Friday, February 6, 2015

Can The Internet Be Neutral?

One of the hot-button issues currently being decided at the FCC is the idea of “net neutrality.” Proponents of net neutrality, mainly end users and content distributors (such as Netflix) want legislation or regulations that prohibit internet service providers (ISPs) from performing analysis on the types of traffic traversing their networks, and assigning different priorities to different types of traffic. Opponents of net neutrality, namely ISPs, would like to not only do just that, but also charge subscribers more money to access different types of traffic at usable speeds. For example, without net neutrality, an Internet subscriber could pay $50 per month for reliable access to email, social networking, and search sites. In order to access news sites, or use streaming services like Netflix or Hulu, they might be required to pay more per month to access these higher-bandwidth services.

Should this be permitted? Should a user’s ISP be able to arbitrarily decide which websites and services are accessible at certain price points, and extort users who wish to do more online? Should the Internet, a resource increasingly being referred to as a necessary utility for modern society, have fast lanes and slow lanes determined by big business? Should laissez-faire economics rule the world’s foremost communication medium?

The answer, this writer believes, is unequivocally no. Let me tell you why. The Internet was, in its infancy, a government research project. In a few short decades, it has evolved into a massive information machine. It has become a social and professional necessity. To borrow a term from Blown to Bits, “it’s all just bits” as far as the Internet and its infrastructure is concerned. Routers, switches, copper, and fiber don’t care what each bit might turn out to be. They care about getting the bits where they need to go as fast as possible. Without net neutrality, ISPs can, and will, get in the way. Your email might work just fine, but don’t you even think about trying Netflix without buying the “streaming media” package from your ISP. That is a glimpse of the future without net neutrality. All data is created equal. Allowing that to be untrue gives ISPs a terrifying amount of power, and sets a terrible precedent.

So, why should the FCC protect the open Internet? It just makes sense. Payment for the use of a service should always mean equal, unabridged use. Metering, like paying for a certain amount of wireless data on a mobile phone plan, is similar yet acceptable. Imagine if the electric utility company implemented a “comfort surcharge” during the summer in order to use air conditioning. You’re already paying for the electricity; why should you have to pay more to utilize its full potential? The Internet is the Internet. There shouldn’t be a different Internet for those who can afford premium packages. Data discrimination creates that divide. You paid for it? Use it. All of it.

- The Admiral

Social Engineering Challenge 1: The Secret Picture



My task for this week was to take a picture of a fellow player without getting cut. My target was Admiral Aquamarine since I knew his real identity, and also he was located across the room from me which made him the perfect target.

It seems that it will be a very easy task but its also easy to get cut taking picture of someone, especially if there is only 5 players in the classroom, so I had to be careful, I tried to take a picture in the beginning of the class but I realized that I looked too suspicious and that it will be easier if Admiral was distracted by someone. so I waited until he started a conversation with the professor and I took the pictures.

I think that My strategy worked pretty well since I was able to take 2 pictures without getting cut. I learned that a distracted target is an easier target.

I think it's morally unacceptable to take a picture of a person without asking the permission. I definitely invaded Admirals privacy By taking his picture secretly but it made me realize how easy is to invade the privacy of a person.

The skill that I learned is to analyze the situation and try to find the easiest and safest way to get the job done, which is a skill that can be use in future class challenges but also for many other regular things in life.

Honestly I enjoyed this task even if it was not very challenging at first, the fact that I had to try to take a picture then realizing that I looked too suspicious and changing my plan to a new one which worked, made me feel like I accomplished my mission. I liked the challenge also because it was not a very bad thing to do, at the end it was only a picture.

Thursday, February 5, 2015

Social Engineering Challenge 1: It's In The Bag

Good Afternoon! Admiral Aquamarine checking in with a successful mission report.

My task for this week was to get my mission card into another player's bag. That seems fairly simple by itself, but time was not on my side. Considering the challenge expired at the beginning of next week's class, I knew I had to act quickly.

As soon as I read the card, I used a stretch as an excuse to turn around and scope out the room. I scanned everyone's immediate area, looking for an open bag. Then, in the back of the room, I saw it. I don't know your alias, but you had a fairly large bag on the table next to you. It was brown and purple and wide open. Now, I needed a plan. How would I get it into your bag without your knowledge? My original plan was to leave the room behind you after class, and drop the card in as you walked away.

Well, sometimes better opportunities present themselves. About a half hour later, my target left the room without her bag. I looked out the window to be sure she was out of sight. Then, in plain sight of the class, I walked over to her bag and stuffed the card in between a hat and a notebook. I made it back to my seat before she came back into the room. Success.

I can't gauge how successful my original plan would have been, but the opening of my target's bag was large enough that I expect she wouldn't have noticed until I was long gone. My actual execution was also quite effective, though I did run the risk of someone ratting me out when my target returned. Why did I still go with that plan, given the risk? In my mind, I was still successful, even if someone informed my target after the fact. She wouldn't have brought the card home, but it would have been in her bag already.

To avoid a novel, I'll wrap this up. Morally, my actions were a breach of privacy. While I didn't remove anything from her bag or rifle through it, I did place my hand inside and certainly popped her personal bubble. Had I done this in her presence, I would expect a strong negative reaction. As for how I felt, well, let's just say I have an empathy problem. I know this. A normal person likely would have felt strange, wrong, or even dirty for doing what I did. I saw it as accomplishing the mission at hand.

For a better challenge, I could have let my golden opportunity slip away and attempted my original plan. Instead, I opted for the greater chance of success. Always take the path of least resistance, right? Maybe. If I had gone with the first plan, it would have been a chance to practice my sleight of hand skills. The method I chose only proved I'm willing to be brazen to accomplish a task. I'll have to work on the subtlety, and I'm sure I'll have to for later missions.

- The Admiral

Tuesday, February 3, 2015

Structure for Your Social Engineering Posts

Here is the structure for your social engineering posts:

1.  What was your task?
2.  What did you do?
3.  How effective was your strategy?
4.  What are the moral stakes?
5.  Now that you have done this, what could you do with the information or skills you obtained?
6.  Reflect on how you felt when you were doing this.

Please don't forget to use hacker identities only within blog posts including your own identity from which you are posting.

Problems, claims, reasons, principles

Today in class, we watched this video by Michael Sandel, "The Lost Art of Democratic Debate."  We learned a method for building moral arguments.  In your blog post this week, please practice this method.

Select a specific situation with moral stakes (a case) in the world of computing.  Piracy.  Communications monitoring.  Whatever.  Include a link to a news story or similar description of the case, and introduce us to the facts of the case in a few sentences.

Then:

Identify the PROBLEM.  The PROBLEM is the situation in which the moral dilemma emerges.  Often, the problem can be expressed as a question beginning with "Should," like "Should governments be allowed to monitor their citizens' email, texts, and phone conversations?"

Make a CLAIM.  The CLAIM is your assertion in answer to that question.  This is what you believe. to be right in this matter of right and wrong.  "Governments should be allowed to monitor their citizens' email, texts, and phone conversations."  Or, "Governments should not be allowed to monitor their citizens' email, texts, and phone conversations."

Support your claim with a REASON.  The REASON is what would come after a "because" attached to the claim statement.  "Governments should not be allowed to monitor their citizens' email, texts, and phone conversations because..." There can be REASONS rather than just one reason.  Often, there are several reasons in a really strong argument.

Then, excavate the PRINCIPLE underlying your reason.  Imagine that after you made the "because" statement in the preceding step, someone asked you, "Why is that so?"  PRINCIPLES get at ideas that are bigger than any one moral situation.  They are also "should" statements, but they're rules that apply in varied situations, like "When they have to make a choice, governments should put the security of their people ahead of their people's liberty and privacy."  Or, "You should tell the truth, no matter what."  They can often include language like "always" and "no matter what," because they are meant to be rules that could be applied to a variety of cases.  The test to identify whether you're talking about a PRINCIPLE (and not a reason) is this: could it be applied to a completely different situation, a completely different context?

I recommend making each of these a separate paragraph, for clarity--so, one paragraph for the description of the case, one paragraph for the problem, one paragraph for the claim, and so on.  The paragraphs can be brief.

Please make an original post using the above method no later than Monday at 9:00 PM.  DO NOT MAKE A COMMENT; make a brand-new post.

Monday, February 2, 2015

Social Engineering Game Instructions

Social Engineering Capture the Points
Social engineering is the most effective way to bypass any hardware or software systems in place. Organizations can spend millions on security, only to have it all bypassed with a simple phone call.
In this game you will social engineer each other, and others, to acquire information or to elicit predetermined behavior.  The social engineering missions will be on index cards and one new one will be available to be chosen at random per student at every class.  If you do not complete the mission by the next class that mission expires and can no longer be completed by you.  If you do not complete a mission you neither gain nor lose points.

For each social engineering hack you successfully complete you will be required to share the details of what you did on the blog.  Your classmates will be able to then respond to your post by suggesting the number of points you be awarded for your hack. 
·         2 points for an easy hack
·         5 for a medium difficulty hack
·         10 points for a difficult hack

Your classmates may mock your easy hacks and recommend low point values.  Or they may congratulate you and offer up high point values for your hack.  Ultimately, the professors will decide the point value and post the rewarded value at the end of the blog post. 

For some missions you may decide to take on a sidekick.  If you choose to engage a sidekick, the sidekick must be rewarded for his/her role in your mission.  The sidekick will be awarded 2 points for successfully helping you complete a mission.  However, the sidekick can turn against you, as they can also be awarded 2 points for causing your mission to fail.  As such, your sidekick might actually be working against you, so be careful.  If you and a sidekick successfully complete a mission against another player in the class, the points awarded will be deducted from the targets point total.

If you attempt a hack mission and fail, you must report the mission and failure on the blog.  You will not be penalized for a failure, unless the mission’s target was a fellow player.  If the targeted fellow player blocks your hack, they will be awarded 2 points which will be deducted from your point total.

Social engineering is as much about learning how to target and acquire information, as it is about preventing you from being the target of it.  If you are the object of a hack, the student who hacked you steals the number of points they earn from your point total.  As such you need to be on your guard. 


A running tally of scores will be kept and shared on the blog regularly to encourage you to continue social engineering your way to the top of the leader board.  The game will run until the end of the semester, with final point tallies being calculated the last week of classes.  The point totals will determine approximately 12% of your grade for the course.

Teaching Presentation Information

Here is the information you need to effectively create your teaching presentations for the course.  The groups and the topics were selected during our first class.  

TEACHING PRESENTATIONS
Presentation Technical Requirements:
·         Must be 20 to 30 minutes long
·         Must include multimedia component (for example Youtube video, video you created, hands-on exercise, or game)
·         Multimedia component must be at least 2 minutes long and not longer than 15 minutes
·         Must be on the topic and include the learning objectives of the topic (see below)
·         Must include a case study or current example from the news headlines

Topics:
Topic 1: Introduction to Ethical Hacking
        Describe the role of an ethical hacker
        Describe what you can do legally as an ethical hacker
        Describe what you can’t do as an ethical hacker

Topic 2: TCP/IP Concepts Review
        Describe the TCP/IP protocol stack
        Explain the basic concepts of IP addressing
        Explain the binary, octal, and hexadecimal numbering systems

Topic 3: Network and Computer Attacks
        Describe the different types of malicious software and what damage they can do
        Describe methods of protecting against malware attacks
        Describe the types of network attacks
        Identify physical security attacks and vulnerabilities

Topic 4: Footprinting and Social Engineering
        Use Web tools for footprinting
        Conduct competitive intelligence
        Describe DNS zone transfers
        Identify the types of social engineering

Topic 5: Port Scanning
        Describe port scanning and types of port scans
        Describe port-scanning tools
        Explain what ping sweeps are used for
        Explain how shell scripting is used to automate security tasks

Topic 6: Enumeration
        Describe the enumeration step of security testing
        Enumerate Windows OS targets
        Enumerate NetWare OS targets
        Enumerate *nix OS targets

Topic 7: Programming for Security Professionals
        Explain basic programming concepts
        Write a simple C program
        Explain how Web pages are created with HTML
        Describe and create basic Perl programs
        Explain basic object-oriented programming concepts

Topic 8: Desktop and OS Vulnerabilities
        Describe vulnerabilities of Windows and Linux operating systems
        Identify specific vulnerabilities and explain ways to fix them
        Explain techniques to harden systems against Windows and Linux vulnerabilities

Topic 9: Embedded Operating Systems
        Explain what embedded operating systems are and where they’re used
        Describe Windows and other embedded operating systems
        Identify vulnerabilities of embedded operating systems and best practices for protecting them
Topic 10: Hacking Web Servers
        Describe Web applications
        Explain Web application vulnerabilities
        Describe the tools used to attack Web servers

Topic 11: Hacking Wireless Networks
        Explain wireless technology
        Describe wireless networking standards
        Describe the process of authentication
        Describe wardriving
        Describe wireless hacking and tools used by hackers and security professionals

Topic 12: Cryptography
        Summarize the history and principles of cryptography
        Describe symmetric and asymmetric encryption algorithms
        Explain public key infrastructure (PKI)
        Describe possible attacks on cryptosystems

Topic 13: Network Protection Systems
        Explain how routers are used as network protection systems
        Describe firewall technology and tools for configuring firewalls and routers
        Describe intrusion detection and prevention systems and Web-filtering technology
        Explain the purpose of honeypots 

Due to the weather, we are one week behind at this point.  The first presentation will be made by me tomorrow provided the college is open and running and we are able to hold class.  This will serve as a model for what I am looking for you to do.  

The presentation on topic 2 will be made next week, so please be prepared.  The schedule for the remaining presentations will appear in a separate post later this week.