Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
RFC2324
Jun 7, 2012

http 418

Achmed Jones posted:

when they said i'd be an apprentice noone said i'd have to learn

wire stripper
watts law
wire puller
ohms law
soldering
grounding
safety
reading resistors
ladder safety
ac
dc
multimeter

I'm being glib and don't intend to offend, but I really don't know what you expected an entry level position in a skilled/technical field to be other than a position where you weren't expected to already be proficient (and to therefore have to learn)

A lot of people tend to be shocked to realize how much they don't know, particularly in computers.

Adbot
ADBOT LOVES YOU

GreenBuckanneer
Sep 15, 2007

Seemed weird to me I guess, since I've been surrounded in IT without ever needing to know how to use any of those things for a decade. "entry level" isn't "entry level" if it means you need to compete some prerequisite levels first.

It would be different if we were talking about a freelance webdev position and you took html and css and Javascript classes ten years ago

In any case, I'm fine with learning the content, I was just surprised

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

RFC2324 posted:

A lot of people tend to be shocked to realize how much they don't know, particularly in computers.

Especially in Security Engineering and Infosec in general, where you have to be a jack of all trades, effectively.

GreenBuckanneer
Sep 15, 2007

Also it's kind of amusing because I know those things and have taken computer engineering courses and more practical electrical house wiring courses

Not confident enough to mess around with a fuse box wiring though

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

GreenBuckanneer posted:

Also it's kind of amusing because I know those things and have taken computer engineering courses and more practical electrical house wiring courses

Not confident enough to mess around with a fuse box wiring though

Well that's where Jack of Trades tends to fall flat, as the other half of that saying is "...master of none.". You will run into specialized concerns that will either require you to do some learning/research or talk to someone who is a Subject Matter Expert (i.e. in this case an Electrician)

Edward IV
Jan 15, 2006

GreenBuckanneer posted:

they said the position was entry level

no one said I'd have to learn

sql
grok
elastic
kibana
logstash
crowdstrike
tenable
varonis
exabeam
more than rudimentary linux knowledge
learn how to use github outside of knowing how to navigate github to download packages

but also putting more effort into excel, doing tons of meetings (that should have instead be emails)

I'm sure I'm forgetting something but :asoiaf:

For what it's worth, I recently got my Masters in CS and I only know SQL and Elastic (assuming you mean Amazon EC2) in your list and only SQL was part of the required Database course. I learned to use EC2 through a Cloud Computing elective though I may have come across some of that other stuff because they seem to be AWS products, tools, etc. I did Mechanical Engineering for undergrad before switching gears so I don't know what the BS coursework looks like

Achmed Jones
Oct 16, 2004



ec2 is not what people mean by "elastic"

"elastic" means lucene/elastic search - inverted index data storage and querying

GreenBuckanneer
Sep 15, 2007

More specifically, elk, so elastic logstash kibana

Achmed Jones
Oct 16, 2004



"elk stack" is basically "generic roll-your-own-siem" at this point. elk/splunk/sumo/etc

GreenBuckanneer
Sep 15, 2007

There also seems like there's some infighting between exabeam wanting to move away from splunk and do their own thing, I heard

Crime on a Dime
Nov 28, 2006

GreenBuckanneer posted:

Also it's kind of amusing because I know those things and have taken computer engineering courses and more practical electrical house wiring courses

Not confident enough to mess around with a fuse box wiring though

bizarre combo ngl

GreenBuckanneer
Sep 15, 2007

Crime on a Dime posted:

bizarre combo ngl

College to college transfer credits where one college has less specialized content (but cheaper)

Crime on a Dime
Nov 28, 2006

GreenBuckanneer posted:

College to college transfer credits where one college has less specialized content (but cheaper)

:golgo:

Absurd Alhazred
Mar 27, 2010

by Athanatos
CS teaches you a lot of theoretically-useful cruft that you need to dig out of to actually do your job, but is good to have as your background.

Asymptotic reasoning about algorithm complexity is great - but you are often NOT at large enough n.

more falafel please
Feb 26, 2005

forums poster

Absurd Alhazred posted:

CS teaches you a lot of theoretically-useful cruft that you need to dig out of to actually do your job, but is good to have as your background.

Asymptotic reasoning about algorithm complexity is great - but you are often NOT at large enough n.

See every 23 year old gamedev thinking that everything should be a red-black tree instead of the humble and cache-coherent flat-rear end array

Absurd Alhazred
Mar 27, 2010

by Athanatos

more falafel please posted:

See every 23 year old gamedev thinking that everything should be a red-black tree instead of the humble and cache-coherent flat-rear end array

Yup! Simplicity and readability trumps cleverness most of the time. You can always add clever later.

GreenBuckanneer
Sep 15, 2007

I am liking learning about some of these things I've never once used in my adult life, like regex. Would have been useful when I was younger for sure.

Defenestrategy
Oct 24, 2010

I think it's one of the things that people coming out of college, a cert program, or some other info sec boot camp don't realize is that IT is a very very broad discipline and don't impress on them that you need to know at least something about every other IT discipline to properly do security on it/with it.

Arsenic Lupin
Apr 12, 2012

This particularly rapid💨 unintelligible 😖patter💁 isn't generally heard🧏‍♂️, and if it is🤔, it doesn't matter💁.


RFC2324 posted:

A lot of people tend to be shocked to realize how much they don't know, particularly in computers.
I was a technical writer, which meant that I had the gift of getting away with asking stupid questions. You'd be amazed how often I'd say, "Okay, what does QYZX actually do?" and a sigh of relief would waft across the room because somebody else had asked.

RFC2324
Jun 7, 2012

http 418

Arsenic Lupin posted:

I was a technical writer, which meant that I had the gift of getting away with asking stupid questions. You'd be amazed how often I'd say, "Okay, what does QYZX actually do?" and a sigh of relief would waft across the room because somebody else had asked.

one of the things I hammer on when I train anyone is "never run a command you don't understand" and it seems to frustrate people

its especially fun to try and follow that while dealing with undocumented behaviors

Zil
Jun 4, 2011

Satanically Summoned Citrus


RFC2324 posted:

one of the things I hammer on when I train anyone is "never run a command you don't understand" and it seems to frustrate people

its especially fun to try and follow that while dealing with undocumented behaviors

"Eh don't worry, we got backups"

CommieGIR
Aug 22, 2006

The blue glow is a feature, not a bug


Pillbug

Zil posted:

"Eh don't worry, we got backups"

Me, usually with a client: "And when did you last test them?"

Client: *eyes suddenly bulge wide*

Sickening
Jul 16, 2007

Black summer was the best summer.
https://twitter.com/samwcyo/status/1570577801790783493?s=20&t=hC8MXOUeW4NkEE5deWIkjw

CLAM DOWN
Feb 13, 2007





holy loving lol i am lollin irl right now lmao lmao

CLAM DOWN
Feb 13, 2007




I cannot stop lol and lmao oh my god this is INCREDIBLE

https://twitter.com/vxunderground/status/1570597582417821703

e: https://twitter.com/Uber_Comms/status/1570584747071639552

Internet Explorer
Jun 1, 2005





Woof, that's pretty bad.

Internet Explorer
Jun 1, 2005





What's going to be worse is when Discord gets popped and someone is able to link Discord MFA phone numbers and Uber account phone numbers. With the home address from Uber.

Ynglaur
Oct 9, 2013

The Malta Conference, anyone?
MFA people, MFA. sigh

CLAM DOWN
Feb 13, 2007






lol. lmao.

Internet Explorer
Jun 1, 2005





Move fast and break things.

CLAM DOWN
Feb 13, 2007




Apparently it wasn't a dick pic. It was goatse. A true hacker of culture imo.

Famethrowa
Oct 5, 2012

I hope they delete the entire loving company

Sickening
Jul 16, 2007

Black summer was the best summer.

Ynglaur posted:

MFA people, MFA. sigh

MFA was part of the first hurdle and it wasn't enough. I will bet anything their secrets server wasn't on SSO or MFA because it was "inside the perimeter". It also gives me the vibes nothing inside is monitored as these actors had tons of free time to look around.

Is there a single org out there that makes sure that VPN connections are more than username/password and mfa?

Sickening
Jul 16, 2007

Black summer was the best summer.
Oh, I also got an interview request from uber to be part of their cloud security team but I refused to do their 2 hour homework assignment before they would interview me.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

CLAM DOWN posted:

lol. lmao.

This perfectly sums up my reaction. Burn it to the ground.

The fallout will likely be impressive.

BaldDwarfOnPCP
Jun 26, 2019

by Pragmatica

Famethrowa posted:

I hope they delete the entire loving company

It would be a fitting end.

Cup Runneth Over
Aug 8, 2009

She said life's
Too short to worry
Life's too long to wait
It's too short
Not to love everybody
Life's too long to hate


GreenBuckanneer posted:

I am liking learning about some of these things I've never once used in my adult life, like regex. Would have been useful when I was younger for sure.

Regex is one of the most important things I ever learned in college

Ynglaur posted:

MFA people, MFA. sigh

Bypassed via API token

Cup Runneth Over fucked around with this message at 07:01 on Sep 16, 2022

Ynglaur
Oct 9, 2013

The Malta Conference, anyone?
I thought the Powershell script had a password, and not a token?

Takes No Damage
Nov 20, 2004

The most merciful thing in the world, I think, is the inability of the human mind to correlate all its contents. We live on a placid island of ignorance in the midst of black seas of infinity, and it was not meant that we should voyage far.


Grimey Drawer
Couple more Uber tweets, including some financial deets. I wonder if this will prove their story that they couldn't afford to make their drivers actual employees and not contractors :thunk:

Adbot
ADBOT LOVES YOU

Vincent Van Goatse
Nov 8, 2006

Enjoy every sandwich.

Smellrose
I know jack poo poo about infosec beyond half-remembered basics but this is funny as hell.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply