How experts stay safe at the Black Hat security conference
usatoday.com
usatoday.com
No company laptops on the trip at all, regardless of hard drive encryption, VPN (both of which were compulsory for off-site laptop use). Company phones had to have a long unlock password, enforced centrally. No 2G - all been hacked, no 4G, hacked, only 3G, but no client details over 3G. They recommended a burner SIM, and to not use the company provided SIM at all.
Eventually they will all start sending voice over the data link, but it isn't guaranteed.
I'm assuming this is my stock S5 won't let me choose 4G only (calls become impossible), where as I can lock it to _just_ 3G.
I don't feel this fully addresses the original statement of "no 4G, hacked", though. If the downgrade-to-2G attack is the worry then 3G & 4G should be perfectly fine.
edit: grammar: supported->support.
Generally seems a bit of a grandiose story with no real evidence backing it up and likes of which have never been repeated, either (though if you know of other 3/4G hacks please say). This was also the same year Karsten Nohl was cracking GPRS [1] (which was extremely novel) and I wonder if the these two events have gotten conflated.
The little bit of evidence given on the FD post [2] and the comments on your reddit link seem to imply this was very much a hack against WiMAX, which whilst called a 4th Generation technology, bears little or no resemblance (or history) to the 3GPP standard known as LTE/4G. I think this is where the confusion comes about and the reason why 3G wasn't broken as a side-effect. We're both using the term "4G"/"LTE" but we mean different technologies.
[1] http://www.itproportal.com/2011/08/11/gprs-can-be-hacked-eas...
Movie opens with Chinese cyber-ops lab, head honcho brings in McGuffin device, plugs it in. Cut to scenes in US of machines being compromised, data, leaking, cars stopping, TV broadcasts being controlled.
Our protagonist is shown, recognising the attack and taking action: she unplugs her computer and goes for a run past stranded trucks and cars.
Titles.
A few weeks later, media is still talking about the biggest attack on US computers. CIA meeting discusses that the Chinese head of cyber-ops is known to be attending Black Hat with the McGuffin (it never leaves him). CIA has a team on trying to hack him, but two deepthroats in the room talk to each other about their suspicion that one of the CIA team is a double-agent.
One Deep Troat, a high level agent from black-ops three letter agency approaches our protagonist, an independent pentester, a hippy wunderkind living in an RV in New Mexico. They ask her to take her team to Vegas, make the hack and identify the CIA mole.
They plan the hack, involving lots of physical as well as digital subterfuge. Then they go to Vegas, have scenes of being out of their element, then the hack begins and they mostly raise their game. The CIA team detects them, destroying their hopes of finding the mole, so they focus on the McGuffin.
At the last minute it turns out the Wunderkind's best friend on her team has also been turned as a spy, and gives her identity to the CIA mole and Chinese authorities. Wunderkind has to finish the hack alone, while being hunted down by both agents.
She does so, even managing to tag her former friend so he can be picked up by the authorities, as the Chinese leave him out to dry when they retreat. Movie ends with Wunderkind receiving an offer from black-ops to work for shadow 3-letter agency full time. She returns to her RV and shreds the offer letter.
https://www.youtube.com/watch?v=Qn2g9qGbH_k
[ed: As usual for Hollywood movies of late, the trailer is considerably better than the actual movie]
I was following 'Hollywood Plotting Cliches', seems the screenwriters of that movie have the same book.
I like my heist movies with fewer gunshots though, even the trailer left me cold.
Slightly terrifying advice. A few years ago Kris Padgett (iirc) demonstrated that nearly all RFID "blocking" wallets were useless. That and they employ some immense collision detection -if you can throw a binbag full of chips past a reader and still manage to scan them all, I find it impossible to believe 2 cards stacked does _anything_ to help.
It's very useful in big gates - like ski lift, where you're likely to have the pass and your wallet with extra cards.
And no more RFID.
Edit: As a frequent (if reluctant) traveler, I've yet to encounter a necessity for RFID at passport control. (I simply avoid that particular queue.)
I've been stopped twice for not being obedient: once because I refused to step into a mm-wave scanner (after the controller refused to send me back through the metal detector after I removed my belt...), and another time for not staring into the hypnotic blinkenlights that were swirling around the cameras above everyone's heads in the queuing area.
Blackhat is so expensive that it's almost entirely government and corporate employees. Always struck me as a bit of a misnomer.
I don't think I'll ever attend Black Hat. I might attend DEFCON, unless the prices go up much higher. The interests of people who can afford tickets to BH USA are already well served by the security consultants they can afford to hire.
And if I ever do speak at DEFCON, it will be repeating a talk I already gave to the local Bsides event. Communty > Industry.
[0] https://en.wikipedia.org/wiki/Chaos_Communication_Congress
Granted, the crowds and general culture of the conference doesn't always support this, but to me it's the best part.
If you're going on the company dime and thus have a rental car, the best thing to do is stay at a hotel somewhere else. I haven't gone since they changed venues, but I used to stay at a chain hotel on the other side of the Strip from the Rio. I'd use their hotel wifi but push all my communications over an ssh tunnel, which is what you should be doing anyway on ANY public wifi.
When I got to the conference, I tended to just put my phone in airplane mode and leave it like that. I'd bring a spare laptop and boot Linux off a USB stick so I could take notes; I sometimes turned on wifi but never signed in to anything online, just looked up wikipedia articles and such. You're probably not at such a great risk because security is a lot better these days (SSL and whatnot), but you'll pay more attention to the talks if you don't have your usual set of distractions available.
Go see the Strip, but after you've seen it once I've never felt much draw to go back. If you have a car, drive over and see Red Rock Canyon in the evening, it's just outside of town and very beautiful. Lots of good restaurants around, just pick what you're interested in. I had some pretty authentic and tasty Chinese food about a mile off the strip last time I went.
It's a lot of fun, relax and enjoy!
except for paranoids - if you're not able to use your regular tools at blackhat by fear of being compromised, this means you don't trust your tools, go fix em - because if they're not safe at bh/defcon, they're safe nowhere.
in reality, even the wifi is pretty safe, LTE-only networking with VPN works out fine etc.
I haven't had chrome crash that hard since I switched back to the stable branch six months ago. The tab crashed first, but the whole Gnome Shell actually went unresponsive except for desktop switching. Apport was running wild and I had to kill it from the console to get X to start responding again.
Having to protect a single laptop isn't that big a deal, Black said. "We get over 20,000 unauthorized probes on our system every minute," he said.
Should be (Black -> Blech) Having to protect a single laptop isn't that big a deal, Blech said. "We get over 20,000 unauthorized probes on our system every minute," he said.> "And they're all staying in the same hotel," said Steve McGregory, director of threat and application intelligence for Ixia, a security firm in Calabasas, Calif..
> Jon Miller, vice president of the security firm Cylance in Irvine, Calif., doesn't see the hacking at Black Hat as malicious so much as simply intellectually curious. But he still turns off Wi-Fi and Bluetooth on his phone and only logs on to the Internet from his hotel room using a virtual private network.
Ok I get it, it's a hacker's con, with hackers hacking hackers. If you don't want your phone hacked, don't bring it to Blackhat. "It's to be expected", right?
But isn't also a little bit insane?
What about the people working there? Hotel staff, catering, nearby bars, shops, etc. Do they get debriefed about security countermeasures like this? Or are they left to their own devices? (or should I say "0wned devices")
Do the hotels use computers? Do they get help protecting their systems from damage? How do they manage to get their systems back into a safe and stable state for the rest of the year for when, you know, the place isn't swarming with people for whom "the rules are a little different".
Sounds to me the waiting staff will be the ones with the least protected phones, attracting the "intellectually curious". I'm just thinking of these additional scripts available, not the exploits, but the ones designed to slurp data after a way in has been found. They are targeted at the common types of accounts/usage, facebook and gmail, automated email digging, further escalation to ID theft, etc. Most security researchers/consultants know of these tools but they never really get to use them in their day job, because usually you don't have to follow an exploit all the way through to begin protecting your client from it. But now, they're on Blackhat! And the rules are a little different! Finally!
And even after all the hackers leave, the exploit's still in your phone.
Perhaps I'm being a bit hyperbolic here, but grant that it is a pretty crazy situation and I'm actually curious, how do the local people working there deal with this?
Imagine going to a gun convention and being advised to better prepare by wearing a bulletproof vest, because "the rules are a little different" there :)