In a computer lab at the University of New South Wales (UNSW) sits a group of students clustered together in front of computers. They are united under a common goal - hacking for the sake of offensive security.
Photo: Fiona Lu
1. University Lecturers Are Teaching Hacking To Anyone Who Is Interested.
The lecturer of this Computer Science Engineering course, Fionnbharr Davies, taught hardcore computer science concepts to students interested in understanding “what the computer understands.”
Along with fellow lecturer Brendan Hopper, Davies secretly trained his students to recognise how they can break into systems, and how they could stop other hackers.
“Hacking is leveraging problems with someone else’s software that allows you to gain access, and then doing a little black magic to run their code,” he said. “We teach how computers actually work. Learning assembly can be incredibly useful for anyone, especially programmers. We teach debugging skills, which is when one of your programs has an issue you go track it down. I think that kind of offensive thinking we teach, like tactical thinking, is really important.”
2. You Can Participate In Hacking Competitions Around Australia
Since UNSW has won first, second and third place in the Department of Defense and Telstra’s Hackathon this year, the university has been portrayed as an institution creating the ‘world’s best hackers.’
However, Davies and Hopper’s ethical teaching copped criticism online. One person labeled their methods as unconventional, whereas others challenged the idea that hacking could be ethical. But both Davies and Hopper said the course is not designed to ensure students do the right thing.
Michael Zhou, a 20-year-old student, spent 24-hours experience completing the Hackathon. He was involved in hacking a simulated company, which was set up to test his problem-solving skills. Before Zhou could have access to everything on the computer, he opened an email that contained a set of instructions he had to configure.
“It was pretty fun. You stay in a room all night and try sort of bashing your head against it,” he said. “Suddenly you start realising things and then you get it.”
After Zhou participated in the Hackathon, he decided to teach his programming class the same important skills he picked up from this experience. Zhou also admitted what his opinion of ethical hacking changed. Currently, Michael is assisting companies in adopting policies and legal frameworks to prevent illegal hacking.
3. You Can Use Hacking To Help The Less Fortunate.
Dr Alana Maurushat of UNSW’s Cyberspace Law and Policy Centre saw hacking could be used to achieve political ends or for a particular cause. Dr Maurushat agreed that students could be taught to ethically and aggressively hack in the name of offensive security.
“While I can state as a lawyer that none of it is legal, many of the teachings and practices are ethical,” she said. “You cannot learn how to defend systems without being able to think like the cyber-attacker and in order to do this, you need to practice both attacking and defending.”
4. If You Are Caught For Hacking Illegally, The Law Says You’re A Criminal.
However Dr Maurushat warned hacking, regardless of motive or intent, are subject to criminal provisions. If caught, the law will enquire into the hacker’s motive, intent, and whether he or she profited from accessing confidential information.
“There are few forms of ethical hacking that promote ethical character,” she said. “Unless there is a method of articulating clearly the goals of the hack, and a code of ethics that it adheres to, then it can be determined.”
5. There Are Diverse Job Opportunities After Graduation.
Despite fears that universities are teaching students about hacking high-level security systems, Hopper believed this fear is based on drivel. The course was not designed to force them into making moral judgements. Instead, the purpose of UNSW teaching students hacking is to provide employment opportunities after graduation.
Hopper emphasised there is an increasing demand for graduates with certain skills, which universities are not teaching correctly.
“A lot of people say ‘This is security,’ and it’s actually encryption,” Hopper said. “Technical ability, the ability to attack stuff and break software, isn’t how you fix the problem. It takes technical know how that a lot of places don’t instill. Courses are moving away from computer science to IT which means they have less ability to do the hacking.”
Unlike other institutions, UNSW used public examples and group projects as educational activities. Last year Davies challenged a group of students to reverse engineer Cityrail tickets so they could read any ticket and the location it was purchased.
“It’s naughty in a sense that we shouldn’t be doing it but it’s not illegal,” Davies said. “This sort of stuff makes it real world. It’s intensely fun and really rewarding especially when they come first, second and third. It’s validation you are doing a good job at least compared to every other university.
Besides projects and competitions, Hopper and Davies objective was to show students how to break into security when hacking.
“Because people don’t know how to break into things they don’t think about security,” Hopper said. “I find as part of that when you actually show someone and get them to break in they understand it and can fix it, whereas when you don’t do that they just never understand.”
6. You Immediately Become More Employable.
Davies and Hopper is determined to expand their students’ skills by providing practical work for them to experience both “defending” and “attacking,” combined with actual theory increases their likelihood of employment.
“We are making our students more employable. We still teach more theory than any other theory based computer course. I work at a bank so I deal with a lot of people who do security like governments, policy and that side of IT. If they all stopped doing their job tomorrow, nothing would be less secure,” he said.
“Because what they are doing is absolute rubbish. There is no application for the real world. All the theory we do teach is real and can actually be mapped into the real world. Our course is more theory than practical because we teach people how to think, not ‘this is what you do.’”
7. You Can Become A White Hat Hacker Or A Black Hat Hacker.
There are two types of hackers in the world. That is, ‘white hat hackers’ and ‘black hat hackers.’ ‘White hats’ are ethical hackers who use their abilities for good and legal purposes and ‘black hats’ are unethical hackers who violate computer security for personal gain.
“The difference between white hat and black hat hacking…the line is really clear,” Hopper said. “If someone’s doing something they could get in trouble which they shouldn’t be caught, that’s black hat hacking."
In response to the media’s negative portrayal of hackers, Hopper slammed his critics. He said hackers could be ‘white hats.’ But there is 99.99 per cent of hackers are ‘black hats’ who hack on their own without being sponsored by a government or company.
“There’s a chance someone could go and use this information for unethical hacking,” he said. “But there’s a chance someone who doesn’t do this course could do the same thing. People do this all the time. By making them more aware we’re actually making them more likely they could get a legitimate job in security.”
8. You Don’t Need A Background Check To Learn Hacking.
Although the course does not have specific requirements that involve performing background checks on their students or a set of rules to bind them to act ethically, both lecturers are not worried they are creating a black hat army.
“I don’t think teaching people how to break into things will make them bad people,” Davies said. “Everyone is incredibly moral in the class.”
Hopper said in order to train someone to be a really good hacker it takes from half a decade to a decade and this cannot be accomplished in two one semester courses.
“Saying people being in the army is going to make people killers is a crazy argument,” Hopper said. “But essentially if people were going to be bad hackers, they would have chosen to do that before they got to university. If they get caught doing it, they go to gaol. So what does a fine or getting kicked out of university matter when you also go to gaol at the same time?”
9. People Are Scared Of Your Power.
Rawan Aliabouni, a victim of hacking, saw hacking differently. She said teaching hacking is dangerous because students could hack people while defending themselves.
“Especially if it’s someone that might not know you. Even if the people did know you, they can go and hack your Facebook,” she said. “They can look through all your private information, and conversations with other people. They can use this stuff against you.”
10. Hacking Can Be Learned Online For Free.
On the other hand, Charles Lu, a high school student, said it is how hacking is practiced that should be of concern. He said there are forums on the Internet, manuals and software anyone can use to learn hacking.
“It’s not about is it ethical that people can hack. There’s no definitive answer for it because each have different intentions and motives so it really depends on the person. But hacking is not a bad thing and that’s what we have to drill into people’s minds,” he said.
“Remember we are targeting computer enthusiasts so whether or not you provide a degree for it they have the ability at the end of the day. It is a hobby for them. It’s something they would experience alone.”