Live data from Hacker News

Shared thoughts after 6 years in Pentesting

0x00sec.org

1–10 of 97 posts

Re: Shared thoughts after 6 years in Pentesting

#3
1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too.

2. Don't get certificates. If you meet a prospective employer who seems intensely interested in them, that's a red flag about that job.

3. The idea that you should aspire to being able to do your whole job from a Linux terminal is pretty silly. Use what works for you.

Maybe it takes more than 6 years in offensive security to realize this, but the #1 bit of advice for this field is: learn to enjoy coding. The worst possible place to end up in security is as a captive to available tooling.

Re: Shared thoughts after 6 years in Pentesting

#4
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I noticed number 3 in an internship I did in a security company. It was what pushed me towards a career in software engineering instead of security, because I was much more into it than most others were, many really weren't that interested in it.

Re: Shared thoughts after 6 years in Pentesting

#5
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

[deleted]

Re: Shared thoughts after 6 years in Pentesting

#6
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I agree with you.

Here are some of my thoughts at 15 years:

1. Get sleep and exercise. Stop drinking soda, just stop it. Drink water, coffee, tea, and scotch.

1a. During undergrad, I would get into a trap where I would think I was too busy with schoolwork some night to exercise. Later, I changed my thinking and realized I was too busy to NOT exercise. My grades improved.

2. Work 40 hours a week. Don't be a hero. You're going to burn out.

3. Keep your mind open, but don't accept what others say uncritically. Investigate and evaluate all new information, time permitting. Don't think you know everything, also, don't think anyone else does either.

4. Be a good programmer.

5. Learn some advanced mathematics and cryptography. Don't listen to the people that say "I've never had to use that." Learn about something until you're unsure and uncomfortable- like exercising until you feel it, that means you're learning something.

6. Make your resume more about stories you can tell and less about tools you can use.

Re: Shared thoughts after 6 years in Pentesting

#7
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits.

I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any experience, even non-pentesting, would probably trump it though.

Re: Shared thoughts after 6 years in Pentesting

#8
post #7
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits. I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any exp…

If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification.

Avoid certification.

Re: Shared thoughts after 6 years in Pentesting

#9
post #3

1. You definitely do not need to make security part of your "lifestyle", much less spend 80 hours a week working at it. The irony is that the author is a netpen person, which is sort of infamously the least demanding specialty in offensive security. If people writing browser drive-by exploits can stay on top of their game with a 40 hour work-week, I think the netpen people can too. 2. Don't get certificates. If you m…

I'm currently doing a PhD in electrical engineering. I've just finished my first year, and I'm starting to realize that the work I'm putting in to research projects isn't being appreciated monetarily. In other words, I feel like my time is worth more.

I like to think of myself as a decent programmer, but I'm not well versed in software security (more of a hardware person). I've also never had a full-time job as I jumped straight from my BS to a PhD.

I'm considering taking some security-related courses next year and getting my MS. I have two options after that: 1) look for summer internships in the field of software security and see if I like it, or 2) look for full-time positions and withdraw from the program temporarily to test out the waters. The issue with 1) is that there are less intern positions available, at least based on what I've seen.

Am I approaching this correctly, or is there something else I could do? Any advice is appreciated!

Re: Shared thoughts after 6 years in Pentesting

#10
We just had some consultants do pentesting on our medical device and its software components. I was pretty impressed by all the problems they found quickly. As developer I find it pretty hard to stay up-to-date with all the possible ways hackers can get into your systems.

To me this was money well spent.

Post reply on HN