1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…
Shared thoughts after 6 years in Pentesting
41–50 of 97 posts
Re: Shared thoughts after 6 years in Pentesting
#42We just had some consultants do pentesting on our medical device and its software components. I was pretty impressed by all the problems they found quickly. As developer I find it pretty hard to stay up-to-date with all the possible ways hackers can get into your systems. To me this was money well spent.
Re: Shared thoughts after 6 years in Pentesting
#43Is blue better than black?
Do red pens last longer?
Re: Shared thoughts after 6 years in Pentesting
#44Earlier quoted context omitted.
Possibly the former, certainly the latter.
Please explain how is that so?
How about if they just had a job in Vb.net form a year and then worked other languages for five years.
I guess it's a very fine difference.
Re: Shared thoughts after 6 years in Pentesting
#45Earlier quoted context omitted.
> That leads me to this: to be great in this industry ( or great for this industry), I believe that InfoSec/NetSec has to become a lifestyle,not just a job. I easily work 80+ hours a week Who is working 80+ a week long term? It throws into question every other statement on the page.
He is including time spent on here :P
Re: Shared thoughts after 6 years in Pentesting
#46I know far more people that moved from Security to development than the other way around. Security work has become less pioneering and more routine. The fun part of security is learning, not work.
The demand for developers increased faster than infosec and so did salaries.
Re: Shared thoughts after 6 years in Pentesting
#471. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
No. The author counted learning (perhaps including going to meetups and watching DefCon videos) in it.
> If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too.
He clearly stated he loves learning. The amount of stuff you can learn around every possible vulnerability is virtually unlimited.
Re: Shared thoughts after 6 years in Pentesting
#481. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
I googled, but I didn't manage to find out what "netpen" is. Network Penetration? I'd assume that virtually all relevant security stuff is network related these days so I'm still confused. Which are the other specialties and why are they more demanding?
Re: Shared thoughts after 6 years in Pentesting
#491. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
I was curious as to what the "most" demanding specialities in offensive security were, but googling "offensive security" mainly returns results about the company that offers the OSCP certification
Are there any general resources online that interested readers could use as a starting point to get an overview of the field?
Re: Shared thoughts after 6 years in Pentesting
#50Earlier quoted context omitted.
Please explain how is that so?
Certification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class. As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is don…