Skip to main content

Posts

Idea: Blind Debate

It has been a while since I last posted, and I apologise for that. The posts I was working on have turned into some writhing epic mess, exceeding even Wait But Why?  (you should most certainly take a look if you are unfamiliar with the site) standards in length, so I'm currently re-writing them into some semblance of readability. Until then, I've a little game for you to try, to help exercise the little grey cells. I call it the Blind Debate, it only takes an hour, and it goes like this: you and a friend, or two groups if you prefer, have a topic chosen at random for a debate. You both get 15 minutes to do some research and form your side of the debate. Then, 10 minutes a piece for opening statements, 5 minutes each for rebuttal and counterpoint, then 5 minutes each for closing arguments. Naturally, you'll want to take some time afterwards to talk it over a bit more and see where everyone stands, but for the most part it can be done in 60 minutes, which is a great way t...

Logical Fallacies - Why do they matter?

I came across a wonderful poster image by a talented artist, Michele Rosenthal , which depicts a robot debate: Granted, these aren't all the logical fallacies that exist, but it covers the most obvious, and most abused ones. But why are they important? We currently live in an age where we have access to more information that at any other point in history, and yet somehow we still think that arguing from emotion, or with our cognitive dissonance blinders on, is both right and acceptable: it isn't, not by any stretch of the imagination. Postmodernism may have a place, but not here. Yes, you absolutely are allowed to feel they way you want to, but debates are places for facts and ideas that need to be scrutinised rigorously, not with playground threats and character assassinations. "I feel" is not an argument that belongs in a debate - your feelings are valid for you, yes, but you can not simply refute the evidence-based assertion of vaccinations work with the st...

Spam, Scam and Outright Blackmail: Inbox Thieves and How to Spot Them

As we know, there are ~235 billion emails sent per day, a number that keeps growing year-on-year. A staggering 48% of that traffic is spam of one description or another, a figure that has actually come down 21% in the past 4 years alone. Despite varying scams and spam being prevalent and well-known, still people fall for them and shell out hundreds of thousands of pounds to cyber criminals each year. Today, I’m going to take a look at an interesting blackmail spam email I received and break down how to identify this as something obviously a scam, and why it is also a phishing expedition as opposed to real blackmail. I’ve taken out my email details, but the rest is exactly how I got it: A Fun Blackmail Scam attempt The first to check, with every email you get not just the ones you suspect of being dodgy, is the sender name and email address. Now even a neo-luddite can spot that something is fishy here: 986@501.416 is clearly not a real email address. If you aren’t sur...

The Welsh Rant

As a Welshman, I have always been cautious of independence: I have always wanted it for my nation, but years of political mistrust and abuse by England have not left us in a good enough state economically to do much of anything to change this state of affairs. Which brings us to the trigger event for this post, and why I'm particularly miffed. The Swansea Tidal Lagoon project had all the hallmarks of Something Good: a renewable energy technology that would create not just jobs at the site, but create employment opportunities and new businesses along the supply chain, as well as regenerate a coastal area. It would also serve as a template business and regeneration project that could be replicated around the UK, and possibly exported abroad. And all for a little more than the cost of a DUP bribe  £1.3 billion. My opening paragraph has probably given away that not all is well with this. Instead of investing in not just a one-off project, but the full rejuvenation of industry and c...

Multidisciplinarianism

Nice, long, big word there as a title. I'll shorten it for you: polymath. A person of wide knowledge or expertise. The desired human state. I have long been an advocate for something I call wide-spectrum literacy: competence in reading, writing, arithmetic, science, technology, politics, philosophy, economics, to say the least. I have what you could mildly call a vehement dislike of ignorance, particularly wilful ignorance: I find little to no excuse for it, especially in developed nations where access to technological marvels which act as gateways to endless learning and knowledge, most of it free, is commonplace to the point of being carried around in pockets. You can imagine, then, my sickening disgust at the state of the world, and the horror of facing an international society in which ignorance, bigotry, and mendacity don't just roam freely, but are actively pursued as if they were the highest virtues.  Now, I'm not going to lay the blame entirely at the feet of...

The Ancient and Venerable Art of Google-fu

Other titles considered for this post: How Not To Piss Off Entire Forums and Facebook Groups; Avoiding the Banhammer; Stop Being Lazy and Look it Up Yourselves. Before you can embark on a career in, well, anything even vaguely IT related (or do practically anything), you must master one crucial skill: information searching. In the days of yore, and even rumoured to still exist despite budget cuts, there were in of cult of specialists in this area, who guarded their domains jealously: the librarians. These knowledge-fanatics could divine what you were looking for from the ridiculously poor and mumbled explanation you gave them, then translated that into a secretive code which led you to a shelf in a library, and then to the book you were after. Just like magic. These days, while librarians are still a vitally important part of cataloguing knowledge, we also have another, less mystical, tool at our fingertips: the Search Engine. Unfortunately, very few people have bothered to le...

It's all about the angles

I could describe the surroundings for you perfectly, down to the way the grain went on each of the wood panels on the floor, I could talk to you at great length concerning the cobwebs knocking at my door or the baying crane flies attacking the windows, baying for the bleeding luminescence seeping from the screen. I could go so far as to describe each and every instrument playing on the track I was listening to, the perfectly clear Irish lung-pipes of Cara Dillon’s songbird vocals. But I won’t, because none of that matters, at least not in this context, or perspective. It all comes down to angles you see. Not the angles of everything around us, but our angles. The tilt of the head to listen more intently, the hunch, or straightening of the back to become comfortable. The adjustment of glasses to see an image properly, or in this instance, to see the image no-one else may have seen. It doesn’t take much to shift your physical perception of anything, but it opens up a myriad new worlds, ...

The Alphabet Soup: A Quick Guide to Post-Nominals

This week, I’ll walk you through the ever-growing list of post-nominal letters you can add to your name through qualifications and certifications. Being a student myself, I’ll start with exploring the academic route, then go through the more popular, and best recognised, vendor and standards organisations’ certifications, highlighting their worth for your CV and career development. It’s not a comprehensive list, by any stretch of the imagination, and is geared towards a more general CyberSec professional, rather than focusing on any one aspect of the industry. I’ll try and shy away from too much debate by running away very quickly to avoid the one about CEH vs. OSCP, and leave it to you instead. *Disclaimer* I am a university student, and haven’t actually done any of the following certifications, at least not to completion. I have explored each in a reasonable amount of depth to see their benefits and worth and consulted with holders of a few to gain their insider opinions. I a...

Jumping the Pond: Making the sideways move into CyberSec pt. 2

Following on from my last article, here’s some more information on changing industries for managers. Hopefully I didn’t put too many of you off switching careers in my previous article, where I explored what managerial life would look like in the InfoSec world. As a continuation, this post looks at which certifications are best to get you the necessary managerial competence in the field to start your new career. Some of these do include a certain amount of technical training in the course material, others just look at concepts instead. Should you choose one of those, I would recommend at least doing some research into the technical side of things. While exploring free, online learning resources might not cut it completely, they are better then nothing and will help give you a grounding for when you choose to complete a recognised technical qualification. Certifications This will be by no means a comprehensive list of certs, but it will be enough to get you started and point...

Jumping the Pond: Making the sideways move into CyberSec

So far, a large portion of this blog has been dedicated to helping people begin their careers within the Cyber Security sector from the beginning, i.e. straight from college or university. This week, I’d like to explore the options for those looking to make the move from other career paths, specifically with an eye to those looking at managerial positions. If you are already coming from an IT background, this post might have one or two things you might find useful, but you’ll probably have access to other resources that might be better suited to your needs. I want to note here that while this will guide you through some of the options and a few certifications that will help move into CyberSec, some technical competency is a must. A good level of understanding of the technologies and principles underlying those technologies is unavoidable in this field, as you’ll see below. My suggestion would be to look at my earlier blogs and some looking around, as I won’t go into depth about t...