SlideShare a Scribd company logo
1 of 41
Download to read offline
Open solutions, smarter people




                           Security

   You are also part of the game




This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
Open solutions, smarter people




                        Who is that guy?
•   Bert Desmet
•   23 years old
•   Fedora – Ambassador, mentor, packager
•   Loadays – Co organizer
•   Numius – System Engineer, Consultant
•   Devnox – Developer, System Engineer
Open solutions, smarter people




                         Today's topics
•   I'm a good hacker.
•   Why I love USB sticks.
•   Remember your password?
•   Shhhhhhht!
Open solutions, smarter people




I am a good hacker.
Open solutions, smarter people




No tech hacking?
Open solutions, smarter people




Shoulder surfing
Open solutions, smarter people




Dumpster diving
Open solutions, smarter people




Social engineering
Open solutions, smarter people




Taking pictures
Open solutions, smarter people




Why I love USB sticks.
Open solutions, smarter people




They are easy
Open solutions, smarter people




And small
Open solutions, smarter people




              They are easily..
• Forgotten
• Stolen
Open solutions, smarter people




                   Some thoughts about it
•   Encrypt your sensitive data
•   Never put passwords on your system
•   Use the intranet
•   Never leave your portable gear alone
•   Never forget your gear
Open solutions, smarter people




                             Some statistics
• 53% of UK workers lost portable devices
   – >50% at a drinking venue
       • Taxis and public transport
• 1 lost data record cost more than $187
   – 70% indirect cost
       •   Lost costumers
Open solutions, smarter people




Remember your password?
Open solutions, smarter people




                How to choose a password
•   Avoid using dictionary words
•   Use special characters and numbers
•   Change your password every month
•   Blah blah blah
Open solutions, smarter people




                How to choose a password
•   Avoid using dictionary words
•   Use special characters and numbers
•   Change your password every month
•   Blah blah blah
Open solutions, smarter people




                          Entropy
• H : Entropy
• N : Possible symbols
• Length of string




                         H= L∗log2 N
Open solutions, smarter people




                          Example time!
• This is.obviously a.bad passw0rd:-(
    – L : 35
    – W : 94
    – H : ±230
• PrXyc.N(n4k77#L!eVdAfp9
    – L : 23
    – W : 94
    – H : ±151
Open solutions, smarter people




                  Time to crack a password
• [[Guesses before string is found = 2H]]
• This is.obviously a.bad passw0rd:-(
    – 2230 = 1.72543659 × 1069
    – 1000 guesses /s = 5.5 x 1058 years
• PrXyc.N(n4k77#L!eVdAfp9
    – 2151 = 2.85449539 × 1045
    – 1000 guesses /s = 9 × 1034 years
Open solutions, smarter people




Password Strenght
Open solutions, smarter people




                             Lastpass
• Fully encrypted
• Generate extremely hard passwords
• Choose a good master password!
Open solutions, smarter people




                            Some tips
• Never store passwords on pc
• Never use autologin
Open solutions, smarter people




Shhhhhhhht!
Open solutions, smarter people




I want you to shut up!
Open solutions, smarter people




               Security through obscurity
• Don't tell anyone
• Security based on secrecy
Open solutions, smarter people




                     Kerckhoffs' doctrine
• Security can't depend on secrecy
Open solutions, smarter people




                           Reality
• There are always leaks
    – By accident
    – Deliberately
• Try to keep 'secrets'
Open solutions, smarter people




Wait! There is more!
Open solutions, smarter people




In a perfect world..
Open solutions, smarter people




There is always a hole.
Open solutions, smarter people




I like onions
Open solutions, smarter people




                      Multi Level Security
• Multiple systems
• Building fort Knox
• You are the first line of defense
Open solutions, smarter people




Extra! Extra!
Open solutions, smarter people




Something you have..
Open solutions, smarter people




Yubikey
Open solutions, smarter people




  I preach.
And I practice.
Open solutions, smarter people




                                         Questions?
• Bert Desmet
• Security, you are also part of the game




•   Mail: Bert@devnox.eu
•   Twitter: @bdesmet_
•   Website: http://blog.bdesmet.be
•   Website: http://www.devnox.eu
•   This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
Open solutions, smarter people




                                                         Sources
•   Chess game: http://www.flickr.com/photos/seeminglee/1479932683/
•   Closed vault: http://www.flickr.com/photos/mstyne/3654056683/
•   Open vault: http://www.flickr.com/photos/spotsgot/156025944/
•   Onion: http://www.flickr.com/photos/inferis/107293622/
•   Laptop + usb stick: http://www.flickr.com/photos/wstryder/2780310027/
•   New York Public Library: http://www.flickr.com/photos/paul_lowry/2616820493/
•   Statistics on loosing gear: http://www.securestix.com/bad_news.php
•   Shoulder surfing: http://www.flickr.com/photos/bonzoesc/209474964/
•   Dumpster: http://www.flickr.com/photos/urbanjacksonville/1803065217/
•   Telephone call: http://www.flickr.com/photos/lst1984/994531885/
•   Taking pictures: http://www.flickr.com/photos/glenpooh/708845839/
•   Xkcd joke: http://xkcd.com/936/
•   Shut up: http://www.flickr.com/photos/lorenia/934705558/
•   3way handhake: http://media.photobucket.com/image/3%20way%20handshake/Haley_Bug/Mission%20Trip%20Choir%20Tour%202006/100_0087.jpg?o=1
•   Yubikey: http://www.flickr.com/photos/thofle/3206443137/
•   Special thanks to: Johnny Long
Open solutions, smarter people

More Related Content

Viewers also liked

догадина&белова1
догадина&белова1догадина&белова1
догадина&белова1guestfb2102
 
Boeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case studyBoeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case studyMuthu Kumaar Thangavelu
 
SESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao AndroidSESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao AndroidRafael Sakurai
 
Social Training Project for Merchandisers
Social Training Project for MerchandisersSocial Training Project for Merchandisers
Social Training Project for MerchandisersRussel C. Arida
 
Semantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical ReportSemantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical ReportMuthu Kumaar Thangavelu
 
Why You Should Partner With Colonial Life
Why You Should Partner With Colonial LifeWhy You Should Partner With Colonial Life
Why You Should Partner With Colonial Lifedonnadwyer
 
Measures of corporate performance
Measures of corporate performanceMeasures of corporate performance
Measures of corporate performanceSamahAdra
 
Bp business and information strategy alignment
Bp   business and information strategy alignmentBp   business and information strategy alignment
Bp business and information strategy alignmentMuthu Kumaar Thangavelu
 

Viewers also liked (10)

догадина&белова1
догадина&белова1догадина&белова1
догадина&белова1
 
Boeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case studyBoeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case study
 
SESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao AndroidSESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao Android
 
Social Training Project for Merchandisers
Social Training Project for MerchandisersSocial Training Project for Merchandisers
Social Training Project for Merchandisers
 
Semantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical ReportSemantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical Report
 
Why You Should Partner With Colonial Life
Why You Should Partner With Colonial LifeWhy You Should Partner With Colonial Life
Why You Should Partner With Colonial Life
 
Buckmann labs KM case study
Buckmann labs KM case studyBuckmann labs KM case study
Buckmann labs KM case study
 
Human Capital Management
Human Capital ManagementHuman Capital Management
Human Capital Management
 
Measures of corporate performance
Measures of corporate performanceMeasures of corporate performance
Measures of corporate performance
 
Bp business and information strategy alignment
Bp   business and information strategy alignmentBp   business and information strategy alignment
Bp business and information strategy alignment
 

Similar to Security, you are also part of the game

Preservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanitiesPreservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanitiesDorothea Salo
 
Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)Ellen Grove
 
Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)Frank Garofalo
 
27 Ways To Be A Better Developer
27 Ways To Be A Better Developer27 Ways To Be A Better Developer
27 Ways To Be A Better DeveloperLorna Mitchell
 
27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)Ivo Jansch
 
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovationImmerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovationPaulJervisHeath
 
introduction.pptx
introduction.pptxintroduction.pptx
introduction.pptxsecurework
 
2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdf2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdfTony Khánh
 
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...Duncan Campbell
 
Low Cost Assistive Technology Solutions
Low Cost Assistive Technology SolutionsLow Cost Assistive Technology Solutions
Low Cost Assistive Technology Solutionswill wade
 
Dark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 CryptographyDark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 CryptographyMarcus Leaning
 
Fall 2011 Parent Tech Conference
Fall 2011 Parent Tech ConferenceFall 2011 Parent Tech Conference
Fall 2011 Parent Tech Conferencetim wojcik
 
Dark Patterns in UX
Dark Patterns in UXDark Patterns in UX
Dark Patterns in UXNomensa
 
Don't let assumptions kill good ideas
Don't let assumptions kill good ideasDon't let assumptions kill good ideas
Don't let assumptions kill good ideasLauren Liss
 
Solving Problems with Web 2.0
Solving Problems with Web 2.0Solving Problems with Web 2.0
Solving Problems with Web 2.0Dorothea Salo
 

Similar to Security, you are also part of the game (20)

So i got an Arduino now what
So i got an Arduino now whatSo i got an Arduino now what
So i got an Arduino now what
 
Preservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanitiesPreservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanities
 
Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)
 
Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)
 
27 Ways To Be A Better Developer
27 Ways To Be A Better Developer27 Ways To Be A Better Developer
27 Ways To Be A Better Developer
 
27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)
 
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovationImmerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovation
 
C1 into to ai
C1 into to aiC1 into to ai
C1 into to ai
 
introduction.pptx
introduction.pptxintroduction.pptx
introduction.pptx
 
The art of AI Art
The art of AI ArtThe art of AI Art
The art of AI Art
 
2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdf2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdf
 
Artificial intelligence
Artificial intelligenceArtificial intelligence
Artificial intelligence
 
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
 
Low Cost Assistive Technology Solutions
Low Cost Assistive Technology SolutionsLow Cost Assistive Technology Solutions
Low Cost Assistive Technology Solutions
 
Dark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 CryptographyDark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 Cryptography
 
Fall 2011 Parent Tech Conference
Fall 2011 Parent Tech ConferenceFall 2011 Parent Tech Conference
Fall 2011 Parent Tech Conference
 
Dark Patterns in UX
Dark Patterns in UXDark Patterns in UX
Dark Patterns in UX
 
Agile tricks
Agile tricksAgile tricks
Agile tricks
 
Don't let assumptions kill good ideas
Don't let assumptions kill good ideasDon't let assumptions kill good ideas
Don't let assumptions kill good ideas
 
Solving Problems with Web 2.0
Solving Problems with Web 2.0Solving Problems with Web 2.0
Solving Problems with Web 2.0
 

Recently uploaded

Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CVKhem
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024Results
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreternaman860154
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...Martijn de Jong
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking MenDelhi Call girls
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptxHampshireHUG
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...apidays
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonAnna Loughnan Colquhoun
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountPuma Security, LLC
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsEnterprise Knowledge
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processorsdebabhi2
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationMichael W. Hawkins
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsJoaquim Jorge
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUK Journal
 

Recently uploaded (20)

Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024A Call to Action for Generative AI in 2024
A Call to Action for Generative AI in 2024
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Presentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreterPresentation on how to chat with PDF using ChatGPT code interpreter
Presentation on how to chat with PDF using ChatGPT code interpreter
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men08448380779 Call Girls In Greater Kailash - I Women Seeking Men
08448380779 Call Girls In Greater Kailash - I Women Seeking Men
 
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
04-2024-HHUG-Sales-and-Marketing-Alignment.pptx
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Breaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path MountBreaking the Kubernetes Kill Chain: Host Path Mount
Breaking the Kubernetes Kill Chain: Host Path Mount
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
IAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI SolutionsIAC 2024 - IA Fast Track to Search Focused AI Solutions
IAC 2024 - IA Fast Track to Search Focused AI Solutions
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 

Security, you are also part of the game

  • 1. Open solutions, smarter people Security You are also part of the game This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
  • 2. Open solutions, smarter people Who is that guy? • Bert Desmet • 23 years old • Fedora – Ambassador, mentor, packager • Loadays – Co organizer • Numius – System Engineer, Consultant • Devnox – Developer, System Engineer
  • 3. Open solutions, smarter people Today's topics • I'm a good hacker. • Why I love USB sticks. • Remember your password? • Shhhhhhht!
  • 4. Open solutions, smarter people I am a good hacker.
  • 5. Open solutions, smarter people No tech hacking?
  • 6. Open solutions, smarter people Shoulder surfing
  • 7. Open solutions, smarter people Dumpster diving
  • 8. Open solutions, smarter people Social engineering
  • 9. Open solutions, smarter people Taking pictures
  • 10. Open solutions, smarter people Why I love USB sticks.
  • 11. Open solutions, smarter people They are easy
  • 12. Open solutions, smarter people And small
  • 13. Open solutions, smarter people They are easily.. • Forgotten • Stolen
  • 14. Open solutions, smarter people Some thoughts about it • Encrypt your sensitive data • Never put passwords on your system • Use the intranet • Never leave your portable gear alone • Never forget your gear
  • 15. Open solutions, smarter people Some statistics • 53% of UK workers lost portable devices – >50% at a drinking venue • Taxis and public transport • 1 lost data record cost more than $187 – 70% indirect cost • Lost costumers
  • 16. Open solutions, smarter people Remember your password?
  • 17. Open solutions, smarter people How to choose a password • Avoid using dictionary words • Use special characters and numbers • Change your password every month • Blah blah blah
  • 18. Open solutions, smarter people How to choose a password • Avoid using dictionary words • Use special characters and numbers • Change your password every month • Blah blah blah
  • 19. Open solutions, smarter people Entropy • H : Entropy • N : Possible symbols • Length of string H= L∗log2 N
  • 20. Open solutions, smarter people Example time! • This is.obviously a.bad passw0rd:-( – L : 35 – W : 94 – H : ±230 • PrXyc.N(n4k77#L!eVdAfp9 – L : 23 – W : 94 – H : ±151
  • 21. Open solutions, smarter people Time to crack a password • [[Guesses before string is found = 2H]] • This is.obviously a.bad passw0rd:-( – 2230 = 1.72543659 × 1069 – 1000 guesses /s = 5.5 x 1058 years • PrXyc.N(n4k77#L!eVdAfp9 – 2151 = 2.85449539 × 1045 – 1000 guesses /s = 9 × 1034 years
  • 22. Open solutions, smarter people Password Strenght
  • 23. Open solutions, smarter people Lastpass • Fully encrypted • Generate extremely hard passwords • Choose a good master password!
  • 24. Open solutions, smarter people Some tips • Never store passwords on pc • Never use autologin
  • 25. Open solutions, smarter people Shhhhhhhht!
  • 26. Open solutions, smarter people I want you to shut up!
  • 27. Open solutions, smarter people Security through obscurity • Don't tell anyone • Security based on secrecy
  • 28. Open solutions, smarter people Kerckhoffs' doctrine • Security can't depend on secrecy
  • 29. Open solutions, smarter people Reality • There are always leaks – By accident – Deliberately • Try to keep 'secrets'
  • 30. Open solutions, smarter people Wait! There is more!
  • 31. Open solutions, smarter people In a perfect world..
  • 32. Open solutions, smarter people There is always a hole.
  • 33. Open solutions, smarter people I like onions
  • 34. Open solutions, smarter people Multi Level Security • Multiple systems • Building fort Knox • You are the first line of defense
  • 35. Open solutions, smarter people Extra! Extra!
  • 36. Open solutions, smarter people Something you have..
  • 37. Open solutions, smarter people Yubikey
  • 38. Open solutions, smarter people I preach. And I practice.
  • 39. Open solutions, smarter people Questions? • Bert Desmet • Security, you are also part of the game • Mail: Bert@devnox.eu • Twitter: @bdesmet_ • Website: http://blog.bdesmet.be • Website: http://www.devnox.eu • This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
  • 40. Open solutions, smarter people Sources • Chess game: http://www.flickr.com/photos/seeminglee/1479932683/ • Closed vault: http://www.flickr.com/photos/mstyne/3654056683/ • Open vault: http://www.flickr.com/photos/spotsgot/156025944/ • Onion: http://www.flickr.com/photos/inferis/107293622/ • Laptop + usb stick: http://www.flickr.com/photos/wstryder/2780310027/ • New York Public Library: http://www.flickr.com/photos/paul_lowry/2616820493/ • Statistics on loosing gear: http://www.securestix.com/bad_news.php • Shoulder surfing: http://www.flickr.com/photos/bonzoesc/209474964/ • Dumpster: http://www.flickr.com/photos/urbanjacksonville/1803065217/ • Telephone call: http://www.flickr.com/photos/lst1984/994531885/ • Taking pictures: http://www.flickr.com/photos/glenpooh/708845839/ • Xkcd joke: http://xkcd.com/936/ • Shut up: http://www.flickr.com/photos/lorenia/934705558/ • 3way handhake: http://media.photobucket.com/image/3%20way%20handshake/Haley_Bug/Mission%20Trip%20Choir%20Tour%202006/100_0087.jpg?o=1 • Yubikey: http://www.flickr.com/photos/thofle/3206443137/ • Special thanks to: Johnny Long