I just presented a talk at DEF CON 24. This discusses "captive portals" -- the websites that attempt to manage access to open WiFi and similar semi-public networks -- and their flaws that allow bypassing them.
I presented a talk at the DEF CON 101 track of DEF CON 23 this year; for those of you who have been directed to the site from the talk, you can find the slides on this site here: DEF CON 23: The Only Way to Be Sure: Obtaining and Detecting Domain Persistence Note that […]
For anyone looking for my talks at DEF CON 22 and Thotcon 0x6 on the topic of detecting Bluetooth surveillance systems, the DEF CON slide deck is available for download here, or in PDF. The (abbreviated) Thotcon version is here.
With Apple's introduction of Touch ID for the new iPhone 5S, there's been a lot of news coverage of their new fingerprint-based unlock system. People want to know: is it secure? Can someone bypass it? But the thing about fingerprints is that they've been easy to bypass for more than 20 years.
We have a hundred thousand spies now: they have the capability, they have the information. The law will change; maybe not now, maybe not for a decade, but if don't strangle this right now, it will change. They can do it, so they must: as Homer said, the blade itself incites to violence.
Recently, the South Carolina Department of Revenue was hacked, losing tax records on 3.6 million people — that is, most of South Carolina’s population. These contained Social Security numbers at the very least, as well as 3.3 million bank account numbers, and may have been full tax returns (they haven’t said.) There’s been the usual […]
This year I've decided to make a departure from the talk-by-talk trip reports I've done in the past. Most of the interesting presentations are already online (the whitepapers and slide decks, at least) and I'll link to them here, but overall this was a very interesting year in information security and I think the gestalt and the keynotes are more important than the specific exploits demonstrated.
Sunday was interesting — this was actually the first DefCon I have attended (and I’ve been to the last five) where Sunday was actually busy. Normally Sunday feels very empty — most people have gone home, and the ones that are still around are too hung over to go to the morning sessions. I was […]
Having finished with BlackHat, I checked out of the Flamingo and moved to DefCon’s new location this year, the Rio. This was an enormous upgrade from the Riviera, the previous location. For one, the conference center is nearly 50% bigger, and it’s beautiful. Traffic flow was greatly improved, despite record attendance (~12,000, from estimates I’ve […]
The second day of BlackHat started out with a keynote by Mudge. I attended this one despite the normally-dull nature of BlackHat keynotes, because while Mudge is a Fed now (he works for DARPA), he has a long history as a contributor to hacker culture and I wanted to hear what he had to say. […]
I spent last week in Las Vegas, for BlackHat USA 2011 and DefCon 19 — my annual security conference pilgrimage. Overall impression: the quality of the actual presentations was below-average this year, but it was still an educational experience, a good professional networking event, and probably the most fun I’ve had at DefCon so far. […]
With the news that the raid on Osama bin Laden's compound resulted in the capture of at least 10 hard drives and over 100 miscellaneous data storage devices (CDs, DVDs, flash drives, floppy disks, etc.), a common question that's come up on news sites is "So, how likely are we to be able to decrypt these things? How good is the best non-government-grade encryption, anyway?"
The mainstream press is full of articles telling you how to use secure passwords, like this one in MSNBC or this one in TechNewsDaily. They echo the traditional wisdom on password security — use a long password, put numbers and symbols and multiple cases in it, and don’t record it anywhere. Well, I suppose there’s […]
I’ve just returned from a trip to BlackHat Briefings USA 2010 and DefCon 18. As always, it was an enjoyable week in Las Vegas learning about the latest research, networking with the surprisingly small world of security professionals, and generally having fun hanging out with a lot of interesting people with the hacker mindset. BlackHat […]
Companies like Apple that try to control devices purchased by end-users create their own serious security problems. It turns out that Apple trying to protect itself from you makes you vulnerable to attackers. Apple doesn’t want you to run anything on your phone that they didn’t approve. But of course, customers want to run whatever […]
At BlackHat Briefings USA 2010 in Las Vegas this year, I presented a session entitled “Secure Use of Cloud Storage,” covering ways that developers can use and misuse cloud storage systems like Microsoft’s Windows Azure Storage and Amazon’s Simple Storage Service (S3) and SimpleDB. While the released versions are available on the BlackHat official website, […]
If you happen to want a machine-readable (e.g. XML or iCal) version of the DefCon 18 schedule, my lovely wife made one which I’ve posted one on Google Calendar: XML iCal HTML This is accurate as of 7/27, so be aware that more recent schedule changes may not be reflected! I’ll be attending the conference, […]
Google has added the ability to access their search engine via SSL. The interface couldn’t be simpler — you just go to https://www.google.com instead of http://www.google.com. The news media has been quite favorable to this — after all, search queries are at least semi-private in that you might not want your employer or neighbors to […]
The Thursday keynote was given by Bob Lentz, a Deputy Assistant Secretary of Defense for the United States. His main point was the paradigm shift from network-centric security to what he called content-centric security, and the fact that this devalues the protections around network perimeters. Static defenses don’t work when all the services being used […]