Recently I saw a former co-worker with a CISSP and wanted to verify the cert. The ISC2 website is completely worthless, they want the last name and "Certification / Designation Number", I tried every possible combination of First Name, Last name, CISSP, CISSP / Number always comes back with not found, I even tried a manager and a member of this website. It really shouldn't be that difficult to verify certs. With the SANS website, you just have to enter last name, and all SANS certifications are listed.

Anyway got me thinking, the verification process for certifications is pretty weak. After all there is more than one John Smith in the world, if you share a name, Pesto, instant resume booster. But there no need to hope someone shares your last name that's a security professional, just change your name to someone with a lot of certifications, get a new driver's license, and just apply for new job. 150k sounds about right. You could even post your photo of yourself on a forum and list your certs, nice little bread crumb trail, see it's me, online proof. While it's true you couldn't do the job, but fake it to you make it. Push your work onto Jr. associate. I could do this task Mr. Jr associate, but why don't you take a shot at it, be good experience for you. Turn in work as "John Smith and team", could take 6 months before someone would figure out you really don't have a clue what your doing. After all be better making 150k for 6 months then $7.25 at Walmart for 6 months.

Finally did get a match on ISC2 for a Manger in my Company. Haven't been able to verify the former Co-Worker in question.
