason frames penetration testing as exciting, high-skill work that lets him keep learning and find impactful flaws before real attackers do.
Key Arguments: Curiosity and obsession can evolve into a security career when channeled into legitimate testing and continuous learning. Physical security is often weaker than people assume; simple environmental tricks can bypass badge readers, magnetic locks, and server-room protections. Reconnaissance matters because large organizations expose many more internet-facing assets than their primary website. A bank’s open cloud storage of check images is a severe privacy issue because the images contain personally identifiable and financial data. Hard-coded credentials in mobile apps can be reused to gain admin access elsewhere, creating a chain from app compromise to server compromise. Weak password policies and insecure reset flows can enable rapid account takeover even when the site’s goal is merely low friction. Finding issues before attackers do can prevent reputational damage and, in sensitive industries, potentially worse real-world consequences.
Data Points: Fake ID price: $120 - Jason says a fake ID cost about this much when he was young. Fake IDs sold: 3-4 good ones - He says he only sold a handful, mostly for himself and friends. Pen tests conducted at HP: a couple hundred - Jason describes doing hundreds of Fortune 500 assessments. Total career penetration tests: around 300 - He estimates his lifetime pen-test count at roughly 300. Bank checks exposed: about 2 million - An open AWS bucket contained approximately two million deposited check images. Password length: 5 characters minimum / 5-character resets - The porn site enforced only a five-character minimum and password resets generated five-character passwords. Brute-force time: about 15 minutes - Jason says the five-character reset password could be brute-forced quickly with Burp Suite Intruder.
Pivotal Quotes: "You could fall into anything. Like, you could fall into a video game or you could fall into some kind of obsession, you know, like, you know, finishing a project." — Jason Haddocks: He explains how his fake-ID experimentation was driven by obsession and curiosity rather than profit. "I mean, the whole reason you get into pen testing: to find big finds like that." — Jason Haddocks: He describes the exhilaration of discovering major vulnerabilities during professional assessments. "It's one of the most coolest fucking jobs that you can have." — Jason Haddocks: He reflects on why he still loves penetration testing and wants to keep doing it.
Implications: The episode shows how small design choices can create outsized risk: open buckets, weak resets, and reused credentials can expose massive datasets. For defenders, layered security and realistic testing are essential.
About Darket Diaries
Explore true stories of the dark side of the Internet with host Jack Rhysider as he takes you on a journey through the chilling world of hacking, data breaches, and cyber crime.