5 ms·
I’ve noticed that majority of people working in “cyber security” are made of management material. Even those working on technical side of things. I’ve seen them
by honkler 4y ago
I’ve noticed that majority of people working in “cyber security” are made of management material. Even those working on technical side of things. I’ve seen them spend all day on Twitter. You have to wonder if they ever get time for actually working on their stuff. As opposed to kernel devs, but they are likely assholes more than anyone else so not a fan of them.
- insanitybit 4y agoAs someone who has spent a career in infosec, I've seen the opposite. Infosec has far more counter culture remaining than software dev (I have worked both roles - currently I'm employed as a Software Engineer). What infosec has much more of is sales people. There's just a huge market trying to solve a tough problem. So from an outside perspective maybe you see a lot of bullshit but it's a highly technical field. Really, I only learned to be a software dev to up my infosec game, I find infosec to be a far more challenging and interesting field.
- honkler 4y agoI know a few full-time infosec professors who spend a ton of time on twitter. You would expect these people to lead path-breaking research in their fields, but all they do is share memes about infosec, and ofcourse a few papers a year written mainly by their grad students. But maybe they too are salesmen types. Marketing their services to midwit management people on twitter. I include politicians in this too. Hurr durr china is going to defeat us in "cyber space" opens up a lot of business opportunities for government contractors. No one care about compilers, or operating systems the same way.
- insanitybit 4y agoIDK maybe my bar is just so low across the board that I don't notice the difference anymore. Devs seem just as bad to me - they don't know shit about compilers or OS either lol As for Twitter, that has to do with infosec having trouble communicating and a bunch of other stuff. I started to explain and it's not really worth getting into. Twitter was really important to infosec communication.
- rychco 4y agoI can agree with this, though I’m presumably (based on the language) earlier into my career. The deeply technical parts & the counter culture found in reversing forums & places like DEFCON are still thriving & always awesome. However, it’s also full of bullshit & marketing that want to convince you that every little technical detail is a vector for a potential cyberattack! You don’t want to be the next business suffering from ransomware gangs, do you? Better purchase our advanced endpoint detection powered by AI/“Neural Networks”, and don’t forget your automated security scanning designed with ChatGPT and quantum encrypted database backups to stop the Chinese/Russian state actors/hackers in their tracks!
- insanitybit 4y agoI only mean to say that the counter culture is there relative to software devs. It's depressing how far from its roots infosec has made it. BlackHat is a great example - it's a fed conference. In terms of the explosion in products, sure. But that doesn't apply to the technical people. There are lots of problems because there's a large market solving a complex problem. If you're actually talking to technical people they can be of a pretty high calibur.
- honkler 4y agoThis could be because product development is much more quantifiable, while infosec is not. This means the grift can continue for a long time, before an actual ransomware incident happens and the team gets fired. Afterall many of the recent companies that were hacked had contracts with cyber defense firms, but they were just too busy posting memes on social media. Side note: you should read my other comment on this thread.
- cbsmith 4y agoI mean, there's a case to be made that security is at least as much a problem you manage as a problem you "solve" with products/tools. You'd want a lot of people with strong management skills.