Showing posts with label DEFCON. Show all posts
Showing posts with label DEFCON. Show all posts

Thursday, September 11, 2014

DEFCON 22 Weaponizing Your Pets Gene Bransfield




Weaponizing Your Pets
Gene Bransfield Twitter @gbransfield


DEFCON 22: Dark Mail Ladar Levison and Stephen Watt



DEF CON 22 Darkmail
Ladar Levison & Stephan Watt

I also strongly recommend Leo Laporte's interview of Ladar Levison on Triangulation, its available as podcast on iTunes or as download at
http://twit.tv/show/triangulation/125

Monday, August 11, 2014

Def Con 21: "Pentesting with an Army of Low-power Low-cost Devices"





Couldn't go to Def Con 22, waiting for vods to come out, so started watching some of the Def Con 21 Youtubes in the meanwhile.

I like this one about Pen Testing with cheap Arm devices by Dr. Philip Polstra aka Dr. Phil the Hacker his Twitter is ppolstra | https://twitter.com/ppolstra.

He uses the BeagleBoard Black as the starting point for his hardware.

Some useful links:
For new readers of my blog, I have labels at bottom left of every post & selected labels at left side of the blog to help find related posts.

These labels can be booked marked so you can just check topics your interested in, so for more posts like this you could click on:

Thursday, May 8, 2014

Security & Hacking: DEFCON 20 "Can You Track Me Now?"



DEFCON 20: Can You Track Me Now? Government And Corporate Surveillance Of Mobile Geo-Location Data

This was posted on Youtube November 22, 2012, so was well before Snowden release of information in May of 2013.

Main emphasis of this talk was tracking of cell phones.

But Christopher Soghoian briefly covers, at 31:05, that both Android (Google) & iOS (Apple) device encryption can be defeated by Google & Apple respectively.

This is a service they provide for Law Enforcement & other Government agencies.

Google can force a password reset for Android device, they don't require physical access.

Apple appears to use what Soghoian calls a "Master Skeleton key," they require departments to provide actual device (ie physical access).  They then provide unencrypted data on a CD, while device remains encrypted.

I wonder if they might actually need device to decrypt data with way devices since iPhone 4S & iPad 2 have been designed (they have hardware based encryption).

Entire video is worth watching, though it is rather long, they joke about having 3 different audience during the course of the talk.
 



Wednesday, July 24, 2013

One NFC Ring to Rule Them All




NFC Ring by John McLear

I really hope this is successful, looks like a very practical solution to smartphone security for average people IMHO.

iPhone 4S and newer, and most Blackberry's (with correct settings for MicroSD card) have good device security if locked with strong password, but entering strong password on touchscreens is a major PITA!

I am thinking this would provide a way to use a very strong password, without having to manually enter it all the time, so if your smartphone was lost/stolen, your data would be secure.

Their Kickstarter link http://www.kickstarter.com/projects/mclear/nfc-ring

Their Blog is at http://blog.nfcring.com/
Their Webpage (future main site?) http://nfcring.com/

I like the Rackspace NFC ring Hacker challenge for DEFCON (can win $100 of  free hosting) see
http://developer.rackspace.com/blog/steal-my-nfc-ring-data-at-defcon-for-100-dollars-of-free-hosting-with-rackspace.html or http://blog.nfcring.com/uncategorized/rackspace-nfc-ring-challenge/