Showing posts sorted by relevance for query edtech fail. Sort by date Show all posts
Showing posts sorted by relevance for query edtech fail. Sort by date Show all posts

Sunday, 29 June 2014

Naked Lies


When you're using digital tools to assist your writing process, you're not only getting grammar and spelling support, but you're also performing your writing process in a fishbowl.  It's amazing how many digital natives seem to be unaware of this.  When you create online you're creating in a radically transparent environment.  If you're going to do something less than honest, it'll show.

I had a series of plagiarism issues teaching elearning this semester.  In one case a student handed in the same thing copied off the internet in two different assignments.  Worst. Plagiarizer.  Ever.


Turnitin lights up copied text and links you to where
the material came from online, very handy.
The Ontario elearning system has Turnitin.com built into it, so catching the plagiarism was a matter of opening the report, screen capturing it and sending it on to the student.  When it's that easy, it's not even particularly time consuming to call a student on copied text.  I often have students try to beat turnitin in order to show them how it works.  They leave with an appreciation of how easy it is for the teacher to wield and how hard it is for a student to beat.  It's easier to just write it yourself.

When I catch a plagiarizer I usually just show them the report without explanation and then see what they say.  I've gotten some funny responses to this, like the time the rural Ontario farm kid stole an essay from an honours student from India.  When I asked him what a 'chap' was, he said it, "was a kind of stick."  That's some quality plagiarism.  To most English teachers it's patently obvious when plagiarism occurs.  When a kid who appears to have a vocabulary mainly consisting of swear words suddenly starts dropping four syllable terms in picture perfect compound sentences, alarms go off.

Since we've gone to Google-docs it gets even more transparent.  A colleague told me about a student who handed in a suddenly perfect French paper.  She opened up the editing history and say that the boyfriend had logged in (under his own account) and edited the entire thing.  When called on it the student said she'd had to use his account because she couldn't get into her's... but she'd shared the file from hers.  It's hard to make lies stick when it's all out there.

Until students realize just how transparent working online is, they are labouring under a huge misconception.  That misunderstanding is based on the false sense of anonymity they feel when they are online.  Because they feel that eyes are off them, they are more likely to push moral boundaries, but they don't understand that digital processes are documenting their every move.

Here is yet another example of how 'digital natives' fail to grasp the basic concepts that drive digital processes.  We shouldn't be smitten with familiarity, we should be advocating for understanding... at least if we're still trying to educate people (which may not be the case).  From that neo-lib point of view, the digital native is one of those magical assumptions that integrate digital technology into the very biology of our students, it becomes a fundamental truth we base learning on, but it's just a convenient assumption that frees us from taking on the responsibility of understanding it ourselves.

Someone shared The Brave New World of 21st Century Teaching the other day in our teacher Facebook group.  I responded:

The subtext of 21st Century skills is the de-branding of educators as teachers and the re-branding of educators as facilitators. Edtech could be used to enhance pedagogy and individualize learning, instead it will be used to Walmart education into a process overseen by centralized administration and bereft of teachers, and it has the convenience of being much more 'efficient' (read: cheaper) than our current system.  It's also more controlable than trying to manage a bunch of professionals bent on something as airy fairy as pedagogy.

Technology doesn't appear to be moving the needle on student success, yet we're pushing into 21st century skills as though they will resolve all ills.  I'm a strong advocate of mastering technology, but integrating it in ignorance is a disaster in the making.  It caters to exactly the kind of blind faith in technocratic neo liberalism that is infecting everything else.  When we adopt machines in ignorance we let their limitations become our limitations.  Those machines are all created and owned by very politically motivated interests.


For someone who has always been involved in the advancement of educational technology, it's heart-breaking to see it implemented as a means of diminishing the teaching profession and placing human learning in the context of a software environment.  I'd always thought pedagogy would drive educational adoption of technology, but as in the rest of society, there is something much more sinister at work in digitization.

The constant downward pressure on freedom of information and the push to striate and own data (including the data users willingly give) points toward a dystopian and authoritarian end to our digital frontier.  The very processes that monitor plagiarism above can as easily be used to invade privacy, grossly simplify learning and itemize people for political reasons, and they are.

I'm glad it's summer.  Time to put this down for a while before we walk straight into another round of manufactured austerity and digital marketing.  I wonder how much longer education can withstand these social forces.

Monday, 22 June 2015

The New Efficiency

This African proverb passed me on the
internet last week, and left me thinking.
Last semester I had an energetic grade 9 suddenly stop his interaction with the internet and wonder out loud (and it was asked in all seriousness):  "why is it in video games and movies old people are so cool, with hidden knowledge and special powers, but in real life they just suck?"

He received an avalanche of 'how could you say that?!', but then everyone went on to say how wonderful their grandparents were.  Everyone loves their grandparents, but no one was willing to defend age and by extension experience in and of itself.

When this African proverb popped up I immediately felt the pinch of that class discussion (yes, I know, we were talking about the value of age and experience in a class where I was supposed to be teaching computer engineering, I guess my kids won't be ready for whatever standardized test they invent for it).

What role does age and experience have in the information age?  This proverb also refers to libraries, which have been facing their own test of relevance thanks to the Googliable nature of information.

Information technology has made personal knowledge irrelevant.  The life experiences of human beings have become meaningless, replaced by internet searches.  Why would you bother to ask your grandfather how to change the brakes on your car when you can just Google it?  Once a useful source of information, the elders around you are now objects of affection and little more, they serve no function.  You can get the information you need without any of the static (anecdotal stories that accompany the information).  This sanitized, machine driven version of knowledge has many benefits.

You can reduce complex human knowledge (for example, the development of literacy) into simplistic, easy to quantify standards and then make sweeping suppositions about the results.  Banal opinion based on internet 'fact' is the new intelligence.  Like any opinion you hear online, carefully crafted grading schemes end up becoming the truth, which fits nicely into the antiseptic version of knowledge the information age peddles.

Another benefit is the downward social pressure on human communities.  When you plug people into a centralized source of information you wean them from the social necessities of family, community and even nation.  When no one needs anyone else (but they do need an ISP), you have removed all the social static and laid the groundwork for a kind of hypercapitalism that will make past look like the middle ages!


When we try and argue for meaningful learning (in anything other than a poster), we are met with educational administration making sad faces and saying it's not viable.  The reasonable provision of caps on class sizes is just such an attempt, which is why the meme on the right goes straight to the heart of this issue.

Tangible data that grossly oversimplify human endeavour are how we roll nowadays.  As the poster states, class caps mean nothing, but fail to hand out a piece of paper with grades so abstract that they are meaningless along with computer generated comments, and 'everyone loses their minds!'

There is some push back against the dimensionless facts that drive the information age.  You find it in the physical world in grass roots movements like slow food or maker spaces
where you see individuals trying to wrest control of production from the hands of remote systems.  In these places the idea of human interaction is key to the process of learning.  They are trying to build communities in an arid digital landscape that is bereft complex human interaction... unless they are under a corporate banner; communities designed for marketing purposes.  What would be the economic sense in creating a community solely for the benefit its members?

Ironically, human interaction is less and less a factor in human education.  The push to integrate technology into pedagogy without considering its implications has infected education systems with the same efficiency that we now enjoy everywhere else.  We can hardly expect the personally demeaned yet highly efficient funployees in the private sector to demand anything other than consistent menial labour, it's what they do.  Developing complex personal relationships in order to effectively mentor and teach aren't very efficient/economically viable.  They are certainly discouraged in the brave new world of 21st Century education where teachers are now facilitators, reduced to getting out of the way of learning and making sure the #edtech is working.

One of my students from many years ago is now out in the world.  She was sitting in a restaurant a few weeks ago watching two employees, a teenage girl and an older woman on their break.  The older woman kept trying to start a conversation.  The teen ignored her, buried in her phone until she finally snapped, 'What? What do you want?"  She was incensed that this woman had interrupted her texting time.  She was probably in withdrawal because they don't let her have the phone while working.  I can bet which one of those two employees gets better performance reviews, though she sounds like an ass.

Maybe human experience is meaningless nowadays.  Maybe old people are useless and libraries are a waste of space (great idea: replace every one in school with franchise coffee shops to balance the books!).  Maybe we don't need each other to learn any more, it's certainly not as efficient.


LINKS

Watch the new efficiency infect the UK's Labour Party
"In 2015 we are living in a cold, cruel, and desolate country in which benefit sanctions, foodbanks, poverty wages, and ignorance reign, governed by a clutch of rich, privately educated sociopaths whose conception of society has been ripped straight from the pages of a dystopian novel."

Thursday, 13 April 2023

How To DIY Your Way To Digital Fluency

 "We've all become used to thinking of Gen Z as the first truly “digital native” generation. They were born when the internet was available to everyone and don’t remember a time when it wasn’t normal to carry a smartphone wherever they go and document their lives on TikTok and Instagram. Unfortunately, it turns out that this form of digital native might not translate to being able to work with the tools and technologies that are expected to shape the 21st century."

- Is Our Digital Future At Risk Because Of The Gen Z Skills Gap?

The digital skills gap is an ongoing concern, but in building a successful digital skilling program over the past two decades I've trial and errored my way to an efficient process for getting students from thinking they have digital fluency to actually having it. Here's how:


Step 1: Start Where People Are Most Familiar (I.T.!)

Information Technology (or I.T.) is where most people have regular contact with digital technology, though many people don't know what I.T. stands for. The devices we live our lives on in 2023 all depend on digital infrastructure and incredible engineering to do what they do. To unpack all that and make people aware of how this technology works, you build it!

RCT Ontario is the local branch of the Computers For Schools national program that takes off-lease technology and gives it to schools and others in need. They are all you need to get hands on with digital technology. I've found that building a desktop computer from scratch is a great way to get past the bluster of self-professed computer experts (aka: students who have been told they are digital natives) and let them show what they actually know.

All digital technology follows the same basic foundation of hardware, firmware, operating system, software. The desktop is a modular, relatively easy to assemble example of this architecture, but everything from laptops to smartphones to ATMs to Teslas uses the same stuff in the same way.

By building their own PCs from scratch, students who have some experience fill in gaps and students with no tech background find that they have a clear understanding based on hands-on familiarity. This also does a lot to clear away misconceptions and myths around digital tech (like that digital native one).

Another good resource is PC Part Picker that lets students theorize their perfect PC. Once they have an understanding of the hardware and how it goes together, suddenly customization becomes a possibility and the generic tech that most people live with isn't enough. Many of my grade 9s have built their own PC at home by the time I see them again in grade 10.

Cisco's I.T. Essentials course is available for free on Netacademy and offers media rich, current online learning support for this hands on I.T. exploration. It also makes students aware of the world of industry certifications out there in information technology. Students starting in I.T. Essentials can work towards their CompTIA A+ computer technician certification which is the first step towards moving in many directions in the industry.

Once everyone has their hardware worked out, it's time to get into operating systems. Like I.T. hardware, people have experience with OSes but seldom get under the hood. A good way to expand familiarity and get students interested in OS options is to have them build a multi-boot system on their DIYed PCs.

Our record OS stacks in grade 9 had many operating systems ranging from various versions of Windows (XP, 7, 8, 10, server, etc) along with multiple Linux distributions (an OS most students haven't touched but one that runs behind a lot of the tech we use) all bootable off one desktop. Familiarity with many different operating systems is a powerful step forward from the 'we just use Chromebooks' approach many schools have adopted (Chrome OS is actually a version of Linux).

We can usually do the PC builds and OS stacks in a week of classes (about 6 hours of instructional time). In an intensive course you could get everyone hands-on and familiar with the architecture of computers and operating systems in a day (6-7 hours).


Step 2: Use Your DIY Tech To Scale Down and Explore Electronics & Coding With Arduino


The Arduino micro-controller is a simple digital device that does a great job of showing the basics of how computer code performs with hardware. It also introduces students to circuits and the electronics fundamentals that drive all digital technology.

Arduino is open-source (like Linux) and doesn't usually come in a pre-fabricated activity/kit from your friendly neighborhood edtech for-profit with pre-set lessons and learning outcomes (a sure way to fail at developing real digital fluency).

With relatively small outlay you can collect together Arduino microcontrollers and basic electronics like LEDs and resistors and facilitate a hands-on understanding of the electronics that make the modern world work. Kits with many parts cost less than $80 and if you're crafty, far less). We always used Abra Electronics in Montreal to keep it Canadian.

There are piles of Arduino projects that students can try, but we always worked through the ARDX Arduino circuits to get everyone familiar with how breadboards and circuits work first. The Arduino plugs into the student-built desktops with a USB cable and then runs software that lets students explore both coding and circuit building in a very real way.

This is another area where the bluster gets cleared away by demonstrated mastery. If a student tells me they already know all about electronics, I tell them that they only have to do circuit number five and then can go right into designing their own project. A few can show what they claim to know, but many struggle and then I gently redirect them to doing the circuits as a 'refresher'. By the end of the Arduino unit everyone has tactile knowledge of the basics in circuit building and coding.

Introducing Arduino and running through the basic circuits typically takes about a week of high school classes, so it would be another day (6-7 hours) if students were in focused training to quickly develop these real digital fluencies.

Step 3: Use Your DIY Tech to Scale Up And Explore Connectivity & Networking

To get students the Arduino software and access to circuits on their desktops, you would have to connect them to the internet. After Arduino, students are more comfortable with their PCs and how they work, so it's time to go upstream and tackle networking!

This is another intimate aspect of people's lives that is often misunderstood. By having students build local networks with each other's machines and pass data across, they again benefit from direct, tactile, experiential learning.

We then connect these local networks together into a class-wide network and watch data travel across it in real time, but the favourite part is stress testing the network to see how much data it can handle. Tools like LOIC (low orbit ion canon!) can be used to DDOS machines off the network by overloading them with data. At this point complex, multi-disciplinary specialities in digital technologies (like cybersecurity) start to glimmer in the distance. Anyone trying to teach cyber with none of these foundational understandings in place is going to have trouble.

Another good stress test is to set up an older LAN based game which requires inputting IP addresses and other details. It's not often students have playing a multi-player game as a classroom learning target. You can guess how popular that is.

Tools wise, Cisco offers their Packet Tracer network simulator for free (you can become a Cisco Network Academy at no cost, which makes dozens of introductory ICT, networking and coding courses available). Packet Tracer lets students build complex theoretical networks and then push data through them to see if and how they work.

The networking unit typically takes another week of high school classes, so could be managed in a single 6-7 hour day. By the end of it students are experimenting with their DIY desktops on their DIY networks. The learning doesn't get any more genuine than this and the result is students who are tangibly developing real digital fluency.


Step 4: Use Your DIY Tech to Explore Data Management and Programming 

In the high school junior grades we focus on Javascript and HTML (both common web-focused coding languages). HTML works well as it allows students to quickly understand how the webpages they spend so much time on are displayed. Javascript is helpful because it allows webpages to run executable scripts and hints at the complexity modern webpages are capable of. LIke the other steps, the point here is to get behind the curtain and begin to make students aware of how the technology they are codependent on works.

Students can create and share simple HTML webpages on their network giving them a hands-on introduction to internet architecture. W3 Schools does a great intro to HTML and Javascript (and CSS and HTML5). The point isn't to create a web developer in a day, but to (once again) develop tactile familiarity with digital technologies that have always been hidden.

Coding takes time to develop, but an introduction to web design typically takes about a week to get students to the point where they know enough syntax to build a simple webpage. What's nice about HTML is that it's a tight feedback loop; you put in a command and immediately see the result.

With webpages rattling around your DIY network, you can talk about ports and how they work, and even get into online databases which tears the cover off one of the biggest problems we face: cloud based personal data. Each layer of this learning builds on the previous ones creating a rich ecosystem of interrelated technologies. Getting newly digitally fluent students to actually understand how the online world we all spend our time in works is where you want people if they want to take a run at cybersecurity with anything like the necessary context.


When you've got digital fluency you can chase down
NASA complex projects! Here CyberTitans Vlad &
Wyatt (also a 2x Skills Ontario medalist in IT &
Networking) are building a Beowulf supercomputer
...out of ewaste!
Step 5: PLAY!

I'd run this in adult up-skilling as an intensive week of digital fluency training. The final day would be a student directed mini-project. For those who dug PC building, they can build something to a specific purpose. For those who dug the Arduino and electronics, opportunities to build original circuits and code await, and for those intrepid few who enjoyed networking and data management and programming, they can chase down more complex connectivity or web development.

When I did my A+ training way back during Y2K it was an intensive week which gave me enough context to chase down my certification in a few months of practice and study. I've had a few students manage to get A+ certified as a computer technician while still in high school, but it's a challenge due to the breadth of material. I.T. techs need to be familiar with older tech and emerging tech as well as what's current. That experience takes time, which is why my seniors do in-school I.T. support. Being dropped into real world technology complications helps them hone the skills they need to be effective technicians. The purpose of this as an upskilling course would be to create contextual understandings that are simply missing for the vast majority when it comes to 'tech'.


Why Do this?


This level of hands-on technical familiarity would revolutionize elearning and make it a viable education tool. Digitally fluent staff and students would make us lock-down resilient and capable of keeping learning alive in difficult circumstances instead of giving up and leaving students behind, and it would only take 35-40 instructional hours. Many adults use digital technology habitually and in profound ignorance. An intensive week of hands on learning would end that approach and give everyone the context they need to move with purpose in our digitized society.

When I see Ontario dedicating time to mandatory historical curriculum I shake my head. This kind of digital fluency would enable pretty much every career pathway and give students essential 21st Century life skills (you don't want digitally illiterate people participating in a technology enabled democracy). Instead we cling to mandatory curriculum designed in the age before our digital revolution. We could be producing digitally competent students that close the digital skills gap, and it's not like it's expensive or time consuming. All that it takes to solve this problem is to solve this problem.

For those tackling adult re-skilling, I see a lot of cybersecurity 'bootcamps' that assume much of this digital fluency in their candidates (like K-12 does) and then wonder why their dropout rates are so high. Cybersecurity is a multi-disciplinary specialization within ICT and you can't get to it directly any more than you can expect an illiterate adult to tackle Shakespeare. You need foundational skills and contextual understandings before you take on that kind of complexity. It isn't an impossible ask, but it is one that needs to start from where people are at, which is further back than we think they are.

How to Build Digital Fluency Before Tackling Cybersecurity


Follow Up Links

The Digital Divide is Deep and Wide (2017): https://temkblog.blogspot.com/2017/12/the-digital-divide-is-deep-and-wide.html

How to Pivot Ontario Education to Prepare for The Next Wave (we didn't): https://temkblog.blogspot.com/2020/05/how-to-pivot-ontario-education-to.html

Exceptional Times: Using a Pandemic to Close the Digital Divide (any day now): https://temkblog.blogspot.com/2020/03/exceptional-times.html

Why Canadian Education is so Reluctant to Move on Digital Literacy (hard to teach it when you don't have it either): https://temkblog.blogspot.com/2023/02/why-canadian-education-is-so-reluctant.html

Friday, 1 September 2017

Management Expertise

WIRED: https://www.wired.com/2017/05/can-denver-become-like-silicon-valley/

This is a WIRED story about tech software startups in the Denver area.  In it a man who has an idea about buying insurance online has become a 'TECH CEO' even though he has no idea of what it is he is actually building.  With no background in technology hardware or software development, this guy is trying to launch a tech-startup with an idea and little else.

The quotes below are from the article.  The bolding is mine...

ROSS DIEDRICH HAD gone pale and raw-boned. The CEO of a year-old startup in Denver, he’d stay at his office until the middle of the night, go home and sleep for about five hours, then chug a spinach smoothie and start again. He was just 27 years old, but he felt wrung out.

He still didn’t have even a basic version of the software that he could demo—an “MVP” in coder parlance, for minimum viable product. Chris was still holding down his full-time job; he didn’t want to quit until Covered had some funding in hand. The lead development engineer that Ross had brought on, a big, quiet nerd named Jonathan Baughn, was juggling a bunch of projects and wasn’t as available as Ross had expected. But Ross didn’t want to put too much pressure on Baughn. As a contractor, he was within his rights to work for others. A junior software engineer Baughn had brought to the project, Reyna DeLogé, tried to manage on her own, but they kept blowing past their self-imposed deadlines.

He navigated to the demo site, typed in his password, and tapped on the mousepad. Then he tapped again. Nothing happened. The demo was broken. “What the heck is going on here?” he murmured.


I'd feel wrung out too if I was building something that I had no idea of how it works and kept blowing through deadlines.  Demoing it and having it fail to launch and then having no idea why would be exhausting.

I would posit that you need at least a passing acquaintance with the technology you're pedalling before you try to claim ownership over it.  An automotive executive who has no idea what is under the hood would be a poor manager.  A head chef who doesn't know how to cook would be a poor manager.  A general who has never stepped foot on a battlefield would be a poor general.  A principal who was a disaster in the classroom would be a poor principal.

The film Steve Jobs does a good job of examining the contradiction of a manager who has no engineering skill:


Where Jobs diverges from the disaster described in the WIRED article above is that he surrounds himself with the most knowledgeable engineers - an orchestra of expertise, and then focuses on having them produce their best possible work.  An argument could be made for a manager like this, but not at the expense of engineering, never at the expense of engineering.

Your ideal manager must have some technical background if they are to work with skilled labour.  In the clip above Woz tells Jobs that he can't do anything, which isn't really true; they met and bonded over their shared knowledge of electronics.  Jobs may not have been able to engineer the devices he helped create, but he was very aware of the technology and how it worked.  With that knowledge he was able to gather experts because he could appreciate their expertise.

A manager who is only an expert in management is best when not managing people who perform skilled work, whether that be engineering or teaching or any other complex, skills based process.  Matt Crawford does a great job of examining this in The World Beyond Your Head.  In the book Crawford distinguishes between the skilled labourer who modifies or 'jigs' their environment to better perform their profession and the unskilled script follower who does what they're told in a prefabricated production line.  Being free to manipulate the physical environment in order to perform your expertise is a foundation stone of professionalism in Crawford's mind.  A lot of the downward pressure you see on worker valuation in education and employment in general is because of the Taylorism of workplaces into script following routines.  Making the end goal of education a result in a standardized test plays to this thinking perfectly.  In those prefabricated and abstracted workplaces skill isn't a requirement, obedience is.

An effective manager of skilled labour acknowledges and cultivates expertise in their people.  You can't do that without having some kind of handle on that skillset.  Being oblivious to how reality works and managing complex, skilled labourers who work in that demanding environment like they are a production line is the single greatest point of failure in management, unless your goal is to chase out skilled labour and turn your organization into a mechanical process where the people in it are little more that scripted robots.  There are financial arguments for that, but they aren't very humane.  We might not perform as many repetitive job tasks in the future, but if we remove human expertise from the workplace it will damage us as a species, and any financial gain from it would be short lived.

Related Readings:

Shopclass as Soulcraft: IT Idiocy, Management Speak & Skills Abstraction
Taylorism in Edtech
Implications of a Situated Intelligence in Education
A Thin and Fragile Pretense
How We've Situated Ourselves



Wednesday, 27 November 2024

Cyber Resilience: the evolution of cybersecurity beyond the technical



Navigating a Generational Digital Skills Crisis


The World Economic Forum's Centre for Cybersecurity recently (Nov '24) released a white paper called Unpacking Cyber Resilience. The goal of this paper is to redefine digital information security (currently called 'cybersecurity') beyond the technical box it currently sits in.

Digital transformation has forced unprecedented change in all aspects of our lives, yet digital literacy has remained at best an afterthought in education even as education systems across the world embrace mandatory eLearning and place students in online learning environments from the earliest grades. Our failure to recognize digital fluency as a foundational skillset has resulted in generational global digital skills crisis demonstrating shocking digital habits that are the main cause of an epidemic of cybersecurity breaches. Hiding cyber in a technical bubble is probably both a reaction and the result of this mess.

WEF's opening remarks in the Unpacking Cyber Resilience white paper describe an expansion of cyber awareness using business language that many educators will use to say, 'that's not our job!' (i.e.: training students for workplace readiness), but this digital illiteracy also damages our democracies by destroying our trust in institutions, creating disinformation echo-chambers that erode public discourse and also preventing us from accessing trustworthy news sources. Surely some of that is the job of public education?

"The digital transformation continuously reshapes and evolves businesses and governments. The primary goals and objectives of organizations are often supported by business processes that are critically reliant on digital technology, commonly without any analogue  alternatives. While primary goals and objectives will differ between organizations, they will always  include the protection of critical service delivery, stakeholder confidence and the principle assets  that underpin value and position in the market. Achieving true cyber resilience is fundamentally a leadership issue, and is paramount to retaining shareholder value."

- Executive Summary, Unpacking Cyber Resilience

Those 'business processes' underlie all aspects of modern life, including those in education. School boards call their operational network domains 'corporate' because it's lifted from the same digital systems that support business and government. Educational operations aren't digitally distinct from those in the public and private sectors, they're the same technologies but with higher security needs because they collect the data of minors (and their families) on a massive scale. Putting employees and students onto these systems without teaching them fundamental digital literacy is akin to putting them in a car and hoping they'll drive it without having an accident.

WEF's efforts to reframe cybersecurity are important because there aren't many aspects of our lives left that are independent from networked information technology. This dependence is absolute because the analogue processes that proceeded digitization have been jettisoned with a promise of cost savings. We live in a world run on ICT where almost no one understands ICT.

Cybersecurity is a particularly difficult nut to crack because it is an interdisciplinary field of study that exists within a larger framework of digital expertise that very few people possess. Cyber also suffers from being the edge of digital where zero days and emerging technologies can have devastating impact. Instead of building stable systems that then change slowly over time, cyber stares into the edge case abyss where you not only need deep digital fluency but also a willingness to step into the unknown.

If we address digital skills at all in education it tends to be a rote coding plug-and-play edtech solution. This one and done approach fails to recognize the complexity of digital literacy.


The Evolution of Digital Information Security


The idea that 'cybersecurity' was the final conception of this rapidly evolving field demonstrates a lack of understanding both in how new it is and how quickly its scope is changing. For a long time the cool kids on the West Coast hated the term cyber and created a lot of political tension in a field that was barely conceptualized. You know you're in trouble when the people doing the thing can't even agree on what to call it. If you take a step back and look at how things have evolved over the past four decades you begin to see the broad strokes of digital information security:

For many even what to call cybersecurity was a sticking point. The good news is that if you don't like it now, it's already moving on. From WEF's Unpacking Cyber Resilience.

One of my favourite early graphics pushing back against the framing of cybersecurity as a purely technical field of study was this one:


Not because it's complete, but because it reframes cybersecurity in a multi-dimensional manner. Through my coaching of student teams in cybersecurity I've found that a mix of talents is much more effective than a group of identical 'head-in-the-machine' types deep diving the technical. That skillset in cybersecurity could be parallelled by a lawyer or surgeon who is doing the point work but is surrounded by specialists with varying skillsets that allow the technical resolution of problems to happen. Can you imagine someone saying that the only people in the medical professions are surgeons, or the only legal professionals are lawyers? These more mature disciplines have a wider understanding of what's necessary to do the work. Clinging to this lone haxor fixation has been one of the mechanisms used to keep cyber a male dominated profession for far too long.

You need team members with organization and communication skills or the technical discoveries get fumbled between detection and response. You also need researchers and admin who understand what everyone is doing so that they can provide resources where needed. Those skillsets are essential to a cybersecurity operation, even a predominantly technical one, but the world of digital information security has expanded far beyond even that scope.

I wrote about this a year ago in a Cybersecurity Secret Sauce post. At that point I was still arguing for better technical training in cyber, but that's the tip of a digital skills iceberg that leans on abilities often ignored in STEM education. The creativity and self-direction demanded by the edge-case nature of cybersecurity is more often found in the arts. My strongest cybersecurity teams included a mix of students from a variety of disciplines, and the very best were also wildly neuro-diverse. Reframing the field to cyber resilience opens the door to those alternative and much needed talents.

Considerations of inclusion are often framed as charitable, but in this case diversity was a genuine performance enhancer, especially once I could convince non-technical students that they had a place on a national championship bound cybersecurity team. STEM education does a great job of selecting out creative thinkers early on. Hopefully reframing to cyber resilience ends this gatekeeping.


Cyber Resilience Reframing Digital Information Security


Multidisciplinary collaboration is a force multiplier well beyond blue teams doing competitive defensive work in capture the flag exercises. I should add here that no one should avoid a hackathon or cyber-defence competition because they are afraid they don't have the hands-on technical skills to do the hacking for a couple of reasons:

CyberTitan Top Defenders in 2021 had
diverse 
and complementary skillsets.
1) The detective process for determining  damage from a cyberattack is remarkably intuitive and the best way to learn it is to watch someone who has developed this intuition display it.

2) If you have half a dozen haxors all digging into a hacked system and attempting repairs at the same time you have chaos, so it's typical to have one operator in the system while others support them. Again, think of the operator as a surgeon with a team of supporting talents around them and you begin to see how even technical cyber needs diversity.

Even in technical cybersecurity team based/complimentary skillsets are the norm. Attempting to solve the global cybersecurity skills gap by minting as many hands on cyber-operators as you can misunderstands the needs of the field, especially with the onset of AI automating basic tasks.

Cyber resilience recognizes the diversity of expertise needed to create functional digital information security. Another example of this expansion is in international collaboration. You can't work across languages and cultures without being eye to eye on the technical aspects. The work I've done this fall around cyber diplomacy both in DC and the DR have shed light on this emerging field and the importance of us understanding the same terminology. You'd think this is how things are done but training is often rolled out by insular regional interests who (incredibly) often lack an understanding of the subject and don't give much thought to national let alone international collaboration. You can't work together defending against cyber attacks when you don't share common understandings. The work Global Affairs Canada has done in providing internationally recognized industry certifications for developing countries is a great example of this in action.

Hundreds of people from dozens of countries all working
together on cyber resiliency at the GFCE annual meeting
in Washington DC in September, 2024 (I'm on the left).
From talking to the newly minted director of cyber at GAC to presenting on emerging technology disruptions in cyber internationally, I'm more aware than ever of the challenges in creating global connections encouraging cyber resilience. Unless we align our terminology and technical awareness we cannot communicate and collaborate effectively. In our one sided world of digital defence where they only have to get it right once but we have to get it right every time, this is a recipe for disaster. Without collaboration and cooperation there is no way organizations can defend against the asymmetrical nature of cyber attacks, the largest of which have the funding of nation states behind them. 


Hope For The Future


Locally, I hope that reframing cybersecurity to cyber resilience means more leaders begin taking it more seriously, especially in education. But even cyber resilience remains problematic because it is hidden inside a larger digital literacy crisis that has grown to such a degree that many in education ignore it rather than recognize the cross curricular damage it is doing, not to mention the societal damage it is doing to our democracies.

Nationally, I hope that cyber resilience creates more diverse pathways into the field. I would love to see the absurdly privileged 'comp-sci degree' base expectations disappear (this is the equivalent of saying everyone who works in the field of law has to be a lawyer). Cyber resilience isn't for specialists, it's for everyone and I hope this reframing encourages more diverse skillsets to engage with it.

Internationally, cyber resilience is where emerging fields like cyber diplomacy and multi-country partnerships grow. If we want the benefits of digital transformation to be available to everyone while relaxing the grip of surveillance capitalists and ensuring our democracies are functional, critically looking at how we compartmentalize digital literacy and opening them up to reinterpretation is essential. Digital technology is only accelerating and clinging to old frameworks makes no sense.




NOTES

The idea that we can resolve a lack of cyber skills when they hide within a much larger digital illiteracy crisis has caused a lot of frustration in cyber training. Teaching information security awareness when users lack basic digital skills is akin to attempting to teach Shakespeare to people who can't read.

Rather than base your cyber stance on this impossible situation and watching training fail to stop the vast numbers of breaches digital ignorance causes, reframing cyber resilience through a human risk management lens reveals a more effective tactic. If people are the weakest link (and they are), don't expect their illiteracy to be an easy fix. Leveraging a wider human risk management approach lets you ensure safety regardless of how digitally clueless your users are.


"In 2024, the idea of human risk management shifted from concept to reality as frustrated CISOs looked for solutions beyond security awareness and training to make real change."


The EU isn't hanging around:  The Cyber Resilience Act

Thursday, 10 October 2019

Cybersecurity and the AI Arms Race

We had a very productive field trip to the University of Waterloo for their Cybersecurity and Privacy Conference last week. From a teacher point of view, I had to do a mad dance trying to work out how to be absent from the classroom since our school needs days got cut and suddenly any enrichment I'm looking for seemingly isn't possible.  I managed to find some board support from our Specialist High Skills Major program and pathways and was able not only arrange getting thirty students and two teachers out to this event, but also to do it without touching the school's diminished cache of teacher out of the classroom days.

We arrived at the conference after the opening keynote had started.  The only tables were the ones up front (adults are the same as students when it comes to where you sit in a room).  Sarah Tatsis, the VP, Advanced Technology Development Labs at BlackBerry, kindly stopped things and got the students seated.  The students were nervous about being there, but the academic and industry professionals were nothing but approachable and interested in their presence.


What followed was an insightful keynote into Blackberry's work in developing secure systems in an industry famous for fail fast and early.  Companies that take a more measured approach to digital technology can sometimes seem out of step with the rock-star Silicon Valley crowd, but after a day of listening to software engineers from various companies lamenting 'some companies' (no one said the G-word), who tend to throw unfinished software out and then iterate (and consider that a virtue), the hard work of securing a sustainable digital ecosystem seems further and further out of reach.  The frustration in the air was palpable and many expressed a wish for more stringent engineering in online applications.

From Sarah Tatsis I learned about Cylance, Blackberry's AI driven cybersecurity system.  This reminded me of an article I read in WIRED recently about Mike Beck, a (very) experienced cybersec analyst who has been working on a system called Darktrace, that uses artificial intelligence to mimic his skills and experience as a cybersecurity analyst in tracking down incursions.

 I spent a good chunk of this past summer becoming the first high school teacher in Canada qualified to teach Cisco's CCNA Cyber Operations course which, as you can gather from the name, is focused on the operational nature of cybersecurity.  After spending that time learning about the cyber-threatscape, I was more and more conscious of how attackers have automated the attack process.  Did you know criminals with little or no skill or experience can buy an exploit kit that gives them a software dashboard?  From that easy to use dashboard, complex attacks on networks are a button push away.

So, bad actors can perform automated attacks on networks with little or no visibility, or experience.  On the other side of the fence you've got people in a SOC (so much of this is the acronyms - that's a Security Operations Centre), picking through anomalies in the system and then analyzing them as potential threats. That threat analysis is based on intuition, itself developed from years of experience.  Automating the response to automated attacks only makes sense.

In the WIRED article they make a lot of hay about how AI driven systems like Darktrace or Cylance could reduce the massive shortage of cybersecurity professionals (because education seems singularly disinterested in helping), but I don't think that will happen.  In an inflationary technology race like this, when everyone ups their technology it amplifies the complexity and importance of jobs, but doesn't make them go away.  I think a better way to look at this might be with an analogy to one of my other favourite things.

Automating our tech doesn't reduce our effort.  If
anything it amplifies it.  The genius of Marc Marquez
can only be really understood in slow motion as he
drifts a 280hp bike at over 100mph.  That's what an

AI arms race in cybersec will look like too - you'll only
be able to watch it played back in slow motion to
understand what is happening.
What's been happening to date is that bad actors have automated much of their work, sort of like how a bicycle automated the pedaling by turning into a motorcycle.  If you're trying to race a bicycle (human based cyber-defence) against a motorcycle (bad actors using automated systems) you're going to quickly find yourself dropping behind - much like cybersecurity has.  As the defensive side of things automates, it will amplify the importance of an experienced cybersec operator, not make it irrelevant.  The engines will take on the engines, but the humans at the controls become even more important and have to be even more skilled since the crashes are worse.  Ironically, charging cyber defence with artificial intelligence will mean fewer clueless script kiddies running automated attack software and more crafty cybercriminals who can ride around the AI.  I've also been spending a bit of time working with AI in my classroom and can appreciate the value of machine learning, but it's a data driven thing, and when it's working with something it has never seen before you quickly come to see its limitations.  AI is going to struggle, especially with things like zero day threats.  There's another vocab piece for you - zero day threats are attacks that have never been seen before, so there is no established defence!

Once a vulnerability is found in software it's often held back and sold to the highest bidder.  If you discovered a backdoor into banking software, imagine what that might sell for.  Did you know that there is a huge market for zero day threats online?  Between zero day attacks, nation-state cyberwar on a level never seen before and increasingly complex cybercriminals (some of whom were trained in those nation state cyber war operations), the digital space we spend so much of our time in and more and more of our critical infrastructure relies on is only going to get more fraught.  If you feel like our networked world and all this cybersecurity stuff is coming out of nowhere, you ain't seen nothing yet.  AI may very well help shore up the weakest parts of our cyber-defence, but the need for people going into this underserved field isn't going away any time soon.

***


Where did the Cybersecurity & Privacy Conference turn next?  To privacy!  Which is (like most things) more complicated than you think.  The experts on stage ranged from legal experts to sociologists and tackled the concept from many sides, with an eye on trying to expose how our digitally networked world is eroding expectations of private information.

I found the discussion fascinating, as did my business colleague, but many of the students were finding this lecture style information delivery to be exhausting.  When I asked who wanted to stick around in the afternoon for the industry panel on 'can we fix the internet', only a handful had the will and interest.  We had an interesting discussion after about whether or not university is a good fit for most students.  Based on our time at the conference, I'd say it isn't - or they just haven't grown into the brain they need to manage it yet.  What's worrying is that in our increasingly student centred, digital classrooms we're not graduating students who can handle this kind of information delivery.  That kind of metacognitive awareness is gold if you can find it in high school, and field trips like this one are a great way to highlight it.

The conference (for us anyway) wrapped up with an industry panel asking the question, "Can the Internet be saved?"  In the course of the discussion big ideas, like public, secure internet for all (ie: treating our critical ICT infrastructure with the same level of intent as we do our water, electrical and gas systems) were bandied about.  One of my students pointed out that people don't pirate software or media for fun, they do it because they can't afford it, which leads to potential hazards.  There was no immediate answer for this, but many of the people up there were frustrated at the digital divide.  As William Gibson so eloquently said, "the future is already here - it's just not evenly distributed."  That lack of equity in entering our shared digital space and the system insecurity this desperation causes was a recurring theme.  One speaker pointed out that a company only fixated on number of users has a dangerously single minded obsession that is undermining the digital infrastructure that increasingly manages our critical systems.  If society is going to embrace digital, then that future better reach everyone, or there are always going to be people upsetting the boat if they aren't afforded a seat on it.  That's also assuming the people building the boats are more interested in including everyone rather than chasing next quarter earnings.

This conversation wandered in many directions, yet it always came back to something that should be self-evident to everyone.  If we had better users, most of our problems would disappear.  I've been trying to drive this 'education is the answer' approach for a while now, but interest in picking up this responsibility seems to slip off everyone from students and teachers to administration at all levels.  We're all happy to use digital tools to save money and increase efficiencies, but want to take no individual responsibility for them.


I've been banging this drum to half empty rooms for over a year now.  You say the c-word (cybersecurity) and people run away, and then get on their networked devices and keep doing the same silly things they've always done.  Our ubiquitous use of digital technology is like everyone getting a new car that's half finished and full of safety hazards and then driving it on roads where no one can be bothered to learn the rules.  We could do so much better.  How digital skills isn't a mandatory course in Ontario high schools is a mystery, especially when every class uses the technology.

I was surprised to bump into Diana Barbosa, ICTC's Director of Education and Standards at the conference.  She was thrilled to see a troop of CyberTitans walk in and interrupt the opening keynote.  The students themselves, including a number of Terabytches from last year's national finalist team who met Diana in Ottawa, were excited to have a chat and catch up.  This kind of networking is yet another advantage of getting out of the classroom on field trips like this.  If our pathways lead at the board hadn't helped us out, all of that would have been lost.

We left the conference early to get everyone back in time for the end of the school day.  When I told them we'd been invited back on the bus ride home they all gave out a cheer.  Being told you belong in a foreign environment like an industry and academic conference full of expert adults is going to change even more student trajectories.  If our goal is to open up new possibilities to students, this opportunity hit the mark.

From a professional point of view, I'm frustrated with the lack of cohesion and will in government and industry to repair the fractured digital infrastructure they've made.  Lots of people have made a lot of money driving our society onto the internet.  The least they could do is ensure that the technology we're using is as safe as it can be, but there seems to be no short term gain in it.


The US hacked a drone out of the sky this summer.
Some governments have militarized their cyber-capabilities and are building weapons grade hacks that will trickle down into civilian and criminal organizations.  In this inflationary threat-scape, cybersecurity is gearing up with AI and operational improvements to better face these threats, but it's still a very asymmetrical situation.  The bad actors have a lot more going for them than the too few who stand trying to protect our critical digital infrastructure.  

Western governments have stood by and let this happen with little oversight, and the result has been a wild west of fake news, election tampering, destabilizing hacks and hackneyed software.  There are organizations in this that are playing a long game.  If this digital revolution is to become a permanent part of our social structure, a part that runs our critical infrastructure, then we all need to start taking networked infrastructure as something more than an entertaining diversion.

One of the most poignant moments for me was when one of the speakers asked the audience full of cybersecurity experts who they should call, police wise, if their company has been hacked.  There was silence.  In a room full of experts no one could answer because there is no answer.  That tells you something about just how asymetrical the threat-scape is these days.  Criminals and foreign powers can hack at will and know there are no repercussions, because there are none.

Feel safer now?  Reading this?  Online?  I didn't even tell you about how many exploit kits drop hidden iframe links into web pages without their owners even knowing and then infect any machine that looks at the page anonymously.  Or the explosion of tracking cookies designed to sell your browsing habits to any interested party.


***

AI isn't just helping the defenders:  https://www.globalsign.com/en/blog/new-tool-for-hackers-ai-cybersecurity/


I'm beating this drum again at ECOO's #BIT19 #edtech Conference in Niagara Falls on November 6, 7 and 8...