Hacker News new | ask | show | jobs
by intpx 978 days ago
> There's also a huge industry around certification and compliance that adds almost no value. I've never known any experienced security professional who places any value in CISSP, CEH, etc. (In fact they're often a negative indicator of competence). They're the security equivalent of a 6-week coding bootcamp. Mostly just a cash grab.

Preach. The number of times I have had to explain basic computer to a cissp is larger than I’d like to admit.

1 comments

That’s because you’re misunderstanding the purpose of CISSP. It’s about risk mitigation and governance, not 0days and buffer overflows.

If you want that, hire a hacker.