Hacker News new | ask | show | jobs
by sharkbot 1277 days ago
There are a few paths forward for you, and a lot hinge upon your skills outside of security (somewhat your morality).

Computer security is a lucrative field, and a broad one.

You could continue the bug bounty approach, which leads into vuln selling (with the attendant morality questions). You could go into systems security research, a long term project but worthwhile intellectually. You could contract (needs networking and business), you could FAANG (needs patience and soft skills), you could government (needs patience and more patience).

My advice: don’t rush. You have at least 50 years of career ahead of you. The decisions you make now will influence your direction for years, but there’s very little you can do to completely derail your future. Try some things, see what resonates and clashes and learn more about you.

Context: 25 years in computer security in a variety of roles, currently FAANG, currently management. My 17 year old self would likely be somewhat surprised at my circumstances, but hopefully not upset :)

2 comments

Thanks, much appreciated.

"You could contract (needs networking and business), you could FAANG (needs patience and soft skills), you could government (needs patience and more patience)" That sounds like a insanely hard approach. I don't really have anything to show, only really got my HackerOne profile to show. Most projects I do is related to it, which I don't really publish or just not allowed to publish.

If someone wanted to get in touch with you, what would be the best way?
You can either contact me on discord, my tag is xor#0001 or you can shoot me a DM on twitter at https://twitter.com/equat0rium
I suppose the #0001 part is not an accident? Mind sharing? :)
Hmm, what do you mean exactly? The #<4_numbers> is part of the username that is required to add someone on discord. So, yea, the full thing to add me is xor#0001
I meant that if you just created a "xor" account, there's not a high likelihood you'd get #0001?

I guess you cared enough about this to automate account creation and waited for the right one? That'd be rather commendable attention to detail!

If you have discord nitro, you can choose the 4 numbers by yourself. I got it gifted, so I set it to be #0001.
> You could continue the bug bounty approach, which leads into vuln selling (with the attendant morality questions)

Can you elaborate on this?

Look into Zerodium https://zerodium.com/.

They sell exploits to government agencies. They are one of the more legit outfits, but researchers can also sell exploits to NSO style bad actors.

I know what Zerodium is, but why does security work "lead to" exploit selling? There are lots of researchers who don't do that.