Thomas

Aaron C. Thomas

Professor Jacqueline Cano Diaz

ENC 1102

20 May 2025

Reading Response 2

        We are in the age of communication, and most of us are in communities where we are able to share ideas, ask questions and help educate each other. I’m personally a part of a few of these communities, but I initially had thought that researching was something only scientists had done. Reading through this chapter gave me a brand new perspective that helped me better understand that research, even if you don’t initially realize it, is something that is done in everyday spaces. The chapter states it best “you may have started because you had an interest that you wanted to pursue, and that interest developed into research” (Hemstrom & Anders 195). That sentence changed my perspective completely, and helped me realize that exploring a topic, asking different questions, and improving in any category can all be research, even if you don't realize it.

        One of the strongest examples of this is a research community that I'm a part of is Hack@UCF. Hack@UCF is an information security group that competes at a national level in both offensive and defensive security. I am majoring in Information Technology with a minor in Secure Computing and Networking (SCAN), and I have been involved in competitions, presentations, and various groups within the club. In this community people routinely share tools, techniques and most importantly advice on how to best meet their specific task. This information is shared through social applications such as Discord, blog posts, and GitHub repositories. This fits the exact criteria for a research community, we build off of each other's knowledge, senior members of the club mentor the novice members helping them understand more advanced concepts and tools. I think that back and forth conversation, that mutual sharing of ideas is a big part of what makes this a research community.

        The conversations that happen within this community are technical and hugely collaborative. Members within the club explore the different ways to ethically hack into different machines, how to defend machines from a variety of attackers and malicious actors, and what tools are best for the specific job or scenario. These collaborative discussions are rarely one-sided, they are usually back and forth, and during these discussions, any member nearby will give their feedback and ask different questions that offer different perspectives. I believe this shows how research communities “create and share information in a conversational way” (Hemstrom and Anders 189). I think the different modes of communicating these ideas changes from person to person, some spend their time making full fledged write ups and walkthroughs, some post different comments, and some members have gone as far as creating video essays. These varying genres ultimately lead to the same goal of improvement, sharing skills and solving problems.

        In terms of specific terms we use, and few would be “privilege escalation”,”post-exploitation”, and “born again shell”. To someone who has never had a glimpse inside of the community of information security, these words mean nothing, but to someone who is a part of our community, knowing what these mean and what they do are vital to your success. It is also harder to be a part of the conversation, knowing the terms within said community can enhance your ability to learn and pick up different skills.

In Hack@UCF, the most experienced and respected members are those on C3, the team within Hack@UCF who competes on a national level. Those who have the most competition wins, most experience, and most contributions within the specific group are people on C3. Certifications play a small factor in judging someone's knowledge within the community, but usually those who contribute often, compete often and help often are the most highly regarded. But the chapter reads that “what counts as expertise is determined by the members of a research community” and I feel as though our research community has deemed C3 members experts. (Hemstrom & Anders 191)

Hack@UCF operates on a code of ethics, given the nature of the club, malicious actors could use the information they gained from the community to do harm unto others, that's why each and every member has to agree to a code of ethics. This code of ethics is not only claiming that your actions are your own, but also that you will abide by the strict legal guidelines put in place by the U.S. Government. Breaking these rules, like attacking unauthorized systems, or stealing information that shouldn't have been accessed in the first place is unacceptable and can lead to expulsion from the club and from the University of Central Florida as a whole.

When I was looking through IEEE Security & Privacy, I noticed a lot of similarities between it and Hack@UCF. The articles are written by people within the industry already focusing their energy on current challenges within the field. They often take bits and pieces from each other's work, building their knowledge off of one another. In my future profession as a Blue Teamer, research is a constant state of being. Daily work within this profession consists of reading logs, investigating different alerts and keeping up to date on threats. Adjusting firewall configurations and automating incident response would be my weekly tasks and every so often presenting my findings that could improve security.

One question that I would pose to the class: How does a research community decide on who counts as an expert within their specific group, other than like a degree or a certain certificate? I feel like this is a very valid question because it poses the question of what really is an expert.