Point of Origin Hacking Workshops

Total Page:16

File Type:pdf, Size:1020Kb

Point of Origin Hacking Workshops POINT OF ORIGIN HACKING WORKSHOPS MeshcO, Inc. Presents Extreme Training • Imported For Your Education October 9th-11th, 2012 • Dayton Ohio • 937-938-9066 • Powered by Sk1llz WHAT YOU DON’T KNOW CAN HURT YOU “Ignorance and sloth are the enemies of effective security. So which is it? Are you stupid, lazy or both?” Angus Blitter 2012 POINT OF ORIGIN HACKING (POOH) What is POOH? It’s not the honey grubbing bear from your youth or stuff you might need to clean off of your shoe. It’s a core tenet of our field-proven methodology. The tenet dictates that organizations should consider theoretical vulnerabilities as part of their risk and trust management practices. We seek a pragmatic approach to isolating the most relevant threat vectors and proactively insulating the organization from negative impact, should that threat vector become exploitable. This approach is very effective when introducing new technologies, procedures or implementing policy changes. We use the term “Exposure Index” (EI) to express the relative confidence in the security effectiveness of a protocol, system or control. Your EI is directly related to the motivation of an attacker to develop a capability in order to exploit a vulnerability. Is anyone motivated to attack you? How would they do it? How should you respond? We bring the best practitioners from around the world together for interactive workshops focused on real and theoretical risks associated with the most relevant technologies. Arm yourself with the tools to predict and prevail in the modern world! MeshcO, Inc. Presents Extreme Training • Imported For Your Education October 9th-11th, 2012 • Dayton Ohio • 937-938-9066 • Powered by Sk1llz EXTREME TRAINING POOH Workshops PAY BY THE DAY FREE Day-Con VI Pass Register NOW All presenters are real Pricing uses a sliding scale If you sign-up for a workshop If you want to attend POOH practitioners with much of based on the number of days you get a complimentary training, simply send an email to the content being presented you want to attend. Day-Con VI pass. [email protected] with by the original researchers 1st Day $900 $250 Value the subject line of POOH 2012. and innovators. 2nd Day $600 3rd Day $500 WE HAVE TRAVELED THE WORLD seeking out the best and brightest security researchers and innovators so you don’t have to. Much of the course content is commissioned or otherwise unique. Our pricing represents a significant savings compared to what you normally pay to take this training in its country of origin (not to mention the exchange rates, hotel pricing and language barriers). All presenters are real practitioners with much of the content being delivered by the original researchers. World renowned experts teach you in an intimate setting to provide an extreme training experience you will never forget! MeshcO, Inc. Presents Extreme Training • Imported For Your Education October 9th-11th, 2012 • Dayton Ohio • 937-938-9066 • Powered by Sk1llz IPV6 SECURITY AGENDA Current state of IPv6 security in LANs • Attack trends and tools • Best practices for network stability and security • RA guard and similar technologies Choosing the right addressing approach • Some notes on the ULA discussion • Link local addresses from a security perspective Privacy extensions • Advantages & disadvantages from a security & privacy perspective • Default behavior of desktop and smartphone technology • Practical implications (e.g. reverse DNS) WHAT KIND OF IPV6 TOOLS DO YOU HAVE IN YOUR KIT? Filtering IPv6 traffic • Best practices and sample configurations This workshop covers advanced security aspects of IPv6 in • Overview of IPv6 support in common security devices enterprise environments. We will focus on architecture and planning aspects and discuss the latest developments in • NAT in the IPv6 world - the endless debate the technology and standards space. Our goal is to enable the participants to make well-informed decisions when it comes to deploying IPv6 in both, a secure and operationally feasible manner. It is assumed that participants already possess some fundamental knowledge concerning IPv6’s inner workings and our actions for considering its use in their environment. ENNO REY Enno Rey is a seasoned information security professional working as the consulting right hand for a number of CISOs. He has vast experience in designing, operating and securing large environments and has passed the typical transformation from a technology-centric to a process-oriented infosec guy. He was initially certified as a BS 7799 LA in 2001 and has been devoted to a risk based approach of steering information security as a supporting process for more than ten years. His current research focus is on trust models, policies and their interaction with real-world infosec and risk analysis tools useful in practice. He's a regular speaker at events all over the world (including Black Hat several times and many other events) and has published a number of books, articles and white papers. “The Insinuator” will lead this workshop. Don’t miss this unique opportunity. MeshcO, Inc. Presents Extreme Training • Imported For Your Education October 9th-11th, 2012 • Dayton Ohio • 937-938-9066 • Powered by Sk1llz MOBILE SECURITY AGENDA Mobile devices Security controls for a • Differences between secure integration the new and old players • Control categories • What makes them the • Structured approach to front-end of the future select controls • User restrictions & Smartphone operating access policy system overview • Mobile device management • Policies & guidelines • iPhone OS: architecture, • Available technical controls security features & attributes If you can’t manage it you can’t secure it • Google Android Mobile device management • Other devices This workshop will include an introduction to mobile • Requirements device security, a discussion on its risks for your • iOS management Corporate challenges organization and will provide you with possible • Configuration profiles solutions. • Do’s & Don’ts of mobile devices • iTunes in business After discussing threats, vulnerabilities and risks of • Achieving security goals • Apple configuration utility mobile device integration, the iOS and Android • Network integration • Over the air provisioning device specific features and vulnerabilities will be • Mobile device management • Android management presented along with several attack scenarios, • Bring your own device • Microsoft Exchange active sync forensic methodologies and real life case studies. • Private use of corporate devices • Third party management solutions We will demonstrate mobile device management • War stories from the wild solutions, along with other possible integration App approvement strategies, such as container solutions and hosted management solutions. We will also discuss Mobile device information • Technical assessment technical controls and how to cover mobile devices security management • Assessment metric within your organization’s IT security policy. During • Standards & approaches the workshop we will discuss different deployment Operations: scenarios as well as BYOD (Bring you own device). • Threats & vulnerabilities • Important processes for This will be a practical workshop where you can (with practical demos) secure operation test various skills in small, hands-on sessions. We • Rapid risk assessment • Implementation hints will provide you with some devices or BYOD. • Required security controls • Mobile device security concept RENE GRAF Rene Graf leads the Mobile Security team at ERNW and has performed a number of BYOD projects including pentests of container solutions and forensic analyses of devices used by CxOs. Real world training from practitioners that know what works! MeshcO, Inc. Presents Extreme Training • Imported For Your Education October 9th-11th, 2012 • Dayton Ohio • 937-938-9066 • Powered by Sk1llz CLOUD & VIRTUALIZATION SECURITY AGENDA • Well-known attacks and risks with an emphasis on VMware ESX • Attacks from the guest against the hypervisor • Typical operational problems • The problem of “Rogue Machines” • Zone concepts in virtualized environments • Role concepts (Roles and Responsibilities) • Three layer computing: storage, network & adequate isolation procedures • Risk evaluation as a basis for efficient security work • Possible security problems & their relevancy in virtualization scenarios VIRTUAL CLOUDS • Approaches for the evaluation of consolidation of The use of virtualization technologies has a considerable various security zones impact on the security architecture in countless organizations. Existing concepts, which are based on network zones and • Amount of security is necessary for which data is classified physical separation of resources cannot be mapped in their • Best security practices in virtualization scenarios entirety and often, are in contrast to the IT targets (key word: consolidation). The introduction of virtualization will lead to • Secure design hardening changing risks, either through a higher complexity (and • Secure operations unclear responsibilities/changing operating procedures) or through new attacks like "Cloudburst"against the hypervisor. • Secure management In many environments, the next degree of abstraction is on the horizon: Cloud Computing • Basic cloud concepts • Threats & vulnerabilities in cloud environments The goal is to achieve an adequate risk level in an increasingly abstract IT world. In order to achieve this you need to develop • Most relevant cloud risks a deep understanding of the involved technologies, • Compliance,
Recommended publications
  • Fill Your Boots: Enhanced Embedded Bootloader Exploits Via Fault Injection and Binary Analysis
    IACR Transactions on Cryptographic Hardware and Embedded Systems ISSN 2569-2925, Vol. 2021, No. 1, pp. 56–81. DOI:10.46586/tches.v2021.i1.56-81 Fill your Boots: Enhanced Embedded Bootloader Exploits via Fault Injection and Binary Analysis Jan Van den Herrewegen1, David Oswald1, Flavio D. Garcia1 and Qais Temeiza2 1 School of Computer Science, University of Birmingham, UK, {jxv572,d.f.oswald,f.garcia}@cs.bham.ac.uk 2 Independent Researcher, [email protected] Abstract. The bootloader of an embedded microcontroller is responsible for guarding the device’s internal (flash) memory, enforcing read/write protection mechanisms. Fault injection techniques such as voltage or clock glitching have been proven successful in bypassing such protection for specific microcontrollers, but this often requires expensive equipment and/or exhaustive search of the fault parameters. When multiple glitches are required (e.g., when countermeasures are in place) this search becomes of exponential complexity and thus infeasible. Another challenge which makes embedded bootloaders notoriously hard to analyse is their lack of debugging capabilities. This paper proposes a grey-box approach that leverages binary analysis and advanced software exploitation techniques combined with voltage glitching to develop a powerful attack methodology against embedded bootloaders. We showcase our techniques with three real-world microcontrollers as case studies: 1) we combine static and on-chip dynamic analysis to enable a Return-Oriented Programming exploit on the bootloader of the NXP LPC microcontrollers; 2) we leverage on-chip dynamic analysis on the bootloader of the popular STM8 microcontrollers to constrain the glitch parameter search, achieving the first fully-documented multi-glitch attack on a real-world target; 3) we apply symbolic execution to precisely aim voltage glitches at target instructions based on the execution path in the bootloader of the Renesas 78K0 automotive microcontroller.
    [Show full text]
  • Anti-Forensic Implications of Software Bugs in Digital Forensic Tools
    Anti-Forensic Implications of Software Bugs in Digital Forensic Tools ALAIN HOMEWOOD Bachelor of Computer and Information Sciences (AUT, NZ) Diploma in Information Technology (AUT, NZ) A thesis submitted to the graduate faculty of design and creative technologies AUT University in partial fulfilment of the requirements for the degree of Master of Forensic Information Technology School of Computing and Mathematical Sciences Auckland, New Zealand 2012 ii Declaration I hereby declare that this submission is my own work and that, to the best of my knowledge and belief, it contains no material previously published or written by another person nor material which to a substantial extent has been accepted for the qualification of any other degree or diploma of a University or other institution of higher learning, except where due acknowledgement is made in the acknowledgements. ........................... Signature iii Acknowledgements I would like to thank everyone that has supported me in writing this thesis. Without their support this thesis may not have been completed. I have received guidance, support and insight from many people during the course of conducting this research. Firstly I would like to express my gratitude to my thesis supervisor, Dr Brian Cusack. Dr Cusack has provided continual support and guidance which has greatly influenced the direction of this research as well as the quality of the thesis. Dr Cusack is the latest of many faculty members of the School of Computing and Mathematical Sciences who have helped me reach my goals throughout my tertiary education. I also thank Campbell McKenzie for his continued support throughout writing my thesis.
    [Show full text]
  • Crystal Eye Technology Report (Updated) – 2020
    Technology Report Red Piranha’s Crystal Eye Platform Peter Hannay & Clinton Carpene [email protected], [email protected] 16th October 2017 Updated Review Red Piranha’s Crystal Eye XDR Platform v4.0 Kenneth Tan – [email protected] Meidi van der Lee – [email protected] Rossa Risdiana – [email protected] 4th September 2020 The statements made and opinions expressed in this report are believed to be correct by the authors, however the authors assume no responsibility or liability for any errors or omissions in the content of this report. The information contained in this report is provided on an as-is basis with no guarantees of completeness, accuracy, usefulness or timeliness. Any discussion of projections or future performance are subject to interpretation and it must be noted that past performance is not a reliable indicator of future results, as such no responsibility can be accepted for decisions made based on this report. 1 Executive Summary Red Piranha Limited is a public unlisted company registered in Australia and currently based out of Perth and Sydney, developing information security products called the Crystal Eye Extended Detection and Response (CE XDR) platform with the immediate target market being small and medium businesses in Australia and exporting to global markets. The Crystal Eye platform integrates a collection of security technologies to provide multiple layers of cybersecurity protection, giving the benefit of defence-in-depth with comprehensive features even without optional functions installed. Clients can add more functionalities from the Marketplace as required according to each business’ inherent risks and requirements. Additional functionality can be included mostly at no additional cost.
    [Show full text]
  • Crystal Eye Technology Report
    Independent Technology Report Red Piranha’s Crystal Eye Next Generation Firewall Operating System Peter Hannay & Clinton Carpene [email protected], [email protected] 6th August 2017 The statements made and opinions expressed in this report are believed to be correct by the authors, however the authors assume no responsibility or liability for any errors or omissions in the content of this report. The information contained in this report is provided on an "as is" basis with no guarantees of completeness, accuracy, usefulness or timeliness. Any discussion of projections or future performance are subject to interpretation and it must be noted that past performance is not a reliable indicator of future results, as such no responsibility can be accepted for decisions made based on this report. 1 Executive Summary Red Piranha Limited is a public, unlisted company registered in Australia. Red Piranha Limited (“Red Piranha”, the “Company”) is currently based out of Perth and Sydney, developing information security technologies and products. Red Piranha is a fully integrated supplier of cyber security services for small to medium enterprises in Australia with export capabilities for global markets. Red Piranha’s advanced intrusion and detection systems, backed by the Company’s threat intelligence, updates systems multiple times a day giving greater protection against zero day attacks and advanced persistent threats. The Company is currently working with its business associates and partners to produce a bundled insurance product. The product provides a complete cyber security service through acombinationoftechnologyandinsurancepackagestoprovideremediationshouldsomedamageor loss eventuate. In 2015, Red Piranha purchased the DNS.Insure platform and began development on the Crystal Eye Unified Threat Management systems (UTMs; the "Technology").
    [Show full text]
  • 1UP A5 40PP BROCHURE Cut Marks
    2017 Contents 3 Introduction 5 Keynote 8 Talks (alphabetically by talk / workshop title) 29 Workshops (alphabetically by talk / workshop title) 39 Thanks 2 Introduction It's that time of the year already. A time for giving and sharing challenges and responses. A time for catching up with old friends around the glow of a warm tty. A time for (get to the point Steve! -A)... erm... ok. It's a time to get a little crazy and break stuff... It's 44CON TIEM!!!!1!11!1!!!one!!ones!!11 Welcome back to another year of 44CON. This year we've gone all out on talks and have some amazing ones from speakers around the world. We have the drinks primed for Gin O'Clock, the bus bar is ready and we have a cracking evening session ahead. Our CTF this year is run by Immersive Labs, who are offering good money for challenges. Go and talk to them if you'd like to make some extra cash developing challenges for their platform, but don't forget to have a go at the CTF too! If this is your first 44CON, you should know we might not be like other events you've attended. Everyone is approachable from our sponsors to speakers to the crew. If you have any questions, problems or suggestions, please do talk to our crew or ask at the front desk. We want to make sure you have the best time possible. 44CON couldn't happen without our sponsors, please make sure you say hello. Our sponsors aren't there to give you a hard sell, they're there to help you have a good time so do make sure to visit them and see what they have to offer.
    [Show full text]
  • APCERT Annual Report 2012
    AAPPCCEERRTT AAnnnnuuaall RReeppoorrtt 22001122 APCERT Secretariat E-mail: [email protected] URL: http://www.apcert.org 1 CONTENTS CONTENTS ........................................................................................................................... 2 Chair’s Message 2012 ............................................................................................................ 4 I. About APCERT ................................................................................................................... 6 II. APCERT Activity Report 2012 ...................................................................................... 12 1. International Activities and Engagements 12 2. Approval of New General Members / Full Members 16 3. APCERT SC Meetings 16 4. APCERT Study Calls 16 5. APCERT Information Classification Policy 17 III. Activity Reports from APCERT Members ................................................................... 18 Full Members 18 1. AusCERT Activity Report 18 2. BKIS Activity Report 20 3. BruCERT Activity Report 24 4. CERT Australia Activity Report 30 5. CERT-In Activity Report 35 6. CNCERT/CC Activity Report 47 7. HKCERT Activity Report 55 8. ID-CERT Activity Report 61 9. ID-SIRTII/CC Activity Report 71 10. JPCERT/CC Activity Report 78 11. KrCERT/CC Activity Report 86 12. MyCERT Activity Report 91 13. SingCERT Activity Report 99 14. Sri Lanka CERT|CC Activity Report 102 15. TechCERT Activity Report 113 16. ThaiCERT Activity Report 122 2 17. TWCERT/CC Activity Report 131 18. VNCERT Activity Report 142 General Members 146 19. bdCERT Activity Report 146 20. EC-CERT Activity Report 150 21. mmCERT Activity Report 154 22. MOCERT Activity Report 160 23. MonCIRT Activity Report 168 24. NCSC Activity Report 179 3 Chair’s Message 2012 The history of CERTs began in 1989 as a result of the Morris worm. As Internet expanded globally, CERTs began to form within the Asia Pacific region and quickly it became clear that collaboration to address challenges that went beyond individual national borders would become essential.
    [Show full text]
  • Download Next Generation Web Scanning
    Next generation web scanning New Zealand: A case study First presented at KIWICON III 2009 By Andrew Horton aka urbanadventurer NZ Web Recon Goal: To scan all of New Zealand's web-space to see what's there. Requirements: – Targets – Scanning – Analysis Sounds easy, right? urbanadventurer (Andrew Horton) www.morningstarsecurity.com Targets urbanadventurer (Andrew Horton) www.morningstarsecurity.com Targets What does 'NZ web-space' mean? It could mean: •Geographically within NZ regardless of the TLD •The .nz TLD hosted anywhere •All of the above For this scan it means, IPs geographically within NZ urbanadventurer (Andrew Horton) www.morningstarsecurity.com Finding Targets We need creative methods to find targets urbanadventurer (Andrew Horton) www.morningstarsecurity.com DNS Zone Transfer urbanadventurer (Andrew Horton) www.morningstarsecurity.com Find IP addresses on IRC and by resolving lots of NZ websites 58.*.*.* 60.*.*.* 65.*.*.* 91.*.*.* 110.*.*.* 111.*.*.* 113.*.*.* 114.*.*.* 115.*.*.* 116.*.*.* 117.*.*.* 118.*.*.* 119.*.*.* 120.*.*.* 121.*.*.* 122.*.*.* 123.*.*.* 124.*.*.* 125.*.*.* 130.*.*.* 131.*.*.* 132.*.*.* 138.*.*.* 139.*.*.* 143.*.*.* 144.*.*.* 146.*.*.* 150.*.*.* 153.*.*.* 156.*.*.* 161.*.*.* 162.*.*.* 163.*.*.* 165.*.*.* 166.*.*.* 167.*.*.* 192.*.*.* 198.*.*.* 202.*.*.* 203.*.*.* 210.*.*.* 218.*.*.* 219.*.*.* 222.*.*.* 729,580,500 IPs. More than we want to try. urbanadventurer (Andrew Horton) www.morningstarsecurity.com IP address blocks in the IANA IPv4 Address Space Registry Prefix Designation Date Whois Status [1] -----
    [Show full text]
  • I Got 99 Trend's and a # Is All of Them!
    I got 99 trend’s and a # is all of them! How we found over 100 RCE vulnerabilities in Trend Micro software Agenda ▪ About us ▪ Smart Protection Server ▪ Motivation ▪ Data Loss Prevention Manager ▪ Targets ▪ Control Manager ▪ Testing approach ▪ InterScan Web Security Virtual Appliance ▪ Pitfalls ▪ Mobile Security For Enterprise ▪ Overall results ▪ SafeSync For Enterprise ▪ Conclusion ▪ References 2 About Us Roberto Suggi Liverani (@malerisch) ▪ Independent Security Researcher ▪ Discovered critical vulnerabilities in vendors such as: Microsoft, Google, Oracle, Mozilla, HPE ▪ Guest speaker at HiTB, EUSecWest, Ruxcon, Kiwicon, DEFCON and HackPra AllStars ▪ http://blog.malerisch.net 3 About Us Steven Seeley (@mr_me) ▪ AWAE Content Developer at Offensive Security ▪ Independent Security Researcher at Source Incite – Focusing on high end desktop, enterprise and SCADA vulnerability discovery and exploitation ▪ Studies the CRCA Wing Chun Martial Arts system ▪ Certified Scuba Diver and Personal Trainer ▪ http://srcincite.io/ 4 What This Presentation is NOT about! ▪ Dropping the zero-day we found ! ▪ A debate on vulnerability disclosure ▪ Putting down Trend Micro. Many other vendors have just as many, if not more vulnerabilities in their code It’s about: ▪ Sharing our failures, successes, approach to testing ▪ Helping other developers and security researchers 5 Motivation 6 Motivation ▪ Trend Micro wants to secure their software ▪ They have a bug bounty ▪ They have a ton of recently acquired / developed security solutions ▪ Knowledge is readily available
    [Show full text]
  • Black Hat USA 2012 Program Guide
    SUSTAINING SPONSORS Black Hat AD FINAL.pdf 1 6/30/12 8:12 PM C M Y CM MY CY CMY K Black Hat AD FINAL.pdf 1 6/30/12 8:12 PM SCHEDULE WELCOME TABLE OF CONTENTS Schedule . 4-7 Welcome to Las Vegas, and thank you for your participation in the growing Black Hat community. As we celebrate our 15th anniversary, we believe that the event Briefi ngs . 8-24 continues to bring you timely and action packed briefi ngs from some of the top Workshops . 21 security researchers in the world. Security saw action on almost every imaginable front in 2012. The year started Turbo Talks . 23 with a massive online protest that beat back US-based Internet blacklist legislation Speakers . 25-39 including SOPA and PIPA, echoed by worldwide protests against adopting ACTA in the European Union. Attackers showed no signs of slowing as Flame Keynote Bio . 25 replaced Stuxnet and Duqu as the most sophisticated malware yet detected. The Floorplan . 40-41 Web Hacking Incident Database (WHID) has added LinkedIn, Global Payments, eHarmony and Zappos.com while Anonymous and other politically motivated groups Arsenal . 42-51 have made their presence known in dozens of attacks. Special Events . 52-53 No matter which incidents you examine—or which ones your enterprise must C respond to—one thing is clear: security is not getting easier. The industry relies upon Stay Connected + More . 54 M the Black Hat community to continue our research and education, and seeks our Sponsors . 55 guidance in developing solutions to manage these threats.
    [Show full text]
  • OWASP NZ Day 2011 Testing Mobile Applications
    OWASP NZ Day 2011 Testing Mobile Applications Presenter: Nick von Dadelszen Date: 7th July 2011 Company: Lateral Security (IT) Services Limited Company overview • Company – Lateral Security (IT) Services Limited – Founded in April 2008, offices in Wellington and Auckland – Directors Ratu Mason and Nick von Dadelszen • Services – Information security testing (design, architecture, penetration testing, security controls, policy and compliance) – Lifecycle auditing (design, pre prod, post prod) – Regular ongoing testing programmes • Differentiators – True vendor independence – Security testing is our unique specialty – Very highly skilled staff Agenda • Why mobile apps • How to test – Attacking the communication – Attacking the server – Attacking the client • iPhone • Android • What to test for • Roundup – What we talked about – What we didn’t talk about Why Mobile Apps • Everyone is developing Mobile apps these days – Banks – Travel industry – Trademe – Subway • Not Web Apps • Similar to my Kiwicon 2007 Fat Client talk BUT – Mobile apps generally customer facing How To Test • Two different approaches to testing: – Whitebox testing • Full information and source code provided – Blackbox testing • No code or information provided • Working only with downloadable app • Three areas to focus on: – Attack the network communication – Attack the server component – Attack the client component Attacking The Communication • Need to check how information is passed between the client and server – Is it encrypted? – Can it be MITMed? – What authentication
    [Show full text]
  • Contactless Payment Systems: Credit Cards and NFC Phones Addendum
    Contactless Payment Systems: Credit Cards and NFC Phones Peter Gutmann University of Auckland Addendum These slides represent a somewhat conservative view of the security of contactless payment cards that lends the card vendors/banks the benefit of the doubt in the number of cases. In practice the situation is rather scarier than what’s presented here, but research into this is still ongoing. In particular getting access to cards and payment systems in order to allow comparisons to be made isn’t easy, if you’d like to volunteer access to a card or card terminal please get in touch Contactless Payment Systems Implemented as a standard credit-card payment mechanism running over RFID/NFC transport • US: Magstripe card data dump in plaintext • Non-US: Allegedly EMV, but usually not – Standard smart-card based payment mechanism, a.k.a. Chip and PIN Completely standard, established mechanisms, but removing the need for a physical comms channel Contactless Payment Systems (ctd) Proprietary protocols for fare and stored-value cards, e.g. Mifare (1st-gen), T-Money (2nd-gen) • Works in areas where EMV/credit cards aren’t feasible – Microtransactions – Stored-value –… • Not limited to the awkward plastic-card form factor Mifare is completely broken from top to bottom • T-Money status is unknown Contactless Payment Systems (ctd) NFC-enabled phones are much like contactless credit cards • Emulate a standard contactless card • “Passive-mode target” in NFC terminology Contactless Payment Systems (ctd) Since phones have their own power, they can also
    [Show full text]
  • COMSEC Beyond Encryption
    COMSEC Beyond Encryption Best title slide ever. By Ben Nagy (@rantyben) and The Grugq (@thegrugq) We’ve added full notes, but you should be aware that they’re not all things we actually said during the presentation, these are just some explanatory notes so that we can publish what is, effectively, 101 lolcat slides. WARNING If COMSEC failure will not result in a negative outcome then this is not the talk for you Some people like to consider improving the COMSEC of the entire world, which is probably laudable, but NOT OUR THING WARNING It’s a pretty fine line between OPSEC and COMSEC. Everyone is free to practice COMSEC, whether or not they’re operational or whether or not they’re facing a genuine adversary. However, in that case, it’s impossible to construct a threat model ( because there’s no threat ), which makes a lot of the tradeoffs moot. The school of thought that holds that all commo failures are the fault of developers for not making things SO usable and pervasive that “average users” cannot ever get things wrong is stupid. It outsources understanding to the developers of those “usable systems” which also outsources trust - but those devs won’t be going to be going to jail for you. The reason we subtitled this talk “Beyond Encryption” is precisely because there are large swathes of COMSEC that having nothing to do with the tools themselves. If you get that stuff wrong, even with the magic super-usable unicorn, you’re still going to see the inside of your potential negative outcome.
    [Show full text]