Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

141–150 of 175 posts

Re: I quit infosec and I couldn't be happier

#141

Earlier quoted context omitted.

Zoomers aren't even old enough to determine that yet. They're in their early 20's at most and no one that age has the experience to definitively say anything regarding this. The alternative to hard work is doing nothing and that certainly will get you no where at all. The idea that a younger generation might have had it slightly better (which I think is pretty subjective anyway, previous generations have all had thei…

> The alternative to hard work is doing nothing and that certainly will get you no where at all. This is a false dichotomy. I put in a solid 40-50 hours at work. If I have to put in double that just to stand a shot -- not get, but have a shot at -- the lifestyle that my parent's had while only putting in 40 hours a week, then the system has failed me. And that was 40 hours a week with one person working and the other…

No, your argument is a straw man. I'm not referring to your personal work ethic here. The general idea that you will get ahead by doing less is just bullshit. You seem to have a narrow focus on the white collar workplace as it pertains to you. I'm speaking about life in general.

"It's a broken system, and the Zoomers can easily see that -- they've had smartphones since they were like 8."

If you're referring to the poor decision making on raising kids with smartphones I'd agree with you, but that's a lack of good parenting and bad moral judgement. It has nothing to do with capitalism or modern work ethic.

The irony and cognitive dissonance in this statement. That means by every economic measure they were doing quite well at age 8. Did boomers get cell phones when they were 8? How about survivors of the Great Depression... do you think they had anything close to the equivalent of a cell phone at the time? The other issue here is that you believe constant negative influx of media as always truthful.

The issue with you is that you assume that a generation having slightly less than the previous means we need to scrap the whole system and it doesn't work. You need to put some things in perspective and maybe realize that the life you had growing up was WAY above average so a slight decline to a lifestyle that's still magnitudes better than what the average world citizen deals with isn't all that big of a problem. There are generations and generations of people that died to give you what you got, went through world wars, civil wars, great depression, pandemics. I'm sure they'd have loved to be "slaving away" in your climate controlled office environment with a smartphone.

"And that was 40 hours a week with one person working and the other staying at home."

You can blame feminism for that. It tricked the average woman into thinking they would have more meaning working in an office 40 hours a week than they would doing the most important job in the world... raising kids. It turns out that when everyone starts having a higher average family income, the market adjusts to that. And, the staying home and raising kids part is key, they weren't just sitting at home doing nothing while their partner worked.

Re: I quit infosec and I couldn't be happier

#142
post #92

Earlier quoted context omitted.

Zoomers aren't even old enough to determine that yet. They're in their early 20's at most and no one that age has the experience to definitively say anything regarding this. The alternative to hard work is doing nothing and that certainly will get you no where at all. The idea that a younger generation might have had it slightly better (which I think is pretty subjective anyway, previous generations have all had thei…

You're putting forward a false dichotomy. Not buying into the ethics of 'work hard for a company, they make money, you make money and that is a self evident net positive' is quite reasonable. There is no need to resort to name calling for people who don't buy into this narrative. There is quite a lot more to live, and to being a good person, then pouring your all into paid work. And it is plain to see there was a nic…

You're putting forth a strawman. Where did I mention anything about a company??? Who did I call names?

"A working person could support a family, buy a home before 30 and have hobbies 50 years ago."

Try not living on the coast near your favorite coffee shop and you too can achieve this. It's almost like those generations didn't expect to have a beach front condo in LA with every tech gadget available.

That's because one person worked. What do you think happens economically when both parents in a family start working? This is basic economic principle.

Re: I quit infosec and I couldn't be happier

#143

Earlier quoted context omitted.

OMG, its like you're speaking right to me! :-) I have a multi-decade career, and for like the first decade or decade and a half or so, i tried to stay as long as reasonably possible at whatever big compoany i worked for....being raised to think that loyalty, and working a long number of years at the same employer was a sort of weird badge of honor. I got hit by bureacratic BS/blocks on such a constant basis, and then…

It's a marathon. When you don't enjoy it, start a new one. There will always be bureaucracy, just deal with it and disconnect at the end of the day so you can do the things you love with the people you love.

Yeah, i guess i wish that i could just join a single marathon (and stop keep starting new ones). I do unplug at the end of the day; that lesson i learned over the many years. But while I'm at my day job, i really want to give it my 100%...But, it seems so many firms can't get out of their own way to let the passionate (and highly competent) people contribute in meaningful ways. Its silly really, since these same firms have everything to gain - from revenue perspective, talent retention, yes good PR too, etc...Oh well. Towards new (smaller) marathons i'll head i guess. :-)

Re: I quit infosec and I couldn't be happier

#145

I had watched a few courses on information security and noticed that those working in the more management / corporate related infosec roles seemed to be massively overweight, almost all of them (I am too, btw). Not saying that to shame anyone, just: Does the job make you miserable or stressed out? I have been forced to do the infosec role as a "side thing" in a couple of jobs now, mainly because nobody else was aroun…

[deleted]

Re: I quit infosec and I couldn't be happier

#146

I have said it before and still say... InfoSec is a glorified policy writer. You spent more time 90% of the time "writing documentation" rather than on finding the security problem and suggesting the fix. That's why i choose development rather than InfoSec (despite having a knack for it), because its more technical and i don't need to explain "why" everytime.

The best security tools and practices won't protect the business if they're not used consistently. Policy is how things get done. It's an expression of the business' values and priorities. Even if it's just "all employees must install the authenticator app or request a Yubikey otherwise the cyberinsurance will drop us."

Re: I quit infosec and I couldn't be happier

#147

Earlier quoted context omitted.

This isn’t universally true. Large tech companies have a need for specialists and are willing to pay quite well for it.

They might pay well, but if you're not in a profit center for the company - you won't be as valued as much as those who are.

Profit/cost center is kind of a false dichotomy in some places. At the least, it lacks nuance. If you sell software or services that require privileged access, security tends to be valued more highly than a checkbox.

Re: I quit infosec and I couldn't be happier

#148
post #16

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

Sounds like folks like you must have been doing a really good job if it's that much harder to exploit vulnerabilities!

I think it's more like software developers have gotten better, leaving less room from cyber security.

When I first started any idiot could back a web application because nearly all of them had a silly exploits like SQL injection.

Re: I quit infosec and I couldn't be happier

#149

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

> Never be a CISO Can you share why?

Well, they don't call it Chief Incident Scapegoat Officer for nothing.

Re: I quit infosec and I couldn't be happier

#150

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

>around quiet quitting Please do not use this phrase. Working 9-5 is called "doing your job" IT in Europe here and we work 8-5 with 1h lunch...

> IT in Europe here and we work 8-5 with 1h lunch...

Similar in the US, I've never actually seen an office that works 9-5, despite that being the phrase. It's always 8:30-5 or 8-5.

It may once have been A Thing here in the US, with a 30-minute lunch and two 15-minute breaks coming out of a total of eight hours at work, since there are legally-mandated break periods for ordinary wage or hourly workers—but it seems like everyone's "exempt" now and so has far less legal protection, plus I'm sure enforcement's nearly non-existent. I assume it did actually exist, once, though, for "9-to-5" to have entered the language to begin with.

Post reply on HN