Why I'm adding offensive security to my toolkit

Twenty years building creative technology, and I've never once tried to break the things I build — until now.

Ted at his desk, laptop open on a terminal, RF gear and a soldering station on the bench beside him.

Twenty years in tech, and I don’t think any of it has stayed still for very long. I started out in music technology, then somehow ended up shooting and editing video, then VFX, then CGI, then AR, then XR, then VR - if there’s been a new bit of creative tech in the last two decades, there’s a decent chance I’ve had my hands on it at some point. Mobile games, WebGL, and more recently the explosive world of AI-built, AI-driven experiences. The last seven of those years have been at R/GA. And these days I work with big enterprise clients like Nike, Google and Sony, partly making innovative digital experiences, but also (increasingly lately) making sure the software we’re building for them is secure enough and compliant enough to actually be allowed to ship.

None of that is or has ever been about any one piece of technology. It’s more that I’m incapable of leaving an exciting new bit of tech alone. I see something I don’t understand and I have to go and understand it — take it apart, poke around inside, figure out what it can actually do (and not do) once you get past the marketing. That’s basically been my entire career, dressed up in a series of different job titles.

And yet — and this is the bit that actually got me writing this in the first place — in twenty years of doing exactly that, I have never once tried, on purpose, to break something. Not properly. Not gone looking for the holes, the way an actual hacker would. Twenty years of building things, and zero days spent seriously trying to take one apart the other way.

The itch to do so has always been simmering away under the surfact and is basically the whole reason this project exists. I just never knew how to get started.

I’ve always been vaguely fascinated by hackers, the way most people probably are — which mostly means the version you see on TV. Hoodie, dark room, green text scrolling past, someone breaking into a bank or holding a hospital to ransom. Honestly, that version never really did anything for me. I have zero interest in stealing money or ending up on the wrong end of a police interview, and if that’s genuinely all “hacking” meant, I wouldn’t be writing any of this.

What actually shifted things was a new point of view I discovered through work. Compliance kept putting the word “pentest” in front of me — reports we’d commission to check whether the stuff we were shipping to enterprise clients could actually survive someone trying to break into it properly. At some point I stopped just filing those reports away and started genuinely reading them, which sent me off down a rabbit hole in my own time that had nothing to do with my job anymore: hacker conference talks at two in the morning, hours of pro-hacker YouTube, people walking through real findings on real systems, done properly, with permission, written up afterwards like it was a piece of craft rather than a crime.

And that’s when it actually clicked for me: there’s a whole, entirely legitimate world built around doing the exact thing the film version never shows you — ethical hacking. People who get paid, with everyone’s blessing, to break things properly so somebody worse doesn’t get the chance to break them badly later on. And I wanted in. Not just because it’s a genuinely cool thing to be able to say you do, although it is, obviously — but because it’s about as close to a perfect match for how my brain already works as I think I’m going to find. I need to know how things actually work. I need to poke at the edge of something and find out whether the limit really is where it says it is, or whether that’s just what’s printed on the box.

If I’m being properly honest about where that comes from, it’s older than my career by a long way. As a kid, if a teacher stood up and announced there was a new rule, I could not just accept that there was a rule. I had to know why. And if there was meant to be a consequence for breaking it, I generally had to find out whether that consequence was actually real — which meant, on more than one occasion, testing it myself. Not because I wanted to cause trouble, particularly — I promise I wasn’t that kid — I just genuinely couldn’t leave an unverified claim sitting there unchallenged. Which, it turns out, is a slightly annoying trait to have as a nine-year-old and a genuinely useful one to have thirty years later, once you point it at systems instead of school rules.

So that’s what this is. Pointing it at systems, properly, for the first time. It’s not a career change — I’ve got no real idea where it ends up, and honestly that’s fine, because that was never really the point of doing it. I want to try a bit of everything and see which rabbit holes I actually fall down. Some of it’s the obvious stuff — pentesting proper, capture-the-flag challenges, maybe pulling a mobile app apart to see what it’s quietly leaking. Some of it’s a lot further from a screen than you’d expect: radio signals, decoded and occasionally sent back out again; cheap hardware, cracked open just to see what’s actually inside it; physical security too — picking locks, cloning the kind of entry card that opens more office doors than it probably should, and social engineering, which turns out to mostly mean talking or tricking your way past security rather than touching a keyboard at all.

The kit for what's coming: an RTL-SDR dongle and RC car remote, a Flipper Zero, a padlock and practice lock with a pick set, an access card cloner, and the laptop it all runs through.

None of that happens without a line, and I plan on staying firmly on the right side of it. Along the way I’ll genuinely be learning where that line actually sits — what separates useful, permitted, productive hacking from the stuff that’s just illegal or malicious — and I’d rather actually learn that properly than assume I already know it because I’ve watched enough YouTube. Within reason, always on my own kit, my own accounts, and with my own permission.

Mostly, if I’m honest, I’m doing this for me. It’s a record I want to have, whatever ends up happening with it. But if there’s an audience out there somewhere for this, I’d like it to be people a bit like me about most things I get curious about — not necessarily technical, just interested. So that’s who I’m actually writing for. Nothing here assumes you already know the jargon, and I’ll explain whatever I pick up as I go, partly because writing it down properly is the only way I actually understand it myself.

First up: what happens when that itch to know how something actually works runs into a $5 toy car with two buttons on the remote — and somehow ends with me driving it from a laptop keyboard, with the remote no longer even in the room.

tags
journey, origin, self-taught