Live data from Hacker News

I'm not burned out, I'm pissed off

myname.website

91–100 of 335 posts

Re: I'm not burned out, I'm pissed off

#91
post #64
post #54

Earlier quoted context omitted.

> I'm tempted to just credit myself 1 monetary unit in production and just show them the statement. I would be tempted too, though I could bet that this will be a termination of an employment, instead of the problem being fixed. I would like to be proven wrong on this speculation..

Yes, that's what I thought as well.I'll just have to suck it up until the test environments are up again and provide a proof of concept exploit. I'm just impatient because it's a really clever and somewhat complex hack that challenges some multi-threading and transactionability assumptions some people mande and I can't really talk about it(which I'd love to share with my peers).

Raducule, did you did CYA (cover your ass)? E-mail(s) to higher ups responsible in case of a fuck-up that most likely will happen in the future? Do it now if you didn't, or "wave and smile" if you did. Let them burn if you are ignored, no longer your problem.

Re: I'm not burned out, I'm pissed off

#92
It seems a lot of people here find information security to be of utmost importance.

I would like you to consider a contrarian position. What if someone said cybersecurity (as in information security) is not very important? http://www.dtc.umn.edu/~odlyzko/doc/cyberinsecurity.pdf

Re: I'm not burned out, I'm pissed off

#93

"A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall? Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one." N…

> No one in management wants the expense or the overhead of actual security. They want the "theater" of security, the good feeling, the box to check on their resume (as management) so everyone can pretend everything is fine and go back to the business at hand. Then something real happens, a leak of user data, or credit cards or internal memos... suddenly everyones job is security and no one knows what to do. The last problem gets solved, there is more "theater" and a few quickly forgotten changes that get worked around or just ignored in the long run.

The incentive is that if every box was checked and shit hits the fan, insurance is on the hook to pay for stuff and not the company or the responsible party.

Re: I'm not burned out, I'm pissed off

#94

Earlier quoted context omitted.

I can't accept that not caring is ok. The small "I don't care" extends into "I don't care about anything outside my immediate environment" and that has political and eventually global consequences. If their bank account is drained they will care, and get angry, and then maybe do something (but preferably the bank will recompense them in which case they feel better and go back to not caring). Some stuff you just can't…

> many people don't want to put in the effort to learn stuff that would benefit them immediately I take it you're not counting yourself in that group? Have you already learned everything that would benefit you immediately?

It would be a better question if you asked it fairly: "Have you already learned everything". I did not suggest or imply 'everything' should be learnt.

Re: I'm not burned out, I'm pissed off

#95
post #5

This is the down-side of artificial scarcity for software. The upside is that sweet sweet green. If you could remain cynical a few years longer, scrimp and save like 10 years of a comfy mid 6 figure salary, you'd stop caring about the BS, and you'd might even learn to love it (or even contribute to it!) After all, nothing quite feels as good as being a well-paid expert in a complicated field, especially when it grows…

What about those of us who don't get crazy compensations, but instead work at a midsized company selling a "security" product? All of the complexity in my field comes from stupidity, either by certifiers, or legacy protocols that can't die or sales people playing "defect/defect" with oneanother so nobody fucking talks with each other. If the complexity at least came from software I would have a reason for my knowledg…

The real knowledge you can gain is:

* Understand the true desired outcome

* Own delivering it

People who can't do the former are naive. People who can't do the latter are unambitious. You can go through life just fine being both.

Re: I'm not burned out, I'm pissed off

#96
post #25

If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…

I work as a contractor for a bank. A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the pro…

Debit yourself 1 monetary unit, and then say you could just as easily credit money.

Re: I'm not burned out, I'm pissed off

#97

"A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall? Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one." N…

> Furthermore your average engineer wouldn't eat a ham sandwich handed to them on the street by a stranger We would however eat one provided by a café that our colleagues recommended.

Or one from the company cafeteria. I’m not sure if this is the point you were making, but trust, insight and ability to get things done is quite different when working internally in an org versus working with an outside-org, and it’s a big deal.

My biggest burnout was when internal teams I worked with started to feel like external teams. That was more about engineering teams but another example: I strongly discouraged internal IT from adopting vendor/client language and mentality.

Relationships like that put them on the back foot, become defensive, and when you encounter problems the sense of being able to honestly ask what’s actually going wrong here? evaporates.

Re: I'm not burned out, I'm pissed off

#98
post #26
post #14

I asked my SO recently how she view the Internet, what it is and how it works. She was honest and told me that, "If I click this button, this websites loads. If that works I'm fine! If it doesn't I will call you. Don't stop working with IT please, if you get it, we need you badly!" I believe that is a good reason to be accepting towards the current state of affairs. People just don't care. They have more important is…

Thing is, it took me a long time to accept that people not caring was ok. Now I realize that my dad is frustrated I never learned something as simple as changing the oil on my car. My mom does not understand how I can't name more than two flowers and can't bake a pie. My legal-minded friends are astounded I do not take a day to work on my legal status to pay less taxes. Hell, my wife does the paperwork I am not even…

This I don't understand.

You are interested in economy and politics, yet you don't know how to file taxes. Is that not connected?

If you understand mechanics, yet can't do maintenance on your car, not even talking about fixing anything.

This level of theoretical knowledge that can't overreach to reality to do basic tasks seems just irrelevant to me. What is it good for apart of talking about it?

Re: I'm not burned out, I'm pissed off

#99
Ah, syslog. Around 18 years ago I was part of an group developing the next syslog protocol with security in mind. My company (one of the top infosec firms at the time) had a product doing this already.

The standards group was a mess. Some other company without any credible security credentials was just forcing their bad implementation (TCP (!) and yet another protocol layer). They were backed by Microsoft and some other corporation. Cisco member just idling there. I ended up leaving as it was a waste of time. Never even bothered checking what happened with those protocols. But I've never heard of them again.

(tinfoil hat on) I think the Microsoft guys sabotaged it on purpose and succeeded.

Post reply on HN