Live data from Hacker News

Security Certifications Are Causing More Harm Than Good

tacnetsol.com

201–210 of 224 posts

Re: Security Certifications Are Causing More Harm Than Good

#201

I was involved once in a criminal forensics case. The defense's "expert" witness was a one man computer shop. He had created his own "certifications" and listed them on his resumé as indications to the court of his suitability as a witness. It was literally "person's-company-name Certified Forensic Examiner". He had created about 6 certifications, all of which he held. It's kinda funny, but also kinda scary that the…

So he got the court to accept a self-signed cert as a trusted root. I don't see how that's much different than asking someone to solemnly swear they are telling the truth, when most humans are as capable as lying about whether or not they are truthful as they are of lying about anything else. If the court has no one capable of gauging the expertise of a witness, it has to trust in someone to do that for them, and if…

I think requiring someone to swear to tell the truth is more a way to nail someone for perjury later than it is to make them tell the truth. It's like those immigration forms where they ask you if you have ever performed an act of terror (or somesuch). Nobody in their right mind is going to check the YES box, but if they find out later that you lied, it's much easier to charge you and jail or deport you.

Re: Security Certifications Are Causing More Harm Than Good

#202

Earlier quoted context omitted.

Obviously it takes time to build a profession, but you've got to start somewhere, and part of that path is certification. Unfortunately the industry is growing far faster than perhaps happened for previous emergent professions, so the time needed to slowly grow professional bodies isn't available. If it's not commercial organisations that start providing those services, the only other options I can see are some form…

No, you're describing a cart that is pulling its horse. The "certification", in whatever form it takes, must follow the professionalization of the field. Regardless, none of the certificates you've mentioned --- OSCP, CREST, or SANS --- will define information security. None of them have any meaningful credibility to experts.

Interesting, so what's your view of how professionalization of the industry should get started?

Re: Security Certifications Are Causing More Harm Than Good

#203

Earlier quoted context omitted.

so, out of curiousity, that implies to me that you don't rate any IT security certifications? So would I be right in thinking you don't think that any of the Offsec certs (OSCP/OCSE), CREST certs (CCT etc) or SANS certs are usful? Also, and I'd be genuinely interested to hear your thoughts here, why do you think that IT/Info Sec will take a different path than other professions (medicine, law, accountancy, engineerin…

The burden of proof should be on whoever is suggesting that security has anything at all to do with those professions, but I'll throw out a couple of observations anyway. Those professions have rules, and are backed by either legislation or science. All participants are bound by said rules. For a lawyer, certain things are legal, certain things are not. Security is a game where the whole objective is to either break…

The challenge that I've been trying to express is that individual excellence is hard to replicate at scale. Sure in sports, that works ok, the numbers are small and the rewards are great, the incentives are there for people to comb through thousands of people to find that one candidate who's truly excellent.

But that's not the reality for most companies, they're not trying to hire the absolute brightest and best, realistcally not everyone can. They're looking for some measurable indications that a candidate has a baseline level of knowledge in a given field.

Now I feel that a good certifiation can be part of that. So a valuable activity for the industry is to try and create better certifications to help companies who aren't in a position to judge for themselves whether someone is great at something or not, that there's a level of knowledge and understanding there.

If current certifications are poor, then it should be possible to articulate why they are poor, and describe what would make them better.

My references to other professions were designed to reference the fact that those professions have had to face similar issues as they've grown and in science, engineering, law, medicine, accountancy, etc etc they've pretty much all decided that some forms of professional certifications are the right way to go.

Not to say that they're perfect, but that they could be better than the alternatives.

Re: Security Certifications Are Causing More Harm Than Good

#204
post #181

Earlier quoted context omitted.

One of the most important aspects of a long report is the prioritization of the contents.

I used to pentest for a living. Still do some red team exercises every now and then, but far less now that I'm mainly blueteam focused. I personally organized my report into three sections, which seemed to work well. Clients seemed to enjoy the formatting: 1. Executive - Summarize everything in one page at a high level. You could skim it fast if you chose to. Highlight potential negative business impact of each findi…

The last (and only) pen test report I saw had some "escalation of such and such via this vague vector, please do x and y to close off this avenue" - strongly implying that they felt the actual trick being used was their IP to be protected?

This was for using citrix boxes to provide saas to a client

Re: Security Certifications Are Causing More Harm Than Good

#205
post #165

Earlier quoted context omitted.

Compliances cover a lot of the basics.

Isn't compliance the reason we have "at least one upper and lower case letter, at least one number, at least one special character and a drop of blood from your first born" style passwords that ruin security?

You're not up to date on your compliance, this sort of stuff is forbidden by the last NIST regulation :D

Re: Security Certifications Are Causing More Harm Than Good

#206
post #165

Earlier quoted context omitted.

Isn't compliance the reason we have "at least one upper and lower case letter, at least one number, at least one special character and a drop of blood from your first born" style passwords that ruin security?

You're not up to date on your compliance, this sort of stuff is forbidden by the last NIST regulation :D

So only 20 years until it filters down to us plebs then?

Re: Security Certifications Are Causing More Harm Than Good

#207
post #163

Earlier quoted context omitted.

How many of those industries does certification actually work in? Does it prevent dodgy lawyers and accountants?

Certification does work in some industries. When a lawyer is admitted to the bar, that is generally taken as proof that they have some idea of what they are doing. Bar exams are hard. And the bar also provides a forum for dealing with shady lawyers. If a lawyer treats you badly, you can file a complaint with their bar association and they might get disbarred. This is an area where cyber training and certs is not as g…

TV may be leading me astray, but isn't disbarment usually for ethical reasons, not general incompetence?

Re: Security Certifications Are Causing More Harm Than Good

#208

Earlier quoted context omitted.

Describe the overflow exploit you wrote. What was the vulnerability, and what did the exploit look like?

Unfortunately I can't get into too much detail because I had to sign an NDA (to prevent cheating). But the process was similar to when I have found them in the wild: identify the app, install it locally, fuzz various parameters (it was a real application, albeit an old one), find the crash, figure out stack space, figure out bad characters, find the right JMP ESP or equivalent instructions in a loaded library, write…

This sounds like a 100-150 points (== entry-level) CTF challenge.

Re: Security Certifications Are Causing More Harm Than Good

#209

Earlier quoted context omitted.

Describe the overflow exploit you wrote. What was the vulnerability, and what did the exploit look like?

Unfortunately I can't get into too much detail because I had to sign an NDA (to prevent cheating). But the process was similar to when I have found them in the wild: identify the app, install it locally, fuzz various parameters (it was a real application, albeit an old one), find the crash, figure out stack space, figure out bad characters, find the right JMP ESP or equivalent instructions in a loaded library, write…

[deleted]

Re: Security Certifications Are Causing More Harm Than Good

#210
Disagree with the sensationalism of the article but for anicdata: I interviewed 41 security engineers last year. Gave offers to 8, hired 5.

A few, less than 10, had certs listed on their resumes and no one in the interview loops gave weight to those certs or even talked about them from what I recall

Post reply on HN