Anyone who's read more than a few write ups of exploit chains wouldn't post something this ignorant. I'm not sure how to interpret this whole post in good faith unless it's satire.
Just go read some posts off project zero.
Anyone who's read more than a few write ups of exploit chains wouldn't post something this ignorant. I'm not sure how to interpret this whole post in good faith unless it's satire.
Just go read some posts off project zero.
Some subset of the industry having "bad opinions" also does not mean their work suddenly has no value or they're not trying hard. To me this approach to the hard work of real experts is immediately disqualifying for someone's opinions. They can think it, but if they want to say it they should be prepared to not be taken seriously.
He has taken to posting mildly trollish stuff ("poasting") on Xitter, but this seems like a well reasoned reply to "Is rewriting entire codebases in a different language worth it?"
Unfortunately, for whatever reasons, large bureaucracies seem to have decided that, after doing the same thing to network engineering and systems administration, computer security is just a dump profession in which you put slightly dim people who are only good at repeating mantras.
For every pen tester or true security expert who breaks things for fun in their spare time, I've run into far too many more of the "just make the vulnerability scanner turn green" type. It's quite unfair actually that they get lumped together.