Live data from Hacker News

Infosec's Jerk Problem (2013)

adversari.es

91–100 of 142 posts

Re: Infosec's Jerk Problem (2013)

#91
post #28

I carve up this problem differently. To me, the field can be divided into two basic categories of people: 1. People who are into security to prosecute some immortal struggle between good and evil. 2. People who are into security because of the engineering challenge. It's the people in group (1) that I tend to have a problem with. Often, for the "good guys" security professionals, engineering facts are just a means to…

>they're the ones shipping grievously broken cryptography to try to "stop the NSA" I don't understand this aspect of the strawman. Could someone help me out? In the context of the previous two examples of how members of group 1 act, is tptacek merely implying that members of group 1 are stupid?

This can probably be read as a dog-whistle to his war on the EFF Scorecard in general, CryptoCat in particular, and Nadim personally.

Re: Infosec's Jerk Problem (2013)

#92
post #89
post #84

Earlier quoted context omitted.

There are people who are both #1 and #2, but they're pretty rare. Or, at least, that's the perception I get, because I don't generally have to interrogate people to learn if they're #1s: they're all too happy to broadcast that fact.

Are you speaking from personal (statistically insignificant) experience or do you have some quantifiable evidence to share? Your HN-karma & real-world accomplishments aside, do you honestly think you can psychologically categorize a group accurately enough that we should use your defined stereotype to improve ourselves and/or society?

I think it's pretty obvious I'm speaking from personal experience, and I'm not sure it matters to me what you choose to do with that information.

Re: Infosec's Jerk Problem (2013)

#93

Earlier quoted context omitted.

>they're the ones shipping grievously broken cryptography to try to "stop the NSA" I don't understand this aspect of the strawman. Could someone help me out? In the context of the previous two examples of how members of group 1 act, is tptacek merely implying that members of group 1 are stupid?

This can probably be read as a dog-whistle to his war on the EFF Scorecard in general, CryptoCat in particular, and Nadim personally.

[deleted]

Re: Infosec's Jerk Problem (2013)

#94

Earlier quoted context omitted.

>they're the ones shipping grievously broken cryptography to try to "stop the NSA" I don't understand this aspect of the strawman. Could someone help me out? In the context of the previous two examples of how members of group 1 act, is tptacek merely implying that members of group 1 are stupid?

This can probably be read as a dog-whistle to his war on the EFF Scorecard in general, CryptoCat in particular, and Nadim personally.

It's not complicated. Most of the world's really bad amateur crypto is written as a vanity exercise in saving the world. It's not like there's uncertainty about whether people have launched grievously, dangerously broken crypto software; they have. And those people do tend to be #1's.

Also, please do not try to represent my problem with the EFF's scorecard as somehow idiosyncratic. There probably aren't too many crypto engineers who don't share my opinion of it. You're probably giving me more credit than I deserve when you call it "my war".

Re: Infosec's Jerk Problem (2013)

#95
post #88

Earlier quoted context omitted.

I can think of several people who fit firmly into both. Moxie, for instance. I fail to see how these two categories are mutually exclusive.

Hold on. The definition of my #1 category isn't a belief in good and evil; it's the idea that their primary function in the field is to save the world, not to perfect security engineering. Looking at Moxie's work, I don't think anyone can legitimately accuse him of not taking engineering seriously.

I understand that, but it's reasonable to suspect that for a significant number of #2s, #1 is the initial motivating factor that got them learning.

We see this all the time in software development, where excellent engineers are borne of trying to build a video game at age x, where x is a relatively low number.

Similarly, there's no reason that someone initially motivated to eradicate "evil" can't become a great security mind, and I suspect Moxie and many like him are of this ilk.

Re: Infosec's Jerk Problem (2013)

#96
Article is fairly similar to my experience- infosec uses up all their goodwill by appearing inflexible on everything before we get to any important points. One of my (admittedly minor) examples: insisting that passwords dialogue boxes be obscured in all situations even in a private office and even if it breaks disabled input abilities and affordances.

Re: Infosec's Jerk Problem (2013)

#97
post #88

Earlier quoted context omitted.

Hold on. The definition of my #1 category isn't a belief in good and evil; it's the idea that their primary function in the field is to save the world, not to perfect security engineering. Looking at Moxie's work, I don't think anyone can legitimately accuse him of not taking engineering seriously.

I understand that, but it's reasonable to suspect that for a significant number of #2s, #1 is the initial motivating factor that got them learning. We see this all the time in software development, where excellent engineers are borne of trying to build a video game at age x, where x is a relatively low number. Similarly, there's no reason that someone initially motivated to eradicate "evil" can't become a great secur…

Again: you're rebutting me as if my argument was that anyone who believed in "good" and "evil" was a #1. That's not my definition of a #1.

Re: Infosec's Jerk Problem (2013)

#98
post #28

I carve up this problem differently. To me, the field can be divided into two basic categories of people: 1. People who are into security to prosecute some immortal struggle between good and evil. 2. People who are into security because of the engineering challenge. It's the people in group (1) that I tend to have a problem with. Often, for the "good guys" security professionals, engineering facts are just a means to…

My #3 would be people seeking a low barrier to entry cushy corporate job. Unfortunately for me, I encounter way more #3's than #1 or #2's...

Re: Infosec's Jerk Problem (2013)

#99
post #92
post #89

Earlier quoted context omitted.

Are you speaking from personal (statistically insignificant) experience or do you have some quantifiable evidence to share? Your HN-karma & real-world accomplishments aside, do you honestly think you can psychologically categorize a group accurately enough that we should use your defined stereotype to improve ourselves and/or society?

I think it's pretty obvious I'm speaking from personal experience, and I'm not sure it matters to me what you choose to do with that information.

Would you consider the Wozniak/Jobs story part of the canon? The hero's journey from #1 to #2?

(i.e. #1 Cops & Robbers -> #2 Realpolitik)

Re: Infosec's Jerk Problem (2013)

#100
post #92
post #89

Earlier quoted context omitted.

Are you speaking from personal (statistically insignificant) experience or do you have some quantifiable evidence to share? Your HN-karma & real-world accomplishments aside, do you honestly think you can psychologically categorize a group accurately enough that we should use your defined stereotype to improve ourselves and/or society?

I think it's pretty obvious I'm speaking from personal experience, and I'm not sure it matters to me what you choose to do with that information.

>I think it's pretty obvious I'm speaking from personal experience, and I'm not sure it matters to me what you choose to do with that information

Everything is obvious to the person who has nothing to learn.

Post reply on HN