4 ms·
Possibly the former, certainly the latter.
by ZephyrP 9y ago
Possibly the former, certainly the latter.
- carterehsmith 9y agoPlease explain how is that so?
- deleted 9y ago[deleted]
- cyphar 9y agoCertification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class. As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is done). So wasting time on a certification that won't help you is putting you behind people that don't waste their time with certifications.
- deleted 9y ago[deleted]
- nulldev 9y agoI think you guys are comparing apples to oranges > Certification in a field such as vulnerability research OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them. > As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications So apparently OSCP won't get you a job at Matasano - but they're not the only game in town, and a lot of other security shops with less name recognition and lower standards do in fact use the OSCP as a positive signal. No, it won't be l33t but it will be a job that they can use to transition to those fancy schmancy companies whose founders are HN regulars.
- tptacek 9y agoName a pentesting firm that cares about the OSCP.
- nulldev 9y agoThe pentesting team at SEI-CERT cares about it.
- raesene6 9y agoIn the UK OSCP can be used for CRT equivalency and I know that many/most pentesting companies care about CRT/CCT qualifications in the UK, if only because they're a requirement for doing work for some government departments, and also some financial services companies will use CREST certification as a check for testers doing work for them. So in that sense, they do care about OSCP.
- carterehsmith 9y ago> Name a pentesting firm that cares about the OSCP. Here: https://rhinosecuritylabs.com/company/ https://rhinosecuritylabs.com/company/ lists OCSP and CISSP and a bunch of other certs. So I guess they care about that. Now, how about you name the pentesting firm that does not list any certs.
- quickben 9y agoWould you hire somebody for c# coding if they have spent a year in school five years ago getting VB.net certification? How about if they just had a job in Vb.net form a year and then worked other languages for five years. I guess it's a very fine difference.
- wepple 9y agopentesting requires fast thinking, an ability to learn quickly, and solve unusual challenges on the go. It could be considered dangerous to become comfortable having lessons to teach you new skills, and fairly arbitrary exams that are a poor replica of the real world to assess your own skill set. A lot of good employers know this, and put zero weight on certa. Or as tptacek mentioned, possibly even consider it a bad thing. If I see a CV with CEH, I go in with an open mind but aware it's probably going to go poorly. I'd rather see someone who bought a stack of books, wrote some vulnerable code to attack, asked for advice from people; demonstrated they could throw themselves in and make it up as they go along.