SlideShare a Scribd company logo
EMOTIONAL
SUPPORT
FOR
“48 HOURS OF
FAILURE”
(Dr?) Alex Dean Cybulski
Research Security Specialist
University of Toronto
ABOUT ME
Security research specialist
University of Toronto’s Information Security Division
Design strategy & policy for securing high performance computing clusters
Also:
Sociologist studying: information security, hacker culture and games
Former prof @ the University of Toronto Mississauga: Hacker Culture
CTF Team: the 212s
Documentarian: Cyberwar on Viceland (2016)
alexander.cybulski@utoronto.ca
@adcybulski on infosec.exchange the and the evil bird platform
20XX PRESENTATION TITLE 2
MY
RESEARCH
3 In-Person CTF Competitions
U.S. & Canada
200 hours of observation
100 hours of interviews
w/ CTF Designers & Players
230-page research report
Sim Cyberpunk: Serious Play, Hackers and Capture the Flag
20XX PRESENTATION TITLE 3
WHY DO
PEOPLE PLAY
IN CTFS?
20XX PRESENTATION TITLE 4
20XX PRESENTATION TITLE 5
I DIDN’T LEARN ANYTHING NEW
I DON’T THINK CTFS ARE FUN
I SPENT 8 HOURS SETTING UP A #@$
LINUX ENVIRONMENT ON MY LAPTOP
AND DIDN’T MEET ANYONE HIRING
I PLACED LAST IN THE DEFCON CTF
QUALIFIER
20XX PRESENTATION TITLE 6
20XX PRESENTATION TITLE 7
• I love CTF
• But it’s easy to quit when your first
competition goes poorly.
• CTF is so frustrating one of my
interview subjects, Pawel, referred to
playing in one as “48 hours of failure.”
• My goal with this talk is:
1. To teach you the stories that the
cybersecurity / hacking community tells itself
about CTF
2. To help you push through failure &
frustration & keep playing CTF
20XX PRESENTATION TITLE 8
• Learning, having fun and networking are stories
we tell ourselves about games. In sociology we
often say that play is “rationalized” we do it for
a reason – we have stories for why, how and to
what end we do certain things.
• CTF is “serious play” which means that we
have often rationalized doing something
(hacking, coding, cybersecurity) that is
laborious (like work), but for a specific reason
(leisure, socializing, professionalization)
• When those stories we tell ourselves about
doing something don’t line up with our
experiences doing that thing AND when play is
so much like doing work, we usually stop
• Why bother?
“FUNDAMENTALLY, YOU'RE WASTING YOUR TIME
WHEN YOU COULD BE READING PAPERS [LAUGHS
HARD]. AND THAT'S A THAT'S A FINE WAY OF
APPROACHING IT TOO.
-Tony (plays in 2-3 CTFs a month)
20XX PRESENTATION TITLE 9
WHY ARE CTFS ARE A POOR
LEARNING ENVIRONMENT
2023 CTF101 10
• CTFs are fundamentally competitions
• Winning is inherently rivalrous
• No hints
• Time-limited
• The expectation is that most players will come with the
knowledge they need to win
• “[CTF] organizers seldom offer to prepare competitors
for the event… it’s incumbent upon them [players] to
acquire the skills necessary to compete well” (p. 69) –
Chris Eagle
• A survey of 15 “vulnerability discovery” exercises (CTFs)
found that almost none satisfied basic pedagogical
goals (Votipka, Zhang & Mazurek, 2021)
• Challenges are heuristic
• They require us to know, or figure out something for
ourselves
CTF HISTORY
2023 CTF101 11
• The term CTF was coined in 1996 at the hacker conference
Defcon
• But Hackers have always been making games out of breaking
security controls
• CTF emerges out of a culture known as the computer
underground – pirates, hackers & phreakers (phone hackers)
• The original CTF was more like a skateboarding contest than
a game (no points, no rules, no scoreboard)
• Started out as a sideshow for a LAN party
• CTF was created to let hackers show off their skills
1. To impress their peers
2. And not get arrested in the process
• CTF was created a time when there weren’t a lot of jobs (1990s)
in information security
• So CTF isn’t necessary about work and/or learning
• It’s about impressing people
CTF CHALLENGES ARE DISCURSIVE
20XX PRESENTATION TITLE 12
• CTF challenges are created by subject matter experts
• These experts think that the problem at the heart of the challenge:
the method/methodology for vulnerability identification is interesting
or meaningful
• For the most part CTFs use ‘constructed’ vulnerabilities that do not
exist in the real-world
• If the problems were identical to real-world ones there would
be a lot of tools to automate their exploitation (Metasploit, for
example)
• So solving a CTF challenge involves analyzing problems using real-
world methods, methodologies and software
CTF CHALLENGES AS COMMUNICATION
2023 CTF101 13
• “CTF is really good to get you to learn about problems
that need solving” – Tim
• CTF challenges are about applying & demonstrating
problem solving skills & techniques
• Demonstrating the intellectual capital of players
• To the things that other people think are meaningful
(social capital)
• In playing, winners demonstrate expertise, they
demonstrate cultural capital – their ability to navigate
knowledge
• So playing in a CTF is about translating knowledge
through meaningful problems to create recognition
CTFS AS NAVIGATION & PRACTICE
2023 CTF101 14
• CTFs are a check on your knowledge of contemporaneous
problems
• Essentially your ability to navigate all of the knowledge that is
freely produced and circulated through hacker communities
• CTFs are a bad place to acquire new knowledge
• But they are great for refining existing skills:
• “It's just learning, getting better, getting better at all those
exploitation [and] reversing tasks.” – Holden
• It’s a “style of thinking” where” the tools and skills you use to
solve the problem tend to be the same ones you would use to
solve a real-world problem.” - Jonah
TAKEAWAYS
CTF is a game about cybersecurity, sure, but really
it’s a form of communication, which translates local
knowledge (intellectual capital) into recognition
(cultural capital) and expertise (social capital)
CTFs aren’t great for traditional learning
(developing new skills)
But they are good at refining skills (practice),
understanding contemporaneous skills and building
a culture of cybersecurity for learners.
• This doesn’t mean if you want to learn you should quit and go
home!
• Just don’t be discouraged if/when you struggle! That’s normal.
20XX PRESENTATION TITLE 15
THANKS &
HAPPY
HUNTING
Alex Dean Cybulski
alexander.cybulski@utoronto.ca
@adcybulski
www.adcybulski.com
2023 CTF 16
WHO THIS TALK IS FOR
20XX CTF 101 17
• This talk assumes you know nothing, or a bit about CTF
• But want to know more
• You want to develop cybersecurity / hacking skills
• I provide some critiques of CTF
• But I do that to help you understand what you’ll get
out of participating
• My arguments are made based on observation & other
people’s experiences
• Blended with a little teaching theory
• But it’s worth saying: your experience may vary!
• The talk is largely non-technical
• But CTF is mostly non-technical
• Sociologists define things, they help us create
meaning and understand patterns
• Terms from economics, psychology and even
gaming are the product of ideas sociologists
created

More Related Content

PPTX
Red vs. Blue Why we’ve been getting it wrong for 25 years
PPT
HKUST Computer Science Festival 2013 - Seminar: Computer Science, Hacking and...
PDF
DIY Education in Cyber Security
PDF
LKCE18 Dimitar Bakardziev - Kanban Policy Game
PPTX
A Stranger in a Strange Land
PPTX
Emerging practices 2019 week 2
PPTX
2015 Arts Midwest Workshop: Embracing the Digital Age
PDF
SpringOne Tour: The Influential Software Engineer
Red vs. Blue Why we’ve been getting it wrong for 25 years
HKUST Computer Science Festival 2013 - Seminar: Computer Science, Hacking and...
DIY Education in Cyber Security
LKCE18 Dimitar Bakardziev - Kanban Policy Game
A Stranger in a Strange Land
Emerging practices 2019 week 2
2015 Arts Midwest Workshop: Embracing the Digital Age
SpringOne Tour: The Influential Software Engineer

Similar to Emotional Support for "48 hours of failure" (20)

PPT
Presentation
PPTX
20250408 RolandRust Societal Impact of AI .pptx
PDF
Military Flight Training - Digital Technology Disruption Ahead?
PDF
Special Topics Day for Engineering Innovation Lecture on Cybersecurity
PPT
Deep sec talk - Addressing the skills gap
PPTX
Computational Thinking - a 4 step approach and a new pedagogy
PPTX
Why schools must lead maker movement
PDF
Mind the gap : Is Norway Security Enough in Cyber Space
PDF
Let's Talk: fundamentals of conversational design
PPTX
Introduction of CTF and CGC
PDF
MITRE ATTACKcon Power Hour - January
PPTX
How to Succeed at Jobs That Don't Exist Yet (Workshop at Queens College-9/26/18)
PDF
Tech Talk @ Dev Bootcamp Chicago
PDF
A Survival Guide for Complex UX
PDF
Bells, Whistles and Digital Tools for the 21st Century Catechist
PDF
ChatGPT OpenAI Primer for Business
PDF
Creating Dynamic Critical Thinkers You Tube
PPTX
Emerging practices 2019 week 1
PDF
Content Strategists (CS Forum, London, UK)
PPTX
Cyber securityeducation may2015
Presentation
20250408 RolandRust Societal Impact of AI .pptx
Military Flight Training - Digital Technology Disruption Ahead?
Special Topics Day for Engineering Innovation Lecture on Cybersecurity
Deep sec talk - Addressing the skills gap
Computational Thinking - a 4 step approach and a new pedagogy
Why schools must lead maker movement
Mind the gap : Is Norway Security Enough in Cyber Space
Let's Talk: fundamentals of conversational design
Introduction of CTF and CGC
MITRE ATTACKcon Power Hour - January
How to Succeed at Jobs That Don't Exist Yet (Workshop at Queens College-9/26/18)
Tech Talk @ Dev Bootcamp Chicago
A Survival Guide for Complex UX
Bells, Whistles and Digital Tools for the 21st Century Catechist
ChatGPT OpenAI Primer for Business
Creating Dynamic Critical Thinkers You Tube
Emerging practices 2019 week 1
Content Strategists (CS Forum, London, UK)
Cyber securityeducation may2015
Ad

More from GDSC UofT Mississauga (20)

PDF
CSSC ML Workshop
PPTX
ICCIT Council × GDSC: UX / UI and Figma
PDF
Community Projects Info Session Fall 2023
PDF
GDSC x Deerhacks - Origami Workshop
PDF
Reverse Engineering 101
PDF
Michael's OWASP Juice Shop Workshop
PDF
MCSS × GDSC: Intro to Cybersecurity Workshop
PDF
PDF
Discord Bot Workshop Slides
PDF
Web Scraping Workshop
PDF
Devops Workshop
PDF
HTML_CSS_JS Workshop
PDF
DevOps Workshop Part 1
PDF
Docker workshop GDSC_CSSC
PDF
Back-end (Flask_AWS)
PDF
Full Stack React Workshop [CSSC x GDSC]
PDF
Git Init (Introduction to Git)
PPTX
Database Workshop Slides
PPTX
ChatGPT General Meeting
CSSC ML Workshop
ICCIT Council × GDSC: UX / UI and Figma
Community Projects Info Session Fall 2023
GDSC x Deerhacks - Origami Workshop
Reverse Engineering 101
Michael's OWASP Juice Shop Workshop
MCSS × GDSC: Intro to Cybersecurity Workshop
Discord Bot Workshop Slides
Web Scraping Workshop
Devops Workshop
HTML_CSS_JS Workshop
DevOps Workshop Part 1
Docker workshop GDSC_CSSC
Back-end (Flask_AWS)
Full Stack React Workshop [CSSC x GDSC]
Git Init (Introduction to Git)
Database Workshop Slides
ChatGPT General Meeting
Ad

Recently uploaded (20)

PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Modernizing your data center with Dell and AMD
PPTX
A Presentation on Artificial Intelligence
PDF
cuic standard and advanced reporting.pdf
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
Encapsulation theory and applications.pdf
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PDF
Approach and Philosophy of On baking technology
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
PDF
Electronic commerce courselecture one. Pdf
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Encapsulation_ Review paper, used for researhc scholars
Modernizing your data center with Dell and AMD
A Presentation on Artificial Intelligence
cuic standard and advanced reporting.pdf
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
The AUB Centre for AI in Media Proposal.docx
Understanding_Digital_Forensics_Presentation.pptx
Encapsulation theory and applications.pdf
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Digital-Transformation-Roadmap-for-Companies.pptx
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
Approach and Philosophy of On baking technology
Dropbox Q2 2025 Financial Results & Investor Presentation
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Unlocking AI with Model Context Protocol (MCP)
The Rise and Fall of 3GPP – Time for a Sabbatical?
How UI/UX Design Impacts User Retention in Mobile Apps.pdf
Electronic commerce courselecture one. Pdf
Build a system with the filesystem maintained by OSTree @ COSCUP 2025

Emotional Support for "48 hours of failure"

  • 1. EMOTIONAL SUPPORT FOR “48 HOURS OF FAILURE” (Dr?) Alex Dean Cybulski Research Security Specialist University of Toronto
  • 2. ABOUT ME Security research specialist University of Toronto’s Information Security Division Design strategy & policy for securing high performance computing clusters Also: Sociologist studying: information security, hacker culture and games Former prof @ the University of Toronto Mississauga: Hacker Culture CTF Team: the 212s Documentarian: Cyberwar on Viceland (2016) alexander.cybulski@utoronto.ca @adcybulski on infosec.exchange the and the evil bird platform 20XX PRESENTATION TITLE 2
  • 3. MY RESEARCH 3 In-Person CTF Competitions U.S. & Canada 200 hours of observation 100 hours of interviews w/ CTF Designers & Players 230-page research report Sim Cyberpunk: Serious Play, Hackers and Capture the Flag 20XX PRESENTATION TITLE 3
  • 4. WHY DO PEOPLE PLAY IN CTFS? 20XX PRESENTATION TITLE 4
  • 5. 20XX PRESENTATION TITLE 5 I DIDN’T LEARN ANYTHING NEW I DON’T THINK CTFS ARE FUN I SPENT 8 HOURS SETTING UP A #@$ LINUX ENVIRONMENT ON MY LAPTOP AND DIDN’T MEET ANYONE HIRING I PLACED LAST IN THE DEFCON CTF QUALIFIER
  • 7. 20XX PRESENTATION TITLE 7 • I love CTF • But it’s easy to quit when your first competition goes poorly. • CTF is so frustrating one of my interview subjects, Pawel, referred to playing in one as “48 hours of failure.” • My goal with this talk is: 1. To teach you the stories that the cybersecurity / hacking community tells itself about CTF 2. To help you push through failure & frustration & keep playing CTF
  • 8. 20XX PRESENTATION TITLE 8 • Learning, having fun and networking are stories we tell ourselves about games. In sociology we often say that play is “rationalized” we do it for a reason – we have stories for why, how and to what end we do certain things. • CTF is “serious play” which means that we have often rationalized doing something (hacking, coding, cybersecurity) that is laborious (like work), but for a specific reason (leisure, socializing, professionalization) • When those stories we tell ourselves about doing something don’t line up with our experiences doing that thing AND when play is so much like doing work, we usually stop • Why bother?
  • 9. “FUNDAMENTALLY, YOU'RE WASTING YOUR TIME WHEN YOU COULD BE READING PAPERS [LAUGHS HARD]. AND THAT'S A THAT'S A FINE WAY OF APPROACHING IT TOO. -Tony (plays in 2-3 CTFs a month) 20XX PRESENTATION TITLE 9
  • 10. WHY ARE CTFS ARE A POOR LEARNING ENVIRONMENT 2023 CTF101 10 • CTFs are fundamentally competitions • Winning is inherently rivalrous • No hints • Time-limited • The expectation is that most players will come with the knowledge they need to win • “[CTF] organizers seldom offer to prepare competitors for the event… it’s incumbent upon them [players] to acquire the skills necessary to compete well” (p. 69) – Chris Eagle • A survey of 15 “vulnerability discovery” exercises (CTFs) found that almost none satisfied basic pedagogical goals (Votipka, Zhang & Mazurek, 2021) • Challenges are heuristic • They require us to know, or figure out something for ourselves
  • 11. CTF HISTORY 2023 CTF101 11 • The term CTF was coined in 1996 at the hacker conference Defcon • But Hackers have always been making games out of breaking security controls • CTF emerges out of a culture known as the computer underground – pirates, hackers & phreakers (phone hackers) • The original CTF was more like a skateboarding contest than a game (no points, no rules, no scoreboard) • Started out as a sideshow for a LAN party • CTF was created to let hackers show off their skills 1. To impress their peers 2. And not get arrested in the process • CTF was created a time when there weren’t a lot of jobs (1990s) in information security • So CTF isn’t necessary about work and/or learning • It’s about impressing people
  • 12. CTF CHALLENGES ARE DISCURSIVE 20XX PRESENTATION TITLE 12 • CTF challenges are created by subject matter experts • These experts think that the problem at the heart of the challenge: the method/methodology for vulnerability identification is interesting or meaningful • For the most part CTFs use ‘constructed’ vulnerabilities that do not exist in the real-world • If the problems were identical to real-world ones there would be a lot of tools to automate their exploitation (Metasploit, for example) • So solving a CTF challenge involves analyzing problems using real- world methods, methodologies and software
  • 13. CTF CHALLENGES AS COMMUNICATION 2023 CTF101 13 • “CTF is really good to get you to learn about problems that need solving” – Tim • CTF challenges are about applying & demonstrating problem solving skills & techniques • Demonstrating the intellectual capital of players • To the things that other people think are meaningful (social capital) • In playing, winners demonstrate expertise, they demonstrate cultural capital – their ability to navigate knowledge • So playing in a CTF is about translating knowledge through meaningful problems to create recognition
  • 14. CTFS AS NAVIGATION & PRACTICE 2023 CTF101 14 • CTFs are a check on your knowledge of contemporaneous problems • Essentially your ability to navigate all of the knowledge that is freely produced and circulated through hacker communities • CTFs are a bad place to acquire new knowledge • But they are great for refining existing skills: • “It's just learning, getting better, getting better at all those exploitation [and] reversing tasks.” – Holden • It’s a “style of thinking” where” the tools and skills you use to solve the problem tend to be the same ones you would use to solve a real-world problem.” - Jonah
  • 15. TAKEAWAYS CTF is a game about cybersecurity, sure, but really it’s a form of communication, which translates local knowledge (intellectual capital) into recognition (cultural capital) and expertise (social capital) CTFs aren’t great for traditional learning (developing new skills) But they are good at refining skills (practice), understanding contemporaneous skills and building a culture of cybersecurity for learners. • This doesn’t mean if you want to learn you should quit and go home! • Just don’t be discouraged if/when you struggle! That’s normal. 20XX PRESENTATION TITLE 15
  • 16. THANKS & HAPPY HUNTING Alex Dean Cybulski alexander.cybulski@utoronto.ca @adcybulski www.adcybulski.com 2023 CTF 16
  • 17. WHO THIS TALK IS FOR 20XX CTF 101 17 • This talk assumes you know nothing, or a bit about CTF • But want to know more • You want to develop cybersecurity / hacking skills • I provide some critiques of CTF • But I do that to help you understand what you’ll get out of participating • My arguments are made based on observation & other people’s experiences • Blended with a little teaching theory • But it’s worth saying: your experience may vary! • The talk is largely non-technical • But CTF is mostly non-technical • Sociologists define things, they help us create meaning and understand patterns • Terms from economics, psychology and even gaming are the product of ideas sociologists created