5 ms·
> pentesting is a low status specialization Depends so much. But yes, the good old "compliance checkers" who run a couple of scripts and call them self pen tes
by borumpilot 7y ago
> pentesting is a low status specialization
Depends so much. But yes, the good old "compliance checkers" who run a couple of scripts and call them self pen tester are very low on the lader. These are the majority nowadays.
People who can actually penetrate stuff "by hand" are considered sexy alright.
- souprock 7y agoPeople who can actually penetrate stuff "by hand" do exist, and I'm one of them, but how many of us work for pentesting companies? I don't think the money is there, mostly, because clients are wary of buying snake oil and because clients don't actually need real live vulnerability exploits. The pentesting clients just need to close holes, or at least satisfy an insurance company that they did so. Pentesting clients want to certify compliance. I put a "by hand" job posting in the "Who Is Hiring?" thread. Here: https://news.ycombinator.com/item?id=19543995 https://news.ycombinator.com/item?id=19543995 It isn't anything I'd call pentesting. We study software, not specific installations of software.