Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

181–190 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#181
post #146

Earlier quoted context omitted.

> The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. As much as I admire people who show the courtesy to the trash bin that will eat their report, before any human reading it, of not feeding it "bad" reports: The OPs point of "sense of false security" unfortunately already sets in once someone is hired t…

One of the most important aspects of a long report is the prioritization of the contents.

I used to pentest for a living. Still do some red team exercises every now and then, but far less now that I'm mainly blueteam focused.

I personally organized my report into three sections, which seemed to work well. Clients seemed to enjoy the formatting:

1. Executive - Summarize everything in one page at a high level. You could skim it fast if you chose to. Highlight potential negative business impact of each finding.

2. Management - A little more detailed. 2-3 pages max. Most severe findings at the top and recommended action for remediation.

3. Narrative - This is the bulk 80-90% of the report detailing your step by step process including screenshots so that if someone wanted to duplicate your findings they could.

Re: Security Certifications Are Causing More Harm Than Good

#182

Articles like this one frustrate me. I'm 30, and am essentially starting life over after finishing my military enlistment a couple years ago. all the experience of setting up shops and drafting reports meant nothing with out a degree. So I start working on my degree, and I am absolutely miserable. My love of learning was sucked out of me because I wasn't learning: I was working towards an extra line on my resume. Rig…

This guy is flat-out wrong. He bags on the CISSP - thats a friggin management cert, not a technical cert. Like bitching the CEH doesn't go hard into Opex/Capex. Meanwhile on planet earth "draw up an inter-agency security agreement compliant with all local jurisdictional laws and industry regs" is also infosec and command line kung-fu will do fuck all to help you get it done. This guy just drinks "unicorn" piss - he d…

Yeah, but let's be realistic. There are very few technologists who are passionate about computing that would really enjoy compliance roles. Infosec is a huge banner and I am going to assume most hackers here are on the technical side. Also no cert can possibly prepare you for negotiating corporate IT security policy.

But even for us (a high end infosec consulting firm) knowing how to relay findings and risk concepts to executives can mean the difference in our work getting implemented, transforming an organization from average to above average in terms of how they approach information security.

Anyway, don't be such a cynic, we just run out of air when we get to the upper reaches of technology expertise so it makes is dumb :P

Re: Security Certifications Are Causing More Harm Than Good

#183

Articles like this one frustrate me. I'm 30, and am essentially starting life over after finishing my military enlistment a couple years ago. all the experience of setting up shops and drafting reports meant nothing with out a degree. So I start working on my degree, and I am absolutely miserable. My love of learning was sucked out of me because I wasn't learning: I was working towards an extra line on my resume. Rig…

This article is talking from the perspective of getting hired by so-called "elite" security firms. That comprises a tiny percentage of the roles you might possibly seek in the future, and shouldn't taint your pursuit. Many employers who are trying to staff some sort of internal security competency will regard it very well -- there's a reason they appear in countless job listing -- as a sign of both focus and interest…

What, everyone doesn't aspire to become an elite hacker speaking at BlackHat?

Seriously, you are spot on. It takes years and dedication and no small amount of coincidence of interests and skills to reach the elite levels. It also takes a kind of persistence and thick skin to do the research and get the skills to get your first real high end job for most people. I tried replying to the OP about how to get to where our senior and principal consultants are and.. it turned into a somewhat muddy word bomb. At some level the advice was basically, "Yeah, just get really good at... everything, then infosec is easy"

There are so many paths and skillsets required and you can specialize in so many areas (operating systems, tools, crypto, memory corruption, etc...). How do you even begin to convey the depth and variety to someone at the start of their journey? Ultimately there are just a lot of common patterns of elite hackers, base skills you use all the time. Get those skills, and keep trying to hack stuff :)

Re: Security Certifications Are Causing More Harm Than Good

#184

Earlier quoted context omitted.

Why would cisco people need to know CS? Different fields.

I mean simple mistakes, like not understanding that information on an air gapped machine is unknowable to another machine on the network. "If you took the tax id and social from 'airGappedMachine'" "It has no connection to any other machine" "Just query the database" "Store it on a thumbdrive and walk it over? It changes quite often I don't think that's a good workflow" "No, just query it" "How?" "SQL!" Or the classi…

Classic. This could be the script for one of those animated videos that https://www.youtube.com/user/gar1t did.

Like the "Mongodb is web scale" one.

Re: Security Certifications Are Causing More Harm Than Good

#185

I wanted to get my consulting company into PCI auditing and you need certifications to do that. One problem with the certifications is they aren't actually skill based. I wouldn't be able to get one despite having experience because: For several of them it requires years of work experience with a specific job titles (your job needs to be security, it can't just be part of your job) and the continuing education credit…

"I wanted to get my consulting company into PCI auditing and you need certifications to do that. One problem with the certifications is they aren't actually skill based."

http://www.rsync.net/resources/regulatory/pci.html

Re: Security Certifications Are Causing More Harm Than Good

#186
post #146
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

> The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. As much as I admire people who show the courtesy to the trash bin that will eat their report, before any human reading it, of not feeding it "bad" reports: The OPs point of "sense of false security" unfortunately already sets in once someone is hired t…

Maybe someone read it but was a teetotaler?

Re: Security Certifications Are Causing More Harm Than Good

#187
post #186
post #146

Earlier quoted context omitted.

> The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. As much as I admire people who show the courtesy to the trash bin that will eat their report, before any human reading it, of not feeding it "bad" reports: The OPs point of "sense of false security" unfortunately already sets in once someone is hired t…

Maybe someone read it but was a teetotaler?

At one company I'd do a similar thing - about two-thirds of the way down a list of dot-points, I'd mention something about free chocolate or a beer. No-one ever mentioned it, not even to reference it in the slightest or tell me I was wasting my time.

Re: Security Certifications Are Causing More Harm Than Good

#188

So the article alluded to reading books and hacking on your own. But for those who need some sort of curriculum, progress bar, or structure, what would HN recommend to get to some sort of level of competency in the infosec field (like intermediate level/beginner-advanced).

Others will likely have more informed opinions, but here's some stuff: Book: Web Application Hacker Handbook http://www.wiley.com/WileyCDA/WileyTitle/productCd-111802647... I've seen it highly recommended and if you're not familiar with the field it's a good overview of exploit types for web apps. Online training for free or cheap: Cybrary - mostly okay, but free. PluralSight - https://www.pluralsight.com/browse/it-o…

Thank you!

Re: Security Certifications Are Causing More Harm Than Good

#189

Earlier quoted context omitted.

Roles I've held: * ISP network security engineering * Network penetration tester * Software developer for network security products * Application security assessor * (Most recently) Security team lead I've had these roles for small companies and for very large ones. What experience am I missing that would lead me to change my mind about the CISSP? I don't think attempting to pigeonhole me as a "crypto expert" is goin…

That's an impressive resume of roles, but security is more than just those areas. I think the grandparent is trying to say that the CISSP is largely for non-technical security roles. People that manage large security organizations are generally believed to be the ones that benefit from the CISSP as they are not interested in the details and more on a 1000 foot strategic view. Without knowing more details about the yo…

Have you actually looked at the CISSP material recently?

It's a hodge-podge of everything under the sun. The only thing it's able to prove is that

a) you have endurance and spare time to sit for a 4-6 hour multiple choice test

b) you can commit to rote memory a bunch of meaningless material which you are unlikely to encounter in real security/risk management role

It truly is the worst of the bunch, but for reasons yet explained, it's the defacto "must have" by bigCorps - which is why it gets picked on by so many folks: everyone knows it's bad, yet most people end up picking it up.

Re: Security Certifications Are Causing More Harm Than Good

#190
I had a CISSP certification, I let it expired, I couldn't afford traveling and going to conferences to get the Continuous Education points.

If you do the math, attending webminars, reading books and writing reviews don't get you all the points you need every year (I can't imagine the fraud that must be going on for people trying to get those points). So I said "fuck it".

Funny thing is, I'm way more experience in security now (with CISSP expired due to stupid points) than when I got it and was certified. Joke and money-grabbing scheme no doubt.

Post reply on HN