Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

21–30 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#21

So the article alluded to reading books and hacking on your own. But for those who need some sort of curriculum, progress bar, or structure, what would HN recommend to get to some sort of level of competency in the infosec field (like intermediate level/beginner-advanced).

Others will likely have more informed opinions, but here's some stuff:

Book: Web Application Hacker Handbook http://www.wiley.com/WileyCDA/WileyTitle/productCd-111802647...

I've seen it highly recommended and if you're not familiar with the field it's a good overview of exploit types for web apps.

Online training for free or cheap: Cybrary - mostly okay, but free.

PluralSight - https://www.pluralsight.com/browse/it-ops/security

Coursera has a Cybersecurity Fundamentals specializationd that's pretty good - https://www.coursera.org/specializations/cyber-security

Other books, if you wanted to go down the reverse engineering route:

Assembly Language Step-by-Step: Programming with Linux

The IDA Pro Book (for the strangely hard to buy IDA Pro, but the free version is pretty good)

Practical Malware Analysis

Re: Security Certifications Are Causing More Harm Than Good

#22

> "Recruiter Thomas Ptacek, whose Chicago-based agency Starfighter specializes in recruiting security folk" NET::ERR_CERT_DATE_INVALID Subject: www.starfighters.io Issuer: Go Daddy Secure Certificate Authority - G2 Expires on: Nov 13, 2016 Current date: Apr 12, 2017 Is there some infosec version of Muphry's law?

Starfighter is defunct. https://twitter.com/tqbf/status/771533037666390017

Re: Security Certifications Are Causing More Harm Than Good

#23
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

Yeah, when I started years back I had the Security+ as it was a requirement by my university at the time. During an interview I had the technical manager ask me about it and openly wonder why I would waste my time with such a useless certification. I didn't get that job, and I still wonder if it's because he thought less of me because of a certification I was required to obtain in order to graduate.

I leave my certifications off my resume now, unless the job posting asks for certifications which is frustrating trying to decide if adding this cert to my resume will help or hurt me in the interview.

Re: Security Certifications Are Causing More Harm Than Good

#24
From most people I talk to, the exception is the OSCP since it requires you to actually pop real, live boxes. Anyone holding that cert has actually exploited a buffer overflow, escalated privileges, etc. CEH, CISSP, etc are just too theoretical with no hands-on requirements.

Re: Security Certifications Are Causing More Harm Than Good

#26
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

The problem is people outside the field of whichever cert pile into them as a means to break in, so the median cert holder winds up being inexperienced and overall unqualified. The cert itself then becomes associated with that. You're not wrong that its silly to be biased against, in the larger context of someones qualifications, but only certs that are sufficiently exclusive will get any respect and that probably isn't going to change.

Re: Security Certifications Are Causing More Harm Than Good

#27

It's the oldest story in tech, certs are "worthless" but look at almost any infosec job posting and you'll see: Ideal candidate will have CISSP, OSCP, CEH, SSCP, WTFBBQ, etc etc

That is because most of these job postings are written by HR who have no other tool to filter successful candidates.

Re: Security Certifications Are Causing More Harm Than Good

#28

So the article alluded to reading books and hacking on your own. But for those who need some sort of curriculum, progress bar, or structure, what would HN recommend to get to some sort of level of competency in the infosec field (like intermediate level/beginner-advanced).

Others will likely have more informed opinions, but here's some stuff: Book: Web Application Hacker Handbook http://www.wiley.com/WileyCDA/WileyTitle/productCd-111802647... I've seen it highly recommended and if you're not familiar with the field it's a good overview of exploit types for web apps. Online training for free or cheap: Cybrary - mostly okay, but free. PluralSight - https://www.pluralsight.com/browse/it-o…

Bear in mind that IT security goes far beyond something with a processor in it.

There are physical access controls, personnel assessments, probability and impact assessments, budgeting, people-monitoring, process analysis and modelling...

Computers are a tiny part of it. This being HN I have understanding for the bias though.

Re: Security Certifications Are Causing More Harm Than Good

#29
post #22

> "Recruiter Thomas Ptacek, whose Chicago-based agency Starfighter specializes in recruiting security folk" NET::ERR_CERT_DATE_INVALID Subject: www.starfighters.io Issuer: Go Daddy Secure Certificate Authority - G2 Expires on: Nov 13, 2016 Current date: Apr 12, 2017 Is there some infosec version of Muphry's law?

Starfighter is defunct. https://twitter.com/tqbf/status/771533037666390017

Well that's less fun. They had just started too.

Re: Security Certifications Are Causing More Harm Than Good

#30
Having a 1-2 certifications on a specific domain means that we speak the "same language" regarding our work.

Red flag: someone that has an email signature with 50 letters next to his/her name,there is NO WAY someone is spent enough time on each: coding, security, audit, accountancy, at the age of 30 AND be proficient in all these domains.

Post reply on HN