1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…
Agreed. I work in infosec as well, and I think the author of this article is confusing time spent vs. passion for something. Coming from software engineering, security is no different than any other technical profession: if you don't love what you do, you probably won't be very motivated to learn, and thus you probably won't be very competent. You need to have the passion. This doesn't need to manifest itself in 80 h…
I think it's true that most passionate people will engage with their field more than 40 hours per week, simply because it's a passion. But hell - some weeks that could mean reading a good novel on the topic, with no direct value to your work. I keep up to date on a bunch of aspects of computing and mathematics because they interest me, but that feels completely different from working long hours and 'training' constantly.
Turning "be interested in your work" into "put in 80 hours, train like you're in boot camp" seems like a silly way to act tough (and exclude people with families or hobbies from a field). Your point, actually caring about your field, seems much better.