Features Podcasts Family Video Comics Music Tech Science Books Film & TV Games ✚

Jill

HOWTO become a security expert, Bruce Schneier style

Cory Doctorow at 8:23 am Mon, Jul 2, 2012

— FEATURED —

Science

Making sense of the confusing Supreme Court DNA patent ruling

Book Review

The 'Geisters: spooky, scary novel

Science

Ants and Stars: Bruce Sterling and Jasmina Tesanovic visit the Sardinia Radio Telescope in Italy

Feature

The Snowden Principle

— FOLLOW US —

Boing Boing is on Twitter and Facebook. Subscribe to our RSS feed or daily email.

 

— POLICIES —

Except where indicated, Boing Boing is licensed under a Creative Commons License permitting non-commercial sharing with attribution

 

— FONTS —

Tweet
Kindle

Brian Krebs is conducting a series of interviews with computer experts on how they got into the field and what they'd advise others to do if they want to break in themselves. The first one, an interview with Thomas Ptacek, ran last month. The latest is from Bruce Schneier:

In general, though, I have three pieces of advice to anyone who wants to learn computer security:

* Study: Studying can take many forms. It can be classwork, either at universities or at training conferences like SANS and Offensive Security. (These are good self-starter resources.) It can be reading; there are a lot of excellent books out there — and blogs — that teach different aspects of computer security out there. Don’t limit yourself to computer science, either. You can learn a lot by studying other areas of security, and soft sciences like economics, psychology, and sociology.

* Do: Computer security is fundamentally a practitioner’s art, and that requires practice. This means using what you’ve learned to configure security systems, design new security systems, and — yes — break existing security systems. This is why many courses have strong hands-on components; you won’t learn much without it.

* Show: It doesn’t matter what you know or what you can do if you can’t demonstrate it to someone who might want to hire you. This doesn’t just mean sounding good in an interview. It means sounding good on mailing lists and in blog comments. You can show your expertise by making podcasts and writing your own blog. You can teach seminars at your local user group meetings. You can write papers for conferences, or books.

How to Break Into Security, Schneier Edition

I write books. My latest is a YA science fiction novel called Homeland (it's the sequel to Little Brother). More books: Rapture of the Nerds (a novel, with Charlie Stross); With a Little Help (short stories); and The Great Big Beautiful Tomorrow (novella and nonfic). I speak all over the place and I tweet and tumble, too.

MORE:  Business • employment • security • web theory

More at Boing Boing

Ants and Stars: Bruce Sterling and Jasmina Tesanovic visit the Sardinia Radio Telescope in Italy

The Snowden Principle

  • Kaleberg

    One time, while I was waiting for a Southwest flight – they are always late – I had a nice chat with a security expert who had spent years as a professional safe cracker and robber. He had done pretty well, but eventually he got caught. When he was released from prison, he found he could work as a security consultant specializing in physical security. If nothing else, he understand how the bad hats worked, so he could now do a good job as a white hat. In fact, he was on his way out on a consulting gig. I can’t recommend this as a career path, but it was an interesting story to hear.

  • noah django

    >…if they want to break in…

    oh, you.

  • Susan Carley Oliver

    Study / Do / Show – isn’t this a roadmap to creating a career in just about any arena?

  • Paul Renault

    If you want to do it Bruce Schneier style, you also have to learn to play a musical instrument.

    I can’t find the youtube video. But in the meanwhile, watch this:
    https://www.youtube.com/watch?v=I6ZkU2fUM5w