Discussion Board
Cybersecurity and Criminal Justice
Task: Write a response addressing the following:
- The Evolution of Crime: Discuss how the “unique attributes of cyberspace” mentioned in the first reading hinder traditional law enforcement investigative strategies. Provide an example of a traditional crime that has become more difficult to prosecute in its digital form.
- The Academic Gap: Based on the second reading, why do you think there is a lag between the reality of technology-connected crime and its representation in mainstream criminal justice research?
- The Interdisciplinary Future: Choose one of the specialized course titles mentioned in the course list (e.g., “Cyber and Surveillance Law and Governance” or “Insider Threat”) and explain how that specific topic bridges the gap between traditional social science and STEM disciplines.
- Conclusion: In your opinion, should the criminal justice system focus on creating specialized “cyber units,” or should every traditional role (patrol, detective, etc.) be retrained to handle digital evidence as a standard part of the job?
Reply:
The “unique attributes of cyberspace” that hinder traditional law enforcement would be that users are able to remain more anonymous in cyberspace, they are able to reach more users and they are able to attack people more quickly. With anonymity comes a lack of guilt where attackers are not truly facing their victims, so they are able to dehumanize the events. Theft is more difficult to prosecute in its digital form. Scammers are able to target victims from different countries. They usually target older people with social engineering and take their information or their life savings at the click of a button. Once they take their money they are difficult to track.
There is a lag between technology connected and mainstream research because it is difficult to truly define the crime and it difficult to explain why a person would commit the crime. One can also see how it would be difficult to penalize the crime. For example the scammers in a different countries who are able to steal thousands of dollars from people. They will probably never see the criminal justice system, they can retain their anonymity and they are able to do it several more times to people around the world. Cybercrimes do not feel like a person who can be tried for their crimes rather they are more like an entity who must be blocked or shut down and even that proves difficult.
Introduction to Cyber Forensics would help bridge the gap between traditional social sciences and stem disciplines because people are able to see the cyber trail that people follow before a crime is committed. Criminologists are able to preserve and see snapshots of evidence like they would in a traditional crime scene. I think that these actions are able to humanize the cyber crimes more.
Cyber units would be better. Traditional roles are for more traditional, hands on, and social people who specialize in those fields while cyber crimes are easier for people who enjoy looking through digital evidence.
Discussion Board: Malicious Code
Task: Write a 250-word response addressing the following:
- Identify the specific security vulnerabilities in DNA analysis software that the researchers discovered.
- Explain the “isolation” strategies (such as VMs or containers) recommended by the researchers to mitigate the damage of potential biological-to-digital exploits.
- Discuss the ethical and security implications of treating biological data as “untrusted input.” As we move toward a future where DNA is increasingly digitized, how should organizations balance scientific advancement with these emerging biocybersecurity risks?
Reply:
The article that we read for our class “Malicious code written into DNA infects the computer that reads it” explains how scientists were able to expose a vulnerability that seemed to be farfetched. Researchers created a buffer over flow attack by embedding too much information stored on base sequences of DNA which was translated into binary code. Scientists explained how there was much more room for code if attackers wanted to do more damage.
DNA analysis software applications must take these risks into consideration and consider opening the data in VM’s or similar containers to isolate these risks. They are not open on the host machine but instead open on virtual software on the machine and ensure that these attacks are less detrimental to entire systems as they are contained.
Treating DNA as untrusted input can raise ethical concerns. DNA is biological data that is used for medical, scientific, and/or research purposes. At what point of the process does a researcher decide which DNA is to be untrusted and which DNA is to be trusted. As technology continues to advance, biological and digital data continue to merge. We must be vigilant in the way we receive information and how we continue to vet it. Knowing that there is a way to infect computers with malicious code on DNA is a good place to start. Knowing that there is a way to infect computers by turning the bases of DNA into binary opens new doors for cybersecurity professionals to consider the possible attacks that can be done with biological data. This opens new libraries for input validation, intrusion prevention, and intrusion detection.
Discussion Board: From Verbeek’s writing Designing the Public Sphere: Information Technologies and the Politics of Mediation
How should markets, businesses, groups, and individuals be regulated or limited differently in the face of diminishing state power and the intelligification (Verbeek, p217) and networking of the material world?
Reply:
First, Vanbeek makes a great point when he recognizes “technology accompaniment”. He states, “rather than keeping humanity and technology apart we should critically accompany their intertwinement.” While we are inclined to “blackmail the enlightenment” we must understand that technological advancements will inevitably be more engrained in humanity. However, this does not mean that we are not entitled to our own self-privacy. As we continue to have technological advancement, there is no longer any point in our lives that is not touched by anything digital. Markets, businesses, and groups should have different policies in place to regulate these devices. People should blatantly be aware of what their hardware is recording and what is being done with their data. I think it is quite technical with the terms of agreement now that a) can be hard to find and b) can be filled with legal jargon which makes it difficult to understand. In Europe the GDPR (General Protection Data Regulation) includes guidelines to supervise how data is being collected and how it is being distributed. Users are also able to make corrections as well as have their data deleted. With the integration of technology it is also easier for IoT devices to be attacked and hacked especially when they are configured with default passwords. Individuals should work on informing themselves on the amount of data that is able to be tracked, how it can be used maliciously against them, and how to protect themselves against these threats. As people become more aware with how easily their data is collected and how easily it is distributed there can be more of a call to action to have their information secured.