Live data from Hacker News

Ask HN: How did you get started in Network Security/Penetration Testing?

news.ycombinator.com

21–30 of 69 posts

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#21

I dabble in netsec, but not in it. My job requires me to work with our netsec team so I prefer to be familiar about the subject matter. I usually lurk on /r/netsec and they have a good resource on their wiki[1] on getting started in netsec. [1] https://www.reddit.com/r/netsec/wiki/start

Thanks! I'm glad you found that useful (I'm one of the mods there).

/r/netsec is no longer the smaller, more personal community it was when I started as a mod (7 years ago now?). If you're just starting out, one of the things I recommend most is finding a meetup in whatever city you live. It's hard to underestimate how useful an in-person conversation over a beer or two can be when you're early on.

I guess my advice for you would be: take your netsec team out to lunch once in a while! :-)

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#22
post #17

Just to clarify for everyone: Be careful switching your career to netsec/pentesting. If that's your thing, great. But you're likely to be a "lifer" because no one will want to hire you anymore for webdev. It's not quite as clear-cut as that, but if you're out of the game for N years, it's really hard to get back into it. Especially when you're not younger than 30. Ageism is a real thing.

I don't think I agree with this, at all. It depends on what you do in security. If you work as a pentester or network security staff, then you might be trading a career in software development for a career in operations. In that career, it's more likely that you will be challenged _use_ tools, build processes, or fight political battles for consensus, rather than build software. On the other hand, there are many firm…

See the sibling comment. Both stories are common, but I think my story is far more common. We don't have data so it's impossible to know, but of course you'd see a lot of people go from security engineering to VP or CTO -- those are the winners. Survivorship bias is a nasty beast.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#23
post #17

Earlier quoted context omitted.

I don't think I agree with this, at all. It depends on what you do in security. If you work as a pentester or network security staff, then you might be trading a career in software development for a career in operations. In that career, it's more likely that you will be challenged _use_ tools, build processes, or fight political battles for consensus, rather than build software. On the other hand, there are many firm…

See the sibling comment. Both stories are common, but I think my story is far more common. We don't have data so it's impossible to know, but of course you'd see a lot of people go from security engineering to VP or CTO -- those are the winners. Survivorship bias is a nasty beast.

I've only seen people make poor choices and limit their own careers. It's nothing inherent in the field of security that forces people to let their dev skills atrophy while turning into script kiddies or non-technical managers. You should be aware of what you are doing when entering ANY new field.

Obviously, if you enter a job where you have to "fight for dev time" as the sibling comment you refer to mentions, then your skills as a dev will suffer. That's not a good career path if you think you might want to return to software development one day. Find a job in security engineering, of which there are many, where you have to fight to take breaks from coding instead.

I think people have a confirmation bias that the security industry is made entirely of "netsec/pentesting" jobs since the news cycle is driven by hype from bug hunters, consultants, and vendor FUD. There are enormous numbers of people working on designing and building new security tools, capabilities, and research. Do that.

Finally, I'd like to say that if my own company wound down tomorrow, I am confident that every single one of my ~30 engineers could find a job in software engineering in an instant.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#24
post #8

I had an oppressive computer teacher in high school and I liked to pull pranks. It started out with simple password guessing, then phishing, then trojaned USB autoruns, SAM hash dumping, and password cracking, then some wifi sniffing... I never thought of what I was doing as hacking at the time (2001-2002). I just wanted to use the computer lab to play video games, and show up my jerk of a teacher. In my senior year…

reminds me that my first programming project was an msdos resident fake virus in assembly

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#25
post #23

Earlier quoted context omitted.

See the sibling comment. Both stories are common, but I think my story is far more common. We don't have data so it's impossible to know, but of course you'd see a lot of people go from security engineering to VP or CTO -- those are the winners. Survivorship bias is a nasty beast.

I've only seen people make poor choices and limit their own careers. It's nothing inherent in the field of security that forces people to let their dev skills atrophy while turning into script kiddies or non-technical managers. You should be aware of what you are doing when entering ANY new field. Obviously, if you enter a job where you have to "fight for dev time" as the sibling comment you refer to mentions, then y…

Coming from someone who holds your company in high regard and loved your companies work in the CGC I really have to disagree. You can be neither a script kiddie or a non-technical manager and still have webdev shops view you with suspicion for much the same reason node shops might see someone who has a lot of Java on their resume as someone who may not be a good fit because of 'technical baggage.' We can say that someone just needs to 'git gud' but I do think it's important to acknowledge that many times their are biases that get placed which are not always 100% rational.

Edit: Also I do believe your claim about all 30 of your engineers being able to find work elsewhere. You have to admit the average employee you have probably isn't reflective of anywhere near the average of the industry or even the enthusiast community.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#26
post #8

I had an oppressive computer teacher in high school and I liked to pull pranks. It started out with simple password guessing, then phishing, then trojaned USB autoruns, SAM hash dumping, and password cracking, then some wifi sniffing... I never thought of what I was doing as hacking at the time (2001-2002). I just wanted to use the computer lab to play video games, and show up my jerk of a teacher. In my senior year…

reminds me that my first programming project was an msdos resident fake virus in assembly

I love it when cool teachers sneak projects like these into their classwork. I had a computer architecture class that had labs to write exploits in MIPS assembly. I'd say 19 out of 20 people didn't even know they were exploits while we were writing them. :>

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#27
post #23

Earlier quoted context omitted.

I've only seen people make poor choices and limit their own careers. It's nothing inherent in the field of security that forces people to let their dev skills atrophy while turning into script kiddies or non-technical managers. You should be aware of what you are doing when entering ANY new field. Obviously, if you enter a job where you have to "fight for dev time" as the sibling comment you refer to mentions, then y…

Coming from someone who holds your company in high regard and loved your companies work in the CGC I really have to disagree. You can be neither a script kiddie or a non-technical manager and still have webdev shops view you with suspicion for much the same reason node shops might see someone who has a lot of Java on their resume as someone who may not be a good fit because of 'technical baggage.' We can say that som…

That sucks, and I'm sorry to hear that. I guess we can both agree that firms with such immature views probably don't deserve your resume to begin with.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#28
post #27

Earlier quoted context omitted.

Coming from someone who holds your company in high regard and loved your companies work in the CGC I really have to disagree. You can be neither a script kiddie or a non-technical manager and still have webdev shops view you with suspicion for much the same reason node shops might see someone who has a lot of Java on their resume as someone who may not be a good fit because of 'technical baggage.' We can say that som…

That sucks, and I'm sorry to hear that. I guess we can both agree that firms with such immature views probably don't deserve your resume to begin with.

Happens and I wont pass judgement. The IoT explosion has been the best thing to happen for me in years career wise and now I get to combine the best of both worlds.

Re: Ask HN: How did you get started in Network Security/Penetration Testing?

#30

Just to clarify for everyone: Be careful switching your career to netsec/pentesting. If that's your thing, great. But you're likely to be a "lifer" because no one will want to hire you anymore for webdev. It's not quite as clear-cut as that, but if you're out of the game for N years, it's really hard to get back into it. Especially when you're not younger than 30. Ageism is a real thing.

I've heard a lot of managers complaining that it was hard to find security people who could code well, so while getting a generic web dev job may be hard due to bias, it should be relatively easy to get a security engineering position where you write security-related code, as long as you're good at the writing code part.
Post reply on HN