Today was a fun but sad day. New friends, new fascinations, and like kid summer camp, sweet goodbyes, and promises to write just as soon as you get home.
Regardless, the day was packed with great talks and fun. The day started with another talk on PLCs (I really like PLCs and ICS) from Matt Caldwell over at Tophat security who showed how Ironmap had scanned some 7.5+ million devices. Its as bad as you think, and possibly worse.
Author's Note: I was hesitant at best to make this post, but after several conversations with others, I am a disabled vet, and attended DefCon with another disabled vet. I was embarassed to have made use of the accomadations available and so neglected to write about day 2. This is my correction to that.
Day 2 resulted in us rolling in to the Convention center and heading to badge pick-up, and despite everyone’s warnings, the badge line was literally non-existent. I headed to the registration room and someone yelled at me to open my qr code before entering the room. Opening up the qr code from the registration email, I walked to a registration worker who booped my phone and sent me on my way.
Today started like most other defcon days, up, eat, rush to the conference center with tons of other people, and see what you can see.
This morning started off with an interesting talk from Samet Can Tasci who presented on Shadow Webhooks:Hunting for Dangling Event Listeners in Enterprise Workspaces. This talk offered a structured way to review Slack, Teams, Jira, et al. For previously configured web hooks that were no longer replying securely and may or may not operate with proper authentication/authorization.
Today was finally the day. 22 years in the making and I was finally going to be a DefCon attendee. I woke up around 0630 and took care of my biological requirements, got dressed, and laid back down in the bed, fully clothed, and ready to surprise xRichless. I must have been an unwelcome surprise as he rolled over and winced his eyes against the light only to see me leap violently from the covers fully dressed while shouting, “Good morning StarShine! The Earth says, ‘Hello!’” He told the Earth a few choice words of his own before rolling back over.
After boarding our flights from Chattanooga at zero-dark-thirty, @xRichless and I were finally on our way to Hacker Summer Camp.
For two men in their late 30’s I’m sure we couldn’t have looked more like excited children as Haileyeliah dropped us off with our Hak5 gear, graphic tee’s and Faraday bags at the municipal airport. A misspelled name, a broken lavatory, and a damaged zipper were the name of the game. Undeterred our intrepid heroes made the journey from Chattanooga to the desert heat of Las Vegas Nevada.
Windows and Linux users: The deadline to update Secure Boot keys is near - Ars Technica - June 24, three certificates that cryptographically verify that each piece of firmware and software that loads during system boot will expire. The Microsoft-signed certificates are the linchpins of Secure Boot, a Microsoft-designed chain of trust. Secure Boot checks the digital signatures of all firmware that loads during system startup to ensure it originates from a trusted provider, such as the manufacturer of the motherboard the system runs on.
There are a lot of issues to be called out around AI, but one that has recently begun to worry me the most isn’t ethical, moral, or even environmental. Rather, its practical.
Once upon a time, the villages and towns were full of worker’s guilds. If a young man or woman wanted to pursue a career of interest, they would find themselves spending hours hanging on the elbows of conversations between persons of import and expertise. If they were brave, they might venture to speak up and ask a question, enduring the good natured ridicule of the absurdity of their inquiry. A master of the art, taking pity on the young acolyte, might then take the fledgling under their wing and begin to educate them in the crafts. As the guild grew, so did its libraries. Knowledge filled the shelves as scribes recorded the decisions of the masters and the outcomes of decision making and debate. Factions formed within the guilds around these decisions, but overall, the discussions were lively and well-intentioned.
Dashlane explains how attackers managed to download encrypted password vaults - Ars Technica - In response, Dashlane’s automated security systems operated as intended, triggering an automatic lockout of the targeted accounts to protect those users. Before the attack was fully mitigated, the threat actor was able to brute force and generate valid tokens for fewer than 20 personal plan customers, allowing them to register a new device on those accounts and download copies of users’ encrypted vaults.