Journal Entry One:
I am excited to pursue a career in cybersecurity; the research I have done for this assignment has opened my eyes to possible routes I can take in the future. Previously, I have always been interested in secure software development or analysis of these systems. Throughout this research, my desire for these work roles has remained prominent. I enjoy coding and problem-solving, which both careers vastly contain. Other work roles that caught my eye are threat and vulnerability analyses. I would be fond of these roles as they are both related to protecting people and businesses. On the other end of the spectrum, I have little to no interest in cybersecurity legal advice or instruction. I would not want to be associated with legal advice strictly because I am not proficient with the language of law and its intricacies. As for cybersecurity instruction, I want to be engaged in active cybersecurity development.I am excited to pursue a career in cybersecurity; the research I have done for this assignment has opened my eyes to possible routes I can take in the future. Previously, I have always been interested in secure software development or analysis of these systems. Throughout this research, my desire for these work roles has remained prominent. I enjoy coding and problem-solving, which both careers vastly contain. Other work roles that caught my eye are threat and vulnerability analyses. I would be fond of these roles as they are both related to protecting people and businesses. On the other end of the spectrum, I have little to no interest in cybersecurity legal advice or instruction. I would not want to be associated with legal advice strictly because I am not proficient with the language of law and its intricacies. As for cybersecurity instruction, I want to be engaged in active cybersecurity development.
Journal Entry Two:
The Principles of Science (Relativism, Parsimony, Determinism, etc.) are related to cybersecurity studies for multiple reasons. The first is that it is essential to have an unbiased and structured process for studying cybersecurity. The principles of Empiricism (only having the ability to study behavior that is real to the senses) and Parsimony (the act of keeping scientific explanations as simple as possible) are the two that come to mind for this first point. The second way they are related is the level of protection necessary with an online presence. Ethical Neutrality (scientists must remain ethical when doing their research) is hands down the most essential principle in this regard. There is so much information about everyone online, and the scientists studying the effects of specific cyber incidents can assist in protecting this information.
Journal Entry Three:
There is surprising data regarding data breaches on the Privacy Rights website, which is public access. Not only does the site have graphs and figures, but it also provides multiple pages of reports and articles. There are several ways that researchers could utilize this information to study breaches. Researchers could learn by looking at the interactive map of the most impacted U.S. states by data breaches. They could then use this information to look deeper into the causes of these “hot spots” to try and rectify the issues in these areas. Researchers can also look into the articles on the site as they can be used to try to prevent further breaches.
Journal Entry Four:
Maslow’s hierarchy of needs applies to my experiences with technology on almost every level. The only level it does not agree with is the first of the two basic needs, namely, physiological needs. My experiences with tech do not apply to this level because this level speaks about the physical requirements of survival, food, water, etc. Maslow’s hierarchy level of safety needs applies to my experiences as I take online safety and security very seriously. Technology drastically enhances the ability to converse with friends and partners, improving the quality of these relationships. Technology has made me feel accomplished in many ways, including learning and completing game missions. I have yet to reach my full potential, but technology has allowed me to get much closer to that goal by providing opportunities to learn, experience, and enjoy many amazing things in life.
Journal Entry Five:
Most cybercriminals commit crimes for multiple reasons. Often, criminals search for compensation, revenge, or satisfaction for a previous event. The second most common motive for cybercrime is to gain money. Criminals in all forms often commit crimes for financial gain, whether it be taking money directly from the victim or selling stolen information. The third most common motive is revenge. Many criminals commit crimes online to enact revenge on a person or company due to something previously done to them. The next most prevalent is committing crimes for political reasons. Criminals may skew ballots or hack campaigns to support or attack a political entity. The final three motives are entertainment, boredom, and recognition. These three are only valid motives in particular instances, usually accompanied by other motives.
Journal Entry Six:
Fake websites can often be identified by certain telltale signs. For instance, a fake “Amazon Support” site may use a suspicious URL like “amaz0n-support.com,” with a zero replacing the letter “o,” and may have poor-quality images or inconsistent branding, unlike the polished, secure Amazon.com. Similarly, a fake PayPal site might have a URL like “paypall-login.com” and feature spelling errors or a low-quality design, while the real PayPal.com is professional, secure, and well-maintained. Lastly, fake sites offering “free Netflix trials” often use strange URLs such as “netflix-free.com” and may bombard users with pop-ups, whereas the real Netflix.com offers a clean, secure layout with no intrusive ads. In general, fake sites lack proper security (no “https://”), have poor design, and feature suspicious URLs that don’t match the official brand names.
Journal Entry Seven:
One image shows a person working at a desk on a computer, which inspires the meme: “When your password is ‘password123’ and you still click on phishing emails… but you swear you’re ‘security conscious.'” It’s a funny reminder of how people often underestimate basic cybersecurity, like using weak passwords, while thinking they’re doing enough to stay safe.
Another image has someone typing on a laptop in a coffee shop. The meme I came up with is: “Just because it’s a public Wi-Fi, doesn’t mean I can’t check my bank account right?” This highlights the common belief that public networks are safe, while they’re actually pretty risky.
Finally, there’s a stressed-out person holding a phone, which sparked the meme: “When you realize you’ve been scrolling through suspicious links for hours… ‘I’ll just click one more.'” This shows how people, ignore security warnings and end up putting themselves at risk by clicking on sketchy links.
These memes really reflect how our behaviors can lead to cybersecurity issues, like being overconfident, seeking convenience, or just not knowing better. A more human-centered approach to cybersecurity aims to understand these habits and create strategies that fit how we actually use technology, making it easier and more effective to stay safe in our daily lives.
Journal Entry Eight:
Media heavily influences our understanding of cybersecurity, especially movies and shows. The depictions of hacking and cyber-attacks shown in the media generally have a basis in truth. However, they are often dramatized and exaggerated to make the scenes more interesting. The hacks and processes are usually based on actual events or techniques, such as the SSH vulnerability that was shown in “The Matrix Reloaded.” The producers frequently oversimplify the tasks, making them executable very quickly for the characters and filling the relatively real task with “Hollywood jargon.” This sped-up hacking was shown in “The Social Network” when the producers compressed the work from multiple days into one night. These changes cause viewers to believe that hacking is relatively straightforward.
Journal Entry Nine:
I scored a two on the Social Media Disorder scale, which fits since I don’t use social media much. The questions got me thinking about my habits, like how I struggle to commit to mundane tasks I need to do due to social media. Overall, I feel like I handle it pretty well. It’s interesting how social media use varies around the world. For example, in America, it’s a major way to communicate, while in some other places, it’s more just for passing the time. I think it varies because of factors like availability of technology, cultural norms, and societal factors. Going through these questions helped me see some of my not-so-great habits online, but I’m aiming to keep my current level of use because it mostly works for me.
Journal Entry Ten:
The article by Beskow and Carley points out how important social cybersecurity has become in modern warfare. In modern times, cyber warfare isn’t just breaking into and controlling information systems; it’s also about manipulating human behavior. Unlike traditional cybersecurity that focuses on protecting data systems, social cybersecurity is more about “hacking” into how people and societies think and act through clever psychology and marketing techniques. This shift has serious implications for strategy. Information warfare is becoming a whole new battlefield where misinformation can erode trust and impact national security without the need for conventional military action. That’s why social cybersecurity is now a crucial part of modern defense strategies, especially since both state and nonstate actors are taking advantage of our interconnected world’s vulnerabilities. It’s pretty unsettling to realize how easily information can be turned into a weapon, but it is important to to understand and tackle these threats for the sake of our national security and social resilience.
Journal Entry Eleven:
Being a cybersecurity analyst really shows how important social skills are, especially when it comes to communication and teamwork. Analysts often work together, so being able to communicate effectively is key for tackling security threats and sharing information across the organization. Trust and accountability are also huge because analysts need to rely on each other for accurate data and quick actions. Plus, they frequently interact with various stakeholders—like managers, developers, and external vendors—so having solid interpersonal skills to handle different viewpoints and priorities is essential. As cybersecurity involves dealing with real-time threats, analysts also need to be able to make quick decisions, all of which are influenced by their interactions and teamwork. Overall, the role is all about cooperation, responsibility, and managing group dynamics in a technical environment.
Journal Entry Twelve:
Rational Choice Theory suggests that businesses and consumers try to get the most bang for their buck by weighing costs and benefits. In this situation, the company decided to outsource its platform to save money but didn’t really think through the risk of data breaches. On the flip side, consumers who enjoy the convenience of online shopping may not have fully considered how their personal info could be at risk. Now, because of the breach, both the company and consumers need to rethink their choices and what they’re really giving up.
Then there’s Classical Economic Theory, which is all about supply and demand with minimal government interference. The breach kind of shows the downsides of a free market when it comes to keeping data safe. If businesses don’t have solid safety measures in place, they can’t protect their customers, which suggests that some regulations might be necessary to fix this.
When we look at the theory of Planned Behavior, it’s clear how the breach impacts what consumers decide to do next. Actions like canceling credit cards or keeping a close eye on their accounts depend on how people feel about the situation, what their friends think, and whether they feel like they have any control. If they think they’re powerless or that the breach is beyond their control, they might just ignore it, which could lead to more issues down the line, like identity theft.
Self-control theory comes into play here, too. Both the businesses and the consumers should have done better in managing long-term risks. The company’s choice to outsource without strong security measures shows a lack of foresight. Meanwhile, consumers often fail to protect their own data, placing too much trust in businesses to keep it secure. This lack of self-control on both sides allows breaches like this to happen.
Journal Entry Thirteen:
I found the article on bug bounty programs very interesting. One of the main points I retained from the article is that hackers are not extremely concerned with reward quantity. This means that even smaller companies can utilize these bug bounties to secure their companies without paying large amounts to build a team of security experts. These programs remove the idea that only large companies can attain access to valuable reports.
Another interesting point is the role that the industry sector plays. Companies in finance, retail, and healthcare generally see fewer reports coming in. It’s also surprising how the age of a bug bounty program affects its performance; older programs tend to get less engagement, but broadening the scope could be a way to boost participation.
Overall, the study was well-constructed and used a solid data set. However, the authors did point out a few limitations, like the need for complete data on how serious the reported vulnerabilities are. In conclusion, this research drastically increases our understanding of bug bounty programs while also showing a need for further research to understand how they affect company security.
Journal Entry Fourteen:
Andriy Slynchuk pointed out severe illegal online actions; five things stand out. First, collecting info about kids under 13 is a big deal because it opens the door to exploitation and breaks privacy laws meant to protect them. Then there’s using someone else’s internet without their permission; it’s like stealing and can get innocent people in trouble, too.
Next, pretending to be someone online can lead to fraud and scams, which ruin trust in online interactions. Bullying and trolling are also huge issues; they can cause a lot of emotional pain, especially for those who are already vulnerable. Lastly, using torrent sites often means stepping into copyright infringement territory, which deprives creators of their fair share and encourages piracy. All in all, these activities harm various people in the digital world.
Journal Entry Fifteen:
Davin Teo’s journey as a digital forensics investigator mixes tech know-how with insights from social sciences in some pretty interesting ways. Digital forensics isn’t just about pulling data out of devices; it’s also about understanding how people behave and the issues they face in society. In his TED talk, Davin likely touches on how important it is for investigators to combine their tech skills with an understanding of psychology to really get to the heart of things.
His work revolves around figuring out how people use technology and what their online actions can tell us about their deeper social or psychological patterns. It’s not just about tracking down digital clues; it’s also about thinking about the bigger picture—like what motivated someone, the context of a crime, and the digital trails we all leave behind.
Davin emphasizes why being a digital forensics investigator isn’t just about having tech skills; it’s about using a social science perspective to make sense of the data and connect the dots in ways that reflect real human behavior in our digital world.
It’s a really fascinating career path because it shows how technology, law, psychology, and sociology can come together. It highlights the potential of combining diverse skills to create a real impact on society.