<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>hackwither notes</title>
  <subtitle>Bandana Kaur on AI agent security, research and getting into cybersecurity.</subtitle>
  <link href="https://hackwither.co.in/feed.xml" rel="self"/>
  <link href="https://hackwither.co.in/notes/"/>
  <id>https://hackwither.co.in/notes/</id>
  <updated>2026-06-12T00:00:00.000Z</updated>
  <author><name>Bandana Kaur</name><uri>https://hackwither.co.in/about/</uri></author>
  <entry>
    <title>Acknowledgement is not remediation</title>
    <link href="https://hackwither.co.in/notes/acknowledgement-is-not-remediation/"/>
    <id>https://hackwither.co.in/notes/acknowledgement-is-not-remediation/</id>
    <updated>2026-06-12T00:00:00.000Z</updated>
    <summary>At 16 I reported a vulnerability exposing PII and financial data of ~399k Indian government officers to NCIIPC. Finding and acknowledging bugs doesn&#39;t secure systems. Remediation does.</summary>
    <content type="html">&lt;p&gt;when i was 16, i found a vulnerability that gave access to PII and financial data of ~399k government officers. i reported it to NCIIPC the way you&#39;re supposed to. i got the acknowledgment. the reference number. the polite email.&lt;br&gt;
then i waited: one month, two months, nothing moved.&lt;/p&gt;
&lt;p&gt;recently, a very similar story has been making headlines: different system, different researcher, same age range, same pattern. a vulnerability gets reported responsibly, acknowledgment arrives, and then little seems to happen until public attention forces action.&lt;/p&gt;
&lt;p&gt;i&#39;m not bringing this up again to say &amp;quot;i called it.&amp;quot; i&#39;m noticing a theme.&lt;/p&gt;
&lt;p&gt;i don&#39;t think the lesson here is &amp;quot;researchers should go public faster.&amp;quot; done the wrong way, it is unethical and most of us don&#39;t want to. going public is a last resort, not a strategy, and it should NOT be the only mechanism that makes remediation happen. that is not a sustainable model for securing critical infrastructure, imho.&lt;/p&gt;
&lt;p&gt;sure, finding vulnerabilities is important, acknowledging reports is important. but neither of those things actually secures systems, remediation does.&lt;/p&gt;
&lt;p&gt;and if the people repeatedly identifying weaknesses in critical systems are teenagers doing unpaid work in their spare time, then the question isn&#39;t whether young researchers are stepping up.&lt;br&gt;
they CLEARLY are.&lt;/p&gt;
&lt;p&gt;india has no shortage of talented researchers. the real challenge is ensuring that the systems, processes, and institutional remediation workflows around them can keep pace. im optimistic we can get there.&lt;/p&gt;
&lt;p&gt;as always, happy hacking!!&lt;br&gt;
–HackWitHer&lt;/p&gt;
</content>
  </entry>
  <entry>
    <title>The thing about roadmaps in cybersecurity…</title>
    <link href="https://hackwither.co.in/introductory-roadmap/"/>
    <id>https://hackwither.co.in/introductory-roadmap/</id>
    <updated>2025-12-31T00:00:00.000Z</updated>
    <summary>How to start in cybersecurity without a one-size-fits-all roadmap: start with the big picture, pick a niche, pivot if it doesn&#39;t click, then go deep. No sponsored certs.</summary>
    <content type="html">&lt;p&gt;I’m HackWitHer, an 18-year-old cybersecurity researcher.&lt;/p&gt;
&lt;p&gt;have you ever tried to follow a roadmap in cybersecurity, but it looked something like “learn hacking in [insert clickbait number] dates!!” or but it just didnt help you learn or accomplish anything?&lt;br&gt;
the thing is, everybody learns differently. most of you aren’t lacking motivation, you’re just lost in the noise.&lt;/p&gt;
&lt;p&gt;i get this question a lot:&lt;/p&gt;
&lt;p&gt;“how do i start in cybersecurity?”&lt;/p&gt;
&lt;p&gt;I’ve talked to ~2,000 students about getting started in cybersecurity, and i’ve been one of them myself. truth is, there’s no single right path. one shoe doesn’t fit all, my dear cinderella.&lt;/p&gt;
&lt;h2 id=&quot;about-this-roadmap&quot; tabindex=&quot;-1&quot;&gt;About this roadmap&lt;/h2&gt;
&lt;p&gt;so, i made a rough structure that might help you find yours. creative liberty matters most in a field like cybersecurity.&lt;/p&gt;
&lt;p&gt;the goal here is NOT to spoon-feed you sponsored certs and courses, it’s to help you think for yourself and explore with purpose. this roadmap is just to give you direction. how you decide to learn and explore the colorful field that is cybersecurity, is entirely upto you :)&lt;/p&gt;
&lt;p&gt;this is the shoe that fits most:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1. Start with the Big Picture — What is Cybersecurity?&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;hacking? what&#39;s that? Don’t jump into coding just yet.&lt;/li&gt;
&lt;li&gt;Begin with a foundational course (like ISC2 Certified in Cybersecurity (CC) or something if you’d like to gain a low cost “industry” cert on the side. otherwise, there’s plenty of introductory labs like some on TryHackMe that you can take)&lt;/li&gt;
&lt;li&gt;Understand what roles exist: Red team, blue team, GRC, threat intel, SOC analyst, DFIR, OSINT, etc.&lt;/li&gt;
&lt;li&gt;Build foundations and understand the HOWs and WHYs. Learn how the internet, systems, and data protection work, to the best of your curiosity!&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;2. Pick a Starting Point — A Niche to Explore&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Choose one path that piques your interest.&lt;/li&gt;
&lt;li&gt;Maybe it’s OSINT, maybe it’s appsec, maybe policy &amp;amp; privacy or something non-technical.&lt;/li&gt;
&lt;li&gt;Don’t worry about picking “the perfect one.”&lt;/li&gt;
&lt;li&gt;Just start reading blogs, following researchers and replicating small things others have done.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Tip: spend at least 10 days exploring a niche before you move on to the next.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3. If It Doesn’t Click, Pivot.&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;You don’t owe any niche your loyalty.&lt;/li&gt;
&lt;li&gt;Test out another subfield. Rinse and repeat until something sparks.&lt;/li&gt;
&lt;li&gt;The “click” comes when curiosity beats burnout.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;4. Go Deeper, Go Niche-Specific&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Once you find your thing, this is when you lock in, niche specific roadmaps==your besties&lt;/li&gt;
&lt;li&gt;Specialized courses (TryHackMe, TCM, SANS, etc)&lt;/li&gt;
&lt;li&gt;Certifications (specific to your niche)&lt;/li&gt;
&lt;li&gt;Labs, writeups, research, content, projects in that niche&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There’s plenty of roadmaps and resources specific to “niches” like red teaming, blue teaming, AI/ML security etc. that you can find online!&lt;/p&gt;
&lt;p&gt;⸻&lt;/p&gt;
&lt;p&gt;You don’t need to be a coder to start.&lt;/p&gt;
&lt;p&gt;You don’t need to spend money to learn.&lt;/p&gt;
&lt;p&gt;You just need to be curious enough to keep exploring.&lt;/p&gt;
&lt;p&gt;The rest? We’ll build it along the way.&lt;br&gt;
Stay tuned for more. happy hacking&lt;/p&gt;
&lt;p&gt;–HackWitHer ❤&lt;/p&gt;
</content>
  </entry>
</feed>
