Live data from Hacker News

I'm not burned out, I'm pissed off

myname.website

61–70 of 335 posts

Re: I'm not burned out, I'm pissed off

#61
post #41

If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…

Conversely, in a lot of industries the security department is only there to prevent you from doing everything you need to do, even if the threat and attack surface are both minimal.

Agreed, too often security people are incentivised to make a massive fuss over tiny issues, and then often don't seem to understand that security is just one of many requirements needing to balanced

Re: I'm not burned out, I'm pissed off

#62
post #54
post #25

Earlier quoted context omitted.

I work as a contractor for a bank. A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the pro…

> I'm tempted to just credit myself 1 monetary unit in production and just show them the statement. I would be tempted too, though I could bet that this will be a termination of an employment, instead of the problem being fixed. I would like to be proven wrong on this speculation..

Not just that, I would expect criminal charges to follow.

Re: I'm not burned out, I'm pissed off

#63
post #14

I asked my SO recently how she view the Internet, what it is and how it works. She was honest and told me that, "If I click this button, this websites loads. If that works I'm fine! If it doesn't I will call you. Don't stop working with IT please, if you get it, we need you badly!" I believe that is a good reason to be accepting towards the current state of affairs. People just don't care. They have more important is…

And users should not need to care (too much). I drive a care and while I know some of the inner workings of an ICE, most people who drive do not and that's FINE. The car is a utility that people just want to work.

Why is software expected to be different? Why should it be? Why does your grandma require a basic understanding of password security anyways?

Re: I'm not burned out, I'm pissed off

#64
post #54
post #25

Earlier quoted context omitted.

I work as a contractor for a bank. A few months ago everybody was up in arms about a "major" security issue discovered by an auditor (you could see the settings of random users by changing an id in a url). I've just shown them you can credit money to your account, yet this is low priority and they provided a fix that I'm 100% percent sure didn't fix anything, unfortunately the functionality is down on all but the pro…

> I'm tempted to just credit myself 1 monetary unit in production and just show them the statement. I would be tempted too, though I could bet that this will be a termination of an employment, instead of the problem being fixed. I would like to be proven wrong on this speculation..

Yes, that's what I thought as well.I'll just have to suck it up until the test environments are up again and provide a proof of concept exploit.

I'm just impatient because it's a really clever and somewhat complex hack that challenges some multi-threading and transactionability assumptions some people mande and I can't really talk about it(which I'd love to share with my peers).

Re: I'm not burned out, I'm pissed off

#65
This guy needs to understand his place in the workings of everyone around him, just like his product's place in the workings of the products around it. If you provide a product with a function that is transparent to the user unless it breaks, then they're going to place their priorities where the needs are most obvious and rewarding. The people who use his products have jobs with focuses are something other than his security product. Their priority will always be on what they have to do to earn their money. A corollary to earning money is saving money. As far as the product never arriving at its ideal function goes, the products that his security products serve will always evolve, so his product will always have to change with them. You can only let these things get to you so much. Source: I was responsible for the surgical equipment for a hospital. You want to see reality avoidance and cost-priorites get ugly?

Re: I'm not burned out, I'm pissed off

#67
post #60
post #55

Earlier quoted context omitted.

"Yo are not seeing the fact that it is only you who are responsible for what’s happening inside you ." This kind of pop-psych babble is naive and abusive.

Blame the whole world, why don’t ya

That's clearly the only other option.

Re: I'm not burned out, I'm pissed off

#68

If you work in security, this resonates so much. No one really cares about security except to check a box or pay lip service to it. That's why so called security products ship without logging and clients don't want to make the smallest effort to enable you to improve their security. It's why companies that sell security products invest more in marketing than the product. The industry is full of conmen and marketeers.…

Bro (or Sis? :) )! They're not supposed to care about security, you are! Our job in infosec is to show others how insecurity affects what they care about so in order reduce,transfer or eliminate risk to what they care about they allow us to implement good security. The failure is on the infosec side of the equation.

It confounds and mildly pisses me off when people get pissed and get burned out over suits not caring about infosec. I mean,they care about promotions,reputation,bottom line,ROI,KPI,etc... That's what they do. You know why the marketeers and buzzword snakeoil salesmen prosper? It is because they communicate not only risk but especially [fake] solutions better! Infosec is full of user and management blaming, expecting peoppe outside of software developers and infosec practitioners to care about infosec. I am not saying I have it figured out but I am fairly certain users and decision makers need to be told solutions within the context of risk that affects them. And if it doesn't affct them they're not supposed to care.

I'll give you an example, a network is filled with tls1.0,and ssl1.3, how does that affect some mid sized company's bottom line or reputation? How do they get ROI on the man hours and resources spent to upgrade everythig to TLS1.3 with proper cipher suites and key exchange? and what KPI can they use to measure efficiency of resources? How will you tell them security hygeine takes a very long time to show ROI as do many other security concepts?

You don't really have to do all that if you don't want to, plenty of skill demand to where you can progress to more exciting positions.

Re: I'm not burned out, I'm pissed off

#69

Earlier quoted context omitted.

Copy and distribution costs are just a part of the cost. Development and maintenance does require real flesh and blood people spending their days working on developing, building, and deployment. That part costs money.

You tacitly assume that I am not aware that software products have an R&D cost, and you are (insultingly) wrong. Of course they do. And without artificial scarcity that R&D cost will not be recouped. The default state of software is an open source model, where the "developing, building, and deployment" doesn't cost money because there isn't any.

Copy and distribution costs for movies in a digital age are non existant. Are movies using artificial scarcity?

Re: I'm not burned out, I'm pissed off

#70
post #57
post #56

Earlier quoted context omitted.

The easiest security investment is to switch your shop from Windows, cutting like 98% of threats out there cold.

As well as cutting 98% of your workforce as no office employee knows how to work on anything different.

> As well as cutting 98% of your workforce as no office employee knows how to work on anything different.

Techies repeating this should take a lot of the blame for why Windows still sell as well as it does.

A 50 year old electrician convinced me to start using Ubuntu 13 years ago after someone at his kids elementary school or something had told him.

UX wise Linux passed Windows in many areas around the time Ubuntu was introduced.

The only reasons now are prefererence, hard dependencies on Windows only software, stubbornness and incomptence.

Only the two first ones are good reason in my opinion.

Post reply on HN