Doing a 'fire-and-forget' text message and then attaching grave consequences to the timing is ridiculous.
Doing a 'fire-and-forget' text message and then attaching grave consequences to the timing is ridiculous.
Nevermind the fact that it was defcon, I'm a regular presenter at conferences and meetups, and literally #1 on my last-minute checklist is to text my wife that I'm now unreachable and silence my phone.
FTFY.
Maybe next time, Salesforce should think twice about sending its executives to DEFCON. Without some basic introduction as to what it's actually about.
I know very little about security or defcon, but I was under the illusion that stuff like running Wifi Pineapple to trick people to connect to their hotspots was common and doesn't require any 0-days.
The concern is man-in-the-middle attacks. Easy, no user interaction required, and works very well. No chipset zero days involved.
Pretty sure some of those are FBI and other agencies ;-)
Reminds me of a friend who said his MySpace password was just "password123" because "It's such a stupid password that nobody would ever use it, so hackers don't even bother trying it!"
I wish I had multiple faces so I could palm more than one.
1) Make sure it has an Apple logo on the back and is up to date. I'm serious on this one. Too many Android phones don't get updated by the carrier and that's why I'm not a fan. Yes, if you have the latest phone from Google, you are fine. From another manufacturer, very questionable. The sheer number of Android phones which have connected to my open research WiFi networks over the years and exposed some secret is just tragic, from user PINs thanks to a carrier installed warranty app to e-mail passwords thanks to broken Samsung KNOX TLS middling implementations.
2) Shut off all background activity from apps when not on and in front of me: settings -> general -> background app refresh. Slide that one to off for everything.
3) Turn off WiFi and Bluetooth.
4) For added paranoia, put it in airplane mode when not being used.
5) Make sure it doesn't have any information or accounts on it which I'd not like to be made public.
6) Back it up.
7) A quick audit of apps I'll be using at the con to ensure they are reasonably secure on the wire by using working TLS exclusively. Yeah, very few people will ever do this but thankfully 1-6 should be sufficient.
There is a XDA post somewhere explaining this.
From what I hear all those Chinese dissidents that are tragically no longer with us were all using Apple products...
SMS is UDP, and voice is TCP?