DEV Community

Discussion on: I'm a security auditor and researcher, Ask Me Anything!

Collapse
 
ondrejs profile image
Ondrej

I see you bio, and I have to admit that we have same interests. I do information security training for few investigative journalists but it does not earn me any money, so I have to do SW development (mainly in Kotlin) for living.
My question is do you earn enough (in infosec field) to focus only on those issues? Or have you some other job?
Also I understand the importance of anonymity in some cases, but do you think that TAILS is really way to go? IMHO it has extremely high threat model, I would rather to suggest solution like this one .
Thanks for what you do though, you focus on right issues and we need more people in this field!

Collapse
 
ondrejs profile image
Ondrej

Ah, I forgot second question - if you use Debian, do you use Testing (Unstable) version? If yes, do you patch your kernel with grsecurity patches? I have tried in in the past but it was nightmare in terms of maintenance and some binaries did not even work.
Don't you think that CentOS (which has SELinux by default) would be safer in case if you don't use kernel hardening patches? Thanks!

Collapse
 
terceranexus6 profile image
Paula

Hello Ondrej, thank you for your answer!

I'm happy to meet other DEV user interested in security. Regarding your question, yes, I can manage to earn fairly enough for a living working exclusively in security, I'm currently switching the company I work for, but yes I do.

I think Tails is interesting in some cases, such as outside home, when you don't have your laptop available at the moment or something, like a lifesaver. The option you suggest is better for home setup, of course! and thanks for sharing btw, the repository is interesting.

Thank you!

Collapse
 
ondrejs profile image
Ondrej

I would highly recommend to go through other Shawn's repositories and articles - they are very interesting, especially if you are interested about Tor. It is *BSD focused though, but you can do almost same things on Linux.