Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

31–40 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#31
post #4

I think soon that this sentiment will start to apply to Universities. It seems inevitable at some point in the near future there will be an online 'university' (for lack of a better word) who's graduates will be considered equal or even better than a standard university education, particularly for tech related degrees. Universities have been a centralized source of accreditation for a long time. All it takes is for s…

That's exactly why a lot of bootcamps have come into existence, along with a guaranteed job in the industry at the end of it. Though many employers hire university grads as a sort of "signal" for people who can work hard, think critically, finish what they started etc. And I'm not saying one is better then the other, just noticing this trend of bootcamps popping up everywhere to replace university CS/CE education.

anecdotally most people I know who have gone through bootcamp have had major issues getting hired and the ones that did were hired into support/saleseng rather than software engineering.

Re: Security Certifications Are Causing More Harm Than Good

#32
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

What you are saying points out problems with contracts, audits, HR. Audits are supposed to meaningful. They aren't supposed to be a waste of time that exists to check off a box. HR is supposed to add value, not subtract. Counterparties should ask for things in contracts that actually benefit them.

From a certain point of view you are right -- an IT manager should cooperate with other facets of the business in order to help the organization succeed, not obstruct because he thinks their requirements are dumb. But from a larger point of view, either organizational or super-organizational, dumb requirements shouldn't exist. To the extent that they do CEOs, industry groups, and/or governments should be modifying them to keep them relevant.

Re: Security Certifications Are Causing More Harm Than Good

#33
post #27

It's the oldest story in tech, certs are "worthless" but look at almost any infosec job posting and you'll see: Ideal candidate will have CISSP, OSCP, CEH, SSCP, WTFBBQ, etc etc

That is because most of these job postings are written by HR who have no other tool to filter successful candidates.

Oh, I know, it's a sick loop. I guess the only way to play is to have two versions of your resume, one with the certs and one without.

Re: Security Certifications Are Causing More Harm Than Good

#34
post #27

It's the oldest story in tech, certs are "worthless" but look at almost any infosec job posting and you'll see: Ideal candidate will have CISSP, OSCP, CEH, SSCP, WTFBBQ, etc etc

That is because most of these job postings are written by HR who have no other tool to filter successful candidates.

[deleted]

Re: Security Certifications Are Causing More Harm Than Good

#35

Having a 1-2 certifications on a specific domain means that we speak the "same language" regarding our work. Red flag: someone that has an email signature with 50 letters next to his/her name,there is NO WAY someone is spent enough time on each: coding, security, audit, accountancy, at the age of 30 AND be proficient in all these domains.

>Having a 1-2 certifications on a specific domain means that we speak the "same language" regarding our work.

Or it means they can drop the same jargon and have maybe a passable understanding about the ideas that jargon is meant to convey.

Often people with extremely narrowly focused bases on knowledge (as indicated by having BAs, MAs, and a giant rap-sheet full of certs all in the same topic) have wound up being thoroughly incapable of actually applying any of their knowledge to the benefit of the team they're on because they just don't know how to get what's in their heads into the heads of people who weren't steeped in the same language as they were.

Re: Security Certifications Are Causing More Harm Than Good

#36

Having a 1-2 certifications on a specific domain means that we speak the "same language" regarding our work. Red flag: someone that has an email signature with 50 letters next to his/her name,there is NO WAY someone is spent enough time on each: coding, security, audit, accountancy, at the age of 30 AND be proficient in all these domains.

I run into this issue on my resume. Do i throw random skills i spent 4 months learning for some project and never used again? I feel like overloading these things devalues the skills i actually AM exceptionally competent at, as opposed to just capable.

Re: Security Certifications Are Causing More Harm Than Good

#37
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

Especially if the person comes from the government. CEH is garbage, but it's also a cert the US gov selected.

I had to get the CEH when I was hired on by a security consulting firm back in Northern Virginia.

I now do not include this cert on my CV for (perhaps irrational) fear that someone in some HR department may think "Oh, no! This guys is a hacker!" Sadly, the word has a negative connotation, because the word "cracker" or "bad actor" never bubbled up past the IT security world.

I also do not include my military service dates, as they reliably peg my age. Most men join at 17 or 18, so they would immediately know my age.

I'm debating whether to include any certifications at all, just include my degree.

Re: Security Certifications Are Causing More Harm Than Good

#38

Having a 1-2 certifications on a specific domain means that we speak the "same language" regarding our work. Red flag: someone that has an email signature with 50 letters next to his/her name,there is NO WAY someone is spent enough time on each: coding, security, audit, accountancy, at the age of 30 AND be proficient in all these domains.

I run into this issue on my resume. Do i throw random skills i spent 4 months learning for some project and never used again? I feel like overloading these things devalues the skills i actually AM exceptionally competent at, as opposed to just capable.

Are they relevant to the position?

I'd keep them if they are and lose them otherwise.

Re: Security Certifications Are Causing More Harm Than Good

#39

From most people I talk to, the exception is the OSCP since it requires you to actually pop real, live boxes. Anyone holding that cert has actually exploited a buffer overflow, escalated privileges, etc. CEH, CISSP, etc are just too theoretical with no hands-on requirements.

It's a joke as well, and it just means the holder could copy and paste an XP-era exploit, which has roughly no relevance today.

Re: Security Certifications Are Causing More Harm Than Good

#40
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

Technology changes so fast that most of this tests are obsolete by the time you take them. The best technologists rely on their knowledge, so they spend their time and efforts staying current. On the other hand, you have weak applicants who know a certification is their only way to a job so they put their efforts into it.
Post reply on HN