Your daily source of Pwnage, Policy and Politics.

[display_podcast]

Episode 519 – Infosec Whiners, Rogue Risk Manager, Steve Was Right, Comcast’s Native IPv6 and 5 iOS Tips

InfoSec Daily Podcast Episode 519 for November 10, 2011.  Tonight's podcast is hosted by Rick Hayes, Boris Sverdlik and Karthik Rangarajan.

Announcements:

Brad Smith (theNurse) and his stroke at Hacker Halted:

We all know and love Brad Smith, aka theNurse.  His humor and smiling positivity is a wonderful example for our community.  At Hacker Halted he had a massive stroke and has been in the hospital in a coma for a few days.

Brad and his wife did not ask for this help, but as a community we feel that if we can help we want to.  Please feel free to check in for status or to donate.  Either way we thank you and I know Brad thanks your for your support, prayers and positive thoughts.

http://www.social-engineer.org/brad-smith-updates/
http://www.social-engineer.org/bradsmithdonation/

BSides Delaware
When: November 11-12th, 2011
Where: Wilmington University, Delaware Campus
http://www.securitybsides.com/w/page/28563447/BSidesDelaware

Vote For Wim Remes
When: Starts November 16, 2011
Where: ISC2
Who: CISSP’s
http://blog.isc2.org/isc2_blog/2011/11/cast-your-vote-isc%C2%B2-board-of-directors-election-begins-nov-16-2011.html

SANS Mentoring: Forensics 408 – Computer Forensic Essentials
When: Starts November 30, 2011
Where: Atlanta, GA
Discount Code: M1011IPAD (free iPad 2)
http://www.sans.org/mentor/details.php?nid=25504

ShmooCon 2012
When: January 27th-29th, 2012
Where: Washington Hilton Hotel, Washington, DC
http://www.shmoocon.org

You don't have a sufficient version of Flash Player to display this animation.

Stories:

Source:http://daveshackleford.com/?p=689

I’m perennially happy. I am almost always in a pretty good mood, despite my inherent sarcasm and less-than-politically-correct approach. But I get the impression that many in infosec are not. Everyone is different, and I don’t want to stereotype, but I do run into a lot of gloomy folks. Why is the infosec profession so unhappy in general? I closed out the IANS forum in Chicago today (which ROCKED, by the way, just too much awesomeness in CHI to contain), and Ron Ritchie made some comments that I thought were pretty spot-on in his closing thoughts. He mentioned a few good reasons to be in infosec, and I’ll list some below, including his:

Reasons infosec rocks:

  • Money is good! (Ron)
  • We have tons of interesting things to work on! (Ron)
  • We bring real value to our organizations! (Ron)
  • We can actually detect and prevent crime in some cases!
  • We have one hell of a solid career path, in general!

I’m sure this all sounds good. High-fives all around! Hmmm. Wait. We’ve still got that “Sad Panda” problem. So there are surely some negative aspects to infosec as well. What are they? Based on my experience as a practitioner, consultant, trainer, and general curmudgeon (albeit a pretty jolly one), a few things I can think of:

Reasons infosec sucks:

  • People ignore us, hate us, or perceive us as roadblocks. Or all three.
  • Infosec never seems to be “done”, ever. Always an ongoing endeavor.
  • The landscape in infosec changes so rapidly it’s difficult to keep up.
  • Overall, infosec is “hard”.
  • Related to the first point in this list, we may feel “at odds” with business units and IT organizations.
  • There’s a general sense of “futility” – we can’t “win”.
  • Our career paths are wack – do we really have any respect?
All works represented here are compiled from various sources (email, IRC, forums, and original author/websites). If the original work is copyrighted it is presented under the fair use of a copyrighted work, Copyright Act of 1976, 17 U.S.C. § 107, for purposes of criticism, comment, news reporting, teaching, and research. No use is directly intended as an infringement of copyright. Attribution is always given to the original source, if known. To have any copyrighted material removed, please contact isdpodcast[at]isdpodcast[dot]com.