You said "This blog post is basically:", which I took to mean that you referring to him specifically (as he is the author of the blog post). I apologize if you weren't targeting him specifically.
Many in security are indeed condescending, although I don't find it to be more true than in the computer community at large; especially amongst programmers (who seem to feel an almost intrinsic need to disparage someone else's opinion about a language or design choice).
It might just be that we travel in different circles, but I actually am constantly impressed with how helpful and non-condescending most folks in the security community are. I frequently ask questions of people on Twitter who are among the best in the industry and I generally get really helpful replies (as helpful as you can be in 140 characters).
And I don't know Nate personally (I only refer to him by his first name because "Mr. Lawson" has a bit too much of a "Agent Smith" vibe to it), but I've never gotten the impression from anything he's written that he's smug or especially competitive about the infosec industry.
I got into tech via the security industry, so all my experience dates back to 10+ years ago when I left it. Since then I have only kept up with the more mainstream stories and the odd blog post.
I did make a sweeping generalization, and if it seems like I am holding a grudge it is probably because I am. I went through a lot of bad issues and arguments through the process of publishing articles, advisories, exploits etc. Enough to turn me (and many others) off for good.
I don't doubt that there are very good people out there in the netsec space, it just seems that every time a story floats up onto my radar it reminds me of the same issues we dealt with all that time ago (ie. pointless arguments, point-counter-point, one-upmanship, eliteness etc.). I recognized the template of that post pretty quickly, and it simply isn't constructive.
For all I know Nate could be awesome, but as somebody who only knows of him through the paragraphs I just read he fits the old stereotype that I am familiar with pretty well. But outside of the first line, the rest of what I wrote was more about that old template of how subjects, even as big and awesome as Stuxnet, are dealt with and written off by some in the sec industry.
You picked a uniquely bad person to use an example of the excesses of the security industry. It's too bad, because I probably could have agreed with most of your issues, but now I think you're a crank.
I opted out of software security ~10+ years ago too (I went from software vulnerability research to streaming media and multicast and then ISP operations software and then marketing). Coincidentally, that was about the same time Nate stopped being one of the world's better software vulnerability researchers and moved headlong into cryptography and hardware. He's a friend and I don't speak for him, but I'm guessing his move was made for similar reasons as yours.
I would hope the takeaway from my post is not "hey, this guy is so smart" but instead "hey, this hype about this malware sample is definitely overblown because he is citing really old work here".
Comments
You said "This blog post is basically:", which I took to mean that you referring to him specifically (as he is the author of the blog post). I apologize if you weren't targeting him specifically.
Many in security are indeed condescending, although I don't find it to be more true than in the computer community at large; especially amongst programmers (who seem to feel an almost intrinsic need to disparage someone else's opinion about a language or design choice).
It might just be that we travel in different circles, but I actually am constantly impressed with how helpful and non-condescending most folks in the security community are. I frequently ask questions of people on Twitter who are among the best in the industry and I generally get really helpful replies (as helpful as you can be in 140 characters).
And I don't know Nate personally (I only refer to him by his first name because "Mr. Lawson" has a bit too much of a "Agent Smith" vibe to it), but I've never gotten the impression from anything he's written that he's smug or especially competitive about the infosec industry.
I got into tech via the security industry, so all my experience dates back to 10+ years ago when I left it. Since then I have only kept up with the more mainstream stories and the odd blog post.
I did make a sweeping generalization, and if it seems like I am holding a grudge it is probably because I am. I went through a lot of bad issues and arguments through the process of publishing articles, advisories, exploits etc. Enough to turn me (and many others) off for good.
I don't doubt that there are very good people out there in the netsec space, it just seems that every time a story floats up onto my radar it reminds me of the same issues we dealt with all that time ago (ie. pointless arguments, point-counter-point, one-upmanship, eliteness etc.). I recognized the template of that post pretty quickly, and it simply isn't constructive.
For all I know Nate could be awesome, but as somebody who only knows of him through the paragraphs I just read he fits the old stereotype that I am familiar with pretty well. But outside of the first line, the rest of what I wrote was more about that old template of how subjects, even as big and awesome as Stuxnet, are dealt with and written off by some in the sec industry.
You picked a uniquely bad person to use an example of the excesses of the security industry. It's too bad, because I probably could have agreed with most of your issues, but now I think you're a crank.
I opted out of software security ~10+ years ago too (I went from software vulnerability research to streaming media and multicast and then ISP operations software and then marketing). Coincidentally, that was about the same time Nate stopped being one of the world's better software vulnerability researchers and moved headlong into cryptography and hardware. He's a friend and I don't speak for him, but I'm guessing his move was made for similar reasons as yours.
I would hope the takeaway from my post is not "hey, this guy is so smart" but instead "hey, this hype about this malware sample is definitely overblown because he is citing really old work here".