5 ms·
> I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that
by tr4cefl0w 9y ago
> I won a free certification course as an EC-Council Certified Security Analyst, and it's the biggest joke I've ever seen. It's such a massive fucking joke that I decided to not even renew my certification for free because it would just have been a waste of time.
I've been in the field for a couple of years. I work for a global corporation with 10k+ employees and most of our team members in the security department are judge on their skills and various other factors and we filter potential candidates with a small CTF. Certs have very little importance for us, but we're the exception. Most big compagnies require certifications and oddly they are the ones getting hacked.
In the field, we all know that EC-Council certs are bullshit. They are, at best, the laughing stock in infosec because their "Ethical Hacker" certification is a multiple choice answer and requires little technical knowledge and no hands-on.
However, there are a few certs out there that need a lot of work and technical knowledge to be learn for passing it, such as OSCP. It might be easy to get for someone with 10+ years but for relatively new comers, it's a really good challenge to tackle. I started with their lab, thinking it was going to be a piece of cake for me but it's more difficult than I expected, which is a good thing.
But I see your point and I mostly agree.
Care to explain why you think intrusion detection is bullshit?
- lawl 9y ago>Care to explain why you think intrusion detection is bullshit? If they're signature based they're not better than antivirus. I have zero faith in signature based systems. For the stuff that uses machine learning, I have to admit, I have no idea how that stuff performs. But in general I wouldn't trust a machine learning model to not be fooled. Edit: Add to that HTTPS, I don't buy any claim that they can spot malware traffic from malware that isn't dumb, and I don't think MITMing all traffic is an acceptable solution.
- tptacek 9y agoAnomaly detection doesn't do much better than signature systems do. It finds real stuff, but it "finds" so much garbage that the signal is swamped by it.
- user5994461 9y agoI don't know about network detection systems but antivirus heuristics used to be terrific. You can assign 100 students to develop a trojan for a week. At the end of the week, more than 90% of the software are detected as generic trojan by the antivirus.
- lawl 9y ago> You can assign 100 students to develop a trojan for a week. At the end of the week, more than 90% of the software are detected as generic trojan by the antivirus. Probably because 90 of these 100 students have no idea how AV heuristics work and what the trivial tricks are to completely stomp them.
- user5994461 9y agoSome of them quickly realize that the AV is flagging all their binaries and they try to evade it. They will soon discover that it is far from trivial. Don't underestimate the students and don't underestimate the AV. The world is full of surprises.
- lawl 9y agoI don't have to underestimate AV's because I know how they work, and tested myself how easy it is to bypass them. You either don't or you're employed by one and shilling here.
- dang 9y agoThis crosses into personal attack, which is not allowed here. Please read https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and follow the rules when commenting here.
- wglb 9y agoI had an intern who came to the job with one he had written in his idle time. Nothing detected this, so I am thinking that it is not hard at all.
- jstarfish 9y ago> For the stuff that uses machine learning, I have to admit, I have no idea how that stuff performs That's ok. You're in good company with the vendors who sell ML cybersecurity appliances.
- tptacek 9y agoI've worked with global retail banks, investment banks, nationwide insurance firms, stock exchanges, power grid operators, biglaw firms, payroll and benefits providers, and a giant global pharma. Not one of them demanded that I or anyone I worked with possess a certification of any sort. I'm confident there are firms that want to see a CISSP --- I'm guessing they're mostly mid-range regional firms --- but it's not a bigco thing. I second the IDS and WAF bullshit argument.
- wglb 9y agoCare to explain why you think intrusion detection is bullshit? See http://cs.unc.edu/~fabian/course_papers/PtacekNewsham98.pdf http://cs.unc.edu/~fabian/course_papers/PtacekNewsham98.pdf. IDS is considered a speed bump by sophisticated attackers. Which is where you want to focus your energy.