It was getting kind of heated yesterday on twitter in response to a thread started by Perry E. Metzger (whom I have never heard of before, but who talks like he is a big deal. Maybe he is I don't know. The linkedin profile I found for a Perry Metzger, not necessarily the same one seemed impressive but not overly so). I thought I would share and see if you guys agree or disagree.
Perry E. Metzger @perrymetzger
I finally realized one of the things that bugs me about most security "certifications" out there. Computer security is warfare. No, really, it's war. There's an opponent who doesn't care about you, doesn't play by the rules, and wants to screw you as fully as possible. 1/
Now, you can do pretty well as a programmer or sysadmin if you're middle
of the road, because that's not an adversarial game. Security _is_
adversarial. In warfare, you don't survive if you're second rate, you
die. 2/
rest of the thread -
follow on:
A security professional who can't program is like a surgeon who doesn't know much about biology. A security professional who doesn't understand the three most common attacks intimately is like an internist who doesn't know how bacterial infections differ from viral infections.