Live data from Hacker News

I quit infosec and I couldn't be happier

paulsec.github.io

81–90 of 175 posts

Re: I quit infosec and I couldn't be happier

#81

I have said it before and still say... InfoSec is a glorified policy writer. You spent more time 90% of the time "writing documentation" rather than on finding the security problem and suggesting the fix. That's why i choose development rather than InfoSec (despite having a knack for it), because its more technical and i don't need to explain "why" everytime.

I think you are mistaken. Obviously InfoSec is a rather generalising term, while you are abstractly describing the work of someone that works in Application Security.

Re: I quit infosec and I couldn't be happier

#82
post #20

Earlier quoted context omitted.

Millennial here as well, it's really excited to see our generation and the next generation reject "making money for someone else" as a way of finding meaning in life. I'm chewing on a lot of blog posts about this, regarding for example how the concept of "retirement" is terrifying. I was on a cruise recently and talking with a bunch of old people, and the subject often came up about how people were "finally taking th…

> busting ass from your 20s to mid to late 50s, and then getting hopefully another 30 years to "enjoy life?" Its just slavery which the older generations thought was appropriate, much like having a large family to look after you was a thing before family sizes came down. It sounds cliched, but have a bucket list of things you want to do and try to do some of them. Put yourself first and your job second because the da…

How is working for money slavery?

Do you believe food just magically appears on your plate, water cleans itself, your plumbing just happens to work, medical services operate autonomously etc.?

The problem here, is you're an elitist. For you, your boring desk job is slavery so you want the freedom to go about doing whatever you want while the peasants provide you the means to continue being fat happy without providing anything back to society.

You're speaking from a small minded subset of white collar society that has the inability to understand how society operates as a whole. What you want is to subject a certain class to "slavery" to support your endeavors.

Re: I quit infosec and I couldn't be happier

#83
post #68
post #53

Earlier quoted context omitted.

I was about to comment on the same... my only question to the OP (and other's who don't enforce HTTPS) is "why?!"

Why does a personal blog page need HTTPS? It's an output page, I read the contents and leave, I'm never submitting any of my information across the wire. Someone along the way might modify the page? Unless they're using HSTS, it won't matter. I'm all for encryption, but I'm also all for using tools when necessary, and not complicating things when not.

troyhunt answers this very question: https://www.troyhunt.com/heres-why-your-static-website-needs...

Re: I quit infosec and I couldn't be happier

#84

I have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reve…

As someone with a C/C++ background considering a move in this direction career-wise, would you still recommend it?

Re: I quit infosec and I couldn't be happier

#85
post #53

By default when I click the link I'm directed to a non-secure HTTP version of github, which I found ironic given the page title

I was about to comment on the same... my only question to the OP (and other's who don't enforce HTTPS) is "why?!"

You'd be surprised how many top websites (e.g. Amazon, eBay) don't even implement HSTS, let alone HSTS Preload. Here's some naming-and-shaming:

https://blog.majid.info/hsts-preload/

Re: I quit infosec and I couldn't be happier

#87
For anybody tempted to skim or not read the article, the title [ps. "quit" is a bit less awkward - imo, natch :) ] is a bit misleading; the main takeaway at the end is the rather more positive:

Looking back, working in infosec was such a great experience and I recommend it to anyone who wants to jump in!

The reflections generally about knowing when to move on are more field-agnostic.

Re: I quit infosec and I couldn't be happier

#88
post #21

Earlier quoted context omitted.

> Never be a CISO Can you share why?

From what I've heard from other CISOs: You own a bunch of unsolvable risk and your head is one of the first to get lopped off if you're popped. Honestly, the CISO role probably needs a golden parachute and a direct report to the CEO for it to be an appealing path for most anyone who's experienced it at least once. The former to incentivize owning that much risk, the latter to enable the role to drive change.

CISOs are starting to report to the board. The biggest challenge is budget. It's hard to put an ROI on a theoretical risk that chances of risk happening are at best an educated guess. Most company leaders don't value detection of breach but only prevention so things like the significant cost of storing network flow logs is an uphill battle.

Re: I quit infosec and I couldn't be happier

#89

Earlier quoted context omitted.

> Never be a CISO Can you share why?

Average tenure for a CISO is lowest of any C suite. You will likely take the hit in the event of a security incident and be fired. Tedious work. What to do is often obvious. Getting everyone to do it is the hard part and usually devolves into politics. Thankless job, you can only be wrong once. Just not appealing and CISO is becoming legally sketchy, requiring a lot of diligence out of a CISO to not end up in legal t…

> Average tenure for a CISO is lowest of any C suite.

Do you have any stats to support this statement? I work as a Information Security Officer, other firms have BISOs or other names for this kind of position.

Additionally, a lot of what you are describing is either cliché ("you can only be wrong once"), only true for certain types of businesses or regions. There have been examples where CISOs have experienced legal pain in the US, see Uber's former CISO. But I would not expect companies to see this as an exemplary case.

Re: I quit infosec and I couldn't be happier

#90
post #6

I'm probably oversummarizing, but this seems to boil down to burnout caused by (from the post): > But why don’t they just patch? It’s not that complicated after all. And you kinda see this later on when the author talks about what they worked on post-transition out of infosec as a mainline career: > I finally joined Michelin in December 2016 where I started working in the CERT team where my main mission was to automa…

Thanks for your reply, I liked it!

> It seems like the author burned out not because of the work but because wherever he ended up

Don't get me wrong and maybe I was not clear enough (my bad). The infosec part I mostly contributed to was within some consulting companies where I was hopping from one assignment to another one, having different clients every week. I saw some clients with some really strong security posture, I mean it. The "burn out" I experienced was clearly not related to that but pretty much from hacking, writing report, sleep & repeat.

Post reply on HN