Material and Resources: Permanent Record, Edward Snowden (Picador softcover, Metropolitan Books hardcover, 2019). Please acquire/order a copy for the first week of class. It is essential for Project 1 (14% of term mark). Other resources will be online or available through Carleton library (electronically) or Brightspace.
Course Calendar Description
A tour of Internet security and privacy. Societal impacts and case studies. Topics from: protection goals of stakeholders; history of public key cryptography; programming languages and security; security engineering and testing; cybercrime and malware; Internet privacy and anonymity; government surveillance; regulation; ethics; blockchain applications.
Grading Scheme
The course has the following grading scheme:
- 20% Class Participation
- 15% Midterm 1 (Tuesday, October 13)
- 15% Midterm 2 (Tuesday, November 17)
- 16% Summary Reflections (roughly weekly). Due on Fridays at noon on Brightspace.
- 14% Technical Report on the book Permanent Record (Due on October 6)
- 20% Final Exam
Missed/Late Assessments: No late submissions for summary reflections are accepted.
A student missing any of the midterms or the final receives a mark of zero.
Special Note: For any course assessment, a set of students may be selected to meet with the TA or the professor to discuss their work. These students must demonstrate an understanding of their submissions. Failure to do so convincingly will result in losing up to the full marks for that assessment.
Summary Reflections:
- Each of the 8 weekly reflections is worth 2% (16% total)
- Length. One full single-spaced page of content (with spacing and formatting as noted above). References if any are extra beyond this (e.g., on an extra page). No figures or diagrams. No cover page. No abstract (instead, give context in the opening sentences). Top line should be: COMP2109 Summary Reflection (dd-mmm-yyyy), student name + student #
- Content. As a guideline, summarize 3 items that most interested you from the week's classes, comment on these items, and why they interested you. Try to connect it to personal stories if possible, such as a relevant article you read, or something you experienced, e.g., in your software configuration. Optionally you may augment this, or replace one of these items, by items that you would have preferred that we not cover at all (and why), or explain what you would have preferred instead and why.
- Grading rubric. The following guide will be used to assign a matching grade (full grade: 2.0):
- 2.0: suitable format, relevant class/course content, writing to the level of Gr.12 English standards
- 1.5: short length, weak format, weak grammar/spelling, content hard to understand or not relevant
- 1.0: seriously short or other major issues (confused content, unacceptable grammar/clarity or format)
- 0.5: essentially nonsense or not a serious effort
- 0.0: not handed in
Technical Report on the book Permanent Record:
- Book content is in-scope for the both Midterms and the Final.
- This is a single-student independent technical report on Permanent Record by Edward Snowden, 2019. The hardcover book is 336 pages, so students should begin 4-6 weeks before the due date. You may begin immediately, as no additional material will be necessary or given, beyond these instructions.
- Collaboration. Reports must be written individually without significant collaboration. Students may post questions for clarification on Brightspace (which the TA will monitor) and may discuss high-level aspects, but may not post or distribute any specific details in written, video or voice recordings, nor directly use specific notes from anyone else (your own personal notes from general discussions may be used); other sharing is viewed as plagiarism is this course.
- Length and formatting. The report must at least 3 full pages of content (excluding references, if any), and at most 5 full pages. Other formatting instructions are as for all deliverables.
- Content. The report should summarize the book content most relevant to our course, especially on technical details and capabilities, discussion of metadata, societal impact, privacy, and surveillance. Give page numbers to locate the concepts you summarize, for example: The author explains (p37) that metadata refers to... Page numbers can be mid-sentence or at the end of sentences or paragraphs, and may include several pages (pp37-38) or (p37; p39; p86), but no ranges longer than 3 (instead, pick the 2 or 3 most relevant pages for a referenced item). The report must begin with an introductory paragraph that explains what the report is about. If you also use an explicit abstract, do not repeat the abstract content in the opening paragraph. You may provide your own insights and opinions, but if so, clearly explain and support them with convincing reasoning (justifying your lines of thought). Figures and diagrams are not expected, but if you do use any, they must be of your own creation. Copy-and-paste of diagrams violates academic integrity in this course; also, do not use screen captures. If you redraw any diagrams, cite the source in a caption and explain (otherwise plagiarism issues arise).
- Presentation appearance, grammar, clarity. It is expected that your report will have proper format and is free of errors in spelling, grammar, punctuation, etc. Reports failing to meet this expectation are subject to a deduction of up to 20% of the total available grade, independent of technical content; such failures typically also make the technical content unclear, further impacting the grade.
- Additional guidance and suggestions:
- Make notes (e.g., pencil marks bracketing relevant sentences) on your first reading pass of the book. This may save a tremendous amount of time in finding relevant content for your report.
- Provide context. Your target reader should be typical 2nd-year CS students not in COMP2109.
- Make your report self-contained. Define any jargon used, i.e., any terminology that a typical 2nd-year CS student (peer student in courses outside of COMP2109) would not understand.
- Formal references. See the previous page for explicit details specifying required reference style. You may, e.g., cite references used to help explain background relevant to the book.
- Grading rubric: 14 marks for content. See above regarding deductions.
- 7 marks: selection and coverage of content, complete with page numbers as explained above.
- 4 marks: clear and accurate summary of content, conveying a technical understanding.
- 3 marks: overall quality. Includes being self-contained with context suitable to target reader.
Course Outline
| Week |
Date (2026) |
|
Topic |
| Week 1 |
Sep 8 |
|
(No class) |
| Sep 10 |
|
Course Intro |
| Week 2 |
Sep 15 |
|
Security and privacy landscape Reflection report due: Sep 18 |
| Sep 17 |
|
| Week 3 |
Sep 22 |
|
Public key cryptography (history + impact on society) + Bitcoin Reflection report due: Oct 2 |
| Sep 24 |
|
| Week 4 |
Sep 29 |
|
| Oct 1 |
|
| Week 5 |
Oct 6 |
Tech Report due |
Assets, protection goals, different stakeholders and their priorities Reflection report due: Oct 9 |
| Oct 8 |
|
| Week 6 |
Oct 13 |
|
Midterm 1 |
| Oct 15 |
|
Computer/Internet (threat models, security and privacy) Reflection report due: Oct 23 |
| Week 7 |
Oct 20 |
|
| Oct 22 |
|
Special Topics (TBD) |
Week 8 |
Oct 27 |
|
Fallbreak (No classes) |
Oct 29 |
|
| Week 9 |
Nov 3 |
|
Privacy & anonymity, pseudonymity, linkability, partial identity Reflection report due: Nov 13 |
| Nov 5 |
|
| Week 10 |
Nov 10 |
|
| Nov 12 |
|
| Week 11 |
Nov 17 |
|
Midterm 2 |
| Nov 19 |
|
Privacy regulation, governments, and ethical issues Reflection report due: Nov 27 |
| Week 12 |
Nov 24 |
|
| Nov 26 |
|
Programming languages & software security Reflection report due: Dec 4 |
| Week 13 |
Dec 1 |
|
| Dec 3 |
|
Cybercrime and crimeware Reflection report due: Dec 11 |
| Week 14 |
Dec 8 |
|
| Dec 10 |
|
Software security - security testing and software development |
| Week ∞ |
TBD |
|
Final Exam |
School of Computer Science Laptop Requirement
Every student that has been enrolled in a 1000-level (i.e., first year) course offered is required to have a laptop. This includes COMP1001, COMP1005, and COMP1006. For more information, please visit here, and then review the requirements here.
Undergraduate Academic Advisors
The Undergraduate Advisors for the School of Computer Science are available in Room 5302HP; or by email. The undergraduate advisors can assist with information about prerequisites and preclusions, course substitutions/equivalencies, understanding your academic audit and the remaining requirements for graduation. The undergraduate advisors will also refer students to appropriate resources such as the Science Student Success Centre, Learning Support Services and Writing Tutorial Services.
SCS Computer Laboratory
Students taking a COMP course can access the SCS computer labs. The lab schedule and location can be found here. All SCS computer lab and technical support information can be found here. Technical support staff may be contacted in-person or virtually, see this page for details.
Mental Health and Wellness
The Carleton Wellness Website is a wonderful resource link to include in the course outline for students
Academic Accommodations and Regulations
Academic Accommodations. Carleton is committed to providing academic accessibility for all individuals. You may need special arrangements to meet your academic obligations during the term. The accommodation request processes are outlined on the Academic Accommodations website.
Chat GPT/Generative AI Usage. As our understanding of the uses of AI and its relationship to student work and academic Integrity continue to evolve, students are generally required to discuss their use of AI in any circumstance not described here with the course instructor to ensure it supports the learning goals for the course. However, note the following:
- Many of the assessed activities in this course were designed to be completed by an individual working alone. Unless it is explicitly stated otherwise, the use of any AI system will be considered academic misconduct. This includes, but is not limited to, chatbots or code generators (e.g., ChatGPT, Google Gemini, Microsoft Copilot), research assistants (e.g., Elicit), and image generators (e.g., Stable Diffusion, Dall-E), etc.
- An exception to the above rule is made for automated grammar and punctuation checking tools (such as Grammarly).
- References to any material you use but did not originate must use the IEEE/APA/MLA citation style. Failure to reference materials correctly can result in severe penalties, and the use of manufactured (i.e., falsified) or misleading references will be treated as evidence of plagiarism and considered academic misconduct.
- Everything you submit for evaluation (i.e., assignments, quizzes, tutorials, examinations, etc.) must be the result of your own work and only your own work. If you copy more than five consecutive words or any non-trivial snippet of code from a single source without providing a valid reference, then that is considered plagiarism.
Academic Integrity. Students are expected to uphold the values of academic Integrity, which include fairness, honesty, trust, and responsibility. Examples of actions that compromise these values include but are not limited to plagiarism, accessing unauthorized sites for assignments or tests, unauthorized collaboration on assignments or exams, and using artificial intelligence tools such as ChatGPT when your assessment instructions say it is not permitted.
Misconduct in scholarly activity will not be tolerated and will result in consequences as outlined in Carleton University's Academic Integrity Policy. A list of standard sanctions in the Faculty of Science can be found here.
Additional details about this process can be found on the Faculty of Science Academic Integrity website.
Students are expected to familiarize themselves with and abide by Carleton University's Academic Integrity Policy. Claiming ignorance of or confusion about the academic integrity standards as described in the Policy does not excuse a student from responsibility for violations of those standards.
All quizzes, tests and exams are expected to be completed individually, and without electronic aid; any communication or access of electronic devices (e.g. cellphones) during the test will be considered cheating. Use of Smart Glasses (or other similar assistive technologies) before or during a test is strictly prohibited and is considered an academic integrity violation. Even if you have prescription glasses with assistive technologies, you will not be allowed to use them during the test, so please make sure that you have acceptable prescription glasses. The proctor has the right to ask to inspect your glasses before or during the test. In addition, unless authorized with PMC accommodations, you are NOT allowed to use headphones nor ear buds during a test. Also, during a test, if you choose to wear a baseball cap, sunglasses or anything else that would prevent a proctor from monitoring where your eyes are focused during the test, you will likely be asked by a proctor to move to a different seat. Lastly, you must submit your test before leaving the classroom or it won't be graded.
Student Rights & Responsibilities. Students are expected to act responsibly and engage respectfully with other students and members of the Carleton and the broader community. See the 7 Rights and Responsibilities Policy for details regarding the expectations of non-academic behaviour of students. Those who participate with another student in the commission of an infraction of this Policy will also be held liable for their actions.