Live data from Hacker News

Infosec's Jerk Problem (2013)

adversari.es

31–40 of 142 posts

Re: Infosec's Jerk Problem (2013)

#31

One of the root causes seems to be that everyone with the aptitude for security crowds toward jobs that don't actually involve implementing good security. It's not as fun to be a developer that is really into security but only have that be part of your job. Even if it's all you do, if your days are just "analyze, document, harden, repeat," that's a lot less fun than getting paid to pop boxes. I know, because that's w…

> that's a lot less fun than getting paid to pop boxes. I know, because that's what I do

Wow, this is an interesting claim. You do this work for a living? Are you ever concerned about getting caught? How do you get paid?

I'm assuming that covering your tracks is some sort of ever escalating cat-and-mouse-game. How do you find out about your adversaries' capabilities regarding investigation after the victim detects the problem?

EDIT: oh, oops. Double-misunderstanding. "that's what I do" meaning "harden,test,repeat" and of course some folks are legitimately paid to do pen testing.

Re: Infosec's Jerk Problem (2013)

#32

The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches. > Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make t…

most developers would love to have the time to make sure their code is secure and well tested This is certainly true. But competitive pressures will always force quick hacks over software robustness. The only real solution is a sort of developers' guild -- whose membership includes over 90% of all worldwide professional developers -- wherein an oath is sworn to always include security robustness as a required feature…

The real solution in my opinion is educating people on security. not just developers, but also end users, sales people, and product managers.

When users start choosing the robust and secure product over the quick and insecure product, sales will pick that up, product will follow, and programmers will treat security just like any other feature.

Re: Infosec's Jerk Problem (2013)

#33

One of the root causes seems to be that everyone with the aptitude for security crowds toward jobs that don't actually involve implementing good security. It's not as fun to be a developer that is really into security but only have that be part of your job. Even if it's all you do, if your days are just "analyze, document, harden, repeat," that's a lot less fun than getting paid to pop boxes. I know, because that's w…

> that's a lot less fun than getting paid to pop boxes. I know, because that's what I do Wow, this is an interesting claim. You do this work for a living? Are you ever concerned about getting caught? How do you get paid? I'm assuming that covering your tracks is some sort of ever escalating cat-and-mouse-game. How do you find out about your adversaries' capabilities regarding investigation after the victim detects th…

What do you mean it's an interesting claim? It makes perfect sense to me, and I'm just a regular old web developer.

Re: Infosec's Jerk Problem (2013)

#34
post #10

The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches. > Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make t…

I would like to add that while this advice would generally work, there are some really shady characters that one has to deal with sometimes. In that case, the other person might just keep taking advantage of your kindness. So, there does have to be a give and take: do a little bit, and hope that they do a little bit as well.

This.

In addition, there are people who are quite literally "dangerously wrong": They talk with great authority and can influence large numbers of people to follow them, even though what they advocate is non-productive. At best they can waste immense amounts of a community's time as they cause great debates among members. (Tabs versus spaces, for example.) At worst they gain actual authority, do great damage, and then leave the community to deal with the aftermath. (Cure your diabetes through positive thinking!) So while being "nice" and "empathetic" are excellent defaults when dealing with people, it's just as important to understand when ugly ideas need to be squashed and the undecided are urged to do what needs doing.

Re: Infosec's Jerk Problem (2013)

#35

One of the root causes seems to be that everyone with the aptitude for security crowds toward jobs that don't actually involve implementing good security. It's not as fun to be a developer that is really into security but only have that be part of your job. Even if it's all you do, if your days are just "analyze, document, harden, repeat," that's a lot less fun than getting paid to pop boxes. I know, because that's w…

> that's a lot less fun than getting paid to pop boxes. I know, because that's what I do Wow, this is an interesting claim. You do this work for a living? Are you ever concerned about getting caught? How do you get paid? I'm assuming that covering your tracks is some sort of ever escalating cat-and-mouse-game. How do you find out about your adversaries' capabilities regarding investigation after the victim detects th…

Penetration testing is legal.

Re: Infosec's Jerk Problem (2013)

#36

I read the first lines and thought immediately of all those e-mails marked IMPORTANT coming from "my bank" that request I immediately enter my username and password somewhere for "security". Teaching blind compliance with any (unauthenticated) request based on "security" is the one way we could make the situation even worse.

Tell me about it.

Got an email from my bank yesterday, "You have an urgent notification waiting on our website! We won't tell you anything about it via email for security reasons!" So I log into the bank, go to the notifications section, "Notification! You have a new IMPORTANT document." Click on documents: "Here's the monthly statement for your savings account."

Thanks guys. I hope you never need to contact me about something urgent.

Re: Infosec's Jerk Problem (2013)

#37

One of the root causes seems to be that everyone with the aptitude for security crowds toward jobs that don't actually involve implementing good security. It's not as fun to be a developer that is really into security but only have that be part of your job. Even if it's all you do, if your days are just "analyze, document, harden, repeat," that's a lot less fun than getting paid to pop boxes. I know, because that's w…

> that's a lot less fun than getting paid to pop boxes. I know, because that's what I do Wow, this is an interesting claim. You do this work for a living? Are you ever concerned about getting caught? How do you get paid? I'm assuming that covering your tracks is some sort of ever escalating cat-and-mouse-game. How do you find out about your adversaries' capabilities regarding investigation after the victim detects th…

No, I mean to say that I'm on the boring side of the line.

But penetration testing is a job that exists. People are hired to do exactly that under contractual terms with the target. (And I don't mean to imply that's the only security job in the more-rewarding/fun category.)

Re: Infosec's Jerk Problem (2013)

#38
post #7

Earlier quoted context omitted.

Just remember that "everyone" includes the infosec people themselves.

Exactly. Many people wouldn't react so negatively to "yet another request from security" if they hadn't experienced a prior river of BS over-escalated requests from security, or a string of purchased and then never-used security "solutions" that were bought at high-cost, installed at high-effort, and then never again looked at. There are no doubt a lot of smart security people with great judgment in the industry. Unf…

"And I'm sure some of them are good people."

Yet another sql injection, but ya, Infosec's the problem.

Re: Infosec's Jerk Problem (2013)

#39
post #32

Earlier quoted context omitted.

most developers would love to have the time to make sure their code is secure and well tested This is certainly true. But competitive pressures will always force quick hacks over software robustness. The only real solution is a sort of developers' guild -- whose membership includes over 90% of all worldwide professional developers -- wherein an oath is sworn to always include security robustness as a required feature…

The real solution in my opinion is educating people on security. not just developers, but also end users, sales people, and product managers. When users start choosing the robust and secure product over the quick and insecure product, sales will pick that up, product will follow, and programmers will treat security just like any other feature.

Respectfully disagree, here. Infosec has been trying the education path for decades, now. It's not working. Either something needs to change about the educational process, or acceptance that it's failed is warranted.

I think fixing development will be more optimal than fixing users. There is no legitimate reason that OWASP top ten or lack of buffer bounds checking should still be in the wild in 2016, whereas users will always fall for scams, phishing or otherwise.

Re: Infosec's Jerk Problem (2013)

#40

Earlier quoted context omitted.

> that's a lot less fun than getting paid to pop boxes. I know, because that's what I do Wow, this is an interesting claim. You do this work for a living? Are you ever concerned about getting caught? How do you get paid? I'm assuming that covering your tracks is some sort of ever escalating cat-and-mouse-game. How do you find out about your adversaries' capabilities regarding investigation after the victim detects th…

Penetration testing is legal.

Oh, yes, of course. I misunderstood!
Post reply on HN