Topic - Human Error, Mistakes, Accidents and Disasters
- This week = Fog of War
- Next week = The China syndrome -> EXAM film
When something goes wrong, what is the root cause?
- Root cause analysis
1. User error (human error) -> hero & villain
2. Culture
3. ? -> the actual cause
- “Last touch” -> blame the person who last touched it. The last person through the door -> puppy analogy
- Honesty -> Commander in Cheat & University Honour Code
- Mis-direction and limited focus and Chekhov 1
-> limited focus, social engineers and magicians utilise this
- Frequency gambling - “what has worked in the past will work in the future”
- Availability heuristic - Kahneman 3
“Habit diminishes the conscious attention with which our actions are performed” - William James 1980
- His obsession: “those factors which lead to and sustain wishful thinking rather than wise thinking”
- Satisficing and bounded rationality
- People prefer positive statements
- Marshmallow analogy - “forget about the marshmallow” only tests at the end - toy train analogy
- Overriding technology to verify generalisations rather than falsify them -> “The human understanding when it has once adopted an opinion draws all things else to support and agree with it” - Francis Bacon 1620
- Confirmation bias - orientation analogy
- Cognitive strain
- Group-think syndrome -> what you value more than anything is to belong in a group rather than challenge things
- Developmental phases:
1. Procedural
2. Meta-procedural
3. Conceptual
- Redundancy = common mode failure
- Common mode failure = one thing cause another thing to fail
SYSTEMS
Cassandra and Apollo and hindsight and Chekhov and simplification
- Cassandra and Apollo -> always see the future (gift) she burned him so he tainted the gift... “no one will ever believe you”
- Hindsight
- Chekhov Gun -> if there is something noticeable then it is going to be used
-> belief event has only one significant cause
-> plan for fewer contingencies than occur
-> ability to control outcomes -> the illusion of control
-> hindsight bias = knowledge of outcome of previous event increases perceived likelihood of that outcome
- Complexity coherence coupling visibility 5
- Defense in depth
- Operator deskilling due to Automatic safety devices
- Common mode failures
- Latent vs active failures
- Kings Cross and Herald for free enterprise 6
- Normal accidents
1. a story (made up)
2. a story (real)
“Dead Battles like dead generals hold the military mind in their dead grip, and Germans, no less than other peoples prepare for the last war.” - Barbara Tuchmann
JUST CULTURE:
Research one of the following:
- Chernobyl
- Bhopal
- Challenger
-> right to be free of undue surveillance
Methods of surveillance:
- Lighter method
- Incognito mode -> stops cookies - not very effective
- Privacy focused browsers -> Duck Duck Go
- Take care of your accounts -> log out when you can, don’t sign up with
other accounts and LIE!
- Heavier method:
- VPN (https://openvpn.net) -> have to trust the VPN provider - based on
whether or not they store data logs
- Onion Routing (3 layers)
- Problems:
- Using it and then logging into a website violating client-server anonymity
- Timing attack
“Equivalent to saying you don’t care about free speech because you have nothing to say” - Edward Snowden
- Express VPN - google “where am I” incognito
Should I be concerned? -> Imbalance of Power
- Branch of forensic science
- Stages:
1. Acquisition/imaging
2. Analysis
3. Reporting
- Types:
- Computer Forensic
- Mobile Device
- Network Forensics
- Database Forensics
- Video/Audio Forensics
- Tooling:
- enCase
- Autopsy
- Drives and portioning (FAT32) -> https://...
- WriteBlocker to stop the disk from being changed
- Hash it so you can know if it has been changed
Normal Accidents - Three Mile Island
-> imagine, new complex technology not a nuclear reactor
-> numerous things that went wrong
Normal accident = a system will undoubtedly fail -> when they do go wrong make sure that the impact will be minimised
UNSW Breach Advice:
1. Determine most important assets and protect those
2. Assume you are going to be breached but set it up so the damage will be minimised
-> prepare 2 different media releases
-> don’t hold on to valuable data