{"id":581,"date":"2025-11-05T12:31:25","date_gmt":"2025-11-05T12:31:25","guid":{"rendered":"https:\/\/donavan.sg\/blog\/?p=581"},"modified":"2025-11-05T12:31:26","modified_gmt":"2025-11-05T12:31:26","slug":"give-yourself-a-chance-to-say-yes","status":"publish","type":"post","link":"https:\/\/donavan.sg\/blog\/index.php\/2025\/11\/05\/give-yourself-a-chance-to-say-yes\/","title":{"rendered":"Give Yourself a Chance to Say &#8220;Yes&#8221;"},"content":{"rendered":"\n<p>In about a week&#8217;s time, I will be in a <a href=\"https:\/\/def.camp\/speakers\/\" target=\"_blank\" rel=\"noopener\" title=\"different continent\">different continent<\/a> to give a talk on threat modeling, and another co-presented topic with SATCR4K on satellite security. <\/p>\n\n\n\n<p>To some extent, this year&#8217;s roll is partially happenstance. <\/p>\n\n\n\n<p>Included in this year&#8217;s roll are many more conference talks, co-founding of <a href=\"https:\/\/luma.com\/tmc-singapore?period=past\" target=\"_blank\" rel=\"noopener\" title=\"\">Threat Modeling Connect&#8217;s Singapore chapter<\/a> and many more friends I have made in the cybersecurity community globally. A few friends even quizzically look at my schedule and give up trying to find a slot to catch up with me. Others tell me I need to take care of myself <\/p>\n\n\n\n<p>Of course, there are others, especially the younger ones, who ask what they can do to perhaps, repeat a <em>fraction<\/em> of what I do. They wish I could explain to them the magic box. I wish, too.<\/p>\n\n\n\n<p>Perhaps the best answer to give is the saying, &#8220;You miss 100% of the shots you don&#8217;t take.&#8221; by Wayne Gretzky. But the advice should also not be construed to try every single shot possible, simply because there may be an infinite number of shots to take, and there be only an infinitesimal amount of energy one can put on each shot, which is counter-productive too. Rather, the advice should be interpreted to take some shots, and to try to take them well.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Desirable Difficulty<\/h2>\n\n\n\n<p>One learning theory that has proven to be good advice (at least for me) is the theory of <a href=\"https:\/\/www.researchgate.net\/profile\/Robert-Bjork-2\/publication\/305433736_Memory_and_Meta-memory_Considerations_in_the_Training_of_Human_Beings\/links\/578ea2dc08ae81b4466ecbd0\/Memory-and-Meta-memory-Considerations-in-the-Training-of-Human-Beings.pdf\" target=\"_blank\" rel=\"noopener\" title=\"\">desirable difficulty<\/a> (on an unrelated note, some aspects of LLM hallucinations could be rationalised with this reading, potentially). In practical terms, this involves putting in place progressively harder tasks that require the learner to more actively engage with the material. Let us chart out such a progression to illustrate this point (a reduced version of the <a href=\"https:\/\/www.learningscientists.org\/blog\/2021\/3\/4-1\" target=\"_blank\" rel=\"noopener\" title=\"\">SQ3R<\/a> technique)<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>Read the material<\/li>\n\n\n\n<li>Recite the material (without looking)<\/li>\n\n\n\n<li>Review the material<\/li>\n<\/ol>\n\n\n\n<p>These tasks provide a gradual increase in difficulty; everyone can read material while presented to them. Thereafter, to test recall, we can get students to recite said material. Examples include providing recall-based quizzes (e.g. do you remember what the syntax is to perform a UDP port scan?), and then a review of the material where you ask questions about the material and more actively engage in it (e.g. how do I know my UDP port scan produces reliable results?)<\/p>\n\n\n\n<p>One can perhaps take this further with higher-order tasks. Examples include <strong>writing<\/strong> and <strong>teaching<\/strong> the material. Providing output is a much more effortful, but intensive learning exercise. For example, to <strong>write<\/strong> a journal article of almost 2,000 words such as this <a href=\"https:\/\/www.isaca.org\/resources\/isaca-journal\/issues\/2024\/volume-6\/demystifying-quantum\" target=\"_blank\" rel=\"noopener\" title=\"one\">one<\/a> required at least fifty readings (twenty-six were eventually cited; account for the number of readings that are irrelevant\/duplicate\/not useful). Naturally, writing is a big level up. But not everyone needs to write 2,000 word articles as a jump. We can write commentary too. Or even discuss such topics with friends. Much less effortful. In fact, I enjoy having juniors bounce ideas with me because they often open up new paradigms that force me to correct a certain set of dogma that could have persisted, sometimes out of bad habit, or sometimes as a consequence of taking some processes for granted and not indulging in the fundamentals enough.<\/p>\n\n\n\n<p>But I thought I would like to mention that conference submissions, to me, are simply an extension. They are simultaneously a <strong>teaching<\/strong> experience, and also a <a href=\"https:\/\/www.bps.org.uk\/research-digest\/learning-teaching-others-extremely-effective\" target=\"_blank\" rel=\"noopener\" title=\"\">highly effective <strong>learning<\/strong> one<\/a>. Want to prove that you are good at your craft? Aim to be able to teach it, especially to someone who has no idea of what you do. But even I don&#8217;t consider myself such a master yet. <\/p>\n\n\n\n<p>Even <strong>teaching<\/strong> has different strata of achievement. When teaching fellow practitioners, such as at a conference, we are teaching <strong>practical skills<\/strong>. For instance, in the subject of threat modelling, we need to use frameworks to provide a more objective method to assess threats. But teaching students who are new to the subject requires us to teach <strong>principles<\/strong>. Principles are important in a subject as it provides the necessary grounding for the student to appreciate the way the subject is being structured the way it is. For instance, the <a href=\"https:\/\/www.threatmodelingmanifesto.org\" target=\"_blank\" rel=\"noopener\" title=\"Threat Modeling Manifesto\">Threat Modeling Manifesto<\/a> is an example of a principle. The four key questions in the manifesto are as follows:<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>What are we working on?<\/li>\n\n\n\n<li>What can go wrong?<\/li>\n\n\n\n<li>What are we going to do about it?<\/li>\n\n\n\n<li>Did we do a good enough job?<\/li>\n<\/ol>\n\n\n\n<p>These questions alone, to a non-practitioner, will not be useful. In fact, one might even critique that teaching <strong>principles<\/strong> at the outset could be too daunting. But I take a different view. For someone to be <strong>highly effective<\/strong> at their craft, they must understand the core principles of said craft. Teachers do not always have the luxury of being by the side of their learners all the time, so the best service we can give is to impart a certain curiosity of learning, as well as a way of thinking that enables them to answer their curiosity.<\/p>\n\n\n\n<p>But what about young learners who may not understand principle, since they are not cognitively mature yet? This is the highest level of achievement in my view: being able to use the <a href=\"https:\/\/fs.blog\/feynman-technique\/\" target=\"_blank\" rel=\"noopener\" title=\"Feynman Technique\">Feynman Technique<\/a>. Imagine teaching a topic to a 12-year-old. This forces us to confront ourselves to make the material <strong>plainly simple<\/strong>. But the true master of craft shows how complex ideas can be simplified, and executed in a way that is almost artistically beautiful.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Habits<\/h2>\n\n\n\n<p>But discomfort is scary. Paper rejections are nasty. I am no stranger to them.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"176\" src=\"https:\/\/donavan.sg\/blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-05-at-20.25.40-1024x176.png\" alt=\"\" class=\"wp-image-582\" srcset=\"https:\/\/donavan.sg\/blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-05-at-20.25.40-1024x176.png 1024w, https:\/\/donavan.sg\/blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-05-at-20.25.40-300x52.png 300w, https:\/\/donavan.sg\/blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-05-at-20.25.40-768x132.png 768w, https:\/\/donavan.sg\/blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-05-at-20.25.40-1536x264.png 1536w, https:\/\/donavan.sg\/blog\/wp-content\/uploads\/2025\/11\/Screenshot-2025-11-05-at-20.25.40.png 1998w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption class=\"wp-element-caption\">LinkedIn isn&#8217;t a great place to write about failure in plain, simple terms. But we all <strong>do<\/strong> fail, at times.<\/figcaption><\/figure>\n<\/div>\n\n\n<p>But to me, filing for conferences and papers is part and parcel of a challenge: do I think I know enough to put together a submission where someone else would benefit? If not, we can just keep honing our craft in smaller settings. Great examples include community meet-ups and smaller conferences (the cybersecurity community is particularly blessed to have conferences such as BSides and OWASP that provide friendly audiences and positive learning environments).<\/p>\n\n\n\n<p>But what one has to be uncompromising about is a relentless habit to keep learning <strong>actively<\/strong> and to <strong>demonstrate<\/strong> said learning. And that begins by saying &#8220;Yes, I will do something outside my comfort zone.&#8221;<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In about a week&#8217;s time, I will be in a different continent to give a talk on threat modeling, and another co-presented topic with SATCR4K on satellite security. To some extent, this year&#8217;s roll is partially happenstance. Included in this year&#8217;s roll are many more conference talks, co-founding of Threat Modeling Connect&#8217;s Singapore chapter and&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-581","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/posts\/581","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/comments?post=581"}],"version-history":[{"count":1,"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/posts\/581\/revisions"}],"predecessor-version":[{"id":583,"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/posts\/581\/revisions\/583"}],"wp:attachment":[{"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/media?parent=581"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/categories?post=581"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/donavan.sg\/blog\/index.php\/wp-json\/wp\/v2\/tags?post=581"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}