Live data from Hacker News

I'm not burned out, I'm pissed off

myname.website

131–140 of 335 posts

Re: I'm not burned out, I'm pissed off

#131
post #68

If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…

Bro (or Sis? :) )! They're not supposed to care about security, you are! Our job in infosec is to show others how insecurity affects what they care about so in order reduce,transfer or eliminate risk to what they care about they allow us to implement good security. The failure is on the infosec side of the equation. It confounds and mildly pisses me off when people get pissed and get burned out over suits not caring…

The problem is, the person who refuses to understand this, typically includes the senior guys in InfoSec who own this, and will continue to do so irregardless of how you present it.

I mean, who else is buying a SEIM, asking for all logs, and then hoping it'll take care of everything? That's the CISO, Director, VP, Head Of, etc.

Re: I'm not burned out, I'm pissed off

#132

Earlier quoted context omitted.

That's fair. Your comment would also be better if you quoted me fairly and didn't cut off the second half of my question. "Everything" and "Everything that would benefit you immediately" are not the same thing. But I don't think there's much to gain from more bickering here, let me just retract my comment.

That's very civil of you, upvoted. OK, now I can answer. It's all a balance of investment, payback (which can be direct - "gets me a job" - and nebulous life-quality stuff - "that's interesting!") and erm, my lifespan. I try to make those tradeoffs consciously. If I decide x is valuable but boring, these days I'll measure it against other priorities, if it wins I force myself to do it. So I try. It's an acquired skil…

What you call an acquired skill is a heuristic most people do unconsciously.

Re: I'm not burned out, I'm pissed off

#133
post #28

what if I tell you that a software banks (B-A-N-K-S) are using to transfer money has hardwired passwords inside, has to run as administrator and has some problems of command injection, etc, etc ... etc ? Sadly company think to security as a cost and to maximize the profit let people should never approach a keyboard to write programs, unsecure programs, because they cost less. Because also testing is expensive, same s…

I assume English isn't your first language, so this is my attempt to correct. Please don't take this as a criticism, but rather as (hopefully) helpful feedback. Even with English as my native language, I'm sure there's some grammar mistake I've made as well. ____ What if I told you that the software banks are using to transfer money has passwords hardwired inside, has to be run as administrator, has some command inje…

Thank you ! Yes it isn't my first language and I wrote the post going at work, on a bus. So no time to review it.

Re: I'm not burned out, I'm pissed off

#134
post #40

Earlier quoted context omitted.

Software costs ~0 to copy and distribute absolutely perfect copies, world-wide. To drive the price up you create artificial scarcity, mostly rooted in IP law. Important note for HN readers: 'driving the price up' is a net benefit for programmers. Artificial scarcity is why you get paid big bucks. Interestingly, data is legitimately scarce. But that's a discussion for another time...

> Important note for HN readers: 'driving the price up' is a net benefit for programmers. Well no, if it is hard to get software written people just won't bother. Most programmers will benefit from a commoditise-the-complement strategy where everyone is using software and need to hire programmers to tweak it to their exact needs. The money is in support & hardware. Trying to primarily compete on software price is pre…

The big paying companies in software aren't in the software business, they're in the data business. The software is a (very cheap, to them) loss leader.

Re: I'm not burned out, I'm pissed off

#135

Earlier quoted context omitted.

This is what happens when companies don't understand security. https://www.csoonline.com/article/3410278/the-biggest-data-b... You think a million a year is expensive? It's not - not if it's saving you a $200m fine, and possible class action damages.

It's tough for me to think that Yahoo! didn't "understand security," and yet, their entire user database was ganked. I have to assume that they were doing everything they could to implement all of the white paper suggestions and consulting recommendations they could get their hands on. I also presume they were running the largest, most-expensive "security" products that they could buy. The depressing thought that str…

Pretty much.

I think it's difficult but there's almost no doubt that Yahoo would have people who understand the problem with security. The problem is, were they, and did they have the power to reign this in at scale?

All too often, you get risk people buying products then asking for all your logs, promising the easy silver bullet. Being a pessimistic engineer, you're unlikely to ever be near a leadership position with people who want easy answers.

Re: I'm not burned out, I'm pissed off

#136

It seems a lot of people here find information security to be of utmost importance. I would like you to consider a contrarian position. What if someone said cybersecurity (as in information security) is not very important? http://www.dtc.umn.edu/~odlyzko/doc/cyberinsecurity.pdf

Highlights from the article:

* we can just stop using computers to avoid security problems.

* Most criminals are dumb, so it doesn't matter that one smart one can control 80K people's computers around the world to mine Bitcoin.

* Data deletion attacks that cripples hospitals and governments is not a problem because they should have backups.

* Persecuting dissidents isn't a big deal?

Re: I'm not burned out, I'm pissed off

#137
post #90

Earlier quoted context omitted.

That's why EU laws to punish such negligence are a good thing. They increase the risk for companies, to something very specific.

I'm in the UK, so all of these companies are either primarily based in the EU, or do business here. GDPR has put some fear back in, but even today there are loads of companies that simply don't give a shit, and will happily risk it all so that they don't have to adapt their practices from years ago. In my experience, smaller companies are the worst offenders, because they know they are small fry. Pipdig are a UK comp…

I think CISOs are a bit more worried than they were before, but CFOs still refuse to pay for individuals. It's the old Capex vs Opex and random jealously that flies around the market, combined with a lack of skills that leads to outsourcing to consultancies that sell snake oil. It'll remain crap I imagine.

Re: I'm not burned out, I'm pissed off

#139

"A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall? Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one." N…

For those who didn't get the reference:

The OP is quoting Tyler Durden, a fictional character of the movie 'fight club'. So take it with a grain of salt.

Post reply on HN