• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Hacker schools/boot camps

Joined
Dec 15, 2012
Messages
3
What do you guys thinking of "hacker schools" like:
Dev Bootcamp
App Academy

I'm thinking about applying to one of these programs. It would also be helpful to hear feedback about these schools from alumnis/former students.
 
lol I think they are full of it.. I think you'd be better off reading a few books or enrolling in a real computer science program.

Our first batch graduated Sep 2012. 93% of our graduates have offers or are working in tech jobs now at an average salary of $83,000.

After 9 weeks training to write software? If it sounds too good to be true....

Look at their curriculum. Does it even seem remotely possible to learn all that stuff in each week?
 
Yea that doesn't look legit at all or covers things so basically along with passing everyone just so you end up having to pay some how.
 
Are you looking to learn penetration testing or software development? Either way neither of those schools look remotely useful. There are a few hands-on courses in pentesting around but the best way to learn is to read books and tinker yourself.
 
Basically those classes are going to give you a somewhat broad but extremely limited understanding of a bunch of different topics. You could do better by watching free video-series online or joining a website that charged $30-$50 a month for quality video lecture series, or just go to the bookstore.

One of those sites said $12,000 with scholarships for the 9 week tuition?! That's sorta insane.. I mean.. some universities are pretty expensive but some are good schools and still not that expensive if you are in state. $12,000 could be a good start on college.

But college may be overkill for your goals. What are you wanting to do? Are you just wanting to become a entry level web developer? What type of software do you think you'd be interested in?
 
If you're passionate about coding just grab a book and write something. Best way to get started and learn.
 
More than $12000 for nine weeks? That seems quite high. Why do these programs appeal to you, bottleofboos?
 
Nine weeks experience, in “school” at that, likely wouldn’t get you a shot at an internship, let alone an interview for an entry-level position, at least not in WA … unless you had other experience/background you could demonstrate.

And $80K/year for an entry level Ruby on Rails developer? Maybe on the back of a proper degree or demonstrable, relevant, experience elsewhere, but not just off a quick-start course.

Their claims about having 93% of their first-batch graduates making $83K/year are pretty meaningless without a good deal more context. How many of their graduates had no prior experience? How many did they employ themselves to run more courses? How many just took the class for a Ruby on Rails quick-start and were already developers in other languages and frameworks?

There are more unpleasant possibilities too … but I’ll leave that with the same sentiment as others … things that sound too good to be true usually are.

A couple of market realities here:

  • Any work I could entrust to someone with just nine weeks of schooling I could just as easily contract out and/or out-source without any fuss at all.
  • While the tech market, especially around here, is definitely picking up (it's rather hot if you're really any good) … $80K/year for no-experience is a non-starter, especially for common/garden web-developer work.

Before you think about spending $12K on something like this, download something like Python, which requires no configuration or setup beyond running its installer, grab a book or a free online course, and see how it goes. It’s a $25 gamble and honestly, if you can’t make progress in it in a month or so (at an hour or two a day), then it’s hard to imagine you making it through such a course and coming away with anything but a smaller bank balance anyway.
 
Probably. There will definitely be yoga, stretching, and even basic meditation and mindfulness training. Sitting in front of a computer all day can be tough on the body and mind, and we will be teaching you good habits and ways to take care of yourself.
Just found this, so maybe it's actually worth it.
 
If you are looking for a bootcamp style, look for a local Code Camp. They are free, typically 2 days of tech sessions. The ones I've seen seem to be .NET leaning, but from word of mouth at other events I attend, they are great for getting up to speed quickly. And you can't beat free.
 
backtrack has some courses, and so does wireshark (though those are more pen testing)
 
Maybe I'm just retarded but I couldn't imagine retaining what you've learned at a really solid level.

If they are talking about 400 hours of training in 9 weeks, that's about 45 hours a week. Chances are you're going to stuck and go over your 45 hour quota. It'll probably be closer to 50 hours a week easily.

If you "work" on weekends (didn't read their FAQ in depth) then you're talking about 7 hours of intense training a day. There's a reason why uni lectures are usually short and spread over a few days with breaks in between.

Have you ever tried to read an 800 page technical book over 2 days and then try to apply what you've learned a few days or weeks later? I have a feeling it'll be like that where you ended up absorbing maybe 10% of the material.
 
you really should go for something tangible like a degree or certification
 
Hmm I heard about pentesting, but I never knew how to start off on that. How would I go about approaching that?
 
I'd start off playing around with backtrack and their forum. Also check out metasploit (be careful here, a lot of firewalls have this site blocked. It is a legal site, but schools and jerbs may block it). Get your feet wet, find out if you like it and want to persue it.

Most colleges have network security classes, so while you may not be able to get a pen testing degree you can take courses.

Also, backtrack offers training. Again, I'd go for something real like a degree or a cert. That sticks out on a resume more than 'relevant coursework'
 
The [H] community is so contradictory.

We have threads in other places where the gist of them is "Don't get a degree. It's so overpriced and we're all brainwashed to think it's worthwhile (Source: genmay thread). You'll be better off going another route." Then you run across a thread like this and all anyone has to suggest is to just get a Degree.




As far as what I would do...Get a better idea of what you want to do. For example, I knew I wanted to do something with computers but didn't know what (software dev, web dev, networking, databases, etc). I ended up going to school for Computer Science and then switched to Networking and quickly switched back to CS. Now I have a Bachelors in CS but wasted money taking some Networking classes. On the other hand I could take about 6 more classes and have a second Bachelors but that wouldn't mean too much unless I wanted to get in to entry level Networking.

Once you narrowed down what you want to do start exploring your options within that field. I would probably start off by building a small portfolio. Since you're new it won't be anything amazing but completing a few small projects will let you know if it's something you want to pursue. Depending on how advanced you get it can also show a potential employer that you are dedicated and have the technological background to be hired.

Just keep in mind, some people need the structure that a school provides while others prefer to organize it all themselves. Just gotta feel out what works for you.
 

I couldn't agree with this more as I had a similar experience.

I started off knowing I wanted to do something with computers so I found a school that specializes in engineering and science. I started off as a Computer Science major but switched my major to Computer Engineering right before I started. A semester in, I realized I didn't want to be an engineer so I switched to a new program my school just started up which focused on computer security. I was in the Cyber Security program until I realized that most of the classes focused on the theoretical mathematics behind cryptography which, while interesting, wasn't what I wanted to get into. So my Junior year I switched back to Computer Science.

Throughout my time at that school I focused all my electives on networking and security-related courses (forensics, network administration, TCP/IP Networking), graduated with a B.S. in Comp Sci in 4 years and I got a job a month after I graduated (Because of contacts I met during school) doing security work (policy work, security assessments, penetration testing, incident response) for a hospital. I then went back for my M.S. because I became interested in enterprise level security.

Long story short, some people need that time at school to figure out what they want to do within their field. For me, it was worth the time and money to get where I am today.

EDIT: Just to be clear, I'm only really talking about a full-on Bachelors or Masters degree program, those 1-3 week crash courses are for people who know what they want to do and want some additional training.
 
The sad part is that most jobs in the 'security industry', you don't need a degree for. Especially a specilalized degree in 'cyber security'.

The auditors we work with all seem to have a certification or two. When they audit one of our products, they simply run a standard suite of tools and go through a list and check off boxes. Sure, they will find that your site doesn't do this or doesn't do that but they aren't able to exploit it. They are clueless monkeys.

The best part is when we have the same auditor and same test suite year after year, and they bring up issues as huge red flags that they never mentioned in the reports for previous years. They basically have to find SOMETHING to flag you for or else it will look like they aren't doing their job (or you have a perfect product).

They love to ask questions that don't even relate to your business (we've failed audits because we don't follow some security protocols, because they don't apply to us or our industry).

1. Is your hosting site SAS 70 II certified?
2. Do you have a high level doc outlining you security posture?
3. Have you had an external security review or pen test of you websites -
if yes, can we see the report?
4. Is the information you collect encrypted in transit and within the
database?
5. Do you co-mingle client data in the databases?
6. Describe how your systems are remotely administered.
7. Do you have a statement of HIPAA compliance?
8. Describe your system redundancy...

These are the same clowns who insist we encrypt a report with AES-256 but then send the login details to the server they want us to upload the files to over a plain-text email. Durr.

The 'real' security researchers are the guys working for the antivirus companies, networking companies, and spam filter companies who are evaluating viruses and security flaws in the wild. And these guys all have degrees (probably graduate degrees) or they are at the very top of their fields, and collectively know everything when it comes to reverse engineering, exploits, the inner workings of network protocols, operating systems, PC hardware, etc.
 
The [H] community is so contradictory.

We have threads in other places where the gist of them is "Don't get a degree. It's so overpriced and we're all brainwashed to think it's worthwhile (Source: genmay thread). You'll be better off going another route." Then you run across a thread like this and all anyone has to suggest is to just get a Degree.
That's to be expected, isn't it? This is a forum where many diverse people come to express their opinions. It can't be a surprise that the opinions aren't unanimous across a large group, particularly when considering a controversial topic.
 
The auditors we work with all seem to have a certification or two. When they audit one of our products, they simply run a standard suite of tools and go through a list and check off boxes. Sure, they will find that your site doesn't do this or doesn't do that but they aren't able to exploit it. They are clueless monkeys.

The best part is when we have the same auditor and same test suite year after year, and they bring up issues as huge red flags that they never mentioned in the reports for previous years. They basically have to find SOMETHING to flag you for or else it will look like they aren't doing their job (or you have a perfect product).

What you're seeing is a common problem in the security industry. Executives in most cases don't seem to understand the difference between being "compliant" and being "secure." Most executives only care about being compliant to the various regulations out there because it negatively affects their bottom line. Auditors are brought in solely to check to see if an organization is in compliance with regulations and, as you pointed out, they are only useful if they actually find something. This means that they'll go to great lengths to nitpick something that doesn't matter in the grand scheme of things, or more maliciously, remove some findings that they can then later come back and tack them onto the next report. True security pros should always think of making something as secure as possible even if it goes beyond the regulatory requirements.

My department for example is responsible for performing technical security assessments of applications both periodically and before they are spun up. While part of our process involves a controls assessment (questionnaire) to get a general idea as to the application's security posture, the rest involves a hands-on penetration test/forensics work. You wouldn't be able to get a job in my dept. w/o some kind of college education.
 
That's to be expected, isn't it? This is a forum where many diverse people come to express their opinions. It can't be a surprise that the opinions aren't unanimous across a large group, particularly when considering a controversial topic.

I'm not saying I'm surprised not all answers are the same. I'm saying that in one thread you will see everyone picking "Answer A" and in another thread everyone will pick "Answer B".
 
I honestly couldn't say that I would risk the $12,000 on that course. It just seems too pricy for what seems to me like too short of a program with too little prerequisite knowledge required to be the end-all solution to getting a programming-related job.

For starters, at about $100/credit hour (for a typical community colleges in my country) and 56 credits for an associates degree, I think it's a fair estimate that getting a related A.S. or A.A.S. degree costs about half as much as that Dev Boot Camp program does. So if we take a simple cost-value analysis approach to looking at this, this program needs to be at least twice as effective as getting as associates degree to even be as worthwhile as an associates degree.

More importantly though, I have strong concerns about the cirriculum for these courses. I personally believe that developing strong programming skills requires 1.) A strong foundation in mathematics, logic and problem solving, and 2.) A reasonable familiarity with how a computer as a machine actually works. It doesn't look like their program (the dev boot camp one, specifically) makes any attempt at laying either of these foundations, and I don't feel a skillset built without said foundation would be a robust, adaptable one. I get the feeling that this program is going to leave students with a procedural knowledge of 'how to do <x> in Ruby on Rails', but not a deep, conceptual understanding of 'why it is a bad idea to take <a> approach to doing <x> instead of <b> approach' or 'how to come up with a solution of how to do <y>, because <x> isn't what people want to do now'.

Like someone else mentioned, $12,000 would also be a pretty substantial start on an education at a 4-year university, too, and if you're successful at that point you would have a reasonable chance at acquiring an internship; with an internship you would most likely get the same level of 'hands on experience', but you would likely be making $12,000 in 9 weeks instead of spending $12,000 in 9 weeks. (Okay, that works out to about $33/hour, which is more than most undergraduate software internships pay, but you get the idea)

I also haven't in this post highlighted the fringe benefits of attending a community college and/or a 4-year university, since I have a lot to say about those, but I will mention that I feel these benefits are quite significant.

And if you're a strong independent learner, $12,000 should afford you a considerable number of books, learning materials and other reasources. Plus, I feel like there's a number of comparable 'ideas' out there in the form of free online courses, and free is a lot cheaper than $12,000.

I think it's a novel idea. It does avoid the catch-22 of 'getting experience is hard when you don't have experience', but I also think there's a considerable number of other, cheaper ways to get around that catch-22, and I feel there's a considerable number of better ways to spend $12,000.

We have threads in other places where the gist of them is "Don't get a degree. It's so overpriced and we're all brainwashed to think it's worthwhile (Source: genmay thread). You'll be better off going another route." Then you run across a thread like this and all anyone has to suggest is to just get a Degree.

Have you considered that those individuals saying not to get a degree might not be the same individuals who are currently posting in this thread?
 
I have strong concerns about the cirriculum for these courses. I personally believe that developing strong programming skills requires 1.) A strong foundation in mathematics, logic and problem solving, and 2.) A reasonable familiarity with how a computer as a machine actually works. It doesn't look like their program (the dev boot camp one, specifically) makes any attempt at laying either of these foundations, and I don't feel a skillset built without said foundation would be a robust, adaptable one. I get the feeling that this program is going to leave students with a procedural knowledge of 'how to do <x> in Ruby on Rails', but not a deep, conceptual understanding of 'why it is a bad idea to take <a> approach to doing <x> instead of <b> approach' or 'how to come up with a solution of how to do <y>, because <x> isn't what people want to do now'.
Let me introduce you to the average 'web programmer'. Cut and paste code from here and there, not knowing why or how, and hack something together using whatever framework is cool this week ;)
And if you're a strong independent learner, $12,000 should afford you a considerable number of books, learning materials and other reasources. Plus, I feel like there's a number of comparable 'ideas' out there in the form of free online courses, and free is a lot cheaper than $12,000.
True - but some people need a class to motivate them and I think part of the appeal of the boot camps is that they hook you up with job contacts and other in the industry which is just as important and technical knowledge when you're trying to find a job.
 
Back
Top