Posts tagged “rants”.

Now I can analyze your intrusions *and* handle your incidents!

I was very lucky this summer because the Security Office got some funding for training and footed the bill for another SANS course. I opted to go for SANS SEC504: Hacker Techniques, Exploits & Incident Handling. I did a “At Home” course this time, which met three times a week online and was taught Ed Skoudis and John Strand. While I did like the self paced learning that I had for SEC503, but it was very cool to be taught by the folks that you always heard on and about PSW. Plus, I was able to make snide remarks in the chat window.

As much as I still wonder about certifications in general, I am starting to really like SANS courses. The course wasted little time on the basics and quickly had us rolling up our sleeves mucking about in what I classify as “cool sh*t”. While I did have stretches where I was just nodding and going “yeah… yeah… know that… uh-huh…” I would occasionally see or hear something, go “Oooh!”, and make write down some notes. The course consisted of 5 books of material, ranging from incident planning and handling to how to exploit systems, and then culminated in a capture the flag contest. I am ashamed to say the CTF was designed well enough that I could barely establish a toehold on the first server, I guess my days of staying up for an entire weekend and dominating the CTF at Northeastern is far behind me.

Although the course itself wrapped up sometime in the summer, I finally took my certification test today and passed with flying colors. I am happy to report that I have even more alphabet soup after my name and I am now “Ben Jackson, GCIA, GCIH”

http://www.sans.org/security-training/hacker-techniques-exploits-and-incident-handling-40-mid

http://www.sans.org/security-training/hacker-techniques-exploits-and-incident-handling-40-mid

Alphabet Soup: SANS, GIAC, GCIA, and Cluefulness

Over the past few months, work generously paid for me to take a SANS course online. I opted to take “SEC503: Intrusion Detection In-Depth.” This was my first “certification” type course, and overall I was pleased. The course was on-target and wasted no time getting dirty into the nuts and bolts of the topic. It was very well done and despite me knowing a bunch of the basics, more often then not it was new territory for me and I had a ball learning it. There were areas which I wondered how useful they were going to be (Attacks against rsh? Really?) but I’d say 95% of the material was relevant to me in dealing with my day-to-day tasks. On the exam, I kicked ass and took names. So now, I am a GIAC Certified Intrusion Analyst. Bow before me.

I’ve always wondered about certifications. While there are people who have them that are very clueful, there is a sizable group who are certified who I often wonder if they really know how to use it. Now that I’ve gone through the process, I still wonder. I now have a sheet of paper that says I can be given a packet dump and tell you if you are doomed or not. While I feel that I am reasonably adept in studying IDS alerts and getting a reasonably good idea as to what is going on, I don’t think I should be put in charge of a large IDS system any time soon.

I’m not knocking ceritifcations. They are a good thing and I believe it does show that I do (partially) know what I am talking about when it comes to these things. More then anything, it shows that I know the basics, I can sit down and field questions tossed at me, and I can answer a 150 question exam. Nothing more, nothing less. What worries me that people take these certifications as gospel and are ready to proclaim people experts by the amount of letters after their name rather then they experience on the ground.

OK… Meandering Rant off.

Women, knowledge, technical fields and the Hacker Ethic

Stacy Thayer, one of the Security Twits that I follow, posted a blog entry regarding an encounter she had with some neanderthal at RSA 2008. Quite frankly, it made me shake my head. The idea of judging someone’s knowledge based on their body parts is far too common in some technical circles, and what drives me nuts is that it often happens to people who tout the “hacker ethic”.

As a brief side, the Hacker Ethic was a term coined by Steven Levy in his excellent book Hackers: Heroes of the Computer Revolution (If you haven’t read this book and are involved in IT, click the link and order it. Now. Go ahead, we’ll wait. Back? Cool.). One of the key points that I always feel is one of the great equalizers in computers is the fact that people are often accepted by their knowledge, rather then their position or their alphabet soup after their name. (However, they are not mutually exclusive)

HACKERS SHOULD BE JUDGED BY THEIR HACKING, NOT BOGUS CRITERIA
SUCH AS DEGREES, AGE, RACE, OR POSITION.

The ready acceptance of twelve-year-old Peter Deutsch in the TX-0 community (though not by non-hacker graduate students) was a good example. Likewise, people who trotted in with seemingly impressive credentials were not taken seriously until they proved themselves at the console of a computer. This meritocratic trait was not necessarily rooted in the inherent goodness of hacker hearts–it was mainly that hackers cared less about someone’s superficial characteristics than they did about his potential to advance the general state of hacking, to create new programs to
admire, to talk about that new feature in the system.

This is often a very common theme technical circles. Unless, of course, you seem to of the female persuasion at which point it seems to be thrown out the window. I really experienced this in college. The handful of women in our classes were leered at, harassed, and generally made uncomfortable by some of our more “vocal” geeks who probably thought that it was some part of the mating ritual. To be 100% honest, I was dismissive of some of them until I came to the conclusion they could hold their own. Since then, I’ve had the pleasure to meet and work with some talented women, some of who can kick my ass technically.

The computer industry is very male dominated. Conferences have booth babes and the likes of Vanna Vinyl, which I’m sure doesn’t encourage women to get involved in the field. However, shouldn’t people who subscribe to the hacker ethic start equally applying it equally to both sexes?

Also, since we’re on the topic:

Talented Women in Computers who’s weblogs I read, and so should you: