Jump to content

Recommended Posts

Posted

It appears that in less than a week I've been volunteered to give a Cafe Scientifique talk on Information/Cyber security. Shouldn't be too hard, as it's only a twenty minute talk (with questions to follow) with no presentation materials allowed. Which of course makes life so much easier.

 

The problem is that I know I can blather on for hours about infosec, going on and on and on - but this is meant to be in laymen's terms, and with only twenty minutes I'm struggling to decide on priorities. I think two or three concepts/topics are the most I can cover - ideally related - but I'm having real difficulty working out what's actually of most interest to people outside the field. So I'm going the crowdsourcing approach.

 

Current suggestions I've had include:

- the dangers of public wifi and why you should never use it

- how North Korea could take down all of our connected infrastructure

- the great Russian Bank cyber-heist

- DoS and DDoS attacks

- why internet-enabled toys and gadgets are the worst idea in existence without proper security (and potentially with)

- what personal information is and why you should care about it

- how to protect yourself from monitoring on the internet (pretty sure I couldn't cover this in twenty minutes without dropping into overly-technical matters)

- symmetric and asymmetric encryption

 

All suggestions are welcome. Basically what I'm looking for is if you were going to something like this, what would you be most interested in hearing about?

Posted

I certainly wouldn't suggest symmetric and asymmetric encryption for laymen's terms :p

 

How laymen are we talking here? Newbies to the IT sector, or your bog-standard office-desk employee?

 

For your average office employee I'd recommend, as you suggested, Public WiFi, Internet-enabled gadgets, personal info (ties in with internet-enabled gadgets) and how to protect yourself online (basic e-safety/common sense).. I think anything else would go over their heads or make them disinterested as "This doesn't really apply to me."

  • Thanks 1
Posted
The Cafe Scientifique setup can be absolutely anyone, but does tend to be weighted towards those interested in science and tech (for obvious reasons). I know that last month they had a chat on beekeeping for example, and previous topics have included signal processing and other esoteric subjects.
Posted
People 'outside the field' won't want to hear about DDoS attacks or encryption IMO. They will want to hear about things that are relevant to them every day, as above; WiFi, personal information on the web (could link into usernames, 'doxxing' etc), maybe look at mobile security? app permissions etc.
  • Thanks 1
Posted

- how North Korea could take down all of our connected infrastructure

 

They can't.

 

There's literally a single feed in/out of the country, and it runs entirely through a single Chinese ISP. [No backup links]

 

It's more likely 4Chan script-kiddies will take out our infrastructure than North Korea.

 

 

...actually make that the topic.

 

Wretched Hive Of Scum And Villainy More Likely To Disable UK Internet Than Psychotic Man-Child.

How 4chan is potentially a bigger thread to UK networks than North Korea.

The results will amaze you!

  • Thanks 1
Posted (edited)

Even when your audience is interested in tech, I think DDoS, Encryption and the Best Koreans is stuff that isn't really condensible into 20 minutes (at least, not to the point of any useful information). Something like Encryption, I'd imagine, would be an entire talk in of itself. However, Encryption will invariably be mentioned when you're discussing keeping information safe (even if just to the point of saying HTTPS is better than HTTP because of encryption) so if they're interested they'll look into it more, but it's a very specialist subject that I reckon would feel a little out of place in a 'general tech' presentation.

 

  • The dangers of Public Wifi
    1. Rogue access points
    2. Weak encryption
    3. MITM attacks

    [*]Internet-enabled gadgets

    1. Lack of security
    2. Baked-in admin credentials
    3. Data leakage

    [*]Protecting your online identities

    1. Strong passwords/Password safes
    2. 2FA
    3. Give as little details as possible
    4. Turn on DNT

    [*]Protect yourself online (General e-safety)

    1. Good judgement of emails
    2. Check URLs
    3. Malware/adware bundled with programs
    4. Viruses and trojans - Antivirus is the last line of defence and isn't infallible

 

I reckon you could stretch 20 minutes out of that and it covers a good chunk of 'the basics' and good practice without getting ridiculously over-technical or cutting topics down to the point that they're not giving any info.

Edited by Garacesh
  • Thanks 1
Posted

I've done good talks about these issues before. 20 mins is really short to go into any great detail though, especially given you don't know the focus of the people attending.

 

My normal topics focus around Social Security and Social Engineering, however.

 

Background/History: We've been cheating and lying to each other for god knows how long in our past, it's human nature. Good examples date back to ~1180bck, with Greece invading Troy with a Trojan Horse. The weakest link in any system is the person involved, so it makes good sense to include this.

  • Thanks 2
Posted

Well the talk's now done, and judging by the followup questions (and the several drinks bought for me afterwards) it went well. Managed to stick to just under the 20 minute time limit, or so I thought. Questions and discussions afterwards added another half hour, and I ended up circulating and discussing, debating and answering questions with smaller groups for the next two hours.

 

In the end I went with:

- Public wifi and why you should be worried about it, and what to look into to protect yourself

- Social engineering and reconnaissance, why all of the 'security' questions companies ask you to fill in are awful and what you can do about it

- Basics of encryption - with a focus on PGP and SSL certificates

 

The SSL certificates one I got a particular thank you for, from someone who apparently keeps getting asked how they work and what the certificate alerts mean in their day job and is going to use my analogy in future.

 

Thanks to everyone for your help and advice on this. :)

Posted
What was your analogy?

 

Keys and padlocks and boxes inside boxes. Then moving on to point out that a trusted certificate just means that someone your browser/computer trusts has signed it - and an untrusted means they haven't. It will still work for encrypting your data between you and whichever endpoint actually holds the certificate, you just shouldn't automatically believe they are who they say they are.

 

The analogy is one I've heard in various forms before, and goes along these lines:

- You have a box and the server has given you a padlock to lock it with. The server has an infinite number of these padlocks and is happy to give them away, but there's only one key which you hold.

- You then have a larger (or smaller - it's not a perfect analogy and is designed to get the idea across rather than the exact functioning) box, and a lot of padlocks your computer has made, along with one key that can unlock it. You put the boxes inside one another, send a load of padlocks out, and send the boxes over to the server.

- The server then unlocks its padlock, reads the message, sticks a new one in the box and sticks one of your padlocks on it so that only you can unlock it. Repeat until you're done.

  • Thanks 1
Posted
I do love the ipviking map (it's my screensaver at work, and I have a monitor running it most of the time at home) but no visual aids were allowed. :)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...