In-person DEF CON 28 cancelled
forum.defcon.org
forum.defcon.org
Along with Black Hat (the "professional" version of Defcon) and B-Sides Las Vegas, this is "security summer camp", the weeks at the end of July and beginning of August. None of these events are likely to occur on-site this year.
Later
And, on cue, in-person Black Hat is cancelled as well:
https://twitter.com/BlackHatEvents/status/125883283428810752...
Black Hat is still going to happen virtually (we just finished selecting talks).
Wired: "'DEFCON is cancelled' jokes are cancelled"
I look forward to the virtual talks from both events. Some incredible talent in both pools.
I'm afraid I haven't been to enough waffle houses to understand if this is a good thing or bad thing?
— burner hardware, — one-time network connections, — one-time user accounts, — one-time identifiers, — read-only OS builds, — physically disabling sensors, — (insert suggestions)
What else might be options for securely accessing the event?
I generally recommend ensuring that your security posture for DEFCON is the same baseline security posture you should have at all times, and for all websites, and then adjusting your habits accordingly months in advance... and then just chilling out because you've adopted a more secure normal (and DEFCON isn't particularly risky compared to everyday life).
Pantomiming paranoid-level security during hacker summer camp is silly. This is true for both in-person events and this year's virtual event.
If you're worried about getting hacked at DEFCON, don't wait until DEFCON to become secure, and don't become lax after DEFCON is over.
If memory serves, the "open" network has seen novel attacks used in years past. But not many.
For example, I might choose not to bring a laptop and just use my phone + take paper notes.
But that's more about not wanting to have to keep track of my laptop than fear of evil maids. Unplugging for a bit can be rewarding mentally and if it's not with you it's one less thing that can be lost or stolen.
The bigger risk is IMHO to end up on someone's watchlist, especially if the country you live in isn't particularly respectful of your individual freedom.
Hacker con sec can be boiled down to 2 simple principles: Update yo shit, and if you have access turned on (ssh, etc) to know their threat model.
(New venue is/will be (?) absolutely enormous; featuring the largest “pillar-less” ballrooms in the world it promised the ability to accommodate not only all talks and villages in a single venue again but everyone in a single keynote talk. Looking forward to witnessing that next year.)
edit: It's occurred to me that it could conceivably be more difficult to get into talks at this year's virtual event than it would have been in-person. Perhaps they'll implement a virtual waiting room so we can get our LINECON fix.
I feel like it is getting worse, and can't wait for Caesars. With the multiple venues and hallway congestion most the people in my company were able to get to 2-3 talks a day max.
Counterfeit DEF CON badges (and a sanctioned competition for them) have really added to capacity issues since about 2016. I know of one vendor that sold over 1,500 last year.
Regardless, I am very intrigued by your experience with counterfeit badges. I'm familiar with the counterfeit badge contest and many jokes were made about last year's "urinal cakes on a lanyard" but this is the first I've heard suggesting there was effectively mass production of counterfeit badges. Can you tell us more?
Given that #badgelife folks have difficulty manufacturing hundreds of badges they themselves designed and there's been no real scrutiny of attendee badges as would surely result if it were found that 5%+ of attendees had counterfeits, I have to call bullshit.
If reasonable evidence is presented to the contrary, I will eat my hat by donating the $300 I won't be spending for this year's DEF CON admission to the EFF.
Given the attendees, I'm surprised some didn't seriously mess with anybody entering their rooms. At the very least, one would expect all the goons getting doxxed, their phones pwned, and the whole shaming posted somewhere.
https://the-parallax.com/2018/08/12/vegas-hotel-room-securit...
What does this mean?
1. that you enter into an abusive legal agreement wherein you agree to give up your civil rights
and
2. that you dox yourself to get an account (you have to give either a non-VPN IP, or a non-VoIP phone number)
My Discord account got banned from being created from Tor and using a burner number and linking my own friends to my own website in DM (because they spy on all the unencrypted messages, natch).
This means I won't be able to participate in DEF CON this year. :(
And I'd assume such a bridge would lose some interactivity features proprietary to Discord.
sigh
————
Suspended sneak.berlin
TEK 9 MAR 2020 • 1 MIN READ
The sneak.berlin instance is a small or single-user instance operated by a software author who writes hostile instance-scraping bots. On the web page for that software, in the ironically named "ethics statement", he writes:
“Publishing your toots/messages on a server without marking them private or requiring authentication and thus making them available to the web is an act of affirmative consent to allowing others to download those toots/messages (usually by viewing them in a browser on your profile page). If you don’t want your toots downloaded by remote/unauthenticated users on the web, do not publish them to the web.
If you publish them to the whole web (and your home instance serves them to all comers), do not be surprised or feel violated when people download (and optionally save) them, as your home instance permits them to.“
This is an interesting take on online privacy, to be sure: "because you have not physically restricted me from harvesting your information, you are affirmatively consenting to it". This is much the same argument as "you shouldn't have let me hit you" and carries about the same moral weight with me.
By choosing not to talk to this instance, I hope we make clear that the Free Radical community does not wish to interact with the author or his software.
I'd rather compare it to not locking your bicycle and then complaining someone stole it. It may be illegal but you're a bit naive for expecting otherwise.
Also, in this instance the users were able to notice the data collection. What about the instances where they aren't, because the scraper just keeps to themselves? And then maybe they start getting very well-targeted spam or phishing, and maybe never find out how they were able to do that?
In a way, this scraper is a service to awareness.
If one were to run it, it does not violate anyone’s privacy because it only indexes information from the public, unauthenticated web.
It’s a bit of a stretch to claim that I myself am collecting anyone’s data. I write software. As a point of fact, I have actually never spidered or indexed the Fediverse (yet).
The software I wrote sends requests to webservers, which are in no way obligated to reply to those requests with any information. This is how the web works, and the tool I wrote is no different than any other web spider/indexer from an ethical perspective.
ActivityPub users seem have interesting concepts of what it means to have “published”.
That’s why I have a bit of a hard time taking your complaints about Def Con seriously.
Quite the contrary, I wish for the things I publish to be read and understood as widely as possible.
That's how the web works: if your webserver (or web host, or mastodon instance, or whatever) receives a request for a webpage, and then it says "yes, sure, here's the webpage", and sends it to the requesting user, there's no ethical or moral framework which at that point says that the webserver has been wronged by the requesting user having that content. It literally sent it to them voluntarily.
If you (or your server, or your host) hands out data to all comers, it is not reasonable to then say that those other people should not have access to that data. You (or your server, or your host) provided it to them.
But in all seriousness, the DEF CON Forums are generally full of helpful knowledgeable people who can help guide you in creating a non-attrib Discord account if you are having problems.
HN doesn’t have DMs, which is a very important distinction. There are no write interactions on HN other than votes and display/noprocrast settings that are not expected to be fully public.
There are no interactions with HN that are assumed to be private, such as talking to other people directly.
> The good news is DEF CON will survive, and DEF CON 29 is planned for August 5-8 2021, you can reserve your rooms now.
But given some of the comments, I'm not really if I should and how, especially since I'll be dialing from home.
I can use VPN, but not sure how the streaming would be on it. Also, what all precautions I should take.
I'm sure many would love a how to guide..
I guess it depends on where the livestream is hosted. Is it YouTube or some other site?