6 ms·
The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is requ
by e79 9y ago
The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. And few certs demonstrate that the person is a good technical writer. It's not enough to know the answers to multiple choice questions. It's not even enough to know how to exploit things. If you don't understand something well and can discuss it in technical detail to a number of different audiences, I don't believe you'll get very far in the industry.
There are a couple of exceptions, of course. OSCP is a good certificate to have. To pass the exam, you are required to not only demonstrate proficiency in several areas (i.e SQL injection, buffer overflows), but you must also write and submit a technical report to a review team. The technical report must address vulnerability overview, impact, risk rating, reproduction steps, and more. Of course the exam isn't perfect, but it's probably the biggest test of real technical understanding and ability I've ever seen.
- dpeck 9y agonice to see OSCP still regarded well. I got it about a decade about when our CTO had an initiative that everyone doing customer interaction (R&D team + professional services support for me at the time) should have a cert. I vehemently disagreed, pointing out that those of us with meaningful degrees from well regarded programs shouldn't have to get one, but in the end I complied to keep the peace. Have to say I enjoyed it at the time and even learned a thing or two. I wasn't exactly new to offensive work, but was nice to get things sharpened up and familiar with a few different approaches. I remember being a bit worked up about the final challenge at the end of it that I took the day off work, but iirc I was able to finish in just a couple hours. It wasn't the most cutting edge content at the time, but it was well organized and ensured that the person being certified could demonstrate some level of practical application and that is far better than most certifications of any sort.
- ganoushoreilly 9y agoThis. So much this. Writing and general social skills are the number 1 thing lacking with people I interact with in the industry. The I know more than you attitude is great amongst peers, but with clients, you don't have to prove you're smarter, instead your job is to make them smarter. Break it down to a 4th grade level, if you can't, you likely don't understand it yourself. I would agree that in general certs have too much weight, but the reality of it is, as it stands, they're the closest bridge / standardization that the market has built for non-Security ilk. Also, Security is not IT. That's another thing that needs to change. As for OSCP, I think it's great and out of all the certs i've taken for various reasons, it's the only one I felt challenged with, in a good way.
- thwarted 9y agoAlso, Security is not IT. That's another thing that needs to change. Do you mean that Security is not currently IT and it should be or do you mean Security is considered to be IT and it shouldn't be ? The amount of stress that you mean to put on the word "not" doesn't come through very well in this medium.
- ZeroManArmy 9y agoI feel like he means it's generalized into the spectrum that falls into IT. Security should be more of specialization, less toolbox?
- Spooky23 9y agoSecurity should be IT. Otherwise, you get a bunch of bullshit cya reports and policies that aren't achievable by the technology deliver people. Security should have an advisory role to the corporate governance folks who maintain policy... usually the lawyers.
- homakov 9y agoKnowing basic English is a prerequisite to any tech job. There's nothing else you need to know to explain a bug. And there's TOEFL/IELTS if you're looking for English language certificate.
- SilasX 9y agoIn theory, maybe, but there are many people who are fluent in basic English but who can't usefully communicate technical matters like bugs (except, perhaps, to someone who already looked at that specific problem with them). Edit: And, in contrast, I've met people who I had a hard time communicating with in spoken English but, had no problems with once we did our communications in writing or with a written point of reference.
- flukus 9y agoIt's a prerequisite until the powers that be realize they can save money by dropping it.
- bitexploder 9y agoCommunication in tech, and especially infosec is a dramatically underrated skill. Infosec consultant for 10 years. I write. A lot. Being able to jump from explaining how we reversed something to devs to an executive who just wants a certain view of how that impacts a release is hard and has taken me a long time. You essentially have to understand the various consumers of your writing at a pretty deep level for it to get read and have impact. A well written report that speaks at the right level to its audiences will generate more proactive security activity than a terse, passive voice bomb of dense technical information.
- tptacek 9y agoIt's unlikely that typical OSCP-holder could write a modern buffer overflow exploit, or even judge exploitability of a memory corruption flaw given the source code and a traceback. Equally importantly: memory corruption exploit development and SQL injection are different skills, and most people who do SQL injection don't need proficiency in "buffer overflows". Why is superficial coverage of "buffer overflows" part of the rubric for that certificate? I don't know, and I don't know that anyone else does either. Is there a single coherent security certificate anywhere in the industry? I'm interested in examples.
- kkirsche 9y agoIf you want that wouldn't you want OSCE instead of OSCP?
- spydum 9y agoTotally agree with this. I think security / infosec is just seen as a small niche, so people lump the cryptographers, auditors, SOC analyst, malware analyst, appsec, incident response type people all in one group. It's hard to find someone who can cover all that ground proficiently. Of course it's also been my findings that people who end up in infosec tends to be generalists, but I wonder if that is shifting now that you see more cyber security school initiatives. Total tangent but, I am absolutely grossed out by "cyber" winning out in the name game. Who let the DoD drive that? Damnit!
- 616c 9y agoThis is why when I was in an infosec bootcamp I begged you to talk to my class and give a dose of reality. The leet kids, a minority few and the rest naïve, I would bribe while they whittled away at online CTFs and MicroCorruption and irritate them with mediocre questions until they tuned me out. I did not care for tools; approach and mindset are order of magnitudes harder to explain. I thought you could be a wakeup call had you told them all the certs pro se is a waste in a program that pushed that nonsense. I talk trash of my certs and skills the whole time and they did not get why. I know you're busy, but I've read your blog and you're preaching to the choir. Starfighter folded, but I would pay for you to test me as a customer and find a mentor to answer my stupid questions that I would pay handsomely for the privilege. I feel I'm not the only one, if you get tired of NCC, that would be amazing!
- jlg23 9y ago> The thing with infosec is that no matter if you're a consultant pen tester or an in-house member of a blue team, a high proficiency in technical writing is required. As much as I admire people who show the courtesy to the trash bin that will eat their report, before any human reading it, of not feeding it "bad" reports: The OPs point of "sense of false security" unfortunately already sets in once someone is hired to "take care of security". This anecdote from about 2000 illustrates that: A friend was hired to do black box penetration testing on the DMZ and internal network of one of the largest travel agencies in Europe. He, of course, found a lot of problems. He wrote a nice report. Like really nice. Point for point "this is your problem, this is what you have to do right now and this is a user-friendly policy you could implement to prevent such issues in the future." It was very pleasant to read, he knows how to handle language. And somewhere on page hundred-something "the first one to claim it, will get a bottle of champagne!". The bottle was claimed a few months later by someone 3 levels above his position. By some high-level manager who did not know anything about IT. But he was the only one to read it (and he only claimed the bottle to figure out whether anyone below him had actually read the report). Two years later company politics allowed those 2 illiterates between my friend and the one manager who could read to be removed from the company. My friend was hired as their chief of security. His first task: work through his own report to fix the 90% that had not been fixed since he wrote it 2.5 years before (the report listed passwords to core routers in plain text as examples for "very stupid passwords" - they all still worked).
- cestith 9y agoOne of the most important aspects of a long report is the prioritization of the contents.
- Liuser 9y agoI used to pentest for a living. Still do some red team exercises every now and then, but far less now that I'm mainly blueteam focused. I personally organized my report into three sections, which seemed to work well. Clients seemed to enjoy the formatting: 1. Executive - Summarize everything in one page at a high level. You could skim it fast if you chose to. Highlight potential negative business impact of each finding. 2. Management - A little more detailed. 2-3 pages max. Most severe findings at the top and recommended action for remediation. 3. Narrative - This is the bulk 80-90% of the report detailing your step by step process including screenshots so that if someone wanted to duplicate your findings they could.