Posts

Week 5: Confidentiality and Privacy: do we need new privacy laws?

I am taking mostly historical information here on the various laws enacted between the 1970's and 2000's which have governed the use of Private Identifiable Information by the federal government and private companies in the US. Most of these laws: like HIPAA and the GLBA are incredibly relevant today to safeguarding our most personal data from people who would do use harm. For a long time this meant keep our data out of the hands of hackers and thieves and while that is still relevant today, there is seemingly a large gap between the US's privacy laws concerning private companies, and those of Europe.  The stark difference is in the EU's General Data Protection Regulation (GDPR) and California's Consumer Privacy Act (CCPA) which were adopted in 2018 and 2020 respectively. The GDPR has a government oversight board by which all private companies must abide by. This creates an active participation in holding private companies responsible for consumer data. It is the jo...

Week 4: Good Sources for Threat Modeling/Risk Analysis

 This pdf from the Cybersecurity and Infrastructure Security Agency has a lot of easy to read, step by step information on conducting risk analysis. For each of the six steps the pdf offers external sources and education. While our main book is very knowledgeable I find these guides to be a bit easier on the eyes when it come to taking in a large amount of information. References: https://www.cisa.gov/sites/default/files/2024-09/24_0828_safecom_guide_getting_started_cybersecurity_assessment_2022_final_508C.pdf

Week 3: The Great IOT Fish Tank Hack (lol)

 From The Hacker News:     It was reported that an un-named casino was the victim of a cyber attack by means of their fish tank's thermometer. The attackers reportedly were able to gain a foothold into the network by compromising a vulnerability in the thermometer. From there the attackers maneuvered and used privilege escalation tactics to gain access to the database of high-roller accounts.      This is not a new phenomenon in the world of cyber security. In the article, Nicole Eagan--CEO of cyber sec company Darktrace spoke about manufactures forgoing common security and encryption methods in their products for accessibility and product use. As we have been discussing in class everytime you connect a new device to your network you increase the attack surface area of the network. More devices equals more opportunities for attackers. Each of these devices must be treated as its own computer. That means strong passwords and software updates. There can be no...

Week 2: Geeks4Geeks

     This is going to be a shorter post because there is not too much to discuss here. I really appreciate the Geeks for Geeks cite. In a time when looking for information on the internet can be cumbersome with advertisements and clickbait articles, G4G posts in-depth articles on most all technological systems. From everything like: CPU, IPS, OSI model, FTP, etc. When I search for information about a system I am currently studying I often add G4G into the search bar. Their articles are able to be referenced and used in paper because they are accurate and well trusted.  For example their introduction to SQL is full of reference links and easy to read wording. They follow up an introduction and technical jargon with a real life example and then a screenshot of what this looks like. That's all I have to say. Make sure you try them out for your next study project! https://www.geeksforgeeks.org/

Week 1: HTB

      Hack the Box is a wonderful cite for anyone trying to gain both knowledge and hands-on experience in Cyber Security and red/blue team activities. The only downside is the amount of time you have to spend to "get good". HtB is an internationally recognized cite and proving yourself in its various "boxes" will also look very good on a resume.      There are two main ways I would suggest using HtB. One, start in their academy and complete modules and skills on different tools like "nmap", "nc", "sql injections", etc. Once you feel pretty comfertable on your abilities to manage a red team job try out hacking the box. There are hundreds of different puzzles called "boxes" where you will need to use your new skills to exploit the machine. It is incredibly educational and I cannot recommend enough. Charlie