1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
I am just starting in Networking and want to progress to NetSec eventually and I was kind of taken back by OPs advice to work 80 hours a week, I want to have a life, not work all the time, so your comment was pretty comforting. > 2. Don't get certificates I am progressing through my CCNP and LPIC-1, mostly because I want to get recognized for my skills, but I also see them as a guideline, what to learn next, kind of…
Shared thoughts after 6 years in Pentesting
21–30 of 97 posts
Re: Shared thoughts after 6 years in Pentesting
#22Earlier quoted context omitted.
I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…
If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.
Why? Is that something that can hurt your abilities, or your employment prospects?
Re: Shared thoughts after 6 years in Pentesting
#23Earlier quoted context omitted.
I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…
If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.
Rather avoid certification if you just want to have 20 lines on your resume to look like a ninja and brag. I'm a hiring manager in infosec, and same deal if you brag about certs I start to tune out.
Re: Shared thoughts after 6 years in Pentesting
#24Earlier quoted context omitted.
I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…
> That leads me to this: to be great in this industry ( or great for this industry), I believe that InfoSec/NetSec has to become a lifestyle,not just a job. I easily work 80+ hours a week Who is working 80+ a week long term? It throws into question every other statement on the page.
Re: Shared thoughts after 6 years in Pentesting
#25Earlier quoted context omitted.
If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.
I'm a fan of yours. I asked before and I'll ask again as someone who is depressed into day 3 of a new annual round of OSCP study and yet again crippled by impostor syndrome: without a formal degree, what is there beyond your Amazon booklist? I started MicroCorruption and RE flummoxes me. I keep coming back to it because I can tell how weak I am and it has pissed me off for 2 years. Even in OSCP i get bent out of shap…
You don't have to do RE to be in software security. There's virtually no assembly-level RE in web application security, and very little of it in mobile security. Both of those specialties are more lucrative than RE, a specialty where maybe the top 10% go to high-status RE and exploit dev careers, and the other 90% go to low-status malware analysis and SOC jobs.
My advice is to pick a technology stack you really like and get comfortable with it at a nuts and bolts level, and then build security expertise on top of that. Maybe that's iOS and Swift, or maybe it's web and Django, or maybe it's distributed databases. Pick something, get good, and then be a security expert for that thing.
Re: Shared thoughts after 6 years in Pentesting
#26Earlier quoted context omitted.
If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.
>> Avoid certification. Why? Is that something that can hurt your abilities, or your employment prospects?
Re: Shared thoughts after 6 years in Pentesting
#27Earlier quoted context omitted.
I'm a fan of yours. I asked before and I'll ask again as someone who is depressed into day 3 of a new annual round of OSCP study and yet again crippled by impostor syndrome: without a formal degree, what is there beyond your Amazon booklist? I started MicroCorruption and RE flummoxes me. I keep coming back to it because I can tell how weak I am and it has pissed me off for 2 years. Even in OSCP i get bent out of shap…
I don't have a formal degree! I have 1 semester of college from 1995, and that's it. You don't have to do RE to be in software security. There's virtually no assembly-level RE in web application security, and very little of it in mobile security. Both of those specialties are more lucrative than RE, a specialty where maybe the top 10% go to high-status RE and exploit dev careers, and the other 90% go to low-status ma…
Re: Shared thoughts after 6 years in Pentesting
#281. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…
This is great advice, but I've never been able to describe it so succinctly.