Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

51–60 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#51
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

> There's no reason someone can't have both skills and certifications

Of course you're right that it's not impossible. But here's why it happens anyway and why the heuristic of them being roughly mutually exclusive is not insane:

1. There's a certification that's nearly meaningless because it's so easy to obtain without also having the relevant expertise that the certificate is supposed to represent.

2. People who are actually good at the thing will notice the certificate doesn't measure the skill correctly, and will also note that there are people in the world with this certificate who don't know the skill.

3. Those experts will not use the certificate when they hire people, and will not get the certificate since it doesn't work and no one who is an expert is using it to hire anyway.

4. Meanwhile, there are basically only two groups that care about the certification:

> a. People who are clueless: a clueless hiring manager who doesn't understand the domain they are hiring for so they are looking for cheap proxies for skill and experience. Clueless wannabe professionals who don't understand the domain or the industry enough to have been in the expert group above but who are still looking for jobs in the field. Clueless clients who are impressed by the certification because they don't know any better.

> b. The people who are taking advantage of the clueless clients: Professionals and hiring managers who know very well that the certification is worthless, but who use it for sales and marketing anyway because it mollifies clueless clients.

If that trend holds, then you have a signal (the certification) the repels experts, while attracting the clueless and those who would exploit them.

So when you find someone in the world with that certification, you should expect on average for them to be clueless or preying on the clueless. That's why treating it as mutually exclusive isn't insane heuristically, even though it's not impossible that someone who is good also has a certification.

Re: Security Certifications Are Causing More Harm Than Good

#52
post #44
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

There's both some truth and some falsehood to the 'certifications don't prove anything' argument: Answer a multiple choice test for an MCSE or whatever? Doesn't prove much. Receive a server that's been wrecked and won't boot, turn it into a load balancing HTTPS server, SMTP server, a bunch of required cron jobs and a boat load more requirements for RHCE? Proves you can do those things. Disclaimer: used to work at Red…

I'd agree that the problem isn't so much that certification has to be bad, but that bad certifications (e.g. those that examine though purely multi-choice) aren't appropriate/good for the industry...

For me the answer is better certifications.

Re: Security Certifications Are Causing More Harm Than Good

#53

From most people I talk to, the exception is the OSCP since it requires you to actually pop real, live boxes. Anyone holding that cert has actually exploited a buffer overflow, escalated privileges, etc. CEH, CISSP, etc are just too theoretical with no hands-on requirements.

It's a joke as well, and it just means the holder could copy and paste an XP-era exploit, which has roughly no relevance today.

OSCP is a bit more than that to be fair, you're not going to pass with copy/paste of existing exploits.

Re: Security Certifications Are Causing More Harm Than Good

#54

Having a 1-2 certifications on a specific domain means that we speak the "same language" regarding our work. Red flag: someone that has an email signature with 50 letters next to his/her name,there is NO WAY someone is spent enough time on each: coding, security, audit, accountancy, at the age of 30 AND be proficient in all these domains.

I run into this issue on my resume. Do i throw random skills i spent 4 months learning for some project and never used again? I feel like overloading these things devalues the skills i actually AM exceptionally competent at, as opposed to just capable.

My advice? Remember that your resume goes through at least 2 filters, HR and IT.

What happened was:

IT boss: "we need to hire a coder"

HR: "What skills?"

IT Boss: "Oh, Foo language. But if they're a good coder they can pick it up, so just a good coder"

HR: "...you're kidding, right? There are millions of resumes out there, most from people with no skills just trying to land a great job. Give me enough to filter"

IT Boss: (provides list of three things)

HR: "This still isn't enough. Practically EVERYONE will have these. Give me years of experience, skillsets, processes, etc.

IT Boss: "Fine, here" (gives long list of things that MAY be useful)

HR: (starts filtering resumes based on these words, removing lots of good people and including lots of bad people)

IT Boss: (looks at resumes) "These people are clearly lying and all over the place, I'm going to focus on one or two things to decide who to interview"

So in writing your resume, you want to make sure you have the buzzwords for the job to get past HR. These buzzwords are pretty much guaranteed to be on the job listing, even if they end up not being very essential to the job. Did they mention Scrum? Better have it on your resume, because you may be filtered out if it isn't, even if it's something you'd not consider worth listing. Also, use the same words. I once was asked if I had "shell experience", even though BASH was on my resume. I assume "Agile" and the various implementations are the same. If they mention XP, you better mention XP.

BUT when your resume then makes it to IT, who (1) know what these words mean and (2) aren't looking for the same things at all, you need to have what they want. I tend to use a sidebar on my resume to capture the HR buzzwords, and emphasize my work experience in the main body, so an IT person skimming it will see what they want to see.

One technique I've taken to handle HR buzzwords on things that I don't think are actually a big deal: If the job listing says "Must know React, Angular, Backbone, or other JS frameworks" and I wasn't really strong in any of them, I'd do enough research and testing coding to do a Hello World in them, then add "Exposure to Foo, Bar" on my resume. It tends to get through HR (word is present!), and I'm not lying to the IT people - they understand that I'm not claiming expertise, but I'm also saying I'm willing to give it a go.

As a corollary to all of this, you need to tweak your resume for every job posting, to match their buzzwords and remove ones they didn't list that aren't really core to your skills.

Re: Security Certifications Are Causing More Harm Than Good

#55
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

Nope, it is in fact the certifications. Strongly agree with the tptacek quote here.

So how would you approach scaling the IT Security industry without some form of industry certification process?

I'm definitely not trying to defend the CISSP/CEH style certs here but I don't see how you reliably expand the industry at scale without some form of certification process.

A company hiring it's first security person or a company trying to hire a lot of security people, need some form of base benchmark to work from, just like with most other professions (e.g. Law, accountancy, architecture etc)

Re: Security Certifications Are Causing More Harm Than Good

#56

I'm going to partially disagree with the article. the problem with the approach of "just learn to be a good security person" is that it doesn't scale. Sure back when I, and a lot of other people who are a bit older, learned security that was the only option, there weren't structured courses and certifications. However when we're working at scale, certifications can be useful as providing a demonstration that the hold…

The only certifications I've picked up so far along my industry journey (I have no college degree and don't plan to get one, so these are necessary) are the Redhat RCSA and RHCE. Both of these certs can't be solved with rote memorization, and required me to log into a virtual machine and solve problems in a live environment, running through a plethora of common systems administration tasks that were then graded by how well I accomplished the requirements. Often the requirements were vague enough that I had to do some digging.

There was no real memorization needed, and I had the full man pages of the operating system at my fingertips, but the time limit ensured that I needed to have at least a certain degree of proficiency with each tool to finish all of my tasks before the end of the exam.

I assumed this was the norm with certifications, but the comments here strongly suggest that it is not. Are Security Certifications really multiple choice questions without any practical applications? That seems like it could stand to be improved greatly.

Re: Security Certifications Are Causing More Harm Than Good

#57

Earlier quoted context omitted.

Nope, it is in fact the certifications. Strongly agree with the tptacek quote here.

So how would you approach scaling the IT Security industry without some form of industry certification process? I'm definitely not trying to defend the CISSP/CEH style certs here but I don't see how you reliably expand the industry at scale without some form of certification process. A company hiring it's first security person or a company trying to hire a lot of security people, need some form of base benchmark to w…

What does "certification" have to do with scaling the industry? Training and nurturing talent is a hard problem, but expensive tests don't do anything to mitigate that problem.

Re: Security Certifications Are Causing More Harm Than Good

#58

I'm going to partially disagree with the article. the problem with the approach of "just learn to be a good security person" is that it doesn't scale. Sure back when I, and a lot of other people who are a bit older, learned security that was the only option, there weren't structured courses and certifications. However when we're working at scale, certifications can be useful as providing a demonstration that the hold…

You're presenting a false dichotomy. The choice isn't between "security certification" and "people learning on their own".

Re: Security Certifications Are Causing More Harm Than Good

#59
Every comment seems to be about whether the certs demonstrate anything but this article says, "a job description requiring a CISSP was a warning flag to industry elite not to apply."

In other words: if the company asks for certs it's the equivalent of wanting "6 years of react.js experience". I completely agree.

Re: Security Certifications Are Causing More Harm Than Good

#60
post #6

There's 'compliance security' and then there's 'street-smart security'. They are very different things. Most organizations aim for compliance (it's cheap and easy). They base security on contracts, certs and insurance policies. Street-smart security practitioners are appalled by this. And, management doesn't understand why the 'security people' aren't on-board with 'compliance'. It's a lot like the old west with Cowb…

Pretty sure you hit it on the head. Over time, security breeches should alleviate this gap.
Post reply on HN