How a 22-Year-Old Discovered Meltdown and Spectre
bloomberg.com
bloomberg.com
Cybersecurity requires a level of expertise that is unexpected of a 22 year old.
Even if we imagine that 22 year olds are just as capable as 32 year olds, his young age would be statistically remarkable - considering the number of people over 22 working in cybersecurity, against the number of people under 22.
They might be as capable but 32 year olds have a 10-year head-start of academic and industry experience to from where to draw. Achieving something that others with all that additional academic and professional experience haven't is a huge feat.
I'm not sure if it's because we have a general perception that youth is when you should learn a thing, you then get a bit older and get good at it, then get a bit older and do great things with that ability, then sort of forget it all and be too old to be useful.
Also the older you are the more time you have had to discover something. Even if it's just by random luck you would have just had more time for it to happen.
Reminds me of the TV news, where any time a number is mentioned, they emphasize the hell out of it like I'm supposed to be amazed!!!!! Do they train 'em in journalism school to do that?
Here I see a story of how someone with at least the minimum level of interest and thinking skills goes and RTFM, then thinks about how to exploit this one design feature (a decision essentially made once per chip design, not a beeeellion times), and finally through experimentation and persistence figures out how to do it.
Maybe that's why he was the first to find it. He was looking where nobody else had thought to look, and he just so happened to have the combination of knowledge and resources (edit: and talent) to find a flaw there.
He had found security glitches in his school's computers network as a kid. Also, he was hired by a security research firm while he was still an undergrad.
In addition to knowledge and resources, he also had the knack.
In college (1997? I was 17) I downloaded the source code of the unix client for back orifice. I read some of the source because I was interested in socket programming and reading Unix Network Programming. I compiled it, and deleted it without running it.
They were on edge because "god" from high school called to warn them about me.
Why cant you just be happy for the kid?
Some people are just plain better than you. And its OKAY. Most of us here are average, and will probably never see our own success story published like this. Kid has done and contributed so much at a young age. He's clearly way above average, judging from the reaction of his peers in the netsec community. His skills has benefited us all. His achievement should be celebrated, not met with bitterness.
Anyone who was at RWC2018 who can tell us what this item was? Presumably it's too technical for bloomberg's readership and not secret.