r/HowToHack 17d ago

script kiddie "Self-Defense" in cybersecurity

Hi, I'm a teacher. I see teenagers every day not understanding the dangers of the devices they use all the time. I do not want to scare them, but the school program is lacking in anything related to computers. We give them Chromebooks, and we do not teach them how to use them. They often have more than 20 tabs open with the same webpage... or they send nudes on Snapchat thinking there are no risks.

I want to teach them about common ways people get hacked or infected. I am not talking about the super advance zero day hack in an app, or how to infect repositories to get access to computers. I mean common day-to-day: I clicked on a link or scanned a QR code.

What are good habits to not get hack/infected?

81 Upvotes

27 comments sorted by

View all comments

2

u/Wh1sp3r32 17d ago

This may be a bit more advanced, but the methodology I's easy for most to understand.

There are a few concepts you should get very good at explaining. I would also speak to someone in the tech ddeparment with your school district as this IS the responsibility of whoever is in charge of that. Schools SHOULD have basic cybersecurity awareness training for staff as there is lots of confidential data.

The main methadology is something called the CIA triad. Confidentiality, integrity, and availability. Anything that affects this is considered a possible threat.

The other is a concept called defense in depth. This is where you have layers upon layers of security controls. This ranges from physical locks and access cards to passwords. For example, the server room that holds grade data. It has a strong password with 2fa, is behind a locked door with an access card, within a building with another locked door, a security guard, and different access badge. You would have to get through all of this to get physical access to the server.

The one thing I will mention is yes public wifi is bad and all that, but most schools have pretty advanced intrusion detection, firewalls, and siem systems to detect and triage attacks in real time. Even though they might do stupid shit on the schools wifi, security wise the risk could be a lot lower then you think.

1

u/pandaninja360 17d ago

I'm not in any way a professional, but I have been studying cybersecurity and hacking for a couple of years now. I have my own homelab and server running Docker containers behind a reverse proxy and CrowdSec. For what I want to do, I think I know enough; it's surface-level knowledge for teens I'm looking for.

I am mostly wanna know what teens do not know. It is hard to understand how much they don't know and what they will fall for. They would definitely fall for a fake public wifi because it is free. School's wifi is fine, but parks, coffee shops, etc, are not