I don't explicitly work in security, but I've had a handful of arguments in the past where I've discovered a serious vulnerability, and been told either by my managers or by a client that it is low-priority. Sometimes, the vulnerability was then exploited, and what shocked me was that people were okay with this. I won't name names, but one marketing department I worked with was happier to suffer a customer data leak…
I'm not burned out, I'm pissed off
161–170 of 335 posts
Re: I'm not burned out, I'm pissed off
#162I asked my SO recently how she view the Internet, what it is and how it works. She was honest and told me that, "If I click this button, this websites loads. If that works I'm fine! If it doesn't I will call you. Don't stop working with IT please, if you get it, we need you badly!" I believe that is a good reason to be accepting towards the current state of affairs. People just don't care. They have more important is…
Thing is, it took me a long time to accept that people not caring was ok. Now I realize that my dad is frustrated I never learned something as simple as changing the oil on my car. My mom does not understand how I can't name more than two flowers and can't bake a pie. My legal-minded friends are astounded I do not take a day to work on my legal status to pay less taxes. Hell, my wife does the paperwork I am not even…
Re: I'm not burned out, I'm pissed off
#163And this cannot be avoided while working as an employee, it's part of the system.
The good news is that there is one way to avoid this (the only way AFIK) is to start your own company, there you get to call all the shots for good or for bad.
It doesn't have to be a big company though, it can be just you and a laptop for starters.
Other than that, as an emotional coping mechanism and to preserve their mental sanity, people will simply become disengaged and cynical.
Take longer breaks and try to have a laugh with your colleagues to blow some pressure and make friends.
Also, because things work badly in those environments, there is a lot of blame deflection going on, which is one of the main causes of stress and burnout.
Again, part of the system, not much that you can do about it other than learning to deflect responsibilities to others.
Getting rid of the hot potato is a very important skill in these corporate settings.
Usually on a team, it's always the same people getting the short end of the stick. Try not to be one of them if you can, but often that's easier said than done.
Also, try to get promoted, you will get more responsibility and might even be able to fix some of these things, that's another positive attitude towards chaos that helps a lot of people cope with it.
Re: I'm not burned out, I'm pissed off
#164Re: I'm not burned out, I'm pissed off
#165The problem with the security mindset is that security goals are relative to other business goals within almost every organization. A breach can be OK. A rebuild can be OK. Some downtime can be OK. It depends on the system. To put it eloquently: I don't trust security people to do sane things. - Linus Torvalds (2017) ... via https://github.com/globalcitizen/taoup
Also the defeatist ‘everything can be hacked if they try hard enough’ attitude, applied as a defense.
It is absolutely true that everything can be hacked if they try hard enough, so the question is — how hard do they need to try, and what resources do they need?
As you reach an answer to that question, you either consider that level of investment a credible threat you need to worry about (in which case you invest in tightening things up) or you don’t (beers at 5?).
Re: I'm not burned out, I'm pissed off
#166"A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall? Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one." N…
And don't forget the universal elixir that cures all security ills: adding even more rules about which passwords are allowed.
Re: I'm not burned out, I'm pissed off
#167I don't explicitly work in security, but I've had a handful of arguments in the past where I've discovered a serious vulnerability, and been told either by my managers or by a client that it is low-priority. Sometimes, the vulnerability was then exploited, and what shocked me was that people were okay with this. I won't name names, but one marketing department I worked with was happier to suffer a customer data leak…
I worked at a healthcare company in the US (we provided HIPAA data connections between insurance and providers) and discovered all the production passwords were storied in a text file in the code repo half the company had access to. The CTO told me "we trust our employees". There was also no auditing on who access the DB and servers, and they never changed the passwords because the chief architect did not want to rem…
Also, I'm so sorry you had to touch EDI, if you did.
Re: I'm not burned out, I'm pissed off
#168"A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall? Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one." N…
For those who didn't get the reference: The OP is quoting Tyler Durden, a fictional character of the movie 'fight club'. So take it with a grain of salt.
Re: I'm not burned out, I'm pissed off
#169I 100% agree as a consultant working in product development. I think what drives this is a lack of ability for anyone to understand the end-to-end product from a technical standpoint and make coordinated decisions about direction. Instead, you have 30 teams with their own architects and roadmaps (which often overlap functionality) so you build the same thing 5 times across the org, then 3 of them end up drawing meani…
Haven’t been able to put my finger on it exactly (definitely a multi dimensional issue), but I don’t think the issues you outlined will continue to fly if you want something of quality that’s not half baked.
This excerpt from agile manifesto comes to mind as part of the problem that I’ve coming to disagree with (at least how I’ve seen it implemented in the past):
> The best architectures, requirements, and designs emerge from self-organizing teams.
Re: I'm not burned out, I'm pissed off
#170If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…
I've heard from someone selling security products that some companies prefer to pay ransonware to a hacker, instead of investing in building up their defense and paying for security products
But from a company's perspective, if they have to pay 1M for an infosec team over five years, or 1M for a breach once every 5 years, what's the difference? You're still paying the same amount of money.