What is extremely frustrating is the rise of "cyber security" Masters degrees. The vast majority of these people have never written a single line of code. They don't understand security, because they can't understand the underlying logic in the code. They just write documentation to meet certain outside standards, and have no idea what I'm talking about when I talk about our security posture. They genuinely think tha…
Well if that's the case, then times are changing ;) I study at the VU University of Amsterdam and took a couple of courses from the security master track. I had to use libnet to create my own custom TCP/IP packets, libpcap to listen to incoming packets (tcpdump for debugging). Obviously, I did a SQL injection, cross site request forgery, cross site scripting and debugged malware with IDA Pro and later (when it was sa…
I work for the National Satellite Operations Facility (NSOF.)
Neither my boss nor the three dozen or so "cybersecurity" folks with whom I've worked have ever written a line of code.
Also, everything you said in the first two paragraphs I either already knew from actual networking security courses, or are trivial. SQL Injection, CSRF, and dynamic executable analysis are unfortunately... Not the most modern techniques... Might as well teach naked buffer overflows.
That said, it's a decent basis. And far far better than what's emphasized on this side of the pond (Mostly policy and automated scanners.)
If what you're saying is truly reflective of "cyber" degrees across the EU, here it's far worse.
It's very frustrating to explain a DNS tunnel to these people, much less how to find a zero day in Cisco IOS.
Occasionally you'll get a hobbyist with some Python or C under their belts, but the vast majority of these "cyber" guys really should just read a book on Kali Linux and sing campfire songs in class for the rest of the year.
Right now these degree programs are turning out graduates that think running Nessus makes them a security god.
Things may well be different in Europe (I'm not going to lie, the Trident and PIN projects sound pretty cool), but it's a nightmare over here.
If you're ever in DC, look me up, we'll have lunch, I'll give you a tour of the facility, and I can introduce you to the cyber guys, and let you draw your own conclusions.
That's a pretty open invitation by the way. Any devs, start up folks or "cyber" people (that won't freak out my girlfriend) are welcome to crash in our guest room for a night or two, if you're in DC for a conference or something.