Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Saturday, May 23, 2026

InnoTech Austin 2026

I checked out a book of essays by Kurt Vonnegut from my local library. Speaking at college graduation ceremonies through the 1990s, Kurt Vonnegut said that you need about fifty people in your life, not “electronic ghosts” but real people. So, I had an additional reason to attend InnoTech Austin. I had not been to an InnoTech conference in too many years. (See “Previously” below.) Celebrating the start of its third decade, this year’s convention was for computer security professionals. I had a great time meeting people and their companies, and talking with them about their products and services. 



This year’s host was The HT Group, a recruiting,
staffing, and management consulting agency.
They had three tables.
 

"In one focused day, Austin InnoTech creates an environment where education, innovation, peer-to-peer networking, and the latest technology and business solutions are all available specifically for IT & security professionals."





Entering the hall, the first people I met were Hannah Webster
and Will Arnett from Alias Digital Forensics.



Among the team sent by Genius Road of Dallas was
Associate Account Manager, Catherine Diaz.


To encourage circulation, there was a “Passport” game.
Completed itineraries were dropped into box from which
randomly selected winners were dawn
.

Loren Woeber, VP at WiCyS: Women in Cyber Security
greeted many interested visitors.


Diane Kenyon and Jazmen Wright from 
Austin Women in Technology
 staffed a table at the Entrance. 




Red Hat was a major sponsor.

They handed out red leis that were popular. 


They say, "Apex sits at the center
of retail investing infrastructure,
supporting millions of accounts across hundreds of clients.
We see what investors buy, sell, and hold—in real time,
across four generational cohorts.
" Apex FinTech Solutions
cites
$265 Billion in assets under custody,
o
ver 40 million brokerage accounts plus another
119 million cost-based accounts. 


There was a lot of active listening.


Contrary to the assertion of Google's AI Overview, the 
conference was held at the PALMER EVENT CENTER at
Barton Springs Road and Riverside Drive.


PREVIOUSLY ON NECESSARY FACTS

InnoTech Austin 2015  

BSides Austin 2023 

Austin Astro Public Star Party

ArmadilloCon 47 Part 3 

(ISC)^2 Holiday Dinner 2018 


Saturday, May 6, 2023

BSides Austin 2023

After a Covid hiatus, the BSides Austin computer security conference returned as an in-person event. We enjoyed meeting people we had not seen in two-and-a-half years. The conference ran three parallel tracks and I blocked out some talks to attend but I spent the day near Laurel’s table supporting Kids First Uganda. It was time well invested, visiting vendors and watching attendees. I even met a recruiter who gave me a QR code to upload my resume. 

Three tracks with 24 sessions included cloud-focused phishing,
containing smishing incidents, attacking Microsoft Cloud,
mitigating malvertising, and "Don't Let Your Roomba
Sell Your Bank Login."


There was a BSides Austin virtual meeting on 2 December 2022 that I did not attend. In the past 30 months, I have been in several virtual conference chatrooms and they are a poor substitute. It is much easier and more comfortable to stand in an open hall just watching and waiting than it is to be in a chatroom by yourself. 



The conference featured a day of training on Thursday. (Laurel attended; I did not.) In fact, this year's theme was "Never Stop Learning." 


Organizer Janice Daquila-Pardo told me that they had 600 sign-ups and about 500 in attendance. The last full-scale event in 2019 tallied 700 attendees. We signed up late but got t-shirts nevertheless because of the no-shows. 



Locksporting (above) had two tables this time.
In addition to a wide range of key locks, there were combination
locks and even ziplocks to try your skills on (bottom right).
Next to them were the hardware hackers (bottom left). 
IT managers worry about clouds as services and they
seldom see the more obvious weaknesses.

History of BSides Austin

“The very first BSides in Austin was organized in 2010 by Jack Daniel and Ben Tomhave. This was the fourth BSides ever to be held, and it had about 30 attendees. In 2011, Michael Gough stepped up and took over organization of our local event. Even as he continued to manage the BSides Austin events through 2015, Michael also helped kick off BSides Texas in 2012, and was heavily involved in BSides throughout Texas (including Dallas, San Antonio and Houston). 

“Matt [Pardo; @ultraslogger] and Janice [Daquila Pardo; @bsidesaustin] have been running BSides Austin since 2016. BSides Austin has grown in that short time into a two-day event with around 750 participants. Our goal is to continue providing a fantastic event with great content and training for the information security community.” -- https://bsidesaustin.com/about/

Security Innovation sponsored this year's capture the flag contest. 
The website of this fictional bank had 30 vulnerabilities
and prizes went to those who found the most.
The overarching comment was: "It was harder this year
and the scores were lower."


Laurel and I have volunteered at BSides Austin and LASCON, the Lonestar Application Security Conference, both created and maintained largely by members of the local OWASP chapter. Laurel worked registration and I monitored the presentation rooms, taking head counts and thanking the speaker with a Starbucks gift card. We also presented. Laurel delivered on securing your home network with a Raspberry Pi and I spoke on physical security for data centers. 

For their conference swag, Blackhills Information Security
brought several games including interactive comics
and a complex card game (three decks). 

Our first computer security conference in Austin was BSides 2013 and then the benefit outreach was Hackers for Charity delivering to Uganda. Just about every white hat hacker gathering has some social engagements supporting local or international communities not usually served well by others. Laurel met Kids First Uganda through a cousin. She had quilts made from t-shirts from previous computer security conferences and those were offered for donated sale at BSides.

Tuesday, December 11, 2018

(ISC)^2 Holiday Dinner 2018

Indeed hosted this year's holiday party for the Austin chapter of (ISC)^2. About 50 people attended and enjoyed a surprising German menu with sausages, sauerkraut, potato pancakes, and chocolate tort.
The computer security community here in Austin centers on OWASP, the Open Web Application Security Project. They host two conferences a year, BSides and LASCON. For over five years they have held weekly lunchtime study cells in space provided by National Instruments. With OWASP, the key word is "open." I am a member of OWASP and I am a technical writer. I volunteer to work the conventions and have even presented. But I hold no certifications in computer security. These people do. The CISSP certification from (ISC)^2 is the gold standard of competence in information security.

The International Information Systems Security
Certification Consortium

https://www.isc2.org/Certifications
Austin boasts one of the largest computer security communities in the world. Fortune 500 companies and multinational corporations that are headquartered elsewhere put their IT departments in Austin.  The US Army Futures Command is here. But as large as it is, the infosec crowd is just another village and pretty soon everyone knows everyone. Parties like these are how we exchange cultural knowledge.


In addition to those large enterprises and governmental organizations, we have no shortage of start-ups. People here solve problems by advancing ideas, building technologies, and delivering solutions.

Austin has three epicenters of information technology: the north side, the hill country, and downtown. Downtown includes both the Congress Avenue corridor and the University of Texas.  The hill country runs west and north off the 360 and Farm to Market 2222 at the iconic Pennybacker Bridge. The north side, north of old Tech Ridge is where you find Dell, HP, GM, and many others. But tech is everywhere here. AMD is on Southwest Parkway. Freescale just moved from there to the Airport area where you can find competing server farms.


Indeed also hosted the launch of the Austin Security Alliance. Over a dozen groups sent representatives to create an ecosystem that will respond, adapt, grow, replicate. and evolve solutions to information security. It goes beyond mere firewalls, important as they are. The technology of trust is how we all sign a hundred contracts a day without even thinking about it. Every time you swipe a card, every time you log in, every time you visit a page, you authenticate by swapping secure tokens.


The most revealing facts were the ones not mentioned. For all of the vulnerability scans, red team - blue team, packet sniffing, threat assessments, responses and remediations, I never heard anyone actually say what they did. The tech talk was fairly abstract. There were no war stories. They did talk about other people's problems because huge data breaches are always in the news.

PREVIOUSLY ON NECESSARY FACTS
READABILITY IS THE ONLY METRIC
AUSTIN B-SIDES 2016
LASCON 2014
CHARLES BABBAGE: CODE BREAKER


Saturday, December 16, 2017

Austin Security Alliance

On Monday, December 11, 2017, members of 14 computer security organizations met at Indeed headquarters to launch the Austin Security Alliance. ISSA's president, Larry Moore, was the tip of the spear: this was his idea. But very many people were involved because they saw the wisdom in the project. With 20,000 to 30,000 professionals employed in computer security, Austin intends to be declared the Computer Security Capital of America.
DON'T PANIC was the cover band: classic 50s to urban.
As Larry and a dozen other organization officers and leaders explained in the opening presentation, the purpose of the ASA is to enable and facilitate cooperation across specialties. ASA maintains no membership of its own  and collects no dues. My perception is that it works. I should have intuited but did not know that we have a local ASIS chapter. It was nice to meet them. I was a national member for two years. Now, I have a reason to renew.

ASA MEMBER ORGANIZATIONS
  • ASIS International
  • Association of Continuity Professionals – Capital of Texas Chapter
  • Austin Hackers Anonymous (AHA!)
  • Cloud Security Alliance – Austin Chapter
  • Electronic Frontier Foundation – Austin
  • Hackformers
  • Infragard
  • Information Systems Audit & Control Association (ISACA)
  • International Information Systems Security Certification Consortium (ISC)² – Austin Chapter
  • Information Systems & Security Association (ISSA) – Capitol of Texas Chapter
  • Longhorn Lockpicking Club
  • Open Web Application Security Project (OWASP)
  • Secure Austin
  • Texas CISO Council
PREVIOUSLY ON NECESSARY FACTS
TDEM 2017
BSIDES Austin 2016
InnoTech 2015
LASCON 2014
BSides Austin 2013
Securing Your Viper Against Cylons

Saturday, May 20, 2017

TDEM 2017 Texas Emergency Management Conference

Laurel and I attended the 2017 Texas Department of Public Safety Division of Emergency Management annual conference in San Antonio. Although it is a four-day show, we were there just for Thursday, May 18. We started with the exhibit hall and attended two break-out sessions. These are some of the vendors whom I met.

Dr. Deb Zoran is the operations supervisor of
VET outreach of Texas A&M University.
They coordinate animal rescue during disasters and emergencies.
John Taylor and Hannah Coffey of BOLD Planning,
one of the providers of mitigation and remediation plans for
organizations that do not have adequate in-house emergency planning.
Sean Scott developed the Red Guide handbooks.
They are available in English and Spanish.
Keith Blaylock of eXpress Sandbag System
did not bring the proprietary machinery with him.
However, I found the sandbags to be portable,
standardized, and stackable.
And he said that he could produce
1000 per hour all day long.
Michael Shanks of LRad explained
that his sound output speakers will cover
huge, city-sized areas with good clarity
for voice notification in times of emergency.
Mike Ross does apps and he has them for
emergency management. In the age of the
smartphone it is an easy and effective way
for jurisdictions to get the word out --
the right information...
from the right source.
Vanessa Forté of ProPac brought a wide range of
pre-packaged emergency supplies from
first aid kits to food and drink for
one person or large groups.
Mark Mathiesen of On the Mark Weather is one of several
commercial meteorologists with his own brand of applied theories.
When I reviewed and edited contracts for TDEM in 2014,
I was surprised to learn that the government agency, NOAA,
as respected as it is, is not the leading edge, and only tells you
what they tell everyone in a wide area all at the same time.
Dr. Mathiesen specializes in micro-events:
he can tell you if your school could be hit. 
Of course, there were many more to be met.  My friends from Intermedix and WebEOC were there. So were the folks from STEAR, the State of Texas Emergency Assistance Registry for people who want to be helped when getting help is a matter of life and death. I met Major Ernest Branscum of the Salvation Army several times during the day as we toured the exhibit hall. I was happy to be able to add my name to the contact list for the local chapter of the Association of Continuity Managers.   

On Thursday, May 18, at 4:00 PM, Laurel and I attended an excellent session on Insurance Fraud. The presenters were Lt. David Taylor (Compliance) and John Plent (Consumer Protection) from the Catastrophe Response Team of the Insurance Fraud unit of the Texas Department of Insurance. Just to note: The Department of Insurance is one of about 20 state agencies and departments that has its own sworn and weaponized peace officers. As explained below, when on the streets, talking to roofing contractors, he has the full law enforcement authority of any police officer in Texas.

In the aftermath of a disaster, swarms of unlicensed contractors appear, soliciting business, and being paid with money from insurance settlements. The work is uneven in quality. Sometimes, the “contractors” take a “down payment” and never return. Occasionally, they take a partial payment, do partial work, then leave, with a promise to return, which puts the matter out of the criminal law and into civil law.

The TDI catastrophe teams help people work with insurance adjusters; and they can assist insurance companies in the field. They work with consumers to help with insurance claims. Lt. Taylor and Mr. Plent come to your town to mitigate (and ideally prevent) violations and victimizations. They start by meeting with city officials. They acknowledge that after a severe storm which has taken lives, mitigating insurance fraud might not seem highly important. However, they have found law enforcement and other city officials to be very helpful. If the city has regulations, they say, then make sure that all solicitors are registered and licensed. Drive the streets; and where you see roofers working or knocking on doors, ask to see their papers. Municipalities should run background checks for outstanding warrants and sex offender registration. Their primary advice is to homeowners is to never accept a solicitation. You, the customer, should drive the process by seeking out reputable companies and getting competitive bids.

We have no state-level licensing of contractors here in Texas. However, we do have the Roofing Contractors Association of Texas and the Building Officials Association of Texas (BOAT at www.boatx.org). In fact, BOAT was one of the vendors at the TDEM conference. 


Read about the fraud team here
Watch one of their videos here.

At 2:30 PM on May 18, Laurel and I attended a disjointed, lackluster session on cyber security.  Despite our abiding professional involvement in computer security, this one put us both to sleep. The presenter was David Morgan (CISSP, CNSS NSA Security), who is a cybersecurity officer and information security manager at the Texas Department of Public Safety. He certainly seemed well qualified from his time in the Marine Corps to his experience as a visiting professor at several colleges and universities. The bottom line is that the content of his presentation did not meet the criteria set by the title of his talk, "Cyber Security - A Critical Component for Emergency Management." 

Everything we do in response to a disaster or a community event depends on computers, from smartphones to laptops. To coordinate our efforts, we bring WebEOC into community shelters. Some at this conference had special responsibilities for the emergency bands such as TICP (Texas Interoperability Communication Package) and MARS (Military Affiliate Radio System). David Morgan did not tell us how to secure any of them, or how to detect an intrusion.

Laurel and I were most interested in knowing about how computer hackers have disrupted emergency response. Aside from mentioning the recent incident in Dallas -- (Dallas Morning News here among very many others) -- in which the weather sirens sounded at midnight, he had nothing to say. 

Hackers have been changing traffic lights since at least 2003, though the ability to do so was known in the 1980s. (See Wired from 2005 here.) Recently, the Surprise, Arizona, city 911 was taken out by a hacker (See Washington Times story here.)  Bear in mind, though, that the infamous “Operation Sundevil” from 1990, which alleged that hackers had broken into the nationwide 911, was exposed and disgraced.  (See  “Operation Sundevil” in Wikipedia here and “Jefferson in Mirrorshades” in a hacker archive here. )  None of that was in this  presentation. 

David Morgan did allude to the existence of viruses, worms, trojans, and spyware, but did not differentiate among them, or tell us how to detect, mitigate, remediate, or prevent them. He did say that the Macintosh operating system is easily given to viruses because it is based on Unix, which is the operating system in which viruses were invented. David Morgan defined “Zero day” as the source of unknown vulnerabilities. He explained a “root kit” by saying that if you are “root” then you own the system.

All of that being as it may, I personally benefited by learning about Shodan.io. Coming to work the next day, I visited the site, read about it on Wikipedia, and made a note to myself to follow up. 
  
PREVIOUSLY ON NECESSARY FACTS
BSides Austin 2016
InnoTech 2015
CERT: Community Emergency Response Team
The Living Fish Swims Under Water

Friday, September 9, 2016

Hackers Heart Small Talk

Social engineering is the gathering of computer system information by other means.

T-Shirt from Defcon 24
It is common for Internet companies to rely on standard software. Even when provided by competing firms, the forms and formats of presentation are necessarily similar.  

What was your childhood pet's name?
What street did you grow up on?
What was the make of your first car?
What is your mother's maiden name?

The last line on the t-shirt is hard to read because it is on the midriff:  Is your voice your passport?  is a reference to Sneakers, the hacker film with Robert Redford, River Phoenix, Dan Aykroyd, James Earl Jones, Sidney Poitier, Mary McDonnell, and Ben Kingsley.     

Other popular keys to your files include
Who was your favorite teacher?
In what city did your parents meet?
What city did you grow up in?
What high school did you attend?
What was your favorite subject in school?

It is not so much that you cannot trust your co-workers (though there is that), but that you cannot know who else is listening when you are out in public socializing with your colleagues.

ALSO ON NECESSARY FACTS
Hacking
Passwords
BSides 2016
Securing Your Viper from Cylons
When Old Technologies Were New

Saturday, April 2, 2016

BSides Austin 2016

The seventh annual BSides Austin computer security conference ran March 31-April 1, 2016. I served as a Host for breakout sessions, introducing speakers, and keeping track of time. It was an overflow crowd of 350 with 150 turned away at the door, or denied a slot on the wait list. In addition, several student groups could not be accommodated at all. 
 
Breakfast with the Sponsors.
We had two tracks on Thursday and three on Friday. You can find the full schedule on the conference website here.  Many of the sessions were easy to label. “I am a Software Developer. What do you mean I’m on the Blue Team?” by Aaron Poffenberger was clearly for the Blue Team. “It’s not About the Technology. It is About the Psychology” by Dr. Hend Ezzeddine and Flora Moon was easy to label for Social Engineering.
 
32 Formal Technical Sessions
The first night also included open mike
"Fire Marshall Talks"
But many others crossed several lines on the corporate org chart, and the sessions were not narrowly defined. You had to pick your presentations. That said, all of the hands-on workshops were held in the same room on the same day.
 
Rapper "Dual Core"
Each track had a Host and a room Monitor.  The monitors counted the room three times (beginning, middle, end) and interfaced with the hotel staff when needed.
 
Waiting for the Keynote by Ed Skoudis from SANS.
The convention would have cost ten times as much to attend were it not for the sponsors. 
Digital Defense, Rapid 7, SANS, and Splunk were gold sponsors this year. 
The silver sponsors were RSA, Log-MD, ISSA, Pluralsight, Checkmarx,
Anomali, and Netskope.
The five core sponsors were Velocitystorm, Expressworks,
Fusion-X (thanks for the beer!),
No Starch Press, and Pentester Academy.
As a technical writer, my interests are more general. I am seldom held accountable for information security, except as we all are. These were among my take-aways:
  • The best lockpicking tools for the money are the Sparrow Tuxedo ($40) and the Tremendous Twelve by Toools from Southern Specialties ($30). 
  • The best locks are biaxials from Medeco and the Schlage Primus. You can spend $75 for one of these and secure your servers, or you can buy a dozen others at $5.95 each and let us all have access to your servers.
  • For a knowledge worker your credibility is your product. 
  • The highest priorities for information security should be Asset and Inventory Management, Decision and Remediation Workflows, and Visualization and Metrics. The lowest priorities are vulnerability assessment and scanning, penetration testing, and buying cool tools. 
  • Work the OWASP Top Ten vulnerabilities. 
  • Amateurs target systems. Professionals target people. 
  • Security will not be accepted until and unless IT is made personal: it is you in your home who will be violated by your release of company information at work.

Basic security
They call it “BSides” in honor of the old rock ‘n’ roll 45 rpm single releases of the 1950s and 60s. The producer picked a hit for Side A and put something else (usually mediocre) on Side B. Elvis Presley’s “Don’t Be Cruel” was an exception. The Beatles releases were all exceptions.
Presentations crossed organization lines
The concept began in the US in 2009 with Mike Dahn, Jack Daniel, and some others because the CFP [Capture the Flag: computer intrusion challenge – MEM] for Black Hat Vegas or DEF CON was oversubscribed and those unable to present decided to hold their own conference on the 'b side'. -- https://en.wikipedia.org/wiki/BSides

PREVIOUSLY ON NECESSARY FACTS


Saturday, January 23, 2016

Passwords

Are your passwords strong enough to resist a brute force attack? Passwords are just about dead. Many systems now offer “two factor identification.” You give them your cell phone number and you have to use both a password and a code number sent to  the phone for your log in.  But passwords continue. They are easy for administrators. They are part of the common culture.

Steve Gibson has the engineer’s “knack.” (See the Dilbert video here.His company, Gibson Research Corporation (here)sells a wide range of computer security products and services. He also offers many for free. Among the freebies is Haystack: How Big is Your Haystack – and how well is your needle hidden? (here)  This utility provides a metric for measuring password security.

It is pretty easy to do yourself, if you like arithmetic. 26 upper case letters, 26 lower case, 10 digits, 33 characters (with the space) for 95 printable ASCII characters in the common set.  So, if you have an 8-character password that is 95 to the 8th power possible combinations: 6.634 times 10 to the 15th power or over 6-and-a-half quadrillion. If you could try a million guesses a second, it would take 6.5 billion seconds or just over 200 years. (60 seconds/minute * 60 minutes/hour * 24 hours/day * 365.25 days / year* 200 years =6.3 billion .)

Gibson Research makes all of that automatic. Just key in your password, and it tells you how long it would take to crack.

Cracking passwords is a routine activity for a hacker. They have tools.  At one meet-up for hackers, the speaker told us, “If you have to use brute force, you are not thinking.”  They do not type in a million guesses per second, of course. They have programs to do that. Also, most websites just do not allow that kind of traffic: you cannot do a million guesses per second. What the hackers do is break in to a site, such as Target, Home Depot, LinkedIn, or eHarmony, download all of the log files, and then, on their own time, let their software attack the data offline.

Also, hackers do not use the same computers that you and I do. They start with gaming machines because the processors in those are built for high-speed calculation. They then gang those multiple processors to create massively parallel computers.  The calculators from GRC show the likely outcome for brute force by both a “regular” computer and a “massive cracking array.”

If someone got hired today at a typical midrange American corporation, their password might just be January2016. If, like most of us, they think that are really clever, it ends with an exclamation point: January2016!  Hackers have databases of these. They start with standard dictionaries, and add to them all of the known passwords that they discover.

One common recommendation is to take the first letters of a phrase known only to you and personal only to you. My mother had naturally red hair for most of her life. She was born in 1929 and passed in 2012. So, “My mother’s red hair came from a bottle” becomes mmrhcfab19292012. According to Gibson Research, brute force guessing with a massive cracking array would take over 26 centuries.

Gioachino Rossini premiered his opera, William Tell, in 1829. “William & Tell = 1829” would take a massive parallel cracking machine about 1 million trillion centuries to guess.  However, Five + One = 27 could be done in under 1.5 million centuries.

Remember, however, that a dictionary attack will crack any common phrase.  With over 1.7 million veterans of the United States Marine Corp, someone—probably several hundred someones—has “Semper Fi” for a password. Don’t let that be you. A brute force attack would need only 39 minutes, but that is not necessary: a cracker's dictionary should have "Semper Fi" in it already.

(Above, I said that cracking passwords is a “routine activity” for a hacker. “Routine activities” is the name of theory of crime.  Attributed to sociologists Marcus Felson and Lawrence E. Cohen, routine activities theory says that crime is what criminals do, independent of such “social causes” as poverty. See Routine Activity Theory on Wikipedia here: )

PREVIOUSLY ON NECESSARY FACTS