4 ms·
As someone who’s gone deep down the rabbit hole of trying to learn this stuff, I’ll give this advice. Focus on learning computer science, computer architecture
by vntx 6y ago
As someone who’s gone deep down the rabbit hole of trying to learn this stuff, I’ll give this advice. Focus on learning computer science, computer architecture and networks as a foundation.
Learning all this technology without understanding the fundamentals is a waste of time.
Most certs are overrated. They don’t actually test your understanding that well. The people who care a lot about certs are people who you probably don’t want to work with. They’re just a way for the IT guys who run the cert programs to make extra cash. By all means, if your company is willing to pay for cert training get it but don’t waste too much time studying for them.
- g_p 6y agoAbsolutely echo this. You need to really start with the basics, and focus on understanding (i.e. asking yourself) *how* and *why* everything works and happens. In order to find vulnerabilities, you need to understand how a system works, and how all the parts that lead up to it work. You'll ultimately want to understand how $high_level_language ends up as bytecode that executes on the CPU, and if/how you can modify/manipulate that. And a bit about the underlying hardware and electronics never does any harm for some rowhammer type attacks. If you want to defend and secure a system, you need to understand it, and all its dependencies, and the assumptions it makes. You'll want to understand the hardware, and how it's secured etc. For networked systems, get a really good understanding of TCP, UDP and IP. Learn how firewalls work. The aim is to get to a point where you know the fundamentals and how things work to the point there's no "magic" in how the computer works - you know enough to explain a PC from reset vector through to UEFI, bootloader, OS load, software load, network exchanges, etc. And similar for an IP network - you want to know everything about subnets, how VLANs work, how tagging works, how 802.1x works, how WiFi works, etc. And this is just the start! You'll struggle to secure something you don't understand - this is why $bigcompany can't secure their basic IT network - those responsible didn't understand the basic principles, or how the moving parts worked (either on their own or as part of the bigger system), and it ends up compromised by someone who does understand those principles.