Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

81–90 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#81
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

This. So much this. Writing and general social skills are the number 1 thing lacking with people I interact with in the industry. The I know more than you attitude is great amongst peers, but with clients, you don't have to prove you're smarter, instead your job is to make them smarter.

Break it down to a 4th grade level, if you can't, you likely don't understand it yourself.

I would agree that in general certs have too much weight, but the reality of it is, as it stands, they're the closest bridge / standardization that the market has built for non-Security ilk.

Also, Security is not IT. That's another thing that needs to change.

As for OSCP, I think it's great and out of all the certs i've taken for various reasons, it's the only one I felt challenged with, in a good way.

Re: Security Certifications Are Causing More Harm Than Good

#82
post #31

Earlier quoted context omitted.

That's exactly why a lot of bootcamps have come into existence, along with a guaranteed job in the industry at the end of it. Though many employers hire university grads as a sort of "signal" for people who can work hard, think critically, finish what they started etc. And I'm not saying one is better then the other, just noticing this trend of bootcamps popping up everywhere to replace university CS/CE education.

anecdotally most people I know who have gone through bootcamp have had major issues getting hired and the ones that did were hired into support/saleseng rather than software engineering.

I've seen the same as well, more so that most of them were taught one structured way to look at problems and only how to use specific tools, rather than why. There's definitely tradecraft learning necessary beyond a bootcamp.

Re: Security Certifications Are Causing More Harm Than Good

#83
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

   There's no reason someone can't have both skills and certifications
Ok, sure...But we're not saying they are mutually exclusive. We're talking about bayesian inference here...

Re: Security Certifications Are Causing More Harm Than Good

#84

Absence of them when you're a consultant is the issue. Its not that it wins you clients by having them, but not having them might lose you opportunities. Also, not obtaining them (especially if you know what you're doing) shows either potential laziness or "better than everyone" attitude that also is negative. The thrust of that article was exceptionally tilted to that attitude, and I would think twice about hiring s…

It depends on the market you're after. Sophisticated buyers won't ask for certifications. They can look at your work and understand your value. Those are the clients my firm is after. Leads that ask for certifications drop out of our sales process, and I refer them elsewhere.

Part of the problem with certifications is that lots of students look at them as a means to an end. This is wrong and counterproductive. Learning to pass a certification is the laziness, most counterproductive exercise you can do to learn security. Yet this is common. Learn by doing. Then get a cert if someone demands it or offers you more money for one.

If more people approached certification that way, there would be less industry-wide pushback about it.

Re: Security Certifications Are Causing More Harm Than Good

#85
Certs show the candidate is in the upper 90% of the group. Its no different than fizzbuzz. Its very much like stack ranking and tossing out the bottom 10%, those being the cert-less.

My day job maybe 15, 20 years ago was basically Cisco CCNP Routing test. It was kinda useful to study and pass Cisco Switching test because switching is a different world of networking. Probably I was in the top 10% of router ops, but I was only in the top 90% of switch ops. For many jobs thats perfectly OK.

Something very few people like to talk about is self inflation of company requirements. Top 90th percentile is frankly more than good enough for most companies. Yes lots of self important strutting about rockstars and ninjas but all they really need, often all they can get, is top 90th percentile, and it works out fine.

A cert is not a Nobel prize or Congressional Medal of Honor. Its not even a PHD. Its kinda like graduating middle school, or having a clean-ish criminal record. Maybe the best example is its like passing a drug test for a job, having the self control to not get high for a whopping two or three days before the test is kind of a minimum display of self discipline to get a job.

Re: Security Certifications Are Causing More Harm Than Good

#86

I was involved once in a criminal forensics case. The defense's "expert" witness was a one man computer shop. He had created his own "certifications" and listed them on his resumé as indications to the court of his suitability as a witness. It was literally "person's-company-name Certified Forensic Examiner". He had created about 6 certifications, all of which he held. It's kinda funny, but also kinda scary that the…

So he got the court to accept a self-signed cert as a trusted root. I don't see how that's much different than asking someone to solemnly swear they are telling the truth, when most humans are as capable as lying about whether or not they are truthful as they are of lying about anything else. If the court has no one capable of gauging the expertise of a witness, it has to trust in someone to do that for them, and if…

Self appointed experts should not be accepted by courts. That is what caused cluster fuck of bite mark non-science and fire non-science.

The differente against lying is that you know when you lie. You dont know when you are overly confident but incompetent.

Re: Security Certifications Are Causing More Harm Than Good

#87
Being a manager of an InfoSec team I agree with this, especially the CISSP and CEH.

I've seen a few folks get a CEH and then they're off to App testing land, but the funning thing is, none of them has ever written an app, some not even a script, and they are now doing security testing on mobile apps. Basically they just push a button on an app scanner and pull a report, it's sad.

The folks that do succeed in security are the ones with curiosity, experience and drive to learn.

Re: Security Certifications Are Causing More Harm Than Good

#88

I once tried to hire for a MS DBA position. The certified MCDBA's could not tell me what an index was or how it would be used. I was shocked so I went and took the tests myself. There were a few questions on indexes but I could see how someone could answer those questions and forget the exam cram by the next week. We ended up hiring someone with no certs and no degree and he was fantastic at the job.

Ah, yes... the "paper tiger". While I do have certs myself, it's only because my employer has required them. Left to my own devices, I would never bother. I've been in IT for almost 20 years and I agree that the "no cert/no degree" guys usually work out.

The team lead whose feet I studied at in my first few years in IT had a high school diploma and he could run rings around the guys from Carnegie Mellon and RIT that worked with us. He was a deep diver mentally. I watched this guy drop awk, sed, bash strings a mile long, write Perl scripts without consulting a single web page. He knew iOS (Cisco), Perl, TCL/Tk, Sun, BSD, and about everything else. He could configure a HA UNIX servers and Oracle DB backends without consulting a manual. It was most impressive. He was let go because he was a team lead (middle manager). The people that replaced him--yes, people-- knew nothing in comparison.

Re: Security Certifications Are Causing More Harm Than Good

#89
post #44
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

There's both some truth and some falsehood to the 'certifications don't prove anything' argument: Answer a multiple choice test for an MCSE or whatever? Doesn't prove much. Receive a server that's been wrecked and won't boot, turn it into a load balancing HTTPS server, SMTP server, a bunch of required cron jobs and a boat load more requirements for RHCE? Proves you can do those things. Disclaimer: used to work at Red…

I just recently had someone ask me to take an assessment test for a senior developer position. There's always some silly hoop to jump through, so I thought "why not".

Well I got booted out of the test because I hit Ctrl-C to copy something for the first warning, and hit Ctrl-L (muscle memory) for the final revocation of the test.

I just thought to myself ... did I just fail an assessment test because I hit Ctrl-L?

The test gets reset and allows me to start back up, only it took 20 minutes off the allotted time for some reason. I didn't even get to the last question on the test.

The results showed me scoring in the 96 percentile. So I basically threw 3 questions away on this test and still scored that high. And I skipped one question because it was asking about building/creating msi files on an C#/ASP.Net/MVC assessment. I have no idea why it was there, but I don't regularly build msi executables (although I regularly automate them).

And the worst part is that a lot of the questions were inane things like "given this inheritance hierachy, sally adds the new keyword in front of one of the child methods, and then this other code uses this inheritance hierarchy. what is the output?".

At no point do I feel like anything on that assessment came even close to assessing my ability as a senior technical person. These were things a college student could have answered just as accurately.

I know it's not quite the same thing as a certification, but I seriously dislike assessment tests. Unfortunately it seems like every company has their games you have to play in order to actually get TO the technical folks.

Re: Security Certifications Are Causing More Harm Than Good

#90
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

Knowing basic English is a prerequisite to any tech job. There's nothing else you need to know to explain a bug. And there's TOEFL/IELTS if you're looking for English language certificate.
Post reply on HN