Social

So you want to work in security (but are too lazy to read Parisa's excellent essay)


If you have not seen it yet, Parisa Tabriz penned a lengthy and insightful post about her experiences on what it takes to succeed in the field of information security.




My own experiences align pretty closely with Parisa's take, so if you are making your first steps down this path, I strongly urge you to give her post a good read. But if I had to sum up my lessons from close to two decades in the industry, I would probably boil them down to four simple rules:






  1. Infosec is all about the mismatch between our intuition and the actual behavior of the systems we build. That makes it harmful to study the field as an abstract, isolated domain. To truly master it, dive into how computers work, then make a habit of asking yourself "okay, but what if assumption X does not hold true?" every step along the way.





  2. Security is a protoscience. Think of chemistry in the early 19th century: a glorious and messy thing, chock-full of colorful personalities, unsolved mysteries, and snake oil salesmen. You need passion and humility to survive. Those who think they have all the answers are a danger to themselves and to people who put their faith in them.






  3. People will trust you with their livelihoods, but will have no way to truly measure the quality of your work. Don't let them down: be painfully honest with yourself and work every single day to address your weaknesses. If you are not embarrassed by the views you held two years ago, you are getting complacent - and complacency kills.






  4. It will feel that way, but you are not smarter than software engineers. Walk in their shoes for a while: write your own code, show it to the world, and be humiliated by all the horrible mistakes you will inevitably make. It will make you better at your job - and will turn you into a better person, too.









Related Posts:

  • TKJeg har i et par innlegg i vår kommentert egenkapitalsituasjonen til TK. Nå viser det seg at TK må nedskrive verdier for 438 millioner. I mars skrev j… Read More
  • How far are we from trend?I am always amazed at how well a log-linear trend line seems to fits real GDP (or per capita GDP) in the United States. Through a great depression, sa… Read More
  • Merkelig konklusjonInternasjonal forskningen viser at staten bør stimulere til mer utenlandsk eierskap. En rapport for Bergens Næringsråd kommer merkelig nok til motsatt… Read More
  • Boolean algebra with CSS (when you can only set colors)Depending on how you look at it, CSS can be considered Turing-complete. But in one privacy-relevant setting - when styling :visited links - the set of… Read More
  • Excess reserves and inflation riskDave Wheelock, my colleague at the St. Louis Fed, points me to this nice article: Repeat After Me: Banks Cannot and Do Not "Lend Out" Reserves (b… Read More

0 nhận xét:

Đăng nhận xét