Hacker News new | ask | show | jobs
by justin_oaks 1203 days ago
I'm very interested in security vulnerabilities and clever hacks. Because of that I thought I'd be good in a security role. Then I discovered that defending against security problems is awful.

The biggest security weaknesses are people. Employee get socially engineered or phished. Management doesn't take security seriously so they put only a tiny budget toward security. Lazy sysadmins don't keep their systems patched. Software developers can't be bothered to learn how to write secure software, and this is mostly because their bosses don't incentivize them to. Security vendors often hype up their snake oil products. Good security protocols and technologies aren't adopted because people don't want to change.

Dealing with these human problems is awful, demoralizing, and generally unsolvable.