Playing whack-a-mole is losing

This article explores the 'hacker ethos' within the security industry, contrasting it with professional engineering approaches. It critiques the tendency to prioritize clever, edgy problem-solving over systematic, sustainable security practices.
Why it matters
It challenges the cultural norms of the cybersecurity industry, suggesting that the 'hacker identity' may hinder effective, long-term product defense.
I want to juxtapose two classes of people in the security industry on the defender side of security engineering for products . The first are the Security as Identity people. This goes back to the security-as-counterculture attitude, glamorized in Hackers and dating back to phone phreaking. It reflects Thompson’s " Workism ", where work is not just a way to earn a living, but a way to build a sense of identity, purpose, and community. In the case of security, this identity tends to be built around being different, seeing things other people do not, and being clever in an edgy and misunderstood way. Someone who is beyond merely a security professional, but has the persona of a Hacker. Stylish outsiders smarter than the system. Detectives finding insights others miss.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in