1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
Agreed. I work in infosec as well, and I think the author of this article is confusing time spent vs. passion for something. Coming from software engineering, security is no different than any other technical profession: if you don't love what you do, you probably won't be very motivated to learn, and thus you probably won't be very competent. You need to have the passion. This doesn't need to manifest itself in 80 h…
Shared thoughts after 6 years in Pentesting
51–60 of 97 posts
Re: Shared thoughts after 6 years in Pentesting
#52Earlier quoted context omitted.
Please explain how is that so?
Certification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class. As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is don…
> Certification in a field such as vulnerability research
OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them.
> As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications
So apparently OSCP won't get you a job at Matasano - but they're not the only game in town, and a lot of other security shops with less name recognition and lower standards do in fact use the OSCP as a positive signal.
No, it won't be l33t but it will be a job that they can use to transition to those fancy schmancy companies whose founders are HN regulars.
Re: Shared thoughts after 6 years in Pentesting
#53Earlier quoted context omitted.
I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…
If you're entry-level and don't have a network, certs help you get through the HR filter. Once you're mid-level, you can use your network and experience.
Re: Shared thoughts after 6 years in Pentesting
#54Earlier quoted context omitted.
I don't have a formal degree! I have 1 semester of college from 1995, and that's it. You don't have to do RE to be in software security. There's virtually no assembly-level RE in web application security, and very little of it in mobile security. Both of those specialties are more lucrative than RE, a specialty where maybe the top 10% go to high-status RE and exploit dev careers, and the other 90% go to low-status ma…
Picking has always been hard I guess. Thank you very much for the solid advice. I will keep it in mind moving forward.
Re: Shared thoughts after 6 years in Pentesting
#551. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
I am just starting in Networking and want to progress to NetSec eventually and I was kind of taken back by OPs advice to work 80 hours a week, I want to have a life, not work all the time, so your comment was pretty comforting. > 2. Don't get certificates I am progressing through my CCNP and LPIC-1, mostly because I want to get recognized for my skills, but I also see them as a guideline, what to learn next, kind of…
Is there something else ? ;)
Honestly without joking, as the OP said, having this as a passion or lifestyle is going to accelerate your proficiency compared to the others. My feeling is that it's not an absolute prerequisite, just a tremendous accelerator.
I started "having a life" maybe 15 years after the beginning of my hacking passion ;) tho my wife would argue about that ;)
Re: Shared thoughts after 6 years in Pentesting
#56So many years pen testing. Is blue better than black? Do red pens last longer?
Red/white may not know how bad and hostile reality is.
Ps: no, there's no comment about ethnicity in this comment.
Re: Shared thoughts after 6 years in Pentesting
#571. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…
There is too much of mathematics to learn all of them. To make maximize, I think I need to focus on some subjects that would be cost-effective. What woulds would this be?
Re: Shared thoughts after 6 years in Pentesting
#58Earlier quoted context omitted.
He is including time spent on here :P
He is including all time spent learning stuff and so on. 40h work + 40h learning/reading HN/doing hobby projects is pretty common.
A more reasonable person would probably put a fair amount of learning time on the weekend, but even then you leave very little time for a social life, physical exercise, eating, relaxing.. things that most healthy people, if not everyone, requires.
Re: Shared thoughts after 6 years in Pentesting
#59Earlier quoted context omitted.
I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…
If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.
So how do you get through HR wall? Padding CV with keywords is a common way to get an interview. I'm an embedded system engineer looking to move closer to IT security, so how do I get there without experience and certifications as virtually all jobs require one, another or both (except junior positions, but I'm too old to start from the very bottom)? I do learn a lot on my spare time, but you still need to get a chance to demonstrate your skills, which is impossible if your CV is discarded as "requirements are not met" (a.k.a not enough keywords on CV match the ones in job description).
Re: Shared thoughts after 6 years in Pentesting
#60Yeah...stopped reading at 80 hour weeks. I don't care how esteemed someone is in their industry, if they have to completely destroy their life to get there I question their judgement and don't want their advice.
I squandered away my 20's and 30's on 80-hour work weeks. It was never expected of me, I just loved my job and did it anyway. Yes, there have been benefits, but today I feel I lost more than I gained.
At the time I would've dismissed you and your comment as you do OP's. Life just isn't that black and white.