Replying to @MalwareJake
It's several factors: - Dunning-Kruger - Lack of people - Overreliance on tech - Defenders not knowing how attackers really operate - Poor use of existing defensive capabilities 1/?
1
But the biggest factor? (and what will likely anger lots) Our industry is filled with people who are more worried about feelings than actual hard facts. I looked through the parent tweet about this... and have a TON to say. Buckle up. This is a rarely seen side of me. 2/?
1
1
1
Let's start off with the harshest stuff first. It's not gatekeeping if you are not skilled. What some are calling gatekeeping... I call "minimum skills required for acceptable job performance". YES this can be toxic. However, it's OK to have standards. 3/?
1
1
I'm talking about the difference between ignorance and stupidity. It's ok to not know something. That can be solved. I'm not sure what can be done with you if you're stupid. Doubly so if you're stupid and proud of it. 4/?
2
1
Dunning-Kruger is something we all should review. Routinely. It's *easy* to get in over your head in this field. Lord knows I've been there a few times. We need to make it OK for people to 'tap out'. I am not sure why me knowing 'X' means I'm on the hook for ABCOMGBBQ 5/?
1
This is a strange take, but I try to embrace imposter syndrome. Is this just my worst self bringing me down? Or is this my better self saying "hey, you're headed to an area where you need to study... NOW" Knowing the difference is essential. 6/?
1
Truth be told, I actively struggle with imposter syndrome. I have a long and accomplished career in this field. I have been on pen tests that are the stuff of legend. But I still battle with this. I think it makes me better. I am my own worst critic. 7/?
1
1
I think though that this last year has been an interesting one... our field has been exposed for just how bad we really are at our jobs. Don't get mad at me. Look at the scoreboard. APTs tacking up point after point. I think we collectively *should* feel bad. 8/?
1
When I look at what the 'big names' in the field are saying in response to this? I'm sickened. We're getting better at making excuses than executing. Get better at doing, or making excuses. Pick one. 9/?
1
It doesn't have to be this way. We all are flawed creatures. All I'm asking is that we admit our flaws. Fight to make yourself better daily. Because the biggest issue and the one I'm going to end this tweet spew on... that only you can solve... Hubris. 10/fin
1
There’s an interesting panel discussion in this

Mar 8, 2021 · 10:21 AM UTC

1
1
Hey @strandjs How about BHIS creates a regular forum for panel discussions about “deep issues” like this?
2
3