Also for a lot of jobs in security it's pretty hard to measure how well it's being done, so if the AI based solutions are worse, that might not show up for a while
Also for a lot of jobs in security it's pretty hard to measure how well it's being done, so if the AI based solutions are worse, that might not show up for a while
Nothing going wrong: “What are we paying you for?”
Everything going wrong: “What are we paying you for?”
It’s a no-win situation unless you manage to score a division manager who understands security and understands the reports a good security division produces. And most importantly, understands that no news is good news.
Cost centers in businesses are early canaries of expected pain, and a reduction in security roles may reflect belt-tightening irrespective of AI impact.
Half the field is B2B "magic bullet" solutions like CrowdStrike and all the associated sales tactics - with pitches that boil down to "you give us money, we make your security issues go away". Half of what remains is mandatory certifications and other flavors of checklist-obsessed cargo cultists - often CYA-driven, often demanding the adoption of the fancy acronym of the day, regardless of the real threat profiles. Then you get the "security snake oil" - "magic bullet" systems that don't work, never did and never will, but are supported by the right influence groups and get the right pockets lined, and so are used anyway. DRM systems like WideVine and PlayReady being the prime examples. Then there are the corporate "security of our business model" shills - who pay lip service to "security", but have the true aims of "prevent anyone we don't like from doing anything that can harm our revenue streams" - with Apple being a common example.
And about a fifth of the field is people who do actual security work, and keep the sky from falling.
It's a growth field, so you have lots of idiots getting certifications and stupid jobs. Reminds me of the 90s when I started, and companies were paying MCSE's (ie read a book, hit next-next-finish in Windows NT) more than software engineers in some markets.
Thank goodness engineers pop up out of the ground fully trained on good general IT practices....
This thread is a microcosm of that. They went on a tangent from a tangent to express how little they think of their colleagues working in security. It wasn't out of curiosity, it didn't raise interesting questions or provoke interesting debate. They didn't defend or substantiate their opinion so that they and we could learn something from it. It was just a drive-by flamebait to stir the pot and express derision. It should be downvoted; it's a bad comment.
Perhaps that pattern is difficult to see when their hot takes align with your own takes.
I didn't write my comment to applaud them.
The facts are that HN has a diverse set of perspectives with many conservative/libertarian commenters who would align with you, but that your comments are frequently shallow flamebait. Though I have seen a couple good points you've made, as well. Do with that information what you will.
In any case, brevity is something great writing and shallow hot takes share.
Just don't pretend that it's for our benefit or that we downvote it because we're unthinking drones, or that you decline to elaborate because we're simply not capable of having the discussion.
I tell you this because if I were insulating myself inside a bubble and rationalizing my interactions with those who disagree with me as being the reflexive behavior of a hive mind, I would hope someone would point that out to me. So here it is; again, do with the opportunity what you will.
It's easy for me to believe you're an intelligent person who's accomplished impressive things. But it wouldn't contradict anything I've said.
This is what I've been saying. You've got some random grievance, you want to take this discussion as an opportunity to get it off your chest. But you don't want to engage with people challenging your ideas. And when for whatever reason you do explain yourself to me, your explanation is "I am wealthy and successful, so I must be right. Those who disagree with me are an undifferentiated mass of imbeciles that I have nothing to learn from."
If that's how you want to live, it's your right. You're only cheating yourself, so maybe I'll just shut up and let you get on with it.
Maybe not "full", statistically, but many times I receive a similar impression.
The reason many comments are downvoted on HN in general is most often unknown to me. One interpretation is that it's a major flaw in HN.
This design decision by HN could be intentional, as a trade-off to achieve something else. For example, it could be done to have high velocity of discussion. High velocity could preserve an invariant of keeping or pulling users on the site.
If it's a trade-off, which would suggest something is given up for it, it might be worth exploring what's given up.
I also just love playing devil's advocate, and I'm adverse to hivemindy-feeling opinions (even when I share them). Maybe this all describes you, too.
Sounds exactly like something the average security practitioner would say...
`not_sure_if.jpg`
I have yet to meet an org whose engineers care about security, or who would not compromise security if secure practices got in the way of shipping a product or feature.
And probably more useless architects.