If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…
Conversely, in a lot of industries the security department is only there to prevent you from doing everything you need to do, even if the threat and attack surface are both minimal.
I'm not burned out, I'm pissed off
61–70 of 335 posts
Re: I'm not burned out, I'm pissed off
#62Earlier quoted context omitted.
I work as a contractor for a bank. A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the pro…
> I'm tempted to just credit myself 1 monetary unit in production and just show them the statement. I would be tempted too, though I could bet that this will be a termination of an employment, instead of the problem being fixed. I would like to be proven wrong on this speculation..
Re: I'm not burned out, I'm pissed off
#63I asked my SO recently how she view the Internet, what it is and how it works. She was honest and told me that, "If I click this button, this websites loads. If that works I'm fine! If it doesn't I will call you. Don't stop working with IT please, if you get it, we need you badly!" I believe that is a good reason to be accepting towards the current state of affairs. People just don't care. They have more important is…
Why is software expected to be different? Why should it be? Why does your grandma require a basic understanding of password security anyways?
Re: I'm not burned out, I'm pissed off
#64Earlier quoted context omitted.
I work as a contractor for a bank. A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the pro…
> I'm tempted to just credit myself 1 monetary unit in production and just show them the statement. I would be tempted too, though I could bet that this will be a termination of an employment, instead of the problem being fixed. I would like to be proven wrong on this speculation..
I'm just impatient because it's a really clever and somewhat complex hack that challenges some multi-threading and transactionability assumptions some people mande and I can't really talk about it(which I'd love to share with my peers).
Re: I'm not burned out, I'm pissed off
#65Re: I'm not burned out, I'm pissed off
#66Re: I'm not burned out, I'm pissed off
#67Re: I'm not burned out, I'm pissed off
#68If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…
It confounds and mildly pisses me off when people get pissed and get burned out over suits not caring about infosec. I mean,they care about promotions,reputation,bottom line,ROI,KPI,etc... That's what they do. You know why the marketeers and buzzword snakeoil salesmen prosper? It is because they communicate not only risk but especially [fake] solutions better! Infosec is full of user and management blaming, expecting peoppe outside of software developers and infosec practitioners to care about infosec. I am not saying I have it figured out but I am fairly certain users and decision makers need to be told solutions within the context of risk that affects them. And if it doesn't affct them they're not supposed to care.
I'll give you an example, a network is filled with tls1.0,and ssl1.3, how does that affect some mid sized company's bottom line or reputation? How do they get ROI on the man hours and resources spent to upgrade everythig to TLS1.3 with proper cipher suites and key exchange? and what KPI can they use to measure efficiency of resources? How will you tell them security hygeine takes a very long time to show ROI as do many other security concepts?
You don't really have to do all that if you don't want to, plenty of skill demand to where you can progress to more exciting positions.
Re: I'm not burned out, I'm pissed off
#69Earlier quoted context omitted.
Copy and distribution costs are just a part of the cost. Development and maintenance does require real flesh and blood people spending their days working on developing, building, and deployment. That part costs money.
You tacitly assume that I am not aware that software products have an R&D cost, and you are (insultingly) wrong. Of course they do. And without artificial scarcity that R&D cost will not be recouped. The default state of software is an open source model, where the "developing, building, and deployment" doesn't cost money because there isn't any.
Re: I'm not burned out, I'm pissed off
#70Earlier quoted context omitted.
The easiest security investment is to switch your shop from Windows, cutting like 98% of threats out there cold.
As well as cutting 98% of your workforce as no office employee knows how to work on anything different.
Techies repeating this should take a lot of the blame for why Windows still sell as well as it does.
A 50 year old electrician convinced me to start using Ubuntu 13 years ago after someone at his kids elementary school or something had told him.
UX wise Linux passed Windows in many areas around the time Ubuntu was introduced.
The only reasons now are prefererence, hard dependencies on Windows only software, stubbornness and incomptence.
Only the two first ones are good reason in my opinion.