If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…
Bro (or Sis? :) )! They're not supposed to care about security, you are! Our job in infosec is to show others how insecurity affects what they care about so in order reduce,transfer or eliminate risk to what they care about they allow us to implement good security. The failure is on the infosec side of the equation. It confounds and mildly pisses me off when people get pissed and get burned out over suits not caring…
I'm not burned out, I'm pissed off
191–200 of 335 posts
Re: I'm not burned out, I'm pissed off
#192I'm a recovering security guy. When I listen to security people rant, I can see their points and it's a bit of fun, I like a good rant. But I get the impression that they're continuously discovering new and exciting ways that individual facets of individual pieces of software (and the processes around them) suck. All without ever accepting that the entirety of the software ecosystem sucks (and that they're rarely mov…
Re: I'm not burned out, I'm pissed off
#193Earlier quoted context omitted.
I've heard from someone selling security products that some companies prefer to pay ransonware to a hacker, instead of investing in building up their defense and paying for security products
I'm studying infosec, so I lean on the "pay for infosec people" side. But from a company's perspective, if they have to pay 1M for an infosec team over five years, or 1M for a breach once every 5 years, what's the difference? You're still paying the same amount of money.
When does infosec start to realize that it's not just about company costs/risks, but the lives of all those users who are going to get screwed when your 'low risk = cheap fix' mentality pays off?
I'm in the Equifax breach (like sooooo many more)... part of my 'general concerns about the world' is whether/when I get my life hacked and have to rebuild.
Let me know where you get hired next, so I can take my business elsewhere.
Re: I'm not burned out, I'm pissed off
#194Sometimes the best way to solve a problem is to stop participating in it. Why do the security breaches matter so much in the first place? If the risk is so high and the security so bad, stop using the technology for things that demand more than provided protection. Otherwise it makes it sound as if we are being sold snake oil. (Hint it’s a stepped approach that starts with being disconnected to the internet.)
It probably doesn't work in many countries due to "Know Your Customer" style laws, but in my systems I throw away all but absolutely required data as I just don't want the liability. Sometimes that means I just keep a username and password hash.
Re: I'm not burned out, I'm pissed off
#195Re: I'm not burned out, I'm pissed off
#196Earlier quoted context omitted.
You tacitly assume that I am not aware that software products have an R&D cost, and you are (insultingly) wrong. Of course they do. And without artificial scarcity that R&D cost will not be recouped. The default state of software is an open source model, where the "developing, building, and deployment" doesn't cost money because there isn't any.
Copy and distribution costs for movies in a digital age are non existant. Are movies using artificial scarcity?
Re: I'm not burned out, I'm pissed off
#197The bad news is that this will happen everywhere where you work for someone else, especially in large companies. And this cannot be avoided while working as an employee, it's part of the system. The good news is that there is one way to avoid this (the only way AFIK) is to start your own company, there you get to call all the shots for good or for bad. It doesn't have to be a big company though, it can be just you an…
First of all, we live in an imperfect world, so there always needs to be a search for balance. No company is perfect, and if it were, we'd be out of a job, so to speak. The balance needs to be that there are enough things going well enough, for you not to get burned down (burned out, pissed off). Enough of the "problems" must be challenges, and actionable, and still excite you to solve them. If this is not the case at your place, I see three possible outcomes:
1. You be cynical. For a miserably long time to come
2. This is not the right company. My experiences are very different. I get cynical about a thing or two, but on balance I love what I do. So look for a better workplace
3. You're not in the right line of work. No hard feelings. Go do something else, I beg you
Re: I'm not burned out, I'm pissed off
#198Earlier quoted context omitted.
I work as a contractor for a bank. A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the pro…
You'd get much less reprimand if this information was somehow leaked to someone else who then was stupid enough to do it, although to avoid any legal "abetting" you'd have to have some actual documented cya saying "don't mess with this broken feature".
I can understand every piece of the long string of factors that lead to this ridiculous situation where such a serious security issue is not being addressed; any one in particular is not ridiculous, but they all compound to the ridiculous of the end result.
I've fixed another ridiculous security issue in the recent past without making big waves, where only one software architect understood the seriousness of just one option in a maven config file(a whole declarative security module was not being weaved into the bytecode because somone added another module and instead of both being applied, only the most recent one was being applied).
Re: I'm not burned out, I'm pissed off
#199Re: I'm not burned out, I'm pissed off
#200Earlier quoted context omitted.
That's really the point of success in business - it gives you the ultimate privilege of hugely decreasing the odds that you'll be held responsible for damage you cause to others. Occasionally the wheels come off (maybe literally) and someone with significant power ends up in jail. But realistically - how often? Which is why software security and quality aren't a thing. There's no pressure to do the job properly and p…
> There's no pressure to do the job properly and plenty of incentive not to. I won't name names, but doing some work for some company in IT security space once, I learned that one of the issue they faced in sales is that the product cannot be too good - because if it points out to a possible vulnerability and then that vulnerability gets exploited, the customer may be on the hook financially and legally, as the softw…
Worked in enough safety-necessary environments (military weapon handling, warehouses, shipyard) that the very idea of deliberately whitewashing a possible failure just makes me angry.
Lessons learned briefings were some of the best OJT I ever had.
I'd have filed CVE's on whatever they told you to leave uncovered and damn the consequences.
(I've also never been in a place where I could afford to be let go, so YMMV/MMMV).