Live data from Hacker News

Shared thoughts after 6 years in Pentesting

0x00sec.org

41–50 of 97 posts

Re: Shared thoughts after 6 years in Pentesting

#41
post #7
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…

If you're entry-level and don't have a network, certs help you get through the HR filter. Once you're mid-level, you can use your network and experience.

Re: Shared thoughts after 6 years in Pentesting

#42
post #10

We just had some consultants do pentesting on our medical device and its software components. I was pretty impressed by all the problems they found quickly. As developer I find it pretty hard to stay up-to-date with all the possible ways hackers can get into your systems. To me this was money well spent.

any specifics you can share? medical device & security, and iot & security will be pretty critical (since it's not already).

Re: Shared thoughts after 6 years in Pentesting

#44
post #26

Earlier quoted context omitted.

Possibly the former, certainly the latter.

Please explain how is that so?

Would you hire somebody for c# coding if they have spent a year in school five years ago getting VB.net certification?

How about if they just had a job in Vb.net form a year and then worked other languages for five years.

I guess it's a very fine difference.

Re: Shared thoughts after 6 years in Pentesting

#45

Earlier quoted context omitted.

> That leads me to this: to be great in this industry ( or great for this industry), I believe that InfoSec/NetSec has to become a lifestyle,not just a job. I easily work 80+ hours a week Who is working 80+ a week long term? It throws into question every other statement on the page.

He is including time spent on here :P

He is including all time spent learning stuff and so on. 40h work + 40h learning/reading HN/doing hobby projects is pretty common.

Re: Shared thoughts after 6 years in Pentesting

#46
> There is a huge need for InfoSec/NetSec professionals

I know far more people that moved from Security to development than the other way around. Security work has become less pioneering and more routine. The fun part of security is learning, not work.

The demand for developers increased faster than infosec and so did salaries.

Re: Shared thoughts after 6 years in Pentesting

#47
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

> much less spend 80 hours a week working at it

No. The author counted learning (perhaps including going to meetups and watching DefCon videos) in it.

> If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too.

He clearly stated he loves learning. The amount of stuff you can learn around every possible vulnerability is virtually unlimited.

Re: Shared thoughts after 6 years in Pentesting

#48
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

> The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security.

I googled, but I didn't manage to find out what "netpen" is. Network Penetration? I'd assume that virtually all relevant security stuff is network related these days so I'm still confused. Which are the other specialties and why are they more demanding?

Re: Shared thoughts after 6 years in Pentesting

#49
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

> The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security

I was curious as to what the "most" demanding specialities in offensive security were, but googling "offensive security" mainly returns results about the company that offers the OSCP certification

Are there any general resources online that interested readers could use as a starting point to get an overview of the field?

Re: Shared thoughts after 6 years in Pentesting

#50
post #40

Earlier quoted context omitted.

Please explain how is that so?

Certification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class. As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is don…

[deleted]
Post reply on HN