Showing posts with label Bsides. Show all posts
Showing posts with label Bsides. Show all posts

Saturday, May 6, 2023

BSides Austin 2023

After a Covid hiatus, the BSides Austin computer security conference returned as an in-person event. We enjoyed meeting people we had not seen in two-and-a-half years. The conference ran three parallel tracks and I blocked out some talks to attend but I spent the day near Laurel’s table supporting Kids First Uganda. It was time well invested, visiting vendors and watching attendees. I even met a recruiter who gave me a QR code to upload my resume. 

Three tracks with 24 sessions included cloud-focused phishing,
containing smishing incidents, attacking Microsoft Cloud,
mitigating malvertising, and "Don't Let Your Roomba
Sell Your Bank Login."


There was a BSides Austin virtual meeting on 2 December 2022 that I did not attend. In the past 30 months, I have been in several virtual conference chatrooms and they are a poor substitute. It is much easier and more comfortable to stand in an open hall just watching and waiting than it is to be in a chatroom by yourself. 



The conference featured a day of training on Thursday. (Laurel attended; I did not.) In fact, this year's theme was "Never Stop Learning." 


Organizer Janice Daquila-Pardo told me that they had 600 sign-ups and about 500 in attendance. The last full-scale event in 2019 tallied 700 attendees. We signed up late but got t-shirts nevertheless because of the no-shows. 



Locksporting (above) had two tables this time.
In addition to a wide range of key locks, there were combination
locks and even ziplocks to try your skills on (bottom right).
Next to them were the hardware hackers (bottom left). 
IT managers worry about clouds as services and they
seldom see the more obvious weaknesses.

History of BSides Austin

“The very first BSides in Austin was organized in 2010 by Jack Daniel and Ben Tomhave. This was the fourth BSides ever to be held, and it had about 30 attendees. In 2011, Michael Gough stepped up and took over organization of our local event. Even as he continued to manage the BSides Austin events through 2015, Michael also helped kick off BSides Texas in 2012, and was heavily involved in BSides throughout Texas (including Dallas, San Antonio and Houston). 

“Matt [Pardo; @ultraslogger] and Janice [Daquila Pardo; @bsidesaustin] have been running BSides Austin since 2016. BSides Austin has grown in that short time into a two-day event with around 750 participants. Our goal is to continue providing a fantastic event with great content and training for the information security community.” -- https://bsidesaustin.com/about/

Security Innovation sponsored this year's capture the flag contest. 
The website of this fictional bank had 30 vulnerabilities
and prizes went to those who found the most.
The overarching comment was: "It was harder this year
and the scores were lower."


Laurel and I have volunteered at BSides Austin and LASCON, the Lonestar Application Security Conference, both created and maintained largely by members of the local OWASP chapter. Laurel worked registration and I monitored the presentation rooms, taking head counts and thanking the speaker with a Starbucks gift card. We also presented. Laurel delivered on securing your home network with a Raspberry Pi and I spoke on physical security for data centers. 

For their conference swag, Blackhills Information Security
brought several games including interactive comics
and a complex card game (three decks). 

Our first computer security conference in Austin was BSides 2013 and then the benefit outreach was Hackers for Charity delivering to Uganda. Just about every white hat hacker gathering has some social engagements supporting local or international communities not usually served well by others. Laurel met Kids First Uganda through a cousin. She had quilts made from t-shirts from previous computer security conferences and those were offered for donated sale at BSides.

Saturday, April 2, 2016

BSides Austin 2016

The seventh annual BSides Austin computer security conference ran March 31-April 1, 2016. I served as a Host for breakout sessions, introducing speakers, and keeping track of time. It was an overflow crowd of 350 with 150 turned away at the door, or denied a slot on the wait list. In addition, several student groups could not be accommodated at all. 
 
Breakfast with the Sponsors.
We had two tracks on Thursday and three on Friday. You can find the full schedule on the conference website here.  Many of the sessions were easy to label. “I am a Software Developer. What do you mean I’m on the Blue Team?” by Aaron Poffenberger was clearly for the Blue Team. “It’s not About the Technology. It is About the Psychology” by Dr. Hend Ezzeddine and Flora Moon was easy to label for Social Engineering.
 
32 Formal Technical Sessions
The first night also included open mike
"Fire Marshall Talks"
But many others crossed several lines on the corporate org chart, and the sessions were not narrowly defined. You had to pick your presentations. That said, all of the hands-on workshops were held in the same room on the same day.
 
Rapper "Dual Core"
Each track had a Host and a room Monitor.  The monitors counted the room three times (beginning, middle, end) and interfaced with the hotel staff when needed.
 
Waiting for the Keynote by Ed Skoudis from SANS.
The convention would have cost ten times as much to attend were it not for the sponsors. 
Digital Defense, Rapid 7, SANS, and Splunk were gold sponsors this year. 
The silver sponsors were RSA, Log-MD, ISSA, Pluralsight, Checkmarx,
Anomali, and Netskope.
The five core sponsors were Velocitystorm, Expressworks,
Fusion-X (thanks for the beer!),
No Starch Press, and Pentester Academy.
As a technical writer, my interests are more general. I am seldom held accountable for information security, except as we all are. These were among my take-aways:
  • The best lockpicking tools for the money are the Sparrow Tuxedo ($40) and the Tremendous Twelve by Toools from Southern Specialties ($30). 
  • The best locks are biaxials from Medeco and the Schlage Primus. You can spend $75 for one of these and secure your servers, or you can buy a dozen others at $5.95 each and let us all have access to your servers.
  • For a knowledge worker your credibility is your product. 
  • The highest priorities for information security should be Asset and Inventory Management, Decision and Remediation Workflows, and Visualization and Metrics. The lowest priorities are vulnerability assessment and scanning, penetration testing, and buying cool tools. 
  • Work the OWASP Top Ten vulnerabilities. 
  • Amateurs target systems. Professionals target people. 
  • Security will not be accepted until and unless IT is made personal: it is you in your home who will be violated by your release of company information at work.

Basic security
They call it “BSides” in honor of the old rock ‘n’ roll 45 rpm single releases of the 1950s and 60s. The producer picked a hit for Side A and put something else (usually mediocre) on Side B. Elvis Presley’s “Don’t Be Cruel” was an exception. The Beatles releases were all exceptions.
Presentations crossed organization lines
The concept began in the US in 2009 with Mike Dahn, Jack Daniel, and some others because the CFP [Capture the Flag: computer intrusion challenge – MEM] for Black Hat Vegas or DEF CON was oversubscribed and those unable to present decided to hold their own conference on the 'b side'. -- https://en.wikipedia.org/wiki/BSides

PREVIOUSLY ON NECESSARY FACTS


Thursday, March 19, 2015

BSides Austin 2015

In the old days of rock 'n' roll 45 rpm records, the "A" side was the hit release and the "B" side was just something else by the group.  The Beatles broke the decade-long precedent by topping the charts with both A-side and B-side songs.  At DefCon 17 (July 2009), the speaker proposals were over-subscribed, so some of them held their own "on the b-side."  B-Sides Austin goes back six years to 2009.  (BSides Wiki here.)  This year continued the trend for informative speakers, entertaining extras, great vendor support, and engaged participation within the computer security community of Austin.
Volunteer Staging in Preparation for the Opening 

About 300 Austin Computer Security Professionals Attended
Issuing ID, lanyards, t-shirts, and tote bags,
orienting the attendees,
and basically bringing normalized database order
to a Markov Chain. 
Our social media coordinator
tweeted his thumbs off
It all hinges on the sponsors.
Without them,
the conference would cost four times as much.
Coffee from the Denim Group
.
The Opening Session
IBM was gracious and supportive. I got a "Think" ballcap.
Rapid 7, ISSA, Kaspersky Lab, Praetorian, IOActive, 

Digital Defense, Synack, OpenDNS,
LastPass, Splunk, 

and the Independence Brewing Company
also underwrote the conference.

(Full list at BsidesAustin.com)
Two job boards
begged for analysts, engineers, and architects.
(The Premera breach was not yet admitted.)
Lock picking is part of hacker culture
as explained …
…in Hackers: Heroes of the Computer Revolution
by Steven Levy (1984).
 
Worth one thousand words.
Friday Keynote Speaker
Reuben Paul (link among others) interviewed.
Conference coordinator
Richard Stephens meets the media.
Austin Fire Marshall Larry Jantzen
spoke at lunch on the 2nd day,
explaining the multifaceted work of his department.
BSides Austin has a love-hate relationship with the Fire Marshall
because he closed our evening session the first year
for violating the attendance limits.
Security is security, physical or cyber.
Breakout session speaker Aamir Lakhami
worked as an advisor on
Big Bang Theory and The Avengers.
I volunteered to serve as master of ceremonies for Track 2. I introduced speakers. Basically, I looked them up on LinkedIn; and then I met them at the conference to get the kind of interesting and positive  things that most people would not know. I timed the talks, kept them on schedule, and counted the audience before and after.

I met Earl Carter from Cisco Systems. Josh Pyorre from OpenDNS, Kate Brew of the Alien Vault and her colleague Charisse Castagnoli (adjunct professor of law at the John Marshall Law School, among other affiliations), Aamir Lakhmi from Fortinet, Praetorian's Julian Dunning, and IoActive's Damon Small. (Damon was at the Happy Hour the night before.)  My sessions closed with Roxy D of Firehost and Mike Sconzo of Bit 9 + Carbon Black.

Also on NecessaryFacts
BSides Austin 2013 
Your Cell Phone is not Safe
Securing Your Viper Against Cylons
Locksporting

Saturday, March 23, 2013

Hacking Computer Security: BSides Austin 2013


The 3-1/2 day event  (March 20-23) kicked off with a screening at the Paramount Theater of Code 2600, Jeremy Zerechak’s documentary about the origins and present reality of computer hacking and privacy issues.  The festival officially began the next morning at the Wingate by Wyndham in Round Rock.  Registration was $10 per day for the official 2-day event.  The movie was extra.  Breakfast, lunch, dinner, and beer (courtesy of New Republic Brewing of College Station) came with the price of admission. Conference schwag included t-shirts and complicated ballpoint pens. Other giveaways and door prizes were plentiful. Officially closing Friday at 5:00 PM,. an after-party and Saturday field trip to Texas A&M’s Disaster City training center capped the hacking holiday of hard work.
Three men standing. One shirt is yellow, the other blue, the third red.
Star Trek theme with
Command for the volunteers,
Blue for attendees
and some Redshirts.

Special two-day games included a lockpicking contest, a social engineering challenge, and “capture the flag.” 

Lockpicking is a traditional cultural aspect of hacking.  The practical side for computer security professionals is that business managers typically hang five dollar locks on server racks with millions of dollars of data: you need to know your exposed risks.

“Social engineering” is the engagement of hapless intermediaries as tools to reveal and expose software and hardware. The two-day challenge was limited to the hotel and the adjacent shopping center: the residential neighborhood with its homes, day care, school, and senior center, was off limits. 

“Capture the flag” involves a server loaded with typical applications. The defense team must keep the system up and running while offense teams attempt to break in.

Sponsors included RackSpace, Digital Defense Inc., Visible Risk, RSA, Rapid 7, Palo Alto Networks, Mandiant, ISSA of Texas, Pwnie Express, Security Innovation, Tenable, The Denim Group, Milton (providers of shwagg), Last Pass, Haking, the International Association of Forensic Investigators, Longhorn Lockpicking, and New Republic Brewery of College Station. Also mentioned were "Protect Your Nuts" and "Kommand && Kontrol: Revenge of the Carders."

Money was collected for two charities, "Hackers in Uganda" and the Electronic Frontier Foundation, via the sale of conference buttons.  EFF is famous for protecting and extending rights in cyberspace.  "Hackers in Uganda" is to be a film by Jeremy Zerechak.
About half the attendees sat in the big room for box lunches
Friday lunch: about half of the 175+
attendees sat in the big room.

BSides San Antonio will be held in May, DFW in November. (BSides Texas here). 



Summaries and reviews of talks delivered follow below.
(Much of this presentation began as posts to the Group64 and the Austin Tech Geeks local groups on LinkedIn.)