Showing posts sorted by relevance for query terabytches. Sort by date Show all posts
Showing posts sorted by relevance for query terabytches. Sort by date Show all posts

Thursday, 24 August 2023

Stories of Innovation Are Never About One Person

I've been involved with Cisco's Networking Academy since we joined the CyberTitan national student cybersecurity competition in its inaugural year in 2018. It's the 25th anniversary of Netacad and this summer they asked alumni to tell them stories that arose from their association with the platform. I told the tale of the Terabytches and bringing the first all-female team to CyberTitan national finals along with my own journey of taking my first technical qualification in almost two decades. It was a story of perseverance in the face of prejudice and a love of life long learning.

To my surprise I made the finalists list out of hundreds of applications from across the globe (Netacademy runs in almost every country in dozens of languages - it's a truly global platform). When I read about some of the other finalists I was thrilled just to be included with them.

On August 15th I was driving through the countryside to the University of Waterloo, listening to the awards being announced on spotty cell phone coverage. It cut out just as the innovation architect award was announced and then came back for the next award, so I didn't hear I'd won when it happened.


At CEMC at UWaterloo I took a room full of computer studies teachers through cyber-range activities and while that was going on my wonderful wife and innovation touch-stone, Alanna, announced that I didn't just win the Innovation Architect Award, but also the Shooting Star grand prize which has me in NYC in mid-September for the Global Citizen Festival

As part of the prize Cisco gave me a communications package and asked for shoutouts, and there are many. Innovating can often feel like a lonely exercise where most of what you're doing seems to aggravate management, but it's really a collaborative exercise, otherwise you're by yourself in a room doing cool things that no one else knows about. The idea of a lone inventor hidden away working on their own is a fiction.

I could never have built the program I developed without getting my school board onside. There are two people in particular who became supporters and advocates for the unique work we were attempting. Charles Benyair was our SHSM lead and he provided the resources that my school would not to get us in motion, and Sandro Buffone in our IT department made a point of attending my cybersecurity sessions at ECOO so he could understanding what I was trying to do. He then was instrumental in clearing away the technical bureaucracy to let it happen.

Convincing students to take on an international competition in a subject we'd never studied before was a challenge, but Cam, Cal, Nick and Justin were seniors in 2017 and bravely jumped into cybersecurity with me. We learned new concepts and got a handle on things to such a degree that we discovered we were going to the first Canadian national cybersecurity finals in Fredericton. Three of those students had never left the province or been on a plane so you can imagine the impact.

As the teams gathered for a photo I happened to be standing next to Sandra Saric, the vice-president in charge of CyberTitan at the Information & Communication Technology Council (ICTC). As the photo got taken she said under her breath, "where are all the girls?" Out of seventy odd students only a handful were girls. That observation put me on a mission. 

Sandra went back and established a program for encouraging all-female teams to sign up and I went back to my junior computer technology classes (the exacting gender expectations of our rural high school made sure that there were no girls in senior computer tech classes) and cajoled six girls to give it a try. That next year we had three full teams instead of two-thirds of one. I encouraged them to find a name that speaks to their experience and the girls came up with the Terabytches (terabyte with a twist).


Those six pioneers faced derision from our school and when they went to nationals a member of one of the other all-male teams said to one of them, "you're lucky you're pretty, because you suck at this." That year emphasized for me how important it is to give girls their own space away from the often corrosive male culture that forms around technology.

In a radio interview in Ottawa at those finals Rachel said something that stuck with me. "We used this name so that it couldn't be used against us." 2019 was an incredible year for getting my head around diversifying access to technology learning, particularly in the hyper-male dominated field of cybersecurity. But it was also a year of finding allies. Joanne Harris at the school board enabled us to attend nationals by coming along as our female chaperone and I got to meet Diana Barbosa, Sheena Bolton and Hayley Heaslip who ran the competition.

That summer Philippe Landry from Cisco Canada got in touch and asked if I'd be interested in working toward my CCNA Cyber Operations Instructor qualification. My last I.T. certification was CompTIA's Network+ way back in 2002, so this would be my first run at a technical certification in seventeen years, and in a subject I'd only been looking for eighteen months. Claude Roy at FTI in Quebec was my instructor and he was patient and very giving of his time. Over the summer I became familiar with Wireshark and all sorts of other cyber-tools and in September I wrote the exam and became the first K12 teacher in Canada qualified to teach cyber operations - I think I am still the only one five years later. Yes, innovating can sometimes feel a bit lonely.

Attending Cisco Live in the fall of 2019 I was again reminded of just how cloud based (and cybersecurity dependent) things have become. I also attended my first University of Waterloo Cybersecurity & Privacy Institute conference (bringing a bus load of students with me) which opened my eyes to the current state of networked technology where we're barely hanging on. To underline that I had my local OPP detachment asking if I could forensically analyze digital evidence for them because they weren't resourced to do it themselves.

We ground through the pandemic but CyberTitan was one of the few events that never cancelled on us. The diverifying of our teams in 2019 led to a richer and more effective co-ed senior team. Some of the girls wanted to join the best of the boys and that mix of skillsets led to a string of top five finishes including a top defender award. The girls team also continued, missing nationals in 2020 but earning top wildcard spots in the '21 and '22 finals.

In 2022 I discovered that I had been seconded to ICTC for the year to advocate for and support cybersecurity education nationally. In this role I've been in classrooms from Newfoundland to British Columbia and many points in between. I've supported two new provinces in joining the competition and continue to bang my drum for recognition of essential Twenty-First Century digital skills that are so often ignored in our school systems, like cybersecurity.

This spring I joined Katina Papulkas' Dell K-12 Education Innovation Accelerator, Part of that program was an opportunity to mentor with someone in the edtech space and I was lucky enough to be placed with Julie Foss, who helped me re-contextualize myself in my first role out of the classroom in two decades.The experience empowered me to apply for the Cisco award. Had I remained lost at sea in terms of understanding how to do what matters in my new role, I would never have done it.

Innovation is often lonely work. It can antagonize status quo types who are intent on maintaining a system that put them in charge, but innovation is also thrilling and can empower those not privileged by that status quo. If you're serious about diversity, equity and inclusion, innovators aren't people you want to be labelling as troublemakers, they're simply committed to finding a better way.

The other nice things about innovation is that you meet the most interesting people. From Ella in UBC to Kyle at Inspiretech, Louise at QAI and Eric George at the CPI, I've had the opportunity to meet some fascinating people who don't status quo anything.

Cisco, both as a company and as individual employees, have been wonderful enablers of innovation, providing me with resources in a subject that everyone uses all day every day in every classroom, but almost no one teaches. Being acknowledged as an innovator by such a forward thinking organization makes me think that I'm on the right track, even if it annoys some of the powers that be.

We face an ongoing shortage in cybersecurity skills and society faces a global digital skills crisis that is grinding on into its second decade. Women remain underrepresented in high paying STEM fields and especially in cybersecurity. Status quo thinking got us here, it's time to innovate our way out of it. Thanks to Cisco for supporting that by acknowledging our work.







Saturday, 25 November 2023

What You Need To Work in Cybersecurity: the secret sauce

I see a lot of rules based 'quick fix' learning opportunities in cybersecurity. These are usually boot camp style condensed programs that promise to turn an accounting or science student into a cybersecurity practitioner in a single semester by showing them how to use tools in a formulaic manner. They treat cybersecurity as though it's an office job: we show you the cybersecurity rules and you follow them. You can see how well this is working by the ongoing shortage Canada faces in finding and retaining cybersecurity professionals.

I got into cybersecurity with my students in 2017 when we started chasing CyberTitan, but I brought something with us that is atypical in the world of STEM: a willingness to hack. I don't like the word hack, it has negative connotations to it in English that have been encouraged by the self appointed masters of STEM (the S&M part), but that willingness to iterate and work outside expected outcomes is the secret sauce in cybersecurity that many ignore, and a major reason for why I've taken to it like I have.

'Necessity is the mother of invention' has been the motivating factor in my relationship with technology since the beginning. I moved quickly from off-the-shelf to customized solutions based on experimentation and need. Within six months of owning my first home computer (a VIC20), I'd figured out how to copy software using a sufficiently low noise audio deck. My first x86 PC was purchased but quickly modified as I came to need more memory and processing power. By the mid-90s I was building my own computers at a time when many people didn't own one.

This process was initially powered by curiosity, which many training programs eclipse with a promise to provide the initiative so you don't have to - something that has never appealed to me and a major reason why I didn't start collecting technical certifications until 2001 (I'd been working in IT for a decade at that point). Schools are bad at nurturing enthusiasm for self-exploration too. Many educators feel that it is their job to impart knowledge in a regimented format (that's why we call them disciplines!) and assess student understanding through a system of providing both the questions and the answers to minimize any frustration. Assessment success is often a measure of compliance rather than cultivating enthusiasm and curiosity.  Many in education call this approach rigorous and disciplined - it's how they demonstrate credibility, and a reason why I haven't continued pursuing academia.

Indians have a term for austere innovation: jugaad (non-conventional, frugal innovation) which doesn't have the pejorative connotations of the English 'hack'. Jugaad celebrates common sense with a solutions focused approach to creative problem solving without needless bureaucracy. It emphasizes an applied approach to making technology work that is especially needed in an industry like cybersecurity where practitioners are often facing edge cases that the people who designed the network never thought of (which is why we're having a cyber problem). WIRED recently did an article on a Ukrainian technologist who demonstrated this start-up/rapid response approach in the war with Russia. There is even an event in cyber that is all about extreme edge cases: the dreaded zero day vulnerability. Jugaad will get you much further than any amount of system think during a zero day attack.

Kintsugi has played a part in my motorcycling.
There is also a term in Japanese that takes the derision found in English out of making old things work. I've long enjoyed the concept of 'kintsugi' or 'golden joinery', which is the repairing of old things using gold to embellish the fix rather than trying to hide it. In typical Japanese fashion it raises what is seen as banal work in the West to an artform. A concept that combines jugaad's celebration of a fix beyond rules based approaches with kintsugi's raising of that fix to an artform is where a good candidate for work in cybersecurity should find themselves inspired. When I started in cyber I found my  IT background helped in terms of understanding the mechanics of what was happening, but my kintsugi powered jugaad approach is what has allowed me to thrive.

This 'secret sauce' is often ignored in education and especially in cybersecurity adult retraining. There are some disciplines that tend to attract rules focused types, but that fixation on systemic order blinds them in the edge cases where cybersecurity often operates. Rather than retraining an accountant or rigorously compliant STEM student, I suspect that those exploring subjects like detective work in policing or creatives in the arts would find the skills they've honed more effective, but that doesn't stop everyone from demanding a computer science degree for any job in cyber.

In 2019 after the Terabytches went to CyberTitan nationals we got invited on the local radio station to talk about the experience. The interviewer asked me a good question about our DIY approach to computer tech. I was annoyed at the lack of resources, but he suggested it might be what gave us an edge. He was right, we'd been jugaading and it made us mighty!

There are many jobs in cybersecurity. People who lean toward the jugaad end where they can problem solve without restrictions can find a comfortable fit in operational cybersecurity where they are monitoring real time threats, penetration testing where they are attempting to exploit a client's system to highlight vulnerabilities, or threat intelligence which focuses on gathering reconnaissance data on threat actors. But even in the policy and compliance work, a willingness to consider and understand threats and solutions that are outside the box is a necessity. The need to nurture and respect those out of the box thinkers working in unexpected end of the cyber-workforce is essential for management. Those industries that thrive on status quo compliance are the ones you see being hacked most often because they don't respect the skillset.

This map of cybersecurity domains gives you an idea of the many specializations that the field offers, though I would argue that in all of them (even those up the compliance end) an ability to work from your own initiative and experience rather a rule book is essential.


Sam Sheepdog & Ralph Wolf know the score.
I sometimes describe cybersecurity types as sheepdogs. I think many in law enforcement also fit this description. You can't send a goat to fend of wolves, but having a wolf of your own will do the trick. Early on in my transition from IT into cybersecurity I found myself leaning on IT administrative habits that don't work in cyber, and came to realize that the jobs are very different, though the technology is the same. If you have an IT person running your cybersecurity you're likely to be constantly surprised by the attacks you face because they tend to see systems in an architectural way rather than as an opportunity to be compromised.


It would be easy to say something silly like, 'there are no rules in cybersecurity!' but that's pointlessly reductive. It would also be easy to describe all the people in it as hackers, but this isn't true either, though a mentality that tackles problems from a place of curiosity and jugaad is far better than a rules compliant myopic who can't see beyond the framework they maintain. At the end of all this I firmly believe that you need a bit of the wolf in you if you want to consider a career in cybersecurity. I wish more cybersecurity training and especially adult retraining would emphasize that when looking for candidates rather than demanding STEM grads often missing these skills. If it's a formulaic job that you're looking for, cyber isn't it.

STEM students are often missing skills which "include teamwork, collaboration, leadership, problem-solving, critical thinking, work ethic, persistence, emotional intelligence, organizational skills, creativity, interpersonal communication, and conflict resolution." Adding an 'A" to STEM doesn't fix this, incorporating an iterative, resilient, interrogative, team-based problem solving mindset into STEM subjects would, but that doesn't tend to be how we teach it.


Another piece of Canada's cybersecurity puzzle came into focus from the last post on how our cybereducation system is broken. In response to that, Francois Guay from the Canadian Cybersecurity Network followed up with the observation that the cybersecurity talent pipeline in Canada is also in tatters.

I've been thinking about that post and believe all of the responses from both new cybersecurity practitioners and veterans are valid. It would appear that when you try to fix a talent shortage with rushed retraining based on incorrect assumptions about the skillsets needed in cybersecurity, no one trusts the results. Problems such as absurd requirements for entry level positions like asking for 5 years of experience on a tool that only came out last year or demands for that vaunted yet irrelevant computer science degree continue to strangle entry level workers coming into the field, even though they have hacked (cough) their way through our broken cyber education system to do it.

Not to sound hopelessly jugaad, but the simple solution would be to introduce cybersecurity apprenticeships that give a more diverse set of potential candidates the opportunity to see if cybersecurity is a field of study that suits them. Those with the right combination of fearless curiosity, critical thinking and tenacity might find their way into it instead of continually opening the doors to STEM grads who are good at being told what to do and enjoyed the privilege growing up of being able to handle the enormous homework loads STEM subjects demand as part of their compliance regime. Students with a background in science and technology might be familiar with the medium that cybersecurity operates in, but that doesn't mean they'll be able to handle the stochastic demands that resonate across cybersecurity work. It's better to find those with the right jugaad mentality; technical familiarity will build quickly powered by enthusiastic initiative and tenacious problem solving.

I've always told my students that if they can bring a willingness to explore, experiment and a fearlessness in breaking things in the process of figuring them out, they don't need to sweat the technicalities, I can teach them those by harnessing the curiosity they bring with them. I've had strong technical students struggle in cyber because they lean on formulaic approaches to computing (they are often maths strong coders) that let them do the bare minimum. If your natural talents in mathematics and computer science have blessed you with a compliance based work ethic, cyber with its changeable success criteria isn't for you. Another favourite adage of mine in the classroom is, 'if you're looking for a way to do less, you'll usually find it.' Those that want to work in a framework often do it so that they can delineate where they can stop; in other words it's used as a way to limit their involvement. That's no way to approach cybersecurity. If solving a problem is a nine to five gig for you, go find work elsewhere.



Much of this comes back to the reductive way we have approached digital skills development (when we're not ignoring them entirely). Cyber Education is the hidden, much larger part of the digital skills iceberg.


Thursday, 21 July 2022

Dancing in the Datasphere 2022 Edition: AI Refined User Interfaces!

This quote is 12 years old now, but it's more true than
ever, and our technology is about to take another leap
forward that will make our current passive information
/screen based approach to digital look
as outdated as a fax machine.
Way back in 2011 I made one of my first presentations for a provincial education conference (Dancing in the Datasphere).  Leveraging years in IT prior to teaching, I tried to edge teachers closer to an understanding of how the rest of the world had moved on in terms of their digital engagement.  Stepping out of IT in 2003 to become a teacher felt like time warping back 20 years, so out of date was the use of technology in education.  In 2019 I attended Cisco Live and discovered that the rest of the world has moved on again, leveraging cloud based systems in a way that no one in education is, so the anti-tech habits of education are still there.  The need for online/cloud based systems in education is apparent (especially since the pandemic began), but poor cybersecurity management is often used as an excuse to stay out of it.  We're still the only school in South Western Ontario doing CyberTitan and one of only five in the province with any kind of cyber-focus.

In the past decade education has staggered into the 21st Century, though Ontario has gone out of its way to fear and shun it until all the tech-haters suddenly desperately needed it during the pandemic.  The past two years have forced a recognition of the importance of digital fluency, though there are still no mandatory digital literacy courses in any Ontario high school.


On To The Future, Ready or Not...

With all that in mind, what's coming next offers some exciting possibilities, not that education will leverage them before I retire.  Machine learning and the artificial intelligence growing out of it is already offering students a silent AI partner for coding with Github's Copilot.  The GPT-3 OpenAI system Copilot runs on is already producing original text, and perhaps even some of the original essays that teachers think are written by students.

As systems become smarter information falls to hand more readily and old habits become irrelevant (like memorizing phone numbers).  With all that in mind, I've had grade 10s building IBM Watson AI powered chatbots for several years now, and this past semester several of my seniors used Copilot to make their culminating coding projects.  Being able to communicate effectively with ML & AI is going to become increasingly important in the next decade.

But what really excites me about intelligent machines is how they're able to simulate activities with human users in order to streamline and improve the human-machine interface.  Last week we were watching FITC's Spotlight UX, an online conference about the multidisciplinary field of User Experience (UX) based on digital design, ergonomics and user interfaces.  UX opens things up to consider all aspects of digital design from a user's point of view; it has a lot in common with student centered learning in education.  The opening speaker was formerly an ethnologist before getting into UX and her background allowed her to dismantle many of the assumptions that alienate users, especially in online systems that may be designed in one country and used many others.

At the same time I was reading Guy Huntington's piece on The Coming Classroom Revolution.  One of the things he covers is the concept of a virtual-self personal learning assistant.  Guy is looking at the AssistBot from a legal/privacy perspective in the article, but a complex digital model of a students' learning habits offers some interesting possibilities.  What if the virtual student could be run through simulations using various software?  User interface issues could be recognized even before a student picks up a new device or software for the first time.  Interfaces that have been refined by AI driven user simulations would feel intuitive in a way they never have been before because each user would be interacting with digital information on an interface that was custom designed for them based on thousands of hours of simulation prior to them ever picking it up for the first time.

The learning benefits should also be apparent if everyone is walking around with a digital doppelganger in tow.  A teacher might pitch a lesson into a simulation space and the virtual student-bots would be able to show where it does and doesn't work for them, and the lesson could then be customized for each student as needed prior to them ever seeing it for the first time.  Classrooms would become radically personalized after over a century of factory conformity and low resolution information sharing.

A buzzword flying about at the moment is 'metaverse', especially after Facebook rebranded itself Meta.  In the last post I talked about my long involvement with interactive and immersive virtual reality, and after years of development we are close to finally making it happen on a system-wide scale, but it's going to happen while the systems themselves are becoming intelligent and the web itself is attempting to evolve itself past the attention merchant economy that web2.0 became.


Back in April I watched FITC's big early conference and they had Jared Ficklin keynoting about how web3 (driven by blockchain encryption) might give us back control of our own data and change the paradigm we're stuck in online with multi-nationals selling our data as if they owned it.  It was a thrilling talk and I've since come across similar thinking in WIRED.

Web3's a bit of a dog's breakfast thanks to crypto and the mess it has made, but the possibility of individuals owning their online presence is a thrilling return to what the internet once was and might be again.

Combining all of these converging ideas into a viable technological future is ambitious, but it's something worth pursuing because if you don't push for the best outcome for the most people we end up with what we have now.

Could the internet provide us with secure interaction and storage without abusing our information?  Could we move past the low-resolution two dimensional windows that we all peer into the datasphere with now?  Could we leverage machine intelligence to treat each other in a more human way than our 'superior' one teacher to 30+ student brick-in-the-wall classrooms continue to do even now?


Imagine if you will a future where you are able to move in and out of digital information at will without it ever distracting you from the real world as it does now.  Peripheral user interface ergonomics will drastically improve as we get clear of the smartphone myopia we're currently stuck in.  When deep diving into digital data you'll be able to do it using complex multi-dimensional interfaces that make our current screen fixation look positively archaic.  Haptic IoT devices mean you'll interact with data with more than your fingers, allowing for much more nuanced control of your digital interactions.  Your awareness of that environment will also be dimensionally greater than peering through a 2d screen.  Moving three dimensionally in digital data offers you a much richer connection to your digital self.

A better interface with digital information is already here and will only improve, and though Web3 struggles to make sense at the best of times, the idea that we could bring our shared network back to a user-centric experience where our privacy and personal information is owned and controlled by users points to a possible future beyond the tyranny of the attention economy.  But what's most exciting to me is the idea that we can have virtual versions of our habits that we can run simulations on in order to produce software experiences unlike any we've had before.  The efficiency in that combined with all these other converging technologies points to a digital future much richer than the step we're stuck on now.

Imagine opening up a brand new app to discover that it intuitively makes sense to you because it was designed using thousands of simulated hours with your digital avatar.  This also offers some interesting security opportunities because no two interfaces would be the same since each would be tailored to its user.  Combined with a more privacy friendly web, multi-dimensional user interfaces and machine learning that enables us to refine the human-machine connection even before first use, the cybernaut of the future will be doing things in digital spaces that will challenge what we think is possible, which is vital because we will interacting with more and more complex artificial intelligences when digitally connected and if we don't refine and improve our ability to operate in digital spaces, we'll rapidly lose touch with what these automated intelligences are doing.

Rachel, one of our founding Terabytches who took care of Cisco networking during cybersecurity competitions has moved on to computer science at university.  Back when she was doing coop it she developed a simple machine intelligence to develop an understanding of what was going on in large datasets.  One of the biggest surprises for us both was how much work is involved in the Explore/Transform section of this hierarchy.  ML, AI and deep learning offer us a new way to understand large, complex data-sets, but they also need human oversight to make them work.  The automation possible in modern data science is another one of those 21st Century skills most classrooms don't consider.