>>539314
Let me just expand on how much I hate the security industry
>Get hired by company due to knowledge of UEFI/EFI
>Get shoved on contractor job
>Hired to work on "persistence"
Some background. The "company" I work for does its work in an offensive manner. It needs a something called a bootkit. Essentially a bootkit is a bot that lives in ring -1 (bios) and can persistently inject itself into the other layers between wipes and reinstalls. They have been chasing this magic fairy bootkit for years. Rootkits have been a thing for a while, but there are only a few good ones (for example, ours is literally a copy paste from crabs and some lines from powerloader for injection, if you know what those are).
>Immediately get shoved onto team
>Half the team is lawyers who are constantly lording over if x/y/z thing is ethical
>I say ethical and not legal, because everything we did was entirely legal
>next forth of the team are diversity hires who don't do shit for the actual project
>they mainly code the C&C server, and the servers that proxy to it, which is an easy as shit job
>I and three other guys are the only ones who do the real heavy lifting
>Start figuring out that you can store shellcode in NVRAM, and start making some good prototypes for the duders
>literally write all the articles on how to replicate this shit for the confluence wiki
>dev group makes a new project on specifically NVRAM
>one of the retarded diversity hires goes to the boss and presents my work as his
>he gets to lead the project
>half way through he promotes me to one of the lead dev positions because he has no idea what he is doing
>eventually a decent prototype is made
>lawyer shoves his cock through the door
>"IS ANY OF THIS ETHICAL!!!!!/?!/!??!?!/??!?!?!?!?!??!"
>mfw you literally just asked us to write a bootkit
>mfw this whole project was unethical from the start
>mfw they scrap the project, and I just wasted like 4 years of my life
The only upside to all of this shit is that the guy who was the head of the project took the fall for everything, and I ended up getting promoted. There is cool shit in this industry, not going to lie, but at the same time infosec/intanl is often misunderstood and mismanaged (at least in my experience).