Live data from Hacker News

I'm not burned out, I'm pissed off

myname.website

281–290 of 335 posts

Re: I'm not burned out, I'm pissed off

#281
post #239

Earlier quoted context omitted.

I hate when I see people throwing in the towel like this. As a two developer company with four separate products doing nearly $500k in ARR collectively, Kumu [1] is a living example that it doesn’t have to be this way. We rely heavily on bash, docker and cloudformation. We only use Ubuntu LTS and we lag a release behind so there are plenty of tutorials available when it comes time to upgrade. After experimenting with…

I'm a bad writer. I'm not trying to throw in the towel, say software can't be fun, or that useful products can't be built within the status quo. I can look at the product I develop and rattle off an impressive list of capabilities, talk about how well it is designed, say why it's the best product for the job on the market and talk about successes in the field. But I can also look at it and see a laundry list of desig…

Your writing is just fine.

To me, most of the critical comments seem to miss the point that your frustration centers around the foolishness of trying "go as fast as possible" while at the same time "your shoelaces are tied together."

Re: I'm not burned out, I'm pissed off

#282
post #99

Ah, syslog. Around 18 years ago I was part of an group developing the next syslog protocol with security in mind. My company (one of the top infosec firms at the time) had a product doing this already. The standards group was a mess. Some other company without any credible security credentials was just forcing their bad implementation (TCP (!) and yet another protocol layer). They were backed by Microsoft and some ot…

Don't know about what group you're talking about but it ended up well: no need for a new protocol, just wrap in TLS with mutual cert authentication. TLS/TCP is fast enough nowadays that the overhead doesn't matter, and it saves you from having yet another standard.

But they did create a protocol with even more layers.

Also our solution did not need two way communication (as per TCP) but had encryption. This is key in a lot of infrastructure when you change environments (e.g. DMZ to some internal subnet). TCP and SSL were supported, too. Our software was used by one of the larges Unix installations and one of the largest telcos in the world. While theirs, not so much.

Re: I'm not burned out, I'm pissed off

#283

Earlier quoted context omitted.

That's true, and a good point, but a big part of that trust comes from the knowledge that no one can run a café without some kind of oversight and inspection on food safety. I probably wouldn't eat a sandwich from a bootleg café.

Define "bootleg." http://heartbleed.com/

s/bootleg/unlicensed/g

Re: I'm not burned out, I'm pissed off

#284

Earlier quoted context omitted.

I experienced this several times as an employee. It becomes hard to stand when you realize that every positive contribution just results in more money being shoveled out of the window behind your back (mainly because of greed, inefficiency, keeping the status quo, and wreckless behaviour caused by trust in your capabilities to somehow fix it again, every time over again) -- as opposed to contributing to a more effici…

> Been doing extreme over-hours in the hope of fixing stuff once and for ever, only to realize your job becomes more and more like shit-shoveling, since management starts to feel invincible (and protected by your contributions) Isn't that when you start earning a lot of money?

> Isn't that when you start earning a lot of money?

This is very dangerous thinking. Figure out why this true if it is not already obvious.

* Not sustainable * Not healthy * Not scalable

No sarcasm here. Try to avoid this thinking-trap.

Re: I'm not burned out, I'm pissed off

#285

Earlier quoted context omitted.

This comment nails it. Is there anyway to fix this problem? Not the burnout as that's the symptom but the cause, bad structure.

Enterprise architecture done well; but the tooling is incredibly difficult, it's expensive and you need a culture devoted to engineering discipline over raw productivity. Other industries manage this just fine: manufacturing and defense contracting are two that come to mind. Both industries have pretty good work / life balance for their employees. Tech is just worse because we haven't unionized like both of those ind…

> you need a culture devoted to engineering discipline over raw productivity

Where can I find this? Sign me up -- please!

Re: I'm not burned out, I'm pissed off

#286
post #139

"A new car built by my company leaves somewhere traveling at 60 mph. The rear differential locks up. The car crashes and burns with everyone trapped inside. Now, should we initiate a recall? Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one." N…

For those who didn't get the reference: The OP is quoting Tyler Durden, a fictional character of the movie 'fight club'. So take it with a grain of salt.

The quote is resonant because anybody with first hand experience with the way "corporations" think internally about such matters KNOWS that this is EXACTLY how it plays out.

Re: I'm not burned out, I'm pissed off

#287
post #230

I'm a recovering security guy. When I listen to security people rant, I can see their points and it's a bit of fun, I like a good rant. But I get the impression that they're continuously discovering new and exciting ways that individual facets of individual pieces of software (and the processes around them) suck. All without ever accepting that the entirety of the software ecosystem sucks (and that they're rarely mov…

Not really security, but regarding software in general, Mud is one of the reasons I gravitated torwards pure FP languages. It doesn't solve everything, but the added guarantees help shift some of the cognitive burden away from having to dig into every method to have to see what's going on, and I can spend that mental budget elsewhere.

This reminds me that "but think of the children" mantra. From my observation programmers often tend to justify / promote their languages/tools/etc under pretense of solving security problems.

Re: I'm not burned out, I'm pissed off

#288
post #26

Earlier quoted context omitted.

Thing is, it took me a long time to accept that people not caring was ok. Now I realize that my dad is frustrated I never learned something as simple as changing the oil on my car. My mom does not understand how I can't name more than two flowers and can't bake a pie. My legal-minded friends are astounded I do not take a day to work on my legal status to pay less taxes. Hell, my wife does the paperwork I am not even…

Your mom and dad, or grandparents probably didn't need to know, even though they know how. Most of their interactions were with local businesses, with people who, like themselves, were part of the local community. The unofficial grapevine worked pretty well for rooting out the good and bad mechanics, lawyers and florists. Your dad could change the oil, but almost certainly knew which mechanics could be trusted to hav…

> The network means nothing, except as something to be gamed.

Thank you for this insight, particularly the concise manner in which you have articulated it.

Re: I'm not burned out, I'm pissed off

#289

1) Increasingly, if you want to be in infosec, you have to learn how to code on the level of a SWE. This is how to not lose your mind when constantly addressing sec issues that others (devs) are entirely responsible for fixing. 2) Department of No doesn't have to be a thing, it just takes some emotional intelligence and pragmatism. 'Always saying no' is as much the fault of the sec eng as it is the system. If you hav…

I've worked in a shop where InfoSec tried to be the Department of Yes. They were very effective at that - they basically never said "No" to anything. The downside was that they weren't actually able to say "No" to the things that they really needed to be able to change. A lack of accountability for decisions meant that people could ignore InfoSec consequence-free. All told, I've learned that security needs to have the ability to say "No" and the organizational backing to make it stick. It's the implicit threat that makes other groups play ball.

I've had at best mixed results with covering people with positivity and admiration in an effort to get them to fix things. It's often easy enough when it's something really small that looks easy and understandable. When you've got a whole architecture predicated on everything accessing everything unchecked, suggesting that maybe this absolutely amazing architecture could be even better with a tiny bit of TLS and authentication is unlikely to get you anywhere.

Re: I'm not burned out, I'm pissed off

#290

>I'm mad that I sat on a call representing my company's (not cloud native) cloud offering listening to Cisco tell us that the only way to get logs from god damned IRONPORT in the cloud was to use syslog! OVER THE INTERNET. FOR SECURITY LOGS. Why is this an issue? This is how syslog works on literally every device ever, you set a destination and it streams it over UDP with optional authentication/encryption. If you wa…

> logs are push (generated), not a pull or sub or whatever you're trying to do

This is incorrect -- and myopic.

Post reply on HN