Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

121–130 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#121

Articles like this one frustrate me. I'm 30, and am essentially starting life over after finishing my military enlistment a couple years ago. all the experience of setting up shops and drafting reports meant nothing with out a degree. So I start working on my degree, and I am absolutely miserable. My love of learning was sucked out of me because I wasn't learning: I was working towards an extra line on my resume. Rig…

Sounds to me like you're doing the right kind of thing to break into the industry. Whilst there are people that, unfortunately, take the attitude in the article, I think that there's a load of others that take a more balanced approach and recognise some of the value of certifications. The other thing I'd recommend, if you're not already doing it, is get along to some of the chapter meetings and conferences that there…

Hey. Again with these false dichotomies. The choice isn't between "certificates" and "never letting newcomers into the industry". In fact, if I accomplished one single thing at Matasano, it's getting newcomers onto our team.

https://sockpuppet.org/blog/2015/03/06/the-hiring-post/

I kind of resent my opposition to certification --- which I see principally as a way of keeping newcomers out of the industry, by requiring them to get expensive certificates to enter it --- being cast as opposition to new talent. I think opponents of certification are far, far more welcoming than the supporters are.

Re: Security Certifications Are Causing More Harm Than Good

#122
I am familiar with people who have purchased undergrad and grad level degrees in various fields as well.

The reality is recognizing the importance of a foundation of education is critical. there will always be shortcuts that people take in every imaginable part of life. With that said, people who have a firm education or knowledge no matter where it is from (institution and/or self-taught) will be able to point out people who took short ccuts fairly quicky. The challenge is knowing the right course of action to take, firing or other knee-jerk reactions can result in more harm than good in some situations.

Re: Security Certifications Are Causing More Harm Than Good

#123

Absence of them when you're a consultant is the issue. Its not that it wins you clients by having them, but not having them might lose you opportunities. Also, not obtaining them (especially if you know what you're doing) shows either potential laziness or "better than everyone" attitude that also is negative. The thrust of that article was exceptionally tilted to that attitude, and I would think twice about hiring s…

Sure, but who are you standing out from? Do you want to optimize your career to stand out from those candidates, or from the person you've optimized yourself to be currently?

Stated another way, getting a bunch of certifications helps you stand out from the entry level. Putting aside a platonic ideal of what certifications should be, you could have done that without those certifications.

With regards to your first paragraph - at this point my consultancy bills five figures per week, and I do absolutely no outbound lead gen. The lack of certifications will lose you business, yes. But I would argue that was not necessarily business you wanted to optimize for.

Re: Security Certifications Are Causing More Harm Than Good

#124

Earlier quoted context omitted.

Yep I think apprenticeships can help too, there's no one thing that's going to help bring a load of people on, I think it's got to be multiple paths.

I believe that too. I simply believe --- with ample evidence --- that certifications aren't going to be one of those paths.

so, out of curiousity, that implies to me that you don't rate any IT security certifications?

So would I be right in thinking you don't think that any of the Offsec certs (OSCP/OCSE), CREST certs (CCT etc) or SANS certs are usful?

Also, and I'd be genuinely interested to hear your thoughts here, why do you think that IT/Info Sec will take a different path than other professions (medicine, law, accountancy, engineering etc) which fairly universally have evolved into a certified professional model?

Re: Security Certifications Are Causing More Harm Than Good

#125

Articles like this one frustrate me. I'm 30, and am essentially starting life over after finishing my military enlistment a couple years ago. all the experience of setting up shops and drafting reports meant nothing with out a degree. So I start working on my degree, and I am absolutely miserable. My love of learning was sucked out of me because I wasn't learning: I was working towards an extra line on my resume. Rig…

This guy is flat-out wrong. He bags on the CISSP - thats a friggin management cert, not a technical cert. Like bitching the CEH doesn't go hard into Opex/Capex. Meanwhile on planet earth "draw up an inter-agency security agreement compliant with all local jurisdictional laws and industry regs" is also infosec and command line kung-fu will do fuck all to help you get it done. This guy just drinks "unicorn" piss - he d…

Exactly... CISSP shows that you have an understanding of risk, numerous compliance requirements, and how much basic housekeeping activities like asset inventory management or having proper data classification/access controls help in maintaining security. The title of "Information Systems Security Professional" suggests that you're knowledgeable enough to speak intelligently in all of the ten domains, but your everyday job might be in a single relatively non-technical domain, like "Business Continuity and Disaster Recovery Planning".

I wouldn't expect anyone with a CISSP to be an expert in "tech ninja" stuff, but he should be able to assess whether overall security is better served by investing in the "ninja work" or, for example, additional phishing training for employees, at a given point in time. This is certainly not a deficiency in CISSP, and I don't think anyone with enough experience in the infosec industry would have such an expectation.

Re: Security Certifications Are Causing More Harm Than Good

#126

Earlier quoted context omitted.

I believe that too. I simply believe --- with ample evidence --- that certifications aren't going to be one of those paths.

so, out of curiousity, that implies to me that you don't rate any IT security certifications? So would I be right in thinking you don't think that any of the Offsec certs (OSCP/OCSE), CREST certs (CCT etc) or SANS certs are usful? Also, and I'd be genuinely interested to hear your thoughts here, why do you think that IT/Info Sec will take a different path than other professions (medicine, law, accountancy, engineerin…

The "certifications" in medicine and law accompany postgraduate degrees and are far, far more recognized than the random certificates you listed, some of which are profit-making enterprises from for-profit companies.

Re: Security Certifications Are Causing More Harm Than Good

#127

Earlier quoted context omitted.

This guy is flat-out wrong. He bags on the CISSP - thats a friggin management cert, not a technical cert. Like bitching the CEH doesn't go hard into Opex/Capex. Meanwhile on planet earth "draw up an inter-agency security agreement compliant with all local jurisdictional laws and industry regs" is also infosec and command line kung-fu will do fuck all to help you get it done. This guy just drinks "unicorn" piss - he d…

Exactly... CISSP shows that you have an understanding of risk, numerous compliance requirements, and how much basic housekeeping activities like asset inventory management or having proper data classification/access controls help in maintaining security. The title of "Information Systems Security Professional" suggests that you're knowledgeable enough to speak intelligently in all of the ten domains, but your everyda…

I've been in the industry since 1995. I've worked for Fortune 500 companies. What's the experience I'm missing to appreciate the CISSP? Because from where I stand, it seems mostly like a scam to me.

Re: Security Certifications Are Causing More Harm Than Good

#128

Earlier quoted context omitted.

Sounds to me like you're doing the right kind of thing to break into the industry. Whilst there are people that, unfortunately, take the attitude in the article, I think that there's a load of others that take a more balanced approach and recognise some of the value of certifications. The other thing I'd recommend, if you're not already doing it, is get along to some of the chapter meetings and conferences that there…

Hey. Again with these false dichotomies. The choice isn't between "certificates" and "never letting newcomers into the industry". In fact, if I accomplished one single thing at Matasano, it's getting newcomers onto our team . https://sockpuppet.org/blog/2015/03/06/the-hiring-post/ I kind of resent my opposition to certification --- which I see principally as a way of keeping newcomers out of the industry, by requirin…

it's not a false dichotomy. The comment I was replying to was specifically expressing disappointment that his efforts in getting certificate would be overlooked because of a negative attitude in the industry to those certifications. I was merely expressing encouragement that not everyone would look on those certification efforts negatively.

The article takes what I think to be an overly absolute position in suggesting that certifications are actually harmful to the industry.

I'm not suggesting that you are opposed to new talent, I've not said that anywhere.

What I've said is that I think that cerifications can be useful for newcomers in demonstrating effort/ability in a field.

I think that those certifications can be useful specifically in scaling entry to the industry (I'm not saying they need to be expensive, heck I'd love it if they were free, but someone has to pay for the effort required).

The problem with leaving individual companies to review every candidate from scratch is that it's a huge waste of effort. If you're starting a SOC and have to fill 50 spots and get 2000 CVs across your desk, you realistically are not going to be able to take an approach of manually interviewing every single candidate.

Now and I'm sure you know more than I , that doesn't apply to high-end security testing companies, but different types of roles require different approaches.

Re: Security Certifications Are Causing More Harm Than Good

#129

Earlier quoted context omitted.

It's a joke as well, and it just means the holder could copy and paste an XP-era exploit, which has roughly no relevance today.

Don't know if you have taken it in the last year or so since they updated it, but it's pretty tough. You may be able to use a public exploit to elevate your shell once on a box, but getting code execution was the difficult part. One of the challenges involved fuzzing, writing custom buffer overflow exploits, and dealing with weird stack pivots. That only got me about 20% of the way to passing the test. All in 24hrs.…

Describe the overflow exploit you wrote. What was the vulnerability, and what did the exploit look like?

Re: Security Certifications Are Causing More Harm Than Good

#130

Earlier quoted context omitted.

Hey. Again with these false dichotomies. The choice isn't between "certificates" and "never letting newcomers into the industry". In fact, if I accomplished one single thing at Matasano, it's getting newcomers onto our team . https://sockpuppet.org/blog/2015/03/06/the-hiring-post/ I kind of resent my opposition to certification --- which I see principally as a way of keeping newcomers out of the industry, by requirin…

it's not a false dichotomy. The comment I was replying to was specifically expressing disappointment that his efforts in getting certificate would be overlooked because of a negative attitude in the industry to those certifications. I was merely expressing encouragement that not everyone would look on those certification efforts negatively. The article takes what I think to be an overly absolute position in suggestin…

No, that's not all you said. Your original comment is right there for everyone to read. You attempted to co-opt a position on an orthogonal debate --- whether the industry is adequately welcoming to new talent --- as part of your position on certification. Since I'm a strong opponent of certification and I'm reasonably confident I've done more than you have to bring talent into this field, I object, vehemently, to that kind of rhetoric.

I'd appreciate it if you'd take a second to retract.

Post reply on HN