Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

141–150 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#141

Earlier quoted context omitted.

You can't wish professionalism into being. You have to build a profession . We're not there yet with any aspect of information security. The hard work of defining the field and its requirements has not yet been done. No organization currently extant on this planet has any business pretending that they know the answers to these questions, let alone charging money to take tests about them.

Obviously it takes time to build a profession, but you've got to start somewhere, and part of that path is certification. Unfortunately the industry is growing far faster than perhaps happened for previous emergent professions, so the time needed to slowly grow professional bodies isn't available. If it's not commercial organisations that start providing those services, the only other options I can see are some form…

No, you're describing a cart that is pulling its horse. The "certification", in whatever form it takes, must follow the professionalization of the field.

Regardless, none of the certificates you've mentioned --- OSCP, CREST, or SANS --- will define information security. None of them have any meaningful credibility to experts.

Re: Security Certifications Are Causing More Harm Than Good

#142

Earlier quoted context omitted.

Exactly... CISSP shows that you have an understanding of risk, numerous compliance requirements, and how much basic housekeeping activities like asset inventory management or having proper data classification/access controls help in maintaining security. The title of "Information Systems Security Professional" suggests that you're knowledgeable enough to speak intelligently in all of the ten domains, but your everyda…

I've been in the industry since 1995. I've worked for Fortune 500 companies. What's the experience I'm missing to appreciate the CISSP? Because from where I stand, it seems mostly like a scam to me.

Then by definition you don't have any expectations for "a CISSP to be an expert in 'tech ninja' stuff", as I was saying... ;-) I'll agree with you that, to an extent, all certifications are a scam, especially those with artificially high sit-down fees. My point is that, CISSP does not claim to be a gauge for whether you are a crypto expert, just that you should know the difference between basic types of encryption and when it makes sense to encrypt your company's data, so that an accountant in one of those Fortune 500 companies you mentioned doesn't make a costly mistake. In short, it's not about "how to trigger an RCE", but, if you're in an Ops role, about "how can I ensure my users are patched without delay, so that I can minimize the impact of an RCE". Does that make sense?

Re: Security Certifications Are Causing More Harm Than Good

#143
post #13

There is a huge problem in IT. It's not certifications. It's the totally illogical bias against certifications. There's no reason someone can't have both skills and certifications, but everyone treats them as mutually exclusive. Certs help with administrative things like HR requirements, contractual obligations, audits, etc... No, those things do not make one secure, but running a business is not only about being sec…

> Certs help with administrative things like HR requirements, contractual obligations, audits, etc. You're pointing out things that are generally considered to be failures in our sphere anyway. I don't think that's unrelated. HR brings us terrible candidates? Certs (currently) don't help that, and when HR over emphasizes them, we can blame the certs. (In theory, certs COULD help, but the people that get the cert inst…

It sounds like when the poster said "address business issues" they meant "enhance regulatory/bureaucratic issues."

Re: Security Certifications Are Causing More Harm Than Good

#145
post #4

I think soon that this sentiment will start to apply to Universities. It seems inevitable at some point in the near future there will be an online 'university' (for lack of a better word) who's graduates will be considered equal or even better than a standard university education, particularly for tech related degrees. Universities have been a centralized source of accreditation for a long time. All it takes is for s…

> near future there will be an online 'university' who's graduates will be considered equal or even better than a standard university education http://www.uoc.edu since 1994

Western Governors University is a choice in the US, too. I am currently attending, and it's different from any other college I have gone too. All of the classes are competency based and self-paced, meaning theoretically you can get a Bachelor's degree in 6 months.

Re: Security Certifications Are Causing More Harm Than Good

#146
post #68

The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in techn…

> The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required.

As much as I admire people who show the courtesy to the trash bin that will eat their report, before any human reading it, of not feeding it "bad" reports: The OPs point of "sense of false security" unfortunately already sets in once someone is hired to "take care of security". This anecdote from about 2000 illustrates that:

A friend was hired to do black box penetration testing on the DMZ and internal network of one of the largest travel agencies in Europe. He, of course, found a lot of problems. He wrote a nice report. Like really nice. Point for point "this is your problem, this is what you have to do right now and this is a user-friendly policy you could implement to prevent such issues in the future." It was very pleasant to read, he knows how to handle language. And somewhere on page hundred-something "the first one to claim it, will get a bottle of champagne!".

The bottle was claimed a few months later by someone 3 levels above his position. By some high-level manager who did not know anything about IT. But he was the only one to read it (and he only claimed the bottle to figure out whether anyone below him had actually read the report). Two years later company politics allowed those 2 illiterates between my friend and the one manager who could read to be removed from the company. My friend was hired as their chief of security. His first task: work through his own report to fix the 90% that had not been fixed since he wrote it 2.5 years before (the report listed passwords to core routers in plain text as examples for "very stupid passwords" - they all still worked).

Re: Security Certifications Are Causing More Harm Than Good

#147
“Would you feel comfortable letting a doctor be your primary care physician if all it took was to pass a written multiple choice exam?”

Doctors have to go through extensive certification in order to be hired, and constantly have to re-certify. The difference, though, is that a doctor's certification is very rigorous and well-designed.

The difference is that a medical certification proves competency. Certifications in our field do not.

Re: Security Certifications Are Causing More Harm Than Good

#148
post #6

There's 'compliance security' and then there's 'street-smart security'. They are very different things. Most organizations aim for compliance (it's cheap and easy). They base security on contracts, certs and insurance policies. Street-smart security practitioners are appalled by this. And, management doesn't understand why the 'security people' aren't on-board with 'compliance'. It's a lot like the old west with Cowb…

Compliances cover a lot of the basics.

Re: Security Certifications Are Causing More Harm Than Good

#149
post #22

Earlier quoted context omitted.

Starfighter is defunct. https://twitter.com/tqbf/status/771533037666390017

Was there ever a post detailing why? I searched for it several times but found nothing...

I think this will probably be it.

http://www.kalzumeus.com/2016/12/30/kalzumeus-software-year-...

Re: Security Certifications Are Causing More Harm Than Good

#150
I had this comment from a recruiter on LinkedIn:

    The CCNA Security only costs $180. It's a very small investment and I don't see why anyone serious about security wouldn't spend the money to get certified
It's like they viewed it as being completely outside of any actual training and development time - even the person hiring saw it as a sticker you were meant to buy.

Edit: Interestingly, this vendor specific cert is far more valuable in my country than anything like CEH if recruiters are anything to go by

Post reply on HN