Live data from Hacker News

Infosec's Jerk Problem (2013)

adversari.es

111–120 of 142 posts

Re: Infosec's Jerk Problem (2013)

#111
post #100
post #92

Earlier quoted context omitted.

I think it's pretty obvious I'm speaking from personal experience, and I'm not sure it matters to me what you choose to do with that information.

>I think it's pretty obvious I'm speaking from personal experience, and I'm not sure it matters to me what you choose to do with that information Everything is obvious to the person who has nothing to learn.

I'm sorry, I'm really not clear on what you're trying to say here. Do you disagree with the #1/#2 breakdown I presented? That's totally fine. But I don't think it's any less productive than the discussion about whether "infosec has a jerk problem".

Re: Infosec's Jerk Problem (2013)

#112

Earlier quoted context omitted.

Yep, within reason - I don't buy into the "I have nothing to hide argument, so I have nothing to worry about." People like Trump or UKIP remind should remind us of the danger of that. Though we should remember, in a realpolitik world, the long-term interests of the NSA -> US Gov -> West etc is in supporting democracy activists for example. It's just a pity that the sensationalism of "counter-terrorism" interests in t…

So I had to read that last paragraph twice. Could you explain what you mean by "human penetration"? And no, I'm not being dirty (though my mind did initially do a few mental flips when I first read that phrase, it's not my fault I never completely matured...) I'm genuinely asking what is meant by that. Do you mean that someone walks in and attaches a serial cable to a router and their laptop, or plugs in a USB stick…

No, at it's most basic level I mean a spy or insider threat.

In the NGO contexts that I have seen that usually means someone who legitimately is works in an organisation but turns for the standard reasons. (More effective, faster and cheaper for an adversary that way)

To a slightly lessor extent, that means someone from the outside who has been placed on the inside. (Less effective, longer and more expensive for an adversary that way).

Sometimes both of these scenarios also include digital aspects, like stealing a USB drive or something but not always.

Before you ask, why do people do it in an NGO environment - fairly similar reasons as elsewhere (though I tend to order them differently based on experience):

US Method of Counter-Intelligence:

-Money

-Ideology

-Compromise or Coercion

-Ego or Extortion

or these days:

-Reciprocation

-Authority

-Scarcity

-Commitment

-Consistency

-Liking

-Social Proof

A good read for more info here: https://www.cia.gov/library/center-for-the-study-of-intellig...

Re: Infosec's Jerk Problem (2013)

#113

One of the root causes seems to be that everyone with the aptitude for security crowds toward jobs that don't actually involve implementing good security. It's not as fun to be a developer that is really into security but only have that be part of your job. Even if it's all you do, if your days are just "analyze, document, harden, repeat," that's a lot less fun than getting paid to pop boxes. I know, because that's w…

Had a good friend and colleague who made an interesting point about how/why a security role can get depressing. What happens if your security program is really really really effective? Answer: Nothing

That's the paradox of security.

You can be a security superstar, or a total idiot, and you may achieve the same result!

Re: Infosec's Jerk Problem (2013)

#114
If Bob gets in trouble with his manager for not prioritizing his features over security features and Alice gets in trouble with her manager for letting the security issues happen then it sounds like an issue with management not working together to set aside time for security related issues as part of the development cycle for the product.

Re: Infosec's Jerk Problem (2013)

#116

Earlier quoted context omitted.

So I had to read that last paragraph twice. Could you explain what you mean by "human penetration"? And no, I'm not being dirty (though my mind did initially do a few mental flips when I first read that phrase, it's not my fault I never completely matured...) I'm genuinely asking what is meant by that. Do you mean that someone walks in and attaches a serial cable to a router and their laptop, or plugs in a USB stick…

No, at it's most basic level I mean a spy or insider threat. In the NGO contexts that I have seen that usually means someone who legitimately is works in an organisation but turns for the standard reasons. (More effective, faster and cheaper for an adversary that way) To a slightly lessor extent, that means someone from the outside who has been placed on the inside. (Less effective, longer and more expensive for an a…

Well that's scary as all fuck! I didn't realise NGOs were as susceptible to this sort of thing as commercial enterprises. I guess I was being naive and should have known better.

Thanks for the insights.

Re: Infosec's Jerk Problem (2013)

#117
post #100

Earlier quoted context omitted.

>I think it's pretty obvious I'm speaking from personal experience, and I'm not sure it matters to me what you choose to do with that information Everything is obvious to the person who has nothing to learn.

I'm sorry, I'm really not clear on what you're trying to say here. Do you disagree with the #1/#2 breakdown I presented? That's totally fine. But I don't think it's any less productive than the discussion about whether "infosec has a jerk problem".

The article show-cased common social problems and then shared ways of mitigating, even understanding, the "jerks". We could all be more kind.

Your post seemed to be focused on the details of those you dislike. That's it. No story about how you built camraderie or struggled to understand them. What lesson should someone learn from your post?

Re: Infosec's Jerk Problem (2013)

#118
post #117

Earlier quoted context omitted.

I'm sorry, I'm really not clear on what you're trying to say here. Do you disagree with the #1/#2 breakdown I presented? That's totally fine. But I don't think it's any less productive than the discussion about whether "infosec has a jerk problem".

The article show-cased common social problems and then shared ways of mitigating, even understanding, the "jerks". We could all be more kind. Your post seemed to be focused on the details of those you dislike . That's it. No story about how you built camraderie or struggled to understand them. What lesson should someone learn from your post?

Huh. Fair enough. My comment is definitely about my issues, and probably not (now that I'm forced to reflect on it) in the original spirit of the post.

This particular issue is buzzing in my head this week because of the stupid grsecurity Twitter drama, which is really bugging me. I guess I'd like an "infosec community" that spends more effort thinking about engineering and less about community dynamics.

We could definitely all be kinder.

Re: Infosec's Jerk Problem (2013)

#119

Earlier quoted context omitted.

No, at it's most basic level I mean a spy or insider threat. In the NGO contexts that I have seen that usually means someone who legitimately is works in an organisation but turns for the standard reasons. (More effective, faster and cheaper for an adversary that way) To a slightly lessor extent, that means someone from the outside who has been placed on the inside. (Less effective, longer and more expensive for an a…

Well that's scary as all fuck! I didn't realise NGOs were as susceptible to this sort of thing as commercial enterprises. I guess I was being naive and should have known better. Thanks for the insights.

Honestly, in many cases NGOs actually have a far higher physical and digital security threat environment than corporations. Partly that's one of the things I love about my job.

I mean yeh, it's cool if you can get paid loads of money for a 9-5 job to throw a ton of resources and people at protecting your Pied Piper software company in suburban USA or Europe....But now take the exact same advisary (China gov for example) and try to think up ways to minimise their threats all while driving around with a hobbiest sysadmin (who the local gov may arrest, torture or disappear if exposed) with very little English in the middle of the night in darkest Africa/Middle East/Asia...The pay is crap or non-existent, it can be high stress but you get to make a real difference, which is rewarding.

Re: Infosec's Jerk Problem (2013)

#120

Earlier quoted context omitted.

This. If the Mossad/NSA/PLA thinks there is anything of value on our network, they either already have it or could trivially get it. It wouldn't be the end of the world if they had it, so I don't really care.

Yep, within reason - I don't buy into the "I have nothing to hide argument, so I have nothing to worry about." People like Trump or UKIP remind should remind us of the danger of that. Though we should remember, in a realpolitik world, the long-term interests of the NSA -> US Gov -> West etc is in supporting democracy activists for example. It's just a pity that the sensationalism of "counter-terrorism" interests in t…

Question for you, what company do you work for? I've really wanted to break into NGO security in particular for a lot of reasons. Spent a lot of years working in NGOs, and now do internal corporate security. Pay's better but it feels different. Could you possibly reach out to me? pdoconnell at gmail
Post reply on HN