Live data from Hacker News

Shared thoughts after 6 years in Pentesting

0x00sec.org

91–97 of 97 posts

Re: Shared thoughts after 6 years in Pentesting

#91

Yeah...stopped reading at 80 hour weeks. I don't care how esteemed someone is in their industry, if they have to completely destroy their life to get there I question their judgement and don't want their advice.

>I don't care how esteemed someone is in their industry, if they have to completely destroy their life to get there I question their judgement and don't want their advice.

Well, the best way to negate that advice is to put out your own and show that someone can achieve the same with a much lesser workload. Any other argument is simply an opinion. I certainly don't want to work 80 hours a week, even if I know that I can get a lot more done in that time. However, depending on what it is you're trying to do, putting in 80 hour weeks might be perfectly appropriate. If you want to be simply the best in the world in anything, you simply have to put in a LOT of work. I'm not saying its 80 hours or 56 hours, but yeah, if being average or good-enough is OK, then work-life balance is very achievable.

Re: Shared thoughts after 6 years in Pentesting

#92
post #6

Earlier quoted context omitted.

I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…

> That leads me to this: to be great in this industry ( or great for this industry), I believe that InfoSec/NetSec has to become a lifestyle,not just a job. I easily work 80+ hours a week Who is working 80+ a week long term? It throws into question every other statement on the page.

It's not just about being able to keep that up, either - it's less efficient to work 80 hours consistently and you end up with a large number of hours worked that you get a negative return on because they contribute to burnout without increasing the amount of work you get done by much at all.

Re: Shared thoughts after 6 years in Pentesting

#93
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I get the certificate hate if you have to pay for them yourself but that seems like an awfully broad statement. Many organizations love to send you off to get certificates. Anytime I need a vacation I simply look for a new certificate to get.

Re: Shared thoughts after 6 years in Pentesting

#94
post #6

Earlier quoted context omitted.

I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…

"Make your resume more about stories you can tell and less about tools you can use." This is great advice, but I've never been able to describe it so succinctly.

I read Chris Lattner's online CV [1] (probably via HN), he of Apple/LLVM/Tesla fame and a technical engineer I regard rather highly.

It's an excellent example of story-driven resumes.

[1] http://nondot.org/sabre/Resume.html

Re: Shared thoughts after 6 years in Pentesting

#95
post #72
post #52

Earlier quoted context omitted.

I think you guys are comparing apples to oranges > Certification in a field such as vulnerability research OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them. > As for job prospec…

Name a pentesting firm that cares about the OSCP.

> Name a pentesting firm that cares about the OSCP.

Here: https://rhinosecuritylabs.com/company/ lists OCSP and CISSP and a bunch of other certs. So I guess they care about that.

Now, how about you name the pentesting firm that does not list any certs.

Re: Shared thoughts after 6 years in Pentesting

#97
post #58

Earlier quoted context omitted.

He is including all time spent learning stuff and so on. 40h work + 40h learning/reading HN/doing hobby projects is pretty common.

Is it really? That's 16 hours of work 5 days a week. If you sleep for 8h you don't do anything but work or learn for all of your waking hours. A more reasonable person would probably put a fair amount of learning time on the weekend, but even then you leave very little time for a social life, physical exercise, eating, relaxing.. things that most healthy people, if not everyone, requires.

Working 40 hours per week and sleeping 8 hours at night leaves you 72 hours of free time a week so you still have time for other activities.

Also, learning and hobby projects can include social aspects.

Post reply on HN