Gosh this was a (recent) first-hand lived experience.
-
Gosh this was a (recent) first-hand lived experience.
I'm dismayed it's more prevalent than I hoped.
Appearing Productive in The Workplace — No One's Happy
AI can produce work that looks expert without being expert. The failure arrives in two shapes, and both are reshaping the workplace.
No One's Happy (nooneshappy.com)

-
Gosh this was a (recent) first-hand lived experience.
I'm dismayed it's more prevalent than I hoped.
Appearing Productive in The Workplace — No One's Happy
AI can produce work that looks expert without being expert. The failure arrives in two shapes, and both are reshaping the workplace.
No One's Happy (nooneshappy.com)

@hrbrmstr Too real
-
R relay@relay.infosec.exchange shared this topic
-
@hrbrmstr Too real
-
I spent more time than I should have correcting fundamentals. Eventually I stopped. He was not, in any meaningful sense, on the other side of the conversation
Also
The reckoning will not be subtle. The firms still doing the work properly will be in a position to charge for it. The firms that have hollowed themselves out will discover that what they hollowed out was the thing the client was paying for.
And
Misunderstanding and misuse of AI in the workplace is rampant. In many of the rooms I now find myself in, expertise has been asked to look the other way: to deliver faster, produce more, integrate the tools more deeply, get out of the way of the colleagues who are “getting things done”
These are all painfully familiar to read these days
-
Gosh this was a (recent) first-hand lived experience.
I'm dismayed it's more prevalent than I hoped.
Appearing Productive in The Workplace — No One's Happy
AI can produce work that looks expert without being expert. The failure arrives in two shapes, and both are reshaping the workplace.
No One's Happy (nooneshappy.com)

@hrbrmstr Meanwhile: I, someone that takes pride in knowing things and how to do them, relishing in the idea of teaching others what I know; I can't find a fucking job to literally save my life.
-
I spent more time than I should have correcting fundamentals. Eventually I stopped. He was not, in any meaningful sense, on the other side of the conversation
Also
The reckoning will not be subtle. The firms still doing the work properly will be in a position to charge for it. The firms that have hollowed themselves out will discover that what they hollowed out was the thing the client was paying for.
And
Misunderstanding and misuse of AI in the workplace is rampant. In many of the rooms I now find myself in, expertise has been asked to look the other way: to deliver faster, produce more, integrate the tools more deeply, get out of the way of the colleagues who are “getting things done”
These are all painfully familiar to read these days
-
@Viss @iagox86 @hrbrmstr fellas this was me last year interviewing interns. Some of the best schools in the country... and they were all caught using AI for their answers. Had to hire one of them. I spent over six months unteaching his reliance on AI. Just in time for him to leave.
I still have no idea if I made any measurable impact on his critical thinking and self-reliance. Sure as shit, he bullshitted all the things he did while he was here and all of the expertise he had (he in fact, did not) on his resume when I looked at his LinkedIn profile.. Expert detection engineer. He submitted a single rule to the ET ruleset the entire time he was here, and even that required heavy modification.
I was livid.
-
@Viss @iagox86 @hrbrmstr fellas this was me last year interviewing interns. Some of the best schools in the country... and they were all caught using AI for their answers. Had to hire one of them. I spent over six months unteaching his reliance on AI. Just in time for him to leave.
I still have no idea if I made any measurable impact on his critical thinking and self-reliance. Sure as shit, he bullshitted all the things he did while he was here and all of the expertise he had (he in fact, did not) on his resume when I looked at his LinkedIn profile.. Expert detection engineer. He submitted a single rule to the ET ruleset the entire time he was here, and even that required heavy modification.
I was livid.
-
@NosirrahSec @da_667 @Viss @iagox86 @hrbrmstr flee into the woods to become that thing everyone tells stories about.
-
@NosirrahSec @da_667 @Viss @iagox86 @hrbrmstr flee into the woods to become that thing everyone tells stories about.
@rootwyrm @NosirrahSec @da_667 @iagox86 @hrbrmstr working on it
-
@Viss @iagox86 @hrbrmstr fellas this was me last year interviewing interns. Some of the best schools in the country... and they were all caught using AI for their answers. Had to hire one of them. I spent over six months unteaching his reliance on AI. Just in time for him to leave.
I still have no idea if I made any measurable impact on his critical thinking and self-reliance. Sure as shit, he bullshitted all the things he did while he was here and all of the expertise he had (he in fact, did not) on his resume when I looked at his LinkedIn profile.. Expert detection engineer. He submitted a single rule to the ET ruleset the entire time he was here, and even that required heavy modification.
I was livid.
@da_667 @Viss @iagox86 @hrbrmstr after seeing the results of hiring one guy who was entirely reliant on LLMs, my policy is now one of "if my only choice is one of these people, then the only ethical course of action is to advise the company simply set the money on fire instead."
I've been burned enough that I absolutely will not sign off on someone who is clearly that unqualified and uninterested. There is no possibility of ROI - especially when the only raise is by jumping employers. -
@Viss @iagox86 @hrbrmstr fellas this was me last year interviewing interns. Some of the best schools in the country... and they were all caught using AI for their answers. Had to hire one of them. I spent over six months unteaching his reliance on AI. Just in time for him to leave.
I still have no idea if I made any measurable impact on his critical thinking and self-reliance. Sure as shit, he bullshitted all the things he did while he was here and all of the expertise he had (he in fact, did not) on his resume when I looked at his LinkedIn profile.. Expert detection engineer. He submitted a single rule to the ET ruleset the entire time he was here, and even that required heavy modification.
I was livid.
@da_667 @iagox86 @hrbrmstr in like 2018 when i wanted to go ceo mode and hire a replacement as the head of the redteam, i took in ~30-40 resumes, whittled than down to 10-12, ended up interviewing like 8 of them.
hired zero people
either people applied with grossly inadequate experience, or outright lied on their resume. i even caught one guy with fake offsec certs. he paid someone to take the tests for him.its horrible.
-
@da_667 @iagox86 @hrbrmstr in like 2018 when i wanted to go ceo mode and hire a replacement as the head of the redteam, i took in ~30-40 resumes, whittled than down to 10-12, ended up interviewing like 8 of them.
hired zero people
either people applied with grossly inadequate experience, or outright lied on their resume. i even caught one guy with fake offsec certs. he paid someone to take the tests for him.its horrible.
-
@Viss @iagox86 @hrbrmstr fellas this was me last year interviewing interns. Some of the best schools in the country... and they were all caught using AI for their answers. Had to hire one of them. I spent over six months unteaching his reliance on AI. Just in time for him to leave.
I still have no idea if I made any measurable impact on his critical thinking and self-reliance. Sure as shit, he bullshitted all the things he did while he was here and all of the expertise he had (he in fact, did not) on his resume when I looked at his LinkedIn profile.. Expert detection engineer. He submitted a single rule to the ET ruleset the entire time he was here, and even that required heavy modification.
I was livid.
-
@Dio9sys @da_667 @iagox86 @hrbrmstr worse - they used docker to light up kali once, and now theyre a combination devops, full stack dev, senior redteamer
someone in a signal chatgroup im in posted a link to some new popularity site for infosec influencers/grifters, and i investigated. its hosted on vercel, and the llm text instructions to generate the site content are in the sourcecode.
people self-label as a job they think is cool, and its all just lies
-
@Dio9sys @da_667 @iagox86 @hrbrmstr worse - they used docker to light up kali once, and now theyre a combination devops, full stack dev, senior redteamer
someone in a signal chatgroup im in posted a link to some new popularity site for infosec influencers/grifters, and i investigated. its hosted on vercel, and the llm text instructions to generate the site content are in the sourcecode.
people self-label as a job they think is cool, and its all just lies
-
@Dio9sys @da_667 @iagox86 @hrbrmstr i wish i could show you all the shit i pulled on the last assessment gig I did - they had stuff hosted in vercel, and i was able to loot the vercel token out of github via loose code perms and abusing actions, then once looted, theres no way to fix it other than to re-roll the api key. and vercel has bupkis for controlling api keys compared to aws. i had to propose an entire architecture change for their ci/cd pipeline to fix it
-
@Dio9sys @da_667 @iagox86 @hrbrmstr i wish i could show you all the shit i pulled on the last assessment gig I did - they had stuff hosted in vercel, and i was able to loot the vercel token out of github via loose code perms and abusing actions, then once looted, theres no way to fix it other than to re-roll the api key. and vercel has bupkis for controlling api keys compared to aws. i had to propose an entire architecture change for their ci/cd pipeline to fix it
@Viss @Dio9sys @da_667 @hrbrmstr For no particular reason, I'm thinking of this line:
I spent more time than I should have correcting fundamentals. Eventually I stopped. He was not, in any meaningful sense, on the other side of the conversation
Imagine doing a technical review and instead of reading feedback, they simply paste it into Claude. I'm not mentioning this for any particular reason of course
-
@Viss @Dio9sys @da_667 @hrbrmstr For no particular reason, I'm thinking of this line:
I spent more time than I should have correcting fundamentals. Eventually I stopped. He was not, in any meaningful sense, on the other side of the conversation
Imagine doing a technical review and instead of reading feedback, they simply paste it into Claude. I'm not mentioning this for any particular reason of course
-
@Viss @iagox86 @hrbrmstr fellas this was me last year interviewing interns. Some of the best schools in the country... and they were all caught using AI for their answers. Had to hire one of them. I spent over six months unteaching his reliance on AI. Just in time for him to leave.
I still have no idea if I made any measurable impact on his critical thinking and self-reliance. Sure as shit, he bullshitted all the things he did while he was here and all of the expertise he had (he in fact, did not) on his resume when I looked at his LinkedIn profile.. Expert detection engineer. He submitted a single rule to the ET ruleset the entire time he was here, and even that required heavy modification.
I was livid.
@da_667 @Viss @iagox86 @hrbrmstr Security is not an entry level position, probs a bit reductive, but at some point people do need to hire juniors. Everyone wants the unicorn. Ya'll. The people with years of experience, but for a bargain, the price of a junior. Nobody wants to be the one to glue a horn to a horse, they don't want to train a junior so they don't suck. Even if it's part of the job. This isn't unique to security. This is an epidemic of not hiring. Across multiple disciplines. An HR problem. At some point the would be juniors, fresh out of school, adapted and that meant fudging the resumes. Gotta put bread on the table somehow, those student loans aren't going to pay themselves and it's not like you can just go back to school. The system forced them to fake it till they make it, and so they're using the fake it till you make it machine. Break the cycle maybe?
