Live data from Hacker News

Shared thoughts after 6 years in Pentesting

0x00sec.org

51–60 of 97 posts

Re: Shared thoughts after 6 years in Pentesting

#51
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

Agreed. I work in infosec as well, and I think the author of this article is confusing time spent vs. passion for something. Coming from software engineering, security is no different than any other technical profession: if you don't love what you do, you probably won't be very motivated to learn, and thus you probably won't be very competent. You need to have the passion. This doesn't need to manifest itself in 80 h…

It sounds a bit like developers who jump on every hyped up new technology without really having a reason.

Re: Shared thoughts after 6 years in Pentesting

#52
post #40

Earlier quoted context omitted.

Please explain how is that so?

Certification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class. As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is don…

I think you guys are comparing apples to oranges

> Certification in a field such as vulnerability research

OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them.

> As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications

So apparently OSCP won't get you a job at Matasano - but they're not the only game in town, and a lot of other security shops with less name recognition and lower standards do in fact use the OSCP as a positive signal.

No, it won't be l33t but it will be a job that they can use to transition to those fancy schmancy companies whose founders are HN regulars.

Re: Shared thoughts after 6 years in Pentesting

#53
post #41
post #7

Earlier quoted context omitted.

I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…

If you're entry-level and don't have a network, certs help you get through the HR filter. Once you're mid-level, you can use your network and experience.

This. Simply saying "certifications are bad don't get them" is not universally helpful advice. Some people will definitely face improved career prospects with the right cert(s) depending on their market and level of experience. Not all companies have equally enlightened hiring practices - and not all prospective employees can pick and choose the way some veteran HN members can.

Re: Shared thoughts after 6 years in Pentesting

#54
post #27
post #25

Earlier quoted context omitted.

I don't have a formal degree! I have 1 semester of college from 1995, and that's it. You don't have to do RE to be in software security. There's virtually no assembly-level RE in web application security, and very little of it in mobile security. Both of those specialties are more lucrative than RE, a specialty where maybe the top 10% go to high-status RE and exploit dev careers, and the other 90% go to low-status ma…

Picking has always been hard I guess. Thank you very much for the solid advice. I will keep it in mind moving forward.

Then don't pick: surf r/netsec and use anything you find fun. 1 month later look at what you practiced most and enjoyed most, here you are, some part of your brain actually picked the possibly right thing for you. :)

Re: Shared thoughts after 6 years in Pentesting

#55
post #17
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I am just starting in Networking and want to progress to NetSec eventually and I was kind of taken back by OPs advice to work 80 hours a week, I want to have a life, not work all the time, so your comment was pretty comforting. > 2. Don't get certificates I am progressing through my CCNP and LPIC-1, mostly because I want to get recognized for my skills, but I also see them as a guideline, what to learn next, kind of…

But... Hey, yes, have a life, that is a hacking / security life !

Is there something else ? ;)

Honestly without joking, as the OP said, having this as a passion or lifestyle is going to accelerate your proficiency compared to the others. My feeling is that it's not an absolute prerequisite, just a tremendous accelerator.

I started "having a life" maybe 15 years after the beginning of my hacking passion ;) tho my wife would argue about that ;)

Re: Shared thoughts after 6 years in Pentesting

#56

So many years pen testing. Is blue better than black? Do red pens last longer?

Black tend to not notice how much / badly tainted they become.

Red/white may not know how bad and hostile reality is.

Ps: no, there's no comment about ethnicity in this comment.

Re: Shared thoughts after 6 years in Pentesting

#57
post #6
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I agree with you. Here are some of my thoughts at 15 years: 1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch. 1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved. 2. Work 40 hours a week. Don't be a hero. You'…

> Learn some advanced mathematics and cryptography.

There is too much of mathematics to learn all of them. To make maximize, I think I need to focus on some subjects that would be cost-effective. What woulds would this be?

Re: Shared thoughts after 6 years in Pentesting

#58

Earlier quoted context omitted.

He is including time spent on here :P

He is including all time spent learning stuff and so on. 40h work + 40h learning/reading HN/doing hobby projects is pretty common.

Is it really? That's 16 hours of work 5 days a week. If you sleep for 8h you don't do anything but work or learn for all of your waking hours.

A more reasonable person would probably put a fair amount of learning time on the weekend, but even then you leave very little time for a social life, physical exercise, eating, relaxing.. things that most healthy people, if not everyone, requires.

Re: Shared thoughts after 6 years in Pentesting

#59
post #8
post #7

Earlier quoted context omitted.

I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…

If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.

"Avoid certification."

So how do you get through HR wall? Padding CV with keywords is a common way to get an interview. I'm an embedded system engineer looking to move closer to IT security, so how do I get there without experience and certifications as virtually all jobs require one, another or both (except junior positions, but I'm too old to start from the very bottom)? I do learn a lot on my spare time, but you still need to get a chance to demonstrate your skills, which is impossible if your CV is discarded as "requirements are not met" (a.k.a not enough keywords on CV match the ones in job description).

Re: Shared thoughts after 6 years in Pentesting

#60

Yeah...stopped reading at 80 hour weeks. I don't care how esteemed someone is in their industry, if they have to completely destroy their life to get there I question their judgement and don't want their advice.

Not sure such an absolutist approach is much better. I definitely agree with your sentiment, but as my own clichéd counter-example, I can tell you that I wasn't always like that.

I squandered away my 20's and 30's on 80-hour work weeks. It was never expected of me, I just loved my job and did it anyway. Yes, there have been benefits, but today I feel I lost more than I gained.

At the time I would've dismissed you and your comment as you do OP's. Life just isn't that black and white.

Post reply on HN