Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

151–160 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#151

Earlier quoted context omitted.

I believe that too. I simply believe --- with ample evidence --- that certifications aren't going to be one of those paths.

so, out of curiousity, that implies to me that you don't rate any IT security certifications? So would I be right in thinking you don't think that any of the Offsec certs (OSCP/OCSE), CREST certs (CCT etc) or SANS certs are usful? Also, and I'd be genuinely interested to hear your thoughts here, why do you think that IT/Info Sec will take a different path than other professions (medicine, law, accountancy, engineerin…

The burden of proof should be on whoever is suggesting that security has anything at all to do with those professions, but I'll throw out a couple of observations anyway.

Those professions have rules, and are backed by either legislation or science. All participants are bound by said rules. For a lawyer, certain things are legal, certain things are not.

Security is a game where the whole objective is to either break the rules (and often the law) or to defend against someone who is.

How are you going to tell me that person A is qualified for the job based on his exam results, and person B is not, when person B got a root shell on your server and stole your data?

It's like the 1989 draft when the Giants tried to make Dion Sanders write an exam to see if he was qualified to play in the NFL.

"“They sat me down and gave me a thick book,” Sanders recalled. “I mean, this thing was thicker than a phone book. I said, ‘What’s this?’ They said, ‘This is our test that we give all the players.’ I said, ‘Excuse me, what pick do you have in the draft?’ They said, I think, 10th [actually 18th]. I said, ‘I’ll be gone before then. I’ll see y’all later. I ain’t got time for this.’ That’s a true story."

Re: Security Certifications Are Causing More Harm Than Good

#152
post #146
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

> The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. As much as I admire people who show the courtesy to the trash bin that will eat their report, before any human reading it, of not feeding it "bad" reports: The OPs point of "sense of false security" unfortunately already sets in once someone is hired t…

One of the most important aspects of a long report is the prioritization of the contents.

Re: Security Certifications Are Causing More Harm Than Good

#153

Earlier quoted context omitted.

I've been in the industry since 1995. I've worked for Fortune 500 companies. What's the experience I'm missing to appreciate the CISSP? Because from where I stand, it seems mostly like a scam to me.

Then by definition you don't have any expectations for "a CISSP to be an expert in 'tech ninja' stuff", as I was saying... ;-) I'll agree with you that, to an extent, all certifications are a scam, especially those with artificially high sit-down fees. My point is that, CISSP does not claim to be a gauge for whether you are a crypto expert, just that you should know the difference between basic types of encryption an…

Roles I've held:

* ISP network security engineering

* Network penetration tester

* Software developer for network security products

* Application security assessor

* (Most recently) Security team lead

I've had these roles for small companies and for very large ones.

What experience am I missing that would lead me to change my mind about the CISSP? I don't think attempting to pigeonhole me as a "crypto expert" is going to persuade me, because that's not the span of my professional experience.

Re: Security Certifications Are Causing More Harm Than Good

#154

Earlier quoted context omitted.

so, out of curiousity, that implies to me that you don't rate any IT security certifications? So would I be right in thinking you don't think that any of the Offsec certs (OSCP/OCSE), CREST certs (CCT etc) or SANS certs are usful? Also, and I'd be genuinely interested to hear your thoughts here, why do you think that IT/Info Sec will take a different path than other professions (medicine, law, accountancy, engineerin…

The burden of proof should be on whoever is suggesting that security has anything at all to do with those professions, but I'll throw out a couple of observations anyway. Those professions have rules, and are backed by either legislation or science. All participants are bound by said rules. For a lawyer, certain things are legal, certain things are not. Security is a game where the whole objective is to either break…

It's difficult to believe that anyone who can claim to really know computers thinks they aren't based on a series of interacting rules. That's basically all they are.

Understanding how those rules interact, how to trigger certain interactions others didn't intend, and the best practices to not get bit by those interactions is what security is all about. It's much like law or medicine in that you are looking at unexpected consequences of multiple complex systems interfering with one another and looking for compromises and best practices to keep the most disastrous interactions the least likely to happen.

Re: Security Certifications Are Causing More Harm Than Good

#155

Earlier quoted context omitted.

So he got the court to accept a self-signed cert as a trusted root. I don't see how that's much different than asking someone to solemnly swear they are telling the truth, when most humans are as capable as lying about whether or not they are truthful as they are of lying about anything else. If the court has no one capable of gauging the expertise of a witness, it has to trust in someone to do that for them, and if…

There is something very different about telling the truth and having knowledge. Everyone can tell the truth, but not everyone knows technical details about something. He is using his certifications to show he knows technical details; he might even believe he knows those things, but he very well could be wrong.

Hell, he may even be right. He might be a real expert. He doesn't make his claim to know things any more credible by way of vouching for himself even if he's an actual expert.

Certifications sometimes set a terrible baseline, but at least it's an independent baseline.

Re: Security Certifications Are Causing More Harm Than Good

#156
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

This. So much this. Writing and general social skills are the number 1 thing lacking with people I interact with in the industry. The I know more than you attitude is great amongst peers, but with clients, you don't have to prove you're smarter, instead your job is to make them smarter. Break it down to a 4th grade level, if you can't, you likely don't understand it yourself. I would agree that in general certs have…

Also, Security is not IT. That's another thing that needs to change.

Do you mean that

    Security is not currently IT and it should be
or do you mean

    Security is considered to be IT and it shouldn't be
? The amount of stress that you mean to put on the word "not" doesn't come through very well in this medium.

Re: Security Certifications Are Causing More Harm Than Good

#157
post #90
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

Knowing basic English is a prerequisite to any tech job. There's nothing else you need to know to explain a bug. And there's TOEFL/IELTS if you're looking for English language certificate.

It's a prerequisite until the powers that be realize they can save money by dropping it.

Re: Security Certifications Are Causing More Harm Than Good

#158
I heard this back in the day when the CNE was "money printing machine, " and the MCSE just kicked off. So nothing has changed from the complainer side of things.

Certs have value depending on the person's skills. Never hire just because they have a CISSP or XYZ.

Sometimes it's just the key to the door to the interview. From there it's up to Employer to properly vet the candidate. If they hire an idiot with a paper cert, then it's their fault... and then they write an article. LOL

Re: Security Certifications Are Causing More Harm Than Good

#159
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

This. So much this. Writing and general social skills are the number 1 thing lacking with people I interact with in the industry. The I know more than you attitude is great amongst peers, but with clients, you don't have to prove you're smarter, instead your job is to make them smarter. Break it down to a 4th grade level, if you can't, you likely don't understand it yourself. I would agree that in general certs have…

Security should be IT. Otherwise, you get a bunch of bullshit cya reports and policies that aren't achievable by the technology deliver people.

Security should have an advisory role to the corporate governance folks who maintain policy... usually the lawyers.

Re: Security Certifications Are Causing More Harm Than Good

#160
post #79

Earlier quoted context omitted.

> There's no reason someone can't have both skills and certifications Of course you're right that it's not impossible. But here's why it happens anyway and why the heuristic of them being roughly mutually exclusive is not insane: 1. There's a certification that's nearly meaningless because it's so easy to obtain without also having the relevant expertise that the certificate is supposed to represent. 2. People who ar…

You've ignored the point of the post you're replying to. You're looking at the credential as a employee signalling tool, not a tool for other parties to satisfy a business need. Your HR department needs avenues to sift through referrals and comparison points. If an individual has the certificate and compares equally with a non-certificate candidate, the first individual has signaled, through the certificate, that he…

> Your HR department needs avenues to sift through referrals and comparison points. If an individual has the certificate and compares equally with a non-certificate candidate, the first individual has signaled, through the certificate, that he is interested in the field, as well as willing to invest time and resources into advancing in that field. This is the flipside of the employee signalling.

The real root of the issue here is that HR can't do their job. An unintended side effect of all this signalling is that future employees will be glad to get filtered out because they don't want to work somewhere that hired on certification instead of competence.

Post reply on HN