knowledge

So you wanna be a hacker?

Occasionally I meet people who thinks being a hacker is a romantic endeavor. And often, they are interested in learning how to become a hacker themselves.

My answer is usually that it takes a lot of hard work, great interest and patience. Since most people - at least the wannabe hackers - do not realize what hard work means, thinking they have a great interest, and just forgets about patience, they push on:

"Oh, tell me, how can I learn to hack?! Can you teach me? Please, please, pretty please!!!"

I guess you know what I mean.

Most of the time I just tell them to learn how to use the computer, and then get back to me. But some are more persistent than others. And that is when I tell them to set up a *ux box to play around with. And when they get back to me and want me to teach them *ux...

Of course, I cannot let them know that although I have been playing with *ux since 1994/1995, I hardly know my way around. In their eyes, I am still the GOD of computers, and who would want them to think otherways?

So, instead of embarrasing myself, I point them to some of my secret resources - like this one. It makes Linux for Dummies look like a book for doctorates. Almost. After all, I can only dream of them actually buying a book and study...

I don't know much, but I know that only by learning and practicing can you develop your skills. So, if you wanna be a hacker, start practicing!

,

Playing with old computers

As with many IT-people who are no longer in the 20s, I have been playing around with hardware and software back in the young years. You know, building computers, soldering bits & pieces, hacking code, trying to get Linux running on a MCA-bus IBM...

And as many of my colleagues and peers, I am still getting my hands dirty from time to time. I guess it is the masochist in me.

Last night I was playing around with battered, old computers. Except. They where not that old. One where only 6 months old. And it should not be experiencing hick-ups, halts and driver problems. Usually.

This particular computer was residing in the reception. Many different users - non with any special computer related abilities - would use it over the week. And it had one major, business critical application inside - the booking system.

They had experienced hick-ups over some time now, and although I usually prefer not to get my hands dirty anymore, I decided to step back in time and sniff the dust. And I did the good'ol trick of removing everything (including the mainboard), and blow it all clean. Well, at least I would have if I had had some pressurized air at hand. After giving the components and the box itself a nice clean, the bits and pieces was put back in.

And to no surprise, there where a few things left over. I am a minimalist, and do not believe in using the computer cases as storagerooms, so I removed unused cards and other bits that no longer was of any use.

As I suspected, the computer came back to life, and works a dream. At least for now. Because this very computer was bought by people with no clue when it comes to computers. They had a need, went to the nearest superstore, and just bought a computer. Now, they did decide that this was a business critical computer, and thus made sure not to buy the cheapest one in the store...

But. They had no clue what-so-ever when it came to what makes a good business computer. And as you may have guessed allready, they came back with an overpriced piece of hardware, in combination with Microsoft XP Home edition. I repeat that. Microsoft XP Home edition. For a business critical computer.

I have made them all write one houndred times on a board: "I will never, ever again buy MS XP Home Edition."

And why is that? Why should you not use the home edition for business? It is all in the name. Home is not Business. Not even if you run a home-based business. The Home edition is a cheaper, less reliable and less sturdy OS than its brother XP Pro. Pro == Professional. Business == Professional.

Let me put this into monetary terms for you.

By choosing a cheaper OS like Home Edition, you may save a few bucks. In Norway, you save say 70$. But you buy yourself a large amount of it-related troubles, and will have to rely on an IT-consultant to help sort out all the troubles (face it, if you had the knowledge reqiured in the first place, you would never buy Home Edition. Period). And that IT-consultant does not come cheaply (if he does, he is not worth the money. Another period.). So the calculation I use in Norway is that you save $70, and that will be spent on the first half-hour of your IT-consultant.

By investing in a more sturdy OS, you may have to pay more to get going, but you will save money in the long run as you will not be required to dish out cash to IT-consultants every week.

Particularly when it comes to environments where there are a number of people involved would you do wisely to ensure that you get advises from people who understand the technology, and that can help you make the right decisions. It may cost a bit more to get going, but doing it right the first time is a huge cost and time saver in the long run.

Lets get back to the computer for a second. This computer was bought in February 2008 - so it is what I would call new. But during these months, it has already cost way more to operate and to keep it operating than the cost to buy it. And I have not even considered the cost of lost business when it was not operating, the stress on the not-so knowledgeable users and so on and so forth.

My advice to you if you are considering buying computers for your business are as follows:

  • get someone who KNOWS for real to help you choose the right solution (ie. do not just pop down to the nearest superstore - pay a bit more and use a specialized IT-supplier)
  • Saving up front usually only serves to increase the costs in the long run. See the first bullet...
  • It is not enough to not buy the cheapest thing in the store - you need to understand what you are getting. See bullet 1.
  • Give the users propper training. People who unpluggs the power to get the computer to shut down is a clear indication of the need for training. See bullet 1.
  • Have a backup solution at hand. That means that you need a second computer available so you can use that if the main one decides to die in your hands. See the first bullet. Yes, again.
  • Restrict the computer. That means someone who knows how to deal with computer (see the very first bullet) should enforce system policies (if you do not know what that means, see bullet one. If the people in bullet one have no clue, then you did not read bullet one, and just picked someone you know/from the top of Yellow pages.). The policies should enable the users to do what they need, and nothing more.
  • Before you do this, you need not to worry about virus, spam and other security threats, as you already have your hands full. It will not help to buy a firewall, a nice antivirus solution or a security scanner. You need the basics first. See bullet 1.
  • See bullet one.
And of course - please share your own advices. So many clueless entrepreneurs and people in general are messing around out there, so any advice will be valuable!





, , , ,

My secret to successful trainings

To facilitate training processes are something I truly enjoy. Particularly when I can enter a class where the energylevel is low, and the participants expects to be handed tasks to work with.

When you enter the room, you feel their lack of motivation. And no motivation usually means a tough day for both participants and the trainer. And if you want people to learn new skills, and hopefully to change their attitude towards the subject, you need them to be motivated.

This is particularly true when training security and user awareness. People act if the topic is as interesting as a piece of dead wood. I believe you me – I do not want to be that piece of wood!

Thus, one of my main focuses during a training is to build; and keep; the energy level high.

This can be done by using groupexercises, open discussions and by sharing of your own crazyness (and boy, can I be crazy!)

I build an environment where it is safe to ask questions and to wonder. A group where they support and help each other – even when I am no longer there. Because only when the motivation and fun is present, can we focus on knowledge transferal. Where the participants get their learning experience. Where the actual message is conveyed, understood and put into use.

 

So now you know my secret to giving successful trainings!

Navigation

Recent comments

Recent blog posts


The blogger is Kai Roer, a European Information security professional.

View Kai Roer's profile on LinkedIn

Resources

Archive

Explore Security Bloggers Network (a FeedBurner Network)