jueves, 26 de marzo de 2009

Technical trainings: The good, the bad, the weird.

Dear Diary,
I'm back in Buenos Aires again, enjoying the end of the summer. The training madness is over, until next May where i'm back with the heap overflow class.
Don't get me wrong, teaching is my favourite task at Immunity and out of it (Next week I'm gonna start as a teacher assistant on the subject "Ethics" on a local university. Greek tragedy is what I will be explaining). But the true is that training takes a lot from you, and at the same time it gives you so much.
My favourite part is in day two, when everything start making sense and you can see people really enjoying each exercise when they put all the pieces together.


The japanese training was amazing, I couldn't enjoy it more. The class was funny and entraining, one of the guys at the beginning of the class introduce himself as Shoichi Nakagawa, Japan's minister of finance who gave a press conference drunk.



The only big problem that i had was obviously the language. I got two girls translating, but it wasn't simultaneous so I have to make a pause on each phrase so its get translate.
The trick I pull to make it more dynamic, was to make a random student who finish the exercise explain what he did and why in the projector computer. It was a win-win situation, students got a second explanation in Japanese while the selected student explanation help him understand the subject even more deeply by being able to teach it.
People there were quite nice, we had pizza and some drinks on the first day, and at some point everyone got in a circle and start giving a small speech of who they were and what they expected for the class. I wish I can do that on every class!
I guess the main problem that i had with languages, was not to be able to listen to what students talk between each other, that's usually a key factor of a class, because it allows me to identify levels and gave different exercise upon it.

Japan itself was amazing, and I want to thanks on the website to the people from cyberdefense (Jack-san, Lauri-san, Yusuke-san and Matsumoto-san) for the big hand they gave me on the training.

They also took us to a traditional salaryman restaurant near Akihabara, where we try different types of local dishes and the freshest sushi i ever try. (yes, all the fishes in the picture were alive).


Going back to the training, I went back from Japan to Buenos Aires, only to stay two days and then back to Miami to give two more training with my dearest friend Kostya Kortchinsky. Those training were pretty good and we got quite an amount of really skilled students, it was a real surprise to see everyone at the same level!
Back in the airport, waiting for my flight back to Buenos Aires, i put together a list of rules (or tips) that i had being collecting over the years:


o Never ever ever never start compiling and fixing stuff in the middle of the class (only like 10 minutes max is allowed).
o Don't look insecure
o Be comfortable with your material, remember to read it and know exactly what is comming next. It's really common to get excited and start explaining stuff that might appear later.
o Always tell war stories.
o Most difficult task: Be prepare for the most advanced student and for the most inexperienced.
o Don't spent your entire class on the slow students: Try to push him, help them as much as possible, but don't loose the track of the class. You request at the beginning of the class for basic requirements that is the student responsibility to get before class.
o Always bring extra exercises.
o Real life examples is always a win. People enjoy owning a real server vs your exercise server.
o Improvization is good and people will appreciate it, only when your material is solid.
o Not knowing the answer of all the question is ok. You are not god neither Kostya.
o Exercise, Exercise and more Exercise. Always support your material with hand-ons exercise.
o Students love owning stuff, if they can archive shellcode execution they will be happy++. The satisfaction of writing a workable exploit is priceless, even tho is on your "hoolio" server.
o Be progressive with your exercise. Each exercise has to teach at least one new thing or introduce a new challenge.
o One, two even three challenges are ok per exercise, but try not overwhelm the students.


Peace,
Nico

1 comentario:

Anónimo dijo...

You're an awesome teacher Nico. I don't think I mentioned that before. Thanks!