Yes, it's been an often-discussed topic in Norwegian media in later years:
"Lack of security-professionals."
Well, as commented in this (Norwegian) article, BY a security-professional; there seems to be a lack of security-oriented IT professionals, but, not because they aren't there at all. They are. What is seriously lacking in this scenario, is competence in recruiting firms looking for this kind of competence. Always has been.
Computer-security is not a fixed-set field, AT ALL. Even though a lot of so-called "professionals" seem to be stuck on the idea that it is.
Serious professionals wanting to work in this field on the other hand, are (often) painfully aware of what it actually entails to do so:
- constant refreshing on networking- / computing- / vulnerability-security in IT
- vulnerability-monitoring of often-used software in the company
- a simple awareness of the fact that: nobody is ever 100% secure
These points are often completely missed by recruiters. They don't look for ability / knowledge / flexibility, they often tend to only look at academic degrees (preferably multiple(!)), gender, published articles / blog-posts and other non-related (and often quite unrealistic) demands for the position(s) in question.
Then, they complain about not finding any candidates for their outrageous requirements.
Seriously, re-define your demands / requirements to a more realistic degree, maybe you'll find a competent person to do the job. But you most certainly will NOT find the dream-candidate with the kind of demands currently set as standard.






You're wrong and probably never worked for a software company.
Software versions are charactized by version numbers, in my case, when I worked for Bentley Systems, a version was designated by numbers like 05.07.01.22.
Software, like Firefox makes versions for Windows and Linux among others. Basically the core parts of the program operate in the same manner and the API is different to work on Linux and adjustments are made for libraries, directories, etc.
The dirty little secret here at ZDNet and among the shills is that they blame an application for allowing an intrinsic problem or vulnerability with the OS to be accessed. Shills, Ed, and ZDNet are great at blaming the application, such as Chrome or Firefox for the problem and not addressing the core Windows vulnerability. Then, they read documentation and without knowing anything about how things are done, blame the Linux counterparts, because they are listed.
The problem is that items present in the application allow the core Windows vulnerability to be used to infect Windows. The application issue may also be present in the Linux version, but because Linux is so much more secure than Windows, there is no problem or infection with Linux. The only way Linux could be infected is if the malware could read the mind of the user and get his password.
Developers review the Windows version issue and make adjustments so it does not allow the Windows vulnerability to be addressed and also make the change across the board to all sister versions to maintain consistency. Because you are naive and see Ubuntu listed as affected, it does not mean Ubuntu ever had a security issue at all, the Ubuntu version is just having the code changed for consistency. In other words, no application for Windows is ever going to fully prevent all the Windows critical flaws from being accessed. Those application characteristics causing the Windows issues may be present the Linux version, but can't be used to attack Linux, but are being changed anyway. In most cases, the change may be an operating improvement and be more efficient.
It's so silly to ZDNet pull the same BS over and over again, year after year. If you want to believe it, you are only following the ZDNet propaganda trail, Do yourself a favor, pour yourself a strong one, and install Ubuntu or Mint on a second machine, run it as a Live DVD, or install it as a dual boot and your primary computer. Then, install, Chrome, Opera or any other open source program you like and try to get infected. Then come back here and post the Website and how you got infected. That's something that no one, in all these years of accusations has ever been able to do. Once you see that you don't get infected you;ll begin to see how ZDNet twists information and is just a stooge for Microsoft.
As far as you referencing Linux Torvalds and the linux.com issue it was related to stolen passwords. Anyone who gets poorly secured passwords an attacks a system can't be stopped. Most times the admins are storing their login information on a Windows box, that gets easily hacked by a zero-day or a crafted emai that allows access. Remember the big ZDNet push for articles about Google, which runs 100% Linux getting hacked? Well, two Chinese employees were storing data on a Windows notebook and it easily got hacked. Since then, Google forbids employees from using Windows or work. you don't hear about that anymore here, do you? Forbidding employees to do company work on Windows is the single most important any manager can make.
If you dig deeply into these articles against open source and Linux, you will find, as I have, that the core problem is Windows and you will see a critical update down the road, at a later time to silently correct the Windows problem. But that is never brought up here.