7 ms·
I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the
by zabuni 9y ago
I thought the OSCP, which is the one he recommends, was a little better than the others. Not enough to be a requirement, given other skills, but better than the multiple choice tests of the CISSP and Security+. Unlike with those, the OSCP involves an actual network and using actual exploits.
I wouldn't automatically discount someone who put the OSCP on their resume, like I would the CISSP, CEH, and Security+. Any experience, even non-pentesting, would probably trump it though.
- tptacek 9y agoIf I'm honest, and I feel like I should be when it comes to talking about my profession even though I'm going to be a little impolitic here and it could cost me elsewhere: yeah, I definitely do discount people a little bit if they volunteer to me that they have OSCP certification. Avoid certification.
- 616c 9y agoI'm a fan of yours. I asked before and I'll ask again as someone who is depressed into day 3 of a new annual round of OSCP study and yet again crippled by impostor syndrome: without a formal degree, what is there beyond your Amazon booklist? I started MicroCorruption and RE flummoxes me. I keep coming back to it because I can tell how weak I am and it has pissed me off for 2 years. Even in OSCP i get bent out of shape on my insufficiency there and never focus on other stuff. I don't want to be a Metasploit jockey. Where to from here? Online CS courses in C and ASM work my way up? I don't have a degree in it.
- tptacek 9y agoI don't have a formal degree! I have 1 semester of college from 1995, and that's it. You don't have to do RE to be in software security. There's virtually no assembly-level RE in web application security, and very little of it in mobile security. Both of those specialties are more lucrative than RE, a specialty where maybe the top 10% go to high-status RE and exploit dev careers, and the other 90% go to low-status malware analysis and SOC jobs. My advice is to pick a technology stack you really like and get comfortable with it at a nuts and bolts level, and then build security expertise on top of that. Maybe that's iOS and Swift, or maybe it's web and Django, or maybe it's distributed databases. Pick something, get good, and then be a security expert for that thing.
- 616c 9y agoPicking has always been hard I guess. Thank you very much for the solid advice. I will keep it in mind moving forward.
- philprx 9y agoThen don't pick: surf r/netsec and use anything you find fun. 1 month later look at what you practiced most and enjoyed most, here you are, some part of your brain actually picked the possibly right thing for you. :)
- Bartweiss 9y agoThis is a great trick in all sorts of settings. If a choice seems meaningful but hard to make, look for a way to bypass it until the answer is obvious.
- SCHiM 9y ago> Avoid certification. IMO that should be avoid current certification. Avoiding all certification for all eternity would imply that training decent pentesters/hackers is something that cannot be done in a controlled methodical way. Which would be a setback for the entire infosec industry, IMO, because I do think that such a thing (infosec is not a special snowflake) is possible. I think OSCP is actually a big step in the right direction. The harder challenges in their training network force you (and encourage you) to deeply investigate the underlying security issue. That part of the training actually focuses on the underlying conditioning that you need to become a good pentester, as shown by their slogan 'try harder'. It's the same thing that armies the world over do. The army also realized that knowing everything there's to know about tactics and how to operate a weapon is not enough, soldiers also need to be aggressive and need to be conditioned to be able to effectively engage an enemy. So there's training designed to increase a soldier's willingness to fire upon enemies when ordered to. The same goes a bit for this training, where underlying simple technical guidance is provided at the start of the training, and later a trainee is left to themselves and pushed to investigate on their own, something that I'd recognize as one of the cornerstones of a successful hacker. Still, I'd also avoid hiring a person for a technical position if all they can show is a CISM/CISP/w\e
- 09pon 9y agoYou'd be better off participating in CTF challenges than doing the OSCP.
- SCHiM 9y agoHeh I tried that a few times, but I found that many of them have devolved into hopelessly contrived abominations of true security issues. Fun games to be sure, but of trivial usefulness for actually building up skills I think. I do like the ones that offer memory corruption/exploitation challenges, but those are few and far between.
- carterehsmith 9y ago>> Avoid certification. Why? Is that something that can hurt your abilities, or your employment prospects?
- ZephyrP 9y agoPossibly the former, certainly the latter.
- carterehsmith 9y agoPlease explain how is that so?
- deleted 9y ago[deleted]
- cyphar 9y agoCertification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class. As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is done). So wasting time on a certification that won't help you is putting you behind people that don't waste their time with certifications.
- deleted 9y ago[deleted]
- nulldev 9y agoI think you guys are comparing apples to oranges > Certification in a field such as vulnerability research OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them. > As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications So apparently OSCP won't get you a job at Matasano - but they're not the only game in town, and a lot of other security shops with less name recognition and lower standards do in fact use the OSCP as a positive signal. No, it won't be l33t but it will be a job that they can use to transition to those fancy schmancy companies whose founders are HN regulars.
- topkeker 9y agoThis might be doing others a disservice. Don't avoid certification altogether, some people actually enjoy the study/test and tangible outcome of certification. I personally have none, it's not for me. Rather avoid certification if you just want to have 20 lines on your resume to look like a ninja and brag. I'm a hiring manager in infosec, and same deal if you brag about certs I start to tune out.
- kbart 9y ago"Avoid certification." So how do you get through HR wall? Padding CV with keywords is a common way to get an interview. I'm an embedded system engineer looking to move closer to IT security, so how do I get there without experience and certifications as virtually all jobs require one, another or both (except junior positions, but I'm too old to start from the very bottom)? I do learn a lot on my spare time, but you still need to get a chance to demonstrate your skills, which is impossible if your CV is discarded as "requirements are not met" (a.k.a not enough keywords on CV match the ones in job description).
- wepple 9y agoHR wall? You're applying at the wrong places. If a company needs to see letters on your CV, it's because they have no idea what/who they want. A decent company will have your future colleagues heavily involved in the hiring process, and they'll know how to chat to you about security.
- nulldev 9y ago> HR wall? You're applying at the wrong places This elitism is not helpful. There are finite employers in the world, and many of them do screen based on keywords. That's reality. Applicants who are entering the job market might not always have the luxury of disregarding n% (where n most likely > 75) of their potential employers based on stuff like "oh well any real company wouldn't screen my resume..."
- wepple 9y agoThe security industry is remarkably small. If you're going to spray your CV and hope for the best, sure, having as many certs as possible will get you past the first interview. But chances are if someone is browsing HN they're at least genuinely engaged enough to do better than that. You're advocating for people to shoot for average, I'm suggesting to not settle.
- nulldev 9y ago
- vellum 9y agoIf you're entry-level and don't have a network, certs help you get through the HR filter. Once you're mid-level, you can use your network and experience.
- nulldev 9y agoThis. Simply saying "certifications are bad don't get them" is not universally helpful advice. Some people will definitely face improved career prospects with the right cert(s) depending on their market and level of experience. Not all companies have equally enlightened hiring practices - and not all prospective employees can pick and choose the way some veteran HN members can.