Live data from Hacker News

Shared thoughts after 6 years in Pentesting

0x00sec.org

11–20 of 97 posts

Re: Shared thoughts after 6 years in Pentesting

#11
post #9
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I'm currently doing a PhD in electrical engineering. I've just finished my first year, and I'm starting to realize that the work I'm putting in to research projects isn't being appreciated monetarily . In other words, I feel like my time is worth more. I like to think of myself as a decent programmer, but I'm not well versed in software security (more of a hardware person). I've also never had a full-time job as I ju…

If you were going to get an internship position anyways, getting an internship at a security company isn't a bad plan. I wouldn't take an internship rather than a starting-level full-time position though, if internships weren't already your plan.

Re: Shared thoughts after 6 years in Pentesting

#12
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

Agreed.

I work in infosec as well, and I think the author of this article is confusing time spent vs. passion for something. Coming from software engineering, security is no different than any other technical profession: if you don't love what you do, you probably won't be very motivated to learn, and thus you probably won't be very competent. You need to have the passion. This doesn't need to manifest itself in 80 hour work weeks.

There's a whole contingent of "infosec ninjas" that think there is some type of bushidō bullshit going on, where if you aren't constantly training for your pentesting job like it's a martial art, you aren't capable of doing your job. In my experience, these people are often the most insufferable to work with and driven more by ego and power fantasy than the desire to tinker or craft.

Security is part of my "lifestyle" just as coding is. I work on security-related stuff outside of work not out of obligation to practice infosec kata, but because I actually like it. Some weeks I don't do anything outside of work other than browse /r/netsec or HN; some weeks (like this one) I'm writing some tools for myself to make a code audit easier.

Re: Shared thoughts after 6 years in Pentesting

#13
post #6
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…

> That leads me to this: to be great in this industry ( or great for this industry), I believe that InfoSec/NetSec has to become a lifestyle,not just a job. I easily work 80+ hours a week

Who is working 80+ a week long term? It throws into question every other statement on the page.

Re: Shared thoughts after 6 years in Pentesting

#14
post #8
post #7

Earlier quoted context omitted.

I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…

If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.

I'm a fan of yours. I asked before and I'll ask again as someone who is depressed into day 3 of a new annual round of OSCP study and yet again crippled by impostor syndrome: without a formal degree, what is there beyond your Amazon booklist?

I started MicroCorruption and RE flummoxes me. I keep coming back to it because I can tell how weak I am and it has pissed me off for 2 years. Even in OSCP i get bent out of shape on my insufficiency there and never focus on other stuff.

I don't want to be a Metasploit jockey. Where to from here? Online CS courses in C and ASM work my way up? I don't have a degree in it.

Re: Shared thoughts after 6 years in Pentesting

#15
post #6

Earlier quoted context omitted.

I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…

> That leads me to this: to be great in this industry ( or great for this industry), I believe that InfoSec/NetSec has to become a lifestyle,not just a job. I easily work 80+ hours a week Who is working 80+ a week long term? It throws into question every other statement on the page.

I've been working 80+ hours per week for nearly 20 years. I wholeheartedly enjoy what I do but I don't just work on one thing though. It's a combination of direct work, research, and FOSS.

Re: Shared thoughts after 6 years in Pentesting

#16
post #15

Earlier quoted context omitted.

> That leads me to this: to be great in this industry ( or great for this industry), I believe that InfoSec/NetSec has to become a lifestyle,not just a job. I easily work 80+ hours a week Who is working 80+ a week long term? It throws into question every other statement on the page.

I've been working 80+ hours per week for nearly 20 years. I wholeheartedly enjoy what I do but I don't just work on one thing though. It's a combination of direct work, research, and FOSS.

Wow. Well I guess there you are. I cannot imagine this! And I work well over 40 hours a week, last few weeks have been near 80. But as a rule, no way. Guess it takes all kinds.

Re: Shared thoughts after 6 years in Pentesting

#17
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I am just starting in Networking and want to progress to NetSec eventually and I was kind of taken back by OPs advice to work 80 hours a week, I want to have a life, not work all the time, so your comment was pretty comforting.

> 2. Don't get certificates

I am progressing through my CCNP and LPIC-1, mostly because I want to get recognized for my skills, but I also see them as a guideline, what to learn next, kind of like a ladder, maybe one day I will get to the top of the ladder and have no where to go, but for now I think that certifications lay a path for me, what do you think about that?

Re: Shared thoughts after 6 years in Pentesting

#18
post #8
post #7

Earlier quoted context omitted.

I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…

If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.

> Avoid certification.

IMO that should be avoid current certification. Avoiding all certification for all eternity would imply that training decent pentesters/hackers is something that cannot be done in a controlled methodical way. Which would be a setback for the entire infosec industry, IMO, because I do think that such a thing (infosec is not a special snowflake) is possible.

I think OSCP is actually a big step in the right direction. The harder challenges in their training network force you (and encourage you) to deeply investigate the underlying security issue. That part of the training actually focuses on the underlying conditioning that you need to become a good pentester, as shown by their slogan 'try harder'.

It's the same thing that armies the world over do. The army also realized that knowing everything there's to know about tactics and how to operate a weapon is not enough, soldiers also need to be aggressive and need to be conditioned to be able to effectively engage an enemy. So there's training designed to increase a soldier's willingness to fire upon enemies when ordered to.

The same goes a bit for this training, where underlying simple technical guidance is provided at the start of the training, and later a trainee is left to themselves and pushed to investigate on their own, something that I'd recognize as one of the cornerstones of a successful hacker.

Still, I'd also avoid hiring a person for a technical position if all they can show is a CISM/CISP/w\e

Re: Shared thoughts after 6 years in Pentesting

#19
post #18
post #8

Earlier quoted context omitted.

If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.

> Avoid certification. IMO that should be avoid current certification. Avoiding all certification for all eternity would imply that training decent pentesters/hackers is something that cannot be done in a controlled methodical way. Which would be a setback for the entire infosec industry, IMO, because I do think that such a thing (infosec is not a special snowflake) is possible. I think OSCP is actually a big step in…

You'd be better off participating in CTF challenges than doing the OSCP.

Re: Shared thoughts after 6 years in Pentesting

#20
post #19
post #18

Earlier quoted context omitted.

> Avoid certification. IMO that should be avoid current certification. Avoiding all certification for all eternity would imply that training decent pentesters/hackers is something that cannot be done in a controlled methodical way. Which would be a setback for the entire infosec industry, IMO, because I do think that such a thing (infosec is not a special snowflake) is possible. I think OSCP is actually a big step in…

You'd be better off participating in CTF challenges than doing the OSCP.

Heh I tried that a few times, but I found that many of them have devolved into hopelessly contrived abominations of true security issues. Fun games to be sure, but of trivial usefulness for actually building up skills I think.

I do like the ones that offer memory corruption/exploitation challenges, but those are few and far between.

Post reply on HN