Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

11–20 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#11
post #4

I think soon that this sentiment will start to apply to Universities. It seems inevitable at some point in the near future there will be an online 'university' (for lack of a better word) who's graduates will be considered equal or even better than a standard university education, particularly for tech related degrees. Universities have been a centralized source of accreditation for a long time. All it takes is for s…

That's exactly why a lot of bootcamps have come into existence, along with a guaranteed job in the industry at the end of it. Though many employers hire university grads as a sort of "signal" for people who can work hard, think critically, finish what they started etc. And I'm not saying one is better then the other, just noticing this trend of bootcamps popping up everywhere to replace university CS/CE education.

Re: Security Certifications Are Causing More Harm Than Good

#12
I was involved once in a criminal forensics case. The defense's "expert" witness was a one man computer shop. He had created his own "certifications" and listed them on his resumé as indications to the court of his suitability as a witness.

It was literally "person's-company-name Certified Forensic Examiner".

He had created about 6 certifications, all of which he held.

It's kinda funny, but also kinda scary that the court accepted this as proof of his qualifications. The prosecution never raised an objection to it either.

Re: Security Certifications Are Causing More Harm Than Good

#13
There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being secure. The problem most IT people have is thinking that certs address technical issues, when in fact they address business issues.

Re: Security Certifications Are Causing More Harm Than Good

#14
post #4

I think soon that this sentiment will start to apply to Universities. It seems inevitable at some point in the near future there will be an online 'university' (for lack of a better word) who's graduates will be considered equal or even better than a standard university education, particularly for tech related degrees. Universities have been a centralized source of accreditation for a long time. All it takes is for s…

> near future there will be an online 'university' who's graduates will be considered equal or even better than a standard university education

http://www.uoc.edu since 1994

Re: Security Certifications Are Causing More Harm Than Good

#15
> "Recruiter Thomas Ptacek, whose Chicago-based agency Starfighter specializes in recruiting security folk"

   NET::ERR_CERT_DATE_INVALID
   Subject: www.starfighters.io
   Issuer: Go Daddy Secure Certificate Authority - G2
   Expires on: Nov 13, 2016
   Current date: Apr 12, 2017
Is there some infosec version of Muphry's law?

Re: Security Certifications Are Causing More Harm Than Good

#16
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

Especially if the person comes from the government. CEH is garbage, but it's also a cert the US gov selected.

Re: Security Certifications Are Causing More Harm Than Good

#17
So the article alluded to reading books and hacking on your own. But for those who need some sort of curriculum, progress bar, or structure, what would HN recommend to get to some sort of level of competency in the infosec field (like intermediate level/beginner-advanced).

Re: Security Certifications Are Causing More Harm Than Good

#18
So the article alluded to reading books and hacking on your own. But for those who need some sort of curriculum, progress bar, or structure, what would HN recommend to get to some sort of level of competency in the infosec field (like intermediate level/beginner-advanced).

Re: Security Certifications Are Causing More Harm Than Good

#19
I joined the workforce at the same time that people were realizing that certs were a joke. That both hurt and helped me, as people hired me based on talent, and not a piece of paper.

But I wasn't in management, and I've since learned how very little technical skill you actually need to be an effective manager, and now I realize that certs are a great way for a manager to understand a complete baseline of the concepts needed for a particular field.

A manager does not need to be a hacker, but they need to understand a baseline of security concepts. That's what certs are really useful for.

Re: Security Certifications Are Causing More Harm Than Good

#20
I wanted to get my consulting company into PCI auditing and you need certifications to do that. One problem with the certifications is they aren't actually skill based.

I wouldn't be able to get one despite having experience because:

For several of them it requires years of work experience with a specific job titles (your job needs to be security, it can't just be part of your job) and the continuing education credits are expensive and largely not helpful.

I would love if there was a recognized certification that was actually interested in proving your skills not for making money.

I know other disciplines are the same way.

They don't really serve to keep unskilled people out, they serve as kind of an elite paywall where you need time and money to break through. And breaking through is largely an exercise in brute force not in skill.

Post reply on HN