Earlier quoted context omitted.
And of your productivity for those tied to excel, word, and powerpoint
LibreOffice.
I'm not burned out, I'm pissed off
211–220 of 335 posts
Re: I'm not burned out, I'm pissed off
#212I'm a recovering security guy. When I listen to security people rant, I can see their points and it's a bit of fun, I like a good rant. But I get the impression that they're continuously discovering new and exciting ways that individual facets of individual pieces of software (and the processes around them) suck. All without ever accepting that the entirety of the software ecosystem sucks (and that they're rarely mov…
I don't understand what "accept" is meant to mean here. If we accept that everything sucks, the only thing left to do is leave the field, since it will always suck no matter what we do. If we try to make it better, then we're not accepting that it sucks. I think there is a better way to phrase what you mean.
If you thought it was already perfect there would be no reason to.
Re: I'm not burned out, I'm pissed off
#213I asked my SO recently how she view the Internet, what it is and how it works. She was honest and told me that, "If I click this button, this websites loads. If that works I'm fine! If it doesn't I will call you. Don't stop working with IT please, if you get it, we need you badly!" I believe that is a good reason to be accepting towards the current state of affairs. People just don't care. They have more important is…
As a user of technology, I want the exact same thing. I'll do research to build a PC, or install a new OS, and tinker with it until it works to my satisfaction. Then, I never want to touch the internals again and I want them to just work. I get very upset when my product stops working.
Same for cars, cell phones, computers, etc.
As software devs, it's our job to make this possible for users.
Re: I'm not burned out, I'm pissed off
#214Earlier quoted context omitted.
Huge problem in many orgs. Many product decisions are made on the fly by the wrong person in an attempt to check a box and get something out the door quick. Or if the right decision gets made upstream, teams downstream don’t align for a litany of reasons. Haven’t been able to put my finger on it exactly (definitely a multi dimensional issue), but I don’t think the issues you outlined will continue to fly if you want…
Do you have any counter-example in mind ?
Re: I'm not burned out, I'm pissed off
#215If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…
Bro (or Sis? :) )! They're not supposed to care about security, you are! Our job in infosec is to show others how insecurity affects what they care about so in order reduce,transfer or eliminate risk to what they care about they allow us to implement good security. The failure is on the infosec side of the equation. It confounds and mildly pisses me off when people get pissed and get burned out over suits not caring…
Mgmt/non-sec care about pretty clear, often profit-oriented metrics (ROI, etc.). There is such a clear precedent for successfully internally selling, implementing, and creating buy-in for cost-producing (i.e. infosec) but business-saving practices. Insurance, financial risk departments, legal departments etc. etc. etc. Sec can fall under that too. Sec people don't bother to learn the language 90% of the time. Sec people then burn out because they feel they're paddling nowhere.
Failure to learn that ^ language as a sec eng, means you fail to learn how to successfully implement sec in a way that has lasting buy-in. It's doable. It takes a bit of leadership, a bit of buzzword-learning.
If you want to play ball with mgmt and not be a mindless keyboard monkey sec eng who has no care if people care about sec or not, you must be able to take all those sec thoughts, distill it into 3 power point slides and 120 seconds of 'so what,' and be ok doing it over and over.
Re: I'm not burned out, I'm pissed off
#216It seems a lot of people here find information security to be of utmost importance. I would like you to consider a contrarian position. What if someone said cybersecurity (as in information security) is not very important? http://www.dtc.umn.edu/~odlyzko/doc/cyberinsecurity.pdf
Some examples: The last US election was won in large part through highly-targeted influence campaigns run based on stolen data. Not to mention the triggering of Brexit. The influence of the NSA / Russia / Five Eyes / etc on geopolitics hinges on poor cybersecurity. I think it would be silly to assume all of the recent leaks we see come from "inside the building".
The entire economics and solution space of what is possible on the internet is shaped by our cybersecurity standards. What would the internet look like if payments and spam were easy instead of hard, or if DDOS was hard instead of easy? I might hazard a guess that this is one factor of many that drives the centralisation of tech into monopolies.
A positive externality: The general failure of the tech industry to develop good content protection has enabled widespread software and media piracy. I might suspect this has allowed second and third world countries to uplift faster than otherwise possible (sci-hub anyone?) while also removing a tool of empire from the first world.
Re: I'm not burned out, I'm pissed off
#217Earlier quoted context omitted.
Bro (or Sis? :) )! They're not supposed to care about security, you are! Our job in infosec is to show others how insecurity affects what they care about so in order reduce,transfer or eliminate risk to what they care about they allow us to implement good security. The failure is on the infosec side of the equation. It confounds and mildly pisses me off when people get pissed and get burned out over suits not caring…
Why doesn't legal have to fight the same fights? Their domain seems similar: Legal problems take years to surface, and when they blow up, they explode spectacular. Implementing procedures involving legal is a huge drain of time, motivation and opportunities. Yet, in many companies the power dynamics is inverted: Anything non-trivial has to go through legal and is blocked by default. Why don't new deployments have to…
Why does legal succeed then? Partially, there are pretty firm laws covering risk, that haven't quite caught up to sec breaches and such (but this is clearly beginning).
However, the big reason: Legal can explain the 'so what' because of that shared common language. Sec folks seem to largely not bother learning how to translate tech jargon to 120 seconds and a power point slide or two that business can understand.
Re: I'm not burned out, I'm pissed off
#218Earlier quoted context omitted.
I work as a contractor for a bank. A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the pro…
Never to yourself. Maybe to a board member. Or all of the board members. But that's a big maybe. And make sure your contract covers your ass, under production system testing / penetration, or something similar.
The bug that lead to me discovering the security issue was mitigated by another developer, the security issue was also deemed fixed, I am 100% it was not, but there's no way to proove it at the moment, except u production, that's why I said I was tempted to actually do it.
Anyway, there's nothing much to gain by me by antagonising another coleague, the management or the bank. It's not worth the ego boost or frustration scratch, worst case scenario, I don't patch the issue in time and the bank looses money and they start taking security more seriously.
Re: I'm not burned out, I'm pissed off
#219Earlier quoted context omitted.
I can't accept that not caring is ok. The small "I don't care" extends into "I don't care about anything outside my immediate environment" and that has political and eventually global consequences. If their bank account is drained they will care, and get angry, and then maybe do something (but preferably the bank will recompense them in which case they feel better and go back to not caring). Some stuff you just can't…
> I really do not understand people. Well, then learning more about people's psychology and motivations seems like a thing you could benefit from immediately :)
Given that I do recognise people won't change, would it help if I did learn to understand their builtin magic curtain / SEP field[0]?
I ask with no hope any more, what do you advise?
Re: I'm not burned out, I'm pissed off
#220Earlier quoted context omitted.
I've heard from someone selling security products that some companies prefer to pay ransonware to a hacker, instead of investing in building up their defense and paying for security products
I'm studying infosec, so I lean on the "pay for infosec people" side. But from a company's perspective, if they have to pay 1M for an infosec team over five years, or 1M for a breach once every 5 years, what's the difference? You're still paying the same amount of money.