I was involved once in a criminal forensics case. The defense's "expert" witness was a one man computer shop. He had created his own "certifications" and listed them on his resumé as indications to the court of his suitability as a witness. It was literally "person's-company-name Certified Forensic Examiner". He had created about 6 certifications, all of which he held. It's kinda funny, but also kinda scary that the…
So he got the court to accept a self-signed cert as a trusted root. I don't see how that's much different than asking someone to solemnly swear they are telling the truth, when most humans are as capable as lying about whether or not they are truthful as they are of lying about anything else. If the court has no one capable of gauging the expertise of a witness, it has to trust in someone to do that for them, and if…
Security Certifications Are Causing More Harm Than Good
201–210 of 224 posts
Re: Security Certifications Are Causing More Harm Than Good
#202Earlier quoted context omitted.
Obviously it takes time to build a profession, but you've got to start somewhere, and part of that path is certification. Unfortunately the industry is growing far faster than perhaps happened for previous emergent professions, so the time needed to slowly grow professional bodies isn't available. If it's not commercial organisations that start providing those services, the only other options I can see are some form…
No, you're describing a cart that is pulling its horse. The "certification", in whatever form it takes, must follow the professionalization of the field. Regardless, none of the certificates you've mentioned --- OSCP, CREST, or SANS --- will define information security. None of them have any meaningful credibility to experts.
Re: Security Certifications Are Causing More Harm Than Good
#203Earlier quoted context omitted.
so, out of curiousity, that implies to me that you don't rate any IT security certifications? So would I be right in thinking you don't think that any of the Offsec certs (OSCP/OCSE), CREST certs (CCT etc) or SANS certs are usful? Also, and I'd be genuinely interested to hear your thoughts here, why do you think that IT/Info Sec will take a different path than other professions (medicine, law, accountancy, engineerin…
The burden of proof should be on whoever is suggesting that security has anything at all to do with those professions, but I'll throw out a couple of observations anyway. Those professions have rules, and are backed by either legislation or science. All participants are bound by said rules. For a lawyer, certain things are legal, certain things are not. Security is a game where the whole objective is to either break…
But that's not the reality for most companies, they're not trying to hire the absolute brightest and best, realistcally not everyone can. They're looking for some measurable indications that a candidate has a baseline level of knowledge in a given field.
Now I feel that a good certifiation can be part of that. So a valuable activity for the industry is to try and create better certifications to help companies who aren't in a position to judge for themselves whether someone is great at something or not, that there's a level of knowledge and understanding there.
If current certifications are poor, then it should be possible to articulate why they are poor, and describe what would make them better.
My references to other professions were designed to reference the fact that those professions have had to face similar issues as they've grown and in science, engineering, law, medicine, accountancy, etc etc they've pretty much all decided that some forms of professional certifications are the right way to go.
Not to say that they're perfect, but that they could be better than the alternatives.
Re: Security Certifications Are Causing More Harm Than Good
#204Earlier quoted context omitted.
One of the most important aspects of a long report is the prioritization of the contents.
I used to pentest for a living. Still do some red team exercises every now and then, but far less now that I'm mainly blueteam focused. I personally organized my report into three sections, which seemed to work well. Clients seemed to enjoy the formatting: 1. Executive - Summarize everything in one page at a high level. You could skim it fast if you chose to. Highlight potential negative business impact of each findi…
This was for using citrix boxes to provide saas to a client
Re: Security Certifications Are Causing More Harm Than Good
#205Earlier quoted context omitted.
Compliances cover a lot of the basics.
Isn't compliance the reason we have "at least one upper and lower case letter, at least one number, at least one special character and a drop of blood from your first born" style passwords that ruin security?
Re: Security Certifications Are Causing More Harm Than Good
#206Earlier quoted context omitted.
Isn't compliance the reason we have "at least one upper and lower case letter, at least one number, at least one special character and a drop of blood from your first born" style passwords that ruin security?
You're not up to date on your compliance, this sort of stuff is forbidden by the last NIST regulation :D
Re: Security Certifications Are Causing More Harm Than Good
#207Earlier quoted context omitted.
How many of those industries does certification actually work in? Does it prevent dodgy lawyers and accountants?
Certification does work in some industries. When a lawyer is admitted to the bar, that is generally taken as proof that they have some idea of what they are doing. Bar exams are hard. And the bar also provides a forum for dealing with shady lawyers. If a lawyer treats you badly, you can file a complaint with their bar association and they might get disbarred. This is an area where cyber training and certs is not as g…
Re: Security Certifications Are Causing More Harm Than Good
#208Earlier quoted context omitted.
Describe the overflow exploit you wrote. What was the vulnerability, and what did the exploit look like?
Unfortunately I can't get into too much detail because I had to sign an NDA (to prevent cheating). But the process was similar to when I have found them in the wild: identify the app, install it locally, fuzz various parameters (it was a real application, albeit an old one), find the crash, figure out stack space, figure out bad characters, find the right JMP ESP or equivalent instructions in a loaded library, write…
Re: Security Certifications Are Causing More Harm Than Good
#209Earlier quoted context omitted.
Describe the overflow exploit you wrote. What was the vulnerability, and what did the exploit look like?
Unfortunately I can't get into too much detail because I had to sign an NDA (to prevent cheating). But the process was similar to when I have found them in the wild: identify the app, install it locally, fuzz various parameters (it was a real application, albeit an old one), find the crash, figure out stack space, figure out bad characters, find the right JMP ESP or equivalent instructions in a loaded library, write…
Re: Security Certifications Are Causing More Harm Than Good
#210A few, less than 10, had certs listed on their resumes and no one in the interview loops gave weight to those certs or even talked about them from what I recall