Live data from Hacker News

Thinking of a Cybersecurity Career?

krebsonsecurity.com

21–30 of 129 posts

Re: Thinking of a Cybersecurity Career?

#21
I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now.

While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge of the platform used (e.g. Microsoft) and internal processes are more important. After all, most companies already fail at the 'fix the obvious' stage, it's not necessary to go looking for clever ways in when there are many doors left open.

Just to elaborate: A lot of discussions go like this. A pentest or random scan finds obvious issue. Ticket is raised to the security team. They go like "WTF why do we still have Windows 95?? Kill it.". Then their boss goes like "Sorry, Bill the manufacturing VP lobbied with the CEO, we have to leave that one alone". Of course when it actually gets hacked, Bill is nowhere to be found. This is why internal influencing skills are so important in real everyday security jobs.

Of course in the pentesting role this kind of thinking is absolutely necessary. However even there the kind of training given right now is too much in the realm of 'scriptkiddie'ism. Hacking is about inventing and true mastery of technology, not about using the tools everyone uses. Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's.

Re: Thinking of a Cybersecurity Career?

#22
post #9

Krebs does not work in Cybersecurity, does not come from a position of knowledge or experience in Cybersecurity and his only skill relating to Cybersecurity is doxxing people. I could understand if this was "Thinking of a Cybersecurity journalism career" but there are better people to learn from.

I do incident response for a living and the general idea of his article was accurate. His message is that many candidates lack the technical capability to do the job but its easy to acquire those skills on your own using resources from the web if you are really interested in it.

He even added a disclaimer that he's not a technical expert.

Re: Thinking of a Cybersecurity Career?

#23
During my degree, I had a crossover unit for cryptography. The unit was a mix of computer science majors, and also a new "cyber security" degree the university had recently started. This was a third year unit.

Holy-moly, did the cyber security students flop from the first class. It was immediately clear that the new "degree" they had signed up for had not given them even elementary math skills in comp. sci related fields (discrete math, linear algebra). A few of them put in the hard yards, studied about a year's worth of math and did okay. But the majority flopped out hard and failed.

The "degree" was dropped a year later. Poor kids.

Re: Thinking of a Cybersecurity Career?

#25

I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now. While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge…

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's.

Be careful here. This is bordering on elitism.

Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile.

In learning how networking works; how operating systems are designed and implemented; why and how the OWASP Top Ten work; and knowing solutions to these problems is still a valuable skill set.

What you're suggesting is everyone has to be willing and able to write fresh exploitation on the spot when they're testing a client's network when in fact there's a lot that can be discovered (and resolved) with basic scans and simple questions based off of Security+ grade knowledge.

Re: Thinking of a Cybersecurity Career?

#26
post #25

I think the cybersecurity (I hate the term cyber btw as it's usually used by people who don't know what they're talking about), is very focused on the 'think like a hacker' skillset right now. While I do agree this is important in various roles in the security realm, there are also many jobs where this doesn't really add value. A lot of work is about implementing things like MFA, role-based-access etc where knowledge…

> Being able to run metasploit and wireshark does not make one a hacker. By doing this, pentesters test for yesterday's hacks, not tomorrow's. Be careful here. This is bordering on elitism. Having someone come into a business and check for "yesterday's hacks" is better than no one doing any checks at all, therefore such skills are still valuable and worthwhile. In learning how networking works; how operating systems…

I know, but most of these "hacks" are identified by internal scans already. The pentest doesn't add much value then. The issue is more internal resistance to change in the management team.

Like I said I know most companies already fail at the basics. But these are normally well known already, just not fixed due to political pressure. Having the security team's management be better at influencing would pre-empt these issues. Pentests serve to bring these known issues under discussion again, but they often don't bring any unknown issues to light.

Also, they tend to be too artificial. In one example: In a recent pentest I know of, they sent some remote access malware to the admins, which they all ignored and reported. However as they couldn't continue they called one admin's manager and asked him to tell the admin to click on the link so that they could proceed. The outcome of the pentest was that if a malicious actor sent a malicious remote access malware and if it was clicked on, they would have remote access. Well duh.

Of course this could be mitigated by having separate workstations for email and admin activity, which was an issue that was already understood and a mitigation in progress. This is what I mean by pentesting not raising new issues. Another example: The company in question already test new web apps for known attacks, and is quite successful (in fact I've never seen a new app come through the certification process in the first round). What I'd expect from a pentest is to tell us something we don't know :) It's an interesting second-opinion but it's not the amazing X-ray it's promised to be.

> What you're suggesting is everyone has to be willing and able to write fresh exploitation on the spot when they're testing a client's network

Which is exactly what a serious adversary would be doing in a targeted hack!

Re: Thinking of a Cybersecurity Career?

#28
In my experience, c level folks just want someone who can produce a dashboard or executive report with a bunch of green check marks that basically say “yay! We’re secure”. They don’t care about the why, how, if the check marks are actually meaningful, etc. This mindset is then reinforced by vendors selling security snake oil - the entire infosec domain is a shit show; if infosec practitioners ever want to be taken seriously, they need to collectively get their shit together and organize around some real tangible standards.

Re: Thinking of a Cybersecurity Career?

#30

As someone undertaking a Master's in Cybersecurity, that table is totally true. Most of my courses have a programming alternative for assignments yet the students alongside me have very little interest. I've been doing this a while so maybe I'm just an outlier as I've always been the guy who is the jack of all trades, but I can't help but see something unknown as something to learn.

It's a similar story in my cybersecurity Master's program. Many students seem to lack any dev or administration skills and are basically locked out of the high quality, practical classes because of it. Everyone that seems to be succeeding in my program and in the job market either has a formal CS background or is a motivated, self-taught dev or admin.
Post reply on HN