Cybersecurity Visuals Challenge
openideo.com
openideo.com
The gist being that grepping your nmap output may not be visual eye candy to us, but it can still invoke a sense of mystery and magic in others since they don’t have a firm idea of what’s happening. But they feel something important is about to happen as a result.
- A country or its institutions may be sanctioned by the sponsor's country. Increasing the difficulty of processing financial rewards.
- Increasing the number of languages covered by the sponsor via Terms & Conditions [1] and Q&A support [2] increases the cost of launching the challenge.
- Some countries have stricter and/or ambiguous digital and financial laws, increasing the risk and cost of compliance to the sponsors.
[1] https://www.openideo.com/content/cybersecurity-visuals-addit... [2] cybersecurityvisuals@ideo.com
https://jvndb.jvn.jp/ja/contents/2007/JVNDB-2007-000398.html https://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000034.html https://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000040.html
Here's the BBC's "cyber attacks" page: https://www.bbc.co.uk/news/topics/cp3mvpdp1r2t/cyber-attacks
Predictably the very first picture is a guy in a hoodie. In all the stories they clearly struggle for images. They picture instead the targets or in some cases resort to people holding laptops or phones or this garbage: https://www.bbc.co.uk/news/uk-england-essex-48351510
For the last year I have been presenting a set of visual models that allow product managers (and people who hold solution risk but don't code) to collaborate on threat modelling with their dev teams, because collaboration is the only viable way to solve security, and it's the one thing we haven't tried because the entire DNA of our field originates in a revolt against solving problems merely by managing to get along with others.
Product and higher love it, but the resistance I have encountered has been from security technologists whose work it simplifies because it does not enable them to express their virtuosity.
The analogy I would use is it's has been a bit like showing a pianist a sequencer/synthesizer or a percussionist a turntable. Excellent tools for composition and making things other people want, but ones that debase the artists investment in talent and physical skill. It does not help them actualize.
Security people become extra suspicious of data viz because they sense they are the ones being persuaded to trust the person who came up with it, and their mission in life is to dig beneath representations. Viz can have the opposite of its intended effect by reducing team alignment as the result of the most technical people defecting in response.
What I have learned about colleagues in the security field is that they want tools to help them become things, not reports to relate with and broker things. Security people tend to want to be powerful outsiders, hackers, researchers & scientists, sheepdogs, magicians, etc. They generally do not want to be the insiders, deal makers, enthusiasts, collaborators, persuaders, deciders, or other people who operate on the level of abstraction where they consume and present visualizations and other representations. If we did, learning about crypto primitives and to reason in BAN logic is the least smart way to achieve that. Similarly, nobody masters the oboe to be cool and popular like a DJ, and while they appreciate the difference it makes in a song, most people are indifferent to whether it is synthesized.
So long as a tool lets a project manager move a risk item from Red to Amber to get them through a project gate, they wouldn't care if we in security used an interpretive dance troupe. The threat modelling tools today are basically toys for technologists where decision makers see them and say, "great, you've shown us how smart you are, what will it take to get you onside?" The irony is that this is success from a security perspective, because it gets them a seat at the table.
So why say this at all? Because the revolutionary change that will solve security will not come from data, or individuals demonstrating how brilliant they are. It will be a function of collaboration, facilitated by clear representations of shared understanding, and alignment of all parties on incentives and risks.
That last part is the Hard problem, because it's fundamentally political, and the one as technologists we are least equipped to resolve. This data viz challenge is a fun idea, but it would be helpful to know just who they think will be the consumer of these visualizations, and what they would do if one were perfect.
That said I do think there's another part of this problem...security vendors have been selling garbage visualization products for at least 20 years now and over-promising greatly what they can do. Anybody that's been burned is going to be incredibly skeptical of something new...especially if it is billed as a way to visualize 'security' and not a laser-focused sub-domain with ample options for extending the visualization for corner cases not included in the tin.
Common visualizations are interesting, but second order to designing a process that works. However, it would be nice to have a library to pick from, as opposed to have to create something ourselves.
The cost of running insecurely should exceed the cost of making it secure.
Usually this is done by the Board firing the CEO and the next CEO firing anyone who fails to improve
For a long time it has been better to do your job insecurely than to fail to do your job whilst being secure.
GDPR, equinox, target are starting to change that
In short, the CIA is very good at operating with high levels of cyber-security. Do as they do.
This was suggested by Bruce Schneier, as well, in one of his books, citing the example of rising difficulty of credit card fraud now that the credit card companies are held wholly liable for it.
The people that are held liable for credit card fraud are, ultimately, the merchants. If someone uses a stolen credit card, it's the merchant who is left without any money after shipping their goods.
But I never really got tired of programming and at this point in my life the latter meshes better with what I’m interested in – privacy, encryption, hardening or subverting systems, etc. – than the former. I also get to reapply knowledge that was abstracted away while I predominantly did front-end development.
In my area cyber security companies only hire people with the same background and experience. Without that, HR will just filter you out.
I'm like you, CompSci degree with embedded background and working on my Offensive Security certificate.
I’ll be talking to contacts in cybersec and HR/recruitment departments in my area since the hiring filter is a bit of a concern. I’m used to going around HR, but not sure how that plays out in this industry. Despite doing front-end and full-stack development for every position I’ve had I do feel I need to groom my experience a bit to downplay my UX/UI contributions. Worst case is I get certs like the OSCP you’re getting to speed things up.
Lame....
Gimme a visualization of TLS for example...
WTF
OK Cool downvote me: but put a freaking visualization example on the fucking main page...
No, because ultimately titles, like images, are made to quickly capture people’s attention, and using images of “real” cybersecurity would be boring. Are you gonna show a WAF? Some logs? A usb?
Better to show a disheveled Russian in a grungy room filled with cigarette smoke and empty vodka bottles. People will associate cybersecurity with whatever they see in movies and shows.