Cybersecurity Movies: Documentaries
Documentaries with no invented hacking scenes: interviews with participants, court material, and footage shot as events unfolded.
Cybersecurity Movies: Documentaries
Part five of six. There are no invented hacking scenes here: interviews with participants, court material, and footage shot while the events were happening.
If you only watch one part of the whole series, make it this one.
Zero Days (2016)
A breakdown of Stuxnet: how the malware reached an isolated facility and what it did to the centrifuges.
Topics: zero-day exploit chains, code signed with stolen certificates, crossing an air gap on removable media, attacks on industrial controllers with falsified readings shown to the operator, the question of attribution and rules of engagement for cyber weapons.
Citizenfour (2014)
Footage of the meetings in a Hong Kong hotel during the exact days the material was being prepared for publication. The camera was running at the time, not a year later.
Topics: practical operational security (phones, typing a password under a blanket, unplugging the room's lines), encrypted correspondence with journalists, mass collection programs, source protection and preparing for disclosure.
The Great Hack (2019)
Cambridge Analytica and the journey of user data from a harmless social network quiz to targeted political advertising.
Topics: data collection through third-party apps and API permissions, psychographic profiling, microtargeting and behavioral manipulation, the right to erasure and attempts to actually exercise it.
Deep Web (2015)
A different view of the Silk Road story: anonymity technology, the trial, and the limits of what can be proven at all in a digital environment.
Topics: Tor and hidden services, cryptocurrency and blockchain analysis, server seizure and questions about the legality of the search methods, digital evidence and how verifiable it is in court.
Kill Chain: The Cyber War on America's Elections (2020)
A security researcher buys decommissioned voting machines and takes them apart.
Topics: hardware security audits, obsolete components and unpatched vulnerabilities, the hardware supply chain, verifiability of results and the paper trail, responsible disclosure and how vendors react.
We Are Legion: The Story of the Hacktivists (2012)
How a movement grew out of an imageboard and then split into groups with very different goals.
Topics: DDoS as a form of protest and as a criminal offense, doxing, coordination inside anonymous communities, deanonymization of participants through small mistakes, the difference between activism and crime in the eyes of the law.
Terms and Conditions May Apply (2013)
About the text nobody reads, and about what people are agreeing to inside it.
Topics: terms of service and the scope of rights handed over, retroactive policy changes, government requests to services, data retention periods and what remains after an account is deleted.
Next part: series.
The whole series: