{"id":3850,"date":"2015-10-21T19:36:12","date_gmt":"2015-10-21T19:36:12","guid":{"rendered":"http:\/\/really.zonky.org\/?p=3850"},"modified":"2015-10-21T19:37:20","modified_gmt":"2015-10-21T19:37:20","slug":"csi-cyber-hit-or-miss","status":"publish","type":"post","link":"https:\/\/really.zonky.org\/?p=3850","title":{"rendered":"CSI: Cyber: Hit or Miss?"},"content":{"rendered":"<p>\n\tSo there&#39;s this new TV series called &quot;<a href=\"https:\/\/en.wikipedia.org\/wiki\/CSI:_Cyber\">CSI: Cyber<\/a>&quot; (well technically it&#39;s new to me and the UK) which is all about an FBI cybercrime unit.&nbsp;\n<\/p>\n<p>\n\t<img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" height=\"208\" src=\"https:\/\/upload.wikimedia.org\/wikipedia\/en\/a\/a7\/CSI-Cyber-Logo.jpg\" width=\"367\" \/>\n<\/p>\n<p>\n\tAs it hapens cyber security (if you insist on calling it that) is something I know a bit about. And so this new TV series has two ways of amusing me &#8211; the normal entertainment that TV offers, and of course the chance at falling about laughing at the mistakes.\n<\/p>\n<p>\n\tIs it entertaining in the first sense? It&#39;s an American cop show with a bit of added &quot;tech&quot;, so to some extent it stands out of the American cop show crowd (or perhaps flood). So yes, it&#39;s mildly entertaining; nothing worth staying in for, but it will kill an hour that you&#39;re too tired to do anything more productive with.\n<\/p>\n<p>\n\tIn the second sense I mentioned &#8211; yes it&#39;s got that in spades.\n<\/p>\n<p>\n\tThe most obvious flaw is that everything happens too quickly. Analysing a malicious printer firmware as you plug in the USB disk that contains it? Not going to happen. Finding a zero-day exploit in a collection of IoT devices within an hour? Not going to happen. Hacking a municipal transport network whilst being driven around at furious speed? Well that&nbsp;<em>could<\/em>&nbsp;happen if you had already done it (they hadn&#39;t), but it isn&#39;t something you would really try.\n<\/p>\n<p>\n\tCausing a printer to burst into flames with a malicious firmware? I believe the possibility was jokingly mentioned a few years ago when printer firmware became a target for attack amongst the white hat community, but it was also mentioned that it was pretty unlikely as things like thermal cut-out units are isolated and hardwired &#8211; you can&#39;t turn them off.\n<\/p>\n<p>\n\tOr a malicious exploit causing a laptop battery to burn up; I&#39;m not saying that&#39;s impossible, but again battery pack microcontrollers are usually isolated from the computer they power.&nbsp;\n<\/p>\n<p>\n\tLabelling &quot;zero-day exploits&quot; as something that effects personal devices? Just plain daft, although the rest of the definition was Okay.\n<\/p>\n<p>\n\tIs this a problem? Well, sensible people will realise that this is all just&nbsp;<em>entertainment<\/em>&nbsp;and will not take it seriously. Indeed it may increase the realisation that criminals with IT skills (and governments) can cause nasty things to happen; even if this show highlights the wrong kind of nasty things.&nbsp;\n<\/p>\n<p>\n\tOf course the knuckle-dragging neanderthals (with apologies to the real <a href=\"https:\/\/en.wikipedia.org\/wiki\/Neanderthal\">Neanderthals<\/a>) who watch this show and pay attention (so perhaps there isn&#39;t much danger after all) will assume that everything this show demonstrates is for real. And starts panicing anytime someone whips out a copy of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Metasploit_Project\">metasploit<\/a>.&nbsp;\n<\/p>\n<p>\n\tI imagine I&#39;ll be saying: &quot;It&#39;s just&nbsp;<em>entertainment&quot;<\/em>&nbsp;many times over the years.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>So there&#39;s this new TV series called &quot;CSI: Cyber&quot; (well technically it&#39;s new to me and the UK) which is all about an FBI cybercrime unit.&nbsp; As it hapens cyber security (if you insist on calling it that) is something I know a bit about. And so this new TV series has two ways of <a href='https:\/\/really.zonky.org\/?p=3850' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"_share_on_mastodon":"0"},"categories":[4,12,489],"tags":[1351,1352],"class_list":["post-3850","post","type-post","status-publish","format-standard","hentry","category-it","category-media","category-security","tag-csi","tag-cyber","category-4-id","category-12-id","category-489-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"share_on_mastodon":{"url":"","error":""},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p1f2KI-106","_links":{"self":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/3850","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=3850"}],"version-history":[{"count":4,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/3850\/revisions"}],"predecessor-version":[{"id":3854,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/3850\/revisions\/3854"}],"wp:attachment":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=3850"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=3850"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=3850"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}