HN user

enderforth

72 karma
Posts0
Comments6
View on HN
No posts found.

It's been my experience that there are 2 types of security people. 1. Are the security people who got into a security because it was one of the only places that let them work with every part of the stack, and exposure to dozens of different domains on the regular, and the idea of spending hours understanding and then figuring out ways around whitelist validations are appealing

2. Those that don't have much technical chops, but can get by with a surface level understanding of several areas and then perform "security shamanism" to intimidate others and pull out lots of jargon. They sound authoritative because information security is a fairly esoteric concept and because you can't argue against security like you can't argue against health and safety, the only response is "so you don't care about security?!"

It is my experience that the first are likely to work with you to help figure out how to get your application past the hurdles and challenges you face viewing it as an exciting problem. The second view their job as to "protect the organization" not deliver value. They love playing dressup in security theater and their depth of their understanding doesn't even pose a drowning risk to infants, which they make up for with esoterica, and jargon. They are also unfortunately the one's cooking up "standards" and "security policies" because it allows them to feel like they are doing real work, without the burden of actually knowing what they are doing, and talented people are actually doing something.

Here's a good litmus test to distinguish them, ask their opinion on the CISSP. If it's positive they probably don't know what the heck they are talking about.

Source: A long career operating in multiple domains, quite a few of which have been in security having interacted with both types (and hoping I fall into the first camp rather than the latter)

This right here is where I feel most concerned

If you haven’t spent at least $1,000 on tokens today per human engineer, your software factory has room for improvement

Seems to me like if this is true I'm screwed no matter if I want to "embrace" the "AI revolution" or not. No way my manager's going to approve me to blow $1000 a day on tokens, they budgeted $40,000 for our team to explore AI for the entire year.

Let alone from a personal perspective I'm screwed because I don't have $1000 a month in the budget to blow on tokens because of pesky things that also demand financial resources like a mortgage and food.

At this point it seems like damned if I do, damned if I don't. Feels bad man.

I didn't always agree with Scott Adams on everything he did and said, but "The Dilbert Principle" taught me more about living in a corporation and management than any other book on business and his dilbert comics were a source of endless wisdom and amusement, which I use often today.

Farewell Scott, you are now God's debris.

Okay, everyone here is talking about dick pics but let's be clear here the goal is

A major expansion of the UK’s Online Safety Act (OSA) has taken effect, legally obliging digital platforms to deploy surveillance-style systems that scan, detect, and block user content before it can be seen.

Do we really believe that no government forever is not going to use this to prevent certain "misinformation" from circulating?

And by misinformation we mean things like MPs breaking COVID lock down rules or "problematic" information about the PM being involved in a scandal, or the list is endless.

Let's be clear this isn't at all and never has been about dick pics this is 100% about being able to control what you can see and share.