Live data from Hacker News

Shared thoughts after 6 years in Pentesting

0x00sec.org

31–40 of 97 posts

Re: Shared thoughts after 6 years in Pentesting

#31
post #6
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…

Most of this applies equally well to data science, natural science, or social science with "statistics, probability, and machine learning" swapped in for "cryptography".

Re: Shared thoughts after 6 years in Pentesting

#32
I would say certs have value in security management, compliance and audit. In fact, if you want to take one of those paths, certs are mandatory. If you want to do technical security (which is totally different), then get a CS or EE degree and maybe a few SANS certs (optional unless you are in a regulated/compliance oriented industry). Finally, having a security clearance will help as well, especially if you or your employer want to do government contracting.

Edit: To expand on the cert topic... if you want to do computer forensics for law offices, police departments, etc. You'll need a technical cert (GCFA, etc.). And having a CS/EE/CE degree won't hurt either. You'll have to have a cert to do serious forensic work.

Re: Shared thoughts after 6 years in Pentesting

#33
post #11
post #9

Earlier quoted context omitted.

I'm currently doing a PhD in electrical engineering. I've just finished my first year, and I'm starting to realize that the work I'm putting in to research projects isn't being appreciated monetarily . In other words, I feel like my time is worth more. I like to think of myself as a decent programmer, but I'm not well versed in software security (more of a hardware person). I've also never had a full-time job as I ju…

If you were going to get an internship position anyways, getting an internship at a security company isn't a bad plan. I wouldn't take an internship rather than a starting-level full-time position though, if internships weren't already your plan.

Yeah, assuming I stick to the PhD, the default plan would be to do an internship every summer. I guess I'll start looking for potential companies before searching for something full-time.

Thanks for the advice :)

Re: Shared thoughts after 6 years in Pentesting

#35
post #15

Earlier quoted context omitted.

> That leads me to this: to be great in this industry ( or great for this industry), I believe that InfoSec/NetSec has to become a lifestyle,not just a job. I easily work 80+ hours a week Who is working 80+ a week long term? It throws into question every other statement on the page.

I've been working 80+ hours per week for nearly 20 years. I wholeheartedly enjoy what I do but I don't just work on one thing though. It's a combination of direct work, research, and FOSS.

Amphetamines? Don't lie.

Re: Shared thoughts after 6 years in Pentesting

#36
post #9
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I'm currently doing a PhD in electrical engineering. I've just finished my first year, and I'm starting to realize that the work I'm putting in to research projects isn't being appreciated monetarily . In other words, I feel like my time is worth more. I like to think of myself as a decent programmer, but I'm not well versed in software security (more of a hardware person). I've also never had a full-time job as I ju…

You don't get into security by taking courses. You do crackmes, you write shellcode, you hack games, you write keygens, crack licensed software/ patch it, write loaders..you packet sniff and figure out unknown binary protocols...you do things..because you want to. You don't get into security because you think its worth the money. You'll just get fleeced. Sorry, just being honest. If you can't even program, security is the last thing you can get into. Stick to legos mindstorm, kid.

Re: Shared thoughts after 6 years in Pentesting

#37
post #6

Earlier quoted context omitted.

I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…

"Make your resume more about stories you can tell and less about tools you can use." This is great advice, but I've never been able to describe it so succinctly.

I agree. Well put. Reminds me of functional resume approach of describing what one did vs where they worked. I've always preferred it.

Re: Shared thoughts after 6 years in Pentesting

#38
post #6

Earlier quoted context omitted.

I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…

Most of this applies equally well to data science, natural science, or social science with "statistics, probability, and machine learning" swapped in for "cryptography".

Pretty much any technical creative field.

Re: Shared thoughts after 6 years in Pentesting

#39

Earlier quoted context omitted.

Most of this applies equally well to data science, natural science, or social science with "statistics, probability, and machine learning" swapped in for "cryptography".

Pretty much any technical creative field.

Pretty much any field

Re: Shared thoughts after 6 years in Pentesting

#40
post #26

Earlier quoted context omitted.

Possibly the former, certainly the latter.

Please explain how is that so?

Certification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class.

As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is done). So wasting time on a certification that won't help you is putting you behind people that don't waste their time with certifications.

Post reply on HN