<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Talk on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/talk/</link>
    <description>Recent content in Talk on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 12 Sep 2023 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/talk/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Breaking DPD Parcel Tracking</title>
      <link>https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/</link>
      <pubDate>Tue, 12 Sep 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/09/breaking-dpd-parcel-tracking/</guid>
      <description>&lt;p&gt;This blog post is the continuation of our parcel research. We already reported&#xA;about how we broke parcel tracking at&#xA;&lt;a href=&#34;https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/&#34;&gt;DHL&lt;/a&gt;&#xA;and the disclosure process of the identified problems. As DHL is not the only&#xA;parcel service in Germany, we also investigated the other available parcel&#xA;services. In this blog post, we want to talk about DPD, also called Geopost,&#xA;which belongs to the French Post Office.&lt;/p&gt;&#xA;&lt;h2 id=&#34;efficient-guessing-of-tracking-numbers&#34;&gt;Efficient Guessing of Tracking Numbers&lt;/h2&gt;&#xA;&lt;p&gt;DPD uses the recipient’s ZIP code to unlock detailed shipment information and&#xA;additional options. After trying some ZIP codes manually, we received CAPTCHA&#xA;prompts in the web interface (more on this later).&lt;/p&gt;</description>
    </item>
    <item>
      <title>All your parcel are belong to us – Talk at Troopers 2023</title>
      <link>https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/</link>
      <pubDate>Tue, 11 Jul 2023 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2023/07/all-your-parcel-are-belong-to-us-talk-at-troopers-2023/</guid>
      <description>&lt;p&gt;At Troopers 2023, we gave a talk on how to attack DHL parcel tracking&#xA;information based on OSINT. Since we previously had an exemplary disclosure&#xA;process about this attack with DHL, Mr. Kiehne (from DHL) joined us to provide&#xA;interesting background information and insights on how they addressed our&#xA;findings.&lt;/p&gt;&#xA;&lt;p&gt;We want to thank DHL and especially Mr. Kiehne for sharing those insights with&#xA;us at Troopers 2023. It is the ideal case, but still not common that&#xA;organizations talk openly about their actions and views on a disclosure process.&lt;/p&gt;</description>
    </item>
    <item>
      <title>SIGS DC Day</title>
      <link>https://insinuator.net/2016/09/sigs-dc-day/</link>
      <pubDate>Fri, 16 Sep 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/09/sigs-dc-day/</guid>
      <description>&lt;p&gt;Today I had to give the pleasure to give a keynote at the &lt;a href=&#34;http://digs.ch/dc-day/&#34;&gt;SIGS DC Day&lt;/a&gt; on the need to evaluate Cloud Service Providers in a way that looks behind (or at least tries to) security whitepapers and certification reports. The slides can be found &lt;a href=&#34;https://www.ernw.de/download/ERNWResearch_TrustEvaluationCloudProvider_mluft.pdf&#34;&gt;here&lt;/a&gt;.&lt;/p&gt;&#xA;&lt;p&gt;I also particularly enjoyed the following two talks:&lt;/p&gt;&#xA;&lt;p&gt;Sean O’Tool from Swisscom AG covered challenges of an infrastructure to cloud migration. Even though he only briefly touched the topic, I enjoyed his description of their firewalling model: Seeing that centralized firewall operation (or more precisely, rule design and approval) is limited/challenged by the understanding of the application, they transferred control over firewall rule sets (beyond a basic set of infrastructure/ground rules) to the application teams (using of features like OpenStack’s security groups, where he also talked about limitations of those). They compensated the loss of “centralized enforcement by a security group” with rule reviews — an approach that will become way more relevant (and necessary) in the future.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Advanced Security Evaluation of Network Protocols</title>
      <link>https://insinuator.net/2015/06/advanced-security-evaluation-of-network-protocols/</link>
      <pubDate>Mon, 08 Jun 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/06/advanced-security-evaluation-of-network-protocols/</guid>
      <description>&lt;p&gt;Hi,&lt;/p&gt;&#xA;&lt;p&gt;I’m back from London where I gave a talk about security evaluation of proprietary network protocols. I had a great time at &lt;a href=&#34;http://www.infosecurityeurope.com/en/education/education-programme/Session-Search-Pages/intelligence-defence/&#34;&gt;InfoSecurity Intelligent Defence&lt;/a&gt; and &lt;a href=&#34;https://www.securitybsides.org.uk/&#34;&gt;BSides London&lt;/a&gt;, many thanks for inviting me and giving me the opportunity to speak to so much nice people.&lt;/p&gt;&#xA;&lt;p&gt;Find the abstract and the download link to the slides after the break.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;Even in the time of Cloud-based security tools, behavior- and machine learning-based APT detection and colorful security appliances, a lot of vulnerabilities are still buried deep within the protocol layers. For security researchers it is quite a challenge to find those in well documented protocols (take SSL for an example), and when it comes to proprietary protocols, the bar is raised even (significantly) higher. This keynote will show that there is still an urgent need for security evaluation on (undocumented) network protocols, discuss war stories on protocol fails, and also give an introduction into the methodology of protocol reversing and how those protocol fails could have been avoided.&lt;/p&gt;</description>
    </item>
    <item>
      <title>OS IPv6 Behavior in Conflicting Environments</title>
      <link>https://insinuator.net/2015/04/os-ipv6-behavior-in-conflicting-environments/</link>
      <pubDate>Thu, 30 Apr 2015 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2015/04/os-ipv6-behavior-in-conflicting-environments/</guid>
      <description>&lt;p&gt;I was invited by the &lt;a href=&#34;http://www.swissipv6council.ch/&#34;&gt;Swiss IPv6 Council&lt;/a&gt; to give a talk on this topic yesterday. We had good conversations after the talk – thanks for the invitation!&lt;/p&gt;&#xA;&lt;p&gt;For those interested the slides &lt;a href=&#34;https://www.ernw.de/download/ERNW_IPv6_Behavior_Conflicting_Environments_20150430.pdf&#34;&gt;can be found here&lt;/a&gt;. I will happily discuss the intricacies of DHCPv6 and how to deploy it in complex environments at the upcoming &lt;a href=&#34;http://www.ipv6conference.ch/&#34;&gt;IPv6 Business Conference&lt;/a&gt; in Zurich and in my “&lt;a href=&#34;http://www.hmtrainingsolutions.com/de/seminare/1-seminar/88-ipv6-in-enterprise-networks141205170702.html&#34;&gt;IPv6 in Enterprise Networks&lt;/a&gt;” training in Berlin.&lt;/p&gt;&#xA;&lt;p&gt;Have a great day everybody&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
