Showing posts with label hacking. Show all posts
Showing posts with label hacking. Show all posts

Saturday, May 6, 2023

BSides Austin 2023

After a Covid hiatus, the BSides Austin computer security conference returned as an in-person event. We enjoyed meeting people we had not seen in two-and-a-half years. The conference ran three parallel tracks and I blocked out some talks to attend but I spent the day near Laurel’s table supporting Kids First Uganda. It was time well invested, visiting vendors and watching attendees. I even met a recruiter who gave me a QR code to upload my resume. 

Three tracks with 24 sessions included cloud-focused phishing,
containing smishing incidents, attacking Microsoft Cloud,
mitigating malvertising, and "Don't Let Your Roomba
Sell Your Bank Login."


There was a BSides Austin virtual meeting on 2 December 2022 that I did not attend. In the past 30 months, I have been in several virtual conference chatrooms and they are a poor substitute. It is much easier and more comfortable to stand in an open hall just watching and waiting than it is to be in a chatroom by yourself. 



The conference featured a day of training on Thursday. (Laurel attended; I did not.) In fact, this year's theme was "Never Stop Learning." 


Organizer Janice Daquila-Pardo told me that they had 600 sign-ups and about 500 in attendance. The last full-scale event in 2019 tallied 700 attendees. We signed up late but got t-shirts nevertheless because of the no-shows. 



Locksporting (above) had two tables this time.
In addition to a wide range of key locks, there were combination
locks and even ziplocks to try your skills on (bottom right).
Next to them were the hardware hackers (bottom left). 
IT managers worry about clouds as services and they
seldom see the more obvious weaknesses.

History of BSides Austin

“The very first BSides in Austin was organized in 2010 by Jack Daniel and Ben Tomhave. This was the fourth BSides ever to be held, and it had about 30 attendees. In 2011, Michael Gough stepped up and took over organization of our local event. Even as he continued to manage the BSides Austin events through 2015, Michael also helped kick off BSides Texas in 2012, and was heavily involved in BSides throughout Texas (including Dallas, San Antonio and Houston). 

“Matt [Pardo; @ultraslogger] and Janice [Daquila Pardo; @bsidesaustin] have been running BSides Austin since 2016. BSides Austin has grown in that short time into a two-day event with around 750 participants. Our goal is to continue providing a fantastic event with great content and training for the information security community.” -- https://bsidesaustin.com/about/

Security Innovation sponsored this year's capture the flag contest. 
The website of this fictional bank had 30 vulnerabilities
and prizes went to those who found the most.
The overarching comment was: "It was harder this year
and the scores were lower."


Laurel and I have volunteered at BSides Austin and LASCON, the Lonestar Application Security Conference, both created and maintained largely by members of the local OWASP chapter. Laurel worked registration and I monitored the presentation rooms, taking head counts and thanking the speaker with a Starbucks gift card. We also presented. Laurel delivered on securing your home network with a Raspberry Pi and I spoke on physical security for data centers. 

For their conference swag, Blackhills Information Security
brought several games including interactive comics
and a complex card game (three decks). 

Our first computer security conference in Austin was BSides 2013 and then the benefit outreach was Hackers for Charity delivering to Uganda. Just about every white hat hacker gathering has some social engagements supporting local or international communities not usually served well by others. Laurel met Kids First Uganda through a cousin. She had quilts made from t-shirts from previous computer security conferences and those were offered for donated sale at BSides.

Tuesday, December 11, 2018

(ISC)^2 Holiday Dinner 2018

Indeed hosted this year's holiday party for the Austin chapter of (ISC)^2. About 50 people attended and enjoyed a surprising German menu with sausages, sauerkraut, potato pancakes, and chocolate tort.
The computer security community here in Austin centers on OWASP, the Open Web Application Security Project. They host two conferences a year, BSides and LASCON. For over five years they have held weekly lunchtime study cells in space provided by National Instruments. With OWASP, the key word is "open." I am a member of OWASP and I am a technical writer. I volunteer to work the conventions and have even presented. But I hold no certifications in computer security. These people do. The CISSP certification from (ISC)^2 is the gold standard of competence in information security.

The International Information Systems Security
Certification Consortium

https://www.isc2.org/Certifications
Austin boasts one of the largest computer security communities in the world. Fortune 500 companies and multinational corporations that are headquartered elsewhere put their IT departments in Austin.  The US Army Futures Command is here. But as large as it is, the infosec crowd is just another village and pretty soon everyone knows everyone. Parties like these are how we exchange cultural knowledge.


In addition to those large enterprises and governmental organizations, we have no shortage of start-ups. People here solve problems by advancing ideas, building technologies, and delivering solutions.

Austin has three epicenters of information technology: the north side, the hill country, and downtown. Downtown includes both the Congress Avenue corridor and the University of Texas.  The hill country runs west and north off the 360 and Farm to Market 2222 at the iconic Pennybacker Bridge. The north side, north of old Tech Ridge is where you find Dell, HP, GM, and many others. But tech is everywhere here. AMD is on Southwest Parkway. Freescale just moved from there to the Airport area where you can find competing server farms.


Indeed also hosted the launch of the Austin Security Alliance. Over a dozen groups sent representatives to create an ecosystem that will respond, adapt, grow, replicate. and evolve solutions to information security. It goes beyond mere firewalls, important as they are. The technology of trust is how we all sign a hundred contracts a day without even thinking about it. Every time you swipe a card, every time you log in, every time you visit a page, you authenticate by swapping secure tokens.


The most revealing facts were the ones not mentioned. For all of the vulnerability scans, red team - blue team, packet sniffing, threat assessments, responses and remediations, I never heard anyone actually say what they did. The tech talk was fairly abstract. There were no war stories. They did talk about other people's problems because huge data breaches are always in the news.

PREVIOUSLY ON NECESSARY FACTS
READABILITY IS THE ONLY METRIC
AUSTIN B-SIDES 2016
LASCON 2014
CHARLES BABBAGE: CODE BREAKER


Saturday, December 16, 2017

Austin Security Alliance

On Monday, December 11, 2017, members of 14 computer security organizations met at Indeed headquarters to launch the Austin Security Alliance. ISSA's president, Larry Moore, was the tip of the spear: this was his idea. But very many people were involved because they saw the wisdom in the project. With 20,000 to 30,000 professionals employed in computer security, Austin intends to be declared the Computer Security Capital of America.
DON'T PANIC was the cover band: classic 50s to urban.
As Larry and a dozen other organization officers and leaders explained in the opening presentation, the purpose of the ASA is to enable and facilitate cooperation across specialties. ASA maintains no membership of its own  and collects no dues. My perception is that it works. I should have intuited but did not know that we have a local ASIS chapter. It was nice to meet them. I was a national member for two years. Now, I have a reason to renew.

ASA MEMBER ORGANIZATIONS
  • ASIS International
  • Association of Continuity Professionals – Capital of Texas Chapter
  • Austin Hackers Anonymous (AHA!)
  • Cloud Security Alliance – Austin Chapter
  • Electronic Frontier Foundation – Austin
  • Hackformers
  • Infragard
  • Information Systems Audit & Control Association (ISACA)
  • International Information Systems Security Certification Consortium (ISC)² – Austin Chapter
  • Information Systems & Security Association (ISSA) – Capitol of Texas Chapter
  • Longhorn Lockpicking Club
  • Open Web Application Security Project (OWASP)
  • Secure Austin
  • Texas CISO Council
PREVIOUSLY ON NECESSARY FACTS
TDEM 2017
BSIDES Austin 2016
InnoTech 2015
LASCON 2014
BSides Austin 2013
Securing Your Viper Against Cylons

Saturday, May 20, 2017

TDEM 2017 Texas Emergency Management Conference

Laurel and I attended the 2017 Texas Department of Public Safety Division of Emergency Management annual conference in San Antonio. Although it is a four-day show, we were there just for Thursday, May 18. We started with the exhibit hall and attended two break-out sessions. These are some of the vendors whom I met.

Dr. Deb Zoran is the operations supervisor of
VET outreach of Texas A&M University.
They coordinate animal rescue during disasters and emergencies.
John Taylor and Hannah Coffey of BOLD Planning,
one of the providers of mitigation and remediation plans for
organizations that do not have adequate in-house emergency planning.
Sean Scott developed the Red Guide handbooks.
They are available in English and Spanish.
Keith Blaylock of eXpress Sandbag System
did not bring the proprietary machinery with him.
However, I found the sandbags to be portable,
standardized, and stackable.
And he said that he could produce
1000 per hour all day long.
Michael Shanks of LRad explained
that his sound output speakers will cover
huge, city-sized areas with good clarity
for voice notification in times of emergency.
Mike Ross does apps and he has them for
emergency management. In the age of the
smartphone it is an easy and effective way
for jurisdictions to get the word out --
the right information...
from the right source.
Vanessa Forté of ProPac brought a wide range of
pre-packaged emergency supplies from
first aid kits to food and drink for
one person or large groups.
Mark Mathiesen of On the Mark Weather is one of several
commercial meteorologists with his own brand of applied theories.
When I reviewed and edited contracts for TDEM in 2014,
I was surprised to learn that the government agency, NOAA,
as respected as it is, is not the leading edge, and only tells you
what they tell everyone in a wide area all at the same time.
Dr. Mathiesen specializes in micro-events:
he can tell you if your school could be hit. 
Of course, there were many more to be met.  My friends from Intermedix and WebEOC were there. So were the folks from STEAR, the State of Texas Emergency Assistance Registry for people who want to be helped when getting help is a matter of life and death. I met Major Ernest Branscum of the Salvation Army several times during the day as we toured the exhibit hall. I was happy to be able to add my name to the contact list for the local chapter of the Association of Continuity Managers.   

On Thursday, May 18, at 4:00 PM, Laurel and I attended an excellent session on Insurance Fraud. The presenters were Lt. David Taylor (Compliance) and John Plent (Consumer Protection) from the Catastrophe Response Team of the Insurance Fraud unit of the Texas Department of Insurance. Just to note: The Department of Insurance is one of about 20 state agencies and departments that has its own sworn and weaponized peace officers. As explained below, when on the streets, talking to roofing contractors, he has the full law enforcement authority of any police officer in Texas.

In the aftermath of a disaster, swarms of unlicensed contractors appear, soliciting business, and being paid with money from insurance settlements. The work is uneven in quality. Sometimes, the “contractors” take a “down payment” and never return. Occasionally, they take a partial payment, do partial work, then leave, with a promise to return, which puts the matter out of the criminal law and into civil law.

The TDI catastrophe teams help people work with insurance adjusters; and they can assist insurance companies in the field. They work with consumers to help with insurance claims. Lt. Taylor and Mr. Plent come to your town to mitigate (and ideally prevent) violations and victimizations. They start by meeting with city officials. They acknowledge that after a severe storm which has taken lives, mitigating insurance fraud might not seem highly important. However, they have found law enforcement and other city officials to be very helpful. If the city has regulations, they say, then make sure that all solicitors are registered and licensed. Drive the streets; and where you see roofers working or knocking on doors, ask to see their papers. Municipalities should run background checks for outstanding warrants and sex offender registration. Their primary advice is to homeowners is to never accept a solicitation. You, the customer, should drive the process by seeking out reputable companies and getting competitive bids.

We have no state-level licensing of contractors here in Texas. However, we do have the Roofing Contractors Association of Texas and the Building Officials Association of Texas (BOAT at www.boatx.org). In fact, BOAT was one of the vendors at the TDEM conference. 


Read about the fraud team here
Watch one of their videos here.

At 2:30 PM on May 18, Laurel and I attended a disjointed, lackluster session on cyber security.  Despite our abiding professional involvement in computer security, this one put us both to sleep. The presenter was David Morgan (CISSP, CNSS NSA Security), who is a cybersecurity officer and information security manager at the Texas Department of Public Safety. He certainly seemed well qualified from his time in the Marine Corps to his experience as a visiting professor at several colleges and universities. The bottom line is that the content of his presentation did not meet the criteria set by the title of his talk, "Cyber Security - A Critical Component for Emergency Management." 

Everything we do in response to a disaster or a community event depends on computers, from smartphones to laptops. To coordinate our efforts, we bring WebEOC into community shelters. Some at this conference had special responsibilities for the emergency bands such as TICP (Texas Interoperability Communication Package) and MARS (Military Affiliate Radio System). David Morgan did not tell us how to secure any of them, or how to detect an intrusion.

Laurel and I were most interested in knowing about how computer hackers have disrupted emergency response. Aside from mentioning the recent incident in Dallas -- (Dallas Morning News here among very many others) -- in which the weather sirens sounded at midnight, he had nothing to say. 

Hackers have been changing traffic lights since at least 2003, though the ability to do so was known in the 1980s. (See Wired from 2005 here.) Recently, the Surprise, Arizona, city 911 was taken out by a hacker (See Washington Times story here.)  Bear in mind, though, that the infamous “Operation Sundevil” from 1990, which alleged that hackers had broken into the nationwide 911, was exposed and disgraced.  (See  “Operation Sundevil” in Wikipedia here and “Jefferson in Mirrorshades” in a hacker archive here. )  None of that was in this  presentation. 

David Morgan did allude to the existence of viruses, worms, trojans, and spyware, but did not differentiate among them, or tell us how to detect, mitigate, remediate, or prevent them. He did say that the Macintosh operating system is easily given to viruses because it is based on Unix, which is the operating system in which viruses were invented. David Morgan defined “Zero day” as the source of unknown vulnerabilities. He explained a “root kit” by saying that if you are “root” then you own the system.

All of that being as it may, I personally benefited by learning about Shodan.io. Coming to work the next day, I visited the site, read about it on Wikipedia, and made a note to myself to follow up. 
  
PREVIOUSLY ON NECESSARY FACTS
BSides Austin 2016
InnoTech 2015
CERT: Community Emergency Response Team
The Living Fish Swims Under Water

Friday, September 9, 2016

Hackers Heart Small Talk

Social engineering is the gathering of computer system information by other means.

T-Shirt from Defcon 24
It is common for Internet companies to rely on standard software. Even when provided by competing firms, the forms and formats of presentation are necessarily similar.  

What was your childhood pet's name?
What street did you grow up on?
What was the make of your first car?
What is your mother's maiden name?

The last line on the t-shirt is hard to read because it is on the midriff:  Is your voice your passport?  is a reference to Sneakers, the hacker film with Robert Redford, River Phoenix, Dan Aykroyd, James Earl Jones, Sidney Poitier, Mary McDonnell, and Ben Kingsley.     

Other popular keys to your files include
Who was your favorite teacher?
In what city did your parents meet?
What city did you grow up in?
What high school did you attend?
What was your favorite subject in school?

It is not so much that you cannot trust your co-workers (though there is that), but that you cannot know who else is listening when you are out in public socializing with your colleagues.

ALSO ON NECESSARY FACTS
Hacking
Passwords
BSides 2016
Securing Your Viper from Cylons
When Old Technologies Were New

Saturday, April 2, 2016

BSides Austin 2016

The seventh annual BSides Austin computer security conference ran March 31-April 1, 2016. I served as a Host for breakout sessions, introducing speakers, and keeping track of time. It was an overflow crowd of 350 with 150 turned away at the door, or denied a slot on the wait list. In addition, several student groups could not be accommodated at all. 
 
Breakfast with the Sponsors.
We had two tracks on Thursday and three on Friday. You can find the full schedule on the conference website here.  Many of the sessions were easy to label. “I am a Software Developer. What do you mean I’m on the Blue Team?” by Aaron Poffenberger was clearly for the Blue Team. “It’s not About the Technology. It is About the Psychology” by Dr. Hend Ezzeddine and Flora Moon was easy to label for Social Engineering.
 
32 Formal Technical Sessions
The first night also included open mike
"Fire Marshall Talks"
But many others crossed several lines on the corporate org chart, and the sessions were not narrowly defined. You had to pick your presentations. That said, all of the hands-on workshops were held in the same room on the same day.
 
Rapper "Dual Core"
Each track had a Host and a room Monitor.  The monitors counted the room three times (beginning, middle, end) and interfaced with the hotel staff when needed.
 
Waiting for the Keynote by Ed Skoudis from SANS.
The convention would have cost ten times as much to attend were it not for the sponsors. 
Digital Defense, Rapid 7, SANS, and Splunk were gold sponsors this year. 
The silver sponsors were RSA, Log-MD, ISSA, Pluralsight, Checkmarx,
Anomali, and Netskope.
The five core sponsors were Velocitystorm, Expressworks,
Fusion-X (thanks for the beer!),
No Starch Press, and Pentester Academy.
As a technical writer, my interests are more general. I am seldom held accountable for information security, except as we all are. These were among my take-aways:
  • The best lockpicking tools for the money are the Sparrow Tuxedo ($40) and the Tremendous Twelve by Toools from Southern Specialties ($30). 
  • The best locks are biaxials from Medeco and the Schlage Primus. You can spend $75 for one of these and secure your servers, or you can buy a dozen others at $5.95 each and let us all have access to your servers.
  • For a knowledge worker your credibility is your product. 
  • The highest priorities for information security should be Asset and Inventory Management, Decision and Remediation Workflows, and Visualization and Metrics. The lowest priorities are vulnerability assessment and scanning, penetration testing, and buying cool tools. 
  • Work the OWASP Top Ten vulnerabilities. 
  • Amateurs target systems. Professionals target people. 
  • Security will not be accepted until and unless IT is made personal: it is you in your home who will be violated by your release of company information at work.

Basic security
They call it “BSides” in honor of the old rock ‘n’ roll 45 rpm single releases of the 1950s and 60s. The producer picked a hit for Side A and put something else (usually mediocre) on Side B. Elvis Presley’s “Don’t Be Cruel” was an exception. The Beatles releases were all exceptions.
Presentations crossed organization lines
The concept began in the US in 2009 with Mike Dahn, Jack Daniel, and some others because the CFP [Capture the Flag: computer intrusion challenge – MEM] for Black Hat Vegas or DEF CON was oversubscribed and those unable to present decided to hold their own conference on the 'b side'. -- https://en.wikipedia.org/wiki/BSides

PREVIOUSLY ON NECESSARY FACTS


Sunday, October 11, 2015

InnoTech 2015

On Thursday, October 8, I spent the morning at the 13th annual InnoTech computer security conference. Seventy-nine vendors filled the floor. I only had time to meet a fraction of them. My tour was facilitated by a "passport" sheet that listed ten sponsors. Track them down, get them to sign their square, and drop the completed form in a box for a drawing.  It was "must be present to win" but I did not stay for that. I met some friends, colleagues from OWASP, and recruiters who sponsor our happy hours.

"Technology Navigators is a technical staffing firm,
specialized in recruiting skilled individuals
for project-oriented consulting and contract positions.
We’ve been firmly rooted in the Austin technology community since 1999,
and have been providing companies that
develop, build, and use technology
with the people they need to grow their business for over 15 years."
"Knight Security Systems has built its reputation over three decades
as one of the country’s leading providers of security system solutions.
With over 4,000 systems since 1983, Knight Security Systems has assisted
our customers in reducing internal and external, loss, legal liability,
employee liability, increasing productivity, safety compliance,
customer satisfaction and bottom line profits."
"Headspring is much more than a provider of
enterprise software strategy and development ...
We are motivated by our daily opportunity
to create a real impact in the world,
and to enable our employees, our clients
and our community
to achieve beyond their perceived potential."
"Bridgepoint Consulting provides
management consulting services
that help organizations optimize financial operations
and information technology
while mitigating organizational risks.
Whether a company needs assistance with strategy,
process improvement,
technology or regulatory compliance—
or simply has resource gaps,
our team of professionals deliver measurable results."
"By partnering with our customers,
Future Com [www.myfuturecom.com]
can give them a competitive advantage
in terms of everything from implementation times
and resources required during deployments
to lowering the total cost of ownership
of technology and solutions as a whole."
PC Magazine Best Antivirus Software 2015.
Available for Macintosh.
Enterprise solutions also available.
"Bitdefender protects its users’ privacy,
as well as the as their devices.
Our award-winning security technologies protect against
all cyber-threats today,
from annoying adware
to dangerous malware
that infiltrates to steal data, intercept online payments,
spy, or hold your information for ransom."
"M-Files is document management the way it should be:
simple to install and learn, reliable, powerful and secure –
without breaking your budget.
Improve workflow, increase information reuse, eliminate redundancy,
securely control content, and avoid conflicts and data loss –
all in a single document management solution
that integrates with Windows Explorer."


"Everything transacts on the wire: 
from raw packets to the payloads of all application transactions. 
Wire data is a deep and rich source that contains 
every conversation occurring on the network. 
Wire data provides an objective, "outside-looking-in" view 
across the entire application delivery chain. 
It serves as the most unbiased source of truth about 
the performance, effectiveness, and security 
of enterprise IT environments." -- Extrahop Networks
"For thirty years,
New Horizons Computer Learning Centers
has provided practical and innovative
corporate training solutions
to help organizations overcome operational challenges
and take advantage of emerging opportunities."
"Advanced communications and cloud solutions
from Time Warner Cable Business Class
can enable your Enterprise to be more successful
in today’s market. ... 
Time Warner Cable Business Class
delivers reliable and scalable voice and data solutions
over our advanced, fiber-rich IP network."
"...Veeam has pioneered a new market of Availability for the Modern Data Center
by helping organizations meet
recovery time and point objectives (RTPO™)
of less than 15 minutes for all applications and data,
through a fundamentally new kind of solution
that delivers high-speed recovery, data loss avoidance,
verified protection, leveraged data and complete visibility."
"Keep your home connected
with powerful High-Speed Internet, Digital TV, Phone Service.
Services designed for business ranging from
home/small offices up to 50 employees,
including Internet Solutions, Phone Services,
and 24/7 Technical Support.
Enterprise-class data, voice, network and cloud solutions
designed to meet the unique needs of your business."
PREVIOUSLY ON NECESSARY FACTS
Available on Slideshare

Thursday, March 19, 2015

BSides Austin 2015

In the old days of rock 'n' roll 45 rpm records, the "A" side was the hit release and the "B" side was just something else by the group.  The Beatles broke the decade-long precedent by topping the charts with both A-side and B-side songs.  At DefCon 17 (July 2009), the speaker proposals were over-subscribed, so some of them held their own "on the b-side."  B-Sides Austin goes back six years to 2009.  (BSides Wiki here.)  This year continued the trend for informative speakers, entertaining extras, great vendor support, and engaged participation within the computer security community of Austin.
Volunteer Staging in Preparation for the Opening 

About 300 Austin Computer Security Professionals Attended
Issuing ID, lanyards, t-shirts, and tote bags,
orienting the attendees,
and basically bringing normalized database order
to a Markov Chain. 
Our social media coordinator
tweeted his thumbs off
It all hinges on the sponsors.
Without them,
the conference would cost four times as much.
Coffee from the Denim Group
.
The Opening Session
IBM was gracious and supportive. I got a "Think" ballcap.
Rapid 7, ISSA, Kaspersky Lab, Praetorian, IOActive, 

Digital Defense, Synack, OpenDNS,
LastPass, Splunk, 

and the Independence Brewing Company
also underwrote the conference.

(Full list at BsidesAustin.com)
Two job boards
begged for analysts, engineers, and architects.
(The Premera breach was not yet admitted.)
Lock picking is part of hacker culture
as explained …
…in Hackers: Heroes of the Computer Revolution
by Steven Levy (1984).
 
Worth one thousand words.
Friday Keynote Speaker
Reuben Paul (link among others) interviewed.
Conference coordinator
Richard Stephens meets the media.
Austin Fire Marshall Larry Jantzen
spoke at lunch on the 2nd day,
explaining the multifaceted work of his department.
BSides Austin has a love-hate relationship with the Fire Marshall
because he closed our evening session the first year
for violating the attendance limits.
Security is security, physical or cyber.
Breakout session speaker Aamir Lakhami
worked as an advisor on
Big Bang Theory and The Avengers.
I volunteered to serve as master of ceremonies for Track 2. I introduced speakers. Basically, I looked them up on LinkedIn; and then I met them at the conference to get the kind of interesting and positive  things that most people would not know. I timed the talks, kept them on schedule, and counted the audience before and after.

I met Earl Carter from Cisco Systems. Josh Pyorre from OpenDNS, Kate Brew of the Alien Vault and her colleague Charisse Castagnoli (adjunct professor of law at the John Marshall Law School, among other affiliations), Aamir Lakhmi from Fortinet, Praetorian's Julian Dunning, and IoActive's Damon Small. (Damon was at the Happy Hour the night before.)  My sessions closed with Roxy D of Firehost and Mike Sconzo of Bit 9 + Carbon Black.

Also on NecessaryFacts
BSides Austin 2013 
Your Cell Phone is not Safe
Securing Your Viper Against Cylons
Locksporting