Live data from Hacker News

I'm not burned out, I'm pissed off

myname.website

201–210 of 335 posts

Re: I'm not burned out, I'm pissed off

#201

I 100% agree as a consultant working in product development. I think what drives this is a lack of ability for anyone to understand the end-to-end product from a technical standpoint and make coordinated decisions about direction. Instead, you have 30 teams with their own architects and roadmaps (which often overlap functionality) so you build the same thing 5 times across the org, then 3 of them end up drawing meani…

This comment nails it. Is there anyway to fix this problem? Not the burnout as that's the symptom but the cause, bad structure.

Enterprise architecture done well; but the tooling is incredibly difficult, it's expensive and you need a culture devoted to engineering discipline over raw productivity. Other industries manage this just fine: manufacturing and defense contracting are two that come to mind. Both industries have pretty good work / life balance for their employees.

Tech is just worse because we haven't unionized like both of those industries did, so the companies are able to operate in a way that is more exploitative of its workers. I think that's actually the source of the outsized margins we see in tech. Agile is just shorthand for "it's too expensive to coordinate things so we'll just make our engineers do that on top of being engineers". The solution is to unionize and start to demand some standards in engineering discipline that allow people to have both a career and a life.

Re: I'm not burned out, I'm pissed off

#202
1) Increasingly, if you want to be in infosec, you have to learn how to code on the level of a SWE. This is how to not lose your mind when constantly addressing sec issues that others (devs) are entirely responsible for fixing.

2) Department of No doesn't have to be a thing, it just takes some emotional intelligence and pragmatism. 'Always saying no' is as much the fault of the sec eng as it is the system. If you have the will power and general positive mindset, it's more than easy to go through a sec career without getting angry. It just requires not default No, and ....

3) Understand people want to do a good job. If you tell them they're doing a shitty job, they'll tell you to fuck off. If you (sarcasm font) admire what they're doing, and have some stuff that can get added to build an even better product, people are surprisingly amenable to working with you. It seems like 70% of sec folks think their job is to say No, and as a result never get there.

4) This was a huge lesson for me that made me understand the field: to be successful in sec, you must learn that your personal risk tolerance will not always equal the enterprise's risk tolerance. Making money, in a digital field, is an inherently risk-on undertaking. It's crucial to know what to not escalate beyond your team, what to not cause a fuss about, what is just a known risk that will continue to exist, and then have clear requirements for what risk you will escalate and shake cages about.

It seems like all of these sec rants boil down to seeing the system and being unwilling to work within it, vs. seeing the system, accepting it, and figuring out how best to navigate it, and what tools and personal skill sets I'll really have to maximize to succeed in it.

Re: I'm not burned out, I'm pissed off

#203

I'm a recovering security guy. When I listen to security people rant, I can see their points and it's a bit of fun, I like a good rant. But I get the impression that they're continuously discovering new and exciting ways that individual facets of individual pieces of software (and the processes around them) suck. All without ever accepting that the entirety of the software ecosystem sucks (and that they're rarely mov…

Yes, this post has an apparently-unearned righteousness to it.

You can get mad when you’re sitting in traffic if you want. Feel free to emphasize precisely how pissed off you are! But you’re still traffic.

Re: I'm not burned out, I'm pissed off

#204
The main thing here is that a company that can't directly tie security to revenue will NEVER value it the way that security people think it should be valued.

I can't count the number of times that some wanker used the words "I will sign off on the risk" when they didn't understand the risk that they were putting off on departments that they had no authority over. What they were really saying was, "I can tell you what to do".

The truth of the thing is that business doesn't care about something being right if it can save a single penny by doing it wrong...the only way that changes is if the cost of doing it wrong becomes dramatically higher than the the savings gained from cutting corners. The operative word there is "dramatically". See the fines that companies pay to regulators when caught breaking the law as evidence.

Re: I'm not burned out, I'm pissed off

#205

The problem with the security mindset is that security goals are relative to other business goals within almost every organization. A breach can be OK. A rebuild can be OK. Some downtime can be OK. It depends on the system. To put it eloquently: I don't trust security people to do sane things. - Linus Torvalds (2017) ... via https://github.com/globalcitizen/taoup

Indeed, if you are a security engineer, everything looks like a threat to you. Therefore, a developer's workstation must be protected just as strongly as a critical database server - at the gross expense, of course, of the developer's productivity.

Precisely. Some folks over-estimate the security risks and under-estimate the business risks. Typically, the biggest risk to any organisation is going bankrupt, and doing "too much security" can make that more likely.

Re: I'm not burned out, I'm pissed off

#206
post #181

The problem with the security mindset is that security goals are relative to other business goals within almost every organization. A breach can be OK. A rebuild can be OK. Some downtime can be OK. It depends on the system. To put it eloquently: I don't trust security people to do sane things. - Linus Torvalds (2017) ... via https://github.com/globalcitizen/taoup

> I don't trust security people to do sane things Seriously. Security decisions that demolish UX can tank entire products. Recent-ish example: Oracle VirtualBox. Used to love that software and I would recommend it to friends needing VMs. They added a new hardening feature that makes it unusable on my setup for whatever reason (VMs fail to start with "hardening failures"). There is no option to disable the hardening f…

Just curious if you have considered migrating from VirtualBox to Hyper-V given you are doing your work on a Windows laptop.

Re: I'm not burned out, I'm pissed off

#207
post #181

The problem with the security mindset is that security goals are relative to other business goals within almost every organization. A breach can be OK. A rebuild can be OK. Some downtime can be OK. It depends on the system. To put it eloquently: I don't trust security people to do sane things. - Linus Torvalds (2017) ... via https://github.com/globalcitizen/taoup

> I don't trust security people to do sane things Seriously. Security decisions that demolish UX can tank entire products. Recent-ish example: Oracle VirtualBox. Used to love that software and I would recommend it to friends needing VMs. They added a new hardening feature that makes it unusable on my setup for whatever reason (VMs fail to start with "hardening failures"). There is no option to disable the hardening f…

FYI, enable hyper-v and you don't need Vbox.

Re: I'm not burned out, I'm pissed off

#208

Earlier quoted context omitted.

I've heard from someone selling security products that some companies prefer to pay ransonware to a hacker, instead of investing in building up their defense and paying for security products

I'm studying infosec, so I lean on the "pay for infosec people" side. But from a company's perspective, if they have to pay 1M for an infosec team over five years, or 1M for a breach once every 5 years, what's the difference? You're still paying the same amount of money.

[deleted]

Re: I'm not burned out, I'm pissed off

#209

Earlier quoted context omitted.

I've heard from someone selling security products that some companies prefer to pay ransonware to a hacker, instead of investing in building up their defense and paying for security products

I'm studying infosec, so I lean on the "pay for infosec people" side. But from a company's perspective, if they have to pay 1M for an infosec team over five years, or 1M for a breach once every 5 years, what's the difference? You're still paying the same amount of money.

Perhaps they consider that the employees will be way more productive without all the security barriers that the Infosec team would set up, so paying for the breach is a net gain in this light.

Re: I'm not burned out, I'm pissed off

#210

Earlier quoted context omitted.

I'm studying infosec, so I lean on the "pay for infosec people" side. But from a company's perspective, if they have to pay 1M for an infosec team over five years, or 1M for a breach once every 5 years, what's the difference? You're still paying the same amount of money.

And then Equifax gets breached. When does infosec start to realize that it's not just about company costs/risks, but the lives of all those users who are going to get screwed when your 'low risk = cheap fix' mentality pays off? I'm in the Equifax breach (like sooooo many more)... part of my 'general concerns about the world' is whether/when I get my life hacked and have to rebuild. Let me know where you get hired nex…

Corporations do not care one bit for

> lives of all those users

Equifax cares about one thing: earning profits for its shareholders. They got caught with their pants down. Now other companies can look and try to estimate their expected cost of being breached (probability of being breached multiplied by the dollar cost) vs the dollar cost to upgrade their IT systems, infrastructure, management, company policies, etc etc etc. Realistically, Equifax is probably incapable of doing the necessary changes upfront without a complete overhaul of it's people and leadership structure.

The vast majority of companies will spend the least amount of money possible to pretend that they fixed the problem.

You want companies to care? Then create regulation that protects

> lives of all those users

Post reply on HN