Live data from Hacker News

Thinking of a Cybersecurity Career?

krebsonsecurity.com

51–60 of 129 posts

Re: Thinking of a Cybersecurity Career?

#51
post #39

Earlier quoted context omitted.

So your point is "bad pentests are bad and provide no value". Yes. You are correct.

Which is exactly why I was saying pentesters should be more inventive :) The level of external pentesters I've seen, has not exceeded the "scriptkiddie" level.

You haven't seen good pentesters then, I suppose. I personally know a lot better than the level you described and I'm not near as experienced as some of the people I know. Question is whether or not whoever holds the purse is willing to pay for the higher quality work.

Dirt cheap programmers from low-economy countries aren't always the best either, just saying.

Re: Thinking of a Cybersecurity Career?

#52
post #36

Earlier quoted context omitted.

Hopefully the answer will be "A LOT more than CEH", but I wanted to test the waters. :P

I do not value CEH or OSCP at all. The candidate will need to demonstrate they can apply that skill against a real world situation. I wont be more likely to interview you by having these on your resume, but it may help a recruiter put it in front of me (though I will never tell them to look for these keywords)

Good!! That's the right approach. I also think these certifications are forcing students to think in the direction intended by the underlying company, whereas hacking is about looking for the unexpected. It's about mastery of technology, not about ticking some boxes and knowing command-line parameters of common tools by heart.

Indeed there is a major issue with HR focusing too strongly on certificates because they lack the knowledge to evaluate a candidate any other way.

Re: Thinking of a Cybersecurity Career?

#53
post #36

Earlier quoted context omitted.

Hopefully the answer will be "A LOT more than CEH", but I wanted to test the waters. :P

I do not value CEH or OSCP at all. The candidate will need to demonstrate they can apply that skill against a real world situation. I wont be more likely to interview you by having these on your resume, but it may help a recruiter put it in front of me (though I will never tell them to look for these keywords)

> The candidate will need to demonstrate they can apply that skill against a real world situation.

I thought this is exactly what holders of the OSCP certificate has demonstrated during the exam?

Re: Thinking of a Cybersecurity Career?

#54
post #31

Earlier quoted context omitted.

How much do you value CEH?

A follow-up: how much do you value OSCP?

I have to be blunt - many of my weakest candidates came with these certs. Im impressed when you are already amazing at these things, and then show the discipline to get the cert anyway.

Im passing on your candidacy when you have the cert, but put me to sleep with the practical application. I'm less interested if you can study, and more interested if you can LEARN.

Re: Thinking of a Cybersecurity Career?

#55

CyberSecurity, the domain that doesn't recruit yet has a shortage. What cybersecurity is to most people is automated security scans. This can be done by interns with a week of training to run the tools. (Interpreting and remediating the findings is another matter). Besides that, security is mainly about authentication. That's done by setting up LDAP, active directory, openid connect and co, and integrating in applica…

> CyberSecurity, the domain that doesn't recruit yet has a shortage.

Yes, they are 100% lying about this. Any time you see an article about skills shortage, it's complete bullshit. It is cheap for them to create the illusion of a skills shortage via articles and blog spam. What they really want is people to spend their own money on training vs. them training their own talent. Then, once you've spent your money on training, you'll still run similar gauntlets in interviews that developers like to complain about.

This is why some of the certs are kind of useless at getting a job despite industry advice to get them. Some places will see something like OSCP and then still give you a time-limited CTF to do before they'll even talk to you about an entry-level position. Other larger companies will praise you for your certs, saying certs + programming skills is what they look for with new people, then just ghost you.

The interviewing process in pentesting is just as bad, if not worse, than development.

Plus, despite most pentesting gigs being more difficult day-to-day than regular web development jobs, they pay much, MUCH less, sometimes as much as $40k less (80k vs. 120k in a large metro area).

All of this is kind of countered by the fact that you can really do bug bounties on your own now, so you may not really need a traditional job. IMHO, you're better off being a developer first before going down that route.

Re: Thinking of a Cybersecurity Career?

#56
post #44

Earlier quoted context omitted.

Which is exactly why I was saying pentesters should be more inventive :) The level of external pentesters I've seen, has not exceeded the "scriptkiddie" level.

> The level of external pentesters I've seen, has not exceeded the "scriptkiddie" level. You get what you pay for. I've taken part in security audits that delivered 0days - but they weren't cheap.

Good point. I'm not sure how much we pay for these as they're not commissioned by me. But knowing the company it's not going to be too much :)

Re: Thinking of a Cybersecurity Career?

#57
post #36

Earlier quoted context omitted.

Hopefully the answer will be "A LOT more than CEH", but I wanted to test the waters. :P

I do not value CEH or OSCP at all. The candidate will need to demonstrate they can apply that skill against a real world situation. I wont be more likely to interview you by having these on your resume, but it may help a recruiter put it in front of me (though I will never tell them to look for these keywords)

GekkePrutser: > Good!! That's the right approach. I also think these certifications are forcing students to think in the direction intended by the underlying company, whereas hacking is about looking for the unexpected. It's about mastery of technology, not about ticking some boxes and knowing command-line parameters of common tools by heart.

CEH is box ticking. OSCP is breaking into stuff. That hacking is about "mastery of technology" I don't agree with. The latest major vulnerabilities identified this month were very low hanging fruits, and I bet you there's still way too many unpatched instances of BIG-IP, NetScaler and Windows DNS out there right this moment. ...two of which have available POCs online for any scriptkiddie to get their hands on. If not all three... the researchers who found the Windows DNS vulnerability have agreed to hold their horses for a while, letting admins patch their systems before releasing all details.

Latteral movement in an Active Directory environment is trickier than looking up a version number and trying your luck with a POC, sure, but you give too much credit to hackers, man. :P

Re: Thinking of a Cybersecurity Career?

#58
post #53

Earlier quoted context omitted.

I do not value CEH or OSCP at all. The candidate will need to demonstrate they can apply that skill against a real world situation. I wont be more likely to interview you by having these on your resume, but it may help a recruiter put it in front of me (though I will never tell them to look for these keywords)

> The candidate will need to demonstrate they can apply that skill against a real world situation. I thought this is exactly what holders of the OSCP certificate has demonstrated during the exam?

Im less interested in someone else telling me you can do it, and more into you demonstrating you can do it in a situation I care about.

See my earlier comment regarding the relative strength of candidates with OSCP.

Re: Thinking of a Cybersecurity Career?

#59
post #51

Earlier quoted context omitted.

Which is exactly why I was saying pentesters should be more inventive :) The level of external pentesters I've seen, has not exceeded the "scriptkiddie" level.

You haven't seen good pentesters then, I suppose. I personally know a lot better than the level you described and I'm not near as experienced as some of the people I know. Question is whether or not whoever holds the purse is willing to pay for the higher quality work. Dirt cheap programmers from low-economy countries aren't always the best either, just saying.

Yes good point. The ones I know come across as "box tickers". They're from a very high profile IT company but that doesn't say much. I assumed they were all like that but I admit that was an assumption.

Re: Thinking of a Cybersecurity Career?

#60
post #36

Earlier quoted context omitted.

Hopefully the answer will be "A LOT more than CEH", but I wanted to test the waters. :P

I do not value CEH or OSCP at all. The candidate will need to demonstrate they can apply that skill against a real world situation. I wont be more likely to interview you by having these on your resume, but it may help a recruiter put it in front of me (though I will never tell them to look for these keywords)

> See my earlier comment regarding the relative strength of candidates with OSCP.

Have you been through the course and exam yourself, or are you basing this on something else? If you've been through the experience, which parts of it contribute to you not valuing it?

Post reply on HN