|
Paul Vixie & Gadi Evron, Internet Survivability, Threats and Efforts
-
www.defcon.org
-
13 years ago
-
eng
In this lecture we will begin with a brief introduction on a couple of the common or not so common threats that exist to the Internet and Internet infrastructure today, provide with some statistics and discuss the harm rather than potential risks. We will then proceed to discuss problems we face dealing with these threats, and what actually gets done to combat them, globally - and by who. We will also try and determine "where do w....
|
|
Paul Vixie & Gadi Evron, Internet Survivability, Threats and Efforts
-
www.defcon.org
-
13 years ago
-
eng
In this lecture we will begin with a brief introduction on a couple of the common or not so common threats that exist to the Internet and Internet infrastructure today, provide with some statistics and discuss the harm rather than potential risks. We will then proceed to discuss problems we face dealing with these threats, and what actually gets done to combat them, globally - and by who. We will also try and determine "where do w....
|
|
Marc Weber Tobias & Matt Fiddler, Physical Security Bypass Techniques: Exploring the Ethics of Full Disclosure
-
www.defcon.org
-
13 years ago
-
eng
Recent public disclosures detailing physical lock and safe bypass techniques have raised consumer awareness detailing the efficacy of the hardware that protects some of our most important assets. This talk will address the ethics of full-disclosure, the liability for failure to disclose, and the impact of public dissemination. Demonstrations and new discoveries of lock bypass techniques will be reviewed. Marc Weber Tobias is an Investi....
|
|
Marc Weber Tobias & Matt Fiddler, Physical Security Bypass Techniques: Exploring the Ethics of Full Disclosure
-
www.defcon.org
-
13 years ago
-
eng
Recent public disclosures detailing physical lock and safe bypass techniques have raised consumer awareness detailing the efficacy of the hardware that protects some of our most important assets. This talk will address the ethics of full-disclosure, the liability for failure to disclose, and the impact of public dissemination. Demonstrations and new discoveries of lock bypass techniques will be reviewed. Marc Weber Tobias is an Investi....
|
|
Patty L. Walsh, Muckraker, Hackers and the Media - Misconceptions and Critical Tools To Combat Them.
-
www.defcon.org
-
13 years ago
-
eng
Ever wonder what to do with the media when it seemingly (and definitely) reports inaccuracies with regard to hackers and hacking in general Fed up with the constant misconceptions you feel the media has of hackers? What is to be done? This forum shall act as an interactive discussion on the misconceptions between hackers and the media, what to do in order to protect yourself, ho to handle the media and your (as well as the media s) constitu....
|
|
Patty L. Walsh, Muckraker, Hackers and the Media - Misconceptions and Critical Tools To Combat Them.
-
www.defcon.org
-
13 years ago
-
eng
Ever wonder what to do with the media when it seemingly (and definitely) reports inaccuracies with regard to hackers and hacking in general Fed up with the constant misconceptions you feel the media has of hackers? What is to be done? This forum shall act as an interactive discussion on the misconceptions between hackers and the media, what to do in order to protect yourself, ho to handle the media and your (as well as the media s) constitu....
|
|
Do you think that all those tools you download for security testing are free? Well, they may be free of cost for some uses, but the licenses of many tools commonly used by the security community are getting more restrictive and complicated. This interactive discussion will look at the current state of security tool licensing and also look at where this field may be headed. Specific examples of license restrictions in many commonly used tool....
|
|
Do you think that all those tools you download for security testing are free? Well, they may be free of cost for some uses, but the licenses of many tools commonly used by the security community are getting more restrictive and complicated. This interactive discussion will look at the current state of security tool licensing and also look at where this field may be headed. Specific examples of license restrictions in many commonly used tool....
|
|
The Dark Tangent acknowledges those who made Defcon 13 possible, contest winners and the techniques that were used to win. Capture the Flag, War Driving, Robot Warz, WiFi Shoot Out, Scavenger Hunt, Coffee Wars, Cannonball Run (Final year!), TCP/IP Device Contest, Amateur CTF, Beverage Cooling Contest, Hacker Jeopardy, and more!
|
|
The Dark Tangent acknowledges those who made Defcon 13 possible, contest winners and the techniques that were used to win. Capture the Flag, War Driving, Robot Warz, WiFi Shoot Out, Scavenger Hunt, Coffee Wars, Cannonball Run (Final year!), TCP/IP Device Contest, Amateur CTF, Beverage Cooling Contest, Hacker Jeopardy, and more!
|
|
Several Regional Defcon Groups get together to answer questions and discuss DC group projects. What goals were in mind when creating a DC group? Five of the largest groups discuss what it means to be a part of a defcon group.
|
|
Several Regional Defcon Groups get together to answer questions and discuss DC group projects. What goals were in mind when creating a DC group? Five of the largest groups discuss what it means to be a part of a defcon group.
|
|
The Winsock SPI, or Service Provider Interface, has been a part of Winsock since the advent of version 2.0. It enables providers to extend the Winsock API transparently, by installing their own hooks and chains to application API calls. However, its formidable capabilities are not put to widespread use... aside from spyware (remember Kazaa's "sporder.dll"?). The talk will discuss (and demonstrate) some of the more insidious uses of the....
|
|
The Winsock SPI, or Service Provider Interface, has been a part of Winsock since the advent of version 2.0. It enables providers to extend the Winsock API transparently, by installing their own hooks and chains to application API calls. However, its formidable capabilities are not put to widespread use... aside from spyware (remember Kazaa's "sporder.dll"?). The talk will discuss (and demonstrate) some of the more insidious uses of the....
|
|
Infra Red is all around us. Most of us will use an Infra Red controller on more or less a daily basis, to change the TV channel, or open a car or garage door, but how often have you thought about how it actually works? This talk will describe not only how to analyse the signals being sent by your remote, but also how to use that information to find hidden commands and reveal functions you didn't even know your systems had.You will lear....
|
|
Infra Red is all around us. Most of us will use an Infra Red controller on more or less a daily basis, to change the TV channel, or open a car or garage door, but how often have you thought about how it actually works? This talk will describe not only how to analyse the signals being sent by your remote, but also how to use that information to find hidden commands and reveal functions you didn't even know your systems had.You will lear....
|
|
In the network security world, event graphs are evolving into a useful data analysis tool, providing a powerful alternative to reading raw log data. By visually outlining relationships among security events, analysts are given a tool to intuitively draw conclusions about the current state of their network and to respond quickly to emerging issues. I will be showing a myriad of graphs generated with data from various sources, such as We....
|
|
In the network security world, event graphs are evolving into a useful data analysis tool, providing a powerful alternative to reading raw log data. By visually outlining relationships among security events, analysts are given a tool to intuitively draw conclusions about the current state of their network and to respond quickly to emerging issues. I will be showing a myriad of graphs generated with data from various sources, such as We....
|
|
The Hacker Foundation, Doing Not-For-Profit Tech: The Hacker Foundation Year in Review
-
www.defcon.org
-
13 years ago
-
eng
Jesse Krembs, President, The Hacker Foundation, Nick Farr (THF Treasurer), Emerson Tan (THF Vice President), Frazier Cunningham (THF Secretary), Jennifer Granick (THF Legal Affairs Officer), James Schuyler (THF East Africa Region Coordinator), and Christian Wright Fresh from a year of grappling with Tsunamis, the IRS and building IT in Uganda, members of The Hacker Foundation will tell the story of their first year as a federally reco..
|
|
The Hacker Foundation, Doing Not-For-Profit Tech: The Hacker Foundation Year in Review
-
www.defcon.org
-
13 years ago
-
eng
Jesse Krembs, President, The Hacker Foundation, Nick Farr (THF Treasurer), Emerson Tan (THF Vice President), Frazier Cunningham (THF Secretary), Jennifer Granick (THF Legal Affairs Officer), James Schuyler (THF East Africa Region Coordinator), and Christian Wright Fresh from a year of grappling with Tsunamis, the IRS and building IT in Uganda, members of The Hacker Foundation will tell the story of their first year as a federally reco..
|
|
When was the last time you visited an actual human being to withdraw some spending money? In a world were most people visit computers for cash, ATM Networks have been traditionally thought of as a secure haven. Financial data theft is more of a reality than ever, but the backbone for the majority of cash to consumer transactions is not a target. I will show you why that is about to change. During my years at the NSA, I witnessed the growth ....
|
|
When was the last time you visited an actual human being to withdraw some spending money? In a world were most people visit computers for cash, ATM Networks have been traditionally thought of as a secure haven. Financial data theft is more of a reality than ever, but the backbone for the majority of cash to consumer transactions is not a target. I will show you why that is about to change. During my years at the NSA, I witnessed the growth ....
|
|
Philip R. Zimmermann, The Unveiling of My Next Big Project: ZPhone
-
www.defcon.org
-
13 years ago
-
eng
Philip R. Zimmermann is the creator of Pretty Good Privacy. For that, he was the target of a three-year criminal investigation, because the government held that US export restrictions for cryptographic software were violated when PGP spread all around the world following its 1991 publication as freeware. Despite the lack of funding, the lack of any paid staff, the lack of a company to stand behind it, and despite government persecution, PGP..
|
|
Philip R. Zimmermann, The Unveiling of My Next Big Project: ZPhone
-
www.defcon.org
-
13 years ago
-
eng
Philip R. Zimmermann is the creator of Pretty Good Privacy. For that, he was the target of a three-year criminal investigation, because the government held that US export restrictions for cryptographic software were violated when PGP spread all around the world following its 1991 publication as freeware. Despite the lack of funding, the lack of any paid staff, the lack of a company to stand behind it, and despite government persecution, PGP..
|
|
David Cowan - The Information Security Industry: $3 Billion of Snake Oil
-
www.defcon.org
-
13 years ago
-
eng
David Cowan, General Partner, Bessemer Ventures A raging fear of The Computer Evildoers has driven enterprises to the safety of the herd, buying whatever elixirs the big vendors peddle. Security consumers waste billions of dollars on ineffective (but well integrated!) solutions. However, as technology users grow more sophisticated about security threats (often learning the hard way), opportunities will surface for innovative startups to de....
|
|
David Cowan - The Information Security Industry: $3 Billion of Snake Oil
-
www.defcon.org
-
13 years ago
-
eng
David Cowan, General Partner, Bessemer Ventures A raging fear of The Computer Evildoers has driven enterprises to the safety of the herd, buying whatever elixirs the big vendors peddle. Security consumers waste billions of dollars on ineffective (but well integrated!) solutions. However, as technology users grow more sophisticated about security threats (often learning the hard way), opportunities will surface for innovative startups to de....
|
|
As you might already know, I like pushing the boundaries of what puppet is able to do. Today, I realized that I needed to include a class by variable name. A simple way to do this is possible with: $foo = 'world' class { "hello::${foo}::params": } I then realized that you could also do this with the standard include keyword: $foo = 'world' include "hello::${foo}::params" If you’re really insane enough to need t..
|
|
As you might already know, I like pushing the boundaries of what puppet is able to do. Today, I realized that I needed to include a class by variable name. A simple way to do this is possible with: $foo = 'world' class { "hello::${foo}::params": } I then realized that you could also do this with the standard include keyword: $foo = 'world' include "hello::${foo}::params" If you’re really insane enough to need t..
|
|
ShitRedditSays and The Downvote Brigades of Reddit (note: if you’re familiar with reddit and ShitRedditSays, you can skip to the next section.) As you probably know, Reddit is a site that revolves around voting. All users are encouraged to vote on things, which are then prioritized based on their total scores. Over time, Reddit’s userbase has grown a lot. It is now one of the most popular sites on the Internet, and nobody has enough ..
|
|
Matt Alexander of One Thirty Seven made so many interesting points I had a hard time choosing an excerpt of acceptable length for this post. I ended up settling on this one though, reflective of the tone throughout his exceptionally well-written article We’re Boring, They’re Sexting : “Sitting on the front porch of our quaint weblogs and latte-art-filled Instagram accounts, we’re collectively yelling at the kids playing in the street u....
|
|
Interesting, all the things people are starting to do with receipt paper. Sean Hollister tells of a DC restaurant that provides a collection of the latest news items printed on receipt paper when you ask for the check. Also mentioned in this article is BERG’s Little Printer , a neat thermal printer with a bunch of cool features . Permalink.
|
|
As I concluded Defining an Industry I again found myself once again trying to decide whether I should continue writing or stop where I was. On the one hand I was happy with the article’s length, approximately 550 words. On the other hand though, I really wanted to spend some time talking about being overtaken in a market and about market cannibalization. Ultimately proposing that adhering to industry standards in a given market will not..
|
|
Lately, I have been spending a lot of time thinking about disruption theory. I’m writing articles about podcasting, technology, and education, in which 5by5, Apple, and the likes of The Khan Academy are disrupting the incumbents in their respective industries to superb results. 5by5 proved the viability of business based on podcasts, and explosive growth in this space ensued as the medium gained increasingly widespread recognition outside o..
|
|
From Christine Pelisek’s article on The Daily Beast, I thought these two excerpts were of particular interest: In the wake of the Newtown tragedy, NRA executive Wayne LaPierre drew criticism for suggesting that posting armed guards in schools could help prevent future shootings. Taft Union High School does employ an armed officer on campus, but he was snowed in on Thursday and did not make it to work. In another ironic twist, the shoo....
|
|
Earlier today I stumbled across an interesting article called We Are In The Final Years of Our Internet over on Stupid Is Winning explaining why the author believes the internet as we know it is likely to gradually fade as a younger, more tech savvy generation comes of age. The author is hypothesizing that a generation raised on touch screens and iTunes is unlikely to use the internet in the same way it is used now, which will eventually ....
|
|
When I was in college I would often skip homework or studying for a test. Why? Because I was inspired to work on something else.
|
This was a busy week for actionHero! We are now up to version 4.2.2. Note that this release again changed some of the internal API’s.
|
|
Paul Shawcross did an amazing job responding to the recent petition for the government to build an actual Death Star. An excellent article. Permalink.
|