Tuesday, August 12, 2008

What I hated about Black Hat this year

I’m on my way home from Black Hat and I have to say, some things have improved since CMP bought the conference a couple years ago. But that is a different blogpost. This is about the things that SUCK now. Like the vendors. Now vendors in and of themselves aren’t so bad when they have technical representation at their booth to talk to con attendees about their products or services. It’s the Booth Bunnies, or in some cases, the Booth Whores, that I find offensive. I’ve gone on record in the past about hating RSA because of the obnoxious marketing overload. I really hope Black Hat isn’t going that direction. I understand that the majority of Black Hat attendees are male, but it is still horribly annoying to watch companies use Cherry 2000 style bimbos try to lure potential customers to their booth based on sex appeal. And the mere fact that booth bunnies exist on the con floor makes it harder to be a woman in this industry and not have the gen pop assume you must be there purely as eye candy.

McAfee had the Security Barbie style booth bunny. I guess to distract you from the fact that their product sucks. I wonder if she comes with the Malibu Beach House.

Cenzic had a Booth Bunny ACROSS the hall from their booth (very sneaky!) stopping people walking by with “are you interested in Web Application Security?” and handing them puzzle pieces you could take to their booth and possibly win a prize. This was really funny, since I was walking with someone who works for one of their competitors (and has better products). As expected, I didn’t win anything. At least she wasn’t dressed up like a tart.

Some company had a Booth Bunny dressed as a Vegas showgirl, which I can at least respect for its theme appropriateness, even if I still hate the Booth Bunny philosophy. She was running different games where people answered questions to win prizes.

The most egregious offender was EdgeOS. When I stopped to snap a picture (and lets be clear, this was the best looking of the three Booth Whores I saw there), one of the guys working the booth asked if I’d gotten an invitation to their Saturday night party. Here is how the conversation went:

EOS Guy: hey, have you gotten an invitation to our party yet?
Me: No.
EOS Guy: you haven’t? how’d that happen? (this was kind of creepy the way he said it)
Me: probably because I didn’t stop by your booth to chat up your booth bunnies for one.
EOS Guy: they aren’t booth bunnies.
Me: no? when they wear pleather they aren’t called booth bunnies anymore?
EOS Guy: no, they’re booth babes (hands me invitation to party)
Me: whatever you call them, they make it harder to be a woman in this industry. (walks away)


You might think calling them Booth Whores is a bit harsh and judgmental. Maybe Goth Booth Bunnies is more sensitive. But this was the most direct sexual marketing I’ve seen at a non-sex industry conference, and if you get paid to dress like that, stick party invitations in your bra, and leverage sexual energy to get geek boys to stop at the booth of your temporary employer, I’d say you are selling your body for profit. AKA whoring.

Anyway, I assume the pleather girls were on display at the EdgeOS party, I don’t know for sure because I didn’t go. If I had, I’d have been the bitchy attendee who just spent the evening giving the hosts and their pleather clad prickteases shit all night, and I didn’t want to waste my time on that even if they were buying the drinks.



Just in case there is some confusion let me be clear: I have no problem with pleather, fetish wear, or pretty girls. That isn’t what I’m complaining about. When vendors bring in booth bunnies it perpetuates the stereotype that the women at cons are not there for the con itself. I have a problem with the fact that every conference I attend, at least one person assumes I must be marketing, PR, or sales. All of those fields are useful and I respect the marketing, PR, and sales people where I work. The problem is that people assume I am something I am not based on my gender. They assume I can’t possibly do anything technical or relevant to their work because I’m female. And that fucking pisses me off. Let me repeat: It isn’t that I don’t respect marketing professionals, its that I get pissed at the discrimination and bias. I understand that guys are surprised I’m a geek, that I game, that I quote sci-fi movies and know what Do Androids Dream of Electric Sheep led to. I understand that compared to the average woman you might meet in the mall or coffee shop, I’m an anomoly. But at a security conference, why WOULDN’T I be just like everyone else there?

Other things I hated:
Dan Kaminsky getting a pwnie. Black Hat overhyped his talk in a frenzy of media whoredom, then he got kicked in the balls by being awarded the most overhyped talk pwnie. He worked his ass off on this issue, did all the right things to try and protect people, and instead of earning the respect he deserved, he got made fun of.

Smells Like Teen Spirit transitioning to Saturday Night Fever. FAIL

French press sniffing creds

Snacktime crowds clogging the halls, making movement impossible

Talks that span 2 hours. I don’t want to commit 2 hours to one talk. C’mon people, tighten it up. There are too many interesting things to see to put all my eggs in one basket for 2 talks. By having a 2 hour talk you are not competing with 4 other tracks, you are competing with 8.


Not enough time or space to talk with everyone I wanted to. The size of Black Hat is a blessing and a curse. You see everyone in one place, where you might only see half as many people you want to at a smaller con. But everyone is circulating so there isn’t time for talking with any one person very much. There are a great many people I wish I’d had time to sit down and talk with more.

Labels: , , , , , , , , , ,

What I liked about Black Hat this year

THE TALKS!!
Dan Kaminsky’s It's The End of the Cache As We Know It. (come on, you know you can't help thinking 'And I Feel Fine' after reading that) Standing room only, Dan’s grandma’s session cookies, talk content, speaker energy, enthusiasm. I <3 Dan. If I could adopt a big brother, it would be Dan.

Bruce Potter’s talk on Net Flow analysis. Super interesting, well presented.

Mark Dowd and Alexander Sotirov’s talk on Bypassing Windows Vista Memory Protections. They’re wicked smaht.

LT. Col. Greg Conti’s talk on visual forensics analysis - I am a sucker for visual representation of any data...

Christopher Hoff's Four Horsemen of the Virtualizaton Security Apocolypse.

I know, my review of the talks is pretty light here, but I don't have to write a trip report for the general public so quitcherbitchen. If you're so interested, you should have gone to the talks yourself.

THE OTHER STUFF
Registration check in lines are sooooo much better than in years past, more lines, move faster, yay. But having a separate line to get your delegate bag is a bit inefficient for attendees.

Box lunch option. Now if only they’d offer a ‘no lunch’ ticket. I don’t even care if it costs the same as a ‘with lunch’ registration. I never eat at the con, whether it’s a box lunch or plated meal. I feel bad wasting the food.

Overall, compared to when I first started attending Black Hat many years ago, the con feels more professional. Talks start and end pretty much on time, I didn’t see any real AV difficulties, logistically things seemed pretty smooth. Awwww, Black Hat is growing up!

Lobster and crab dumpling things, sushi, and sliders at a vendor party. Best party food all week.

The conference continues to grow and mature. I’m excited to see that, big conferences are a great initiation ground for new security professionals who may not know about or understand yet the value of smaller cons like ShmooCon or Toorcon, and a great ‘reunion’ spot for people who may talk via IM/Twitter/Facebook/MySpace/IRC/email/whatever all the time but only see each other IRL a few times a year at cons. But the size of Black Hat is a blessing and a curse. You see everyone in one place, where you might only see half as many people you want to at a smaller con. But everyone is circulating so there isn’t time for talking with any one person very much.

Wall of Sheep. A DefCon staple, nice to see it at Black Hat too. Baaaaaaaaa.

Not really about Black Hat, but a Vegas thing: there is now one cab company that takes credit cards in Vegas. w00t. I hate carrying cash.

$32K raised for EFF between Black Hat and Defcon. nice.

Several people arranged hotel suite Rock Band parties in the evenings. That is awesome. !..!,

See y’all again in 2009. Wouldn’t miss it.

Labels: , , , , , , , , , ,

Wednesday, February 28, 2007

Responsibility runs both ways

If you read Emergent Chaos (and if you don't, you need to add it to your reading list right now) you've already seen that the RFID talk Chris Paget was scheduled to deliver at Black Hat Federal is back on.

Apparently HID doesn't have a Webster's dictionary, because they now claim they didn't demand that the talk be pulled.

"HID Global did not threaten IOActive or Chris Paget, its Director of Research and Development, to stop its presentation at the Black Hat event being held in Washington, DC on Wednesday, February 28, 2007."


and

"Under no circumstance has HID asked IOActive or Mr. Paget to cancel their presentation. In fact, we were surprised by their decision to cancel the presentation and to attribute the cancellation to a threat from HID. This was not, and never was, HID’s position."


*cough* *cough* bullshit *cough*

You can read the entire letter HID sent here, but here are a couple snippets:

We understand … that you intend to publicly present and publish additional information about your spoofer at the Black Hat convention … We believe such presentation will subject you to further liability …

…hereby demand that you refrain from publishing any information at any public forum including the upcoming Black Hat convention…


that sounds like a demand/threat to me...

Anyway, this is all very interesting but it is distracting us from the real issue of responsibility. I personally believe that researchers have a responsibility to work with vendors to resolve security issues in a way that protects customers. But I also believe that vendors have a responsibility too, a responsibility to make sure that they are doing everything they can to stay on top of known vulnerabilities in their products, provide customers with workarounds and mitigations, and ultimately create more secure products. RFID vulnerabilities have been publicly known since 2005, Paget's presentation is not really NEW (even Jeff Moss calls it "largely a rehash of known issues, intended more as an introduction").

And remember, HID claims “cloning is simply not a credible threat”.

Long ago (in a galaxy far, far away) the only way to get vendors to fix security problems was to report them publicly and shame them into a fix. Today, vendors (most of them anyway) try to work with researchers to fix vulnerabilities and protect their customers. What keeps me up at night after events like this is the fear that more vendors will choose to ignore vulnerabilities and try to strong arm researchers into silence about the flaws in their products, and that will be used to further justify full disclosure. I don't want to live in a world where only way to get a vulnerability fixed is to drop it anonymously to a mailing list and hope the good guys fix it before the bad guys leverage it.

yearning for utopia,
~Elphie

Labels: , , ,

Monday, February 26, 2007

Black Hat Federal this week

If I were there, I'd definitely make a point of seeing Jose Nazario and Ollie Whitehouse. Both are delivering fairly new talks on the con circuit, and look like interesting stuff. If you catch either of the talks, let me know what you think?

Also, if you haven't heard already about the Chris Paget talk that has been withdrawn from the conference, go read this now. Then go make a donation to the ACLU for being the good guys.

Y'all know I'm a big supporter of responsible disclosure, but when I read things like this, I have to shake my head and wonder what the vendor is thinking.

"These systems are installed all over the place. It's not just HID, but lots of companies, and there hasn't been a problem. Now we've got a person who's saying let's get publicity for our company and show everyone how to do it, and it puts everyone at risk. Where's the sense of responsibility?" Carroll said.


Yes, where is the sense of responsibility? Such as HID's responsiblity for delivering on their promise of a security solution to customers? Does HID deserve an opportunity to work with researchers to fix their security problems and protect customers? Absolutely. But these vulnerabilities have been widely known for over a year, and until now have been pooh-poohed by HID.

She [Kathleen Carroll, a spokeswoman for HID's Government Relations group] said that the company has long been aware that its proximity cards are vulnerable to hacking but does not believe that the cards are as vulnerable as Paget suggests.

"For someone to be able to surreptitiously read a card, they'd have to get within two or three inches and get into the same plane as the card," Carroll said.

HID is also concerned that Paget's demonstration will popularize the vulnerabilities in its proximity cards and endanger its many customers.


You can't have it both ways. Either you don't take it seriously as something to fix (in which case a conference talk is no real threat), or you do take it seriously and would have developed some sort of strategy or plan to solve the problem. Make up your mind.

Asked why HID hasn't addressed the issue in more recent proximity card systems, after knowledge of RFID threats became common, Carroll said that doing so would cause "major upheaval" among customers.


oh yeah, because their customers are really just shopping for a bit of security theater; something that keeps the lamer criminals out. I'm sure they would rather have a physical security system that can be trivially compromised by a skilled/motivated attacker using publicly known vulns than do what it takes to actually have a secure physical security system...

bah. makes me cranky.

~Elphie

Labels: , , ,

Saturday, June 03, 2006

Black Hat Vegas Speaker Schedule Posted!!

Check it out - looks like an awesome lineup. Very impressive...

~Elphie

Labels: ,

Wednesday, March 08, 2006

Everything old is new again

hmm, big news week I guess. Too bad this isn't NEW news.
Microsoft Fingerprint Reader Hacked

InfoWorld - 3/7/2006
A security researcher says the Microsoft Fingerprint Reader fails to encrypt fingerprint images, making the device vulnerable to hackers.
Even the researcher points out that the Microsoft Fingerprint Reader says right on the box that it is not a security tool but a convenience for users who don't want to or have a hard time remembering passwords. This translates to me as a power toy for geeks and the forgetful.

The unfortunate thing is how the journalist glommed onto this presentation as groundshaking when Joe Grand demonstrated several ways to hack fingerprint readers as well as several other hardware devices at Black Hat Vegas in July 2005. Joey, I guess you are just ahead of your time...

~Elphie

Labels: , , , ,