<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://adcybulski.github.io/feed.xml" rel="self" type="application/atom+xml" /><link href="https://adcybulski.github.io/" rel="alternate" type="text/html" /><updated>2024-11-04T09:07:56-08:00</updated><id>https://adcybulski.github.io/feed.xml</id><title type="html">Alex Dean Cybulski</title><subtitle>personal description</subtitle><author><name>Dr. Alex Dean Cybulski, MI, SSAP</name><email>a.d.cybulski at gmail dot com</email></author><entry><title type="html">Hacker Culture Reading Lists: Hackers and Intellectual Property</title><link href="https://adcybulski.github.io/posts/2021/03/2021-03-15-hacker-reading-lists-hackers-and-IP/" rel="alternate" type="text/html" title="Hacker Culture Reading Lists: Hackers and Intellectual Property" /><published>2021-03-15T00:00:00-07:00</published><updated>2021-03-15T00:00:00-07:00</updated><id>https://adcybulski.github.io/posts/2021/03/Hackers-and-IP</id><content type="html" xml:base="https://adcybulski.github.io/posts/2021/03/2021-03-15-hacker-reading-lists-hackers-and-IP/"><![CDATA[<h1 id="hacker-studies-reading-list-hackers-and-intellectual-property">Hacker Studies Reading List: Hackers and Intellectual Property</h1>

<p>This bibliography should give you a good start in investingating near and dear to hackers fond of free and open source software, but also some insight into considerations around piracy and the work of pirates in their interventions against copyright and intellectual property.</p>

<h2 id="reading-list">Reading List</h2>
<p>Benkler, Y. (2006). The wealth of networks: How social production transforms markets and freedom. Yale University Press.</p>

<p>Bretthauer, D. (2002). Open Source Software: A History. Information Technology and Libraries, 1(21), 3–10.</p>

<p>Coleman, G. (2013). Coding freedom: The ethics and aesthetics of hacking. Princeton University Press.</p>

<p>Groom, N. (2010). Unoriginal genius: Plagiarism and the construction of “Romantic” authorship. In L. Bently, J. Davis, &amp; J. C. Ginsburg (Eds.), Copyright and Piracy: An interdisciplinary critique. Cambridge University Press.</p>

<p>Kelty, C. (2008). Two Bits: The Cultural Significance of Free Software. Duke University Press.</p>

<p>Liang, L. (2011). Beyond Representation: The Figure of the Pirate. In G. Krikorian &amp; A. Kapczynski (Eds.), Access to Knowledge in the Age of Intellectual Property (pp. 353–376). Zone Books.</p>

<p>Maxigas. (2012). HackLabs and HackerSpaces: Tracing Two Genealogies. Journal of Peer Production, 2(2012).</p>

<p>Mueller, G. (2016). Piracy as Labour Struggle. TripleC: Communication, Capitalism &amp; Critique, 14(1). 333-345.</p>]]></content><author><name>Dr. Alex Dean Cybulski, MI, SSAP</name><email>a.d.cybulski at gmail dot com</email></author><category term="Reading lists" /><category term="Hacker culture" /><category term="Copyright" /><category term="Intellectual property" /><category term="Hacker Studies" /><summary type="html"><![CDATA[Hacker Studies Reading List: Hackers and Intellectual Property]]></summary></entry><entry><title type="html">Hacker Culture Reading Lists: Hacktivism</title><link href="https://adcybulski.github.io/posts/2021/03/2021-03-15-hacker-reading-lists-hacktivism/" rel="alternate" type="text/html" title="Hacker Culture Reading Lists: Hacktivism" /><published>2021-03-15T00:00:00-07:00</published><updated>2021-03-15T00:00:00-07:00</updated><id>https://adcybulski.github.io/posts/2021/03/Hacktivism-Reading-List</id><content type="html" xml:base="https://adcybulski.github.io/posts/2021/03/2021-03-15-hacker-reading-lists-hacktivism/"><![CDATA[<h1 id="hacker-studies-reading-list-hacktivism">Hacker Studies Reading List: Hacktivism</h1>

<p>This bibliography should give you a good start in investingating hacktivism and hacktivist practises, their politcs, etc.</p>

<h2 id="reading-list">Reading List</h2>
<p>Coleman, G. (2014). Hacker, Hoaxer, Whistleblower, Spy. Verso.</p>

<p>Di Salvo, P. (2017). “Coder,” “Activist,” “Hacker”: Aaron Swartz in the Italian, UK, U.S., and Technology Press. International Journal of Communication, 11, 1149–1168.</p>

<p>Gorham, A. E. (2020). Anonymous’s Glory. International Journal of Communication, 14, 3399–3417.</p>

<p>Jordan, T. (2002). Activism! : direct action, hacktivism and the future of society. Reaktion Books.</p>

<p>Sauter, M. (2014). The Coming Swarm: DDoS actions, hacktivism, and civil disobedience on the Internet. Bloomsbury Academic.</p>

<p>Schrock, A. R. (2016). Civic hacking as data activism and advocacy: A history from publicity to open government data. New Media &amp; Society, 18(4), 581–599. https://doi.org/10.1177/1461444816629469</p>

<p>Tanczer, L. M. (2015). Hacktivism and the male-only stereotype. New Media &amp; Society, 1–17.</p>]]></content><author><name>Dr. Alex Dean Cybulski, MI, SSAP</name><email>a.d.cybulski at gmail dot com</email></author><category term="Reading lists" /><category term="Hacker culture" /><category term="Hacktivism" /><category term="Hacker Studies" /><summary type="html"><![CDATA[Hacker Studies Reading List: Hacktivism]]></summary></entry><entry><title type="html">Hacker Culture Reading Lists: Hacking as Work: Precarity and Labour</title><link href="https://adcybulski.github.io/posts/2021/03/2021-03-11-hacker-reading-lists-labour/" rel="alternate" type="text/html" title="Hacker Culture Reading Lists: Hacking as Work: Precarity and Labour" /><published>2021-03-11T00:00:00-08:00</published><updated>2021-03-11T00:00:00-08:00</updated><id>https://adcybulski.github.io/posts/2021/03/Hacking-work-and-risk</id><content type="html" xml:base="https://adcybulski.github.io/posts/2021/03/2021-03-11-hacker-reading-lists-labour/"><![CDATA[<h1 id="hacker-studies-reading-list-hacking-as-work---precarity-and-labour">Hacker Studies Reading List: Hacking as Work - Precarity and Labour</h1>
<p>This reading list focusing on workers in high-tech industries. In particular it consider the working conditions and issues around labour, gender and race that are part of technology work.</p>

<h2 id="reading-list">Reading List</h2>
<p>Downey, G. (2003). Commentary: The Place of Labor in the History of Information-Technology Revolutions. International Review of Social History, 48(S11), 225–261. https://doi.org/10.1017/S0020859003001330</p>

<p>Duffy, B. E. (2018). Not Getting Paid to Do What You Love (Vol. 1). Yale University Press. https://doi.org/10.12987/yale/9780300218176.003.0001</p>

<p>Dunbar-Hester, C. (2020). Hacking Diversity: The Politics of Inclusion in Open Technology Cultures. Princeton University Press.</p>

<p>Irani, L. (2015). Hackathons and the making of entrepreneurial citizenship. Science, Technology, &amp; Human Values, 40(5), 799–824.</p>

<p>Neff, G. (2012). Venture Labor. MIT Press.</p>

<p>Turner, F. (2009). Burning Man at Google: A cultural infrastructure for new media production. 11(1 &amp; 2), 73–94.</p>]]></content><author><name>Dr. Alex Dean Cybulski, MI, SSAP</name><email>a.d.cybulski at gmail dot com</email></author><category term="Reading lists" /><category term="Hacker culture" /><category term="Labour" /><category term="Risk" /><category term="Precarity" /><category term="Hacker Studies" /><summary type="html"><![CDATA[Hacker Studies Reading List: Hacking as Work - Precarity and Labour This reading list focusing on workers in high-tech industries. In particular it consider the working conditions and issues around labour, gender and race that are part of technology work.]]></summary></entry><entry><title type="html">Hacker Culture Reading Lists: Hacker History</title><link href="https://adcybulski.github.io/posts/2012/08/2020-03-11-hacker-reading-lists-history/" rel="alternate" type="text/html" title="Hacker Culture Reading Lists: Hacker History" /><published>2020-04-11T00:00:00-07:00</published><updated>2020-04-11T00:00:00-07:00</updated><id>https://adcybulski.github.io/posts/2012/08/hacker-reading-lists-history</id><content type="html" xml:base="https://adcybulski.github.io/posts/2012/08/2020-03-11-hacker-reading-lists-history/"><![CDATA[<h1 id="hacker-studies-reading-list-hacker-history">Hacker Studies Reading List: Hacker History</h1>
<p>Like the word hacker, the history of hackers and hacking is pretty diffuse and it is not particularly helpful to try to establish a totalizing point of origin.</p>

<p>As such, the history of hackers doesn’t fit neatly into a single book when there are diffuse hacker cultures based in computing, cybercrime and counter-culture. While MIT is often understood as the origin point of much of what is thought of as hacker culture, it is worth de-centering the campus to identify alternative hacker cultures and use their histories to contrast values and material contributions to the idea of hackers broadly.</p>

<h2 id="reading-list">Reading List</h2>
<p>Bretthauer, D. (2002). Open Source Software: A History. Information Technology and Libraries, 1(21), 3–10.</p>

<p>Brunton, F. (2013). Spam: A shadow history of the internet. MIT Press.</p>

<p>Levy, S. (2010). Hackers (1st ed). O’Reilly Media.</p>

<p>Menn, J. (2019). Cult of the Dead Cow: How the original hacking supergroup might just save the world. PUBLIC AFFAIRS.</p>

<p>Middleton, B. (2017). A History of Cyber Security Attacks: 1980 to Present. Auerbach Publications.</p>

<p>Peterson, T. F. (2011). Nightwork: A history of hacks and pranks at MIT. MIT Press.</p>

<p>Pettis, B. (2008, June 28). The Chaos Computer Club 1981-1984 » NYC Resistor. NYCResistor. https://www.nycresistor.com/2008/06/28/the-chaos-computer-club-1981-1984/</p>

<p>Pettis, B. (2008, July 4). Cats, Dataloos, and a BTX Bank Robbery – The CCC in 1984 » NYC Resistor. NYCResistor. https://www.nycresistor.com/2008/07/04/cats-dataloos-and-a-btx-bank-robbery/</p>

<p>Sterling, B. (1993). The hacker crackdown: Law and disorder on the electronic frontier. Bantam.</p>

<p>Thomas, D. (2002). Hacker culture. University of Minnesota Press.</p>

<p>Turkle, S. (1984). The Second Self: Computers and the Human Spirit (Twentieth Anniversary Edition). MIT Press.</p>

<p>Wasiak, P. (2012). ‘Illegal Guys’ A History of Digital Subcultures in Europe during the 1980s. Studies in Contemporary History, 9, 257–276.</p>]]></content><author><name>Dr. Alex Dean Cybulski, MI, SSAP</name><email>a.d.cybulski at gmail dot com</email></author><category term="Reading lists" /><category term="Hacker culture" /><category term="History" /><category term="Hacker Studies" /><summary type="html"><![CDATA[Hacker Studies Reading List: Hacker History Like the word hacker, the history of hackers and hacking is pretty diffuse and it is not particularly helpful to try to establish a totalizing point of origin.]]></summary></entry><entry><title type="html">Hacker Reading Lists: Introduction to Hacker Culture</title><link href="https://adcybulski.github.io/posts/2020/03/Hacker-Reading-List-Intro/" rel="alternate" type="text/html" title="Hacker Reading Lists: Introduction to Hacker Culture" /><published>2020-03-10T00:00:00-07:00</published><updated>2020-03-10T00:00:00-07:00</updated><id>https://adcybulski.github.io/posts/2020/03/Hacker-Reading-List-Intro</id><content type="html" xml:base="https://adcybulski.github.io/posts/2020/03/Hacker-Reading-List-Intro/"><![CDATA[<h1 id="hacker-culture-reading-lists-introduction-to-hacker-culture">Hacker Culture Reading Lists: Introduction to Hacker Culture</h1>
<p>Hopefully this will be the first in a series of reading lists I’m compiling in March 2020 with the intention of documenting and expanding the bibliography of works included as part of hacker studies.</p>

<p>As a PhD candidate who struggles to think about the literature contemporaneously, and as someone with lots of training as a historian I am also stuck thinking about studies of hackers and their culture historiographically: in that case I am very interested in how writings and understandings of hackers has changed over time. Literature on hackers streches from the 1980s to present day, but along the way there are waves of hacker-interested academic work that is often unknown, excluded or hard to find because it doesn’t fit popular or contemporary ontological considerations of hackers. For example, present-day theorizing of hackers tends to focus on their role as technology/political activists (F/OSS, Hacktivism) and their potential for inciting social change, but in the 90s through the early 2000s an overwhelming amount of the literature is fixated on hackers as cybercriminals. Comparatively, early lit from the 80s like Turkle and Levy are very interested in theorizing about the relationship between humans and computers as understood through the virtuosity of hackers. In many cases there are essays, books and articles that didn’t quite fit the dominant narrative of the day and I’ve rarely seen cited.</p>

<p>In other cases, I’m hoping to document some papers are just hard or difficult to find. Older papers often use weird keywords or outmoded, apochryphal language to describe hackers (e.g. “hacker underground,” “crackers,” “virus writers”). Other papers and writings I’ve collected might just be included because they are curiosities or neat historical artifacts (See Dorothy Denning’s paper in this list for a very forward thinking paper about early hackers in the security community). If nothing else, I’m hoping that these lists will prevent someone from getting a rude comment from reviewer #2 to effect of: “Egads ye plebian, have you not heard of XXXX (20xx)???” or “how DARE you say (TOPIC X) is understudied! Are you not familiar with …?”</p>

<p>This first list is purely for my own sake: I wanted to compile a short list of readings which I would consider to be useful for students studying hacker culture for the first time, or even just to share with another academic interested in how hackers are theorized.</p>

<h2 id="reading-list">Reading List:</h2>

<p>Coleman, G., &amp; Golub, A. (2008). Hacker practice: Moral genres and the cultural articulation of liberalism. Anthropological Theory, 8(3), 255–277.</p>

<p>Denning, D. E. (1990). Concerning Hackers Who Break into Computer Systems. 653–664. https://faculty.nps.edu/dedennin/publications/ConcerningHackers-NCSC.txt</p>

<p>Jordan, T., &amp; Taylor, P. (1998). A Sociology of Hackers. The Sociological Review, 46(4), 757–780.</p>

<p>Kelty, C. (2008). Two Bits: The Cultural Significane of Free Software. Duke University Press.</p>

<p>Levy, S. (2010). Hackers (1st ed). O’Reilly Media.</p>

<p>Peterson, T. F. (2011). Nightwork: A history of hacks and pranks at MIT. MIT Press.</p>

<p>Thomas, D. (2002). Hacker culture. University of Minnesota Press.</p>

<p>Turkle, S. (1984). The Second Self: Computers and the Human Spirit (Twentieth Anniversary Edition). MIT Press.</p>]]></content><author><name>Dr. Alex Dean Cybulski, MI, SSAP</name><email>a.d.cybulski at gmail dot com</email></author><category term="Reading Lists" /><category term="Hacker Studies" /><category term="Hacker Culture" /><summary type="html"><![CDATA[Hacker Culture Reading Lists: Introduction to Hacker Culture Hopefully this will be the first in a series of reading lists I’m compiling in March 2020 with the intention of documenting and expanding the bibliography of works included as part of hacker studies.]]></summary></entry><entry><title type="html">Technological Fetishization in Information Security</title><link href="https://adcybulski.github.io/posts/2019/09/blog-post/" rel="alternate" type="text/html" title="Technological Fetishization in Information Security" /><published>2019-09-04T00:00:00-07:00</published><updated>2019-09-04T00:00:00-07:00</updated><id>https://adcybulski.github.io/posts/2019/09/blog-post</id><content type="html" xml:base="https://adcybulski.github.io/posts/2019/09/blog-post/"><![CDATA[<p>While technologies play a pervasive role in information security, they can’t and won’t fix a shortage of practitioners.</p>

<h1 id="technological-fetishization-and-the-infosec-skills-shortage">Technological Fetishization and the Infosec “Skills Shortage”</h1>
<p>The overstated role of technology in information security is probably best exemplified by the current phase of hype around blockchain technologies. While a distributed and open ledger promised by blockchain does have some promise in improving the integrity and transparency of some record keeping systems, the costs associated with the use of this technology (computationally, energy use) and other social drawbacks makes implementation in what seem like useful applications (elections, financial transactions) unfathomable. The costs of running a blockchain would be both cost-prohibitive and socially unfathomable for how it would impact privacy in most use cases.</p>

<p>The absence of a clear-cut use case scenario has not stopped private interests and governments from touting their investment in these technologies to emphasize their interest in security and integrity. These kinds of investments far outstrip the educational investments made by governments and private organizations in providing security education for their citizens and employees.</p>

<p>To be clear, when I say a security education, I mean training a potential or existing practitioner in information security skills, not to provide digital literacy skills in the form of information security awareness. Don’t get me wrong: security awareness is important! But even if people aren’t clicking on phishing e-mails and using complex passwords there is still a lot of risk out there for information security practitioners to address.</p>

<p>The failure to invest in security education is likely why Canada and the rest of the world is entering into a significant “<em>“</em>cough”*” cyber-skills shortage, as it is frequently described. It would be more accurate to say that this shortage exists becuase</p>

<p>At present there is something like a 0.06% unemployment rate amongst information security professionals and it is projected that between 2017 and 2021 Canada will need to fill 8,000 infosec related roles - globally this number will probably look more like 3.5 million (this comparison is not unimportant). Looking at those same projections for how Canada’s infosec workforce has grown over time, it seems Canada will only be able to fill 3,200 of those roles. While achieving less than half isn’t helpful, it’s important to remember that global deficiet - information security work will reward a premium to skilled practitioners. So while many countries can’t offer the same social safety net or Justin Trudeau - they can offer high salaries and private healthare, diminishing returns for those projected 3,200 new workers.</p>

<h1 id="will-ai-fix-the-skills-shortage">Will AI Fix the Skills Shortage?</h1>
<p>It is presumed by many governments and organizations that new and innovative technologies will address this skills shortage. That technology like blockchain or AI will arrive fully-formed and start shoring up gaps in the defenses of strategic and economic interests. But this belief and its anticipation deeply betrays any understanding of how technologies work in information security and what role they play.</p>

<p>Look no further than 2-factor authentication (2FA) as a case where even a good technology can still fall down on its face. While the implementation of 2FA through phones has been largely concurrent with excitement arond blockchain technologies, it is an example of a practical tool that has not been subject to the same hype. 2FA has been succesful in providing some better security features for users than those without, but it is at best an incremental improvement. To bypass 2FA criminals have utilized a different vulnerability, attacking telecommuniucations providers to fraudelently obtain access to phone numbers for accounts protected by 2FA.</p>

<p>In this example 2FA didn’t fail, our telecommunications companies failed. Their failure significantly diminishes the efficacy and security gains of 2FA. Comparably, AI and blockchain technologies are nowhere near as practical or applied as 2FA. But even if (and that is a huge IF) AI or blockchain were implemented practically, how would we know that the systems they rely upon won’t fail utterly, leaving individuals, governments and businesses completely exposed? Who would pick up the pieces?</p>

<p>In information security marketing companies like Cylance tout that its machine learning technologies protect against malware and “even those types of malware that are unknown and never-before-seen, such as in the case of zero-days.” To suggest that a machine learning system could detect zero days is an incredibly brave thing to say in the infosec community. Not because it’s a deeply held conviction, but because such a bold claim opens the speaker up to ridicule for their overconfidence.</p>

<p>While I was at BSides Las Vegas this year, news broke that the software used by Cylance’s machine learning platform could be easily tricked into ignoring even the most common garden malware if it had been disguised in a fairly trivial manner. The vulnerability isn’t a small bug in Cylance’s software, but a fundamental problem in the way machine learning can be abused. The system it relies upon.</p>

<p>The idea that there are vulnerabilities in security software, their gaps and failures isn’t a new or novel concept. At a practitioner level the information security industry has many approaches to this problem. Ultimately, new technologies act as force-multiplier, but they aren’t a replacement for people on the ground maintaing the security of the systems they are entrusted with. At a recent Usenix Security Summity, haroon meer</p>

<p>Something I hope to explore in my thesis is how the technologies that are touted as a pancea are ultimately by practitioner knowledge and expertise on a daily basis. The work that prevents a systemic risk from becoming a systematic failure.</p>

<h2 id="links">Links</h2>
<p>[1] https://www2.deloitte.com/content/dam/Deloitte/ca/Documents/risk/ca-cyber-talent-campaign-report-pov-aoda-en.PDF
[2] https://www.herjavecgroup.com/wp-content/uploads/2018/11/HG-and-CV-Cybersecurity-Jobs-Report-2018.pdf
[3] https://www.bloomberg.com/opinion/articles/2019-05-03/blockchain-hype-missed-the-mark-and-not-by-a-little
[4] https://medium.com/@kaistinchcombe/decentralized-and-trustless-crypto-paradise-is-actually-a-medieval-hellhole-c1ca122efdech</p>]]></content><author><name>Dr. Alex Dean Cybulski, MI, SSAP</name><email>a.d.cybulski at gmail dot com</email></author><category term="technology" /><category term="information security" /><category term="fetishization" /><category term="labour" /><summary type="html"><![CDATA[While technologies play a pervasive role in information security, they can’t and won’t fix a shortage of practitioners.]]></summary></entry></feed>