Live data from Hacker News

Infosec's Jerk Problem (2013)

adversari.es

71–80 of 142 posts

Re: Infosec's Jerk Problem (2013)

#71
post #50

Earlier quoted context omitted.

I'm also on the defensive side. I went to the last "DefCon", which you'd think expands to "Defense Conference". There was a grand total of one presentation that had defensive elements in it and I still don't recall it being dedicated to the topic. I don't intend to go back. Great conference, don't get me wrong, I got personal enjoyment out of much of it, but it's impossible for me to professionally justify it. Defens…

Nonsense. Defense is plenty fun. Anyone can find a 0-day. The principles and some methods are the same crap as Schell et al did in MULTICS security evaluation they published decades ago. Same kind of stuff Burroughs was preventing in 1961. More interesting was when the old guard tried to build something that couldn't be compromised under any circumstances. Others tried to find and master key areas of the problem. The…

"To me at least."

I suppose I wasn't clear. I have fun with it too for the most part or I wouldn't be doing it. But I observe that I'm a rare duck that way.

And the unrelenting stream of bugs caused by the same fundamental root-cause issues over and over again can get old. How many times do I have to see an XSS brought on by using string concatenation on HTML? How many times do I have to see, well, any of several vulnerabilities based on string concatenation before the engineering community actually acknowledges it's a problem? That can grate on someone after a while.

Re: Infosec's Jerk Problem (2013)

#72
post #50

Earlier quoted context omitted.

I'm also on the defensive side. I went to the last "DefCon", which you'd think expands to "Defense Conference". There was a grand total of one presentation that had defensive elements in it and I still don't recall it being dedicated to the topic. I don't intend to go back. Great conference, don't get me wrong, I got personal enjoyment out of much of it, but it's impossible for me to professionally justify it. Defens…

Let's be honest, Summer Security Camp is far more about socializing with "our tribe" than it is about learning. That said, understanding how the red team does things is extremely useful for formulating one's own defense.

You're right. But at times it feels like the red team has gotten so far past the blue team that it's hard to learn much from them. The red team is on unicycles juggling flaming torches while keeping three plates spinning and still successfully picking the lock while the blue team is trying to figure out how to take three steps without breaking a leg and flinging the complete contents of their wallet at the nearest brigand, which they are really good at, sometimes nailing the guy from several miles away.

Re: Infosec's Jerk Problem (2013)

#73
post #28

I carve up this problem differently. To me, the field can be divided into two basic categories of people: 1. People who are into security to prosecute some immortal struggle between good and evil. 2. People who are into security because of the engineering challenge. It's the people in group (1) that I tend to have a problem with. Often, for the "good guys" security professionals, engineering facts are just a means to…

This is a strange statement. Do you underestimate how many of your friends and respected peers are #1?

I think it's the #2s who are too quick to dismiss #1s that I tend to have a problem with.

I don't think jerkiness correlates with either of them even a little bit.

Re: Infosec's Jerk Problem (2013)

#74
post #28

I carve up this problem differently. To me, the field can be divided into two basic categories of people: 1. People who are into security to prosecute some immortal struggle between good and evil. 2. People who are into security because of the engineering challenge. It's the people in group (1) that I tend to have a problem with. Often, for the "good guys" security professionals, engineering facts are just a means to…

One of the worst is the cyber-security political purist. The person who has drunk the kool-aid so badly and/or likes to use their knowledge to beat others round the head with it. The person who likes to talk about things like "risk/threat modelling" but actually doesn't: a) Have a real understanding of the needs of the people they say they are trying to help b) Have the courage to make tough calls related to ideal vs…

This. If the Mossad/NSA/PLA thinks there is anything of value on our network, they either already have it or could trivially get it. It wouldn't be the end of the world if they had it, so I don't really care.

Re: Infosec's Jerk Problem (2013)

#75

The lack of self-awareness here is breathtaking.

I have read through every comment here, and fail to see a lack of self-awareness in any of them. Perhaps you are seeing things from a perspective I have not considered...or you are boldly trolling from a throwaway account. If it is the former, please elaborate.

I suspect it has something to do with tptacek's very strongly pro-US-state political views and his dismissive attitude to people who don't share those views, as demonstrated in the above comment.

Re: Infosec's Jerk Problem (2013)

#76

InfoSec: "There is a vulnerability." me: "PR or GTFO." The problem described is that ISOs are professional nags instead of software shippers.

That only works if your application is simple enough for the infosec folks to know how to write a patch for it.

If the organization has 200 of those apps, it's unlikely a transversal security team is able to write patches for each one of them.

Re: Infosec's Jerk Problem (2013)

#77
I have 40 year experience in developer, systems and security. The real problem comes from the top. Upper management, CEO, CIO, CFO do understand risk and don't understand technology. To them, security wholes are just bugs in "the code" or product liabilities in products used.

More then once I showed management they had a life ending bug. (Little Johnny drop tables) and was fired for being the messenger.

Re: Infosec's Jerk Problem (2013)

#78
post #60
post #24

What is extremely frustrating is the rise of "cyber security" Masters degrees. The vast majority of these people have never written a single line of code. They don't understand security, because they can't understand the underlying logic in the code. They just write documentation to meet certain outside standards, and have no idea what I'm talking about when I talk about our security posture. They genuinely think tha…

Someone I know is getting one of those 'cyber security' Masters degrees at Mercyhurst in Erie. I respect the guy, he's really smart, he has an intuitive and pragmatic view of politics... but he hasn't written a line of code ever. He uses a Mac, but he's never opened Terminal. And apparently the average graduation salary for these people at companies like Disney is around 120K. I want my friend to do well, but I also…

I mean, I earn more than my boss, but he's still in charge. He gets the credit for the software projects I actually have to manage. So it's likely he'll rise up the ladder more quickly, and earn a multiple of my salary.

Yet, he's further up the chart and makes the final decisions, when he can't understand basic variables that go into what applications (especially early stage platforms) are even supposed to do.

I'm coming to the realization that I just need to bite the bullet, and get one of those "cybersecurity" degrees. The classes are remote, self-paced, easy to earn a 4.0 GPA, and so heavily subsidized by the company as to be nearly free, so I might as well.

I'm also making my way through the various certifications they seem to value (CISSP, PMP, CEH (Certified Ethical Hacker).)

They're very easy to pick up. I just took a CISSP practice exam for the first time and passed quite easily.

Re: Infosec's Jerk Problem (2013)

#79

Earlier quoted context omitted.

One of the worst is the cyber-security political purist. The person who has drunk the kool-aid so badly and/or likes to use their knowledge to beat others round the head with it. The person who likes to talk about things like "risk/threat modelling" but actually doesn't: a) Have a real understanding of the needs of the people they say they are trying to help b) Have the courage to make tough calls related to ideal vs…

This. If the Mossad/NSA/PLA thinks there is anything of value on our network, they either already have it or could trivially get it. It wouldn't be the end of the world if they had it, so I don't really care.

Yep, within reason - I don't buy into the "I have nothing to hide argument, so I have nothing to worry about." People like Trump or UKIP remind should remind us of the danger of that. Though we should remember, in a realpolitik world, the long-term interests of the NSA -> US Gov -> West etc is in supporting democracy activists for example. It's just a pity that the sensationalism of "counter-terrorism" interests in the short-term, actually damage the long game.

On a sidenote, as a digital and physical security training company for NGOs we manage to get a look at cases from both sides of the coin. Our very very rough guesstimate is that we see confirmed human penetration about 3 times more than we do digital penetration. Of course, this is very rough and has soooooo many other bias factors at play (numerical, cultural how many we see vs not see etc.). But I think it is a point that we keep having to reinforce. Too often powerful "infosec jerks" distort the the focus towards Western biases because of Snowden, Facebook, SnapChat, iPhone and this distracts time, money, energy, training and security measures from the human penetration aspect of things - which are very common in the developing world.

Re: Infosec's Jerk Problem (2013)

#80
post #28

I carve up this problem differently. To me, the field can be divided into two basic categories of people: 1. People who are into security to prosecute some immortal struggle between good and evil. 2. People who are into security because of the engineering challenge. It's the people in group (1) that I tend to have a problem with. Often, for the "good guys" security professionals, engineering facts are just a means to…

>they're the ones shipping grievously broken cryptography to try to "stop the NSA"

I don't understand this aspect of the strawman. Could someone help me out? In the context of the previous two examples of how members of group 1 act, is tptacek merely implying that members of group 1 are stupid?

Post reply on HN