Historical interview: The following preserves the research experiences and personal views expressed in the original manuscript.
PhDSciNet Interview Series
Cybersecurity, Part 1
In this rapidly expanding online world, are you leaving yourself exposed? Who builds the walls that protect us? As cybersecurity becomes increasingly important, how should we protect ourselves?
Academic background of the science presenter: doctoral research in cybersecurity.
What exactly does cybersecurity involve?
Chilled Foam: Cybersecurity mainly studies vulnerabilities in networked systems and works to strengthen them. Put simply, it is a confrontation between harmful actors and those trying to protect systems.
Hackers generally focus on vulnerabilities, such as weaknesses in networks or mobile apps. After finding them, they may attack to achieve their goals. Defenders—cybersecurity professionals—mainly design techniques for detecting those attacks and corresponding protective strategies.
01 Major hacking incidents
Chilled Foam: There have been quite a few. We call it a game of power. Among major social incidents, we focus on three categories. The first compromises confidentiality, causing information to leak into criminal markets or the dark web. A prominent example is Edward Snowden's disclosure of the US PRISM program. It was a comparatively concealed insider incident, because Snowden worked within the organization. Although the US National Security Agency had strict, layered defenses and detection mechanisms, his activities remained relatively hidden within that system. According to the retrospective account after he left, he sent a few megabytes of data each day, within the range permitted for work, and sometimes used colleagues' email to send classified plans and copy information from surveillance programs.
Another example discussed when many people used Zoom during the pandemic was credential stuffing. This means automatically trying username-and-password pairs leaked elsewhere against another service; it differs from guessing passwords from scratch through brute force. The original interview mentioned that information for over 500,000 accounts was sold, but supplied no statistical or investigative source. That does not establish that all those accounts leaked because Zoom itself was compromised. The example illustrates how reusing passwords can amplify the consequences of one leak.
The second category compromises integrity, generally while information is being transmitted. For example, imagine an intermediary intercepting a payment between us on WeChat and changing the amount from 100 to 10,000.
The third compromises availability, preventing a service or device from working normally. A well-known example is Stuxnet, which became publicly known in 2010, involved Windows systems and industrial-control software, and could manipulate industrial processes. It exploited several vulnerabilities and transmission routes, including removable media. This restoration does not simplify the incident into “all Iranian nuclear facilities stopped functioning,” or treat the source's unsupported state attribution and “first state-level attack” label as established conclusions.
Wasn't there a notorious virus called Panda Burning Incense some years ago?
Chilled Foam: Panda Burning Incense and WannaCry need to be distinguished. CNCERT/CC's 2007 report described Panda Burning Incense as malicious code with both virus and worm propagation characteristics; it should not simply be called encryption ransomware. WannaCry is ransomware that can encrypt files and demand payment. Both kinds of attack illustrate the importance of system updates and backups.
Calorie: A senior student in our group suddenly found his computer frozen one morning. The attacker said all his data had been locked and that he had to pay a certain amount in bitcoin to recover it.
Fantuan: One of my iPads was locked in a similar way. You do not even know what you did. It then tells you to add a QQ contact to unlock it. You have to pay before they release it.
Chilled Foam: These experiences could involve extortion, account misuse, or malware; a locked device alone does not establish encryption ransomware. The original interview also expressed the view that “at least 70% of apps, especially Chinese apps, contain malicious plug-ins.” [Editorial correction: The source supplied no statistics supporting that percentage, so 70% is not treated as a general fact about malicious app plug-ins. Download sources, permissions, and actual behavior should be checked.]
[A reminder: Software from unknown sources can pose risks. Check its source and permissions carefully.]
02 How hackers operate
How do we get hacked?
Chilled Foam: Some hackers are cybersecurity experts, sometimes more capable than people working routinely in defensive security. They know systems thoroughly. Software, hardware, networks, and protocols generally have some design weaknesses. It is like a barrel whose shortest plank determines its capacity: whoever finds that weak point can enter the system and damage or exploit it.
We often receive phishing links. What can happen if we click them?
Chilled Foam: Do not casually open attachments or links from unknown sources. They may be used for phishing or exploit particular vulnerabilities. Cross-site request forgery, or CSRF, tricks an already logged-in user into sending an unwanted request to a website. It is different from directly executing malicious code on a computer or obtaining administrator privileges. Clicking a link does not inevitably result in administrator-level compromise; the outcome depends on vulnerabilities, permissions, user actions, and other conditions.
There are many possible entry points: links, USB drives, email, and other attack surfaces.
03 Different kinds of hackers
Do hackers have factions, like characters in martial-arts novels?
Chilled Foam: We generally talk about three kinds:
1) Black-hat hackers are the “bad hackers” people usually imagine. They study and produce malware and attack tools, seek system vulnerabilities, and attack networks or computers to cause damage or commit cybercrime.
2) White-hat hackers, also called ethical hackers, use their expertise to research defenses and maintain cybersecurity. They work against malicious hacking.
3) Gray-hat activities lie between legally authorized security research and unauthorized conduct. Whether an activity is lawful or compliant depends on its authorization and specific actions; a label alone does not settle that question.
A door-lock analogy can help: a black hat might exploit a lock to steal things; a white hat finds vulnerabilities within an authorized scope and helps repair them; a gray hat might investigate or disclose weaknesses without permission. The analogy does not replace examining the actual authorization and conduct, nor does it mean every gray hat steals first and then notifies the owner.
Are you white-hat hackers?
Chilled Foam: Nominally, yes. White hats generally conduct simulated attacks to discover vulnerabilities, motivated by a wish to do good. They often investigate weaknesses and report them to vendors. Microsoft,360,Tencent, and Huawei, for example, have long invited white hats to find vulnerabilities and offered substantial rewards. If a black hat finds one, a vulnerability might instead lead to a demand for 500,000 or 1,000,000.
I do some related research. Professional roles may require particular qualifications or certifications, but “white hat” is not an identity that requires everyone to hold one universal certificate. What matters is legal authorization, the scope of testing, and responsible handling of vulnerabilities. Researchers look for system weaknesses during authorized testing.
04 Things you and I may have encountered
[1: Should passwords be saved?]
Browsers now save usernames and passwords automatically. How secure is that?
Chilled Foam: Personally, I used not to save passwords automatically and worried about unfamiliar websites and third-party services. [Editorial correction: Storing passwords in a browser or reputable password manager is not the same as publishing them on a webpage. NIST recommends using a password manager to generate and store distinct strong passwords for different accounts, while protecting access to the device and manager. A site's use of third-party services does not automatically mean saved passwords will leak.]
[2: Should pirated software be used?]
Calorie: I once installed a QQ game on my computer. Advertisements later kept popping up. I uninstalled it, but could not get rid of the advertisements. It was very annoying.
Chilled Foam: That can also be part of the illicit online economy. Operating systems we download, or even small equation-editing programs, may contain advertisements that cannot be blocked and appear periodically. In effect, malicious advertising has been embedded in the program.
I recommend using genuine software. Even something labeled a “clean” edition may not be completely clean; it may contain advertisements or a default browser.
Calorie: Is genuine software safer and more reliable, or does it simply lower the likelihood of problems?
Chilled Foam: Genuine software generally has better access to vendor maintenance and updates, but that does not guarantee absolute safety. Microsoft, for example, normally schedules security updates for the second Tuesday of each month, rather than every Wednesday, with additional updates when necessary. Pirated or modified software from unknown sources may contain advertising and malicious components, so download from trusted sources and keep software updated.
[3: Should antivirus software be installed?]
There is a rumor that 360 antivirus removes malware but also examines every file on your computer and obtains your information. Is that kind of antivirus software really trustworthy?
Chilled Foam: Security software generally needs certain permissions to inspect files and system activity, and some products may include advertising or additional data collection. Check a specific product's source, permissions, privacy policy, and actual behavior. We cannot guarantee that every antivirus product undergoes the same compliance assessment, never leaks private information, or poses no risk to individual users.
[4: My device was hacked seemingly out of nowhere]
There is a novel form of extortion: your phone has not been lost, and you have not clicked any links, yet information about banks and online-payment platforms on it has been stolen. How can that happen?
Chilled Foam: Such leaks may involve stolen accounts, malware, system vulnerabilities, or inappropriate permissions, among other routes. The cause cannot be determined from this description alone, and it should not be generalized into a claim that radio signals or cloud transfers can reveal all banking information.
Fantuan: Is it really that insecure?
Chilled Foam: Mobile systems provide application interfaces and permission mechanisms to support functions while protecting data. An interface is not automatically a “backdoor.” What different apps can access depends on permissions, system protections, and specific vulnerabilities. We should not broadly assume that communication between devices of the same brand makes personal information easy to read.
[Editorial correction: Removed a specific claim in which the source inferred, from recommended content, that a partly masked platform read notes. The available material does not support that conclusion about the platform. An app's permissions and data processing need to be checked against its actual behavior.]
An application's access to data should be assessed through system permissions, actual behavior, and applicable rules. Downloading or registering an app does not automatically allow it to access every photograph, contact, and banking login. Sending a photograph through the cloud does not inevitably install a backdoor either. A particular attack requires corresponding vulnerabilities or other conditions; these possibilities should not be presented as universal, inevitable outcomes.
[5: How vulnerable are our networks in reality?]
Chilled Foam: In the original interview, I used the statement “I could attack 90% of computers if I wanted to” to emphasize security awareness. [Editorial correction: The source supplied no measurement scope, method, or statistical basis, so 90% is not treated as a verifiable general compromise rate. Awareness, device maintenance, and specific protective measures all matter.]
What would you recommend?
Chilled Foam: • Lock your computer whenever you step away. That is the most basic precaution.
• Do not reuse the same username-and-password combination everywhere. Most people make that mistake.
• Do not open untrusted files or links in email. Using a firewall can provide additional protection.
• Use reliable protective features, including appropriate built-in system defenses or trustworthy security software, and keep them updated.
• Back up data regularly, and be cautious about creating shared resources on your computer. Do not download software casually; the risk can be substantial.
By sharing, do you mean AirDrop and Bluetooth?
Chilled Foam: Yes, and even shared printers. An attacker might compromise printer components and use them to attack back into a network. Many large attacks have entered through printers.
Science presenter: Chilled Foam (冰镇泡沫)
Editor: Honey Peach Oolong
Interviewers: Fantuan and Calorie
Audio recording: Calorie
*This article represents the author's personal views, not the views of this website.
Revised on 2026-10-10: Corrected the descriptions of credential stuffing, CSRF, Panda Burning Incense versus ransomware, authorized white-hat work, and Microsoft's update cycle; clarified password managers and application permissions; removed an unverified platform accusation about reading notes; and identified 70%/90% as claims in the interview without a supplied statistical basis.
Supplementary references
- OWASP: Credential stuffing and password reuse
- OWASP: Cross-site request forgery
- NIST: Strong passwords and password managers
- Microsoft: Security Update Guide FAQs
- CNCERT/CC: Panda Burning Incense in the 2007 annual report
- Microsoft: WannaCrypt ransomware worm
- CISA: Historical Stuxnet advisory
Sources and editorial history
Restored from a complete historical article exported from the PhDSciNet Official Account.
Editorial revision: Revised on 2026-10-10: Corrected the descriptions of credential stuffing, CSRF, Panda Burning Incense versus ransomware, authorized white-hat work, and Microsoft's update cycle; clarified password managers and application permissions; removed an unverified platform accusation about reading notes; and identified 70%/90% as claims in the interview without a supplied statistical basis.