Wow. It’s finally happened – the fabled 40th birthday that everyone loathes. It’s upon me. At 40, I think you’re supposed to reflect back on what you’ve done, what you’ve accomplished, what’s been good and bad, and where the hell you’re going in life. Right? OK, this will depend largely on the individual, but 40 feels like a pretty damn good spot to reflect. Why not?
Some of you will say “40? WTF? That’s nothing.” And you know what? You’re right. 40 IS nothing. It’s been the most amazing ride so far, and things are only getting more interesting. So…a few observations on infosec, life, and the big picture. Warning: opinions ahead, and I get it if this is content easily skipped.
First, the industry we’re in. WOW. What a shit show. Who could have known what it’d turn into – I remember how I got into infosec, and never for a second thought it’d be this. So first, I was a fucking nerd as a kid. I wrote computer games in BASIC for the Commodore and Atari systems, most of which consisted of “What do you do? Turn left. Well, you die!” So yeah…game designer was out. I exploded shit in my basement as a kid with my chemistry set. I also took apart every electronic thing I could get my hands on, and *sometimes* put them back together. I was born to be a hacker, and that is all there is to it. So when one of my college professors hired me into a large Fortune 500 program, I had no idea what I was getting into, but security felt RIGHT. And today? Man, who could have imagined this?
I get bored easily. REAL easily. I need mental stimulation, and boring ass IT gigs sucked for me. Can you imagine being a day-to-day Exchange admin? That’s a “wake up in a cold sweat” nightmare for me. Day in, day out, Exchange. GAWD. So infosec? Yeah, it is volatile, and messy, and changes all the time. Thank goodness. I think change keeps you fresh, and this industry is just insane.
I miss some of the “old days”. I think it’s natural for some of us “old schoolers” who did infosec in the 90′s (or before). Back then, people had to innovate “solutions”, and actually understand sysadmin roles, technology, and maybe even code. Today, that is more rare than ever. We have pockets of brilliance…surrounded by an ocean of “just got my information assurance degree” bullshit that belies total lack of experience and real technical competence. Some of that is likely me being old and curmudgeonly, but damn…don’t talk security until you have done the actual work, or at least SOME of it.
So at 40 – how am I feeling about my infosec career and life in general? Let’s start with infosec, naturally. Infosec is the most incredible gift I could ever have received. All cynicism aside, it pays well, is dynamic, and more than anything…I love you people. Many of you are not just assholes, but FUCKING assholes. Some of us assholes NEED other assholes to hang out with. I love the vitriol, technical condescension, and pathetic attempts to deflect Twitter comments from your employers. You’re good company, and challenge the status quo…which is exactly what the industry needs. The ridiculous focus on all these stupid ass conferences? Not so much. But…you take the bad with the good.
What about life in general? Well, I’ll keep it short. I have far exceeded all of my wildest dreams. I have no real regrets at all, even though I’ve done some of the dumbest shit you’d ever hear about (most of which will remain private). I have an incredible wife and daughter, a few good friends, a lot of insane hacker acquaintances, and a good paying gig that I absolutely love. So all is well with the universe.
What advice could I offer? Heh. If you take advice from me…a big grain of salt should be involved. But in general, a few things I’ve learned along the way:
- Learn more. Constantly. If you are chillin’ with your skills from a few years back, no. Advance, learn more, or find a new gig. Infosec does NOT need dead weight.
- Make sure you have thick skin. If you are easily offended, or get worked up about critical comments and such, you need to toughen up. This is not an industry that cares about personal feelings. Good and bad, true, but it is what it is.
- Make as much money as you can. Seriously. Don’t be lulled into this “greed is bad, do it for the community” horseshit. You are in a very in-demand industry, and SOMEONE is going to make great money at it. Might as well be you. So do this.
- Do not make infosec your life. It’s a job. One you can, and should, enjoy SO MUCH. But your REAL life? That’s other things. If it’s not, you are putting all your eggs in one basket, and that directly defies some-or-another CISSP principle, I’m pretty sure. Seriously – get out more, explore hobbies, and think about the other part of your life that does not involve infosec. If there’s not one, you need to develop one.
- 1′s and 0′s are our work life. But step back. Look at the PEOPLE. Your family, friends. This is what matters most. Appreciate this more. Yes, you can.
- If your health sucks – change it. You cannot live a full and awesome life 200 pounds overweight and miserable. There’s nothing awesome about being a walking heart attack- and no, I’m not telling you to become a fitness nut. I am one, but that’s irrelevant. This is your LIFE. Your body lets you enjoy it. So take care of yourselves, people! I want to have a drink with you at DEF CON, and if you fucking die, that won’t happen.
All in all, this hacker is looking at 40 with an incredible perspective on life. I’ve had severe highs and the most guttural lows along the way, but I would not trade my life for anything. I hope you feel the same. Cheers.