None of them know what they're talking about. Source: my direct experience
None of them know what they're talking about. Source: my direct experience
You can't go into business selling software on the assumption you'll sell a single copy and your work is finished. Infosec is no different. There is always this paradoxical need to ensure you never become entirely redundant, regardless of the function you specialize in
I think a lot of the great "evolutionary difficulties" in our industry can be phrased this way. It's why things like Microsoft Excel are laughed at even as hundreds of thousands are trained in the art of constructing effectively bespoke spreadsheets apps in Django by the million every year. I hope for a correction some day, just as much as I hope I'm on the right side of it when it comes..
It's all bullshit, and these people are pure scum.
> because 98% of us are completely clueless
Do universities/bootcamps teach OWASP-style classes of programming vulnerabilities these days? Some developers are curious enough to learn them on their own, but many are oblivious.
I suspect there could be a startup idea here somewhere.
> absolutely not thinking about this stuff as we're trying to clear a sprint board
Does anyone have a decent tool/process for remembering all of the detailed tasks for every type of software deliverable? I find myself in a state of cognitive coma after sprint planning when I need to divide tasks into subtasks.
(Crypto and security in general were a hobby of mine until I realized how difficult the field really is. "Programming Satan's computer" was one paper that contributed to that.)
I had exactly one course that touched on security.
A course in web programming.
The instruction we received consisted of: "If your project is not secure, it will lose points."
I'm not sure a single person on that class had one point taken off for getting security wrong.
Why would a university care about educating people in something ephemeral, and domain-specific, like security, when it could instead be teaching them about complexity theory and Djikstra, and third normal form?
The real problem is that there is a vast need for professionals and the lack of them calls a lot of smoke-sellers. And for a lot of people is hard to tell wether they are legit.
Just look at the Machine Learning / Artificial Intelligence industry. Also "fraudulent" if you apply the same logic.
And yeah, most of the ML industry is in precisely the same category. A bunch of frauds.
You'd be surprised just how many places run public unpatched stuff with admin/root holes here and there. Ive seen passwords like "123456" and "password" and plenty other badness that nobody really bats an eye to.
And even simple things like "Use WPA2 and a password manager", for low barrier infosec is routinely ignored. Companies can barely even manage that.... and they have the funds.
And it's not like the bad stuff is scare quotes. Ransomware is a thing. Ive seen a hospital network up north get hit by it. City of Madison IN (1h away from me) ended up paying a large sum, cause they thought backups were pointless. Even know of a story where a state government's machine ended up being a warez server. The lead though to clean up a trojaned linux box, was to rsync from a clean one. Left most of the trojan kmods intact. I caught it down the line.
Sure, if the likes you're talking about is complaints about IBM with QScan or similar, with grandiose claims that their software will save everything - thats obvious bullshit. Security is definitely a process and procedures, ALONG WITH technical means to facilitate that. Even automated scanning of "front doors", or doing routine searches in Shodan is a magnitude better than nothing.