Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

111–120 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#111
post #79

Earlier quoted context omitted.

> There's no reason someone can't have both skills and certifications Of course you're right that it's not impossible. But here's why it happens anyway and why the heuristic of them being roughly mutually exclusive is not insane: 1. There's a certification that's nearly meaningless because it's so easy to obtain without also having the relevant expertise that the certificate is supposed to represent. 2. People who ar…

You've ignored the point of the post you're replying to. You're looking at the credential as a employee signalling tool, not a tool for other parties to satisfy a business need. Your HR department needs avenues to sift through referrals and comparison points. If an individual has the certificate and compares equally with a non-certificate candidate, the first individual has signaled, through the certificate, that he…

I did ignore that mostly, you're right. My basic claim is that on average this is actually true:

> The only time avoiding the certificate entirely is when the signal it provides is negative.

And further, I think all your examples are perfectly valid, real-world examples that I don't dispute exist and that lots of people find important. I also think perfectly good and reasonable people operate in the reality of their industries and play ball with these things when necessary. AND I think all the use cases you mentioned are bad for the system overall. As in, they are real, and in a practical sense we can't just ignore them, but ideally we wouldn't have them.

HR using negative signals for filtering is bad. Job requirements tailored to the actual job are good. Broad and mostly arbitrary requirements from a third party are bad. Applicants to a well specified job also know to address weaknesses in their cover letter. Specific and well-specified requirements are also useful in legal disputes. Using arbitrary requirements to provide legal for firing people is bad. Employers colluding to control the training pipeline using arbitrary requirements encoded in law is bad.

I agree with you that they useful in the real world, but I'm arguing that that usefulness is evidence that the system is worse than it could be.

Re: Security Certifications Are Causing More Harm Than Good

#112
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

Communication in tech, and especially infosec is a dramatically underrated skill. Infosec consultant for 10 years. I write. A lot. Being able to jump from explaining how we reversed something to devs to an executive who just wants a certain view of how that impacts a release is hard and has taken me a long time. You essentially have to understand the various consumers of your writing at a pretty deep level for it to get read and have impact.

A well written report that speaks at the right level to its audiences will generate more proactive security activity than a terse, passive voice bomb of dense technical information.

Re: Security Certifications Are Causing More Harm Than Good

#113

Articles like this one frustrate me. I'm 30, and am essentially starting life over after finishing my military enlistment a couple years ago. all the experience of setting up shops and drafting reports meant nothing with out a degree. So I start working on my degree, and I am absolutely miserable. My love of learning was sucked out of me because I wasn't learning: I was working towards an extra line on my resume. Rig…

Sounds to me like you're doing the right kind of thing to break into the industry.

Whilst there are people that, unfortunately, take the attitude in the article, I think that there's a load of others that take a more balanced approach and recognise some of the value of certifications.

The other thing I'd recommend, if you're not already doing it, is get along to some of the chapter meetings and conferences that there are increasing numbers of in security.

In particular I'd recommend BSides conferences (http://www.securitybsides.com/w/page/12194156/FrontPage) there's loads of them around and they're good places to meet people in the industry and also in many cases the sponsors are looking to hire.

Re: Security Certifications Are Causing More Harm Than Good

#114
post #106

Earlier quoted context omitted.

Certifications are used by many industries to provide a demonstration of a common baseline level of knowledge and experience, so that each individual person doesn't need to be assessed by each hiring organisation. For example Certified accountants, Lawyers etc. Without some common baseline, how do people looking to hire security types who don't have the experience to assess their skills and knowledge avoid getting ba…

Apprenticeship works. Lots of places will have junior people work below senior ones on projects and gradually gain experience and become senior.

Yep I think apprenticeships can help too, there's no one thing that's going to help bring a load of people on, I think it's got to be multiple paths.

Re: Security Certifications Are Causing More Harm Than Good

#116
post #108

If I'm a competent enough services and web developer wanting to move into infosec, what else could I be doing to get my foot in the door besides collecting certs, as ostensibly shite as they are?

Bug bounties. Andddd that's it, you're done. Find a few in recognizable companies, and jobs will simply come to you.

I'm not going to engage in the debate about what certifications should be in the industry, but I'm happy to show which option is most advantageous for your particular needs right now:

* Certifications mostly do not teach you anything that you, as a competent web developer, cannot learn from the same five textbooks tptacek, others and myself recommend in these threads.

* Certifications cost money.

* Certifications optimize for companies and roles that disproportionately do not pay highly.

* Many certifications require upkeep.

Let's contrast with bug bounties:

* Bug bounties grow your real-world, hands on experience.

* Bug bounties do not cost you anything (in fact, you can get paid!).

* Bug bounties cover a much more diverse and up to date set of security flaws than certifications.

* Bug bounties optimize for companies and roles that will respect you more highly, pay you far better and aggressively try to hire you after you find more than, let's say, two serious vulnerabilities in recognizable companies.

* Bug bounty recognitions do not expire.

Re: Security Certifications Are Causing More Harm Than Good

#117
There is a similar issue with technology certifications (e.g. FIPS 140-2).

A lot of companies treat these as some kind of mystical incantations that will protect them if sufficiently invoked. Case in point: being mandated to switch from one OTP generator app to another because the latter is "FIPS-Compliant" - regardless of the fact that both generate the exact same set of OTPs.

This cargo-culting is not inherently harmful, but it leads to magical thinking and a false senses of security, as well as diverting time and energy away from more productive avenues.

I suspect that the CISSP-genre of certifications suffers from a similar pathology: intrinsically they do function as at least a partial indicator of some type of competence. The problem is when actors with a financial incentive to game the system meet up with bureaucracies: the less defined but more accurate metrics are thrown under the bus in favour of something that is easy to quantify and sell.

Re: Security Certifications Are Causing More Harm Than Good

#118
post #106

Earlier quoted context omitted.

Apprenticeship works. Lots of places will have junior people work below senior ones on projects and gradually gain experience and become senior.

Yep I think apprenticeships can help too, there's no one thing that's going to help bring a load of people on, I think it's got to be multiple paths.

I believe that too. I simply believe --- with ample evidence --- that certifications aren't going to be one of those paths.

Re: Security Certifications Are Causing More Harm Than Good

#119
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

It's unlikely that typical OSCP-holder could write a modern buffer overflow exploit, or even judge exploitability of a memory corruption flaw given the source code and a traceback.

Equally importantly: memory corruption exploit development and SQL injection are different skills, and most people who do SQL injection don't need proficiency in "buffer overflows". Why is superficial coverage of "buffer overflows" part of the rubric for that certificate? I don't know, and I don't know that anyone else does either.

Is there a single coherent security certificate anywhere in the industry? I'm interested in examples.

Re: Security Certifications Are Causing More Harm Than Good

#120
post #104

Articles like this one frustrate me. I'm 30, and am essentially starting life over after finishing my military enlistment a couple years ago. all the experience of setting up shops and drafting reports meant nothing with out a degree. So I start working on my degree, and I am absolutely miserable. My love of learning was sucked out of me because I wasn't learning: I was working towards an extra line on my resume. Rig…

You won't be sidelined. If you internalize most of the material from your SANS courses you'll probably be smarter than 2/3 of the people in this industry, if not more. Most of the articles like this seem to come from people in the top 1-5%. Most of them are people that have started their own companies. I'm not a unicorn and most people aren't. I'm pretty confident that Tptacek and everyone else quoted are better secu…

I have no idea if you are or aren't (be careful about your assumptions!). But I am certain that certification has nothing to do with the delta between the two of us.
Post reply on HN