In greed we thrust.
72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
21–30 of 46 posts
Re: 72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
#22Not really worth the time to read.
Re: 72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
#23TL;DR: author did some gambling in casinos and got drunk in strip clubs, barely attended any talks because he doesn't understand the jargon, almost got pwnd by connecting to the wrong WiFi. Not really worth the time to read.
Re: 72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
#24Earlier quoted context omitted.
I went to HOPE a few weeks ago, after having been to such things before, but not for a few years. I had exactly the same impression - mostly a lifestyle / social / political thing, pretty light on in the way of talks with actual technical detail. Kind of like TED talks - well presented, entertaining, but not really actionable. In years gone by, I went to some excellent events, with talks on really specific, useful th…
What talks did you attend at HOPE? There were tons of hard technical presentations. The two guys who cracked the Iridium satellite network in particular were amazing, going into deep detail on the techniques and methods used to decode the frequencies. The talk on medical device hacking was also awesome - I mean they showed you how to get on a radiology machine and other exploits. And after I saw the talk on hacking y…
https://xi.hope.net/schedule.html#-coding-by-voice-with-open...
There was definitely some good stuff, just seemed to me that overall, the mix of practical/technical vs cultural/lifestyle/political at events like this has changed a lot over the years. Either that, or my perception has changed, it's hard to tell.
Re: 72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
#25He should have gone to BlackHat if he wanted to see anything really interesting. Def Con is mostly a big party with life style talks and people talking about old stuff. Thats not to say there isn't neat stuff to do at Def Con (I've seen plenty of neat talks) but its mostly a big party. There's nothing really scary going on there.
It sounds weird that they're selling key-logging sticks for $50 and spoofing routers for $100 at a convention where you'd think everyone can build that stuff by themselves for a much lower price. Just to add to your point, I suppose.
At volume. But if you only need one (or ten), assuming your time has some non-trivial value, it's much cheaper to just buy off the shelf.
Re: 72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
#26There ought to be a way, at the OS level, to configure a machine so no network traffic goes in or out over an unsecured link except for the VPN application's traffic. Then, if you configure secure links to be WPA at work, WPA at home, and your VPN, there should be little risk to joining an open network to bring up a VPN.
Last I checked, it was a bit more difficult to do on Windows, because it didn't allow interface-specific rules, and because software installers had a habit of opening holes for themselves in the firewall without asking you.
Re: 72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
#27> “Aren’t those the people who break into computers?” > > “Yes—also phones, cars, airplanes, and human bodies.” > > “I thought that stuff was illegal.” While I think they're truly innovative and inevitable, the advent of "secure CPUs" [1] over the last decade or two will eventually become the norm. And once they do -- lookout, brother. The woman who was having this conversation scoffs at how Def Con can even take pla…
Consider all the phone "OSes" (aka ROMs) you can install on phones with locked boot loaders that just replace a few binaries/files here and there in an existing OS to change how it works/feels. The maker of said ROMs may not have the ability to replace the kernel but any vulnerability in said kernel will allow them to replace everything else which is precisely where userland security lives.
So the hardware may be "secure" from the perspective of the manufacturer but not from the perspective of the user. They can still be pwned.
Re: 72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
#28Earlier quoted context omitted.
It sounds weird that they're selling key-logging sticks for $50 and spoofing routers for $100 at a convention where you'd think everyone can build that stuff by themselves for a much lower price. Just to add to your point, I suppose.
Even if you value your time as worthless then maybe you could build a hardware key logger for less than $50 in parts but I really doubt it.
http://www.freetronics.com.au/products/leostick
...and stick it inside a generic keyboard (which has plenty of room).
I always thought that the fact that big corporations hand out the same keyboard to everyone enables these sorts of attacks. Any would-be spy could just make a handful of hardware key-logging generic HP and Dell keyboards and easily swap out any given keyboard at any given big company without having to even think.
I never use my employer's provided mouse/keyboard combo. Mostly because they're always absolute crap but also because I want to give any potential attackers a hard time. I can only imagine the look on some attacker's face when they show up at my desk and see custom hardware everywhere =)
Re: 72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
#29Earlier quoted context omitted.
It sounds weird that they're selling key-logging sticks for $50 and spoofing routers for $100 at a convention where you'd think everyone can build that stuff by themselves for a much lower price. Just to add to your point, I suppose.
At a convention you can pay cash (semi-)anonymously where if you had to build that stuff you'd leave a paper trail. Many I know in this group of people (DefCon/HOPE attendees) do things like trade around craigslist-cash-purchased laptops.
Re: 72 Hours of Pwnage: A Paranoid N00b Goes to Def Con
#30TL;DR: author did some gambling in casinos and got drunk in strip clubs, barely attended any talks because he doesn't understand the jargon, almost got pwnd by connecting to the wrong WiFi. Not really worth the time to read.
As an active DEF CON attendee and seeing the press coverage over the years, I can start to "see the matrix" of how to lazily assemble a news story. He even links to the Hacker Manifesto FFS. I thought VICE was aiming higher than this kind of trash.
It makes me distrust reporters. Do they just turn off the "I'm a noob" angle, assume the standard authoritative tone they always use and cover other topics with just as flimsy of an understanding?