{"id":345,"date":"2026-05-04T03:41:37","date_gmt":"2026-05-04T03:41:37","guid":{"rendered":"https:\/\/sites.wp.odu.edu\/joshuaoania\/?p=345"},"modified":"2026-05-04T03:41:37","modified_gmt":"2026-05-04T03:41:37","slug":"cyse-368-reflection-paper-2","status":"publish","type":"post","link":"https:\/\/sites.wp.odu.edu\/joshuaoania\/2026\/05\/04\/cyse-368-reflection-paper-2\/","title":{"rendered":"CYSE 368 REFLECTION PAPER 2"},"content":{"rendered":"\n<p>Joshua Oania<\/p>\n\n\n\n<p>Reflection Paper 2<\/p>\n\n\n\n<p>Date: 3\/8\/26<\/p>\n\n\n\n<p>ODU Spring 2026<\/p>\n\n\n\n<p>Earth Viability Center<\/p>\n\n\n\n<p>Professor Teresa Duvall\/TA Joshua Russell<\/p>\n\n\n\n<p><strong>Internship Reflection Paper<\/strong><\/p>\n\n\n\n<p>Over the next 50 hours, I began working on my assigned tasks.&nbsp; The main task I tackled is the concept of user tracking and storage in the Place4Us platform.&nbsp; During this time, there was no way to track user activity, nor was there a clear understanding of what we could track without violating user privacy, so I spent a lot of time researching the legality of user activity tracking on social media platforms to better understand what we can and can\u2019t collect, so I was able to develop a plan for what could be implemented and present it to the other&nbsp;<\/p>\n\n\n\n<p>On that note, one of the biggest challenges I faced over the next 50 hours was determining what could and couldn\u2019t be collected.&nbsp; One of the ways I was able to do that was by developing a baseline of the bare minimum required from users to keep the platform operational, both from a general and a security standpoint.&nbsp; Through my assessments, I found that users had an option to track their logins, which was turned off by default.&nbsp; At a glance, it seemed like a good security measure because users had the option to opt out of getting this particular information collected from them.&nbsp; However, from a security perspective, it was concerning because, should an incident such as a brute-force attack occur, there would be no way to determine that an attack happened, as that information wasn\u2019t collected.<\/p>\n\n\n\n<p>Another challenge I faced was determining what work had already been done to harden the platform.&nbsp; During the onboarding process, I was told where to find interns&#8217; previous work, so I spent a lot of time reading through it to better understand what had already been done and avoid reinventing the wheel.&nbsp; I also hoped to improve and build upon their work.&nbsp;&nbsp;<\/p>\n\n\n\n<p>I read a particular report that was very valuable.&nbsp; It was a comprehensive risk assessment of the platform done by a previous group of interns.&nbsp; During their risk assessment, they used Valor\u2019s Top 10 Digital Security Checklist and NIST 2.0 to identify threats and vulnerabilities across the platform.&nbsp; And one of the things they found is that the login page is susceptible to brute-force attacks because it has a weak CAPTCHA.&nbsp; Based on my own assessments, I found that the CAPTCHA is only shown when signing up for the platform, which doesn\u2019t help stop brute-force attacks (or verify that a user logging into an account is legitimate).&nbsp; Further assessments showed that the platform did not implement multi-factor authentication (which the previous interns had also found).<\/p>\n\n\n\n<p>With all of that being said, I, along with another intern, worked on a presentation to share our findings with the interns and supervisors.&nbsp; Some of the solutions I proposed include implementing mandatory user login tracking.&nbsp; More specifically, tracking successful and failed attempts in order to determine whether there is a brute-force attempt that is happening.&nbsp; Furthermore, I proposed tracking account changes (such as email changes) and session activity (e.g., logins from a new device) to detect unauthorized modifications and unusual logins.&nbsp;&nbsp;<\/p>\n\n\n\n<p>Overall, a lot of progress has been made in that area.&nbsp; And I\u2019m looking forward to finishing up the last 50 hours of my internship with Dr. Hans-Peter.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Joshua Oania Reflection Paper 2 Date: 3\/8\/26 ODU Spring 2026 Earth Viability Center Professor Teresa Duvall\/TA Joshua Russell Internship Reflection Paper Over the next 50 hours, I began working on my assigned tasks.&nbsp; The main task I tackled is the concept of user tracking and storage in the Place4Us platform.&nbsp; During this time, there was&#8230; <\/p>\n<div class=\"link-more\"><a href=\"https:\/\/sites.wp.odu.edu\/joshuaoania\/2026\/05\/04\/cyse-368-reflection-paper-2\/\">Read More<\/a><\/div>\n","protected":false},"author":27857,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wds_primary_category":0},"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/posts\/345"}],"collection":[{"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/users\/27857"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/comments?post=345"}],"version-history":[{"count":1,"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/posts\/345\/revisions"}],"predecessor-version":[{"id":346,"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/posts\/345\/revisions\/346"}],"wp:attachment":[{"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/media?parent=345"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/categories?post=345"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sites.wp.odu.edu\/joshuaoania\/wp-json\/wp\/v2\/tags?post=345"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}