First, a few words regarding my experience at Black Hat: for me, it was the
first time attending the conference and then directly as a speaker. I thoroughly
enjoyed Black Hat. It took a while to get used to the size of the conference and
the vibe of Las Vegas. What was especially interesting for me was connecting
with other researchers. One thing that stood out was meeting with the team from
MSRC and putting faces to the team itself. It feels way more personal to know
who you’re talking to when you know the people handling your cases. During
TROOPERS I typically have the chance to connect with many researchers, mainly
from Europe. At Black Hat US, on the other hand, it is possible to connect more
with the US scene and meet people you haven’t seen in a long time! Seeing
familiar faces again is always nice, as opposed to putting them into your
biometric template database. One nice detail was that some international
researchers are aware of the research BSI (German: “Bundesamt für Sicherheit in
der Informationstechnik” – “German federal office for IT security”) is
facilitating. The results of our presentation stem from the “Windows Dissected”
project we are performing on behalf of the BSI.
I’ve been at Black Hat Vegas last week and in the following I’ll shortly discuss some talks I’ve attended and which I found interesting.
Gabriele Fisher & Luke Valenta: Monsters in the Middleboxes. Building Tools for Detecting HTTPS Interception
This talk was about identifying if inbound HTTPS traffic reaching a server had been intercepted by a middlebox (or its software equivalent which is usually called “middleware”, a prominent example being the Lenovo Superfish piece a few years ago) on its path.
Given the CfP for Black Hat US in Vegas ends in a few days – and as apparently somepeople have already started to think about their TR18 submissions – I’ll quickly provide some loose recommendations on how to write a submission here. There’s quite some reasonable advice out there already (the BH CfP site lists this and this which you should both read as well) but some of you might find it useful to get (yet) another perspective.
A few months ago I had the opportunity to visit this year’s Black Hat in Las Vegas. Due to a few weeks of vacation following the conference here are my delayed 2 cents (part 1)
Just a few days ago I had a blast again at this year’s Black Hat. Some of the talks were really worth listening to, so I wanted to point them out and give a short summary.
They had the last slot at the last day of Black Hat which resulted in a kind of empty room, but in my opinion it was an awesome talk and I even had the pleasure to meet these two guys at our ERNW dinner.
I won’t be in Vegas for Black Hat this year as there’s a direct conflict with one of my kids’ birthdays, but I thought one or another reader might find it helpful to get some inspiration as for selecting the talks to catch (not least as there’s so many interesting ones). I hence decided to quickly write this post.
Here’s my would-be schedule for the first day (second day to follow, maybe, in another post), under the assumption to attend exactly one talk per slot. I could give a longer rationale per talk than the one below, based on several (mostly technical) factors, but this is just about providing suggestions in a brief form.
Disclaimer: I was on the BH guest review board this year so I might be biased in some cases.
While searching for some photos for my last blog post on Thinkst Canary I found a couple more from our recent trip to Black Hat USA and DEF CON, which I consider worth sharing. Nothing too technical, just some visual impressions and comments from my side. Let’s get it on!
My colleague Patrik and myself arrived one day early before the briefings and headed right to Mandalay Bay to check out the Black Hat venue and get a feel for the city. The sheer size of just everything is mind-blowing.
Well, it’s a canary (these cute yellow songbirds some people have as a pet), and its main feature is that it dies before you will.
What the hack [pun intended]? And by the way… what has this to do with IT Security? Well… let me first quote Wikipedia on the birds:
“Canaries were once regularly used in coal mining as an early warning system. Toxic gases such as carbon monoxide, methane or carbon dioxide in the mine would kill the bird before affecting the miners. Signs of distress from the bird indicated to the miners that conditions were unsafe.” Source: https://en.wikipedia.org/wiki/Domestic_canary#Miner.27s_canary
This year’s Black Hat US saw a number of quite interesting talks in the context of Windows or Active Directory Security. For those of you too lazy to search for themselves 😉 and for our own Windows/AD Sec team (who couldn’t send anyone to Vegas due to heavy project load) I’ve compiled a little list of those.
Paul Stone & Alex Chapman: WSUSPect – Compromising the Windows Enterprise via Windows Update
Slides here.
Whitepaper here. (Attention: on the BH website there’s an older this. the above link leads to the latest one).
Information security conferences are known to be attended because of several reasons. For some it’s the technical content, for others the networking potential and for some others simply meeting old friends. Pinpointing our motives is clearly a challenging task, but the following wrap-up ought to share our personal highlights of the week we spent visiting Black Hat USA 2014 and DEFCON 22 in Las Vegas.
After somewhat 18 hours of flight, some sleep and with the beautiful scenery of perpetual clear skies above Las Vegas we began what was to be an incredible week.