Tuesday, August 12, 2008

What I hated about Black Hat this year

I’m on my way home from Black Hat and I have to say, some things have improved since CMP bought the conference a couple years ago. But that is a different blogpost. This is about the things that SUCK now. Like the vendors. Now vendors in and of themselves aren’t so bad when they have technical representation at their booth to talk to con attendees about their products or services. It’s the Booth Bunnies, or in some cases, the Booth Whores, that I find offensive. I’ve gone on record in the past about hating RSA because of the obnoxious marketing overload. I really hope Black Hat isn’t going that direction. I understand that the majority of Black Hat attendees are male, but it is still horribly annoying to watch companies use Cherry 2000 style bimbos try to lure potential customers to their booth based on sex appeal. And the mere fact that booth bunnies exist on the con floor makes it harder to be a woman in this industry and not have the gen pop assume you must be there purely as eye candy.

McAfee had the Security Barbie style booth bunny. I guess to distract you from the fact that their product sucks. I wonder if she comes with the Malibu Beach House.

Cenzic had a Booth Bunny ACROSS the hall from their booth (very sneaky!) stopping people walking by with “are you interested in Web Application Security?” and handing them puzzle pieces you could take to their booth and possibly win a prize. This was really funny, since I was walking with someone who works for one of their competitors (and has better products). As expected, I didn’t win anything. At least she wasn’t dressed up like a tart.

Some company had a Booth Bunny dressed as a Vegas showgirl, which I can at least respect for its theme appropriateness, even if I still hate the Booth Bunny philosophy. She was running different games where people answered questions to win prizes.

The most egregious offender was EdgeOS. When I stopped to snap a picture (and lets be clear, this was the best looking of the three Booth Whores I saw there), one of the guys working the booth asked if I’d gotten an invitation to their Saturday night party. Here is how the conversation went:

EOS Guy: hey, have you gotten an invitation to our party yet?
Me: No.
EOS Guy: you haven’t? how’d that happen? (this was kind of creepy the way he said it)
Me: probably because I didn’t stop by your booth to chat up your booth bunnies for one.
EOS Guy: they aren’t booth bunnies.
Me: no? when they wear pleather they aren’t called booth bunnies anymore?
EOS Guy: no, they’re booth babes (hands me invitation to party)
Me: whatever you call them, they make it harder to be a woman in this industry. (walks away)


You might think calling them Booth Whores is a bit harsh and judgmental. Maybe Goth Booth Bunnies is more sensitive. But this was the most direct sexual marketing I’ve seen at a non-sex industry conference, and if you get paid to dress like that, stick party invitations in your bra, and leverage sexual energy to get geek boys to stop at the booth of your temporary employer, I’d say you are selling your body for profit. AKA whoring.

Anyway, I assume the pleather girls were on display at the EdgeOS party, I don’t know for sure because I didn’t go. If I had, I’d have been the bitchy attendee who just spent the evening giving the hosts and their pleather clad prickteases shit all night, and I didn’t want to waste my time on that even if they were buying the drinks.



Just in case there is some confusion let me be clear: I have no problem with pleather, fetish wear, or pretty girls. That isn’t what I’m complaining about. When vendors bring in booth bunnies it perpetuates the stereotype that the women at cons are not there for the con itself. I have a problem with the fact that every conference I attend, at least one person assumes I must be marketing, PR, or sales. All of those fields are useful and I respect the marketing, PR, and sales people where I work. The problem is that people assume I am something I am not based on my gender. They assume I can’t possibly do anything technical or relevant to their work because I’m female. And that fucking pisses me off. Let me repeat: It isn’t that I don’t respect marketing professionals, its that I get pissed at the discrimination and bias. I understand that guys are surprised I’m a geek, that I game, that I quote sci-fi movies and know what Do Androids Dream of Electric Sheep led to. I understand that compared to the average woman you might meet in the mall or coffee shop, I’m an anomoly. But at a security conference, why WOULDN’T I be just like everyone else there?

Other things I hated:
Dan Kaminsky getting a pwnie. Black Hat overhyped his talk in a frenzy of media whoredom, then he got kicked in the balls by being awarded the most overhyped talk pwnie. He worked his ass off on this issue, did all the right things to try and protect people, and instead of earning the respect he deserved, he got made fun of.

Smells Like Teen Spirit transitioning to Saturday Night Fever. FAIL

French press sniffing creds

Snacktime crowds clogging the halls, making movement impossible

Talks that span 2 hours. I don’t want to commit 2 hours to one talk. C’mon people, tighten it up. There are too many interesting things to see to put all my eggs in one basket for 2 talks. By having a 2 hour talk you are not competing with 4 other tracks, you are competing with 8.


Not enough time or space to talk with everyone I wanted to. The size of Black Hat is a blessing and a curse. You see everyone in one place, where you might only see half as many people you want to at a smaller con. But everyone is circulating so there isn’t time for talking with any one person very much. There are a great many people I wish I’d had time to sit down and talk with more.

Labels: , , , , , , , , , ,

What I liked about Black Hat this year

THE TALKS!!
Dan Kaminsky’s It's The End of the Cache As We Know It. (come on, you know you can't help thinking 'And I Feel Fine' after reading that) Standing room only, Dan’s grandma’s session cookies, talk content, speaker energy, enthusiasm. I <3 Dan. If I could adopt a big brother, it would be Dan.

Bruce Potter’s talk on Net Flow analysis. Super interesting, well presented.

Mark Dowd and Alexander Sotirov’s talk on Bypassing Windows Vista Memory Protections. They’re wicked smaht.

LT. Col. Greg Conti’s talk on visual forensics analysis - I am a sucker for visual representation of any data...

Christopher Hoff's Four Horsemen of the Virtualizaton Security Apocolypse.

I know, my review of the talks is pretty light here, but I don't have to write a trip report for the general public so quitcherbitchen. If you're so interested, you should have gone to the talks yourself.

THE OTHER STUFF
Registration check in lines are sooooo much better than in years past, more lines, move faster, yay. But having a separate line to get your delegate bag is a bit inefficient for attendees.

Box lunch option. Now if only they’d offer a ‘no lunch’ ticket. I don’t even care if it costs the same as a ‘with lunch’ registration. I never eat at the con, whether it’s a box lunch or plated meal. I feel bad wasting the food.

Overall, compared to when I first started attending Black Hat many years ago, the con feels more professional. Talks start and end pretty much on time, I didn’t see any real AV difficulties, logistically things seemed pretty smooth. Awwww, Black Hat is growing up!

Lobster and crab dumpling things, sushi, and sliders at a vendor party. Best party food all week.

The conference continues to grow and mature. I’m excited to see that, big conferences are a great initiation ground for new security professionals who may not know about or understand yet the value of smaller cons like ShmooCon or Toorcon, and a great ‘reunion’ spot for people who may talk via IM/Twitter/Facebook/MySpace/IRC/email/whatever all the time but only see each other IRL a few times a year at cons. But the size of Black Hat is a blessing and a curse. You see everyone in one place, where you might only see half as many people you want to at a smaller con. But everyone is circulating so there isn’t time for talking with any one person very much.

Wall of Sheep. A DefCon staple, nice to see it at Black Hat too. Baaaaaaaaa.

Not really about Black Hat, but a Vegas thing: there is now one cab company that takes credit cards in Vegas. w00t. I hate carrying cash.

$32K raised for EFF between Black Hat and Defcon. nice.

Several people arranged hotel suite Rock Band parties in the evenings. That is awesome. !..!,

See y’all again in 2009. Wouldn’t miss it.

Labels: , , , , , , , , , ,

Thursday, November 01, 2007

updates. finally.

conference calendar updated, and the blogroll. I know, I've been ignoring you for a few months. But David Litchfield is blogging now. I figured that alone was worth a post.

Labels: , ,

Wednesday, May 23, 2007

w00t

Another new conference in the fold. WOOT, the Workshop On Offensive Technology is launching this summer in conjunction with USENIX. While WOOT sounds extremely cool and the advisory panel is made up of uber smart people, having six conferences on three continents in August makes for some serious competition for top speakers as well as attendee dollars. WOOT is invite only though, so they might win on leet factor.

Don't count Jeff Moss out though - looks like he is planning 8 (that's right, EIGHT) tracks at Black Hat Vegas this summer. So their cfp must be doing pretty well if they can project that much content with a straight face...

~Elphie

Labels: ,

Tuesday, April 10, 2007

Con Calendar updated

I took some time tonight to update the conference calendar - LOTS of interesting new stuff. IT Underground is going to Dublin... London is getting yet another confab that looks to have good potential, it will be interesting to see what overlap (if any) the Black and White Ball will have with EUSecWest and UnCon. BAD ELPHIE, I didn't get HITB Dubai on the list until after the event, my deepest apologies to the HITB crew (not that any of them read this, but still...) The third CONfidence happens in Krakow Poland in May. Perhaps most interesting is the new conference in Asia, VNSeCon in Ho Chi Minh City, Vietnam. VIET-freaking-Nam! That's awesome. We're everywhere.

When I have time I'm going to try to create a section for some of the smaller meet-up events like ChiSec, BeanSec, Atlanta's SIP, etc. But no time for that this week.

Did I miss an event? Let me know!

~Elphie

Labels: ,

Thursday, March 29, 2007

ShmooCon rawks!

ShmooCon 2007 is over, and what an awesome conference! There is just too much good stuff and not enough time. The talks were great, the networking in the halls was wonderful and usually led to deeper intellecutal discussions over coffee/lunch/dinner. The conference is well organized (well, a slight hiccup delayed registration a bit but not too bad overall) and as always, the parties were fun. Even the weather was fantastic. It is such a solid conference, I can't do justice to it in words. Suffice to say I'll be back again next year for sure. Snaps to the Shmoo Group for another great year.

~E

Labels: ,

Thursday, March 15, 2007

A message from your friends at the Institute of Self Determination

- Do you feel like you lack control over your schedule?
- Have you had to cancel things in your personal life with short notice due to last minute business travel?
- Are you burnt out on conferences?
- Have you delivered presentations to low priority audiences in the middle of nowhere?

If you answered yes to at least two of the questions above, you might be asking how this happened to you and what you can do about it. You might be hoping leet haxors broke into your scheduling application to send you off to Boise at a moment's notice - you can simply rebuild your box and do a better job defending it in the future. But unfortunately, you my friend are victim to something far more nefarious. You are pwned by PR.

Our experts at the Institute of Self Determination have developed several strategies to cope with situations like this. Many of our clients lack the ability to simply tell their PR department NO to that next business trip. They don't want to look like an ass or be the bad guy. Or maybe they are not in a power position to say no without losing their job. Here are our four most popular self-help programs:

1. Cloning - send your replicants out to do the speaking engagements you don't want to do. This has become more difficult since villainsupply.com went out of business. They were by far the most reputable of the Evil Villain cabals that thumbed their noses at political ramifications of scientific experiments on humans. Of course there are rumors that villainsupply has merely gone deeper underground to protect their plots for world domination. Unfortunately we cannot confirm or deny this rumor or we'd have to kill you later. Our clients have to find their own cloning firm, but once they do we'll help them train and store their replicants as well as deal with the psychological trauma of losing their sense of individuality.

2. Teflon - PR requests slide off you onto someone else. We can help you develop a strategy to find, mentor, and train a flock of lackeys to send off in your place the next time a travel request comes your way. Why be randomized yourself, when you can delegate that randomization to someone else?

3. White lies - the sick parent/pet excuse. While weak, sometimes it is just easier to feign personal obligations that require you to stay home. We can help you craft a believable story that isn't so complicated you screw it up and get caught. Note that this is just a temporary solution to the pwnership problem to buy you a reprieve.

4. Acceptance - the final stage of grieving. If none of the above options work for you, we can counsel you on ways to accept your PR biatch status. Lets face it, unless you use your spine, become utterly incompetent or quit your job, PR will keep pimping you out. It will be easier on you if you learn to accept your Media Whore situation and quit fighting it.

The Institute of Self Determination is accredited in multiple temporal dimensions, provides services worldwide, and offers a variety of payment plan options. Don't let your PR department push you around any more! Contact the Institute of Self Determination and start down the road towards a more self-determined life today!


++++++++++++++++

hee hee hee. This is for a friend. He knows who he is.

~Elphie

Labels: ,

Monday, March 05, 2007

On deck... Security Opus

Black Hat Fed and EUSecWest are done, so the next big con coming up is Security Opus. Though to be honest, everyone I know is talking about ShmooCon. The Security Opus speaker agenda is decent - you know anything with Window Snyder has to be rad - but as far as conferences go it just isn't as big or as affordable as Shmoo. The Shmoo schedule and speaker list is now posted (though I'm told there is at least one more talk that is going to be added) and it looks like a great con. As usual, I always plan to attend way more talks than I actually make it to. Should be hella fun. And I have to say that the Shmoo organizers are fracking geniuses. That's right, once again they are wise enough to schedule the first speakers at 10am. Thank you, ShmooCon organizers, for recognizing that no one attending ShmooCon goes to sleep at a 'reasonable' hour.

Don't have a ticket for ShmooCon? There were a few on eBay this morning...

~Elphie
unofficial ShmooCon fangirl

Labels: ,

Wednesday, February 28, 2007

Responsibility runs both ways

If you read Emergent Chaos (and if you don't, you need to add it to your reading list right now) you've already seen that the RFID talk Chris Paget was scheduled to deliver at Black Hat Federal is back on.

Apparently HID doesn't have a Webster's dictionary, because they now claim they didn't demand that the talk be pulled.

"HID Global did not threaten IOActive or Chris Paget, its Director of Research and Development, to stop its presentation at the Black Hat event being held in Washington, DC on Wednesday, February 28, 2007."


and

"Under no circumstance has HID asked IOActive or Mr. Paget to cancel their presentation. In fact, we were surprised by their decision to cancel the presentation and to attribute the cancellation to a threat from HID. This was not, and never was, HID’s position."


*cough* *cough* bullshit *cough*

You can read the entire letter HID sent here, but here are a couple snippets:

We understand … that you intend to publicly present and publish additional information about your spoofer at the Black Hat convention … We believe such presentation will subject you to further liability …

…hereby demand that you refrain from publishing any information at any public forum including the upcoming Black Hat convention…


that sounds like a demand/threat to me...

Anyway, this is all very interesting but it is distracting us from the real issue of responsibility. I personally believe that researchers have a responsibility to work with vendors to resolve security issues in a way that protects customers. But I also believe that vendors have a responsibility too, a responsibility to make sure that they are doing everything they can to stay on top of known vulnerabilities in their products, provide customers with workarounds and mitigations, and ultimately create more secure products. RFID vulnerabilities have been publicly known since 2005, Paget's presentation is not really NEW (even Jeff Moss calls it "largely a rehash of known issues, intended more as an introduction").

And remember, HID claims “cloning is simply not a credible threat”.

Long ago (in a galaxy far, far away) the only way to get vendors to fix security problems was to report them publicly and shame them into a fix. Today, vendors (most of them anyway) try to work with researchers to fix vulnerabilities and protect their customers. What keeps me up at night after events like this is the fear that more vendors will choose to ignore vulnerabilities and try to strong arm researchers into silence about the flaws in their products, and that will be used to further justify full disclosure. I don't want to live in a world where only way to get a vulnerability fixed is to drop it anonymously to a mailing list and hope the good guys fix it before the bad guys leverage it.

yearning for utopia,
~Elphie

Labels: , , ,

Monday, February 26, 2007

Black Hat Federal this week

If I were there, I'd definitely make a point of seeing Jose Nazario and Ollie Whitehouse. Both are delivering fairly new talks on the con circuit, and look like interesting stuff. If you catch either of the talks, let me know what you think?

Also, if you haven't heard already about the Chris Paget talk that has been withdrawn from the conference, go read this now. Then go make a donation to the ACLU for being the good guys.

Y'all know I'm a big supporter of responsible disclosure, but when I read things like this, I have to shake my head and wonder what the vendor is thinking.

"These systems are installed all over the place. It's not just HID, but lots of companies, and there hasn't been a problem. Now we've got a person who's saying let's get publicity for our company and show everyone how to do it, and it puts everyone at risk. Where's the sense of responsibility?" Carroll said.


Yes, where is the sense of responsibility? Such as HID's responsiblity for delivering on their promise of a security solution to customers? Does HID deserve an opportunity to work with researchers to fix their security problems and protect customers? Absolutely. But these vulnerabilities have been widely known for over a year, and until now have been pooh-poohed by HID.

She [Kathleen Carroll, a spokeswoman for HID's Government Relations group] said that the company has long been aware that its proximity cards are vulnerable to hacking but does not believe that the cards are as vulnerable as Paget suggests.

"For someone to be able to surreptitiously read a card, they'd have to get within two or three inches and get into the same plane as the card," Carroll said.

HID is also concerned that Paget's demonstration will popularize the vulnerabilities in its proximity cards and endanger its many customers.


You can't have it both ways. Either you don't take it seriously as something to fix (in which case a conference talk is no real threat), or you do take it seriously and would have developed some sort of strategy or plan to solve the problem. Make up your mind.

Asked why HID hasn't addressed the issue in more recent proximity card systems, after knowledge of RFID threats became common, Carroll said that doing so would cause "major upheaval" among customers.


oh yeah, because their customers are really just shopping for a bit of security theater; something that keeps the lamer criminals out. I'm sure they would rather have a physical security system that can be trivially compromised by a skilled/motivated attacker using publicly known vulns than do what it takes to actually have a secure physical security system...

bah. makes me cranky.

~Elphie

Labels: , , ,

Monday, February 05, 2007

Updated the con calendar...

okay, so I think I got most of the conferences for the first half of 2007 updated... DAMN there is a lot going on in February-March-April! You'll notice that I don't discriminate, small regional cons (notacon, carolinacon, outerz0ne) all the way up to big events (Black Hat, RSA) are listed. If you're a semi-professional con spaker with a fresh and interesting topic, you can stay pretty busy if you like to travel.

~Elphie

Labels:

Thursday, February 01, 2007

ShmooCon is uber1337

Didn't I tell you that ShmooCon would sell out quickly? Turns out that as I was posting this, they were just 60 seconds away from being sold out. Over 300 tickets gone in a little over 13 minutes, and this based purely on con reputation - the speaker list isn't even public yet! Congratulations to the ShmooCon team for putting together such a kick-ass event, I can't wait to see what they have in store for us this year.

~Elphie

Labels: ,

conferences...

ok, so I'll make an effort to do a better job keeping the conference calendar up to date in 2007. promise.

For those of you who don't already have tickets to ShmooCon in late March, you better get on the ball. The last lot went on sale about 15 minutes ago and I expect will sell out quickly. Naturally I didn't post this until I had my tickets purchased and confirmed. heh. See you there.

~Elphie

Labels: ,

Tuesday, June 13, 2006

Sex in Videogames Conference

Wish I'd known about the First Annual Sex in Videogames Conference ahead of time... I'd have taken some time off work to personally attend. Maybe next year since the conference agenda topics look pretty interesting from a sociological perspective.
The Sex in Video Games Conference: Exploring the Business of Digital Erotic Entertainment. This unique conference will focus on the design, development, and technology of sex in video games from a national as well as international perspective. In addition, this conference will also have a strong focus on business matchmaking and networking. During the conference's two day run, it will feature numerous lectures and keynotes, a machinima art show (erotic art and movies derived from video games) as well as panel discussions with leaders in video game and adult video game development.

If, like me, you didn't attend this conference, Wired has an interesting writeup on one of the panels and the focus on how to make pornographic videogames into a viable business, what some of the barriers are to success (porn is usually low investment/high profit, while game development is high investment, pre-existing notions of what is adult entertainment) etc.

The Friday keynote sounds like it might have been pretty interesting.

Sheri Graner Ray has been announced as the keynote for Friday, June 9.

Ms. Graner Ray is an accomplished game designer with 16 years experience in the video game industry and is the author of “Gender Inclusive Game Design: Expanding the Market.” She will be speaking on how to make adult games that appeal to women, using her research on creating games that appeal to women to specifically discuss what women would want to see within the adult game space.

According to Brenda Brathwaite, Game Designer and Chairperson of the Sex in Video Games Conference, “everyone knows Sheri as the expert on gender issues in video games. I'm really looking forward to how she applies that body of knowledge to adult games. The same lessons she teaches mainstream developers will apply to adult content developers, too. Who doesn't want a bigger audience?”

Suzanne Freyjadis-Chuberka, President of Evergreen Events, agrees that, “Sheri Graner Ray is a well respected authority on the issues of what attracts women to games and her insight into this area will be invaluable for developers of adult oriented games."


IMO one of the main reasons to have a diverse workforce in the field of software development (not just sex games but any application) is so you are designing and developing products that will appeal to and be usable by a diverse customer base. It isn't about affirmative action, it is about creating the best product for the broadest audience.

~Elphie

Labels: ,

Saturday, June 03, 2006

Black Hat Vegas Speaker Schedule Posted!!

Check it out - looks like an awesome lineup. Very impressive...

~Elphie

Labels: ,

Tuesday, May 09, 2006

content only matters if the audience is listening

I have an office job and I attend a lot of conferences. Those two things mean that I end up seeing a lot of presentations. A few are very good. Some are very bad and lead many to the belief that slideware is evil. Most are mediocre. So I’m only going to say this once: if you are giving a presentation you owe it to your audience to stop hiding behind the ‘I’m an engineering geek who can’t make a slick slide deck or speak to people engagingly’ excuse. I’m not saying you need to go get an MBA and have m4d ppt skillz, but for gods sake don’t read the damn slides to me. I am capable of reading on my own, and if I feel like I could have given your presentation for you with the deck and 20 minutes prep time, then you are wasting the time of your audience and insulting their intelligence.

Now I’m not claiming to be a slidedeck guru, but here are a couple links to things I’ve found useful, and suspect most presenters could learn from.

Presentation Zen (humorous AND educational, a virtual treasure trove)

Making a (Power)Point of Not Being Tiresome

And to lighten things up a bit more…

The Many Uses of Power Point

http://www.theregister.co.uk/2006/01/26/public_speaking_advice/

yeaaaah, that last one, I’m not sure what to call it so the URL will have to do. But trust me when I say it is pretty damn funny, and advice everyone I know would love to take regardless of whether they do any public speaking or not. :)

~Elphie

Labels: ,

Thursday, April 13, 2006

Layer1 this weekend

The third of the badass con trifecta in the lower 48, Layer1 is in Pasadena CA this weekend. A solid quality (and reasonably priced, thanks Noid & crew) con like ToorCon and ShmooCon, Layer1 has some great speakers lined up for attendees. The talks by Billy Hoffman, David 'H1kari' Hulton & Johnny Cache, Strom Carlson, and Luiz Eduardo Dos Santos top my list of stuff to see...

~Elphie

Labels: ,

Friday, April 07, 2006

I'd like to buy an 0, HOPE6, BSOD, Captain Obvious and media whoring...

Let's start with CanSecWest, and the vulnerability commercialization panel they had on Wednesday. There was much spirited debate but no end agreement between the parties... takes me back to ShmooCon and the BOF panel on training... but I digress.

In the press, Michael Sutton is quoted as saying that vendors need to pay for vulns, and later in the article a customer states he expects vendors to pay for vulns as well.
"The only economic model that does not make sense to me is the vendor's," Sutton said. "They get to know about a vulnerabilities ahead of time, but they are unwilling to pay for them."
Let's blithely assume for a moment that vendors and researchers could agree on the dollar value of a vulnerability (ROTFLMAO). There is still a big problem with the 'buying vulnerabilities protects customers' argument: if Oracle buys a vuln from David Litchfield, Oracle now owns the vuln. That means that they don't EVER have to fix it if they don't want to. I'm not just picking on Oracle - this is true of ANY vendor. They wouldn't be buying vulns, they'd be buying silence. And that would just piss everyone off - hell, that's why full disclosure practices started to begin with - the only way to get a vendor to fix a security bug was to publicly shame them with it. So I wholeheartedly disagree that vendors buying bugs would make me as a computer user any safer.

I have no problem with reputable third parties buying vulnerabilities and working with vendors to protect customers. I'll admit I think Tipping Point's ZDI program does a better job of that than iDefense's VCP program simply because iDefense's customers leak their confidential advisories all the time before patches are available. But these programs do play an important role in the security ecosystem that benefit customers, researchers, and vendors.

Other stuff:

Dates for HOPE number 6 have been announced - July 21-23, just a week or so before Black Hat Vegas. Of course I've added HOPE to the upcoming cons list...

Check this out - I've heard most people aren't having much trouble with Apple's Boot Camp beta, but this guy managed to get the legendary Blue Screen of Death. I haven't seen that on one of my boxes in over five years. Wow. Comments on the blog suggest that this was a known bug in the beta relating to iSight... doh!

Adam Shostack makes some interesting observations on recent media regarding rootkits on the Emergent Chaos blog. Yeah, he is right, this is a Captain Obvious type of situation where everyone in the security space already knew that rootkits were a big dangerous problem. But I think (or at least hope) the point of the Microsoft presentation at InfoSecWorld in FL that spurred the eweek article was to educate less security savvy customers about threats we are facing today and give guidance on how to deal with them. Adam also mentions the extremely cool work being done by John Heasman of NGS on ACPI BIOS rootkits that was presented not only at Black Hat Federal, but Black Hat Amsterdam and will again be presented in May at the Computer and Enterprise Investigations Conference. Right now it is super cutting edge stuff - so maybe if John gives the talk often enough, more people will pay attention (and by someone I don't mean the bad guys). After giving the talk at Black Hat Federal in January, Rob Lemos ran a story which quoted Greg Hoglund as saying:
"It is going to be about one month before malware comes out to take advantage of this," said Greg Hoglund, CEO of reverse engineering firm HBGary and editor of Rootkit.com. "This is so easy to do. You have widely available tools, free compilers for the ACPI language, and high-level languages to write the code in."

It would be a shame if the security industry didn't pay attention in January to John's early warning and is surprised when malicious bios rootkits emerge.

And since I've mentioned CEIC, I may as well throw a shameless plug out for Vinnie Liu's talk on Defeating Forensic Analysis (with his business partner Patrick Stach) on Thursday May 4 at the con. Vinnie is a very smart guy - if you are attending CEIC, I'd definitely attend their session. I'm such a groupie I'd go to NV just to see this talk, but I think that would violate the restraining order...

~Elphie

Labels: , , , , , , , , , ,

Wednesday, March 29, 2006

CanSecWest is coming up...

If you haven't checked out CanSecWest yet, I highly recommend it. It is next weekend in Vancouver BC so time is short to make your plans, but the speaker list is solid and the crowd is always high on the clueful meter if you can make it.

And if you attend cons just to party your ass off, well, you can do that at CSW too. My fave DJ, Keith, will be tearing things up Wednesday April 5 at 686. If you are skipping CSW but attending NotACon (after all, Cleveland rocks I'm told) he'll be there too on April 7-8.

~Elphie

Labels: , ,