This past July I went out to Las Vegas for the first to attend some of the events referred to as "hacker summer camp": Black Hat, BSides, and Defcon.
Now, I did not attend Black Hat as the event was pretty expensive. I did want to drop by the exhibit hall, but couldn't get in. I did attend the ISSA and ISC(2) receptions tied to the event. I was a little disappointed that ISACA made a big deal about being at Black Hat but didn't do a reception of some kind.
I mainly came to attend BSides and Defcon and stayed at the Tuscany Suites where BSides was being held, which I recommend. This guaranteed you a ticket for BSides. I also got the meal ticket deal (breakfast & lunch) at BSides, which made me a sponsor and got me earlier checking at the sponsor table. I also pre-ordered a t-shirt (recommended).
There were a lot of interesting sessions I attended. I'll need to do another posting on some of the sessions I went thru and give more info on them.
Once BSides was over I attended Defcon. This event was a bit overwhelming. There was a big line for the trading post (cash only!), and I mainly wanted to get a t-shirt. I was a little disappointed that the badge this year was a rubber badge, not an electronic one. But many others had their own badge and I got a few.
Defcon is almost a collection of conferences. There are main Defcon sessions, which are in HUGE rooms, four at a time. Then there are a half dozen or so "villages" which have activities and their own sessions. Skytalks was a good one, but there are villages for privacy & crypto, car hacking, IoT, and many others. There was also a vendor area (but not open the first day). There were many interesting vendors. One I had met at BSides is HackerBoxes.
As I noted, a lot of groups, including some of the villages, had their own electronic badges. I really wanted a few, but they were cash only. I didn't consider that and didn't bring a lot of cash with me. And using ATMs was expensive. So next time I will bring a lot more cash.
I did some fun things, like solider a small badge at the Hardware Hacking Village (wasn't their big electronic badge they had, missed out on that). Had some interesting conversations with several people. Met a few interesting people and groups.
Not sure if I'll go back next year or when I'll go back. I would probably want to submit some talk proposals to BSides (I had thought of doing some this year, but wasn't certain if any I do would get accepted, but after seeing the sessions I should have submitted some). I would again get a room at the Tuscany and had debated getting one just in case I decided to go. Just don't know at this point.
I'll post some pics soon.
Showing posts with label Black Hat Security Conference. Show all posts
Showing posts with label Black Hat Security Conference. Show all posts
Monday, September 18, 2017
Monday, August 7, 2017
New stuff coming soon
Been awhile since I've posted anything. I was recently out in Las Vegas for what some call "hacker summer camp": BlackHat, BSides Las Vegas, and DefCon. I had never been out there and had heard about it from several of my friends and associates who go out there almost annually. For various reasons I haven't been able to, but made the point to get out there this summer.
I learned some interesting things, saw some interesting presentations. So over the next week or so will have several postings on these items.
I learned some interesting things, saw some interesting presentations. So over the next week or so will have several postings on these items.
Wednesday, April 5, 2017
Upcoming Security Conferences for 2017
There are several conferences in the South Florida (and other areas) that I plan to be at in the coming months, and am speaking or hope to be.
BSides Orlando will be April 8th, but now moved to Valencia College-West Campus. Also different this year is this will be a one day event, but will again be right before SANS Orlando. I will be there speaking on the topic of Risk. This talk is aimed at the entry level security professional to help them gain a better understanding of the importance of IT Risk in what we do in security.
The South Florida ISACA Chapter will be having their 10th WOW event on Friday, April 21st. This will be an all day event at the FIU Biscayne Campus as usual. Registration is already open and the focus is on "Emerging Threats in Cybersecurity". Will be there. Had hoped to speak, but didn't happen.
HackMiami will be back with their 5th conference on May 19-21, again at the Deauville Beach Resort in Miami Beach. I will be speaking there on the topic of Cyber Resilience.
Further out, there is of course Black Hat, DefCon, BSides out in Las Vegas from July 22-30th. I have never been out there, and plan to go out for BSides and DefCon. Barring any financial issues. I am also planning to submit for BSides. Probably submit a few of my talks and see if any get picked. Not sure if what I speak on would be accepted at DefCon.
Interestingly, ISC(2) has moved their Security Congress event out of being co-located with ASIS's conference. This one will be September 25-27 in Austin, TX. To be honest, I have no plans to attend this. I felt their event was a bit pricey.
Now, ASIS, which is more for security folks who deal with physical security then information security, will have their conference September 25-28 in Dallas, TX. ISSA is working with them to have infosec speakers at this event. Kind of filling the void that ISC2 left. And again, Infragard is co-hosting their annual conference there as well. Sounds interesting, but again, probably will not be at this event. Just can't afford it.
ISSA will be having their 2017 International Conference in San Diego from October 9-11. I am on the conference committee for this one again, and again submitted some talk proposals.Unless one of my talks gets picked I'm not certain I'll go this year. [UPDATE: my talk on Cyber Resilience was picked]. I do want to go next year when it'll be in Atlanta.
Now, the only other conferences this year I look forward to is a possible Security BSides happening in Southwest Florida, where I am from. Heard about this at BSides Tampa and the group hopes to have this in Ft Myers. I hope to hear more about it as I'd love to be involved. Tentative time they are aiming for is June.
Another one I should mention is BSides Jacksonville. This is usually held in October. I've never been to one.
If any will be at the above ones I'll be at, stop by and say hi!
BSides Orlando will be April 8th, but now moved to Valencia College-West Campus. Also different this year is this will be a one day event, but will again be right before SANS Orlando. I will be there speaking on the topic of Risk. This talk is aimed at the entry level security professional to help them gain a better understanding of the importance of IT Risk in what we do in security.
The South Florida ISACA Chapter will be having their 10th WOW event on Friday, April 21st. This will be an all day event at the FIU Biscayne Campus as usual. Registration is already open and the focus is on "Emerging Threats in Cybersecurity". Will be there. Had hoped to speak, but didn't happen.
HackMiami will be back with their 5th conference on May 19-21, again at the Deauville Beach Resort in Miami Beach. I will be speaking there on the topic of Cyber Resilience.
Further out, there is of course Black Hat, DefCon, BSides out in Las Vegas from July 22-30th. I have never been out there, and plan to go out for BSides and DefCon. Barring any financial issues. I am also planning to submit for BSides. Probably submit a few of my talks and see if any get picked. Not sure if what I speak on would be accepted at DefCon.
Interestingly, ISC(2) has moved their Security Congress event out of being co-located with ASIS's conference. This one will be September 25-27 in Austin, TX. To be honest, I have no plans to attend this. I felt their event was a bit pricey.
Now, ASIS, which is more for security folks who deal with physical security then information security, will have their conference September 25-28 in Dallas, TX. ISSA is working with them to have infosec speakers at this event. Kind of filling the void that ISC2 left. And again, Infragard is co-hosting their annual conference there as well. Sounds interesting, but again, probably will not be at this event. Just can't afford it.
ISSA will be having their 2017 International Conference in San Diego from October 9-11. I am on the conference committee for this one again, and again submitted some talk proposals.
Now, the only other conferences this year I look forward to is a possible Security BSides happening in Southwest Florida, where I am from. Heard about this at BSides Tampa and the group hopes to have this in Ft Myers. I hope to hear more about it as I'd love to be involved. Tentative time they are aiming for is June.
Another one I should mention is BSides Jacksonville. This is usually held in October. I've never been to one.
If any will be at the above ones I'll be at, stop by and say hi!
Friday, August 16, 2013
Security in the "Internet of Things"
Friday, July 5, 2013
New Android Security hole
So am not the first to bring this to others attention. I've seen several articles on it over the last week on the Android "Master Key" vulnerability.
Basically, researchers at Bluebox Security have found this security hole that has been present in all version of Android since v1.6. The firm informed Google about this in February. The Samsung Galaxy S4 supposedly has been patched for it. No word on any other Android device.
More information on it will be forthcoming at the Black Hat Security Conference. But for right now, you can check out their blog posting HERE on it.
Now, a basic thing about this issue is that it is exploited by malicious apps. And malicious apps, despite tools like Bouncer in the Google Play Store, can still be put up there. Patching Android is always a tough thing, because the process has to include both the manufactors and the carriers. According to a recent item on CIO, Google has already updated Play Store to block apps that take advantage of the issue. But I hope people see that as only a stop gap to getting the Android OS itself patch.
For those interested, here are the articles I've see so far on this:
Bluebox Blog
Techcrunch
Android Central
CIO
Basically, researchers at Bluebox Security have found this security hole that has been present in all version of Android since v1.6. The firm informed Google about this in February. The Samsung Galaxy S4 supposedly has been patched for it. No word on any other Android device.
More information on it will be forthcoming at the Black Hat Security Conference. But for right now, you can check out their blog posting HERE on it.
Now, a basic thing about this issue is that it is exploited by malicious apps. And malicious apps, despite tools like Bouncer in the Google Play Store, can still be put up there. Patching Android is always a tough thing, because the process has to include both the manufactors and the carriers. According to a recent item on CIO, Google has already updated Play Store to block apps that take advantage of the issue. But I hope people see that as only a stop gap to getting the Android OS itself patch.
For those interested, here are the articles I've see so far on this:
Bluebox Blog
Techcrunch
Android Central
CIO
Subscribe to:
Posts (Atom)

