SlideShare a Scribd company logo
1 of 41
Download to read offline
Open solutions, smarter people




                           Security

   You are also part of the game




This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
Open solutions, smarter people




                        Who is that guy?
•   Bert Desmet
•   23 years old
•   Fedora – Ambassador, mentor, packager
•   Loadays – Co organizer
•   Numius – System Engineer, Consultant
•   Devnox – Developer, System Engineer
Open solutions, smarter people




                         Today's topics
•   I'm a good hacker.
•   Why I love USB sticks.
•   Remember your password?
•   Shhhhhhht!
Open solutions, smarter people




I am a good hacker.
Open solutions, smarter people




No tech hacking?
Open solutions, smarter people




Shoulder surfing
Open solutions, smarter people




Dumpster diving
Open solutions, smarter people




Social engineering
Open solutions, smarter people




Taking pictures
Open solutions, smarter people




Why I love USB sticks.
Open solutions, smarter people




They are easy
Open solutions, smarter people




And small
Open solutions, smarter people




              They are easily..
• Forgotten
• Stolen
Open solutions, smarter people




                   Some thoughts about it
•   Encrypt your sensitive data
•   Never put passwords on your system
•   Use the intranet
•   Never leave your portable gear alone
•   Never forget your gear
Open solutions, smarter people




                             Some statistics
• 53% of UK workers lost portable devices
   – >50% at a drinking venue
       • Taxis and public transport
• 1 lost data record cost more than $187
   – 70% indirect cost
       •   Lost costumers
Open solutions, smarter people




Remember your password?
Open solutions, smarter people




                How to choose a password
•   Avoid using dictionary words
•   Use special characters and numbers
•   Change your password every month
•   Blah blah blah
Open solutions, smarter people




                How to choose a password
•   Avoid using dictionary words
•   Use special characters and numbers
•   Change your password every month
•   Blah blah blah
Open solutions, smarter people




                          Entropy
• H : Entropy
• N : Possible symbols
• Length of string




                         H= L∗log2 N
Open solutions, smarter people




                          Example time!
• This is.obviously a.bad passw0rd:-(
    – L : 35
    – W : 94
    – H : ±230
• PrXyc.N(n4k77#L!eVdAfp9
    – L : 23
    – W : 94
    – H : ±151
Open solutions, smarter people




                  Time to crack a password
• [[Guesses before string is found = 2H]]
• This is.obviously a.bad passw0rd:-(
    – 2230 = 1.72543659 × 1069
    – 1000 guesses /s = 5.5 x 1058 years
• PrXyc.N(n4k77#L!eVdAfp9
    – 2151 = 2.85449539 × 1045
    – 1000 guesses /s = 9 × 1034 years
Open solutions, smarter people




Password Strenght
Open solutions, smarter people




                             Lastpass
• Fully encrypted
• Generate extremely hard passwords
• Choose a good master password!
Open solutions, smarter people




                            Some tips
• Never store passwords on pc
• Never use autologin
Open solutions, smarter people




Shhhhhhhht!
Open solutions, smarter people




I want you to shut up!
Open solutions, smarter people




               Security through obscurity
• Don't tell anyone
• Security based on secrecy
Open solutions, smarter people




                     Kerckhoffs' doctrine
• Security can't depend on secrecy
Open solutions, smarter people




                           Reality
• There are always leaks
    – By accident
    – Deliberately
• Try to keep 'secrets'
Open solutions, smarter people




Wait! There is more!
Open solutions, smarter people




In a perfect world..
Open solutions, smarter people




There is always a hole.
Open solutions, smarter people




I like onions
Open solutions, smarter people




                      Multi Level Security
• Multiple systems
• Building fort Knox
• You are the first line of defense
Open solutions, smarter people




Extra! Extra!
Open solutions, smarter people




Something you have..
Open solutions, smarter people




Yubikey
Open solutions, smarter people




  I preach.
And I practice.
Open solutions, smarter people




                                         Questions?
• Bert Desmet
• Security, you are also part of the game




•   Mail: Bert@devnox.eu
•   Twitter: @bdesmet_
•   Website: http://blog.bdesmet.be
•   Website: http://www.devnox.eu
•   This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
Open solutions, smarter people




                                                         Sources
•   Chess game: http://www.flickr.com/photos/seeminglee/1479932683/
•   Closed vault: http://www.flickr.com/photos/mstyne/3654056683/
•   Open vault: http://www.flickr.com/photos/spotsgot/156025944/
•   Onion: http://www.flickr.com/photos/inferis/107293622/
•   Laptop + usb stick: http://www.flickr.com/photos/wstryder/2780310027/
•   New York Public Library: http://www.flickr.com/photos/paul_lowry/2616820493/
•   Statistics on loosing gear: http://www.securestix.com/bad_news.php
•   Shoulder surfing: http://www.flickr.com/photos/bonzoesc/209474964/
•   Dumpster: http://www.flickr.com/photos/urbanjacksonville/1803065217/
•   Telephone call: http://www.flickr.com/photos/lst1984/994531885/
•   Taking pictures: http://www.flickr.com/photos/glenpooh/708845839/
•   Xkcd joke: http://xkcd.com/936/
•   Shut up: http://www.flickr.com/photos/lorenia/934705558/
•   3way handhake: http://media.photobucket.com/image/3%20way%20handshake/Haley_Bug/Mission%20Trip%20Choir%20Tour%202006/100_0087.jpg?o=1
•   Yubikey: http://www.flickr.com/photos/thofle/3206443137/
•   Special thanks to: Johnny Long
Open solutions, smarter people

More Related Content

Viewers also liked

догадина&белова1
догадина&белова1догадина&белова1
догадина&белова1guestfb2102
 
Boeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case studyBoeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case studyMuthu Kumaar Thangavelu
 
SESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao AndroidSESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao AndroidRafael Sakurai
 
Social Training Project for Merchandisers
Social Training Project for MerchandisersSocial Training Project for Merchandisers
Social Training Project for MerchandisersRussel C. Arida
 
Semantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical ReportSemantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical ReportMuthu Kumaar Thangavelu
 
Why You Should Partner With Colonial Life
Why You Should Partner With Colonial LifeWhy You Should Partner With Colonial Life
Why You Should Partner With Colonial Lifedonnadwyer
 
Measures of corporate performance
Measures of corporate performanceMeasures of corporate performance
Measures of corporate performanceSamahAdra
 
Bp business and information strategy alignment
Bp   business and information strategy alignmentBp   business and information strategy alignment
Bp business and information strategy alignmentMuthu Kumaar Thangavelu
 

Viewers also liked (10)

догадина&белова1
догадина&белова1догадина&белова1
догадина&белова1
 
Boeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case studyBoeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case study
 
SESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao AndroidSESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao Android
 
Social Training Project for Merchandisers
Social Training Project for MerchandisersSocial Training Project for Merchandisers
Social Training Project for Merchandisers
 
Semantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical ReportSemantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical Report
 
Why You Should Partner With Colonial Life
Why You Should Partner With Colonial LifeWhy You Should Partner With Colonial Life
Why You Should Partner With Colonial Life
 
Buckmann labs KM case study
Buckmann labs KM case studyBuckmann labs KM case study
Buckmann labs KM case study
 
Human Capital Management
Human Capital ManagementHuman Capital Management
Human Capital Management
 
Measures of corporate performance
Measures of corporate performanceMeasures of corporate performance
Measures of corporate performance
 
Bp business and information strategy alignment
Bp   business and information strategy alignmentBp   business and information strategy alignment
Bp business and information strategy alignment
 

Similar to Security, you are also part of the game

Preservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanitiesPreservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanitiesDorothea Salo
 
Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)Ellen Grove
 
Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)Frank Garofalo
 
27 Ways To Be A Better Developer
27 Ways To Be A Better Developer27 Ways To Be A Better Developer
27 Ways To Be A Better DeveloperLorna Mitchell
 
27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)Ivo Jansch
 
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovationImmerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovationPaulJervisHeath
 
introduction.pptx
introduction.pptxintroduction.pptx
introduction.pptxsecurework
 
2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdf2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdfTony Khánh
 
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...Duncan Campbell
 
Low Cost Assistive Technology Solutions
Low Cost Assistive Technology SolutionsLow Cost Assistive Technology Solutions
Low Cost Assistive Technology Solutionswill wade
 
Dark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 CryptographyDark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 CryptographyMarcus Leaning
 
Fall 2011 Parent Tech Conference
Fall 2011 Parent Tech ConferenceFall 2011 Parent Tech Conference
Fall 2011 Parent Tech Conferencetim wojcik
 
Dark Patterns in UX
Dark Patterns in UXDark Patterns in UX
Dark Patterns in UXNomensa
 
Don't let assumptions kill good ideas
Don't let assumptions kill good ideasDon't let assumptions kill good ideas
Don't let assumptions kill good ideasLauren Liss
 
Solving Problems with Web 2.0
Solving Problems with Web 2.0Solving Problems with Web 2.0
Solving Problems with Web 2.0Dorothea Salo
 

Similar to Security, you are also part of the game (20)

So i got an Arduino now what
So i got an Arduino now whatSo i got an Arduino now what
So i got an Arduino now what
 
Preservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanitiesPreservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanities
 
Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)
 
Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)
 
27 Ways To Be A Better Developer
27 Ways To Be A Better Developer27 Ways To Be A Better Developer
27 Ways To Be A Better Developer
 
27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)
 
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovationImmerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovation
 
C1 into to ai
C1 into to aiC1 into to ai
C1 into to ai
 
introduction.pptx
introduction.pptxintroduction.pptx
introduction.pptx
 
The art of AI Art
The art of AI ArtThe art of AI Art
The art of AI Art
 
2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdf2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdf
 
Artificial intelligence
Artificial intelligenceArtificial intelligence
Artificial intelligence
 
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
 
Low Cost Assistive Technology Solutions
Low Cost Assistive Technology SolutionsLow Cost Assistive Technology Solutions
Low Cost Assistive Technology Solutions
 
Dark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 CryptographyDark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 Cryptography
 
Fall 2011 Parent Tech Conference
Fall 2011 Parent Tech ConferenceFall 2011 Parent Tech Conference
Fall 2011 Parent Tech Conference
 
Dark Patterns in UX
Dark Patterns in UXDark Patterns in UX
Dark Patterns in UX
 
Agile tricks
Agile tricksAgile tricks
Agile tricks
 
Don't let assumptions kill good ideas
Don't let assumptions kill good ideasDon't let assumptions kill good ideas
Don't let assumptions kill good ideas
 
Solving Problems with Web 2.0
Solving Problems with Web 2.0Solving Problems with Web 2.0
Solving Problems with Web 2.0
 

Recently uploaded

Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfOverkill Security
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamUiPathCommunity
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxRustici Software
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024The Digital Insurer
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerThousandEyes
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...apidays
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsNanddeep Nachan
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfOverkill Security
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProduct Anonymous
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfsudhanshuwaghmare1
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesrafiqahmad00786416
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKJago de Vreede
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Angeliki Cooney
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024The Digital Insurer
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAndrey Devyatkin
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024The Digital Insurer
 

Recently uploaded (20)

Cyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdfCyberprint. Dark Pink Apt Group [EN].pdf
Cyberprint. Dark Pink Apt Group [EN].pdf
 
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 AmsterdamDEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
DEV meet-up UiPath Document Understanding May 7 2024 Amsterdam
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024AXA XL - Insurer Innovation Award Americas 2024
AXA XL - Insurer Innovation Award Americas 2024
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
Apidays New York 2024 - Passkeys: Developing APIs to enable passwordless auth...
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
Biography Of Angeliki Cooney | Senior Vice President Life Sciences | Albany, ...
 
Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024Manulife - Insurer Transformation Award 2024
Manulife - Insurer Transformation Award 2024
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 

Security, you are also part of the game

  • 1. Open solutions, smarter people Security You are also part of the game This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
  • 2. Open solutions, smarter people Who is that guy? • Bert Desmet • 23 years old • Fedora – Ambassador, mentor, packager • Loadays – Co organizer • Numius – System Engineer, Consultant • Devnox – Developer, System Engineer
  • 3. Open solutions, smarter people Today's topics • I'm a good hacker. • Why I love USB sticks. • Remember your password? • Shhhhhhht!
  • 4. Open solutions, smarter people I am a good hacker.
  • 5. Open solutions, smarter people No tech hacking?
  • 6. Open solutions, smarter people Shoulder surfing
  • 7. Open solutions, smarter people Dumpster diving
  • 8. Open solutions, smarter people Social engineering
  • 9. Open solutions, smarter people Taking pictures
  • 10. Open solutions, smarter people Why I love USB sticks.
  • 11. Open solutions, smarter people They are easy
  • 12. Open solutions, smarter people And small
  • 13. Open solutions, smarter people They are easily.. • Forgotten • Stolen
  • 14. Open solutions, smarter people Some thoughts about it • Encrypt your sensitive data • Never put passwords on your system • Use the intranet • Never leave your portable gear alone • Never forget your gear
  • 15. Open solutions, smarter people Some statistics • 53% of UK workers lost portable devices – >50% at a drinking venue • Taxis and public transport • 1 lost data record cost more than $187 – 70% indirect cost • Lost costumers
  • 16. Open solutions, smarter people Remember your password?
  • 17. Open solutions, smarter people How to choose a password • Avoid using dictionary words • Use special characters and numbers • Change your password every month • Blah blah blah
  • 18. Open solutions, smarter people How to choose a password • Avoid using dictionary words • Use special characters and numbers • Change your password every month • Blah blah blah
  • 19. Open solutions, smarter people Entropy • H : Entropy • N : Possible symbols • Length of string H= L∗log2 N
  • 20. Open solutions, smarter people Example time! • This is.obviously a.bad passw0rd:-( – L : 35 – W : 94 – H : ±230 • PrXyc.N(n4k77#L!eVdAfp9 – L : 23 – W : 94 – H : ±151
  • 21. Open solutions, smarter people Time to crack a password • [[Guesses before string is found = 2H]] • This is.obviously a.bad passw0rd:-( – 2230 = 1.72543659 × 1069 – 1000 guesses /s = 5.5 x 1058 years • PrXyc.N(n4k77#L!eVdAfp9 – 2151 = 2.85449539 × 1045 – 1000 guesses /s = 9 × 1034 years
  • 22. Open solutions, smarter people Password Strenght
  • 23. Open solutions, smarter people Lastpass • Fully encrypted • Generate extremely hard passwords • Choose a good master password!
  • 24. Open solutions, smarter people Some tips • Never store passwords on pc • Never use autologin
  • 25. Open solutions, smarter people Shhhhhhhht!
  • 26. Open solutions, smarter people I want you to shut up!
  • 27. Open solutions, smarter people Security through obscurity • Don't tell anyone • Security based on secrecy
  • 28. Open solutions, smarter people Kerckhoffs' doctrine • Security can't depend on secrecy
  • 29. Open solutions, smarter people Reality • There are always leaks – By accident – Deliberately • Try to keep 'secrets'
  • 30. Open solutions, smarter people Wait! There is more!
  • 31. Open solutions, smarter people In a perfect world..
  • 32. Open solutions, smarter people There is always a hole.
  • 33. Open solutions, smarter people I like onions
  • 34. Open solutions, smarter people Multi Level Security • Multiple systems • Building fort Knox • You are the first line of defense
  • 35. Open solutions, smarter people Extra! Extra!
  • 36. Open solutions, smarter people Something you have..
  • 37. Open solutions, smarter people Yubikey
  • 38. Open solutions, smarter people I preach. And I practice.
  • 39. Open solutions, smarter people Questions? • Bert Desmet • Security, you are also part of the game • Mail: Bert@devnox.eu • Twitter: @bdesmet_ • Website: http://blog.bdesmet.be • Website: http://www.devnox.eu • This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
  • 40. Open solutions, smarter people Sources • Chess game: http://www.flickr.com/photos/seeminglee/1479932683/ • Closed vault: http://www.flickr.com/photos/mstyne/3654056683/ • Open vault: http://www.flickr.com/photos/spotsgot/156025944/ • Onion: http://www.flickr.com/photos/inferis/107293622/ • Laptop + usb stick: http://www.flickr.com/photos/wstryder/2780310027/ • New York Public Library: http://www.flickr.com/photos/paul_lowry/2616820493/ • Statistics on loosing gear: http://www.securestix.com/bad_news.php • Shoulder surfing: http://www.flickr.com/photos/bonzoesc/209474964/ • Dumpster: http://www.flickr.com/photos/urbanjacksonville/1803065217/ • Telephone call: http://www.flickr.com/photos/lst1984/994531885/ • Taking pictures: http://www.flickr.com/photos/glenpooh/708845839/ • Xkcd joke: http://xkcd.com/936/ • Shut up: http://www.flickr.com/photos/lorenia/934705558/ • 3way handhake: http://media.photobucket.com/image/3%20way%20handshake/Haley_Bug/Mission%20Trip%20Choir%20Tour%202006/100_0087.jpg?o=1 • Yubikey: http://www.flickr.com/photos/thofle/3206443137/ • Special thanks to: Johnny Long