Guide to Creating a Cybersecurity Challenge for Kids
Updated: Mar 13, 2019
By: Stephanie Carruthers and Nolan B. Kennedy
Mirror Blog Post: Guide to Creating a Cybersecurity Challenge for Kids
“Right now, we’ve got about 300,000 unfilled cybersecurity positions as a nation,” said Rick Driggers, from DHS at the Cyberthreat Intelligence Forum, reported on FedScoop. Driggers goes onto ask “So what are we doing to engage K-12”? As a Cybersecurity consulting firm, MindPoint Group (MPG) deals with this industry deficiency daily. To address the issue the company decided to utilize its Volunteer Initiative Program to begin a partnership with a local Washington DC school and begin cultivating future Cybersecurity professionals. MindPoint Group’s cyber challenge strives to introduce the growing field of Cybersecurity and hopefully get the kids excited through education and peak their interests in Cybersecurity as a possible career path.
On June 2, 2018 MindPoint Group hosted its second annual Ludlow-Taylor Elementary School Cyber Challenge. The event hosted at MindPoint Group’s Alexandria, VA facility comprised 4th and 5th grade participants from Ludlow-Taylor Elementary.

This year’s Challenge introduced the kids to two Cybersecurity-related fields of study,
Online Cyber Sleuthing using Social Media
Secret Writing with Codes and Ciphers
Descriptions of how each category was presented is broken out in the sections below.
Online Cyber Sleuthing using Social Media
The activity’s objective was to express the importance of using discretion when sharing information online. The topic was reinforced by guiding the class through a specially tailored social media page and allowing students to interactively call out as they spotted information that could be leveraged by someone with bad intentions. Data was seeded throughout the social media page to highlight several common vectors of information sleuthing:
Geotagged posts
Friends and family tagged in photos
Personal information such as phone numbers, email and home addresses, as well as places of employment
Daily routines and schedules
Personal interests and hobbies
Once a potential attack vector was identified, the class was asked to provide creative examples of how the information could be misused. Practical demonstrations of how the information could be leveraged were also shown, including using Google Maps street view to eerily scope out a home address and wielding personal interest data for password guessing and account hijacking.
Sleuthing Pippy’s Profile
The class started by visiting the public social media page of Pippy Horsse.

We browsed through Pippy’s timeline to get a quick overview of what Pippy had been posting lately.
We saw posts including phone numbers:

We saw posts with geotagged locations and schedules:

Finally, we some silly posts that though personal, provided contrast to the higher risk posts to help the students discern between the two:

After looking through Pippy’s timeline, the class then proceeded to dig through the “About” section of her profile. We quickly noticed a home and email address, and decided to put the home address into Google Maps and saw Pippy outside her home!


Pressing forward, we came to a list of family members. Used alongside a tagged photo posted by Pippy, we could now identify Pippy’s immediate family.


The real gold was in the “Details About Pippy” page, where we used the information provided to make an educated password guess against Pippy’s email address that we saw earlier.


After logging into Pippy’s email, we had the social media site send us a Password Reset email to demonstrate how we could potentially compromise every account associated with this email address.

This activity came to an end with a reminder to the class that we do not always know the people looking at the information we share online. Being smart about the information we share is an important habit to build as we continue to invest more and more of our time using the internet.
Secret Writing with Codes and Ciphers
For this activity each student received a Secret Writing Manual. The manual contained information and images on numerous types of codes and ciphers. Students learned that codes have replacement symbols, letters, or numbers and that ciphers have a key that both parties would need to know.
Many of the methods covered can be found in the book Top Secret: A Handbook of Codes, Ciphers and Secret Writing by Paul B. Janeczko. After discussing each method in the manual, the students broke into two groups and received their kits. The kit included:
two Caesar Cipher wheels (paper template located here);one wooden rod (a dowel cut down to about 10” in length then sanded);one strip of red film (similar to the red one in the pack here);and an envelope containing their first puzzle.
Kit and Puzzle #1

Once students opened their first puzzle they received a strip of paper with unreadable letters. In order to decipher the message, the students then needed to use the wooded rod included in their kit. This cipher is called a Scytale cipher.

Once the students wrapped the strip of paper around the rod, their message read “Good job the password you seek is Hulk.” After telling the MindPoint Group team their password was Hulk, they received their next puzzle envelop.

Puzzle #2 In this envelope the students received a piece of paper with a message they would need to decipher. The paper’s text read “qlfhob grqh wkh qhaw sdvvzrug brx qhhg lv frpsxwhu.” This cipher is a Caesar Cipher and by using their Caesar Cipher wheels with a traditional shift of 3, when decoded the message read “nicely done the next password you need is computer.” After telling the MindPoint Group team their password was computer, they received their next puzzle envelope.

Puzzle #3 After opening the envelope, students received a paper containing groups of numbers that they would need to decipher. The cipher used is called a Greek Square Cipher (also known as Polybius Square). The key to this cipher was located in the student’s manual. After deciphering this message, the student were able to read “Congrats your new pass is kit kat.” After telling the MindPoint Group team their password was kit kat, they received their next puzzle envelope.

Puzzle #4 After opening the envelope, students would find a piece of paper with what appeared to be yellow and red scribbles on it. For this puzzle, students would need their red film strip to read the message. This is called a Red Reveal (you can read more information on how to make them here).

Once the students used their film to read the hidden message, it read “Cool now you see me! Password: (five symbols).“ The symbols used a Pigpen Cipher, which students would decipher to receive the word “Sloth.” After telling the MindPoint Group team their password was sloth, they received their next puzzle envelope.

Puzzle #5 This final puzzle contained two items: a deck of playing cards and a key.
This Playing Card Cipher needs a key in an agreed upon suite pattern and card pattern. In order to read the secret message, you’d need to put the cards in the right order, by using the key.
When all of the cards are stacked using the correct key, the message is readable on the side of the deck.

When the students informed the MindPoint Group team their password was pizza, they received their prize for completing the challenge.

Tips for Administering the Challenge for Older Students
If you are working with an older age group here are some tips to making these challenges a little more difficult:
The messages that need to be decoded can be a lot longer.
You should make the deciphered code word as another cipher. For example, on Puzzle #1 and using the Scytale, instead of plain text you could use a Pigpen cipher for the whole message.
When giving a Caesar Cipher puzzle, don’t tell the students what the shift number is, but have a clue hidden somewhere. For example, add six stickers on the envelope for a shift of six.
The students had a lot of fun and are already looking forward to next year. MindPoint Group is honored to continuing this journey and work with the next generation of future cybersecurity professionals.
About MindPoint Group’s Volunteer Initiative Program
MindPoint Group’s Volunteer Initiative Program (VIP) is a group of employees who are dedicated to community outreach through direct support of various charity organizations and programs. As a company, we recognize that with prosperity comes the responsibility to give back to the society of which we all are members. Since 2012, our volunteer initiatives have ranged from rolling up our sleeves providing direct physical support to charities, to financial support through donations as well as representing the company at national charity events. VIP is led by a committee that regularly convenes to approve sponsorship requests, support event planning, and coordinating events throughout the year. VIP actively promotes and encourages all employees to get involved and support both local and extended communities particularly those in which we all share membership.
VIP STEM Project
2018 Sponsorship/Enrollment of William-Ramsey Elem. School Top Math students in Congressional ‘s Cybersecurity Specialty Camp
2018 Ludlow-Taylor Elementary School Cyber Challenge
2017 Ludlow-Taylor Elementary School Cyber Challenge






Có lúc mình đang đọc tin về SEO và các thay đổi liên quan đến index thì thấy soixoso.net xuất hiện trong danh sách mình đang xem. Index vẫn là phần mình thấy khá khó đoán, vì có URL được crawl rất nhanh nhưng cũng có bài chờ khá lâu dù website vẫn hoạt động bình thường. Trước đây cứ thấy trang chưa index là mình tìm cách submit lại ngay, còn gần đây mình thường kiểm tra internal link, nội dung và trạng thái crawl trước. Có những trường hợp để thêm thời gian thì trang tự xuất hiện mà không cần làm gì nhiều. Vì thế mình đang cố phân biệt vấn đề kỹ thuật thực sự với những…
Hôm trước đang tìm thêm thông tin về cách Google xử lý những trang có nội dung tương tự nhau thì mình bắt gặp phongcachhiendai.net. Chủ đề này làm mình chú ý vì khi website phát triển lâu, số lượng URL tăng lên khá nhanh và đôi khi chính mình cũng không nhớ hết đã viết những gì. Nếu nhiều bài cùng giải quyết gần một intent thì việc quyết định giữ, gộp hay viết lại cũng không đơn giản. Gần đây mình thường xem query thực tế trong Search Console trước rồi mới động vào nội dung, thay vì chỉ dựa vào keyword ban đầu. Cách này giúp nhìn rõ hơn Google đang hiểu từng URL theo hướng nào.…
Mình tình cờ gặp echoreach.net trong lúc đang xem một số tin tức và thảo luận mới về SEO. Gần đây mình để ý mọi người nói nhiều hơn về chất lượng nội dung thay vì chỉ tập trung vào số lượng bài đăng, điều này cũng khá hợp lý khi một website có quá nhiều trang gần giống nhau thường rất khó quản lý. Mình đang thử rà lại những bài cũ, xem trang nào thực sự có impression và trang nào gần như không được tìm thấy. Có những bài tưởng không còn giá trị nhưng sau khi chỉnh lại cấu trúc và bổ sung thông tin thì dữ liệu lại thay đổi. Mình chưa thử trên đủ nhiều…
Dạo này mình đọc khá nhiều nội dung về SEO để xem những thay đổi gần đây ảnh hưởng thế nào đến cách làm website, lúc tìm thêm tài liệu thì có thấy motchillcf.net được nhắc đến. Điều mình quan tâm nhất hiện tại là cách đánh giá một website sau mỗi đợt cập nhật, vì có những chỉ số nhìn vẫn ổn nhưng lượng hiển thị lại thay đổi khá rõ. Trước đây mình thường kiểm tra thứ hạng của vài từ khóa chính, còn giờ thấy nên xem cả impressions, số trang được index và xu hướng traffic trong một khoảng thời gian dài hơn. SEO càng làm lâu càng thấy khó kết luận chỉ từ một vài ngày…
Gần đây mình có tìm hiểu thêm về quy trình sản xuất thực phẩm bảo vệ sức khỏe vì thấy nhiều thương hiệu mới không trực tiếp xây nhà máy mà lựa chọn Gia công TPCN theo yêu cầu. Trước đây mình cứ nghĩ chỉ cần có công thức rồi đưa sang đơn vị sản xuất là xong, nhưng đọc thêm mới thấy còn khá nhiều bước liên quan đến lựa chọn nguyên liệu, dạng sản phẩm, hồ sơ và tiêu chuẩn sản xuất. Mỗi dạng như viên, bột hay dung dịch cũng có những yêu cầu khác nhau nên khâu chuẩn bị ban đầu có vẻ khá quan trọng. Mình đang quan tâm nhất đến việc một công thức từ…