Top Banner
TRIAL BY FIRE: SECURITY @ DEF CON 21 REED LODEN, INFORMATION SECURITY, LOOKOUT
16

Trial by Fire: Security @ DEF CON 21

Jan 15, 2015

Download

Technology

Lookout

DEF CON is the world's largest hacker conference, and it's easy to get PWND. Reed Loden leads Information Security at Lookout, and this is his summary of how to stay safe at DEF CON 21.
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Trial by Fire: Security @ DEF CON 21

TRIAL BY FIRE:SECURITY @ DEF CON 21

REED LODEN, INFORMATION SECURITY, LOOKOUT

Page 2: Trial by Fire: Security @ DEF CON 21

It’s the world’s largest hacker conference

DEF CON IS AWESOME

Images via defcon.org and @mikko

Page 3: Trial by Fire: Security @ DEF CON 21

But it’s easy to get burned

People will try to hack youIt’s a hacker conference after all...

Page 4: Trial by Fire: Security @ DEF CON 21

DEF CON TOP 5 TIPS

• Be paranoid. Expect to be a target of social engineering.• Leave devices at home or in the hotel safe if you don’t need them.• Limit your texts and calls, and assume they’re being monitored.• Don’t connect to WiFi, Bluetooth, NFC, etc. • Remember hacking is not limited to computers and phones.

Things in your wallet or purse (like credit cards, passports, IDs, access badges) might have NFC or RFID.

Page 5: Trial by Fire: Security @ DEF CON 21

CAN PREVENT HACKERSImage via www.smokeybear.com

Page 6: Trial by Fire: Security @ DEF CON 21

Your computer can’t get hacked if you don’t take it!

What could happen if the stuff on your computer got leaked?

• Confidential documents or info• Source code• Privileged access• Other intellectual property

LEAVE YOUR COMPUTER

Image via www.razorreef.com

Page 7: Trial by Fire: Security @ DEF CON 21

• Keep mobile devices turned off unless needed• Don’t install or update any software• Keep it locked with a passphrase• Turn off WiFi, Bluetooth, NFC, etc.• Maintain physical possession of your bags and devices—

don’t set them down!• Log out of work email, personal email, social networks so

they won't auto-connect

USE YOUR PHONE OR TABLET (SAFELY)

Page 8: Trial by Fire: Security @ DEF CON 21

• Limit calls and SMSes. Expect all messages and calls to be monitored or recorded, so don't say anything confidential.

• Clear your list of saved WiFi networks and SSIDs to avoid wireless access point spoofing.

• If possible, back up your phone, wipe it and restore it later• Watch out for weird behavior that might indicate someone

is trying to intercept your calls, like: • Looks like you have full signal strength, but you can’t

make a call• Your signal keeps getting downgraded to 2G, EDGE or

GPRS

PHONE AND TABLET USE, CONT.

Page 9: Trial by Fire: Security @ DEF CON 21

Download Lookout’s mobile security app before DEF CON!

Remember, your smartphone or tablet is just as critical as your computer, and probably has lots of sensitive personal and company data on it.

WAIT, YOU DO HAVE A SECURITY APP, RIGHT?

Page 10: Trial by Fire: Security @ DEF CON 21

DON’T CONNECT TO NETWORKS

DEF CON networks are extremely hostile. Don’t connect to ANY of them!

• Avoid all networks at the Rio (where the con is hosted), all WiFi networks, all public networks... you get the idea.

• VPN from hotel networks. (Unless you’re at the Rio... in which case don’t connect!)

• Don’t log into your company’s services, like email, wikis, internal environments, etc.

Page 11: Trial by Fire: Security @ DEF CON 21

ENJOY PUBLIC SHAMING? US NEITHERIntercepted account info will be posted to the infamous WALL OF SHEEP. So think twice before logging in to check Twitter (or trying to update your

MySpace like this example).

Page 12: Trial by Fire: Security @ DEF CON 21

• Watch for social engineering• Don’t scan QR codes• Don’t use ATMs at the Rio; bring cash with you to Vegas• Beware of giveaways— CDs, USB sticks, anything electronic• Don’t use public charging stations. It might be juice jacking.• Don’t use dongles that aren’t yours, like adapters or converters

for DVI, VGA, Thunderbolt

BE PARANOID

Page 13: Trial by Fire: Security @ DEF CON 21

If you do have to bring your RFID or NFC items (passports, credit cards, badges or IDs), wrap them in tin foil or put them in a copper-lined envelope to block hackers.

It’s like a DIY Faraday cage.

(Or check out DIFRwear.com)

TIN FOIL IS BACK

Image via badattitudes.com

Page 14: Trial by Fire: Security @ DEF CON 21

BUT MOST OF ALLHAVE FUNBE SMART

LEARN SOMETHING