Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

71–80 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#71
Many certifications are worthless, but I would argue that not all of them are.

I learned more useful, practical concepts and skills by taking a couple of SANS courses than I did in four years of a CIS program at a University. Both my university classes and the SANS courses consisted of books, presentations, lectures, and individual or group assignments/labs. If they are taught the same as a university course, why is it automatically considered inferior? SANS teaches a lot of tools, but they also teach the underlying concepts to prevent people from becoming dependent on tools. In some subjects, it would be insane to not teach tools. For example, I took the GREM (Malware Analysis) course. Its an very basic course, but it would be foolish for anyone to teach a course about reverse engineering or malware analysis without using IDA or OllyDBG.

While the class won't (and doesn't claim to) turn someone into a professional-level reverse engineer, this course helped me understand a few things about assembly that I just wasn't comprehending when I used other sources.

Would I attempt to use my GREM as justification for applying to a malware analysis job? Of course not, but the course has helped put me on the right path. Its possible many people learned through another, far less expensive method, but that doesn't mean the training was worthless.

If I were hiring someone, I wouldn't use certifications as a sign that they are qualified. However, I would use the certifications listed on their resumes, combined with their work experience, to figure out what kinds of questions I should ask them.

I also wouldn't use certifications or a lack of certifications to disqualify a person. Using your anecdotal evidence of bad experiences with certified people to label all of them as incompetent is ignorant.

Re: Security Certifications Are Causing More Harm Than Good

#72

Earlier quoted context omitted.

So how would you approach scaling the IT Security industry without some form of industry certification process? I'm definitely not trying to defend the CISSP/CEH style certs here but I don't see how you reliably expand the industry at scale without some form of certification process. A company hiring it's first security person or a company trying to hire a lot of security people, need some form of base benchmark to w…

The problem is one of trust, methinks. Most certs require only that you "know" the material well enough to pass a test that uses your memory. If the tests were empirical, say like the Red Hat tests or the Cisco CCIE, then the trust that someone actually has skills might be more believable. Having worked in IT security for many years, I can attest to the fact that IT security is more of a subjective set of processes r…

Yep the problem is that some of the well known certs are bad, not that the concept of IT security certifications are bad.

I've been in IT/Infosec for 17 years now. I have certs that I literally maintain as a HR/sales checkbox (e.g. CISSP) and certs that make me think every time I need to refresh them (e.g. CREST CCT). It's possible to have good IT sec. certs.

Re: Security Certifications Are Causing More Harm Than Good

#73
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

> There's no reason someone can't have both skills and certifications Of course you're right that it's not impossible. But here's why it happens anyway and why the heuristic of them being roughly mutually exclusive is not insane: 1. There's a certification that's nearly meaningless because it's so easy to obtain without also having the relevant expertise that the certificate is supposed to represent. 2. People who ar…

This is a great comment to illustrate grandparent's point that irrational hate of certifications permeates the industry. Many certifications under discussion here are meant to assist at the entry-level. That's what the certificate is "supposed to represent". That's what skill the certificates "measure correctly." That's the 3rd group of people who care: people operating at or near the entry level.

It is no surprise that experts hiring experts in any field couldn't care less about certifications (aside from ones required by regulation). At the expert level, you hire real, verifiable experience.

Re: Security Certifications Are Causing More Harm Than Good

#74
I think the point is more that security certifications CAN be worthless and you don't NEED them, but that doesn't make them inherently bad/worthless. I think the author's argument should be that the industry has begun to rely on them too heavily for vetting. That makes sense though because it can be very difficult to vet the skills of a client. The hiring process is very time consuming so if you see two candidates and one has "proven" they at least have some baseline skill in an area then they will lean on that for decision making in the same way they look at education or self reported experience.

Experience on a resume is self reported so that is an even worse indicator of skill than a cert. At least one of those two involved external validation by a 3rd party.

I think there are a few good ones out there and getting them ensure the person has at least a baseline knowledge of some subject. I have worked in the industry for years as a pentester, but I still went and got my OSCP and OSCE for fun. A lot of it was review, but it was nice to fill in some gaps and practice things I hadn't had as much experience with.

Certs are like college degrees, you can get by without them, but it can be easier if you have them. You will probably learn some things along the way and the provide a foundation for later studying or pursuit. You don't NEED them, but you don't need a lot of things in life, that doesn't make them worthless.

Re: Security Certifications Are Causing More Harm Than Good

#75
I don't really go along with this post. I think the title is a good eye-catcher, but inaccurate. Terry seems biased toward working on the cutting edge of embedded firmware and I agree that is really important work. I also agree that a certification like the CISSP (I have one of those) won't prepare you for that sort of work.

I'll wildly speculate that some potential Tactical Network Solutions customers are asking about DoD 8570.1 security certifications. That may be a mistake on their part for something as far down in the weeds as embedded firmware solutions or the Centrifuge IoT Security Platform.

On the other hand, some of Terry's customers likely hold those 8570.1 certifications, so he might want to be careful about rubbing in how they wasted their time in acquiring them.

If he takes a look at SI-7 in the System and Information Integrity control family (found in NIST Special Publication 800-53) he might find some selling points for his products. A certified security engineer who had done a RMF audit would know that ;)

Re: Security Certifications Are Causing More Harm Than Good

#76
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

nice to see OSCP still regarded well. I got it about a decade about when our CTO had an initiative that everyone doing customer interaction (R&D team + professional services support for me at the time) should have a cert.

I vehemently disagreed, pointing out that those of us with meaningful degrees from well regarded programs shouldn't have to get one, but in the end I complied to keep the peace.

Have to say I enjoyed it at the time and even learned a thing or two. I wasn't exactly new to offensive work, but was nice to get things sharpened up and familiar with a few different approaches. I remember being a bit worked up about the final challenge at the end of it that I took the day off work, but iirc I was able to finish in just a couple hours. It wasn't the most cutting edge content at the time, but it was well organized and ensured that the person being certified could demonstrate some level of practical application and that is far better than most certifications of any sort.

Re: Security Certifications Are Causing More Harm Than Good

#78
I once tried to hire for a MS DBA position. The certified MCDBA's could not tell me what an index was or how it would be used. I was shocked so I went and took the tests myself. There were a few questions on indexes but I could see how someone could answer those questions and forget the exam cram by the next week. We ended up hiring someone with no certs and no degree and he was fantastic at the job.

Re: Security Certifications Are Causing More Harm Than Good

#79
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

> There's no reason someone can't have both skills and certifications Of course you're right that it's not impossible. But here's why it happens anyway and why the heuristic of them being roughly mutually exclusive is not insane: 1. There's a certification that's nearly meaningless because it's so easy to obtain without also having the relevant expertise that the certificate is supposed to represent. 2. People who ar…

You've ignored the point of the post you're replying to. You're looking at the credential as a employee signalling tool, not a tool for other parties to satisfy a business need.

Your HR department needs avenues to sift through referrals and comparison points. If an individual has the certificate and compares equally with a non-certificate candidate, the first individual has signaled, through the certificate, that he is interested in the field, as well as willing to invest time and resources into advancing in that field. This is the flipside of the employee signalling.

If an applicant applies without the certificate to a post which requires it, he will recognize his cover letter/interview should make a point of demonstrating competence in the area of the certificate. This is an instance of employer signalling.

If an applicant fakes having acquired the certificate and there is an easy way to determine whether or not he is faking, then HR now has an easy sieve for removing employees willing to misrepresent their skills to obtain the job. This is a step in the HR QA process.

Some employers work outside the 'work for hire' states. If they contain a certificate requirement in a job posting with enumerated skills, they can point to ineptitude in the certificate skillset as reasons for dismissal depending on the jurisdiction they're in. This is a tool in legal's toolbox.

Perhaps the certificate system is the result of the collaboration of a number of employers attempting to pool credential and training requirements for an industry, then create requirements for credentialing into legislation to control the industry pipeline of workers. This is a method of signalling to legislators or restricting competitors by indirect means.

And so on.

Additionally, your fact pattern has a small problem: expert acting as hiring managers who have knowledge of the problems with the certificate are free to adjust their screening procedure to obtain more fully vetted candidates. The only time avoiding the certificate entirely is when the signal it provides is negative.

This doesn't mean that certs are useful, merely that they might be useful to stakeholders you aren't considering.

Re: Security Certifications Are Causing More Harm Than Good

#80
Absence of them when you're a consultant is the issue. Its not that it wins you clients by having them, but not having them might lose you opportunities. Also, not obtaining them (especially if you know what you're doing) shows either potential laziness or "better than everyone" attitude that also is negative. The thrust of that article was exceptionally tilted to that attitude, and I would think twice about hiring someone with such a huge head. I'm sure those guys are good at what they do. If so, take the minimal effort to credential yourself so when people see your name on paper, they have some reference that you know what you're doing. Without it, is the readers imagination.

I have CEH, EnCE, and EnCEP. Doing CISSP this year. Why? Because it makes me stand out regardless. And I've landed clients who were amused by the "ethical hacker" destination. So don't undervalue cert just because of some cocky nerds.

Post reply on HN