Live data from Hacker News

Ask HN: How did you get started in Network Security/Penetration Testing?

news.ycombinator.com

11–20 of 69 posts

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#11
post #8

I had an oppressive computer teacher in high school and I liked to pull pranks. It started out with simple password guessing, then phishing, then trojaned USB autoruns, SAM hash dumping, and password cracking, then some wifi sniffing... I never thought of what I was doing as hacking at the time (2001-2002). I just wanted to use the computer lab to play video games, and show up my jerk of a teacher. In my senior year…

What year did you graduate? I went to grad school through the SFS program and graduated in 04. I remember hearing mudge talk and I thought it had been around for a little while before I graduated.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#12
post #2

I’ve been a professional software developer for the last 4-5 years, but never took security serious until iot took off. Get some raspberry pis, install kali Linux on a VM or spare computer, and go to work! It’s just so easy and cheap to setup a pen test lab. I’d recommend every dev have a few attack machines for fun. That’s how I got started . It’s also a huge field. Try checking out security in your current discipli…

Hey man this is really inspiring. I've been thinking about switching from web dev to security. How do you like it in comparison?

Right now I am happy as a freelance software engineer. I wasn't looking for a new job (I wanted the KNOW), but I _was_ looking for validation among business-types. I also have a few certs from AWS, and attaining those created the validation I needed in Devops/cloud (so it can be worth it for career growth).

Honestly, I just got tired of being THAT developer who willingly shirked his security duties. I always let someone else 'handle it'. In comparison now, I'm much more confident because I know (more) about securing the network and underlying ecosystem that my applications live in.

I think most people hiring want to see a developer who is excited and puts out lots of work. I've always been pursuing this in my free time, which goes a long way to show that I am truly interested in the subject. But at the end of the day, your cert can't secure a network if you can't. Get the KNOW and you'll find an opp w/ or w/out the semantics.

Hope that helps.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#13
post #11
post #8

I had an oppressive computer teacher in high school and I liked to pull pranks. It started out with simple password guessing, then phishing, then trojaned USB autoruns, SAM hash dumping, and password cracking, then some wifi sniffing... I never thought of what I was doing as hacking at the time (2001-2002). I just wanted to use the computer lab to play video games, and show up my jerk of a teacher. In my senior year…

What year did you graduate? I went to grad school through the SFS program and graduated in 04. I remember hearing mudge talk and I thought it had been around for a little while before I graduated.

I graduated in 2008. I feel like SFS really caught its stride in the second half of the 2000s. I remember when NSA started making different levels to the CAE certification (Education -> Research -> Operations), and that created a rush to build out lots of new coursework and pulled many new universities into the bottom tier, and SFS along with it. I don't have data to show, but I feel like both SFS and universities with CAE were more rare or exclusive earlier than that.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#14
I can tell you how not to do it. I'll never forget the funniest interview I ever had. I interviewed with this company called Deja vu Security.

http://www.dejavusecurity.com/

I explicitly told them, via email, I have ZERO experience pen testing, or anything related to hacking. I'm a terrific software engineer looking to pivot into this market, would take a salary cut to get my feet wet and be mentored. Would this be possible? Are you guys remotely interested in an arrangement like this?

They say great, when can we sync up? That's definitely something we can do.

So we set a call up and the call takes literally 39 seconds, I'll never forget it. He asked me what experience I had, and I reply: None whatsoever, like I mentioned in my email I'm interested in jumping into this line of work though.

"Thanks but we're not going to move forward."

Before I can even say thank you for your time, goodbye, the dude just hangs up the phone on me lol.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#15
Just to clarify for everyone: Be careful switching your career to netsec/pentesting. If that's your thing, great. But you're likely to be a "lifer" because no one will want to hire you anymore for webdev.

It's not quite as clear-cut as that, but if you're out of the game for N years, it's really hard to get back into it. Especially when you're not younger than 30. Ageism is a real thing.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#16

I can tell you how not to do it. I'll never forget the funniest interview I ever had. I interviewed with this company called Deja vu Security. http://www.dejavusecurity.com/ I explicitly told them, via email, I have ZERO experience pen testing, or anything related to hacking. I'm a terrific software engineer looking to pivot into this market, would take a salary cut to get my feet wet and be mentored. Would this be p…

Not involved in the company, but fyi the reason for that is because this is the pentest equivalent of not having any github repo as a dev. There's virtually no barrier to playing/attempting a ctf or testing a vulnerable VM, so it's sensible to expect that of all candidates and shows a genuine interest.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#17

Just to clarify for everyone: Be careful switching your career to netsec/pentesting. If that's your thing, great. But you're likely to be a "lifer" because no one will want to hire you anymore for webdev. It's not quite as clear-cut as that, but if you're out of the game for N years, it's really hard to get back into it. Especially when you're not younger than 30. Ageism is a real thing.

I don't think I agree with this, at all. It depends on what you do in security.

If you work as a pentester or network security staff, then you might be trading a career in software development for a career in operations. In that career, it's more likely that you will be challenged _use_ tools, build processes, or fight political battles for consensus, rather than build software.

On the other hand, there are many firms that hire primarily for security engineering and focus on building software. Any skills you have in software development will stay current, and your work in security would make you a better, and more desirable, software engineer.

Anecdotally, I can name many people who have made the jump from security engineering to positions like VP of Engineering, CTO, or simply software engineering.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#18

Just to clarify for everyone: Be careful switching your career to netsec/pentesting. If that's your thing, great. But you're likely to be a "lifer" because no one will want to hire you anymore for webdev. It's not quite as clear-cut as that, but if you're out of the game for N years, it's really hard to get back into it. Especially when you're not younger than 30. Ageism is a real thing.

As someone who has tried a couple times to jump the other way I can attest to this. Completely stonewalled for full stack developer positions.

I have found exploits by knowing the quirks of all sorts of libraries and I have to be able to understand how things work on a deep level. But because a lot of the job is tracing other peoples work and finding gaps in their logic, you don't have as much 'dev' time in the traditional sense. Most of your coding turns into ways to prep your exploit. Your life gets wrapped up chasing obscure malloc bugs or strange chrome behavior rather than contributing in normal developer ways and companies don't recognize this as transferable. I'm only a little bit bitter about it, but I love my work. I just hope the pay stays solid and I don't end up in a dead end job later in life.

Also it's really hard to be good in this industry. It is almost entirely driven by the top 1% of people and as someone who is not in that demographic it feels like a constant struggle to keep up.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#20
I dabble in netsec, but not in it. My job requires me to work with our netsec team so I prefer to be familiar about the subject matter. I usually lurk on /r/netsec and they have a good resource on their wiki[1] on getting started in netsec.

[1] https://www.reddit.com/r/netsec/wiki/start

Post reply on HN