{"id":121,"date":"2006-03-06T00:59:16","date_gmt":"2006-03-05T22:59:16","guid":{"rendered":"http:\/\/www.kill-9.it\/blog\/index.php\/2006\/03\/06\/mjr-pentesters\/"},"modified":"2006-03-06T00:59:16","modified_gmt":"2006-03-05T22:59:16","slug":"mjr-pentesters","status":"publish","type":"post","link":"https:\/\/www.kill-9.it\/blog\/index.php\/2006\/03\/06\/mjr-pentesters\/","title":{"rendered":"mjr &#038;&#038; pentesters"},"content":{"rendered":"<p>From bugtraq:<\/p>\n<blockquote><p>\nSo, as much as you may not like it, there are plenty of folks out there who understand that software security is a design and architecture issue &#8211; not a process of slapping band-aids on bad code until it&#8217;s, well, bad code covered with band-aids. What you&#8217;ll find is that engineers who understand engineering discipline find bug-hunting to be an utterly boring process; well-designed and implemented systems don&#8217;t need &#8220;pen testers&#8221; &#8211; they cross-check themselves. The only reason the industry is in the horrible condition it&#8217;s in today is because the vast majority of code that&#8217;s been fielded to date is crap. That will have to change. And when it does, &#8220;pen testers&#8221; will become peons in the quality assurance department.\n<\/p><\/blockquote>\n<blockquote><p>\nI would say that most pentesters are failed security analysts who do not understand engineering discipline and have chosen to engage in the war of band-aids instead of learning how to build correct systems. And then there are the pentesters who really are cybertrespassers at heart, who have found a financial and moral justification for doing something for money that they&#8217;d otherwise do anyhow, for free, in the wee hours of the night.<\/p>\n<p>Put differently: either way you slice it, pentesters aren&#8217;t worth a bucket of warm spit as far as I am concerned.\n<\/p><\/blockquote>\n<p>There would be so many things to say, that keeping my mouth shut is maybe the best thing to do.<br \/>\nWell, almost.<\/p>\n<p>I&#8217;ve always felt part of the &#8220;quality assurance department&#8221; when I was asked to prod things that had or were being deployed, just to be sure that another pair of eyes would spot more security problems; never felt like a peon though. Damned self-esteem.<\/p>\n<p>It looks like Marcus is not taking into consideration that even deploying perfectly secure &#8220;software units&#8221; there always can be unexpected\/funny\/dangerous problems glueing them all together.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>From bugtraq: So, as much as you may not like it, there are plenty of folks out there who understand that software security is a design and architecture issue &#8211; not a process of slapping band-aids on bad code until it&#8217;s, well, bad code covered with band-aids. What you&#8217;ll find is that engineers who understand &hellip; <a href=\"https:\/\/www.kill-9.it\/blog\/index.php\/2006\/03\/06\/mjr-pentesters\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;mjr &#038;&#038; pentesters&#8221;<\/span><\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,3,4],"tags":[],"class_list":["post-121","post","type-post","status-publish","format-standard","hentry","category-english","category-geek","category-security"],"_links":{"self":[{"href":"https:\/\/www.kill-9.it\/blog\/index.php\/wp-json\/wp\/v2\/posts\/121","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kill-9.it\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kill-9.it\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kill-9.it\/blog\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kill-9.it\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=121"}],"version-history":[{"count":0,"href":"https:\/\/www.kill-9.it\/blog\/index.php\/wp-json\/wp\/v2\/posts\/121\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.kill-9.it\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=121"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kill-9.it\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=121"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kill-9.it\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=121"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}