Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Certification in a field such as vulnerability research doesn't help with your abilities because the techniques you learn are rarely related to the techniques you need to be the best in your class.

As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications (the former is usually where all of the really interesting work is done). So wasting time on a certification that won't help you is putting you behind people that don't waste their time with certifications.



I think you guys are comparing apples to oranges

> Certification in a field such as vulnerability research

OSCP is basically tool-based network pen testing with a bit of outdated websec and buffer overflows thrown into the mix. It's not "vulnerability research" in any meaningful sense of the word. They have some other certs (OSCE) that might purport to target that domain, but idk much about them.

> As for job prospects, generally certification won't get you into companies that are only looking for talent as opposed to a checklist of certifications

So apparently OSCP won't get you a job at Matasano - but they're not the only game in town, and a lot of other security shops with less name recognition and lower standards do in fact use the OSCP as a positive signal.

No, it won't be l33t but it will be a job that they can use to transition to those fancy schmancy companies whose founders are HN regulars.


Name a pentesting firm that cares about the OSCP.


In the UK OSCP can be used for CRT equivalency and I know that many/most pentesting companies care about CRT/CCT qualifications in the UK, if only because they're a requirement for doing work for some government departments, and also some financial services companies will use CREST certification as a check for testers doing work for them.

So in that sense, they do care about OSCP.


> Name a pentesting firm that cares about the OSCP.

Here: https://rhinosecuritylabs.com/company/ lists OCSP and CISSP and a bunch of other certs. So I guess they care about that.

Now, how about you name the pentesting firm that does not list any certs.


The pentesting team at SEI-CERT cares about it.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: