5 ms·
This is a complete waste of time and money with the usual bullshit material taught by people who don't really have a clue and completely-out-of-touch-with-reali
by insertcredit 8y ago
This is a complete waste of time and money with the usual bullshit material taught by people who don't really have a clue and completely-out-of-touch-with-reality academic focus (write a buffer overflow!).
If you really want to learn invaluable cybersecurity skills,
start playing wargames. I suggest (1) which is one of the best. If you manage to reach level 25 on your own, then you are elite and the knowledge you gained doing so is not only extremely valuable but something you can be proud of.
(Sidenote: I would hire anyone who reached vortex level 25 on the spot and pay him a six figure salary, without looking at any of his other qualifications/degrees/past experience)
Additionally, read every single phrack (2) magazine from the past 20 years and try to understand most of the material within.
(1) http://overthewire.org/wargames/vortex/ http://overthewire.org/wargames/vortex/
(2) http://phrack.com http://phrack.com
- growtofill 8y agoThanks for sharing Vortex wargame! > I would hire anyone who reached vortex level 25 What would be the position/role?
- insertcredit 8y agoI'm not currently in a position to hire people, see my previous reply to danesparza. Doing these and other similar challenges and reading and understanding phrack articles would give you a solid foundation to start doing reverse engineering and vulnerability research and reap the rewards that come from successfully doing so.
- noelwelsh 8y agoSecurity is a much larger field than what the game you linked covers.
- mehrdadn 8y agoAlmost every single comment I've seen on this page is about how the parent comment/post doesn't understand what security is about...
- noelwelsh 8y agoMost of the comments I see are about the reputability of an online degree, the value of getting a degree, and comparisons to other similar options. I'm not even sure we're reading the same comments section.
- mehrdadn 8y agoI guess those floated to the top... I had read a bunch of the comments (e.g. [3-6]), but now yours and the parent's [1, 2] are now near the top: [1] https://news.ycombinator.com/item?id=17772970 https://news.ycombinator.com/item?id=17772970 [2] https://news.ycombinator.com/item?id=17773218 https://news.ycombinator.com/item?id=17773218 [3] https://news.ycombinator.com/item?id=17770602 https://news.ycombinator.com/item?id=17770602 [4] https://news.ycombinator.com/item?id=17770724 https://news.ycombinator.com/item?id=17770724 [5] https://news.ycombinator.com/item?id=17770883 https://news.ycombinator.com/item?id=17770883 [6] https://news.ycombinator.com/item?id=17770722 https://news.ycombinator.com/item?id=17770722 etc.
- ai_ia 8y ago> (Sidenote: I would hire anyone who reached vortex level 25 on the spot and pay him a six figure salary, without looking at any of his other qualifications/degrees/past experience) This is a strong statement. I remember reading somewhere that Bill Gates said he would hire anyone who has read The Art of Computer Programming by Knuth. I think these challenges should be collated and put up in a website where motivated individuals can grab the opportunity to prove themselves.
- qeternity 8y agoReading != doing I take the same approach. Have been around many well qualified people who lack critical thinking and thus suffer poor output. There is no amount of education that can correct for this.
- yayana 8y agoMy coworkers who stayed in security all did the master's route instead of the competent pentester route.. There are a lot of jobs and they are a lot more stable for people who have studied the fields academically. There's some high pay for those who haven't, but a lot of it ends up being temporary.
- danesparza 8y agoThanks for sharing. Just out of curiosity, are you in a position to hire somebody -- or are you just suggesting that you would be a willing teammate for somebody with these criteria?
- insertcredit 8y agoI'm not currently in a position to hire people, but having served in that role in the past, I would given the opportunity not hesitate to follow through with what I said (practical concerns aside such as figuring out if someone went through the challenges on his own). So my comment was mostly trying to illustrate that the skills one learns by going through these kind of challenges are extremely useful in practice and the skills one learns by doing an Msc of the sort advertised here pretty much completely useless, assuming one wants to do reverse engineering and vulnerability research and not just push paper, point at his Master's and call himself a "security expert".
- eganist 8y agoI am, and I disagree with a lot of what the OP put forward. Security academics, self-taught pentesters, and people who simply gained hard security experience in their day to day jobs each bring something unique to the table. I'm far more likely to pick up the principal engineer with a security MS for a security architect role than I am someone who can prove to me they passed an OSCE. That said, for the person who can prove to me they passed an OSCE, I'll knock two years off the pentest experience requirement for any such role.
- vultour 8y agoThanks for the wargame. Seems like fun, although the SSH connection feels like it's hosted in someone's basement.
- justonepost 8y agoI think what you're referring to is pentesting. Agreed, for pentesting I highly doubt the course will be of much benefit. However, for developing compliance and architectural plans for a large enterprise, it's quite a bit more complex problem.
- insertcredit 8y agoWhat I'm referring to is the core of cybersecurity: Reverse engineering & vulnerability research.
- blazespin 8y agoUnfortunately, that doesn't help much if you're managing security for a group of 500 engineers releasing product everyday.
- deleted 8y ago[deleted]
- jgeralnik 8y ago+1 to vortex. I participate often in CTF competitions and it's my go to recommendation for serious people looking to get more involved. Most of the early stages are great because they are no nonsense - they give you the papers explaining the solution, and just ask you to do the work of understanding and implementing them. Stage 16 is one of my favorite challenges all time. It took me weeks to solve and the solution is very impressive. I've been stuck for the last few years on stage 23. Unlike the rest of the challenges it is a stenography level, and I'm not convinced that it is still solvable today.
- philipodonnell 8y ago> I'm not convinced that it is still solvable today. This sounds fascinating since progress does not tend to work that way. What is it about this problem that leads you to think it was solvable in the past but no longer?
- jgeralnik 8y agoThe challenge in question is just a jpg of the logo of ruxcon 2004. The password for the next level is presumably steganographically encoded in it. The challenge is much easier (and perhaps only possible) given the original image, but the logo is no longer on the internet. After scouring web archive and using all Google fu at my command I found some instances of the image but all in different sizes/dimensions. The name of the level is "the properties of a mirror" which hints that you need to find a mirror of the original site in order to solve the level, and I think that the mirrors are no longer online. Note for anyone unfamiliar that this level is not at all representative of vortex - all the other levels are all hard core exploit implementation and not stego challenges. In general I don't like stego because I feel that it is more of "try to guess what I'm thinking" than solving interesting challenges.
- philipodonnell 8y ago> The name of the level is "the properties of a mirror" which hints that you need to find a mirror of the original site in order to solve the level, and I think that the mirrors are no longer online. I would assume that if this were the case someone who has already completed that level could check if where they found it was still up? Perhaps this is not the interpretation of the level name that the writers had in mind?
- personlurking 8y ago> (Sidenote: I would hire anyone who reached vortex level 25 on the spot and pay him a six figure salary, without looking at any of his other qualifications/degrees/past experience) It may be obvious but I'm currently drawing a blank. What are other possible non-programming examples of reaching a certain level in a game and that being worthy of an immediate hire (not including the video game industry)? Complete courses via gamified education is a cool concept.
- blazespin 8y agoIts not really a game, but a series of tests that have been gamified. I am sure you could do the same with leetcode.
- bufferoverflow 8y agoIs it a waste of time and money though, if you want MS on your resume? It's a known fact that MS-holder salaries grow faster than BS (and PhD faster yet). So seems like financially it's a no-brainer.
- bovermyer 8y agoThe cost of a master's or doctoral program is significant. It's not just the price of admission, but also the opportunity cost. Most employers who will do education reimbursement only cover a small portion of the cost. If you leave the workforce to study full-time, then it's often free (with the caveat that you must have a research assistantship or teaching assistantship), but then you lose out on multiple years' worth of salary. So it's not a "no-brainer," financially speaking.
- bitL 8y ago> Sidenote: I would hire anyone who reached vortex level 25 on the spot and pay him a six figure salary, without looking at any of his other qualifications/degrees/past experience Anyone reaching 25+ would either: 1) Command significantly more than just (low) 6-figure salary 2) Won't be willing to be hired as an employee
- insertcredit 8y agoHaving done 25 myself, I was willing to get hired as an employee doing reveng a long time ago. But that was before 2010 and you're probably right today. Good reverse engineers can print money and don't have to work for pointy hair bosses. Good point.
- deleted 8y ago[deleted]
- vzcx 8y agoI appreciate your mentioning overthewire and claiming that you'd hire someone on the basis of their ability to make it through these challenges. I do wish more CTFs kept their challenges online after the competition: good ones and these wargames form what are essentially the problem sets for a top-tier exploit engineering program. I cut my teeth on these wargames, as well as pwnable.kr/tw and, of course, microcorruption. While working through some of these challenges and finally popping a shell was definitely satisfying, I'm not sure I'll feel "elite" until perhaps I take home master of pwn at cansecwest.