Live data from Hacker News

Infosec's Jerk Problem (2013)

adversari.es

101–110 of 142 posts

Re: Infosec's Jerk Problem (2013)

#101
post #75

Earlier quoted context omitted.

I have read through every comment here, and fail to see a lack of self-awareness in any of them. Perhaps you are seeing things from a perspective I have not considered...or you are boldly trolling from a throwaway account. If it is the former, please elaborate.

I suspect it has something to do with tptacek's very strongly pro-US-state political views and his dismissive attitude to people who don't share those views, as demonstrated in the above comment.

[deleted]

Re: Infosec's Jerk Problem (2013)

#103
post #76

InfoSec: "There is a vulnerability." me: "PR or GTFO." The problem described is that ISOs are professional nags instead of software shippers.

That only works if your application is simple enough for the infosec folks to know how to write a patch for it. If the organization has 200 of those apps, it's unlikely a transversal security team is able to write patches for each one of them.

Not patches, bug reports. With information in. So the problem can be reproduced and prioritized. As part of the normal development process.

Re: Infosec's Jerk Problem (2013)

#104

The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches. > Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make t…

Until companies start being held liable for their software deficiencies there won't be a change. This is also why I find "Software Engineering" a joke. The equivalent of what passes for Software Engineering, in any other engineering field, would put people in prison.

Re: Infosec's Jerk Problem (2013)

#105

Earlier quoted context omitted.

This. If the Mossad/NSA/PLA thinks there is anything of value on our network, they either already have it or could trivially get it. It wouldn't be the end of the world if they had it, so I don't really care.

Yep, within reason - I don't buy into the "I have nothing to hide argument, so I have nothing to worry about." People like Trump or UKIP remind should remind us of the danger of that. Though we should remember, in a realpolitik world, the long-term interests of the NSA -> US Gov -> West etc is in supporting democracy activists for example. It's just a pity that the sensationalism of "counter-terrorism" interests in t…

So I had to read that last paragraph twice. Could you explain what you mean by "human penetration"? And no, I'm not being dirty (though my mind did initially do a few mental flips when I first read that phrase, it's not my fault I never completely matured...) I'm genuinely asking what is meant by that. Do you mean that someone walks in and attaches a serial cable to a router and their laptop, or plugs in a USB stick into an unlocked workstation?

Re: Infosec's Jerk Problem (2013)

#106
Security professionals should try to practice avoiding the use of the word "no". Instead, help to explain what controls can be implemented to help reduce risk. Encourage a sense of camaraderie with system owners and develop powerful communication skills with everyone.

Help them to be excited to work with you, rather than to turn the other way when they see you in the hallway.

The mentioned topic of "Recalibrate 'urgent'" is a great message. We're rapidly approaching a desensitized feeling of security risk within organizations and in the general public. As breaches/incidents continue to rise we'll approach a "who cares?" level from the public.

What can they do? Steal my CC? Already been stolen. Steal my SSN? Already done.

What's left to fear when privacy is gone?

What really keeps me up at night is when security incidents are measured in lives. Scary...

Re: Infosec's Jerk Problem (2013)

#107

The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches. > Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make t…

> most developers would love to have the time to make sure their code is secure and well tested

I'm suspect not.

No matter how much time you have, it's more exciting to work on something new than going through testing. Time is not all equal. Even if you have an unlimited supply of time (everlasting life), you cannot somehow use a time block that occurs 1000 years from now, in order to displace the boredom you feel from what you're doing now.

If anything, unlimited time will increase procrastination. "If this isn't debugged for another 500 years, that's okay; I will live long enough to see it debugged.".

Thus, I suspect, most developers would actually love to have a vast army of other people with unlimited time to do the QA to make sure their code is secure and well-tested. :)

Re: Infosec's Jerk Problem (2013)

#108
Tribalism is really hurting the progress that security folks could be making. Development and operations are starting to collaborate and make huge gains in productivity. Rebranding security as a component of quality can help.

Coming into meetings with other teams with a list of (often unfounded) assumptions does not help anyone. I wrote about this a bit last year: https://blog.conjur.net/devops-and-security-the-five-monkeys

Re: Infosec's Jerk Problem (2013)

#109
post #104

The (un)funny thing is, most developers would love to have the time to make sure their code is secure and well tested. Very often they lack a voice to product stakeholders, to get the time off feature development, and make sure their software is up to date with patches. > Practice active kindness. Go out of your way to do kind things for people, especially people who may not deserve it. If you wait for them to make t…

Until companies start being held liable for their software deficiencies there won't be a change. This is also why I find "Software Engineering" a joke. The equivalent of what passes for Software Engineering, in any other engineering field, would put people in prison.

That's hardly the case. A lot of what passes for software engineering also passes for other engineering.

What we actually see is a lot of apologizing, recalls and class-action suit settlements, and nobody actually seems to go to jail.

Not all engineering is about bridges not collapsing; conversely, there is some software that is equally safety-critical and carefully developed.

There is also "everyday engineering", like in consumer products. That's a category that fails miserably. Put simply, shit breaks. Past the one year warranty? Too bad!

Re: Infosec's Jerk Problem (2013)

#110

One of the root causes seems to be that everyone with the aptitude for security crowds toward jobs that don't actually involve implementing good security. It's not as fun to be a developer that is really into security but only have that be part of your job. Even if it's all you do, if your days are just "analyze, document, harden, repeat," that's a lot less fun than getting paid to pop boxes. I know, because that's w…

Had a good friend and colleague who made an interesting point about how/why a security role can get depressing.

What happens if your security program is really really really effective?

Answer: Nothing

Post reply on HN