(Lecture:5) Exhaustive Guide to Network Security, Web Tracking, and Social Engineering
Course Logistics, Assignment Rules, and Memory Retention
Classroom Discipline Example:
In a past 8:00 AM Survey of Western Civilization history class, an instructor dealt with sleeping lfreshmen who took advantage of newfound freedom away from home by staying up late.
When students fell asleep in class, the instructor warned that it would not happen again.
During the following class period, when a student fell asleep, the instructor brought a water gun, soaked the student down, and kicked them out of class.
Canvas Assignment Requirements:
A podcast assignment is posted on Canvas focused on the concept of the Right to Repair (alongside secondary sections covering sustainability).
Notes must be handwritten unless an official accommodation is on file with the Accessible Education Center (AAC), in which case notes may be typed after email verification.
Notes must conclude with answers to three or four specific questions, which will directly guide the classroom discussion on Friday.
Pedagogical Reasons for Handwritten Notes:
Verification: Hand-writing notes verifies that the student actively sat down and completed the work personally.
Cognitive Retention: Numerous recent studies demonstrate that the mechanical effect of writing enhances memory retention compared to typing. Reliance on typing throughout grade school and high school represents a disservice to memory building.
AI Deterrence: Writing by hand makes it significantly more difficult to rely blindly on Artificial Intelligence (AI). Even if AI is used, mechanically transcribing the text forces the student to track and absorb the material.
Assignment Late Policy:
First 10 Minutes: Deducts per minute for the first past the deadline (e.g., turning work in at 8:01 AM or 8:02 AM avoids a full 10-point loss).
10 Minutes to 24 Hours Late: Submissions between and late suffer a flat deduction.
Subsequent Days: Submissions lose an additional for each subsequent day.
Maximum Late Window: Work can be turned in up to late for a maximum attainable score of . After , late work receives zero credit unless explicitly pre-approved.
Contemporary Topics Series and Announcement Structure:
Friday classes focus on contemporary IT and business topics outside the standard curriculum. Content from these discussions and podcasts is directly tested on exams.
Assignments are posted by Tuesday evening prior to Friday discussions.
Canvas announcements for past podcasts are cycled out to avoid confusion between required assignments, then consolidated into a summary announcement following Friday sessions.
Fundamentals of Web and Network Security
Distinction Between Internet and World Wide Web:
The capitalized term "Internet" refers to the overarching network supporting the World Wide Web (WWW), which hosts e-commerce, Learning Management Systems (Canvas), and administrative portals (Tech Express, Eagle Online).
Hypertext Transfer Protocol Secure (HTTPS):
Modern web browsers mandate HTTPS to display websites securely.
Navigating directly to an unencrypted IP address (such as Tennessee Tech's address) triggers explicit browser security warnings indicating an unsecure connection due to the absence of HTTPS.
IT terminology heavily relies on acronyms; understanding and defining these terms is essential for technical literacy and coursework evaluations.
Security Certificates and Cryptography:
HTTPS relies on a digital security certificate to establish secure communication between a client and a remote server.
Security certificates utilize cryptographic algorithms (programs designed to mathematically encrypt data) to verify identity and encrypt transit.
Cryptography Defined: Cryptography refers to the science of securing messages or information into formats that are mathematically complex and difficult for unauthorized parties to decipher.
Historical contexts of code-breaking include the WWII Enigma machine (analyzed by Alan Turing) and classic cipher mechanisms.
Unsecured websites (lacking HTTPS) carry severe security risks. Common vectors for unsecure sites include illegitimate video game ROM repositories (used with emulators) and dark-web or non-mainstream merchant platforms.
Man-in-the-Middle (MitM) Attacks:
Concept: An attack where an unauthorized third party positions themselves electronically between two communicating nodes to intercept, view, or modify data in transit.
Analogy: Equivalent to an individual in a classroom listening in on and observing a conversation between two people sitting directly in front of them.
Data Packets: Information transmitted over a network is divided into discrete chunks called data packets. MitM attackers capture and inspect these raw packets.
Web Tracking Mechanisms: Cookies, Session Storage, and Local Storage
Cookies Overview:
Cookies are small data files deposited onto a client computer via a web browser to track user activity, session state, and preferences.
Authentication and Convenience: Platforms like Amazon avoid forcing users to re-log in constantly because adding login friction costs quantifiable revenue per second. Instead, Amazon uses cookies to persist authentication.
If an attacker intercepts an unencrypted authentication cookie via a MitM attack, they can clone the user session and make unauthorized purchases or changes.
First-Party vs. Third-Party Cookies:
First-Party Cookies: Created and stored directly by the host domain visited (e.g., Tennessee Tech, Amazon, Instagram). Used for core functionalities such as preserving light/dark display mode preferences, maintaining items in a persistent shopping cart, and retaining user login sessions.
Third-Party Cookies: Added by external domains embedded within the visited site (primarily advertising and tracking networks).
Third-Party Tracking Mechanics: Platforms such as The Weather Channel site/app embed extensive third-party ad networks that deposit tracking cookies.
Higher Education Marketing Tracking Example: Higher education institutions utilize contracted third-party cookies to track visitors on
tntech.edu. If a prospective student visits two or three times, the system updates messaging to invite them for a campus visit. It also tracks if the user is cross-shopping competitor institutions (e.g., MTSU, TSU, ETSU, UT Knoxville) to build a competitive marketing profile.
Session Storage and Local Storage:
Modern web technologies that store larger volumes of data directly within the user's local browser environment without transmitting data to the server on every request.
Advantages over Cookies: Reduced network bandwidth overhead and lower direct exposure during standard HTTP requests, as data remains client-side until explicitly queried.
Practical Application (Tech Express): Tech Express stores custom portal themes (red, orange, green, purple, dark mode) and persistent authentication tokens within local storage.
Attendance Tracking Mechanism: Tech Express stores a unique numerical "Device ID" inside the browser's local storage. When a student scans an attendance QR code, this unique Device ID is retrieved and transmitted with the request to verify identity.
Security Vulnerabilities of Cookies and Web Storage
Cookie Security Risks:
Because cookies are transmitted to the remote server automatically with every HTTP request, they are exposed to server-side breaches, bad actors, and network interception if not protected by HTTPS.
Local Storage and Session Storage Risks:
Cross-Site Scripting (XSS): Web storage is vulnerable to XSS attacks, wherein malicious scripts are injected into trusted websites and executed on the client's browser.
Cryptojacking / Crypto Mining: Attackers use XSS to execute background cryptocurrency mining scripts (e.g., Bitcoin) on a user's machine, causing severe system slowdowns and rapid battery drain.
Lack of Native Encryption: Data in local and session storage is stored in plain text and is not natively encrypted or obfuscated.
Obfuscation Defined: Obfuscation involves scrambling or writing data in a format that is difficult for a human to visually parse (e.g., reversing letters like
passwordtowordpass), but it provides no true cryptographic security.Exploitation Risk: Anyone with physical or remote access to an unlocked browser can read local storage keys, copy authentication numbers or Device IDs, hijack sessions, modify account states, or drop enrolled classes.
Wi-Fi Protocols, Firmware Maintenance, and Cyber Threats
Wi-Fi Protected Access (WPA) Protocols:
WPA3 Standard: The modern Wi-Fi security standard requiring a simultaneous cryptographic handshake between the client device and the access point.
Handshake Mechanics: Identifiers change every microsecond, rendering traditional MitM packet interception ineffective against fully updated implementations.
Crack Timeframes: Decrypting fully updated WPA3 security algorithms requires of continuous compute power. Conversely, legacy protocols or unpatched router firmware can be cracked in less than .
Public Wi-Fi Risks:
Unencrypted or open public networks (such as those in hotels, McDonald's, Walmart, or Wendy's) expose users to malicious interception.
Rogue Access Points (Wi-Fi Pineapple): Attackers deploy portable hardware routers configured with SSID names matching public venues (e.g., "Wendy's Public Wi-Fi"). Unsuspecting users auto-connect, allowing the attacker to monitor all unencrypted traffic passed through the device.
Firmware Updates and Drone/Botnet Networks:
Consumer hardware (TP-Link, Google Nest) requires active firmware updates to patch security vulnerabilities.
Unpatched routers are compromised by automated scans and converted into "drone devices" (botnets).
Command-and-control networks use thousands of compromised consumer drone devices to launch large-scale cyberattacks against high-profile targets (including Microsoft, Meta, YouTube, and government networks).
Zero-Day Exploits:
Definition: A zero-day exploit is a computer software or hardware vulnerability that is unknown to the software vendor or the public, leaving for a patch to be developed before potential exploitation.
Market Value: Nation-states and independent security researchers spend millions of dollars acquiring zero-day exploits. High-value zero-days command values from hundreds of thousands to millions of dollars.
Stuxnet Case Study: A sophisticated virus targeting Windows operating systems was deployed against nuclear facilities in Iran. The virus utilized an unknown Windows zero-day exploit to manipulate programmable logic controllers, causing centrifuges used for uranium enrichment to over-speed and physically destroy themselves. This cyber-weapon was attributed to nation-state operations by Israel and the United States.
The Human Link: Social Engineering and Cyber Exploitation
Human Factor Vulnerability:
Human users represent the weakest point of failure in any information security architecture.
Shoulder Surfing:
Mechanics: Physically looking over an individual's shoulder or observing their screen and keyboard input in public spaces, classrooms, or via installed cameras to harvest passwords, PINs, and personal data.
Extension and Wallpaper Malware:
Users frequently compromise their own devices by installing third-party browser extensions (e.g., ad blockers like uBlock) or decorative desktop software (e.g., festive wallpaper themes) containing bundled malware.
Social Engineering Foundations:
Definition: The psychological manipulation of people into performing actions or divulging confidential information through confidence scams, perceived authority, or friendly persuasion.
Phishing: A primary social engineering delivery method designed to solicit credentials under false pretenses.
Pretexting Scams: Calling an IT Support Desk, pretending to be a colleague, and using gathered personal facts to persuade staff to reset a target's password or disclose employee identification numbers (e.g., T-Numbers).
Physical Impersonation: Wearing a hard hat, high-visibility vest, and driving a vehicle with a yellow strobe light allows unauthorized individuals physical access to secured facilities without challenge.
Johnson Hall Incident: A student walked into a packed auditorium of 80+ people in Johnson Hall at 11:00 AM on a Thursday during an active meeting. The individual walked to the front, bent behind the desk, unplugged a desktop computer, picked it up, and walked out. Because the individual acted with total confidence and authority, no one questioned the physical theft.
Kevin Mitnick Case Study:
Widely regarded as the pioneer or "godfather" of social engineering.
Mitnick bypassed technical firewalls primarily by calling telephone company employees, posing as a utility field repair worker, and convincing personnel to provide restricted operational access. These activities defrauded phone companies of millions of dollars.
During prosecution, legal hyperbole claimed Mitnick could "whistle into a payphone and launch nuclear missiles."
Following a 10-year prison sentence and a multi-year ban from accessing electronic devices or the Internet, Mitnick demonstrated live caller-ID spoofing on national television by placing a call that displayed as "The White House" on the host's telephone.
Phone Scams and Impersonation Case Study:
Caller ID Spoofing: Malicious actors manipulate caller ID data to impersonate law enforcement or government entities (e.g., Putnam County Sheriff's Office, FBI).
Putnam County Educator Case Study:
A schoolteacher received a spoofed call appearing from the FBI claiming an active arrest warrant existed for tax fraud.
The bad actors coerced her into absolute secrecy under threat of immediate physical arrest.
Over three consecutive days, the victim took out a second mortgage on her home, drained her bank accounts, secured title loans on her vehicles, and obtained personal loans, remaining on a continuous phone call via an AirPod.
The victim lost approximately before the financial destruction was discovered by her spouse via bank inquiries regarding the secondary mortgage.
Core Guidelines for Safe Browsing and Security Hygiene
Safe Browsing Standards:
Validate Encryption: Ensure websites use active HTTPS encryption verified by the padlock icon in the address bar before entering credentials or sensitive data.
Cookie Management: Restrict cookie acceptances strictly to essential or required cookies (facilitated by EU data privacy regulations).
Firmware and Patch Management: Maintain automated system software updates across all local operating systems, applications, and network routing hardware.
Operational Vigilance: Maintain continuous skepticism regarding unexpected communications, authority-based urgency, unsolicited credential reset requests, and public network usage.