
Sign up to save your podcasts
Or


About our Guest:
Sinead Tuite
Innovation, Science and Economic Development (ISED) Canada
https://www.ic.gc.ca/eic/site/icgc.nsf/eng/home
Papers or resources mention in this episode:
Safeguarding your Research
This website provides information on how to safeguard your research and innovation.
https://science.gc.ca/eic/site/063.nsf/eng/h_97955.html
The Government of Canada's National Security Guidelines for Research Partnerships
https://science.gc.ca/eic/site/063.nsf/eng/h_98257.html
The US Government's Executive Order on Improving the Nation’s Cybersecurity
https://www.whitehouse.gov/briefing-room/presidential-actions/2021/05/12/executive-order-on-improving-the-nations-cybersecurity/
The UK Centre for the Protection of National Infrastructure (CPNI) Trusted Research Guidance for Academia
https://www.cpni.gov.uk/trusted-research-academia
Australia's Cybersecurity Strategy 2020 (Section 40, Page 23)
https://www.homeaffairs.gov.au/cyber-security-subsite/files/cyber-security-strategy-2020.pdf
About our Guest:
Dr Victoria Lemieux
https://ischool.ubc.ca/profile/victoria-lemieux/
Dominic Vogel
https://ca.linkedin.com/in/domvogel
cyber.sc
Papers or resources mention in this episode:
Lemieux, V. L. (2022). Searching for Trust: Blockchain Technology in an Age of Disinformation. Cambridge University Press.
https://www.cambridge.org/core/books/searching-for-trust/B2F64551393899EBC6306EB42FCBE856
Lemieux, V. L., & Feng, C. (2021). Building Decentralized Trust. Springer International Publishing. https://doi. org/10.1007/978-3-030-54414-0.
https://www.researchgate.net/profile/Victoria-Lemieux/publication/350180597_Multidisciplinary_Blockchain_Research_and_Design_A_Case_Study_in_Moving_from_Theory_to_Pedagogy_to_Practice/links/60a542afa6fdcc3f30b5cbb4/Multidisciplinary-Blockchain-Research-and-Design-A-Case-Study-in-Moving-from-Theory-to-Pedagogy-to-Practice.pdf
Other:
Here is the oldest surviving record of the 60% of hacked SMBs go bankrupt claim,
https://docs.house.gov/meetings/SM/SM00/20150422/103276/HHRG-114-SM00-20150422-SD003-U4.pdf
National Cyber Security Alliance (NCSA) Statement Regarding Incorrect Small Business Statistic
https://staysafeonline.org/press-release/national-cyber-security-alliance-statement-regarding-incorrect-small-business-statistic/
60% of Hacked Small Businesses Fail. How Reliable Is That Stat?
https://www.bankinfosecurity.com/blogs/60-hacked-small-businesses-fail-how-reliable-that-stat-p-2464
The fact that we can't find who is responsible for these numbers is kind of the point of having record keeping.
Just to put this claim in context in 2015 the US had 28.8 million Small businesses (https://www.sba.gov/sites/default/files/advocacy/United_States.pdf)
If half of those businesses were hacked, as claimed that would be 14.4million Breaches. If 60% of those went out of business, that would be 8.64 million businesses folding, which you might expect would be noticed economically. In particular, it would mean that around half of the US population lost their job. I suspect that we might have noticed that.
About our Guests
Dr Asier Moneva
https://asiermoneva.com/
Dominic Vogel
https://ca.linkedin.com/in/domvogel
cyber.sc
Papers or resources mention in this episode:
Moneva, A., Leukfeldt, E.R. & Klijnsoon, W. Alerting consciences to reduce cybercrime: a quasi-experimental design using warning banners. J Exp Criminol (2022). https://doi.org/10.1007/s11292-022-09504-2
https://link.springer.com/article/10.1007/s11292-022-09504-2
Moneva, A., Leukfeldt, E. R., Van De Weijer, S. G., & Miró-Llinares, F. (2022). Repeat victimization by website defacement: An empirical test of premises from an environmental criminology perspective. Computers in Human Behavior, 126, 106984.
https://www.sciencedirect.com/science/article/pii/S0747563221003071
Miró-Llinares, F., & Moneva, A. (2020). Environmental criminology and cybercrime: Shifting focus from the wine to the bottles. The Palgrave handbook of international cybercrime and cyberdeviance, 491-511.
https://link.springer.com/content/pdf/10.1007/978-3-319-78440-3_30.pdf
Other
Hacker Mobility in Cyberspace and the Least Effort Principle: Examining Efficiency in the Journey to Cybercrime
https://osf.io/ufdp8
Bhuiyan, Johana (2022, 4 Apr) How can US law enforcement agencies access your data? Let’s count the ways, The Guardian, https://www.theguardian.com/technology/2022/apr/04/us-law-enforcement-agencies-access-your-data-apple-meta
Carcamo, Cindy (2022, 10 May) Immigration officials created network that can spy on majority of Americans, report says, Los Angeles Times, https://www.latimes.com/california/story/2022-05-10/report-immigration-officials-spying-on-majority-of-americans
About our guest:
You can find out more about the design team for Northsec at https://nsec.io/team/
Papers or resources mentioned in this episode:
Challenges from previous northsec competitions can be found here:
https://nsec.io/competition-write-ups/
In particular, we referred to this challenge:
https://github.com/JaneBdemented/NSEC2019_DEFEC8ED_Walkthroughs
Other:
If you want to have a try at CTF challenges, you can try this site from Carnegie Mellon University
https://picoctf.org/
You can also try this website for getting started with hacking techniques
https://www.hackthissite.org/
Jax was actually feeling ill during this interview but did it anyway, what a champion.
About our guests:
Dr Susanne van’t Hoff de Goede
https://www.thehagueuniversity.com/research/centre-of-expertise/details/centre-of-expertise-cyber-security#team
https://www.linkedin.com/in/susanne-van-t-hoff-de-goede-8057a98/
https://victimologie.nl/netwerkleden/susanne-van-t-hoff-de-goede/
Dominic Vogel
https://ca.linkedin.com/in/domvogel
cyber.sc
Papers or resources mentioned in this episode:
Van ’t Hoff-de Goede, S., Leukfeldt, R., Van der Kleij, R., & Van de Weijer, S. (2020). The online behaviour and victimization study: The development of an experimental research instrument for measuring and explaining online behaviour and cybercrime victimization. In M. Weulen Kranenbarg & R. Leukfeldt (Eds.), Cybercrime in Context. The human factor in victimization, offending and policing. Springer.
Van der Kleij, R., Van ’t Hoff-de Goede, S., Van de Weijer, S., & Leukfeldt, R. (2021). How safely do we behave online? An explanatory study into the cybersecurity behaviors of Dutch citizens. In M. Zallio, C. Raymundo Ibañez, & J.H. Hernandez (Eds), Advances in Human Factors in Robots, Unmanned Systems and Cybersecurity. AHFE 2021. Lecture Notes in Networks and Systems, vol 268. Springer, Cham. https://doi.org/10.1007/978-3-030-79997-7_30
Other:
We weren't able to include all of the discussion in the podcast, but there is an interesting discussion to be had around the relationship between theory and research method. Often this kind of discussion is around how a theory might shape the research methods that are chosen, in this case Dr van’t Hoff de Goede raised the issue of methods and theory reinforcing each other as the method provides proof of the theory and the theory provides valid application of the method. I am not a great discussant for this particular debate, but I would say that it provides an argument for a greater range of research methods being a component of strong science.
About our Guests:
Dr Tommy Van Steen
https://www.universiteitleiden.nl/en/staffmembers/tommy-van-steen#tab-1
Dominic Vogel
https://ca.linkedin.com/in/domvogel
cyber.sc
Papers or resources mentioned in this episode:
Van Steen, T., Norris, E., Atha, K., & Joinson, A. (2020). What (if any) behaviour change techniques do government-led cybersecurity awareness campaigns use?. Journal of Cybersecurity, 6 (1)
https://academic.oup.com/cybersecurity/article-abstract/6/1/tyaa019/6032830
Michie S, Richardson M, Johnston M, Abraham C, Francis J, Hardeman W, Eccles MP, Cane J, Wood CE. The behavior change technique taxonomy (v1) of 93 hierarchically clustered techniques: building an international consensus for the reporting of behavior change interventions. Ann Behav Med. 2013 Aug;46(1):81-95. doi: 10.1007/s12160-013-9486-6. PMID: 23512568.
https://pubmed.ncbi.nlm.nih.gov/23512568/
Canada Revenue Agency, Be Scam Smart – Tax Refund
https://www.youtube.com/watch?v=lGNb7JCElzY&list=PLWsWrJHQSlisHkd5uCkyfaO3x2h4P2rsq&index=2
Other:
The Behaviour Change Wheel organizes the taxonomy into a way that allows it to be used as a tool during the design and implementation of tools. You can find a presentation from Dr Susan Mitchie, presenting that approach in this video https://www.youtube.com/watch?v=2-KvaIsb0fM
Thanks to Domenic Vogel’s son for providing some background ambience during the interview. Its always amazing how the sound of a child playing helps adults to remember to play too.
About Our Guests:
Dr. David Maimon
https://news.gsu.edu/expert/david-maimon/
Dr. Joshua James
https://dfir.science/
Papers or resources mentioned in this article:
Maimon, D., Howell, C. J., Perkins, R. C., Muniz, C. N., & Berenblum, T. (2021). A Routine Activities Approach to Evidence-Based Risk Assessment: Findings From Two Simulated Phishing Attacks. Social Science Computer Review. https://doi.org/10.1177/08944393211046339
Maimon, D., Howell, C. J., & Burruss, G. W. (2021). Restrictive deterrence and the scope of hackers’ reoffending: Findings from two randomized field trials. Computers in Human Behavior https://www.sciencedirect.com/science/article/abs/pii/S0747563221002661
Other:
Dr Maimon mentions sending a link with a EULA or End User License Agreement. A EULA is a contract between a software producer and the eventual user of the product, specifying the terms and conditions of use.
The music for this episode is called “G0n3 Ph1sh1ng”. I do like a good metaphor.
One thou is 25 micrometres. Metric is more precise. In practice, I use both. Such is the joy of Canada.
You might get 40 rods to the hog’s head and like it that way; I respect that.
About our guests:
Dr. Marleen Weulen Kranenbarg
https://research.vu.nl/en/persons/marleen-weulen-kranenbarg
Dr. Joshua James
https://dfir.science/
Papers or resources mentioned in this article:
Weulen Kranenbarg, M., & Leukfeldt, R. (2021). Cybercrime in Context . Springer International Publishing.
https://link.springer.com/book/10.1007/978-3-030-60527-8
Weulen Kranenbarg, M., Ruiter, S., & Van Gelder, J. L. (2021). Do cyber-birds flock together? Comparing deviance among social network members of cyber-dependent offenders and traditional offenders. European Journal of Criminology, 18(3), 386-406.
Weulen Kranenbarg, M., van der Toolen, Y., & Weerman, F. (2022). Understanding cybercriminal behaviour among young people.
Weulen Kranenbarg, M., Ruiter, S., Van Gelder, J. L., & Bernasco, W. (2018). Cyber-offending and traditional offending over the life-course: An empirical comparison. Journal of developmental and life-course criminology, 4(3), 343-364.
Other:
The episode with Dr. David Decary-Hetu is episode 55, you can go back a couple of episodes to find that or look here: https://cybercrimeology.com/episodes/dark-data-scraping-studying-on-the-dark-web-publishing-on-the-open-web
I edited this episode a little more aggressively to get it down to 30 minutes, it may have lost a little of its smoothness, but it is concentrated goodness ;).
About our Guests
Dr Maria Grazia Porcedda
https://www.tcd.ie/research/profiles/?profile=mariagrp
Dr. Joshua James
https://dfir.science/
Papers or resources mentioned in this article:
Porcedda, M. G., & Wall, D. S. (2021, September). Modelling the Cybercrime Cascade Effect in Data Crime. In 2021 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW) (pp. 161-177). IEEE.
http://www.tara.tcd.ie/bitstream/handle/2262/97548/2021_Modelling_the_Cybercrime_Cascade_Effect_in_Data_Crime.pdf
The Cambridge Computer Crime Database (Maintained by Alice Hutchings )
https://www.cl.cam.ac.uk/~ah793/cccd.html
The Computer Evidence Database of Computer Misuse Act cases (Maintained by Michael Turner)
https://www.computerevidence.co.uk/Cases/CMA.htm
Other:
During the outro I managed to say "Mater data" instead of "Meta data". I don't think that mater data exists as a term but perhaps we will need it or something like it to describe the data that gave birth to other data. If we keep having to chase data back to its point of origin and it is being transformed and transferred by automatic processes we might well one day have deliberate conversations about mater data. That hasn't happened yet and in this case it was just another of my many mangled mispronunciations.
About our Guests:
Dr David Décary-Hetu
https://ddhetu.pubpub.org/
Dr. Joshua James
https://dfir.science/
Papers or resources mentioned in this article:
The Crim Archive.
https://www.crimrxiv.com/
Human Cyber-Centric Cybersecurity Partnership
https://www.hc2p.ca/
Ouellet, Marie; Décary-Hétu, David; and Bergeron, Andréanne, "Cryptomarkets and the Returns to Criminal Experience" (2022). CSLF Articles. 3. https://scholarworks.gsu.edu/ays_cslf_articles/3
David Décary-Hétu & Benoit Dupont (2012) The social network of hackers, Global Crime, 13:3, 160-175, DOI: 10.1080/17440572.2012.702523
Flamand, C., & Décary-Hétu, D. (2019). The Open and Dark Web. The Human Factor of Cybercrime, 34-50.
Other:
My husky voice is as a result of testing how much my lung capacity has degraded as a result of covid-19 with a short work through metre deep snow. Turns out it has degraded a lot. If you have wondered if show shoes are worth the hassle, they absolutely are.
From the publisher's feed