Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

151–160 of 175 posts

Re: I quit infosec and I couldn't be happier

#151
post #83
post #68

Earlier quoted context omitted.

Why does a personal blog page need HTTPS? It's an output page, I read the contents and leave, I'm never submitting any of my information across the wire. Someone along the way might modify the page? Unless they're using HSTS, it won't matter. I'm all for encryption, but I'm also all for using tools when necessary, and not complicating things when not.

troyhunt answers this very question: https://www.troyhunt.com/heres-why-your-static-website-needs...

It's an answer, but I still find it entirely unconvincing for a static personal blog. Better? Sure. Necessary? Damning if it's absent? No.

Re: I quit infosec and I couldn't be happier

#152
post #91

Earlier quoted context omitted.

I think the trick to staying happy in cyber security is to chase down niche fields in technology. Your work won't be perceived as sexy by the broader community since you're not tracking north korea, but the trade off is that you will have fun and not have to brush shoulders with so many egos. So what's green these days? That's for you to decide, but one area I think is interesting is smart contract security on blockc…

Moving into the blockchain space to avoid brushing shoulders with egos is like living in a pig pen to avoid getting dirty.

Sure there are a lot of egos on the business side of blockchain, but I meant smart contract & protocol auditing.

Re: I quit infosec and I couldn't be happier

#153
post #16

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

Sounds like folks like you must have been doing a really good job if it's that much harder to exploit vulnerabilities!

Yeah, ultimately the goal of infosec is to make itself obsolete. On the one hand, it seems to be working because exploiting things has become more difficult/expensive. On the other hand, cyber attacks seem more rampant than ever, because exploiting things has also become more lucrative. So are the effects of the infosec industry real? Or is it just an arms race?

Re: I quit infosec and I couldn't be happier

#154

Earlier quoted context omitted.

This isn’t universally true. Large tech companies have a need for specialists and are willing to pay quite well for it.

They might pay well, but if you're not in a profit center for the company - you won't be as valued as much as those who are.

I was working for a hospital, then they converted us to work for a company that sells our services to hospitals, then they outsourced 300 of us to offshore including me.

Re: I quit infosec and I couldn't be happier

#155
@PaulSec, Why didn't you move to blue team side of things? It may have been more enjoyable catching actual threat actors and learning the latesr tech/platform/attack sp you can defend against it. Glad it worked out for you though.

I almost can't imagine not working in infosec, it might feel like losing a limb I think. It's not the assembly, exploits,etc... that does it for me but how I am never bored and always learning something new. The feeling when you find a compromise by sophisticated actor or even stop a compromise in progress, even if no one ever hears about it is amazing. I did networking and other types of jobs that were great too but eventually you master those more or less and start to get bored. I suspect pentesting is similar in that you learn new techniques all the time but the vulns you find are still the same stuff more or less? I have no idea, just guessing. I guess what I am trying to say is how rare it is to find someone with passion for infosec that applies themselves and how broad the industry is (maybe you might enjoy being an instructor or manager?) and how any job in infosec would love to have you because of your background.

Re: I quit infosec and I couldn't be happier

#156
post #50

Earlier quoted context omitted.

They shared why in the prior two sentences, when saying what they enjoy when not a CISO. "Show up. Hack. Write report."

I asked for more detail because I’m in a role training under a CISO and rapidly approaching a decisioning point to assume their role. Sorry I didn’t make that clear in my original comment.

Anyhow, I think I elaborated in other places. I don't think it is a bad role, but as a tech first, programming first type of person I would never be a CISO. Even as a manager I want to manage interesting technical things and spread knowledge and skills of how to build (secure) interesting technical things to people. CISO and risk management roles everywhere herd cats and don't really get to do that. So you have to keep in mind my perspective. Comp and top end of the risk management and information security management career can be really rewarding, but it is a mostly thankless job trying to get people to do things that no one will ultimately like all that much even if it is the right thing and they know it :)

Re: I quit infosec and I couldn't be happier

#157
post #16

Earlier quoted context omitted.

Sounds like folks like you must have been doing a really good job if it's that much harder to exploit vulnerabilities!

Yeah, ultimately the goal of infosec is to make itself obsolete. On the one hand, it seems to be working because exploiting things has become more difficult/expensive. On the other hand, cyber attacks seem more rampant than ever, because exploiting things has also become more lucrative. So are the effects of the infosec industry real? Or is it just an arms race?

We still find SQL Injection at an alarming rate... but yes, eventually it would be nice to make it nearly impossible to do the wrong thing by default for programmers. That is the dream. Information systems are just too vast and complex for that to be true on any time scale I could predict for you, though, so job security seems pretty good!

Re: I quit infosec and I couldn't be happier

#158

> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that mak…

>around quiet quitting Please do not use this phrase. Working 9-5 is called "doing your job" IT in Europe here and we work 8-5 with 1h lunch...

9 to 18 in France, mostly. Time for lunch is usually in the 30-45 min but this is by choice.

Quite a lot of people stay after 18, mainly because of historical/ tradition reasons.

Re: I quit infosec and I couldn't be happier

#159
post #8

Earlier quoted context omitted.

I don't think it was meant to be an "infosec is wrong and I'm right so I'm leaving" type story. I like that the author wasn't afraid to make a change, not everyone can but it makes for an interesting story!

Sure. But the title insinuated an analysis of how information security causes one unending stress, day after 20 years if working in it one develops a hardened siege mentality etc etc etc. I have read things like that befire, which were interesting perspectives That would be more on point with the title. Anyways nothing wrong with the text, but my comment stands.

Your comment should kneel before the reasoning of his argument.

Re: I quit infosec and I couldn't be happier

#160

Earlier quoted context omitted.

Sure. But the title insinuated an analysis of how information security causes one unending stress, day after 20 years if working in it one develops a hardened siege mentality etc etc etc. I have read things like that befire, which were interesting perspectives That would be more on point with the title. Anyways nothing wrong with the text, but my comment stands.

Your comment should kneel before the reasoning of his argument.

That's okay. I didn't read it.
Post reply on HN