31 ms·
I quit infosec and I couldn't be happier
- unixhero 4y agoThis is about developer burnout, and doesn't really point to anything in particular regarding infosec.
- jrumbut 4y agoI don't think it was meant to be an "infosec is wrong and I'm right so I'm leaving" type story. I like that the author wasn't afraid to make a change, not everyone can but it makes for an interesting story!
- gtirloni 4y agoIt's a nice story. The author discovered he's passionate about people. Did a lot of thinking and seems happier now. I don't think it speaks badly about the pentesting part of infosec, even though those in auditing tell me it's extremely boring to be in infosec.
- unixhero 4y agoSure. But the title insinuated an analysis of how information security causes one unending stress, day after 20 years if working in it one develops a hardened siege mentality etc etc etc. I have read things like that befire, which were interesting perspectives That would be more on point with the title. Anyways nothing wrong with the text, but my comment stands.
- P_I_Staker 4y agoYour comment should kneel before the reasoning of his argument.
- unixhero 4y agoThat's okay. I didn't read it.
- yootyootr 4y agoBy default when I click the link I'm directed to a non-secure HTTP version of github, which I found ironic given the page title
- cojant 4y agoI was about to comment on the same... my only question to the OP (and other's who don't enforce HTTPS) is "why?!"
- mcsniff 4y agoWhy does a personal blog page need HTTPS? It's an output page, I read the contents and leave, I'm never submitting any of my information across the wire. Someone along the way might modify the page? Unless they're using HSTS, it won't matter. I'm all for encryption, but I'm also all for using tools when necessary, and not complicating things when not.
- iamjkt 4y agotroyhunt answers this very question: https://www.troyhunt.com/heres-why-your-static-website-needs-https/ https://www.troyhunt.com/heres-why-your-static-website-needs...
- yamtaddle 4y agoIt's an answer, but I still find it entirely unconvincing for a static personal blog. Better? Sure. Necessary? Damning if it's absent? No.
- fmajid 4y agoYou'd be surprised how many top websites (e.g. Amazon, eBay) don't even implement HSTS, let alone HSTS Preload. Here's some naming-and-shaming: https://blog.majid.info/hsts-preload/ https://blog.majid.info/hsts-preload/
- 4y ago
- hsnewman 4y agoI was a CISO for a Credit Union, and retired early. Couldn't be happier now, I would never go back to infosec. The stress and anxiety was terrible. Infosec is a target for management if there is a breach, fortunately for me I never had an incident, though. After 3 years my mental state is so much better, I highly recommend retiring/switching carreers if your unhappy in your job.
- 1970-01-01 4y agoCISOs that have experienced a breach are worth more than ones that have not. https://blog.nacdonline.org/posts/cisos-breach-experience-preferred https://blog.nacdonline.org/posts/cisos-breach-experience-pr...
- adamgordonbell 4y agoGot to be honest, I only clicked on the link because 'quitted' bothered me, but the Take-Aways are interesting.
- cuttysnark 4y agoStuck out to me as well—author uses it only once apart from the title, and it's in scare quotes. Are they calling attention to the fact that it's not the usual form of the word, but then failing to explain why that's important to the subject of the post? In any case, TIL that although "quit" is most common for past tense/past participle, "quitted" is sometimes included in dictionaries as an alternative.
- Mikushi 4y agoThe author is French, the usage of quitted is more likely a mistake outright. As for the quoted version it's explained next to it, he's quitting professionally but likely will continue as a hobby, in French you'd use quotes to highlight the fact it's not to be taken literally.
- PaulSec 4y agoOP here, that is correct and I am french, I thought that it was right actually. what should have been the proper way to say I left that industry?
- bdsa 4y ago> I quit infosec...
- cuttysnark 4y ago"I quit infosec and I couldn't be happier" is how I'd have written it. Thanks for the good-read!
- dang 4y ago
- eganist 4y agoI'm probably oversummarizing, but this seems to boil down to burnout caused by (from the post): > But why don’t they just patch? It’s not that complicated after all. And you kinda see this later on when the author talks about what they worked on post-transition out of infosec as a mainline career: > I finally joined Michelin in December 2016 where I started working in the CERT team where my main mission was to automate scanning and reconnaissance phases [emphasis added] on internet-facing assets and this was my real first experience on the other side of the story - defending infrastructure and where I finally experienced change management (and the complexity behind it), impact evaluation and so on. It seems like the author burned out not because of the work but because wherever he ended up, there was no strategic initiative to streamline and automate patching to a point where it's largely invisible. It's also a hard problem given the risks of patching bringing reliant services down and the need to automate a slew of testing to validate that said patches won't torpedo production and mission critical systems. The bit above is important not just because it solves a problem but because (I'm convinced that) people like knowing they actually built something and enacted lasting change. And security may be one of the least likely engineering disciplines where you'll experience building a tangible product as an IC. At least in software security it's a bit easier with build and deployment pipelines offering an opportunity to block when patches are outstanding, but I can see where the burnout would arise when a strategic effort to invisibly ensure patching isn't in place or well funded. No one gets to build anything, and likewise, nothing gets solved because nothing was built. --- So if I could add another takeaway: • if your job involves running around and putting out fires, consider recommending up the chain and across the aisle all the ways to prevent the fires. And if those recommendations don't catch fire (so to speak), may be worth exploring alternative means to address the burnout risk long term with the current role.
- PaulSec 4y agoThanks for your reply, I liked it! > It seems like the author burned out not because of the work but because wherever he ended up Don't get me wrong and maybe I was not clear enough (my bad). The infosec part I mostly contributed to was within some consulting companies where I was hopping from one assignment to another one, having different clients every week. I saw some clients with some really strong security posture, I mean it. The "burn out" I experienced was clearly not related to that but pretty much from hacking, writing report, sleep & repeat.
- itsmemattchung 4y ago> The main warning I might just give to people is to keep proper distances between work and personal life I've been thinking about this a lot lately. As a millennial, I've tied so much my self-worth into my career and recently, started questioning this belief and I think the next generation (i.e. Gen Z) might be on to something around quiet quitting, their generation placing extra emphasis on pursuing things that make them happy and viewing work as .... well, work.
- flerchin 4y agoLOL welcome to your thirties. Try to lean more towards the weird new hobby side of things, instead of the 20yo girlfriend side.
- swader999 4y agoSage advice.
- jraph 4y agoMillennial too. Thought for thoughts then! For me, paid work is a means to achieve what I personally want to achieve. If I can achieve what I want during work hours that's great, stars are aligned. If not, work is just a way of getting the money I need to achieve what I want, and should never drain me. I don't care about career, I care about being paid enough to do what I want to do of my life. I won't sacrifice personal life for it. Work is a good chunk of the time so it should also be enjoyable as best as possible. Of course, advancing your carrier can help get paid even more / enjoy even better, if so it might be good thing to do. It's just that it's a means, not a goal, like it seemed to be for some of our parents or grand parents.
- komali2 4y agoMillennial here as well, it's really excited to see our generation and the next generation reject "making money for someone else" as a way of finding meaning in life. I'm chewing on a lot of blog posts about this, regarding for example how the concept of "retirement" is terrifying. I was on a cruise recently and talking with a bunch of old people, and the subject often came up about how people were "finally taking the trips they always wanted to," or "finally exploring xyz hobby they never had time for." How terrifying is that, busting ass from your 20s to mid to late 50s, and then getting hopefully another 30 years to "enjoy life?" I mean I'm sure many people find enjoyment along the way but damn that just seems so depressing. Maybe it wasn't bad when that generation was working, I know many had a very nice quality of life for relatively less effort due to higher purchasing power and lower housing costs.
- bitexploder 4y agoI have been an information security consultant for a long time. Software dev background. 2006 start app sec consulting -> senior consultant —> principal consultant -> CTO (of small consulting firm) -> get bought by NCC start my own company 10 yrs ago -> CTO/managing principal -> sell company -> still consulting. Done so many different things but the common theme is app sec. Finding bugs and risks in software via reversing, assessment, threat modeling, and code review. Do I still love it after 17 years? no. A lot has changed. A lot has not. I still like it most days. By far my favorite thing has been building a team and teaching others what I learned. I hit burn out here and there. I think computers and tech are different and objectively a little less fun now for this field. When I started I could find a bug in a system and write an actual exploit (actual machine code!) for it by hand in a reasonable time scale and that was always really cool. Now teams of people are required to achieve the same exact goal. Just one of many examples. So anyway, some get off my lawn cause I am older now, some is just me changing what I like and want from life, some is tech changes. It’s still a great field as a consultant. Show up. Hack. Write report. Leave. Never be a CISO, you can’t pay me enough to do it. The end.
- toomuchtodo 4y ago> Never be a CISO Can you share why?
- fegu 4y agoI am a CISO, but transitioning away. It is just plain boring. Lots of admin, reports, reviews, very little actual IT.
- deleted 4y ago[deleted]
- eganist 4y agoFrom what I've heard from other CISOs: You own a bunch of unsolvable risk and your head is one of the first to get lopped off if you're popped. Honestly, the CISO role probably needs a golden parachute and a direct report to the CEO for it to be an appealing path for most anyone who's experienced it at least once. The former to incentivize owning that much risk, the latter to enable the role to drive change.
- throwawaaarrgh 4y agoThis really resonates with me. I'm also passionate, and most corporate gigs I've had over 20 years kill my soul. I wish there was a place I could use my skills where they weren't wasted, where I could perform at the top of my game and really make incredible things happen. The reality is I spend 90% of my time trying to work around some stupid bureaucratic limitation, and it's not uncommon for my work to be literally thrown away after months or years of work.
- 4RealFreedom 4y agoI've been in this position a few times throughout my career. Try looking around and see what else is out there. Maybe consider a smaller company that doesn't have the level of politics that you've described. Wish you the best!
- Clubber 4y agoI recommend smaller companies were you take an architect type role where you build the systems, or at least have a domain you control and are accountable for. I've been doing exclusively that since about 2005. It has it's own problems, mainly pressure to constantly get things done, which is fine, but it can be unrelenting sometimes. The soul sucking large corporate entities, I couldn't agree more. Stay away from that if you can. You really only need one big company household name to spice up your resume and you probably have that already. I have mine and never went back.
- mxuribe 4y ago> I recommend smaller companies... Yep, this is the direction i wish to take next. ;-)
- mxuribe 4y agoOMG, its like you're speaking right to me! :-) I have a multi-decade career, and for like the first decade or decade and a half or so, i tried to stay as long as reasonably possible at whatever big compoany i worked for....being raised to think that loyalty, and working a long number of years at the same employer was a sort of weird badge of honor. I got hit by bureacratic BS/blocks on such a constant basis, and then got hit by my first layoff...then i thought: "oh man, its me, i'm the problem, maybe i'm not as good as i thought, etc." Then I got yet another corporate job....and then another layoff...which by the way both layoffs were to due to re-orgs, and impoacted many people, and not specific to my performance. But, you know, the ego and heart gets hit hard. So, i tried 1 year (during the middle of the pandemic) to work for a non-profit...thinking that maybe i can use my passion and people and tech skills for some good causes...Nope, never again! The sample size is of course so small (I only worked for a single non-profit), but i encountered the same corporate blocks as in the for-profit world, but with a vastly reduced paycheck. I still love my peers in the non-profiut, and while i was there i actually made a difference in thousands of people's lives, as well as gaining accoloades from IRS for a model and taxpayer experidnc e that i developed foir some web potals that i lead the dev. for. And, i still very much believe in what the non-profit where i worked does...But wow was the org. crazy disfunctional! Anyway, over the last couple of years since then, i keep jumping from one big company to another....and after all these decades i feel i have more passion than ever before for the tech and the problem spaces! ...BUT...now i have less patience for corporate buracratic BS/blocks...so i jump more often nowadays; which i dont like doing. Maybe i will try small, for-profit firms and see how things go....but, man, corporations really do know how to hamper those among us who have the passion, drive, and technical chops to really make a difference. Passion and competency - at least at the big boys/girls where i worked - seem to count for nothing nowadays.
- icedchai 4y agoThe truth is, a lot of this work is drudgery. You either get used to it or find something else to do.
- hgsgm 4y agos/this// When you get older you lose the fun of learning new stuff, and you are paid to do what to know.
- ceva 4y agoFunny thing is i was mentioning milw0rm this morning to a colleague and remembering the old days when astalavista was a thing :) nice story thanks for sharing!
- 4RealFreedom 4y agoI read astalavista and thought you meant AltaVista. After rereading, I'm not sure.
- gtirloni 4y agoastalavista was the security search engine (or portal-like website). AltaVista was a Google competitor, IIRC.
- another2another 4y agoAltaVista was the search engine of the internet, way before Google. Developed by Digital to showcase the power of their CPU the DEC Alpha IIRC...
- 4RealFreedom 4y agoI never knew about astalavista. Thanks for sharing!
- quacked 4y agoIf you're looking to avoid burnout, it helps to think of your profession as something entirely separately from your identity. I'm not an "aerospace engineer" or a "project manager", I am merely a man who plies the trades of engineering and project management during the day. That's the service I provide to society in exchange for food, fuel, land, tools, weapons, medicine, textiles, etc. (I don't think it's a fair trade but that's out of the scope of this discussion.) The parts of life that I actually consider meaningful parts of my identity occur outside of work and mostly revolve around my family, friends, religion, storytelling, and art. This may kind of seem tautological, but I think adding the extra degree of mental separation (I am a man/woman who practices X profession vs. I am X profession) can help clear your head and open new life avenues to you. If you spend 8 years grinding for a graduate degree and enter into an obscenely competitive job market and find little success, it's easy to feel claustrophobic and like you've failed if you take a job outside your field. However if you think "for 8 years I performed statistics, writing, lecturing, and reading, and now in order to make my fortune I'll try another trade" you feel feel less indebted to your past self and make more clearheaded decisions about what to do in life.
- DeathArrow 4y agoI work to provide food for my children and me. I am not my work. Even if I like development, I do more interesting types of development outside of my job.
- roguesupport 4y ago[flagged]
- hoosieree 4y agoIf your prone to loose you're temper over minor linguistic gaffes, supposably the best advise is too just kick back and have an expresso.
- Tepix 4y agoHey, you're not french so it's espresso for you ;-)
- bthrn 4y agoThe author is French. I'd be curious to see if you could write something in a second language well enough such that the only criticism a native speaker had was your use of a technically valid, but uncommon word.
- jjulius 4y agoI hope that the rest of your day goes well and that you find at least a moment of peace.
- deleted 4y ago[deleted]
- pizzaknife 4y agomy friends, consider only working 4days a week, 6hrs a day, and your profession not defining you, your value nor your ego. Its not a simple matter but worth the effort. Full disclosure i struggle w self value statement constantly still
- tiffanyh 4y agoSome general (unsolicited) advice ... for whatever field you're interested in - go work for a company that sells that as a service. E.g., - Don't be an internal company accountant, go work for Big 4 accounting firm to sell your skills - Don't be in internal company IT Security, go work for a company who sells that skill It's all about moving up in the value chain. By moving up in the value chain, you're more "valued" / appreciated / sought after. You're general happiness will be much better as a result, and you'll also make much more money.
- DebtDeflation 4y agoYes. You always want to be part of a profit center, where (directly or indirectly) there is revenue associated with what you do, rather than being part of a cost center where you are just an expense for the company.
- dreamcompiler 4y agoLikewise if you work for a company that sells a security product you're in a profit center, which is good. What's bad is that those sales are extremely difficult to make because what your company is selling is avoidance of loss which is much harder to sell than a product that increases revenue. This is more true if you're a small startup selling a security product. It's less true if you're one of the top 5 companies in the field.
- DeathArrow 4y agoHow would that work for a developer?
- RugnirViking 4y agowork for a company where you are developing the comapny's main product, and where the product can be substantially improved by further development. For example, working to develop a website for a supermarket chain, or an app for dominoes pizza, will always have a limit and little respect
- sasas 4y ago> Taking your passion and making it your day work is obviously tempting but also a risky game, as you will keep “working” tirelessly if you’re not putting barrier Risky game indeed. It’s 1:24am here in Australia and I’ve finally stopped attempting to reverse a network protocol for an embedded device which I’m pentesting. Reading the article is a good reminder of what can happen if you push it too far. The challenge is with this type of work you often have to put in the hours, particularly if it’s a hard target.. If you lack the passion and drive you simply just won’t retain and develop the skills required to deliver. If seasoned pentesters disagree, then I’m all ears.
- jordanmorgan10 4y agoDoes anyone else wonder what their life might have been if you had never gotten into tech? I sometimes think I may be happier, but certainly less wealthy. My free time would probably be just that, free time - instead of having the relentless drive I have to do another app, blog post, etc. On the other hand - the "hustle" economy is everywhere now, not just tech. Everyone has a side gig, and the grass isn't always greener. So, who knows. Great post and best of luck in management.
- _2uwr 4y agoI do, knowing the physical and mental harm of being stuck in front of a computer for most of my life, believe it or not but being sat in a chair for extended periods of time is considered a stress position, and not getting the fun exercise to keep you body fit, bugs me a lot as my health declines and the so called experts ie doctors dont know enough and they are risk averse conformists.
- swader999 4y agoMost non technical white collar sit in front of a computer all day too. Trades like electrical, plumbing, mechanic etc wear out their bodies. Other jobs that emphasize relationships like sales is something I wonder if might have been a better path. In your old age you have a nice rolodex to market yourself with instead of a decaying skill set that gets more difficult to refresh as you age.
- DeathArrow 4y agoWhen I was 18-20 I was also passionate about infosec. But I liked development more and infosec didn't seem at that time a domain that is very easy to find employment and gain money.
- saagarjha 4y agoYou can find a role as a software engineer with a security focus.
- justin_oaks 4y agoI haven't see a lot of job postings for those. It's either a dedicated security professional, or a software engineer. I once worked for company making a security product. The other software engineers knew almost nothing about security or secure coding practices. It was never a requirement for the company to hire people with security skills, nor did security skills even get taught! I tend to think that's the norm in the industry, but I'd be happy to be proven wrong.
- saagarjha 4y agoI have one of those jobs, which is why I brought it up :P I am a software engineer and provide security direction to a team of "pure" software engineers (who are slowly getting better at security). Sometimes I help them with the implementation of things. Other security adjacent roles can be found in areas like web browsers, compilers, and kernels; there's a massive amount of software engineering work that goes into securing existing systems that goes beyond trying to break things. Most large companies will have many people working in such roles.
- bayesian_horse 4y agoI had watched a few courses on information security and noticed that those working in the more management / corporate related infosec roles seemed to be massively overweight, almost all of them (I am too, btw). Not saying that to shame anyone, just: Does the job make you miserable or stressed out? I have been forced to do the infosec role as a "side thing" in a couple of jobs now, mainly because nobody else was around that even had the basic skills. One of the things that discouraged me from going further in that field is that it doesn't seem to make people all that happy and fulfilled. Again, I may be wrong on that, as an outsider looking in.
- conorcleary 4y agoYou're always, always going to be playing catch-up with criminals. It's a defense-only game. It's also like the scenario that caused the development of police radar detector-detectors, etc.
- debacle 4y agoSecurity is always a cost. It's never a benefit until after someone has already been hacked, and you're the cleanup crew/IT oncologist. I decided 10 years ago to never work in a role/company where my job didn't contribute to the bottom line. It's much more satisfying.
- mango7283 4y agoI was a lot happier when I was working for a security tool vendor than I am now working in itsec on the customer side...
- bell-cot 4y agoOh, yes. Infosec has all the downsides of being an ER/ICU nurse at a miserably understaffed hospital, with ~none of the upsides of saving people or genuine patient/family gratitude.
- mango7283 4y agoHaha you said it...
- SadWebDeveloper 4y agoI have said it before and still say... InfoSec is a glorified policy writer. You spent more time 90% of the time "writing documentation" rather than on finding the security problem and suggesting the fix. That's why i choose development rather than InfoSec (despite having a knack for it), because its more technical and i don't need to explain "why" everytime.
- _tk_ 4y agoI think you are mistaken. Obviously InfoSec is a rather generalising term, while you are abstractly describing the work of someone that works in Application Security.
- SadWebDeveloper 4y agoI would rephrase the question... what InfoSec jobs doesn't involve spending writing documentation? pentesting? 20% finding the low hanging fruit, 80% writing and explaining your findings. forensics? 10% finding how they did it, 90% writing and explaining your findings. malware/policy/security/cloud security analyst? 100% writing and explaining your findings. the list goes on and on... you are basically and a slave for word processing software, thats why totally understand OP quitting infosec.
- deleted 4y ago[deleted]
- supertrope 4y agoThe best security tools and practices won't protect the business if they're not used consistently. Policy is how things get done. It's an expression of the business' values and priorities. Even if it's just "all employees must install the authenticator app or request a Yubikey otherwise the cyberinsurance will drop us."
- mellosouls 4y agoFor anybody tempted to skim or not read the article, the title [ps. "quit" is a bit less awkward - imo, natch :) ] is a bit misleading; the main takeaway at the end is the rather more positive: Looking back, working in infosec was such a great experience and I recommend it to anyone who wants to jump in! The reflections generally about knowing when to move on are more field-agnostic.
- _tk_ 4y agoI have been working in infosec for 10 years now. I know this author doesn't want to convince anyone, and I am happy that they are happy. :) But I am kinda wondering why this brings so much attention? To me this reads like a long trip down memory lane. Is your takeaway: "if your job and your hobby are too similar, then this will lead to burnout?" Or is it "a job in infosec will lead to burnout, because infosec has certain inherent problems?"
- recrudesce 4y agoI think it's mostly that the echo chamber that is the Infosec world gets tiring after a while. Let's just shout "ffs, just patch yo' shit" rather than actually trying to educate people. Let's all go to a hacking convention, and act like children and hack everything within arms reach at all times. Let's all belittle people who don't have the same level of technical skill as us. Let's all be arseholes to women in the field. etc etc. that's why I took a step back, because for all the "we want to help you fix things to make the world a more secure place", the infosec industry seems to not want to help make it happen.
- localplume 4y ago[dead]
- PeterStuer 4y ago"Quitted", srsly? Yeah, blow my karma idk
- owlglass 4y agoEven if English is the lingua franca of the world, people master it to varying degrees. Also, it seems like 'quitted' was the more common form up until the ~late 1930s [1], so it's not entirely unreasonable to assume that, if this person learned with some vintage material or they read classics, they've seen 'quitted' more often. [1] https://books.google.com/ngrams/graph?content=had+quitted%2Chad+quit&year_start=1800&year_end=2000&corpus=0&smoothing=3 https://books.google.com/ngrams/graph?content=had+quitted%2C...
- _8j50 4y ago@PaulSec, Why didn't you move to blue team side of things? It may have been more enjoyable catching actual threat actors and learning the latesr tech/platform/attack sp you can defend against it. Glad it worked out for you though. I almost can't imagine not working in infosec, it might feel like losing a limb I think. It's not the assembly, exploits,etc... that does it for me but how I am never bored and always learning something new. The feeling when you find a compromise by sophisticated actor or even stop a compromise in progress, even if no one ever hears about it is amazing. I did networking and other types of jobs that were great too but eventually you master those more or less and start to get bored. I suspect pentesting is similar in that you learn new techniques all the time but the vulns you find are still the same stuff more or less? I have no idea, just guessing. I guess what I am trying to say is how rare it is to find someone with passion for infosec that applies themselves and how broad the industry is (maybe you might enjoy being an instructor or manager?) and how any job in infosec would love to have you because of your background.
- anuraaga 4y ago[flagged]