Key Themes from the Lecture
1. Security Theater: Challenging Assumptions
- The shredding challenge demonstrated that cross-cut shredding can be reassembled with the right approach (divide and conquer strategy)
- Real-world example: "Top Men" from Indiana Jones - when authorities say "don't worry, top men are looking at it" - be skeptical
- Bike lock story: A combination lock was picked by feeling internal clicks while applying tension - expensive doesn't mean secure
- Takeaway: Always test security claims rather than accepting them at face value, a key aspect of Comprehensive Guide to Ethical Hacking: From Basics to Advanced Concepts
2. The Engineering Paradox: Why Bridges Stay Up But Computers Get Hacked
- Bridges are reliable due to:
- Standards and professional certification
- Factors of safety (overbuilding by 10-50%)
- Peer review and testing
- Public sharing of knowledge (unlike early steam engine secrecy)
- Computers are vulnerable because:
- Patch Tuesday never stops - vulnerabilities are constantly discovered
- Complexity makes perfect security impossible
- Human error - developers who cut corners do so everywhere
- Critical difference: Anyone can attack a computer system anonymously from their bedroom, highlighting why understanding Common Cybersecurity Threat Vectors and How to Protect Your Systems is crucial
3. Framework: DAEM Acronym (Week 1-2)
- D - Defender mindset → Attacker mindset
- A - Assume nothing, test everything
- E - Engineering approach to security
- H - Human factors
4. Engineering Practices to Steal for Cybersecurity
| Engineering Practice | Cybersecurity Application | |---------------------|--------------------------| | Measurement & estimation | Quantify risk and security posture | | Standards compliance | Follow established security frameworks | | Failure mode analysis | Anticipate attack vectors | | Destructive testing | Penetration testing | | Peer review | Code review for vulnerabilities | | Risk identification & mitigation | Threat modeling | | Prototyping | Red team/blue team exercises | | Closing the loop | Post-incident reviews |
5. Case Study: The Halifax Explosion (1917)
- What happened: French ship Mont Blanc (carrying explosives) collided with Norwegian ship Imo in Halifax Harbor
- Result: Largest man-made explosion before atomic bombs (~2.9 kilotons)
- 1,600+ dead, thousands injured
- Key failure: Language barrier, no evacuation plan, no communication of dangerous cargo
Analysis Exercise: Students were asked to provide ranked recommendations as consultants to the Mayor of Halifax.
- Key lesson: Don't focus on blame (impatient Norwegian captain) - focus on system failures
- Good recommendations focus on what the Mayor can actually control:
- Harbor traffic rules for dangerous cargo ships
- Evacuation planning and drills
- Communication requirements (language, warnings)
- Zoning restrictions for explosive storage near populated areas
The Halifax case illustrates many principles of Network Security Zones and Attack Surface Reduction, where proper separation and controls prevent cascading failures.
6. Attack Anatomy Framework
Reconnaissance (Recon)
- Passive: Looking at websites, social media, public records
- Active: Dumpster diving, walking through offices, sending network probes
Vulnerability Economics
- 0-day vulnerabilities are sold on markets:
- iOS: Most expensive (FBI paid ~$1M in 2015)
- Android: Moderate cost
- Windows: Variable pricing
- Adobe: Practically worthless ($150+ lollipop)
- Bug bounty programs now compete with black markets
The Reality: Most attacks succeed through non-technical means (human error, social engineering) rather than sophisticated zero-days. This is a core lesson in Complete Cybersecurity Full Course: Threats, Tools & Career Guide
7. The Future: Will We Ever Be Secure?
- No - Complexity is the enemy of security
- Humans always push boundaries (e.g., AR glasses limited by 10W cooling, not batteries)
- Simple systems can be made secure, but nobody wants simple systems
- The economy of zero-days ensures continued exploitation, even at the level of Defending Against Nation-State Cyber Threats: Insights from Tailored Access Operations
- Conclusion: Security is a constant race, not a destination
Student Project Opportunities
Something Awesome Project (30 hours, due Week 8, showcase Week 9)
Available projects:
- Royal Hospital for Women - Analyze milk labeling system to prevent babies getting wrong mother's milk
- Sydney Children's Hospital - Cybersecurity posture assessment for a non-profit
- Fintech Startup (Pea) - Security review of a company managing $1B in customer assets
Security Everywhere Challenge: Weekly photo submissions of real-world security examples (good or bad)
Final Takeaway
"When someone claims something is secure, just think 'Top Men' and laugh hysterically - then give it a go. You'll be astonished, especially with physical security, how easy they are to circumvent." - Richard Buckland
ideas but we didn't Overlook the traditional approaches cuz sometimes you get so excited by inventive things you
forget about the traditional thing and really you just got to do the best thing not the cleverest thing so I felt very
positive about yesterday so it's lovely to see you all because there were just so many people who did The Shred
challenge um can everyone that is doing it what first of all put up your hands if you're doing it you're under way whoa
put up your hands if you finished it benil close yes yes oh no you told me I've
forgotten your name how how can I have forgotten so quickly I even I thought I don't even need to write that down I
remember Lin Marcus Marcus Marcus Marcus come down and show every so Marcus was the first
[Music] one actually can we just have can everyone that's working on it stand up
just stand up if you're working on it or have solved it can we have an enormous Round of Applause for all of these
people uh I I was so amazed that so many people were trying it someone actually got it out in the lecture theater while
I was shredding it for other people how did that happen um so Marcus you've got your um thing here
what was your your message um was wasn't very personalized cuz I thought it was just going to be you doing it but it
does reveal a secret about me and what was it Richard loves cheese Richard loves Chee it's true let's have a look
at what you did so let me turn on the doc camera no Messi's
good look on the yeah on the pH he's fine go
hopefully the do camera oh oh it's got a light we probably don't want
that we go camera is it display yeah uh
yes it's a huge phone there we go well you want to arrange it so people can see so oh I'll give you my mic tell oh I'll
just stand near you so I can here I don't uh set up what's this doing maybe if I hit menu again that'll
go away yeah there we go all right so can you tell everyone how what was your approach um so I
remember the card that gave me and um I know one side probably had text for they had text yep so I was oh turn off
keep going I decided to focus on thees of text so together at Le like a paragraph
or something yes and then I'll be able to f it and then I be able to see what the message was I'm not going to get
this working okay so you found words you assembled Words which we saw briefly on the camera there a series of parallel
words you then assembled the words to make sentences yeah yeah um that's like uh chunking it's a very clever strategy
when you got a really big problem is breaking it into smaller chunks divide and conquer is um You probably seen the
strategy used in in Search and in sort is um often amendable to this strategy so yeah that was really good so you
found the words you put the words together how long did it take you in total 4 hours 4
hours finish at eight 20 one all right can we just give him an enormous Round of Applause
than thank but also thank you to everyone who did it I'm so impressed you Rose to the challenge now what's that
telling us the idea is I was just talking about it with another lecturer today and I said so we shredded the card
and then the students had to join it together and we used a crosscut shredder so it didn't just shred them into
vertical strips it also chopped it sideways and competitor and um though that to be fair
slightly larger than the p a piece of uh you know whole punch confetti but not much
um and and the lecturer started laughing and said oh you got them good and I said no they're able to do it and he said you
can't reassemble shredded stuff it's shredded okay so what we're looking at
here we're shredding is an example of something called security theater you often face something that looks
really good and you need some sort of courage and to have this mindset to think maybe it's not as good as it looks
maybe the level of security is a bit deceptive there are lots of famous stories about people reassembling
shredded documents at the end of various Wars there's that wonderful scene in Argo has anyone seen the film
Argo we should Replay that um the the was um the people in there were held hostage or or captured essentially in an
uprising in I think it was Iran was it Iran yeah and there's of the people storing the embassy and the people
inside flipping from thinking we're completely safe I can't wait till the police arrive and deal with this
thinking no we're not completely safe actually things are going to go bad very very quickly they had minutes or seconds
that when they flipped from thinking everything was right suddenly realized and we'll see that over and over again
that humans are like that oh yeah sorry we just lost audio you lost audio
Yeah right uh do we have audio oh are you want sorry I'm going to follow you back up
there um so we'll see that we'll look later on
that's called incident response we'll look later on at how we respond to incidents and how people don't really
recognize an incident happened until it's a bit too late normally um but in any case uh the people that were hiding
were basically safe until the Iranians had reassembled enough of the shredded documents or frantically trying to shred
documents to work out that there were some extra people they hadn't caught um so it was it's a very exciting film and
true um and so shredding is an example of security theater but there's lots of examples of
security theater and I guess the first one I ever personally discovered and you all probably have an example of your own
the first one I personally discovered was I was in the city meeting someone for an important meeting and I was a
very Junior person and it was someone who'd come out from another country and they were interviewing people and asking
questions and I was so honored to be invited that I cycled all the way into the City and I chained my bike up in
York Street and I ran to whatever Cafe we were in and I did the interview and I felt so happy and during the interview
it got dark and then it started running raining and I thought o this isn't good I'm going to get wet riding home and
then I walk outside in the dark wet and I suddenly realize I don't know the the the combination code for my bike lock um
because it's I got a new lock I put a new one on that day I thought oh yeah I should put the new one on because I'm
going into the City and people are criminals and I'll have to so I'm sitting there in the rain I'm standing
there in the rain getting wet with people bustling all around me it's dark and I can't unlock my bik and I was so
depressed and I stood there and I think at that point I faced a choice and I'm so excited at the choice that I ended up
taking it sort of been a motto for me for the rest of my life I could have just gone home I thought I'll stuff this
I'll go home I'll come back tomorrow with some bolt cutters and I'll free the bike or something maybe I'll find the
instructions with the code on it or something and the other one is maybe I won't give
up maybe I can unlock this bike without knowing the combination I thought well I'll give it a go so the first think is
like that lecturer was saying to me yeah it's impossible give up and the second one is like all you people have thought
well maybe I can do this so I sat down and I had no idea how to pick a lock or anything it was a combination lock so I
put it under tension because you don't know it's unlocked unless you're pulling hard on it because then it pops out put
it under tension and I just rotated the wheels randomly in the dark and I could feel this little sort of Click when one
of the wheels got in a certain position I thought oh that's good I'll put that one in that position and then I left
that one there and I started rotating another fiddling with another wheel and nothing happened so then I went to
another wheel and I felt a little click on that one and I thought oh this is good and those of you who know
lockpicking know what's going on inside the lock but essentially I had two and I went and B within a very short period of
time a minute or two my bike was unlocked I've always used that very expensive bike lock on my bike after
that time because I'm very shortsighted and it was fast that to open picking it and actually by setting the combination
so I used to just set it up and and open it up so locks are another example of security theater and we will do some
lockpicking at some stage and if you go to the conference there'll be a big lockpicking table where we'll teach you
how to do lock picking um because it's great to see that I was at a conference L are you
here I think Lia was there too I was at a conference with some very senior judges and I was teaching them about
security and all sorts of things and as the breakout activity I got them to pick locks and they said you can't do that
and I said no here's how you do it and they go oh wow and and they're very competitive I guess cuz they've risen up
through the legal system and then the Barrister system and they're just hyper competitive people so they're all going
well I'm going to get it first I'm going to get it first and one of them would knock the other one and knock their
thing on the floor so they couldn't do it and put smoke in their eyes and anyway and they someone gets whoa she's
so happy and the man next was really cross but anyway I thought later on why didn't I take a photo of that a room
full of Judges all picking locks would have been very funny but they were equally surprised so this is security
theater security theater is something often has the Baner of being secure but if you actually prob it and test it you
find it's not secure so that's one of the things we're going to add to our checklist of things we need in our state
of mind we're always going to probe and test things and when someone says this is secure we're going to go o not oh
okay we're going to go challenge accepted so there's a movie called Indiana Jones has anyone ever seen that
it's a very old movie with Harrison for oh you've seen it oh fantastic uh and the Raiders of the Lost Arc is the one
I'm thinking of and they find the Arc of the Covenant and it is this as they describe it this terrible weapon that
can do anything it melts people's faces and does all sorts of things because it's just this holy thing with full of
electricity or something and so the long film goes on they're trying to stop the Nazis finding it the Nazis find it they
have to get it back from the Nazis cuz if the na had this terrible weapon who knows what would happen they finally get
the weapon back and there's this big climactic scene and in the end Indiana jabr Jones
prevails and the arc goes to the good guys and then there's this final scene which steelberg didn't have to put in
but I'm so glad he did there's this final scene where Indie is sitting in an office with the other guy from his uni
and two Anonymous guys from the FBI or NSA or Secret Service or someone and they're in identical boring sort of
Secret Service clothes and he says where is it where's the ark you know where did it end up you know you know can I see it
can I get it now because you know I'm this historian and they said no no no don't worry we've got it away and it's
being examined by top men and he said well who who I know the field who's who's examining it um no one
I know says they're looking at it you know who who who are the top men and this is pause and they go top men and
then that's the end of the scene they're just saying essentially shut up we've got top men looking at it and always on
the TV the government introduces something whether it's you know covid vaccination things or this current new
proof of age that you can prove you're over a certain age in order to use social media or um and and it's got all
these challenges and problems to it that we're skeptical about and we're asking questions and the constant response from
the government is don't worry we've got top scientists at the a ASD looking at it or don't worry we've got our cyber
experts looking at it they're really good or something and whenever they start saying don't worry it's all under
control we're looking after it my wife and I always just look at each other and go dop men so I'd really like you to
have that sense that when someone claims something is secure either by Authority don't worry I've got some brilliant
people looking at it or just it looks Complicated by shredding or it looks unlockable unbreakable because locks
sort of had that Persona of being unbreakable especially if they're expensive you think they must be super
Unbreakable whenever that happens I just want you to think top men and laugh hysterically and then give it a go and
you'll be astonished especially with physical security measures how easy they are to circumvent all right so yesterday
we finished I was talking about this weird acronym d a e h we did the D the oh the projector's not
working oh thank you so much people taking the notes said oh Chris are you
here or is anyone here uh Tom maybe you someone said they can't take notes because the permissions answer
upright the request oh man this is what happens when we can't trust you
anymore go go to the collaborative do you want me to go to it yep oh this is awful never had to do this
before collaborative lecture notes oh my computer's very slow webcms is very
slow okay everyone write if you're writing lecture notes write them yourself we're going to come up with a
better solution in the future but today just write lecture notes yourself and then send them all to
Tom or to your tutor or to each other it's only one tutorial yep send it to your tutor yeah at the end of tonight
send the notes to your Tor and they will work out miraculously how you can all collectively edit it things like that I
think we might just make it a Wiki on webcms or something might be an easy get to do all right so sorry about that
um but yes please do take notes if you're in the Friday 9 t for 6441 uh and in the second hour if you're
in the Friday 11 shoot for 6441 or I can't believe it I always get that course code wrong it's it's getting
better it's not 3034 it's 3040 I guess because of a technicality
you don't have to take notes now so here are the things the first D is for just this sort of thinking like a defensive
person I mean it's important to think like a defensive person but um I sort of want you to move beyond that to think
like an attacker and get the attacker mindset but then the next thing is e and then we've got
H what's E stand for e is for me well let me tell you a story uh
I'm to get here I have to drive across the Sydney Harbor Bridge let let's say and I'm driving across the Sydney Harbor
Bridge and the whole time I'm driving across the bridge what am I thinking have you I gu you pretty much everyone
in this room's driven across the Sydney hover Bridge or caught a train across or walk AC what's the thought in your mind
when you're Crossing are you thinking oh goodness gracious I'm going to die I hope this doesn't crash this is so scary
the sea is so far below I can't swim oh and you get there the side phew I'm across no I think when we go across a
bridge we don't even think twice we just know that bridge is going to be okay now not all bridges are and I do
collect stories of bridge disasters around the world and we'll we'll we'll talk a bit more about them later on
but a long time ago it wasn't the case that Bridges would be like that a famous bridge and I went to Scotland recently
and I saw what was left of this bridge called the Tay bridge is anyone heard of that across the river Tay Slightly North
of Edinburgh a famous bridge which had a rail line that went from one side of the river to the other the Train on one
really stormy night departed one end the signal guard waved it through it never turned up at the other
end and the next morning whenever I woke and had a look there was a big storm the middle of the bridge was just missing so
many people died they didn't even know everyone who died because I'm not you know we didn't have good records of who
bought a ticket so Bridges weren't always safe but now they are and you could even say safe as
Bridges how come when we drive across the Sydney Harbor Bridge we're not panicking let's
just unpick that and be analytical what is it about the Sydney Harbor Bridge that makes us feel safe
yes that's a great answer what's your name Adam yeah great answer from Adam he can trust it because it's been built by
engineers and the Design's been checked by engineers and they follow the rules of physics and they understand them and
physics always works and the engineers do make sensible informed decisions based on those rules and there are
Structural Engineers and geophysical engineers and Engineers that do the footings yeah what were you going to say
it's been standing for 80 years so how long it has been oh yeah it's been working for a long time it hasn't
crashed yet what's that it could be Defender mindset to think like that we will later on I actually get very
excited in a slightly weird morbid way whenever a volcano erupts I'm always interested in whenever there's a
disaster or anything like that I'm very interested in what the people said before that and I'll hunt back through
news articles and things like that so the people that are living around the volcano that say we don't have to
evacuate it is rumbling but it's never erupted before it's okay so some things never happen until they do and we will
look at volcanoes and things later on actually because it's very interesting things that are not very likely to
happen but things that when they do happen it's catastrophic we sort of have to deal those things otherwise but yeah
I'd say 90 years of people driving across it without even a wobble is pretty good evidence that there is a
famous bridge in the US now I'm not thinking of the Tacoma Bridge I'm thinking of the one where the
the ring snapped have you does everyone know this bridge I can't remember what it's called The Bridge
thatting no that's the Tacoma Bridge the one that oscillated with the frequency of the wind no there's another one where
a ring snapped I'll show you tomorrow next time we get together um and actually I was at n the National
Institute of Standards the people that did the investigation into the breaking of that bridge and I was so excited
because I've you know Tor it for years and they have the ring there the ring that
broke I will show you a picture of the ring but um yeah okay so yeah but that it hasn't broken yet gives us some
confidence though it's a bit hard to work out how much but it certainly gives us some yes another reason is that the
bridge is considerably stronger than it needs to be all those Engineers do those calculations and then they add a big
factor of safety on top of that in case their calculations a bit wrong that's right that's right I'll just repeat that
if you didn't hear um uh there's a big it's much stronger than it needs to be the engineers have a big margin of error
built into the bridge yeah I think in our lifeim in the area also other Bridges haven't collapsed I think other
bridges are collapsing ah yeah we haven't seen other Bridges collapse so bridges built by
australi Engineers tend to not collapse so that gives us some confidence but you know if in our country bridges built by
Engineers kept I mean there's some countries where um the um authorities that have to certify things are
sometimes a bit corrupt in some countries and then when that happens you do see a series of um oh you guys
are yeah well sometimes sometimes yeah I would be a lot less confident in an Australian apartment building than I
would be yeah yeah be less confident Australian Department okay so can we just disentangle that I think if I can
summarize the reason that I'm confident on a bridge is because it has involved engineers and Engineers are a special
thing they're recognized by the government they have certain powers under certain legislation or under
certain they are allowed and in fact required to certify things under some rules and regulations so they're
recognized by law it's a profession that's been around for a long time what is a profession cyber security is not a
profession so we'll talk a little bit about what that is but I just want you to
think how come we can build a bridge that doesn't fall down but we can't make a computer that can't be
hacked how can it be that every computer in the world is hackable that every operating system is riddled with
vulnerabilities if you get um if it's Patch Tuesday if you've got some sort of Microsoft product and you get patches
for it what are those patches they they're fixing well we've got bugs which are errors in the
program and a subset of bugs are bugs or errors that potentially let an attacker do something bad we're going to call the
attack of the adversary bugs that let the attacker do something bad we're calling a
vulnerability finding a way of doing something bad runting a piece of software that does it or interacting
with the system in a way to cause the bad thing to happen is called an exploit R ation of that vulnerability and the
mechanism for exploiting it we call an exploit so what's happening when you get on on Patch Tuesday is there's a
bazillion updates some are just functional ones but a lot of them are security patches
and that means someone's found a vulnerability Microsoft's found a vulnerability in one of their programs
or 50 vulnerabilities in 50 of their programs and they're issuing patches to patch and fix that vulnerability now
just to be really precise those vulnerabilities didn't just appear last week and they're getting patched
this week those vulnerabilities have always been there or always or for a long time they might have been
introduced in something that came last week but nine times out of 10 they've been there for a very long time it's
just that they weren't noticed before now and it's not that we can go once Tuesday's passed oh few now they've
noticed all the vulnerabilities now we can stop now we can rest we can't because next Patch Tuesday they're going
to have noticed a whole lot more and they're going to notice a whole lot more and also some of of the patches they put
through are going to introduce new vulnerabilities and in fact there is no end to this game Patch Tuesday will
never stop we're just not capable of writing software that doesn't have
vulnerabilities and we're not capable of Building Systems that don't have vulnerabilities and we've tried all
sorts of ways of doing it using maths and formal methods and restricted functionality and all sorts of scrutiny
processes and you know we try means of things but the fact remains we cannot build a secure computer we cannot write
secure code we cannot make a computer that doesn't fall down but we can make a bridge that doesn't fall down so this is
the question come to you in a TI this is the question I want you to ponder for a sec what's the difference why is it that
we can't make things secure what can we do as professionals when you emerge to make things better
are there better things we can do can we learn and my step number one I'm going to say and then I'll come to you
is I think the first thing is we need to start stealing ideas from Engineers now we're going to steal lots of ideas from
people over this course we're going to go through lots of professions and disciplines and ways of thinking and
we're going to notice they have good ideas we can steal cyber so new now we we haven't developed a lot of our own
Theory but we can certainly steal Theory so that's why this course is called security engineering our first step is
what can we steal from Engineers that hopefully will make things a little bit better yes I was going to say I feel
like it's not a very good analogy because there's no one attacking bridges in Sydney if someone else was someone
was bombing the Sydney Harbor Bridge it probably be a lot less structur it could fall down know the attacks is the
critical yeah so to what extent are computer programs insecure because we've got uh an
adversarial they're approach they're subject to adversarial pressures and bridges IR
approach to adversarial pressures I think um I know a lot of people say that it is it is a common response but I
still I still think what I think because I think it's just part of the spec the spec is you've got to build a bridge so
it's not going to fall down under the expected uses of it and that involves the wind though we didn't think of that
it involves the pressure of the the water the river that's what knocked the Tay bridge out eventually it involves
unexpected loadings I once had a Chinese student who told me of a news story just from um their local area near their
house where a series of heavily loaded trucks to a construction site like massively there was a traffic jam on a
bridge and the bridge was just full of thousands of all the trucks stopped on the bridge and eventually the bridge
collapsed because it was just over loaded Way Beyond what anyone thought the bridge would do so we know the
computers will be subject to adversarial forces so we have to design them so the adversaries can't do bad things it's a
harder job than a bridge but it's really just that's the specification we're trying to meet why can't we meet that
specification it's not as though the adversary is doing anything magic it's just if
there's a weakness the adversary will find it if there's a weakness in a bridge Randomness might not find it you
know maybe the wind will never blow at that frequency and we'll never find out but I still think so yeah it's not the
same as a bridge but I still think it's the case that controlling for factors that help us achieve our mission
is something that Engineers are very good at and cyber security people oh dissing Engineers I love it
my under is civil engineer yeah yeah you know how the sausage is made to me civil engineers are fantastic it's computer
scientists useless no but we probably the same oh sorry sorry sorry sorry uh you know who's really
useless how long have they known about global warming those little bastards they've known about it forever they've
been so ineffectual and all they do is they got a conference and go oh oh oh climate change is happening oh it's not
magically being fixed oh oh oh oh and I think GE you knew about it why didn't you do something about it Heaven
Heaven's Sake so hopefully we're not going to do that we're not going to be cyber people that go around going oh oh
oh all these bad things are happening hopefully we're actually going to try and fix them because we're Engineers not
complainers yes I mean good Lu trying to build a bridge that will survive constantly
being shelled by artillery or having planes crash into it well you just have to build it to meet the spec I think I
think the difference is is that with like with Bridges it is very hard to be an adversary because the will come and
stop you while if you're trying to hack computers you can just hack them in the of your bedroom from God yeah so it's so
bridge building is very different to making a computer it's much easier to be adversary yeah so it's much easier to
see that there's a mistake because the adversary has a much greater hand because anyone can go and fool around
with a program anonymously you fool around with a bridge people will start asking
questions but nonetheless the underlying thing that's shocking me is not that the bridges not that the computers crash
not that the they're constantly exploited the thing that astonishes me is on every Tuesday we find a range of
ways that someone could have attacked it we find that we had built it thinking it was
Secure confident it was Secure and then we fine we've made mistakes so yeah absolutely Bridges
programs very different but how can we have some sort of confidence CU it's not that it's insecure because there's some
magic new thing they have thought of we've known about format ring vulnerabilities how are they still there
we've known about all these things how are they still there there's a failure of process going on yeah absolutely so
what I'd like us to do not saying it will solve all our problems it's just one of the letters that we're coming up
to but that will improve our practices and we don't currently do it is we need to bring engineering to security it's
not going to be enough it's going to be a step in the good direction so that's what we're going to explore a little bit
in the Monday lectures from now on is we'll start looking at engineering ideas but I just wanted to tease some of them
out today what what is it I want you to think yourselves what is it that
Engineers do civil engineers say what are the processes they follow
that make it more likely that the things they build are reliable that meet the requirements just think of some let's
just call some out one follow the fal rules follow the r the boss rules yes
well one thing about engineers who who are professionals is a professional has a duty to their boss but a professional
also has a duty to the profession so if your boss says we're going to use these size nuts on the join
and you think those nuts aren't big enough and the person who's employing you says yeah but we can't afford
anymore you got to use those ones as an engineer you'll stay back and go nope not doing it boss and that's really hard
to do as an engineer but you you can't actually if you do what people pay you to do you're just what do we call them a
technician if you have a higher Duty or not a high duty if you have multiple duties you have a duty not only to your
self-interest of being paid but you have a duty to society if you're a doctor you have a duty to the patient if you're a
lawyer you have a duty to the court if you're um an engineer you have duty to the profession to to stand up and do the
right thing um that's a good professional thing so I would hope you don't do what the boss says because the
boss is sometimes wise but sometimes the boss is more interested
in perhaps short-term viability or profit or something rather than engineering so but let's keep going what
are what are more things yeah the standard standards so standards are a great idea what happens is we try
something we try something we try something after a while we work out this sort of thing sort of works instead of
keeping it secret amongst ourselves which is what Engineers used to do when Engineers started it was in the days of
steam engines which is engineer and when the steam engine was invented and started being used in England it gave
them this it was the beginning of one of the industrial revolutions it gave them this incredible wealth like with they
could now pump water and a dirty air out of Mines they could drive ships across the ocean at ridiculous speeds they
could have automated Mills that did the work of a thousand looms they could drive um you know they just suddenly
everything you could have production lines uh you could mill stuff even when the wind's not
blowing it was like a printing money it was sort of like the digital Revolution and it was a closely guarded secret and
people that knew how to use steam engines or build them or construct things using them didn't want to tell
other people and in fact there's all these very funny stories of Americans um trying to to steal engines out of
England so they can take them back and explore them and then Britain sending people over to to break in and smash
them up so they couldn't see them and various people trying to be bribed to go away and how they taught engineering was
you'd just be Apprentice to someone who knew how the engine worked and then you'd slowly learn it's a very slow
method but gee Britain had the best engineers and it really helped everyone else was really quite stressed by the
whole thing um and eventually in Paris they came up with this great idea they said
let's create something called the poly Technic which is a place where you can go and rather than learning by
apprenticeship we'll teach you at scale we'll teach everyone about engineering and what some of the ideas they came up
with then we're breaking away from this secret idea which lets you make Monopoly power profits the idea that let's all
work together as a profession in at scale and if one of us discovers something let's share it amongst all of
us and that's what a standard is so you start to work out the wisest people how thick should that nut be and everyone
debates about you go well I reckon in this circumstance you should always use a 5/8 nut so then that becomes a
standard then when you build a bridge someone will say I want you to build this bridge and you got to follow this
standard and you go okay and then suddenly now all using all the right NES and your boss can't say do something
else because then it doesn't comply with the standard and it won't get signed off so absolutely standards is one let's
keep going yes yeah can I grab the estimation one Engineers use numbers and they make
calculations and they estimate stuff so they don't just go how thick shall I make that oh that looks sort of thick
enough no let's go twice this thing that's really good like your comment from before where are you you've gone oh
yeah your comment before they know the rules of physics so they and they do all sorts of tests and they check it out and
they find this beam will only deform when put this sort of pressure and under these circumstances so they they measure
and they estimate and they calculate that's absolutely right yes another thing is testing testing that's not
necessarily so important for something like a bridge where it's relatively standard but for something complicated
like say a car or they test like crazy test like crazy because are all these unexpected fa
mod yep 100% test test you test you test and they actually do test Bridges like you can still go around testing concrete
after it's poured and you're supposed to every now then check that the concrete has certain strengths and it's not got
rot and things like that there's Institue testing in fact there's this whole range of ways of testing cement
and concrete it's very exciting um so yeah test you test you measure
you share things through standards what else have we got yeah they know more about failure yeah
this guy mentioned failure modes before that's really good a a way of failing is a failure mode and that's common
knowledge and it's shared and then you sort of said um you anticipate you try and work out what could go wrong once
you know all the failure modes and you know you need to test against all the different ways things canile that's a
great Point yeah Engineers use models of physical system engineers make models and test the models so they might do um
you you're saying they might do a little mini thing and test it right because building the thing in sit you yeah
that's right that's part of testing it's a really clever idea it's too expensive to build a bridge and test it like
matches yeah that match works okay we can use that yeah that match works sometimes testing is destructive so you
can build a model yeah security can't really do can't oh no in security we can we'll
next week we'll look are you one of the engineering students in yeah yeah we'll talk about that in next week or the week
after we'll start looking about how we measure security and yeah we do put in margins yeah yeah well of course um this
is a really good point the idea of overbuilding if you have an infinite budget then of course you can make the
most secure bridge in the whole world but you never have an infinite budget so you don't want to go nuts on one thing
and then have something just Bare Bones just doing it you want to somehow make sensible tradeoffs so everything's at a
constant level of quality so yeah it's sort of wasteful to make the bridge twice as thick as it needs to be maybe
you just make it 10% thicker than it needs to be and then use all that extra money you've saved to make the footings
10% more than they need to be and so on security is the same the bad guys will always attack where we're weakest so
it's stupid building the world's best front door with the world's best lock on it if they can just walk around the back
and open the back door with a screwdriver so we actually need to make really sensible tradeoff decisions which
is going to need us to make calculations and do estimations so we can do this so we make sure that we have a uniform
level of security everywhere because as you say it's completely pointless to go nuts on one bit and get the other ones
going all right let's just pick up one or two more ideas of Engineers at the back sorry I walked past I didn't see
your hand what site called it out loudly Rie reviewing yeah peer reviews so you do something and then someone checks it
it's fantastic well done yes someone wave another hand is that at the very back sorry are so bad yeah at
the very back identifying risks and that's part of the anticipation thing that someone
rant here mentioned before yeah identify the risks and then work out strategies to deal with them uh and generally
dealing with risk we call mitigating you can't solve it but you deal with how you can either reduce it transfer it um make
it so that if the risk happens it's not so bad there's a whole range of ways we'll see when we get to the risk week
but yeah you explicitly think about the risks yep prototyping prototyping and what's the advantage of
prototyping yeah yeah yeah yeah yeah yeah yeah so it's really a good strategy to enhance our testing ability that we
test individual components we test subsets we you know rather than building the whole thing and testing it let's
analyze and test each little individual bit they did that with the Apollo moonlander it's very very clever way of
that's making it really safe it was a super engineering feat are there any more
yes forced RK for example oh constant monitoring closing the loop sort of thing or part of it yeah for example oh
now there's a climate change factor that you're meant to use increased yeah yeah yeah yeah so con
don't just build set and forget and walk away somehow keep a record of what you've done and why so as new risks
become realized in the future you can go back and make appropriate adjustments yeah and we'll take one more
yes creativity tell us about that yeah yeah that's a wonderful skill creativity maybe not just belonging to
Engineers but more widely but that's right trying lots of things not getting stuck on one way of solving it but being
able to jump around and we've seen brilliant Engineers like Edison uh even Elon Musk though he appears to be a dick
but um you know just absolutely brilliant Engineers that think of things that no one's thought of or dreamed of
before well Stevenson with the steam engine so yeah brilliant okay so these are all the sorts of things we want to
add now taking your point this is not going to solve everything for us but this is going to move us to a much
better place here are some key characteristics we measure things we're skeptical when people tell us don't
worry it's okay we go yeah show me we test we review We Believe In openness and transparency we share we let
everyone see what we're doing the calculations are public it's never trust us top men it's always this is verified
and earned trust not trust that you just have to take on board the way we treat errors oh I didn't none of us have
talked about errors let me say errors I've sort of hinted at it before but in this course in your future life
whenever you see an error you should get very excited because we need to understand errors because there are
risk so Dr document errors analyze errors share errors and make sure the errors you're seeing now won't affect
future things I love errors I document errors like crazy we will later on look at a guy called James rezon who who
wrote a really funny book called a life in error and his whole life was about errors documenting errors and finding
errors he's a very good man we we'll see lots of errors in this course standards professionalism and closing the loop woo
we hit them all all right estimation reasonableness we'll talk more about all that we mentioned that already when we
get to the measurement week just racing through now why do things fail we we'll look at
the we've got a week on safety where we'll look at Safety Science which looks at why things fail I want you to just
start thinking about it now why is it that amusement park rides don't work sometimes and kids get killed or injured
why is it that Bridges collapse why is it that I mean just pick your fam oh why is it the crowd strike disaster happened
bu why do things not work there's actually rather than just going ah life it's not
an engineering approach we need to understand what's leading to that are there different classes of errors are
there different reasons behind different sorts of errors and so are there different things we can do does this
suggest strategies we can follow was that a hand yeah shoot poor planning poor planning yes yes yes we don't need
to answer this fully now but certainly a lack of planning is going to be a disaster yeah we we are Absol absolutely
your spot on thinking ahead and planning that's engineering rather than I just reckoned this will be thick enough it'll
be fine uh yeah absolutely right absolutely right um there is a really good project book I read called um
something like why projects fail does anyone know the name of the book it's I can't remember it exactly and it's a guy
that looks at Mega projects so projects around the world that cost more than a billion dollars and he works oh civil
you must have studied this in this like why projects fail Computing projects are the most famous for failing and costing
too much and then not delivering what they promise it's just automatic whenever anyone asks me ah our firms
doing this and we're doing this big software thing what's your advice my advice is don't do it it won't work it
will cost too much it will be embarrassing and it won't work at the end um but even worse than them are
transport apparently transport projects fail ridiculously often um so there's a whole range of projects that fail and
reasons for it and there's a lot of analysis as to why projects fail and planning is one of the top four things
that he goes through so yeah we might even talk a bit about that book if we get time I'll bring in a copy of the
book if I can find it at home it's somewhere at home so you can all read it all right so we'll think about why
things fail I want to do a case study now you'll do a case study each week in your
T and I thought it'd be nice to give you a sample of what they look like after we'll go on and then we'll
take a break I'm going a bit slowly because we took a bit longer to talk about engineering than I thought we
would but I don't mind because if it's it's a success for me if you're going to go home and you're just going to ponder
this now and you're going to start looking at things and just noticing instead of just noticing there's a
disaster in the news if you're going to start thinking wonder why that disaster happened what did they say the weeks
before that disaster were there clues that should have happened I met a lady from the police Integrity commission
once at a dinner we're having this great dinner and then I broke the rules of dinner and started asking her a
questions about a work I said police Integrity commission the police must hate you guys because they are the
people that police the police she said ah yeah sort of and then I said oh tell me um when you find a corrupt policeman
and when you investigate it do you notice any patents are there things that were red flags that people
could have seen that would have given a hint that this policeman was about to go corrupt and she said you know I've never
really thought about that so we never want to be like that we always want to be thinking of that she mused about a Lo
dinner at the end she said I can't think of anything they have in common except they're all a little bit too interested
in money towards the end um so but yeah I don't know if that's a a fine enough brush to separate corrupt from uncorrupt
but okay so here's here's our story this is oh I've written the date there because I can never remember dates
oh you can't see it oh I can see more on the screen than you can isn't that weird this hasn't come down far
enough is it actually projected there oh no my screen's bigger than yours
there we go all right December the 6th a great day St Nicholas's day in 1917 a ship called The Mont Blanc a French
ship sailed it's the world World War I friendship sailing across from France to Halifax in Canada loaded to the gunels
with explosives and ammunition and shells and ingredients used for making uh
explosives and propellants for shells and oil and petrol it's just like a walking
disaster a sailing disaster and it s well doesn't sail it's steam powered or something it it toles along and it's
over in Halifax which is one of the um provinces in Canada on the on the right hand side a lovely Province and they're
they're sailing up to the harbor now I've got to say by the way uh is going to explode and when it
explodes it's going to actually be the loudest explosion man-made explosion ever heard and will remain then until
the atomic bomb is detonated in hos oh no one of the tests one of the early tests yeah one of the Trinity test
probably yeah the blast when it goes off is going to
vaporize the harbor outside of Halifax port and I've been there um is going to vaporize it all that water and it's just
going to be showing bare water bare dirt when the water comes back and wax into each other it create
tsunamis that bounce back in both directions that wipe out a tribe of local indigenous people a couple of
Miles Away In One Direction and flatten a whole lot of things in it's like a tsunami that
happens the force of the explosion is so great that the enormous ship's Cannon which weighs tons is found a couple of
Miles Away In One Direction and the ship's anchor which is equally massive is found a couple of miles away in
another Direction it is going to be the largest manmade explosion till nucleus happened so the ship is sailing into the
harbor we know something they don't know now and it's sailing into the harbor and the ports just opened because it shuts
at night and they're sailing in and they're all a bit nervous and they're French and coming coming down out of the
harbor is a Norwegian ship called something like the Ito I can't remember the exact name and the captain's
impatient because he tried to get out the night before but they you got to go down this long stretch to get out and
they'd closed the harbor just before he could get out so we had to stay in the harbor he's got to be late now he's been
to lay today so he's steaming full steam ahead coming down and he's anxious to get out and
he's feeling a bit grumpy and the Mont Blanc is coming in and he's coming out now there's a rule you have to give
way to the left or right I can't remember one one one I used to know one goes on the port one goes on the stared
so there's a standard sort of collision avoidance thing we you're on the same path if the paths are far enough apart
you don't have to worry about it but if you're sort of on the same path then you have to pass in a particular way I can't
remember which and in any case the mon Blanc has ride away and the Ito is sort of screaming towards her and the captain
of the Ito says essenti I'm making this up but let's suppose he says let's those silly
French people uh he said with a Frank French accent so terrible have you noticed how bad Norwegians are at doing
French accents it's terrible and he said don't give way just go straight ahead we're not going to Veer blow the horn
instead and the French Captain starts blowing the horn back and they're just blowing the horn at each other heading
towards each other like this and um at the last minute one of them veers and the other one veers but they both Veer
the wrong way or something or something or something and they just and they slam on brakes and the French guy obviously
and the whole crew are just going nuts they're think we're sitting on a time bomb what's this guy doing and they just
slow down slow down slow down are they're going to miss a they just sort of bump a little bit and uh a thing of
fuel Falls over and starts spilling oil around on the deck and um and then they sort of go in reverse and try and back
out or something I can't remember the exact details and anyway at some point the armor plating on the two boats as
they're trying to disentangle each other causes a spark and the deck catches fire on the
French boat and the French people um try and put the fire out and they can't so they jump into the lifeboats and they
row like crazy to the the warf and it's not too far away they're fing quite near the main WARF in Halifax Harbor and they
rad to the warf and they run through the warf and then through the town shouting run away run away it's going to explode
get out of here save your lives Run for the Hills run but in French so it's can someone speak
frenchette bagette bagette beet bagette bagette bagette and I often think what I would do I mean now we're getting to the
serious part I what I would do I I love playing this little mental imagine game when I read about disasters I just
suppose I'm sitting at the cafe it's a lovely morning on S Halifax Harbor maybe I've just met someone who's really nice
and we're just in love and we're holding hands and we're having a a baguette and and and she says
um what what are those French guys shouting did you hear that someone said Le bomb or something and I'm going yeah
I wonder what it was and we look around no one else is running ah and we just stay eating I think so what would it
take when a group of crazy French people run through saying run run flee flee flee what would it actually take to make
you change your behavior and to run and flee I don't know but it didn't whatever they did didn't work very well so
um we know they ran through because they ran past the train station and as they went past the train station they did
manage to persuade the PE they explained to the people in the train station what was going on they did manage to persuade
them to flee so the all the people in the train station flee so
um so the ship drifts closer it takes about 20 minutes before it eventually explodes they put tenders out they put
little boats out with hoses on um the Port Authorities trying to squirt water on it trying to put out the fire um
people start Gathering because it's a really interesting thing so a lot of people are gathering looking at it when
the explosion goes though one of I mean it flattens a square kilometer I can't remember the exact number but kills a
thousand people straight away I mean the town is like matched the weird uh unusual thing about it and it's a
slightly happy thing only slightly that um the people watching it tended to get their eyes shredded if they're out of
the eye blast blast range and so actually uh one one good thing is for years afterwards um if you had an eye
problem in the world the best eye surgeons were in Halifax because they' just done so many um operations and had
so much experience doing it that actually Halifax got a name for eye surgery but the devastation was awful
you know it just killed people and it wounded thousands of people as well it was an incredible and awful explosion
now the challenge for you is that's the background this is how a case study works you find the background normally
it's not us telling you a story normally it's us saying read some stories about this read about Halifax Harbor I'd say
go and here are some sample articles on Halifax but you can find your own if you want to but spend some
time half an hour an hour going away understanding Halifax Harbor and what happened and then when you turn up at
the tutorial and we do the case study we're going to get you to do some analysis here's the analysis we used to
do when Halifax was one of the tutorial questions we'd say the mayor of Halifax has appointed
you to be to head up Commission of inquiry you are to make recommendations of what the Lessons
Learned From the accident should be for the town of the city of Halifax and in particular What legislation or rules or
changes he should make in light of this thing having happened what can they learn from so that's your job now I'd
like everyone and you can talk to one or two people around you or just think by yourself for a bit let's spend like four
or five minutes now where you just just think about that what are your recommendations when we do this sort of
case study we always ask for a certain number of recommendations so give that number of recommendations I I'll give
you a clue in the early days people would give a different number of recommendations or they'd say yeah I
thought about it but no we actually want recommendations we need you to make a decision every case study involves
making a decision not just understanding something but making a decision based on that understanding so I want you to
recommend let's say two recommendations for the me
and as always we will do in this course I want them ranked so the most important one first the second most important one
second so talk now amongst yourselves we'll leave it for five minutes at the end I'd love to see and hear your
recommendations your most important and your second most important recommendation for the mayor go
[Music] [Music] [Music]
[Music] [Music] s
[Music] [Music] [Music]
[Music] [Music] [Music]
[Music] okay [Music]
[Music] [Music] [Music]
don't want to be that again um if anyone's connected to UNI we're having issues with bit rate so all of the live
stream attendance and and everything like that um it's way way down so if you can it would be great if you could
Hotpot we can actually upload uh to UNI we don't have another option and secondly Richard um every time you move
we have to rebuff all of those frames so if you could be a statue right over rund is on about 45
seconds before up the back it's funny we asked it support can we have a room with a
dedicated internet connection because we're live streaming and they said just use uniwide and we said yeah I don't
know if it'll work and they said yeah it'll work fine and we said can we just have it just in case anyway and they
said no uni has never had problems before never um so I'm thinking what we might do and this is for the online
people but you guys can all help is if I post an email address if maybe everyone could write to
it just saying there's a bit of a problem with uniwide in this lecture and we send them 900
emails polite respectful emails maybe then they will listen yes is the mic not
on oh oh it needs to be more like this ah you can see the difference
okay all right now all that thought you've hopefully you've hopefully all done some
analysis it's your first analysis So you you're not magically going to know what we're looking for and what we think is
good and what isn't um just good on you for doing it if you were tempted to not do it if you thought I'll just sit here
and do something else or I'll browse the internet or something and I just really won't engage you're very always welcome
to do that but can I just say there's a whole lot of psychology about about the difference between listening to
something passively and getting engaged with it and if you want to change it's really good to get engaged
so if you're too shy to talk to other people that's absolutely f i I hate talking to other people I'm very shy at
a party I'll hide in the kitchen unless there's too many other shy people in there um so it's fine you don't have to
talk to anyone but if you could just think about it or write notes or do whatever works for you but just somehow
hold it touch it feel it grapple it work with it don't just think I'll do this later yeah that's a wor thing uh okay
hold on to your two top recommendations well done if you spoke to other people and also well done if you're sitting in
a different seat before we come back to this I'm just going to talk briefly about um the project you'll all
be doing because we want you to go away tonight and start thinking about your project so I just want to talk briefly
about it and I'll tell you we've got a couple of projects that we've lined up where you get to work with someone that
we've found uh who we think is really cool um we've got three of those projects so I'll tell you about that and
one of those people is here so they'll actually introduce the project themselves so um here's how it goes the
something awesome project you're supposed to put about 30 hours work into it you're supposed to produce something
by about week eight but check the actual deadlines online don't trust me there's one truth of source of truth and that's
what's online you'll hand it in and then you'll showcase it to Eon in week nine the show
case I think I've mentioned before is the most amazing thing ever so pick something that you'll be proud of doing
that you'll be happy to Showcase to other people that other people will find interest actually everyone will find
everything interesting so don't worry about that try and stretch yourself it has to
be something to do with security it can relate to anything taught in the first half of the course and I'm about to show
you all the topics of the first half of the course so you'll know those topics or and um I actually don't want to
scroll ahead head uh but it can be to make something it can be to teach
something actually there's a whole range of things but one of the projects is to do something so we've got three do
something projects we've lined up and you might want to line up some yourself which is fine we need to know your
project by when do we need to know by Sunday project yeah when do they put their submission in Sunday would be best
Sunday um might might not get a response from your before your first send it to the tutor and they'll give
you response in your first T and that's when we'll approve it and then you can Stu get jump stuck in if you leave it
too late you lose a whole week and everyone's already into it and we're hoping everyone will show a progress
report in week four so the three projects we have lined up already and there'll be more coming in but I'll have
to get them in before Sunday for them to be available to you uh uh one is with the Royal hospital for
women there's doing um they have this interesting problem that when a mother comes in who's given
birth maybe because the baby is um sick or maybe because the mother is sick the mother expresses a whole lot of milk for
the baby so the nursing staff can feed the baby and it's absolutely critical that
the baby gets the correct milk from the correct mother now if that doesn't happen it can
be okay or it can be catastrophic for a whole range of reasons so they have a very strict protocol in place to make
sure that the bottles never get mixed up that no one ever gets it from the wrong person by mistake or gives it to the
wrong baby by mistake that there's no confusion in storage they have this very elaborate system I've actually walked
through the whole system with them at the hospital but every year a couple of babies get the wrong
milk something's going wrong the system is isn't quite good enough they're desperate I've said I know 900 super
smart students who would look at this and notice and come up with a sensible analysis of strengths and weaknesses and
risks of the whole project and at the end we can produce a report and I'll help you with this report that we'll
present to the hospital board asking from funding for a project to actually fix the system up maybe it'll need an IT
solution maybe it's a labeling solution maybe it's a a staff rostering whatever it is you have to cast your security
eyes over it and just work out how to fix the problem maybe you come up with a plan A and A Plan B in case they have
different amounts of money available and then we will pitch it to the board and we will try and get funding so this is a
project and then if you want we also have a whole lot of project courses including 9301 and we've got security
project courses depending on if it's a security solution or just a software solution uh and Amir is involved with
this too a what's his name not Amir am oh I'm so embarrassed I can't
remember the last letter of his name the nicest man in the world uh he's involved as well and he's happy to supervise the
9301 project so can lead lead to something great so that's project number one I've actually got a meeting with the
hospital next Monday or Wednesday and which you have a student or students if a small team wants to do it wants to do
it come and talk to me today and get your name on the list and we'll go and see them next week and start the ball
rolling there's also a project running with the Sydney um Children's Hospital weirdly enough also just next door where
they of security there their ciso is essentially looking after it security for a large charity I mean
they're not not for profit at least and he just doesn't have enough budget and he said man I would love it if someone
could come in and do an order of what we're doing and make recommendations and notice weaknesses and make
recommendations for what we should do for our cyber security posture and things that's a big project um might be
something you doing a team but he's happy to take people on he said well the first round through maybe won't get much
done if they're just news security students but it'd be nice to get to meet them and then maybe they want to do more
advanced work later on so they're two projects the third project is there's an IT startup that's pretty fantastic but
they need help with security and they would love some sharp eyes to come in look over their security and make
helpful recommendations and help them that's something you could all do when you leave you might join a startup and
startups are one of the organiz categories of organizations that usually can't afford to hire a security person
and usually they can't afford to do anything you know you're just rushing around with so much little money and so
much you got to deliver see you cut Corners everywhere it's really hard to make sensible decisions and we talked
that about that before so you don't cut too many corners away from security so you could work with a successful startup
that's still in the startup phase and see how that goes and that's Hayden's company and Hayden is here who who might
have taught you before Oh you know Hayden fantastic Hayden let me give you a mic
this one coming out yeah we have to be together you need both cuz they're both recording yeah
one's for one's for this room and one's for the people are outside the room man there you go 60 seconds 90
seconds as long as you want but yeah hopefully not to I'll just do minute up to uh I'll put that on here yeah this
all I need yep okay did I give two I just have one and that two
hello uh good evening everyone um Richard is very kindly given me a couple of minutes just to quickly talk to you
about um the company that I run mostly just to give you context so it seems like more than just a startup just an IT
startup and might interest you so I run a company called pea we're a startup based in Sydney all of our employees are
Australian based we have 20 employees and we have about 100,000 customers and that's all kind of the metad data but
what's more exciting is what we do as a company we kind of started the company with a vision and a mission that um
Australians everyday Australians are impacted by money quite a lot you know all of you here have experienced
Financial stress or you know someone who has whether it's like a bill to get paid or mortgage like it just affects
everyone across the board so we basically made an app to help people uh manage their money across a whole range
of things like tracking spending um buying a first home quicker by using you know Australian tax policies uh and then
our main product has been investing where we help people invest in really boring investments in the stock market
basically index funds or ETFs if you've heard of them so that they can build up a portfolio basically we know most
people don't want to work forever but if you put aside $500 a month $1,000 a month after 230 years and the magic of
compound interest you will have some money you can live off so you don't have to work to 0 that's the startup on what
we're doing we have about a billion dollars of our customers money that we manage which is a very terrifying thing
that keeps me up at night that's a lot of API key that I manag that involve quite a lot of zeros that I'm personally
and legally liable for and we have a very small team as I said it's just like a dozen it's literally 17 people is the
exact number of headcount we have and there a lot of customers we have to manage so the risk that we tackle are
predominantly technical risk you know there's a lot of again Keys databases AWS websites web apps you know versions
of dependencies like all kinds of things that could go wrong every day and we know we can't keep on top of absolutely
everything all all the time and then we also have a bunch of legal risk around compliance because we're a regulated
fintech so if we say the wrong thing somewhere someone could exploit that they could say ah you said this would
happen at this time but it happened at this time we have a customer every month come in and say you said this so you owe
me $400 now or I'm suing you you know something like I mean that doesn't happen every month but you kind of get
the gist of it so there's these kind of big surface areas we have of risk and as Richard so well pointed out we don't
have the resourcing that Commonwealth Bank does l they're Sole and their very large employee base so we basically
decided to opt in to be part of all of this to see if we could utilize your big brains to find things that we just
simply aren't resourced to look [Applause] for how many are you looking
for um it's a good question uh probably like you know somewhere between 5 and 10 oh that's a lot yeah we can dou I mean
there's a there's like a point where you can bounce off each other a little bit hopefully um but it depends on the group
size I'd say something yeah I mean somewhere up to 10 do you want lawyers yeah lawyers would be great it's
actually funny because um my friend he runs another Finance startup and he told me that if he had to fire everyone his
lawyer would be the last person he fired which kind of concerns me because half of our team are Engineers so I love
computer scientists right love computer scientists love Engineers that's why our company's really technical heavy um so
we'd love that help but honestly to the lawyers and law students in the room you're also just golden to us because
like we don't have a big heavy compliance team we have no dedicated cyber security staff we have no like
full-time legal council we have some like part-time lawyers so honestly it's all all good around every corner thanks
that's ftic thanks Richard would you be right to start next week yeah thank you very much that's awesome well done
thanks for coming um have people been taught by Hayden before you do the web course yeah
oh wow that's a great course yeah interesting see you bye let's all say goodbye haen
woohoo um oh I'm so pleased you know him I really like Hayden um he's such a nice
guy and super smart so anyway there are three options there's many more you can think of some yourself uh it can be
anything one year someone um built an Enigma machine that Nazi encoding decoding machine out of Lego and they
designed it themselves um someone designed a course to teach people about cyber security someone did and this is
something that might be of interest to everyone someone did some Freedom of Information requests and gippers you
have to put them in early because everyone's slow to comply to find out about things I would love if someone
wanted to find out about speed cameras and traffic cameras if you look around New South Wales now every time you look
up there's a camera um and they're collect Ed the cameras are put up for a particular purpose but of course the
police always want access to the cameras police aren't allowed to put cameras up but they're lucky they live in a society
where all the other agencies are allowed to put cameras up so um it would be fun to gier them Gipper is what you do if
it's a state body you're trying to get information and they're supposed to tell us information or Freedom of Information
if it's a federal and just find out um for example I had a student do it once uh what their arrangements are with
police and is it the case that police have real time access to all the cameras everywhere and do they have access to
all the opal data in real time and do they have access to the cameras on the stations and do that you know be really
nice to know that um and that would be a fun project it would also be challenging because they're bound to come back to
you and say we can't tell you that because I mean we'll see that when we get to privacy and data but that's the
job of the whole government is not to tell you things really um so yeah you have a fun little to and fro getting
information and seeing what you can find so yeah you might want to work out a G campaign or a um and one of them cost
nothing and one of them cost $30 to put in and we could help you or connect you with people and show you how to put them
in and give you advice on what to do we did once interview um in one year um Matt O Sullivan the Herald's transport
reporter about how he puts in gippers because he finds all the information he reports there's a transport article
every day in the herald um he finds it out through Freedom of Information requests he had all sorts of neat little
tricks for how to get information even when they don't want to tell you so that's another another fun one or you
might want to do anything yeah the sky a limit but I want you all to start thinking about it now let's resume to
the lecture do you remember you had that discussion where we're talking about the
Mont Blanc yes can I just have from some people put
your hands up and suggest something what's one thing you'd recommend y limit how much explosives can be on a
boat yep human error in terms of the boats colliding communicate what you're
carrying so people are less likely to be stupid around you indicate if you're carrying
dangerous goods and trucks do that now they have a little special symbol on the back so if a truck's had an accident you
can look at the symbol and see what it's carrying uh yeah we uh we're thinking that uh you can have it externally
managed who has priority hoping that each person's going to abide by the principles that allow them to decide you
know who goes first you have somebody externally giving permission to each Bo to uh so have a trusted third party if
you can't trust the individuals to make sensible decisions yes if you're carrying dangerous cargo
should give priority to other people you think it' be in your interest to do that yeah that would be just what you do
yeah spons but instead of priority uning there should special rules about how many ships are allowed a dangerous cargo
ship rules about dangerous cargo ships import Sorry rules about how many other ships are allowed
special are different sh all right that's great so distance from distance from special rules about
behavior in Harbor so if there's a ship that is carrying dangerous goods there's a limit to the number of other ships
that can be in the harbor and they have to keep a certain distance and behave in certain ways their behavior is more
constrainted that's really good yep um have a way to actually like evacuate citizens like a way that people have a
way to evacuate citizens what's your name Tes oh I've never heard that name before it's a new name how do I spell it
t e j a s tages well done tages yeah that's a great one way of evacuating people yep make houses moreof make
houses more fireproof yes though they didn't catch fire they were blown over like matchsticks you should see a photo
of it it was unbelievable it's like they were flattened but yeah construction codes for areas which are in danger
yeah I forgotten your name I should know it I didn't you didn't tell me oh okay shoot have a standardized language um
when especially if you're carrying dangerous cargo have at least a couple of people who speak the language of
whatever report you're going yes you should have a lang like there was a language problem that was Fran France
and Canada is anyone from Canada here is there a Canadian there must be a Canadian here in the room no oh Canadian
call out oh hello does everyone in Canada speak French or just some people just the Quebec people from
Quebec Oh I thought it was a dual language country no did they teach
you run away run away it's going to explode what would you say how do you say that because I've never known and
it's really let down this part of the lecture tell me run away run away it's going to explode
is it just bagette bagette bagette bagette or was someone playing a trick on
me all right look I want to get more hands there's lots of hands oh I I'll get your hand cuz you look disappointed
um I think compartmentalizing the problem so if they like um kept the fuel Barrels in a place where it got overturn
what's your name Ry rosney yeah that's a great one look I reckon we could go around and there'd be so many brilliant
ideas all of these ideas are brilliant but yeah compartmentalizing the ship essentially um we're g to look at that
as a general strategy with risk so if something bad happens it limits how bad it can get but can I I won't ask for
more answers because uh we haven't taught you about how to do these or how we want you to think about them so um I
I want to say all the answers you you've given so far have been been clever and I've been proud of you but most of them
are not the answer we're looking for so let me talk a little bit about the answer we're looking
for do you remember who are you in this scenario you're not the mayor of
Halifax you're a consultant you're giving the report to the mayor of Halifax the mayor of
Halifax needs to know what changes he can do now in lots of uni assignments or in maths assignments when you're in high
school there's a whole lot of word that's just color text I don't even know what's there John buys three apples to
put in every bag he has six bags how many apples has he bought we don't really care that his name's John we
don't really care that they're apples we don't care what the bags are made out of it's all color text they might as well
just ask you what's 6 Time 4 but in these questions we care deeply about it this is a real world problem and one of
the complaints we get about graduates is when they encounter a real world problem they give like a primary school sort of
answer that's ignoring all the important things who are you giving the advice to the mayor of Halifax
what can the mayor of Halifax do can the mayor of Halifax mandate that they needs to be a
French speaker on every boat in the ocean no although it was a brilliant point and very clever and I'd never
thought of it before and it was a real part of it there is some Communication Breakdown here that you're drilling into
but notice you have to give recommendations that are relevant and this is often uh newb Consultants
getting in a lot of trouble for for this they write a list of recommendations and the people commissioning it say well
this is useless because I I can't do these things they're not in my power you also have to think
about well okay I just want to think a bit more deeply that most people and I try and tell the story in a way that
makes you think about this I'm trying to trick you really and this is the way I tell the story is the way the newspapers
told the story most people think stories like this are about right and wrong and
they're outraged and there were I think three inquiries into this and one of the inquiries everyone got really angry with
all the French Sailors and locked them up and then another inquiry run got really angry with the Norwegian captain
and tried to lock him up but he was over in Norway and wouldn't come back and but it we never care about blame so don't be
outraged yes there is no doubt that Norwegian is a very annoying man and there is no doubt that he caused
the accident by not obeying the rules of the sea cuz he was impatient but the problem is how do we
end up at a system where if you have an impatient ship's Captain a thousand people die this is the real question
because there's always an impatient ship captain and it's not the blame of the impatient ship captain though the
newspapers will always try to find a scapegoat the real problem is how did this situation even happen
how come and some of you address this boats crammed full of explosives are allowed into a place where people
live how come in an environment where there are massive explosives allowed to be near people there's no way of
evacuating people and we haven't planned and rehearsed for how to evacuate people how come the Norwegian Captain didn't
know that he had to be super careful that I'm going to place low down the list but it's still really important
it goes to the communication people lot of a lot of people are talking about we have to build a system that's going to
be safe even in the presence of human error or miscommunication
so what will probably happen in your chew when you get together in a group you'll first to get together will be
given a scenario and you'll work it out in a pair and you will find the other person in the pair thinks of things
you've never thought about and you'll be impressed and I remember when I was very young I used to think I was just so
smart everyone else was so stupid and once I worked out the answer to something I could go like this I go yeah
I worked out the answer I know the answer and I'd just sit there I'd start browsing on my phone which hadn't even
been invented yet that's how clever I was we never want you doing that so hopefully what you'll find is when you
talk with someone else in a pair you'll find although you've got brilliant ideas down One path and you possibly because
you're extraordinarily clever and you are extraordinar clever you might have gone down that path further than most
people could have gone and you've thought of really clever things but you talking with the people you find there's
someone who's gone down another path and that path's interesting too and that'll be when you're in pairs and then when
you get together in the four I'm hoping what you'll find is oh yeah okay so we sorted this out and we think we've got
the right answer in the pair of us has a great thing but then when you get in the four you'll find the other pair thought
of a whole lot of stuff you didn't even think about and then when you and it'll keep happening as you Cascade up and
it'll turn out that the wisdom of the class will come up with a solution that's far better than any one of you no
matter how smart you are could ever have come up with by yourself and just realizing that and it took me a long
time to realize that I was a very arrogant young man but realizing that I think was one of the best lessons I
learned at Union and hopefully is a lesson you're going to get so you're going to get used to working together
and analyzing problems you really have to listen to everyone else's ideas not just think you know the answer and you
don't have to shut up you don't have to listen to everyone and you work through it and your ideas will be great and
their ideas will be great and then somehow you have to prioritize them but please when you ask the question
actually answer it don't think oh I wonder what the answer will be I'll wait till the end and find out that's useless
you're not developing your skill it's like it's like what I used to do because I'm really interested in in crosswords I
don't know if anyone ever does crosswords and a couple of years ago I tried to do the cryptic crossword and I
had no idea what the cryptic crossword was or how it worked but I discovered I could get it completely correct every
day because the next day day they print the answer so all I had to do was wait till
the next day and I could just fill it in completely in a sense that's good but in a really profound sense that's stupid
which is probably why you laughed because I'm not actually learning crossword skills and I'm no better at
the end I'm just getting marks or I'm just getting the crossword ticked off or I'm just I'm getting things that don't
matter but actually what I really needed to do was work out how to do the cryptic crossword and then do it and I did I did
eventually slowly work out how the damn things worked and that's what I want you to do and at the end of this course
hopefully you'll be a little bit better at doing crypto crosswords and Analysis so when you see a situation and when
they're interviewing you they'll ask you they'll say this and this has happened what do you
recommend and I hope you blow their socks off that you think for a bit and you go I've got three
recommendations the most important one is we should do this the second one is we should think about this whole area
and the third one is we need to do this and they'll go wow that's amazing that's my dream so that's the case studies does
everyone understand the case studies now are there tutors in the room I think I saw some tutors over here yeah yeah yeah
oh hey there all lots of them so um case study this week oh no don't say what it is is it one I think it
is yes yes that's the one the one we talked about in the meeting last week yeah it's so good isn't it yeah it's a
very good one it's a very good one so yeah don't be too smug thinking you've got the right answer it's the only clue
I'm going to give you um okay okay let me go on with the lecture
um okay I'm just going to race over some things that you just need to know very
quickly and then we'll get to the interesting bit physical security it's a foundation
for everything I said that yesterday if you don't have physical security it's game over um it's very hard to get right
I'd say it's it's extraordinarily hard to get right I'd like you to now be in the habit of as you walk around noticing
where people get physical security wrong and years ago we were invited up to me and a group of students were invited up
to the level the top level of the library where the it security people used to be and they wanted us to do a
project with them about it security and I had some quite senior students and we went up in the lift I don't think this
was your time Chris you weren't in this this was probably before your time yep you didn't go up the library with us to
do the Consulting no no so we went up we went up the lift we went into the level 10 or 11 or whichever one it was we
wandered around we talked to them they discussed the project we left we got in the lift the lift doors closed and I
said what did you notice and one person said Hing is on the wrong side of the door you just pop them out with the
screwdriver another one said magnetic locks could defeat with heat another one said did you notice the walls didn't go
up past the petitions and you could just pop the petitions off and climb over the wall another said I noticed the wiring
cabinet was open but it was out of view of everyone and we weren't escorted back to the door I could have just taken a
step to the side and I'd have been in their wiring cabinet someone else said I saw a password on a Post-It note on the
screen we just laughed and laughed on all the way down of all the things we'd seen that's what I want you doing that's
security eyes you're in every situation you're looking if there's a bank armored guard pulled up outside an ATM machine
and they're reloading the ATM machine I'm expecting you're going to walk past very
slowly watching the ATM machine um anyway I whenever I go into my bank branch I lotice all sorts of fun things
I probably better not say them but I just want you to do that all the time that's security ey so I just want you
physical security just watching watching thinking thinking all right uh notice that sometimes you don't
have to make something tamper proof you don't have to stop someone being able to get into it sometimes it's sufficient to
be tamper resistant it's true evident sometimes
you don't want to stop the tampering happen you just want to be able to tell if it's happened can anyone think of a
tamper evident device fire fire extinguisher oh because they have a a filter gauge that tells you the pressure
inside yeah there's something even more commonplace but yeah that's a good one what's that open yeah boxes boxes that
you've opened from a shop that have special tape on them Che a check sum oh yeah check some yes that's right I'm
looking for something in the physical world but these examples are all hacking your
phone uh how would they know you've hacked your phone how is it tamper evidence yeah they might have it so that
when you open sometimes they put a little bit of Stack sticky stacky little gooey seal on it and when you open it it
breaks the seal so they can see yep smoke alarm how do you know if they've been tampered with
oh yeah no I'm wondering just devices or physical things that are built so you can tell if someone's tampered they
can't stop you tampering with it that's too difficult or too expensive but sometimes it's sufficient to meet the
security requirements that you just know something's been tampered with bottle bottle cap that's the one I was looking
for you don't want people putting poison in your bottles it's too hard for them to invent a bottle cap that can't be
open until after you bought the bottle but they put on bottle caps now these little thin plastic things so you can
tell when someone opens a bottle so first thing you should do Chris are you paying attention in this lecture are you
writing root things in the course notes again he does it every year so here's a fun challenge for you
at home how many tamper resistant devices how many tamper evident devices can you defeat without evidence of
tampering that's a really fun exercise I've got a whole range of home of things in stores a whole range of things that
are designed to stop you fiddling with them it's remarkable how often you can actually fiddle with them and defeat the
thing um I won't do anymore but I just want to get you into the mindset of the sorts of thinking we want you to have
because every week we have something called security everywhere and how
security everywhere works is every week we want you to notice something that's a real world application of something
we've talked about in the lectures and submit a photo of it and you'll all submit your photos and we'll have this
massive scroll every week of 900 photos so you might submit a photo of someone insufficiently doing tamper evidence
yeah tamper evident device or you might submit a photo of anything uh I can't wait to see your photos but real world
examples of things we've done security everywhere it's called it's really really fun and as we do more and more
Arcane topics and advanced topics as we move through the course you'll still find real world analoges of all those
topics and you'll be able to find fantastic photos of them and post them so yeah so and the reason we do that is
I just want your eyes open now I want you to as you walking around all week be thinking what photo can I put in what's
something in the real world that corresponds to what we covered this week and then when you get it you go oh look
at that the way they've set up the letter box next to that door oh good grief and you'll send a picture of that
and we'll all laugh and laugh and laugh and laugh and laugh you could find examples of security theater that's a
great one think just now can you think of something in your life recently I did
ideally that is an example of security Theater now we've we've set that up actually it's a we got the QR code set
up it is I make it live as soon as yeah make it live let's do it everyone everyone just start thinking about it
now I'll keep doing the lecture for a little bit but then eventually um we'll give you the QR code and you can type it
in but just think of something in your life that you've seen that is an example of security theater but let's keep going
you don't I'll give you a minute or two to type it in later on quite soon all right here we go super
fast now everyone concentrate you need to get off the Wii
so I can actually hit upload oh man this is so funny I I will I can't upload it because everyone's
gone to get the QR codes oh wow oh wow we we didn't plan that very well did we um so I will find that email address for
it support but maybe you can just find it yourself and don't say Richard told me to write this or it's instantly
nullified in its usefulness just write saying hi I was in a lecture last night in this theater and we didn't have
uniwide and it actually interfered with the lecturer and the release of the activities and I couldn't take my notes
is there some way you can fix that problem please and if you're online if you could say um oh we didn't get good
streaming last night is there some way you can get better interference yeah just letting you know that there has
been an announcement that's something something is wrong with uniw ah
cool so there you go fix the problem that doesn't fix the problem so they'll they'll be so yeah don't say my name or
I'll get in trouble now but um it would be nice if they gave us a wide connection down here thanks Lia okay let
I'm going to go through this really quickly because we're not going to open it just yet there's a couple of points I
want to make so just focus Recon the start of every attack is Recon or most attacks so the
bad guy will try and find out information about what they're attacking the more information the easier it is to
attack something so the Recon phase can be passive or active passive is you just look at things without doing anything
without giving away that you exist I guess you could look at a web page which will submit a web request so it'll be
clear that you've submitted a web request but let's say that's still fairly passive active is when you
actually send packets in or you walk into the building and you take some stationary or you go to their bin and go
through them or something like that bit dumpster diving that's called that's all Recon but that's active and it exposes
you to more chance of being discovered passive Recon is where they don't even know you've done the Recon we're going
to do lots of pass uh passive Recon of a sort in this course but can I just remind everyone that U The Good Conduct
code the good faith policy we don't want you investigating or stalking or following anyone in the real world
unless you've got their permission so yeah don't don't don't stalk crazy we'll give you lots of
stalking things you can do and things you can Recon U but do the things we give you don't think it'd be funny to
stalk someone there is a few exceptions it's fine to stalk elong musk it's fine to St stalk Putin just
don't say my name okay but uh don't go and try and stalk the Prime Minister and work out
where he lives or where his children are or their names or any that's just so not good thing to do please don't do it and
it's also not respectful to people we're going to talk bit about privacy and it's just not the right thing to do um it's
surprisingly easy to do Recon years ago we used to have a Recon exercise where everyone had to Recon a company and I
gave everyone real companies um and they had to Recon them and work out the name of the managing director and the name of
the firm that did their cleaning we think of a supply chain attack if you wanted to infiltrate the cleaning firm
and the name of the company that did their database backups and things like that um and we just gave everyone fairly
small companies I thought it was a fairly innocuous exercise and Google had just started up in Sydney and one team
got Google Sydney the Sydney office as as their target and the next day the vice
Chancellor got an email from I think Alan Noble head of engineering at Google at the time saying I hear that some of
your students are trying to Recon our offices and we believe strictly and firmly in privacy at Google and uh we
don't think that that should happen and what blew me away is the people in that team that got given
Google hadn't told anyone else they'd got Google they said and they hadn't told Google they'd got
Google but they had discussed it amongst themselves on Gmail I I still don't know but there you
go um we're going to talk about OS yeah but please be respectful don't do that uh please be respect respectful uh we'll
talk about OSN later we'll talk about this very funny plane picture later we'll talk about the history of
cyber can we do the history of cyber in a second no because I want to do more interesting things we'll come back to
the history of cyber in the future history in the future so uh the anatomy of an attack a basic attack is
very simple I was going to tell you one of my first attacks but uh an attack normally as you do some Recon you find
something stupid that someone's overlooked you make of the stupid thing and you get access to the system it's
remarkable how rarely you need to actually do elaborate sophisticated technical
attacks now that's slowly changing over the time as people are becoming more cyber aware and certainly there are
sophisticated attacks launched against sophisticated companies but um for simple things and for simple people and
simple organizations it's rare that you need to do anything technical to break in and I do have a very funny story that
I don't have time to tell now but if you remind me can someone remember to tell me the story about the Philippines
I have a very funny story about someone who was hired to pentest um well essentially red team one
of the very big and you probably know who I'm talking about Chris I'm looking across but I hopefully I've never
mentioned this person's name uh and I haven't mentioned the company but it's one of the very big it firms that you'd
know one of the top five in the world and he was hired to pentest um a former student hired to Red Team them to see if
he could get in uh and his Target was to either get the MD the managing director or the Chief
Financial Officer to click on a link and you got the managing director to click on a link uh and it took him a month of
stuffing around not doing anything and feeling guilty about not doing anything because he's a
procrastinator and then a day of Recon and then about an hour to do the most ridiculous low Tech attack you've ever
seen that got him essentially owning a very large company uh and I will tell you details of the attack one day if you
remind me it's the Philippine story remind me about that um cuz he he went in through the Philippines um okay so
but the point of that is and I'm not telling the story but I want you to get the point technical things are very
interesting and we will look at them but just be aware the lwh hanging fruit it's usually just human error and
non-technical things that are the easiest way for an attacker to get in and an attacker will always Target the
easiest way unless they've got other constraints on them because it's just more efficient for them to do it so if
you can get in an easy way without giving away some of your special tools then why wouldn't you go in that way if
there's a vulnerability do I have that chart of vulnerabilities here we have them so this is a list from February
this is more than a decade old this list if the day that a company discovers that there's something wrong in their system
that there's an ex there's a vulnerability and it needs to be patched we're going to call that day
one and if it takes them five days to patch it then it's not patch until day six so that's five days that a
bad guy could use it if the bad guy knows the vulnerability before the company even
knows about it we call that day Zero though if you're a hacker you pronounce zero as O So o day is what it
used to be called but I have heard lots of people say zero days now weird so OD days zero days are vulnerabilities you
know in software that the company doesn't know about yet so they haven't even tried to fix them there are people
who make money by finding oday and selling them and you can actually buy packs of oday they all get bundled
together for different prices you can get different packs often they come with all sorts of legal requirements on them
that you can't tell the company about them and so on and so on um this is a list from 2012 of the list for the price
for OD days to let you break into certain systems so to break into anything from Adobe really
nothing to break to break into max o Mac OS X it costs 20 to $50,000 to break into Android costs more
gee that's changed so much uh to break into flash well that's weird to break into wood oh wow these have all changed
okay to break into windows and look iOS the most expensive to break into the FBI how much did they end up paying oh what
are you gonna say Chris yeah uh iOS 2015 they paid out of 1 milliony was 10 years ago now yeah iOS
was that was the FBI paid that out didn't they they needed to get that guy I actually thinkle paid out a couple of
these in the past oh in terms of bug bounties bug bounties yeah yeah they pay yeah yeah so now the
companies realize they'd rather buy the odas from you than have you sell them to the bad guys so they have programs
called Bug Bounty programs and if you find a vulnerability you can sell it to the company and then they'll fix it y
just on that because bug bounties are paying so highly um the bad guys will for them because they they're
bad otherwise you're going to take more money yeah don't Dole or yeah no adob Adobe um if you find a vulnerability in
an adobe product they um they give you $150 and a lollipop I believe so that's their sweetness they don't even give you
a subscription because it's a vulnerability no one was taking them up um okay so here's my challenge for you
can you try and update this list for 2024 this list is 10 years old so see if you can find how much it costs so this
is the world we're in now of cyber that it's become business and that people specialize so you don't even have to be
an elite hacker to find a vulnerability to break into something youve just got to have a bank balance and you buy a
vulnerability and you can break into someone and actually you can buy all the other services there's there's malware
as a service there's ransomware as a service you can buy these servic and there Specialists who will deliver them
all for you okay um I won't talk much about that I won't talk about that I promis L we
wouldn't skip things L I'm just going to delete these out of the slides and we'll put them in next week because I wanted
to get to this question can we ever be secure are we now in just the wild west but one day we'll understand all the
Securities and then we'll be able to patch and fix and we will be secure is in other words this a temporary
anomalous time of change and eventually cyber people will be out of work and there won't be things it's an
interesting question and I've talked about it with lots of really smart people in the profession the general
consensus and it's what I believe is this will keep going forever because vulnerabilities exist
when the systems are so complex that humans make mistakes when we design them and those mistakes arise
out of the complexity of the system if the system was really simple we could make it secure but no one wants a simple
system we want a system that can drive the car that displays the clock in the top left hand corner that lets you also
do this and share it over messages and at the same time should do this and that you know we just add more features I
think it's a nature of humans that our reach exceeds our grasp we just always trying to build the most complex system
we can at any instant with the funds we have available and resources we have available I was speaking to an engineer
at meta who works on the facial things augmented reality things they're doing and um he said that to
stop people being cast feel sick when they put them on what they do now is they run a GPU and they estimate the
velocity of they identify all the objects in the scene and they place them in 3D space and they estimate their
velocity and then they roll forward into the future to predict what things will look like in the future and they show
you that so what you're seeing doesn't then have that lag that processing lag because even a tiny lag of a few
milliseconds is enough to make you start feeling sick and he said they can just adjust how far in the future they go
when they hit a sweet spot it's just like wearing glasses you don't do it but they have to run a GPU constantly
analyzing assessing breaking the scene into components doing all sorts of AI projecting into the future and so on he
said that's really compute intensive and he said their limit is 10 watts the device can't use more than 10 watts it's
got nothing to do with batteries can anyone guess why it's 10 watts cooling it generates heat he says if you
wear a really good one with a really big GPU after a couple of minutes you have to take it off and your face is covered
in sweat so that's the constraints you can see they're just pushing it to the limit so their whole team is trying to
do the best compute they can the best prediction the be on the best GPU with the best AI and they're just straining
at the limits and if someone comes out with a slightly faster chip tomorrow and a slight they're going to do it straight
away we always want to do the best we can the most complex we can and I think that is our fatal human flaw we will
always build complex systems complex systems are too hard to understand so they will have errors in them bad guys
can always exploit errors so I think um these are the patterns we're going to see we always have complexity so we'll
always have vulnerabilities um I've talked about top men have I talked about user
error and we'll always have user error um bad guys work by exploiting our trust these are just the touch points I wanted
to mention uh cutting Corners yeah people cut Corners I was speaking to a hacker once whose job it was to find
oday and sell them he's very wealthy now and he said one of the things he used to do and actually I think shabs used to do
this too he'd look on open source projects and he'd find a bug and then he'd look to see who contributed that
bug and then he find every piece of software that person had ever been involved in and he said it's so fruitful
once you find someone who cuts Corners they cut Corners everywhere we tend to cut Corners
another example of human error and the last example I wanted to give no I'll do it next week I'll L I've so let you down
on my promise that I'm not going to leave things till that week next week um so because I I did want to show you the
topics we're going to be covering so you can think about what you might want your something awesome to
be um uh here they are in we one we're doing security and Engineering security that's what we've just done in week two
we're looking at risk and Trust in the Monday lecture lawyers don't have to come but if you're interested in Risk
you might want to come risk is something that cuts across everything we're looking at secrets in the Tuesday
lecture and the characteristics of Secrets and how security depends on secrets and the structural weaknesses of
secrets on in week three we're looking at how to measure information how to measure security do some of those
engineering calculations on security we're also starting to look at modern ciphers post the Enigma machine and just
the ideas behind them uh on the Tuesday lecture we're looking at humans human weaknesses human flaws this you're
taking a photo but this is hopefully all available hopefully you can just click through this on the lecture slide page
and if you can't see it please let us know uh we're talking about on week four we talk about confidentiality protocols
to give confidentiality asymmetric encryption and ciphers in General on the Monday lecture might be fun for lawyers
and on the Tuesday lectures we're looking at one of the most underrated and important topics in cyber security
which is insiders sometimes the attack doesn't come from the outside and we put all our
effort into defending it none of you said this in burgling a house what's the easiest house to
burgle your own house s surprising how many security features just don't
work we look at Integrity in protocols and we look at privacy okay um and here is we've reached the end now
here's the summary of the something awesome just let me finish and then we're
done you can audit something which means analyze it and do an analysis report pick something fun or important and we
gave an example today and audit that the project can be to make something but it should be a challenge you
about the challenge can be to learn something maybe you want to learn how to lockpick we had a policeman doing the
Course once and he really wanted to learn how to lockpick and he sent us a photo from the bunker uh wherever he was
I don't know if he's a normal policeman and they had a whiteboard and he'd got the whole team working it and they had
all these challenges and they were ticking them off as they did them and there's a whole Army of police now that
know how to lockpick um you might want to do a CTF online you might want to learn something to do with coding but
make it security related show the code show the QR oh I haven't showed the QR okay where is it
Chris oh okay I have to log in you guys let me fix this I'll log in
yeah there you go unlikely to work we SE being P um so anyway you see how to access it we won't
turn it off for a couple of hours so you can enter it later on all right see you everyone oh and we're going to do a film
now that's what I was going to say so those that are waiting we're about to do the movie with pizza those that are
leaving goodbye and I look forward to seeing you next week hey um I'd love to be a part of one of the three
[Music] a [Music]
[Music] yes [Music]
[Music] [Music] so
yes [Music] [Music]
Bridges benefit from established standards, professional certifications, safety factors (overbuilding by 10-50%), and rigorous peer review and testing. In contrast, computer systems face constant vulnerability discoveries (like Patch Tuesday), immense complexity, and human error, and they can be attacked anonymously from anywhere, making perfect security elusive.
DAEM stands for: (D) Shift from a defender to an attacker mindset, (A) Assume nothing and test everything, (E) Apply an engineering approach, and (H) Consider human factors. This framework helps you systematically assess vulnerabilities and build more robust security by challenging assumptions and using structured methods.
Engineering practices such as measurement and estimation quantify risk; standards compliance follows frameworks; failure mode analysis anticipates attacks; destructive testing becomes penetration testing; peer review is code review; risk mitigation is threat modeling; and closing the loop involves post-incident reviews. These methods replace reactive security with proactive, disciplined defenses.
The key lesson is to focus on system failures rather than assigning blame. Effective recommendations target what the mayor (or system owner) can control: implementing traffic rules for dangerous cargo (like network segmentation), conducting drills (incident response planning), requiring clear communication (security protocols), and zoning restrictions (access controls). This prevents cascading failures.
Most attacks exploit human error and social engineering because these are easier and more effective than finding technical vulnerabilities. Systems are complex, but humans often click on phishing links, share passwords, or leave data exposed. The lecture emphasizes that even high-value zero-days are less prevalent than simple human mistakes.
No, security is a constant race, not a destination. Complexity is the enemy of security, and users demand complex systems. The economy of zero-day vulnerabilities ensures continued exploitation. While simple systems can be made secure, few want them, so we must accept ongoing vigilance and adaptation rather than a final state of safety.
The lecture's bike lock story shows that an expensive lock can be picked by feeling internal clicks while applying tension. Instead of relying on the lock's price or claims, you should physically test its resistance to common attacks. This principle applies to all security: challenge assumptions, simulate attacks, and verify effectiveness before trusting it.
Keep this summary
Save it to LunaNotes and it becomes a real note in your library — editable, searchable, and ready to turn into flashcards or a diagram. Free to start.
Save to LunaNotesOr summarise for another video.
This summary and transcript were automatically generated using AI with the Free YouTube Transcript Summary Tool by LunaNotes.
Related summaries
Complete Cybersecurity Full Course: Threats, Tools & Career Guide
This comprehensive cybersecurity full course covers everything from fundamental concepts and common threats (malware, phishing, DDoS) to hands-on tools like Kali Linux, Nmap, and Wireshark. Learn about cryptography, ethical hacking phases, and the career roadmap to become a cybersecurity engineer.
Common Cybersecurity Threat Vectors and How to Protect Your Systems
This video explores various methods attackers use to infiltrate systems, known as threat vectors, including messaging platforms, malicious files, network vulnerabilities, and supply chain risks. Learn key strategies to identify, prevent, and mitigate these threats to enhance your organization's cybersecurity posture.
Exploring the Love-Hate Relationship with Offensive Security Work
In this engaging keynote, the speaker shares a personal and nuanced perspective on offensive security work, discussing both the reasons for their passion and the challenges they face. The talk highlights the technical, economic, and emotional aspects of offensive security, while also addressing the ethical implications and societal responsibilities that come with the field.
Network Security Zones and Attack Surface Reduction
Explore the fundamentals of network security architecture, focusing on security zones and attack surface reduction. Learn how to logically segment networks with zones like trusted and untrusted to control traffic flow and minimize vulnerabilities, while understanding practical steps to protect network connectivity and data.
Defending Against Nation-State Cyber Threats: Insights from Tailored Access Operations
In this talk, Joyce from Tailored Access Operations shares critical insights on how organizations can defend against nation-state cyber threats. Emphasizing the importance of understanding one's own network, Joyce outlines key strategies for identifying vulnerabilities, implementing best practices, and maintaining robust security measures to thwart advanced persistent threats.
Most viewed summaries
A Comprehensive Guide to Using Stable Diffusion Forge UI
Explore the Stable Diffusion Forge UI, customizable settings, models, and more to enhance your image generation experience.
Kolonyalismo at Imperyalismo: Ang Kasaysayan ng Pagsakop sa Pilipinas
Tuklasin ang kasaysayan ng kolonyalismo at imperyalismo sa Pilipinas sa pamamagitan ni Ferdinand Magellan.
Mastering Inpainting with Stable Diffusion: Fix Mistakes and Enhance Your Images
Learn to fix mistakes and enhance images with Stable Diffusion's inpainting features effectively.
Pamamaraan at Patakarang Kolonyal ng mga Espanyol sa Pilipinas
Tuklasin ang mga pamamaraan at patakaran ng mga Espanyol sa Pilipinas, at ang epekto nito sa mga Pilipino.
How to Install and Configure Forge: A New Stable Diffusion Web UI
Learn to install and configure the new Forge web UI for Stable Diffusion, with tips on models and settings.
Found this summary useful?
Take it with you. One click puts it in your own LunaNotes library.
Save to LunaNotes