Live data from Hacker News

I'm not burned out, I'm pissed off

myname.website

241–250 of 335 posts

Re: I'm not burned out, I'm pissed off

#241
post #156

Earlier quoted context omitted.

Qualcomm is like this. Their developer workstations are ultra locked down. If you so much as plug in a flash drive, alarms will start going off. If you email them a file, any attachments are instantly quarentined. While I was there it was extremely difficult to transfer a log file from one of their workstations to my laptop for analysis during a debug session. It was also extremely difficult getting new builds into t…

I guess you could have used a private nextcloud instance to transfer it.

I guess in such a locked down environment that would be grounds for termination.

Re: I'm not burned out, I'm pissed off

#242
15 years ago, a classmate of mine went into security and had a similar state soon after. He decided that the entire industry was either snake-oil, or installing a 3rd deadbolt on the front door to a house with open windows.

He quit the security field, became a DBA, and moved to be close to his family in the midwest, collecting a an annual paycheck roughly equal to the cost of a 4BR house there.

Re: I'm not burned out, I'm pissed off

#243
post #166

Earlier quoted context omitted.

>They want the "theater" of security, the good feeling, the box to check on their resume (as management) so everyone can pretend everything is fine and go back to the business at hand. And don't forget the universal elixir that cures all security ills: adding even more rules about which passwords are allowed.

Make sure you change your password every 30 days, too. That way I have to write it down, or use a sequential password just in order to be able to remember it.

No worries, though: if you forget your password you can just call up IT and get it changed to "welcome1" :)

Re: I'm not burned out, I'm pissed off

#244
post #236
post #206

Earlier quoted context omitted.

Just curious if you have considered migrating from VirtualBox to Hyper-V given you are doing your work on a Windows laptop.

No, actually I had somehow never heard of Hyper-V before today (or maybe I had but for some reason it didn't click it was software I could make VMs with). Great suggestion, I'll look into it.

Definitely give Hyper-V a shot. I've been using it at home and work since Windows 8. I had a lot of issues with VirtualBox and networking (I could never SSH into a VM from the host working, for example). In Hyper-V, all you need to do is setup a virtual switch and the host and VM can talk to each other just fine. Hyper-V just works. I've got Linux and Windows VMs and have never had a problem with either (as far as virtualization goes). I use it less frequently now that Win10 has WSL & WSL 2, though (although WSL 2 uses a lightweight VM on Hyper-V).

Re: I'm not burned out, I'm pissed off

#245
post #239

I'm a recovering security guy. When I listen to security people rant, I can see their points and it's a bit of fun, I like a good rant. But I get the impression that they're continuously discovering new and exciting ways that individual facets of individual pieces of software (and the processes around them) suck. All without ever accepting that the entirety of the software ecosystem sucks (and that they're rarely mov…

I hate when I see people throwing in the towel like this. As a two developer company with four separate products doing nearly $500k in ARR collectively, Kumu [1] is a living example that it doesn’t have to be this way. We rely heavily on bash, docker and cloudformation. We only use Ubuntu LTS and we lag a release behind so there are plenty of tutorials available when it comes time to upgrade. After experimenting with…

"MRR per year".... hilarious.

I personally make over $1MM every single day per decade

Re: I'm not burned out, I'm pissed off

#246
post #166

Earlier quoted context omitted.

>They want the "theater" of security, the good feeling, the box to check on their resume (as management) so everyone can pretend everything is fine and go back to the business at hand. And don't forget the universal elixir that cures all security ills: adding even more rules about which passwords are allowed.

Make sure you change your password every 30 days, too. That way I have to write it down, or use a sequential password just in order to be able to remember it.

"Your password is too similar to one of your previous 24 passwords" -- an actual error message I've gotten before.

Re: I'm not burned out, I'm pissed off

#247

I'm a recovering security guy. When I listen to security people rant, I can see their points and it's a bit of fun, I like a good rant. But I get the impression that they're continuously discovering new and exciting ways that individual facets of individual pieces of software (and the processes around them) suck. All without ever accepting that the entirety of the software ecosystem sucks (and that they're rarely mov…

> I get the impression that they're continuously discovering new and exciting ways that individual facets of individual pieces of software (and the processes around them) suck As a software engineer, I think this is my experience at every job I've had around systems in general.

As a person sometimes overly distracted by grammar, I would like to thank you for using the "As a [description of subject], [subject] [rest of sentence]" construction correctly. Getting this wrong, which is called a "dangling modifier" error, is common. Examples from today's front-page HN discussions:

As a new (1 year) coder starting out at 39 years old, this sounds very similar to the path I envision for myself.

As another former Googler, yes, searching the entire monorepo was a frequent occurrence.

Corrected:

As a new (1 year) coder starting out at 39 years old, I envision a very similar to the path for myself.

I'm another former Googler. Yes, searching the entire monorepo was a frequent occurrence.

Re: I'm not burned out, I'm pissed off

#248
Well, the entire purpose of the infosec industry is to cover for the sh*t practices in the software development industry (and no it ain't engineering what most of these people practice).

So you have to expect that if your vendor is CADT your security is going to be full of holes and undiscovered bugs, critical missing features/etc. Move fast and break things also means shed-loads of bugs, many of which could be exploited by an enterprising individual for gain.

Re: I'm not burned out, I'm pissed off

#249
We're creating more complexity every day. Kubernetes, microservices, microfrontends, "big data" lakes, etc etc. Now instead of securing a physical server, or even a VM, you have to somehow secure thousands of interconnected endpoints in PaaS products in a cloud you can't even debug appropriately. Is it a surprise our software is worse than ever these days?

We've added complexity but we haven't increased our capabilities. What software can we make today that we couldn't 10 years ago? I'll even stipulate there could be a few examples, but 99% of the stuff we build today could have been built faster, cheaper and secured easier 10 years ago.

Re: I'm not burned out, I'm pissed off

#250

I 100% agree as a consultant working in product development. I think what drives this is a lack of ability for anyone to understand the end-to-end product from a technical standpoint and make coordinated decisions about direction. Instead, you have 30 teams with their own architects and roadmaps (which often overlap functionality) so you build the same thing 5 times across the org, then 3 of them end up drawing meani…

I experienced this several times as an employee. It becomes hard to stand when you realize that every positive contribution just results in more money being shoveled out of the window behind your back (mainly because of greed, inefficiency, keeping the status quo, and wreckless behaviour caused by trust in your capabilities to somehow fix it again, every time over again) -- as opposed to contributing to a more effici…

> Been doing extreme over-hours in the hope of fixing stuff once and for ever, only to realize your job becomes more and more like shit-shoveling, since management starts to feel invincible (and protected by your contributions)

Isn't that when you start earning a lot of money?

Post reply on HN