Live data from Hacker News

Shared thoughts after 6 years in Pentesting

0x00sec.org

81–90 of 97 posts

Re: Shared thoughts after 6 years in Pentesting

#81
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

Agreed. I work in infosec as well, and I think the author of this article is confusing time spent vs. passion for something. Coming from software engineering, security is no different than any other technical profession: if you don't love what you do, you probably won't be very motivated to learn, and thus you probably won't be very competent. You need to have the passion. This doesn't need to manifest itself in 80 h…

The whole "80 hours a week" bit definitely seems to elide the difference between "working two full time jobs" and "being involved with the topic when you're off the clock".

I think it's true that most passionate people will engage with their field more than 40 hours per week, simply because it's a passion. But hell - some weeks that could mean reading a good novel on the topic, with no direct value to your work. I keep up to date on a bunch of aspects of computing and mathematics because they interest me, but that feels completely different from working long hours and 'training' constantly.

Turning "be interested in your work" into "put in 80 hours, train like you're in boot camp" seems like a silly way to act tough (and exclude people with families or hobbies from a field). Your point, actually caring about your field, seems much better.

Re: Shared thoughts after 6 years in Pentesting

#82
post #73
post #68

Earlier quoted context omitted.

The security industry is remarkably small. If you're going to spray your CV and hope for the best, sure, having as many certs as possible will get you past the first interview. But chances are if someone is browsing HN they're at least genuinely engaged enough to do better than that. You're advocating for people to shoot for average, I'm suggesting to not settle.

> You're advocating for people to shoot for average, I'm suggesting to not settle. From my perspective, I'm advocating that people don't inadvertently shoot themselves in the foot. They might not yet be qualified to work at Matasano or [insert top tier security shop here] : not everyone is. Assuming someone isn't (yet) qualified to work with their dream employer, what do you suggest they do? "Don't settle" in that sc…

I'm generally on board with this point - encouraging everyone to shoot for the top 10% inherently means letting down 90% of people.

But I think in this case, the issue might be that rather than one job being the first step to the other, we're talking about two totally distinct tracks. If a company is sufficiently shoddy and certification-happy, it's possible that they don't even provide meaningful experience for someone seeking the top-tier options. You might be better served by hardening systems at some general software job than getting an entry-level security job and blindly throwing Nessus at client's systems.

Re: Shared thoughts after 6 years in Pentesting

#83
post #80

Earlier quoted context omitted.

> Learn some advanced mathematics and cryptography. There is too much of mathematics to learn all of them. To make maximize, I think I need to focus on some subjects that would be cost-effective. What woulds would this be?

Just learn what you need: https://gist.github.com/tqbf/be58d2d39690c3b366ad

Sorry, could anyone enlighten me on the "Avoid ElGamal" part? I thought it was pretty secure. Is it due to bad efficiency?

Re: Shared thoughts after 6 years in Pentesting

#84
post #54
post #27

Earlier quoted context omitted.

Picking has always been hard I guess. Thank you very much for the solid advice. I will keep it in mind moving forward.

Then don't pick: surf r/netsec and use anything you find fun. 1 month later look at what you practiced most and enjoyed most, here you are, some part of your brain actually picked the possibly right thing for you. :)

This is a great trick in all sorts of settings. If a choice seems meaningful but hard to make, look for a way to bypass it until the answer is obvious.

Re: Shared thoughts after 6 years in Pentesting

#85
post #83
post #80

Earlier quoted context omitted.

Just learn what you need: https://gist.github.com/tqbf/be58d2d39690c3b366ad

Sorry, could anyone enlighten me on the "Avoid ElGamal" part? I thought it was pretty secure. Is it due to bad efficiency?

I would guess the author wanted to say "avoid cryptosystems that work over Z_n ring", especially that you will use ElGamal when signing or encrypting over elliptic curves.

Re: Shared thoughts after 6 years in Pentesting

#86

Yeah...stopped reading at 80 hour weeks. I don't care how esteemed someone is in their industry, if they have to completely destroy their life to get there I question their judgement and don't want their advice.

Not sure such an absolutist approach is much better. I definitely agree with your sentiment, but as my own clichéd counter-example, I can tell you that I wasn't always like that. I squandered away my 20's and 30's on 80-hour work weeks. It was never expected of me, I just loved my job and did it anyway. Yes, there have been benefits, but today I feel I lost more than I gained. At the time I would've dismissed you and…

It's more nuanced than that.

Working at your job 80 hours a week = a waste. Always.

HOWEVER, spending 40 hours a week engaged with something you enjoy and are interested in is a perfectly fine way to spend your time.

But what, I hear you ask, if I enjoy my job? Well, what about the job do you enjoy? See, if it's the work, chances are you can freelance, self-study, build stuff for yourself, in the same field, and get the same impact, AND you're free to do it how you want, free to learn whatever lessons you want, AND to capture any value it may add for yourself, rather than giving it to your employer.

This person is spending their time learning. I.e., investing in themselves. I disagree with their statement that that's required for their job, but it -does- likely make them better at their job than they'd otherwise be, and so long as they enjoy it, I can't find fault with it. But it shouldn't be a burden.

Re: Shared thoughts after 6 years in Pentesting

#87
post #42
post #10

We just had some consultants do pentesting on our medical device and its software components. I was pretty impressed by all the problems they found quickly. As developer I find it pretty hard to stay up-to-date with all the possible ways hackers can get into your systems. To me this was money well spent.

any specifics you can share? medical device & security, and iot & security will be pretty critical (since it's not already).

The stuff they found were some big picture stuff but also little things like misconfigured drive encryption. So even if you do the right things it's good to have someone check that the right thing has been done right. This is way too specialized for the regular dev to stay up-to-date with.

Re: Shared thoughts after 6 years in Pentesting

#88
post #87
post #42

Earlier quoted context omitted.

any specifics you can share? medical device & security, and iot & security will be pretty critical (since it's not already).

The stuff they found were some big picture stuff but also little things like misconfigured drive encryption. So even if you do the right things it's good to have someone check that the right thing has been done right. This is way too specialized for the regular dev to stay up-to-date with.

i could totally see these. it's also easy to hack up some stuff to make it work, and then forgetting about it.

thanks for sharing.

Re: Shared thoughts after 6 years in Pentesting

#89
post #9
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I'm currently doing a PhD in electrical engineering. I've just finished my first year, and I'm starting to realize that the work I'm putting in to research projects isn't being appreciated monetarily . In other words, I feel like my time is worth more. I like to think of myself as a decent programmer, but I'm not well versed in software security (more of a hardware person). I've also never had a full-time job as I ju…

>I've also never had a full-time job as I jumped straight from my BS to a PhD.

Not having any work experience means you'll go through "University Recruiting" (vs experienced hire) recruiting channels at any large company. This gives you tremendous freedom to explore a variety of careers as employers will only be able to judge you by your academic credentials and you won't be pigeon-holed by your professional experience. Use this to your advantage and explore as many careers & companies as possible.

Your internship will be your first professional anchor point so choose wisely - you may consider starting with a broader, more general software engineering experience before specializing to keep your options open.

Re: Shared thoughts after 6 years in Pentesting

#90
post #83
post #80

Earlier quoted context omitted.

Just learn what you need: https://gist.github.com/tqbf/be58d2d39690c3b366ad

Sorry, could anyone enlighten me on the "Avoid ElGamal" part? I thought it was pretty secure. Is it due to bad efficiency?

It is fine, but a good reason to avoid FFDH, RSA and other algorithms over multiplicative groups is that you need longer parameters compared to ECC.
Post reply on HN