During my stay in The Hague I needed to print something, so I asked for a Copy
shop and this is where they sent me:
Against the common rule to just talk about the personal favorites, I will cover
all talks in one, two or more sentences (arbitrarily decided while
writing). This also gives you a broader picture of the conference.
Jumping right in with the keynote of Day 1 by Jon Callas and my favorite quote
“Make your devices fixable”. Enough said.
Unlike the German Oktoberfest in Munich which already started in September, the
Oktoberfest in The Hague started on 2nd October.
In spite of this competing event the decision going to the last day of the
hardwear.io Conference definitely paid off.
Day 2 started with the Keynote from Harald Welte (the father of Osmocom) and his
view about Telecom Security for the last few years. His observation is that
nothing has changed so far – we still suffer from a lack of tools and
monoculture throughout the industry.
On October 1st and 2nd Flo and I were presenting at
hardwear.io in The Hague, NL. My topic was
“Living in a fool’s wireless-secured paradise”
and Flo was presenting his current research
on medical device security. It was the first talk at an international
security conference for me and I am still quite excited!
I was speaking about the (in)security of wireless consumer alarm
systems, which you can buy just in every consumer electronics store
around the corner for about $10 – $250. I analyzed the systems on
different levels, e.g. looking at UART and JTAG and the wireless domain
with Software Defined Radio (SDR). I gave an overview of my current
research and the tools I usually use for hardware hacking, especially my
favorite thing to play with: SDR.
I am currently at the 25th
Virus Bulletin International Conference in
Prague. The VB2015 is hosted by the Virus Bulletin portal and provides three
full days of learning opportunities and networking.
VB2015 focuses on the key themes:
Malware & botnets
Anti-malware tools & techniques
Mobile devices
Hacking & vulnerabilities
Spam & social networks
Network security
General Observations:
What I liked about VB2015 was the very friendly and always helpful staff. The
good conference location, it never felt overcrowded or to empty and the very
good catering during the conference.
In the beginning of September, I had an opportunity to take part in BlackHoodie
– a reversing workshop for women organized by Marion Marschalek, senior malware
researcher at Cyphort, Inc. It took place on 5th and 6th of September at
University of Applied Sciences St. Pölten, Austria.
Besides me, 14 more young women from different countries came to attend the
workshop; the overall atmosphere was very friendly and productive. Before the
actual event all participants were getting preparatory assignments and
recommendations (not to spend our two days on learning the very basics), and
during the workshop itself we got our hands on analyzing and reversing some
actual malware samples. I personally found it very interesting how one can
detect and overcome several layers of anti-analysis protection. I left the
workshop excited and packed with some new knowledge as a basis for further
skills development – it’s just the beginning! 😉
While searching for some photos for my
last blog post on Thinkst Canary
I found a couple more from our recent trip to
Black Hat USA and
DEF CON, which I
consider worth sharing. Nothing too technical, just some visual impressions and
comments from my side. Let’s get it on!
My colleague Patrik and myself arrived one day early before the briefings and
headed right to Mandalay Bay to check out the Black Hat venue and get a feel for
the city. The sheer size of just everything is mind-blowing.
Well, it’s a canary (these cute yellow songbirds some people have as a pet), and
its main feature is that it dies before you will.
What the hack [pun intended]? And by the way… what has this to do with IT
Security? Well… let me first quote Wikipedia on the birds:
“Canaries were once regularly used in coal mining as an early warning system.
Toxic gases such as carbon monoxide, methane or carbon dioxide in the mine
would kill the bird before affecting the miners. Signs of distress from the
bird indicated to the miners that conditions were unsafe.”
Source: https://en.wikipedia.org/wiki/Domestic_canary#Miner.27s_canary
On Saturday last week I had the pleasure of delivering a
workshop on IPv6 networking
at the MRMCD2015 conference in Darmstadt, Germany. It goes
without saying that the atmosphere was quite amicable; as usual at CCC-related
events. What definitely impressed me the most was the diversity of the audience.
There were around thirty attendees representing several age groups and all with
seemingly differing backgrounds.
The engagement of everyone was stunning. I questioned the most engaged attendees
relentlessly and they fired back. I was being constantly bombarded with
questions from enthusiastic geeks and they got, hopefully, what they deserved.
This provided for a great learning environment, a friendly atmosphere and in my
humble opinion really constructive dialogues. Well, one has to be interested and
enthusiastic in order to spend three hours on a rainy Saturday evening
discussing IPv6.
Recently I had the pleasure to attend the 24th USENIX Security Symposium and its
co-located Workshop on Offensive Technologies (WOOT) in Washington, D.C. The
workshop has received quite some attention this year, 57 submissions of which 19
have been accepted, so that the organizers decided to double its length from one
to two days.
The first day of the workshop began with an excellent keynote by Adam Langley,
in which he reflected on the current state of SSL/TLS and its vulnerabilities.
As a side remark he mentioned that to tackle the everlasting problem of such
vulnerabilities to occur, research should be performed with a much higher level
of abstraction rather than focusing on the exact details of a “certain hash
function of some specific CBC cipher”.
This year’s Black Hat US saw a number of quite interesting talks in the context
of Windows or Active Directory Security. For those of you too lazy to search for
themselves 😉 and for our own Windows/AD Sec team (who couldn’t send anyone to
Vegas due to heavy project load) I’ve compiled a little list of those.
Paul Stone &
Alex Chapman: WSUSPect – Compromising the Windows
Enterprise via Windows Update
Slides here.
Whitepaper
here.
(Attention: on the BH website there’s an older this. the above link leads to the
latest one).