I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits.
I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any experience, even non-pentesting, would probably trump it though.
If I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification.
IMO that should be avoid current certification. Avoiding all certification for all eternity would imply that training decent pentesters/hackers is something that cannot be done in a controlled methodical way. Which would be a setback for the entire infosec industry, IMO, because I do think that such a thing (infosec is not a special snowflake) is possible.
I think OSCP is actually a big step in the right direction. The harder challenges in their training network force you (and encourage you) to deeply investigate the underlying security issue. That part of the training actually focuses on the underlying conditioning that you need to become a good pentester, as shown by their slogan 'try harder'.
It's the same thing that armies the world over do. The army also realized that knowing everything there's to know about tactics and how to operate a weapon is not enough, soldiers also need to be aggressive and need to be conditioned to be able to effectively engage an enemy. So there's training designed to increase a soldier's willingness to fire upon enemies when ordered to.
The same goes a bit for this training, where underlying simple technical guidance is provided at the start of the training, and later a trainee is left to themselves and pushed to investigate on their own, something that I'd recognize as one of the cornerstones of a successful hacker.
Still, I'd also avoid hiring a person for a technical position if all they can show is a CISM/CISP/w\e
Heh I tried that a few times, but I found that many of them have devolved into hopelessly contrived abominations of true security issues. Fun games to be sure, but of trivial usefulness for actually building up skills I think.
I do like the ones that offer memory corruption/exploitation challenges, but those are few and far between.
So how do you get through HR wall? Padding CV with keywords is a common way to get an interview. I'm an embedded system engineer looking to move closer to IT security, so how do I get there without experience and certifications as virtually all jobs require one, another or both (except junior positions, but I'm too old to start from the very bottom)? I do learn a lot on my spare time, but you still need to get a chance to demonstrate your skills, which is impossible if your CV is discarded as "requirements are not met" (a.k.a not enough keywords on CV match the ones in job description).
This elitism is not helpful. There are finite employers in the world, and many of them do screen based on keywords. That's reality. Applicants who are entering the job market might not always have the luxury of disregarding n% (where n most likely > 75) of their potential employers based on stuff like "oh well any real company wouldn't screen my resume..."
The security industry is remarkably small. If you're going to spray your CV and hope for the best, sure, having as many certs as possible will get you past the first interview.
But chances are if someone is browsing HN they're at least genuinely engaged enough to do better than that. You're advocating for people to shoot for average, I'm suggesting to not settle.
> You're advocating for people to shoot for average, I'm suggesting to not settle.
From my perspective, I'm advocating that people don't inadvertently shoot themselves in the foot. They might not yet be qualified to work at Matasano or [insert top tier security shop here] : not everyone is.
Assuming someone isn't (yet) qualified to work with their dream employer, what do you suggest they do? "Don't settle" in that scenario sounds a lot like "be unemployed". I'm straight up saying it's better to build up skills at a job - even if that job isn't their endgame.
I'm generally on board with this point - encouraging everyone to shoot for the top 10% inherently means letting down 90% of people.
But I think in this case, the issue might be that rather than one job being the first step to the other, we're talking about two totally distinct tracks. If a company is sufficiently shoddy and certification-happy, it's possible that they don't even provide meaningful experience for someone seeking the top-tier options. You might be better served by hardening systems at some general software job than getting an entry-level security job and blindly throwing Nessus at client's systems.
"A decent company will have your future colleagues heavily involved in the hiring process"
Of course, but you still have to get to them first as no sane company makes their engineers to do 1st round CV screening (especially for publicly announced positions where tens or hundreds of CVs are applied). From my personal experience, technical interview with an engineer is usually only on 2nd/3rd round, so we are back to square 1. Yes, I know the best positions are filled through networking and recommendations, but that's not an option when you live outside of tech bubbles.
I'm a fan of yours. I asked before and I'll ask again as someone who is depressed into day 3 of a new annual round of OSCP study and yet again crippled by impostor syndrome: without a formal degree, what is there beyond your Amazon booklist?
I started MicroCorruption and RE flummoxes me. I keep coming back to it because I can tell how weak I am and it has pissed me off for 2 years. Even in OSCP i get bent out of shape on my insufficiency there and never focus on other stuff.
I don't want to be a Metasploit jockey. Where to from here? Online CS courses in C and ASM work my way up? I don't have a degree in it.
I don't have a formal degree! I have 1 semester of college from 1995, and that's it.
You don't have to do RE to be in software security. There's virtually no assembly-level RE in web application security, and very little of it in mobile security. Both of those specialties are more lucrative than RE, a specialty where maybe the top 10% go to high-status RE and exploit dev careers, and the other 90% go to low-status malware analysis and SOC jobs.
My advice is to pick a technology stack you really like and get comfortable with it at a nuts and bolts level, and then build security expertise on top of that. Maybe that's iOS and Swift, or maybe it's web and Django, or maybe it's distributed databases. Pick something, get good, and then be a security expert for that thing.
Then don't pick: surf r/netsec and use anything you find fun. 1 month later look at what you practiced most and enjoyed most, here you are, some part of your brain actually picked the possibly right thing for you. :)
This is a great trick in all sorts of settings. If a choice seems meaningful but hard to make, look for a way to bypass it until the answer is obvious.
This might be doing others a disservice. Don't avoid certification altogether, some people actually enjoy the study/test and tangible outcome of certification. I personally have none, it's not for me.
Rather avoid certification if you just want to have 20 lines on your resume to look like a ninja and brag. I'm a hiring manager in infosec, and same deal if you brag about certs I start to tune out.
pentesting requires fast thinking, an ability to learn quickly, and solve unusual challenges on the go. It could be considered dangerous to become comfortable having lessons to teach you new skills, and fairly arbitrary exams that are a poor replica of the real world to assess your own skill set.
A lot of good employers know this, and put zero weight on certa. Or as tptacek mentioned, possibly even consider it a bad thing. If I see a CV with CEH, I go in with an open mind but aware it's probably going to go poorly. I'd rather see someone who bought a stack of books, wrote some vulnerable code to attack, asked for advice from people; demonstrated they could throw themselves in and make it up as they go along.
Certification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class.
As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is done). So wasting time on a certification that won't help you is putting you behind people that don't waste their time with certifications.
> Certification in a field such as vulnerability research
OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them.
> As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications
So apparently OSCP won't get you a job at Matasano - but they're not the only game in town, and a lot of other security shops with less name recognition and lower standards do in fact use the OSCP as a positive signal.
No, it won't be l33t but it will be a job that they can use to transition to those fancy schmancy companies whose founders are HN regulars.
In the UK OSCP can be used for CRT equivalency and I know that many/most pentesting companies care about CRT/CCT qualifications in the UK, if only because they're a requirement for doing work for some government departments, and also some financial services companies will use CREST certification as a check for testers doing work for them.
If you are a black hat, would that help if you have a certificate and half the world knows about it? Transitioning from a (anonymous) black hat to a white hat is relatively painless. However the opposite could be quite painful, because the probability of you ending up on the suspects list will be much higher. Also consider how blurred the line between white/black hat really is.
If you're entry-level and don't have a network, certs help you get through the HR filter. Once you're mid-level, you can use your network and experience.
This. Simply saying "certifications are bad don't get them" is not universally helpful advice. Some people will definitely face improved career prospects with the right cert(s) depending on their market and level of experience. Not all companies have equally enlightened hiring practices - and not all prospective employees can pick and choose the way some veteran HN members can.
I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any experience, even non-pentesting, would probably trump it though.