Monday, July 20, 2009

Never forget to enjoy ideas

On a personal note, this weekend was a birthday celebration for both me and my daughter. I am 40, she is 2. A recent student is enjoying a commencent for his bachelores degree with his family in AZ. In one weekend he is recognize for both this and a new ECSA certification. He also has a great personal story.

I am on cloud nine for a number of reasons.

My daughter's presents involved a lot of assembled parts. She (who understands remote controls, cell phones, and will not fall for fake laptop toys verses dads office computer) tried to help assemble her own presents. Those moments were so much damn fun I can't begin to get into it.

I was reminded of a quote from Mr. Rogers many years ago; "Play is serious business for children. It is how they learn" (If you don't know who this is, please wiki 'Mr Roger's Neigborhood)

Is this much different for adults? We often forget to play with ideas. We forget to have fun doing what we do. Even the most dry and boring compliance thing can be approached with the curiosity and wisdom of a child that has not yet learned the "I don't care about this crap, just give me the answers to the test" attitude. Our discipline depends upon this.

Nuance in information assurance is a Mandelbrot formula. There is always something else buried in the details. The only way to enjoy tackling a challenge is inderstand how to play with it.

My friend Jason that just graduated, has this spirit too. I was glad to have met him as he is the very definition of this principle. My daughter is a person I cannot possibly be more proud of as she teaches me what it is like to grow up in this age, and reminds me about what hacking is really about.


Friday, July 17, 2009

Students are evolving faster than the courseware changes

First I would like to thank two very recent classes, one in DC (CEH) and the other in Atlanta (ECSA) for a great time. The fact that those classes were successful were all the credit to the students. They were loose, understood the concept of how a "hacking" course really works, and enlightened each other with different points of view. Even the non-related discussions we had at breaks were educational.

During my CEH class in DC I was talking to another instructor, Claude Williams, a CISSP instructor extraordinaire that has perfected his delivery of that class. I was picking his brain about courseware updates and I brought up my theory that eventually, printed courseware will be outmoded. "Liquid materials" are the next step for training, courses that evolve and are flexible.

I based this theory on a number of issues that I couldn't get into at that moment. He asked me "Do you think this is a good thing?"

I paused for a moment because I had actually never assessed it that way. I just assume it is happening so accept or die. But the truth is that changing courseware "on the fly" plays havoc with a lot of logistic elements of the training industry behind the scenes. It made me realize that the real reason I think fluid courseware is a necessity is not that the subject matter really changes much over time, it is that our students change. Their environments are not the same as they were even a year ago and they are coming into class with difference perceptions of the subject matter.

For example: One of the students in my CEH class mentioned that the tools he uses at work do so much work automatically, that he has no idea what is really going on. I felt like an old man about to give that "When I was a boy I walked uphill both ways barefoot in the snow speech" when I said "When I was a young pentester, we used to have to but effort into network mapping and assessments."

I give this guy a lot of credit for understanding that the ease of use in his tools are not representative of the actual events taking place. But this was also an indication that he would have an entirely different way of looking at the material than those in the room that had no idea what we were even talking about. I worried that those students would get hired one day at a company that does robo-pentests and with adventurous excitement expects to apply the skills he learned in CEH, only to be laughed at and told, "No, just enter this data and click this button. Left click to be specific".

About every third class I get a student who argues "Routers don't pass ICMP". Before I get frustrated I consider why he would say such a thing. It is because in his world this might be the truth, and all he has ever seen.

Training classes are not about validating the students experiences. But the curriculum must be adapted to these perceptions. Otherwise those of us in the adult certification training world will be labeled as "academic dinosaurs".

This is why I characterize my students as teachers. It is why some instructors run classes a bit loose and stress free. We appreciate the contributions we get when people relax and participate. The stories of everyones experience, including life experience enhances the course. Then we turn that around to keep improving every class; even if the printed courseware has not changed.

I think at some point though, it will have to be this flexible in terms of materials also. The turn around window is getting smaller and smaller.

Thursday, July 2, 2009

Student or Teacher?

I just had a spirited debate with Larry Greenblatt, and good friend of mine that founded "Internetwork Defense"(1). We have been back and forth on a few items in our disciplines on many occasions and mostly end up in a similar place that was arrived at from differing angles.

I go back to a statement I make often that the fun of the security vector of information technologies is that you get to be philisophical. It is your job to play with ideas. I teach ethical hacker classes and part of that is selling the idea that critical thinking is a responsibility. You are paid for providing this service. Be respectful and understand the scope of the situation, but challenge wisely. Do challenge the situation.

Instructors and students are interchangable. Larry sat my class and I sat his. Next week I will sit a class of ten student teachers.






Wednesday, July 1, 2009

Technical writing - "With style"

We are currently working on a book that will be published very soon. The process of writing this book has been extraordinarily illuminating. Or, just a lot of fun.

Along the way I wanted to be refreshed on some basic tips for effective penmenship. Knowing one of my editors has a Masters in English and that I can not explain the difference between a noun and a participle if my life hanged in the balance; I was intimidated at first.

All of us have to, and I mean this with criticality, be able to write technical documents and make a writen point effectively. In the information security world reports = dollars. There is a direct corrolation to the size of the payment recieved and quality of chosen words.

I have the benefit of a mentor that humbles me on this front and I pass this experience along to the LPT classes where writing is a requirement.

As I looked for some outside coaching for this book I recalled two resources I have used in the past to get a crach course in how to write good. Kurt Vonnegut in this classic essay about writing with style is something that everyone needs to take a look at. Particularly those in the technical industry.


There is also a tool I think is fun called "Bullfighter". It scoures your documents looking for wordiness, jargon and various forms of BS that complicate the communication. It is available here:




Friday, June 26, 2009

Don't underestimate a class that is "A mile wide, but an inch deep."

In a recent CEH class I taught, a group of students had an unusually broad background and motivation for taking on the course. One thing that impressed me a great deal was how well they seemed to understand this even before meeting each other. Everyone had healthy expectations, and were looking toward realistic outcomes, but at the same time I felt it was a challenge to make sure I could both fit the course for them and stay within the scope of the curriculum. We needed to pass the exam, not conduct an improvised 5 day Q and A session, though I was tempted to do exactly that.

This got me thinking a bit about something that recent trends I have noticed has brought to light about the way students and training programs evolve together.

I often say that "there are entry level info sec classes but info sec is not an entry level topic". I think the reality however is that as IT assignments branch out, security becomes an efficient solution for bridging and broadening a persons understanding of IT no matter what their background. Sometimes people take infosec classes not so directly for security information, but for the unusual point of view. It is very unsanitized, imperfect at times, philosophical, and demands critical thinking.

CEH paired with CISSP is in a sense, a way to be exposed to an encyclopedic knowledge of all of the basics, from techie to management, from data to packets, and from apps to hardware. Being a mile wide is perhaps harder in some ways than being a mile deep. These classes are incredibly challenging for precisely this reason. Every student will find one chapter, module or domain that they think has been simplified into silliness. They will also encounter a portion of the class that is so unfamiliar it may seem the instructor has begun to speak a martian language. Yet to those who work in that area, it is as simple silly as the other aspect of the course was.

The first step is figuring out the difference, the second step is reconnecting the dots.

As any technology advances a compression phenomenon occurs. What once took a career to learn and master eventually becomes required basics just to attend a 5 day bootcamp. "Assumed knowledge" at this point to even enter the discussion of information security is more than many people even care to know in what would be gained in a lifetime of experience in IT.

The goals of technical training therefore needs to adapt to this. Bootcamps such as what we offer are designed to demonstrate key ideas that help the disparate parts of day to day experiences come together. Its like finding the one piece of a jigsaw puzzle that helps connect too other vary large assemblies. Sometimes however, a student grasps this catalyst, but has to wait until some time down the road to realize why it is important.

One thing we can absolutely guarantee is that all of the effort placed toward this goal will become useful at some point. No knowledge in info sec is wasted, no matter how unrelated it might seem to a current assignment.

Monday, June 22, 2009

Putting off the exam (reconsidered).

In a recent ECSA/LPT class a concerned student wondered if he really had to take the exam that week and asked for advice. My response was short "If you take the exam in two weeks instead, what will change?"

There was a still pause for a moment. He thought about work, schedule, distractions, other projects. He knew he took the bootcamp specifically to step away from those things for 5 grueling days to knock out this challenge. Then he said "Nothing will change, I see that I should just give it a shot on Friday then"

He realized it was unlikely that he would make time to study, and that once this training was over, the endgame was to be able to move on; not let it linger around for weeks and months. This is something everyone should consider before they attend a bootcamp. It is why it is so important to prepare your schedule to minimize interruptions and get pre-study materials to read up on topics before coming to class. You want to think about the follow through, the idea that the training will start a new process for your career, it is not the end of one.

When the week is over it is important to be able to move on.

Saturday, June 6, 2009

The mobile workforce and hacking (cont...)

Udpate post;

On 6/03 I talked about getting a netbook and dual booting both Windows and Ubuntu. I was willing to swap out drives; being in the habit of days of old that meant having the drive bay with the plastic tray thing and the stack of 5.25 drives.

Nowadays that has been replaced with 8g SD cards that can be purchased for a few dollars a piece (I cannot wait for the day when a tube of them costs $4.99) The old is forever new and we are still running OSs from floppies (in essense, USB stick and SD Cards are just higher capacity floppies).

I knew this netbook thing could be done for some time, it is important to say that this technique isn't "news". Maybe it was a professional obligation to buy a netbook just for this reason. My budget manager wasn't buying as she knows I am on a 12 step for gadget problems. Students kept bringing them in with sh!t eating grins on their faces.

In less than 10 minutes I created two OS swap outs using UNetbootin(1). The major problems arose in getting certain OSs to like the Atom processor and the screen resolution of the netbook display. These are all things that will get worked out.

For the Ubuntu task I used "EasyPeasy"(2) which is optimised for netbooks and worked perfectly on the first try. It auto mounted the partitions on the drive with my netbook allowing access to all of the data. Essentially the only thing that would make this a better solution is if the netbook had two SD card slots so I wouldn't have to give up the one. (I like not having a USB key dangling off the side or having yet something else to carry around and keep track of. Mobile form factors should be as all inclusive as possible or they aren't mobile).

I digress; so what does all of this have to do with InfoSec? If you are asking that question keep reading this blog. This topic will be brought up alot mixed in with the other topics we have planned.

Some netbooks have wifi chipsets that support sniffing(3), but not yet packet injection it seems. Operating systems and tools can easily be stored on mini sdcardsg (the size of your fingernail) and carried around ready to boot on the right hardware. Google "wave" will likely change mobile collaboration forever(4). Skype and so on ..... what I am asking is that you take a moment connect the dots and imagine the possible scenarios..

The only thing left is cheap Internet everywhere all the time, and we all know that is coming one way or the other. Thats enoough for now, I need to change a diaper (not mine), but stay tuned for updates.


(1) http://en.wikipedia.org/wiki/UNetbootin
(2) http://www.geteasypeasy.com/index.php?menu=download
(3) http://clipmarks.com/clipmark/AB945FA1-6A1F-48CD-A12A-B962CB229572/
http://forum.eeeuser.com/viewtopic.php?id=13673
(4) http://wave.google.com/