4 ms·
Isn't the whole "security industry" a prank gone bad?
by jpr 16y ago
Isn't the whole "security industry" a prank gone bad?
- JoachimSchipper 16y agoNot everything is useless. Code auditing is not necessarily useless; looking at the physical security of smart cards is not necessarily useless (but it looks like they could use some tougher certifications); pentesting/social engineering can have its uses. That said, "security appliances" and other magical solutions tend to be rather imperfect. tptacek (of http://insecure.org/stf/secnet_ids/secnet_ids.pdf http://insecure.org/stf/secnet_ids/secnet_ids.pdf) may have something to say about that, too.
- ryan-allen 16y agoEveryone I've met who's been working in the "IT Security Industry" have been exceptionally coy about what they test for and how. After a few drinks I've managed to get out that they're testing for "XSS, and SQL injection, you know things like that". It stinks of proprietary crap and I wonder what it would look like if they took a more OSS approach? When you can't even talk about XSS testing without a bit of prodding as if it's something exceptional it really makes me wonder what on earth these guys are selling.
- JoachimSchipper 16y agoI've never done anything with them, but e.g. http://www.rootlabs.com/engineer-job.html http://www.rootlabs.com/engineer-job.html sounded a lot more interesting than what you describe. On the open-source front, you find stuff like Metasploit, nmap, Snort, previously Nessus (forked as OpenVAS), web stuff like Nikto, etc. Don't forget that lots of "programmers" are barely-skilled and working on VBA macros - one label can cover a wide range of skill.
- maigret 16y agoI've met some guys who were pretty fit in encryption topics / key management etc on whole corporations. And it actually works, so you rarely hear about that. Quite some skills are needed to master that actually.
- tptacek 16y agoThere are a whole lot of charlatans in the field. Certifications and credentials are often a good tip-off.