logoalt Hacker News

normie3000yesterday at 10:01 PM6 repliesview on HN

> Top infosec talent doesn't want to do it (and there's not enough of it).

What is the top talent spending its time on?


Replies

hinterlandsyesterday at 10:40 PM

Vulnerability researchers? For public projects, there's a strong preference for prestige stuff: ecosystem-wide vulnerabilities, new attack techniques, attacking cool new tech (e.g., self-driving cars).

To pay bills: often working for tier A tech companies on intellectually-stimulating projects, such as novel mitigations, proprietary automation, etc. Or doing lucrative consulting / freelance work. Generally not triaging Nessus results 9-to-5.

mr_mitmtoday at 10:32 AM

Working from 9 to 5 for a guaranteed salary that is not dependent on how many bugs you find before anybody else, and not having to argue your case or negotiate the bounty.

kalium-xyztoday at 11:53 AM

From my experience they work on random person projects 90% of their time

tptacekyesterday at 10:40 PM

Specialized bug-hunting.

UltraSanetoday at 2:49 AM

The best paying bug bounties.

atemerevtoday at 4:51 AM

"A bolt cutter pays for itself starting from the second bike"