Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

131–140 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#131

Earlier quoted context omitted.

so, out of curiousity, that implies to me that you don't rate any IT security certifications? So would I be right in thinking you don't think that any of the Offsec certs (OSCP/OCSE), CREST certs (CCT etc) or SANS certs are usful? Also, and I'd be genuinely interested to hear your thoughts here, why do you think that IT/Info Sec will take a different path than other professions (medicine, law, accountancy, engineerin…

The "certifications" in medicine and law accompany postgraduate degrees and are far, far more recognized than the random certificates you listed, some of which are profit-making enterprises from for-profit companies.

Ah ok, so would it be fair to say that you're not opposed to the concept of certifiation, per se, but that you're not a fan of existing options in the field?

Of course one problem is "how does a certification become recognized", I mean in IT security it's going to have to start somewhere...

In the UK the IISP are perhaps closest to the "traditional profession" certifications, but they're struggling a bit to get traction.

Re: Security Certifications Are Causing More Harm Than Good

#132

Earlier quoted context omitted.

The "certifications" in medicine and law accompany postgraduate degrees and are far, far more recognized than the random certificates you listed, some of which are profit-making enterprises from for-profit companies.

Ah ok, so would it be fair to say that you're not opposed to the concept of certifiation, per se, but that you're not a fan of existing options in the field? Of course one problem is "how does a certification become recognized", I mean in IT security it's going to have to start somewhere... In the UK the IISP are perhaps closest to the "traditional profession" certifications, but they're struggling a bit to get tract…

You can't wish professionalism into being. You have to build a profession. We're not there yet with any aspect of information security. The hard work of defining the field and its requirements has not yet been done. No organization currently extant on this planet has any business pretending that they know the answers to these questions, let alone charging money to take tests about them.

Re: Security Certifications Are Causing More Harm Than Good

#133
post #104

Earlier quoted context omitted.

You won't be sidelined. If you internalize most of the material from your SANS courses you'll probably be smarter than 2/3 of the people in this industry, if not more. Most of the articles like this seem to come from people in the top 1-5%. Most of them are people that have started their own companies. I'm not a unicorn and most people aren't. I'm pretty confident that Tptacek and everyone else quoted are better secu…

I have no idea if you are or aren't (be careful about your assumptions!). But I am certain that certification has nothing to do with the delta between the two of us.

I'm not crediting my entire base of knowledge with a certification course, but I did learn quite a bit at some of the courses I've taken. I've also learned quite a bit from books, articles, security conference talks, and of course, by spending a ton of time putting the things I read/watch into practice.

I guess my point is that I agree with you that no one needs certifications, but I didn't think the contents of the courses I took were completely worthless.

IMO, some subfields of security are better suited to structured learning than others. For example, forensics can be taught very well in the format of a certification course. However, from my experience, exploitation and reverse engineering are pretty hard to learn in the same format.

Re: Security Certifications Are Causing More Harm Than Good

#134
post #133

Earlier quoted context omitted.

I have no idea if you are or aren't (be careful about your assumptions!). But I am certain that certification has nothing to do with the delta between the two of us.

I'm not crediting my entire base of knowledge with a certification course, but I did learn quite a bit at some of the courses I've taken. I've also learned quite a bit from books, articles, security conference talks, and of course, by spending a ton of time putting the things I read/watch into practice. I guess my point is that I agree with you that no one needs certifications, but I didn't think the contents of the…

I doubt the curricula of any certification is entirely worthless. You're saying you appreciate their value as a forcing function and as a set of guideposts for what to learn. I'm saying: there have to be cheaper ways of setting up forcing functions, and I know there are better guideposts on what to learn --- they're just not promoted as heavily as the certifications, because nobody (except hiring managers, who are too dumb to realize it) makes any money on them.

Re: Security Certifications Are Causing More Harm Than Good

#135

Earlier quoted context omitted.

it's not a false dichotomy. The comment I was replying to was specifically expressing disappointment that his efforts in getting certificate would be overlooked because of a negative attitude in the industry to those certifications. I was merely expressing encouragement that not everyone would look on those certification efforts negatively. The article takes what I think to be an overly absolute position in suggestin…

No, that's not all you said. Your original comment is right there for everyone to read. You attempted to co-opt a position on an orthogonal debate --- whether the industry is adequately welcoming to new talent --- as part of your position on certification. Since I'm a strong opponent of certification and I'm reasonably confident I've done more than you have to bring talent into this field, I object, vehemently, to th…

The original article it titled "Information Security Certifications are Worthless and Causing More Harm than Good"

yes?

The top comment expressed quite clearly discouragement that this attitude of negativity to certification would affect their job prospects.

Yes?

My comment line that I'm presuming you object to is

"Whilst there are people that, unfortunately, take the attitude in the article, I think that there's a load of others that take a more balanced approach and recognise some of the value of certifications."

Didn't mention you, wasn't intending to mention you, referred to the article which clearly takes the position that certifications are actively harmful to the industry, a position that I disagree with.

If you feel I've insulted you, I apologise for that, but I'm afraid I'm currently a bit unsure as to why you feel insulted.

Re: Security Certifications Are Causing More Harm Than Good

#136
post #133

Earlier quoted context omitted.

I'm not crediting my entire base of knowledge with a certification course, but I did learn quite a bit at some of the courses I've taken. I've also learned quite a bit from books, articles, security conference talks, and of course, by spending a ton of time putting the things I read/watch into practice. I guess my point is that I agree with you that no one needs certifications, but I didn't think the contents of the…

I doubt the curricula of any certification is entirely worthless. You're saying you appreciate their value as a forcing function and as a set of guideposts for what to learn. I'm saying: there have to be cheaper ways of setting up forcing functions, and I know there are better guideposts on what to learn --- they're just not promoted as heavily as the certifications, because nobody (except hiring managers, who are to…

I agree completely. There are books that cover the same content in many cases, but not always. I've read quite a few of these books, sometimes they are actually better. I was fortunate enough to take all of my courses for free, but if I was paying $5k out of pocket each time I wouldn't recommend it. I think the norm is to have an employer pay for it.

Re: Security Certifications Are Causing More Harm Than Good

#137
post #136

Earlier quoted context omitted.

I doubt the curricula of any certification is entirely worthless. You're saying you appreciate their value as a forcing function and as a set of guideposts for what to learn. I'm saying: there have to be cheaper ways of setting up forcing functions, and I know there are better guideposts on what to learn --- they're just not promoted as heavily as the certifications, because nobody (except hiring managers, who are to…

I agree completely. There are books that cover the same content in many cases, but not always. I've read quite a few of these books, sometimes they are actually better. I was fortunate enough to take all of my courses for free, but if I was paying $5k out of pocket each time I wouldn't recommend it. I think the norm is to have an employer pay for it.

I know that's true and I find that especially alarming, because it gives those employers a tremendous amount of leverage as gatekeepers to the industry (by underwriting certifications for people they elect to employ and retain).

Re: Security Certifications Are Causing More Harm Than Good

#138

Articles like this one frustrate me. I'm 30, and am essentially starting life over after finishing my military enlistment a couple years ago. all the experience of setting up shops and drafting reports meant nothing with out a degree. So I start working on my degree, and I am absolutely miserable. My love of learning was sucked out of me because I wasn't learning: I was working towards an extra line on my resume. Rig…

Just in general, if you want to stay desirable, you'll always need to be taking the market's pulse. Ask real employers which certifications they value. But since you have to be able to actually do something and not just bluff well to work in this industry, everything hinges on skill at the core.

Focus on developing the skills, not the paper, even if the paper is pre-requisite to get promoted. Credentials should always be second priority. If you have the skills, you'll be in demand as long as this class of problems exists. People hire people to do something. Do that thing they want. Don't put your trust in any type of credential.

That said, very few people will hold worthless certificates against you, and risk-averse corporations will want to hire someone as highly decorated as possible so that they're clean if there's a lawsuit related to operator error or negligence. If they're available at low mental and financial cost, they won't hurt.

Don't get discouraged. Work on developing the skillset and the rest will flow. Get the certs as needed or as they're available, but do not attach your own sense of worth, value, or success to them. Your skills are what will distinguish you no matter how respected or despised your credentials become.

Re: Security Certifications Are Causing More Harm Than Good

#140

Earlier quoted context omitted.

Ah ok, so would it be fair to say that you're not opposed to the concept of certifiation, per se, but that you're not a fan of existing options in the field? Of course one problem is "how does a certification become recognized", I mean in IT security it's going to have to start somewhere... In the UK the IISP are perhaps closest to the "traditional profession" certifications, but they're struggling a bit to get tract…

You can't wish professionalism into being. You have to build a profession . We're not there yet with any aspect of information security. The hard work of defining the field and its requirements has not yet been done. No organization currently extant on this planet has any business pretending that they know the answers to these questions, let alone charging money to take tests about them.

Obviously it takes time to build a profession, but you've got to start somewhere, and part of that path is certification.

Unfortunately the industry is growing far faster than perhaps happened for previous emergent professions, so the time needed to slowly grow professional bodies isn't available.

If it's not commercial organisations that start providing those services, the only other options I can see are some form of union, or some government mandated body. Those are options, but both have their challenges.

Both those options have their downsides.

Post reply on HN