Ah, yes... the "paper tiger". While I do have certs myself, it's only because my employer has required them. Left to my own devices, I would never bother. I've been in IT for almost 20 years and I agree that the "no cert/no degree" guys usually work out.
The team lead whose feet I studied at in my first few years in IT had a high school diploma and he could run rings around the guys from Carnegie Mellon and RIT that worked with us. He was a deep diver mentally. I watched this guy drop awk, sed, bash strings a mile long, write Perl scripts without consulting a single web page. He knew iOS (Cisco), Perl, TCL/Tk, Sun, BSD, and about everything else. He could configure a HA UNIX servers and Oracle DB backends without consulting a manual. It was most impressive. He was let go because he was a team lead (middle manager). The people that replaced him--yes, people-- knew nothing in comparison.
The problem is one of trust, methinks. Most certs require only that you "know" the material well enough to pass a test that uses your memory. If the tests were empirical, say like the Red Hat tests or the Cisco CCIE, then the trust that someone actually has skills might be more believable.
Having worked in IT security for many years, I can attest to the fact that IT security is more of a subjective set of processes rather than a specifc product or set of products.
There are skills involved as far as tools and knowledge of how to use tools, but these change depending on the use case.
I had to get the CEH when I was hired on by a security consulting firm back in Northern Virginia.
I now do not include this cert on my CV for (perhaps irrational) fear that someone in some HR department may think "Oh, no! This guys is a hacker!" Sadly, the word has a negative connotation, because the word "cracker" or "bad actor" never bubbled up past the IT security world.
I also do not include my military service dates, as they reliably peg my age. Most men join at 17 or 18, so they would immediately know my age.
I'm debating whether to include any certifications at all, just include my degree.
You can always use CryptDNS, which prevents this. CryptDNS plus OpenDNS and you're pretty good. Add a VPN and you're doing better than 99% of people online. Add uBlock Origin, Decentraleyes, Privacy Badger, and block http/s referrer, disable mediaconnect (prevents RPC from seeing your RFC 1918s--private address scheme) and you're largely unidentifiable in the true sense.
You can do this for $5 a month by renting a droplet virtual server on Digital Ocean and setting up Streisand. Don't log anything. You will control the VPS/VPN. Use it for your mobile phone and household router (if your router supports this). If not, individual machines, but having a router that does this is key.
Use Opera and it's free VPN until you can get something sorted for yourself.
I rang up Verizon Wireless this morning and asked to speak with a supervisor. I use a Google Pixel. I told the woman that came on the line my fear of AppFlash not only ruining the security of my mobile phone, but molesting the beauty that is pure Google Android.
At first the lady was perturbed that I called, but after calmly explaining to her what was at stake, she actually seemed to agree with me it was a problem. I pray she gets to keep her job, considering she agreed with me on a recorded line.
The takeaway from her is that Verizon does not plan on soiling Google Pixel devices due to their deal with Google to keep the ecosystem clean and allow Google alone to push software updates to the Pixel line. I'm praying this is the real story and I won't come to learn my phone has been infected with spyware.