Live data from Hacker News

When Security Compromises Security – The Caesars/Defcon debacle

defiant.com

31–40 of 133 posts

Re: When Security Compromises Security – The Caesars/Defcon debacle

#31
post #22

On the other hand Black Hat Asia is freaking awesome and pretty much the best BH I've been to and I keep hearing about CCC being way better thsn Defcon. There are options outside the US! Also if you're into crypto you should go to the summerschool in Croatia or the workshops at Eurocrypt!

Do you have a link to the summer school? That sounds super interesting.

Re: When Security Compromises Security – The Caesars/Defcon debacle

#32
post #8

Surely this is at the very least a breah of privacy, and possibly a warrantless search? A hotel room, while occupied by a paying customer, should be treated as private property.

Warrantless search only applies if it was the police going in there; if it's hotel security, and if the terms and conditions of said hotel indicate hotel security can enter your room at any given time, then you'll have nothing.

Unless you‘re in Europe (or at least Germany) where Hotel staff is only allowed to enter on your invitation, no matter what the ToS say.

Re: When Security Compromises Security – The Caesars/Defcon debacle

#33
post #23

Earlier quoted context omitted.

You're trying to make it sound like AirBnB would be a better option, but just no. A hotel has accountability at least. AirBnB as an organization has and takes none, and you have to deal with the individual and their house yourself. A hotel chain has their reputation to maintain, a random guy renting out his apartment doesn't.

That's true but the sad thing is that random people renting out their apartments are, in practice, more accountable via airbnb reviews than a major hotel chain who can implement an evil policy like this across their properties and do a lot of damage before it's reined in.

I can imagine a (three-letter-agency) renting out places on AirBnB and the likes and wait for a fish to be caught in the net. Esp. in Vegas if only for gambling-related fraud (initially, at least).

Re: When Security Compromises Security – The Caesars/Defcon debacle

#34
post #22

On the other hand Black Hat Asia is freaking awesome and pretty much the best BH I've been to and I keep hearing about CCC being way better thsn Defcon. There are options outside the US! Also if you're into crypto you should go to the summerschool in Croatia or the workshops at Eurocrypt!

CCC is better than Defcon. It's actual hackers, not the Infosec Industry.

Sadly, it's around Christmas an I have a definitive veto from wife and kids.

Re: When Security Compromises Security – The Caesars/Defcon debacle

#35
post #13

Had a room visit. The two security guys were friendly in that weird way where they're all smiley and talkative, but completely ignore anything you say. Weird stuff. Oh, and they made fun of how much I paid for room service, which is weird because it's overpriced to help pay their salaries... shrug I get the why of what they're doing, but they didn't look through anything, so if I was planning something I could have h…

> Defcon is moving to Paris, Bally's, and Planet Hollywood next year, but those are all Caesar owned properties, so it doesn't address anything. DEFCON was at Bally's and Paris for two or three years two or three years ago. The theory a few of us have is the Caesar's Palace people were looking for soldering equipment (that might damage their tables) and that Caesar's doesn't care as much if there is damage to their l…

Strange theory, why not just charge people retroactively for the damage and then repair it? Is that not how hotels usually work?

Re: When Security Compromises Security – The Caesars/Defcon debacle

#37
post #4

Had a room visit. The two security guys were friendly in that weird way where they're all smiley and talkative, but completely ignore anything you say. Weird stuff. Oh, and they made fun of how much I paid for room service, which is weird because it's overpriced to help pay their salaries... shrug I get the why of what they're doing, but they didn't look through anything, so if I was planning something I could have h…

> because it's overpriced to help pay their salaries That's something you assume but cannot know unless you had a look at their books. Paying security out of room service seems quite odd. I don't think that the salary of security is based upon room service at all. Apparently these security people weren't that useful security wise, but maybe it's more that they know that too.

What? Money that people pay for room service is money flowing into the business, all of which helps pay staff salaries. I didn't realise there was any controversy around this arrangement.

Re: When Security Compromises Security – The Caesars/Defcon debacle

#38
post #34

Earlier quoted context omitted.

CCC is better than Defcon. It's actual hackers, not the Infosec Industry.

Sadly, it's around Christmas an I have a definitive veto from wife and kids.

The good news: you can watch practically all sessions on youtube: https://youtube.com/user/mediacccde/playlists

Re: When Security Compromises Security – The Caesars/Defcon debacle

#39
post #13

Earlier quoted context omitted.

> Defcon is moving to Paris, Bally's, and Planet Hollywood next year, but those are all Caesar owned properties, so it doesn't address anything. DEFCON was at Bally's and Paris for two or three years two or three years ago. The theory a few of us have is the Caesar's Palace people were looking for soldering equipment (that might damage their tables) and that Caesar's doesn't care as much if there is damage to their l…

Strange theory, why not just charge people retroactively for the damage and then repair it? Is that not how hotels usually work?

The last time I went to Defcon, someone drove the security golf cart into the pool. Others were flushing bags of concrete down the toilet. There's damage, and then there is Defcon.

Re: When Security Compromises Security – The Caesars/Defcon debacle

#40
(posted in another thread, but applies here too)

From https://marcrogers.org/2018/08/13/open-letter-to-the-hacker-.... (linked in the article): "Yes hotel staff NEED to check rooms but if we, who can change the very building blocks of life, can’t come up with a safer way to do this then we really aren’t trying hard enough."

No, they don't. They have thousands of security cameras set up, and I'd be shocked if they didn't have technologies like facial recognition built in. They have the ability to do a background check on every guest who checks in. They also have people working the front desk who likely get training to see if you're a "bad guy" or not.

So with all that, please explain why this additional search, which is a massive violation of privacy (and apparently the Constitution) is necessary?

Post reply on HN