[00:00.000 --> 00:02.640] In the back of the room, if you could try to keep it down during the discussions. [00:02.880 --> 00:08.740] I know that's sort of become like a social area back there, but please keep it at a whisper as your voice does carry up here. [00:09.320 --> 00:19.600] If you've been coming to some of these HOPE conferences for a while, you will recognize this hat because RenderMan wears it to every conference that he comes to. [00:20.140 --> 00:29.640] He's the involuntary leader of the Church of Wi-Fi, which I believe is some kind of tax-deductible haven of some sort. [00:30.000 --> 00:30.600] In Canada. [00:30.820 --> 00:31.920] In Canada, correct. [00:32.480 --> 00:35.360] This is How Do I Pwn The Let Me Count The Ways by RenderMan. [00:44.870 --> 00:47.450] Okay, so can everybody hear me okay? [00:48.990 --> 00:50.550] All right, I see some thumbs up. [00:51.650 --> 00:52.630] I am RenderMan. [00:53.190 --> 00:57.910] Many of you probably know me or I probably owe a drink too, in which case I won't be seeing you later. [01:00.150 --> 01:08.530] I will warn you, I don't think my dinner is agreeing with me, but I do have a bucket over here, so if I do make a quick run, it's nothing personal. [01:09.970 --> 01:13.410] This talk is where I start getting literary with my titles. [01:13.670 --> 01:16.190] It's called How Do I Pwn The Let Me Count The Ways? [01:16.910 --> 01:24.730] And it all started out with a conversation I had with a guy named Dino from South Africa at a convention in Toronto called Sektor. [01:25.690 --> 01:35.690] We both kind of noted that the workforce, you know, the business workforce that's out on the road a lot is increasingly mobile, increasingly using and relying on wireless devices. [01:36.290 --> 01:42.350] And most of these people, you know, by and large can be as dumb as toast. [01:42.910 --> 01:57.070] So there's an awful lot of opportunities for these people to, you know, make your BOFH job kind of difficult, because they're away from, you know, your ability to smack them around and enforce the rules. [01:57.250 --> 01:58.430] They can disable things. [01:58.510 --> 01:59.810] They can do stupid things. [02:00.430 --> 02:09.530] And it's actually rather terrifying when you look at it, how easy these people can usurp all of the security measures you put in place. [02:10.730 --> 02:12.870] This is by no means an exhaustive list. [02:13.110 --> 02:16.110] If you have any suggestions at the end, I'd love to hear them. [02:17.230 --> 02:23.350] And as part of full disclosure, I will say that there is probably not any terribly new wireless content in here. [02:23.750 --> 02:26.790] There's, you know, it's just sort of an accumulation of everything. [02:27.090 --> 02:34.330] Probably some things that, you know, angles you haven't thought of before, but just in case anyone's expecting, you know, some brand new zero day or something like that. [02:34.610 --> 02:34.810] Sorry. [02:36.850 --> 02:37.570] Meet Bob. [02:38.550 --> 02:40.850] Bob works for Widgets International selling widgets. [02:41.590 --> 02:42.070] Fancy that. [02:42.950 --> 02:44.590] He travels to customer sites. [02:44.930 --> 02:46.370] You know, he's always flying everywhere. [02:46.570 --> 02:48.950] He's the guy who knows every article in the in-flight magazine. [02:49.290 --> 03:00.510] And, you know, the kind of guy you see at all these airports that's, you know, take, he's got the 500 Club pass to get into the lounge and everything like that. [03:00.510 --> 03:05.090] You know, when you're sitting back in cattle class and everything, he's getting, you know, samosas up in the first class. [03:05.550 --> 03:06.610] The kind of guy you just like to hate. [03:08.290 --> 03:09.030] Is that me? [03:11.650 --> 03:16.430] How many of you actually work with anybody like this who has a sales force like this? [03:17.370 --> 03:17.730] Wow. [03:17.990 --> 03:18.710] That's a fair bet. [03:20.970 --> 03:23.930] As you probably know, Bob can be your worst IT nightmare. [03:26.250 --> 03:28.370] He kind of likes to think himself tech savvy. [03:28.590 --> 03:30.570] Oh, look at this fancy-ass laptop I've got. [03:30.750 --> 03:33.310] I can, you know, oh, it's nice and shiny and big. [03:33.970 --> 03:36.530] I have absolutely no idea what's in it, but, you know, look at it. [03:36.670 --> 03:37.030] It's shiny. [03:38.650 --> 03:41.190] Really, you know, he just knows enough to get access to his porn. [03:41.390 --> 03:42.050] That's about it. [03:42.270 --> 03:43.570] That's all he really cares about, too. [03:45.070 --> 03:47.190] And he can be your worst nightmare. [03:48.410 --> 03:52.770] In this particular case, you know, our fictitious Bob is going to be our worst case scenario. [03:53.310 --> 03:56.630] You know, the absolute worst possible user you could possibly imagine at your business. [03:58.410 --> 03:59.450] So let's pwn Bob. [04:00.930 --> 04:05.890] We're not going to touch him, you know, we're not going to, you know, punch him in the face, steal his wallet or anything like that. [04:05.990 --> 04:14.630] We're just going to say, okay, just for instance, you're a bored hacker going to a conference in New York or Norway or some such case. [04:15.690 --> 04:17.430] And you're sitting in the departure lounge. [04:17.650 --> 04:18.990] You've got an hour and a half to kill. [04:19.510 --> 04:24.270] You see this guy across from you pounding away on his laptop, looking like he's so important, Bluetooth headset in. [04:25.930 --> 04:28.870] Yeah, when a hacker gets bored, bad things tend to happen. [04:29.170 --> 04:32.470] So let's kind of say, you know, let's see what we can do to him. [04:33.930 --> 04:36.510] First and most obvious, he's sitting there working on his laptop. [04:36.830 --> 04:51.470] So you've got a laptop, tons of private company information that, you know, not only do you now have to worry about mortar searches for all that information, you know, the guy sitting across from you can be doing just as many bad things. [04:52.010 --> 04:53.850] You know, Bob will connect to anything. [04:54.130 --> 04:58.130] You know, hot spots at train stations, airports, hotels, wherever. [04:58.850 --> 05:02.130] You know, the Linksys global network I'm sure you're all very familiar with. [05:04.530 --> 05:12.670] And, you know, I'm not saying by any means that there's, you know, 500 networks, many of which are open around this hotel, but he's the kind of guy that would take advantage of this. [05:13.150 --> 05:16.270] One of my favorite stories actually is, despite this being a felony, [05:19.910 --> 05:25.750] there was a magazine article where they're giving an interview with, I think it was Steve Ballmer. [05:26.190 --> 05:32.250] And they were at a hotel for some conference or something like that, and the hotel didn't have free Wi-Fi, or they didn't have Wi-Fi in the hotel. [05:34.250 --> 05:35.930] So they're trying to get some work done. [05:35.930 --> 05:37.110] They're trying to figure out how to get online. [05:37.690 --> 05:43.130] And one of the guys calls, you know, Bill Gates and says, hey, you know, I got an open access point over in my room. [05:43.250 --> 05:43.730] Come on down. [05:44.150 --> 05:52.170] So there's, like, you know, some of the top executives going on and using some bakery's access point to get on to the corporate VPN to get into Microsoft. [05:52.370 --> 05:55.690] I'm like, here it is, the richest man in the world just admitted to committing a felony. [05:56.810 --> 05:58.610] It's like, there's no justice in the world. [06:01.710 --> 06:05.190] As I'm sure many of you know, hot spots generally do not encrypt. [06:05.190 --> 06:12.730] If you're connecting in a T-Mobile hotspot, a Starbucks, or AT&T, or whoever they're using now, they're not encrypted. [06:13.090 --> 06:17.250] You know, it's a service, but it's a service that anybody can see. [06:17.470 --> 06:20.570] If it's clear text, anybody can see it. [06:20.630 --> 06:24.390] They can see what you're transmitting, unless it's, like, SSL or VPN or something like that. [06:25.210 --> 06:34.390] The other thing is they're also free to inject because, hmm, I can see what you're looking for and do interesting things to respond to that. [06:36.190 --> 06:40.590] If you're not using a VPN at one of these hotspots and you've got company data going over it, you're screwed. [06:40.830 --> 06:41.670] You're gonna get boned. [06:42.190 --> 06:46.710] You know, you've got company secrets going through the air to anybody within range. [06:47.470 --> 06:49.030] Bob probably doesn't know this. [06:49.130 --> 06:55.830] Bob is probably more worried about the fact that he can, you know, get his email from his wife or kids or, you know, access to whatever porn sites he's got with him. [06:56.850 --> 06:59.350] And not thinking about the company's assets. [06:59.630 --> 07:08.270] He's not thinking about the fact that he's got this, you know, database sitting there on an open share on his computer that, oh, gee, he doesn't have a firewall. [07:08.490 --> 07:19.470] Anybody who's on the local LAN also connected to the access point can now start browsing his shares and, hmm, oh, gee, look, customer list, costing for products. [07:20.170 --> 07:27.110] This could be very interesting to other people, particularly if you happen to be sitting in an airport departure lounge and you see your competition sitting across the way. [07:28.990 --> 07:33.790] You know, the usual man-in-the-middle attacks, passwords, narfing, you know, all that's applicable. [07:34.970 --> 07:44.630] But a really telling example is at DEFCON 15 last year, there was about 20 access points a couple of days before the conference. [07:44.830 --> 07:49.850] There was about 20 access points that had the SSID of the hotel's network. [07:51.270 --> 07:53.530] By Saturday night, there was 150. [07:56.110 --> 07:58.170] Who's going to play Russian roulette with that? [07:58.410 --> 08:05.650] How do you know that the access point you're connecting to is actually the hotel one and not somebody just doing something nasty? [08:06.690 --> 08:09.070] Most of these hotspots don't do any authentication. [08:09.670 --> 08:21.470] You know, they might ask you for a username and password, but, you know, there's nothing verifying, no certificate coming back saying, yes, this is me, this is, you know, an actual hotel network, no verification or anything like that. [08:21.610 --> 08:26.270] And at best, you might see, oh, it's a MAC address that's written on the sheet in your room. [08:26.630 --> 08:28.030] Well, that could be easily spoofed too. [08:30.470 --> 08:31.470] You also have to think. [08:32.010 --> 08:33.850] The attacker's on your local network. [08:34.490 --> 08:37.170] He's sitting right next to you for all intents and purposes. [08:37.570 --> 08:43.970] If you don't have a firewall up or anything like that, it's like the guy sitting in the cubicle next to Bob back at, you know, Widgets International. [08:44.830 --> 08:49.150] So all the attacks that usually would be mitigated by firewalls suddenly apply. [08:50.450 --> 08:58.790] And that's not even to speak of things like the driver vulnerabilities that have come out recently that, you know, who knows what kind of fresh hell can be unleashed with that stuff. [09:00.630 --> 09:17.430] When I was in Norway for a conference back in February, I had basically had the worst travel experience possible between canceled flights, you know, airplanes having to turn around because the pilot comes on and says, yeah, we've got a broken plane, we need to get a new one, [09:17.430 --> 09:19.730] you know, after you've been flying for an hour in this thing. [09:20.430 --> 09:22.830] It just wasn't a pleasant experience. [09:23.590 --> 09:31.210] So I'd been up for like 36 hours or so before I got to the conference and with the time zone change, oh, I got there just at the very beginning of the day. [09:31.530 --> 09:33.130] So I hung around. [09:34.050 --> 09:36.030] And you get tired, you get punchy. [09:36.690 --> 09:38.130] Let's start doing some experimentation. [09:39.270 --> 09:53.190] So I wanted to see if other countries, because I'd only experimented in North America, I wanted to see if other countries and continents had, you know, enough wherewithal to realize that maybe they shouldn't be using open networks at conferences where there's, [09:53.210 --> 10:00.010] you know, half the speaking rosters known hackers that go to DEFCON and, you know, under assumed names and everything like that. [10:00.230 --> 10:04.530] So, you know, let's see if these people really figured out. [10:04.710 --> 10:16.910] So I fired up Airpone, which I don't know if many of you know, but essentially when you make a request for, say, Google, you get the HTTP GET request for the image on the front page. [10:17.830 --> 10:22.370] Now, that will take like 200 milliseconds to get there, 200 milliseconds back. [10:22.910 --> 10:34.590] If I'm in the same room as you and you're running on an unencrypted network, I can see this GET request and, with any luck, supply my own image back, fudging that it's coming from Google and feed it back to you. [10:34.870 --> 10:37.370] And your browser says, oh, this must be the image that I was expecting. [10:38.110 --> 10:40.330] And put up, you know, whatever image it is. [10:41.430 --> 10:43.410] This is the first image I started injecting. [10:46.250 --> 10:49.930] I don't know if you can tell, but that's a 10-foot kayak and a 12-foot shark. [10:51.670 --> 10:53.590] If that doesn't say pwned, I don't know what does. [10:57.350 --> 10:58.450] Hardly anybody noticed. [11:00.010 --> 11:01.970] Most people didn't actually look at the image. [11:01.970 --> 11:03.870] They just saw this blue thing. [11:04.030 --> 11:05.030] They didn't really look at it. [11:05.110 --> 11:06.370] They didn't spend any time on it. [11:07.090 --> 11:09.190] Just a lot of like, okay, what's going on? [11:09.290 --> 11:10.130] Am I getting corrupted images? [11:10.330 --> 11:10.650] What's going on? [11:11.390 --> 11:14.570] Now, at this conference, they had three networks running. [11:14.850 --> 11:16.090] One was running open. [11:16.290 --> 11:17.510] One was running WEP. [11:17.830 --> 11:19.270] One was running WPA. [11:21.610 --> 11:25.650] Now, I was monitoring traffic for the two days of the conference. [11:25.650 --> 11:29.710] I only saw two logins to the WPA network. [11:29.710 --> 11:35.390] And one of those I had verified was actually for maintenance to go in and double-check it was actually running because nobody was connecting. [11:36.690 --> 11:38.990] So everybody was using the open network. [11:40.430 --> 11:44.030] And, okay, after the first day, let's up the ante. [11:44.170 --> 11:49.010] Let's see what, you know, if these people will actually figure out that maybe somebody could possibly be screwing with their network. [11:55.580 --> 11:59.580] Grab the camera, took a picture, started up, you know, injecting that. [12:01.320 --> 12:02.140] They got the hint. [12:02.700 --> 12:03.600] And I didn't get punched. [12:04.260 --> 12:10.560] There were some people coming up to me who, you know, they've got their corporate web mail open and they're looking at it and I'm like, what are you doing? [12:10.740 --> 12:12.580] How are you getting into my laptop? [12:13.140 --> 12:14.200] What are you doing to me? [12:14.320 --> 12:15.500] Like, what did I do to you? [12:15.940 --> 12:18.580] And I'm like, coming to my talk, I'll explain. [12:20.060 --> 12:32.540] And actually, Roger Dingledine from the Tor project had asked me to continue doing this through the rest of the weekend because it fit very nicely into his talk about Tor and how it can actually be used to mitigate against something like this. [12:32.760 --> 12:35.960] But in this particular case, I'm just injecting my face. [12:37.080 --> 12:38.480] What else could I inject? [12:40.400 --> 12:43.740] JavaScript, you know, change DNS entries. [12:44.500 --> 12:50.560] You know, the classic one that Airpone originally started with was injecting goatse at DEFCON. [12:51.780 --> 12:52.740] So, yeah. [12:53.720 --> 12:56.420] Yeah, that one actually confused a lot of people. [12:56.520 --> 12:59.620] People were thinking it was DNS poisoning or something weird like that. [12:59.700 --> 13:02.920] They didn't think actual, like, literal man in the middle through the air. [13:03.700 --> 13:09.440] And the fact that this is a valid attack vector still is kind of scary, you know, that people are using an open network. [13:11.400 --> 13:14.480] Karma is another one that can turn around and bite you. [13:14.800 --> 13:16.440] I don't know if... is everybody familiar with Karma? [13:17.400 --> 13:18.140] A little bit? [13:18.320 --> 13:18.380] Okay. [13:18.920 --> 13:27.320] Essentially what it is is when a laptop with Windows or whatever is trying to connect to... is out of range of its home networks. [13:27.680 --> 13:32.040] There's that preferred list that it says, you know, automatically connect to whenever you're in range. [13:32.300 --> 13:34.700] Well, it's sitting there beaconing, looking for these networks. [13:35.160 --> 13:36.560] Karma says, oh, that's me. [13:37.320 --> 13:38.580] You know, here's an IP. [13:38.580 --> 13:39.640] Here's how to connect. [13:41.180 --> 13:42.680] And generally, it will. [13:43.080 --> 13:44.520] You know, a Windows laptop will. [13:44.640 --> 13:48.440] So now I've got a direct connection to you because now I'm on the local network. [13:52.140 --> 13:59.120] Hotspotters does the same thing, but it emulates pay for play, access points, presents, you know, your nice login page and everything like that. [13:59.600 --> 14:02.120] Metasploit has some new tools for this sort of stuff. [14:04.460 --> 14:10.560] Simple Nomad has, two, three years ago, had a talk at ShmooCon... [14:10.560 --> 14:11.220] Three years ago? [14:11.440 --> 14:19.980] Had a talk called Hacking the Friendly Skies where he pointed out, hmm, you're at 30,000 feet inside a big metal tube away from any other sources of interference. [14:20.460 --> 14:33.480] Yes, the stewardesses tell you to turn off your wireless, but, you know, that idiot in first class that's, you know, Bob sitting there typing away at a letter or something like that, doesn't necessarily listen to that or necessarily know how to turn off the wireless. [14:34.080 --> 14:36.880] So he's sitting up there broadcasting, looking for networks. [14:37.180 --> 14:39.480] There's no way in hell he's going to find them at 30,000 feet. [14:40.200 --> 14:47.500] Except for the guy back in economy who fires up karma or something like that and connects up to the guy in first class. [14:47.960 --> 14:49.560] Oh, now he's, you know, browsing his shares. [14:49.820 --> 14:51.600] Oh, you know, this guy works for this company. [14:51.840 --> 14:53.720] You know, oh, here's a customer database. [14:53.900 --> 14:56.560] Oh, here's a memo that went around or something like that. [14:57.140 --> 15:04.620] And I don't know if anybody has seen Simple Nomad, but he's not the kind of guy that you would expect to wear a suit all the time, you know, big long beard and everything. [15:05.840 --> 15:13.900] Great guy, but just not, you know, one of Bob's usual kind of people he deals with. [15:14.280 --> 15:19.740] So Simple has some great stories about going up into the guy in first class, seeing the laptop open. [15:19.900 --> 15:21.600] Hey, Bob, how's it going? [15:21.820 --> 15:23.220] You know, how's the kids? [15:23.460 --> 15:25.880] You know, did you get that memo about that thing? [15:26.180 --> 15:29.920] And this guy's looking and he's like, who are you? [15:30.060 --> 15:31.660] How do you know all this? [15:32.180 --> 15:34.480] I'm just scaring the living crap out of this guy. [15:34.740 --> 15:44.360] And you've got to think about it that even at 30,000 feet where theoretically nobody's supposed to be broadcasting wireless, somebody probably is and could be exploited. [15:44.840 --> 15:55.020] One of the best stories I ever heard was from a friend of mine that does pen-testing for a living, and he was talking about that they were flying out to a customer site to do an audit. [15:57.520 --> 15:58.660] The... excuse me. [15:59.280 --> 16:07.180] One of the top people from that site that they were going to, one of the top execs, happened to be on the same flight, you know, obviously probably flying first class. [16:08.980 --> 16:12.920] They connected to his laptop in the middle of the flight and literally pre-hacked him. [16:13.580 --> 16:16.700] So that when he logged into the corporate network, he created a back door for them. [16:17.440 --> 16:20.700] So before they even landed, they had compromised the site. [16:23.680 --> 16:27.080] You know, it's absolutely terrifying to think that this is possible. [16:29.840 --> 16:38.160] There's a cafe latte exploit, which even if you're not connected to the corporate network, could divulge a web key if for some stupid reason you're still running web on a corporate network. [16:38.600 --> 16:49.020] So if I know that Bob works for Widgets International and that I live in the same town as their headquarters and I want to do something bad to them, I'd target Bob, get the key, and, you know, then log into the corporate network. [16:49.700 --> 16:50.400] Simple as that. [16:50.940 --> 16:56.880] You know, there's the usual de-authentication headaches that can ensue. [16:57.840 --> 17:04.040] You know, some guy just fires a void 11 or MDK or something like that and just starts de-auth-ing everything. [17:04.600 --> 17:10.580] Kind of a... that's more of an annoyance situation than anything, but prevents this guy's ability to work. [17:12.120 --> 17:15.860] Generally, if your wireless is on, you're prone-able in one way or another. [17:16.100 --> 17:18.620] It's your driver exploit, active exploits, something. [17:19.860 --> 17:28.580] Particularly on the road when you're not at a corporate network that can't, you know, you can't do WPA2 radius over a hotspot at Starbucks. [17:28.900 --> 17:32.040] You can VPN in, but who knows what else could be done. [17:33.920 --> 17:35.600] Disable your Wi-Fi when not in use. [17:36.460 --> 17:37.140] Simple thing. [17:38.060 --> 17:42.080] You know, you got guys going out there, well, turn it off on the airplane because I don't want to be on the same plane as you in Crash. [17:44.680 --> 17:46.260] Use a VPN for everything. [17:47.120 --> 17:48.320] Assume you're being attacked. [17:50.000 --> 17:54.620] There's a bunch of different products out there that will give you indications that, wait, something's hinky here. [17:54.780 --> 17:59.940] The access point just changed channel or, you know, the MAC address just changed or something weird like that. [18:00.560 --> 18:01.960] You know, good products to investigate. [18:02.080 --> 18:05.940] To put on Bob's laptop so it puts up a big sign saying, hey, you're under attack. [18:06.640 --> 18:08.720] Stop doing anything confidential. [18:10.140 --> 18:11.980] Don't trust customer networks either. [18:11.980 --> 18:16.220] I've actually heard of a couple of stories where they were... [18:17.200 --> 18:17.920] Customers were... [18:18.440 --> 18:29.340] Sales guys were going out to customer networks or customer sites and say, oh, I need to get some information from the corporate network and then, you know, logging in, going back to the corporate and then bringing something down. [18:29.880 --> 18:35.660] Well, they're sitting there connected to the customer's network and the customer would be really interested to know exactly how much margin is on all these widgets. [18:36.400 --> 18:42.540] So if they were, you know, bidding a contract or something like that, they could see how much they could shave off and just, you know, those sorts of games. [18:43.960 --> 18:52.600] If you've got, like, an open share or something like that sitting on the laptop when he plugs it in, hey, you know, an OIT guy could be interested to say, hey, new host on the network. [18:52.760 --> 18:54.380] Ooh, what's the... Ooh, this is interesting. [18:54.840 --> 18:57.620] Oh, there's a lot more money in this contract than we were bidding for. [18:57.760 --> 19:00.440] Hey, we'll just, you know, add another zero to the contract. [19:02.180 --> 19:03.900] Turn on firewalls, be cautious. [19:05.120 --> 19:21.080] Tor is a really useful tool to have handy for this because if you catch yourself having to use a hotspot outside of the office or something like that, what Tor does is it encrypts from your laptop over the wireless connection to a Tor endpoint and then, [19:21.120 --> 19:30.060] you know, your connection will pop out in, like, Hungary or Germany or someplace like that and then go for the actual content and come back through the same way. [19:30.220 --> 19:30.540] Yes? [19:31.720 --> 19:34.780] Google did the same thing for, like, a few months, like, Tor. [19:34.960 --> 19:42.920] Remember they had, like, a little private Wi-Fi security VPN tool and they were trying to, like, make... [19:42.920 --> 19:44.560] Not that I know of specifically. [19:44.860 --> 19:46.300] That was probably just for a short while. [19:46.500 --> 19:48.840] That's why probably... I was just wondering why they took it down. [19:49.000 --> 19:49.840] It was, like... [19:49.840 --> 19:58.480] He was basically asking about Google having a similar tool that allowed you to anonymize your traffic and encrypt your traffic on the first hop. [19:59.260 --> 20:05.140] But basically, anything that would do that would mitigate a lot of these attacks because you're not seeing clear text go through. [20:05.260 --> 20:06.260] You can't inject anything. [20:06.400 --> 20:08.420] You can't ascertain anything from that. [20:08.720 --> 20:15.840] Yes, there's still vulnerabilities with Tor that, you know, you have to trust who your endpoint is that's coming out because somebody could be sniffing that. [20:16.260 --> 20:23.820] But really, you're not protecting the actual content going through, just only on that link between you and the access point in the Starbucks. [20:26.440 --> 20:27.580] Let's go after his phone. [20:28.840 --> 20:31.860] How many of you guys have... and ladies. [20:32.220 --> 20:40.620] How many of you have sales guys that seem like they've got their phone permanently welded to the side of their head and you really, really hope these things actually give brain cancer? [20:42.100 --> 20:42.940] Okay, fair number. [20:44.060 --> 20:49.640] How many of you have the sales guys with the Bluetooth headset permanently welded to their head? [20:50.740 --> 20:52.580] How many of you hate those things as much as I do? [20:53.380 --> 20:54.620] A lot of hands, okay. [20:57.900 --> 20:58.720] Bob loves it. [20:58.860 --> 20:59.980] You know, he's got his headsets. [21:00.120 --> 21:00.880] He's got his phone. [21:02.880 --> 21:11.840] His bank, every time he does a transaction online, sends him a one-time passcode over his SMS that he then has to enter to verify the transaction. [21:12.660 --> 21:14.080] A really reasonable system. [21:14.080 --> 21:23.360] He also keeps, you know, private company information on his phone, directory listings, you know, that sort of stuff you typically find on a corporate phone. [21:24.660 --> 21:30.920] Now, with Bluetooth, if the phone is on and discoverable, it's probably got a default pin on it. [21:31.540 --> 21:33.720] How many of you have changed your default pin? [21:35.080 --> 21:36.180] How many of you hadn't? [21:37.480 --> 21:39.020] Why did you put your hand up? [21:43.960 --> 21:49.280] Basically, in a lot of cases, paired devices can get full access to the other device. [21:49.520 --> 21:59.160] So if I pair my phone with yours, my phone inexplicably has full access to your phone, not just, you know, for OPEX exchange of business cards and things like that. [21:59.340 --> 22:00.700] It's the whole shebang. [22:01.660 --> 22:03.940] Why I need that much access, I don't know. [22:04.860 --> 22:10.300] So if I can convince you to pair with my phone for whatever reason, I can make your phone do some interesting things. [22:10.760 --> 22:18.020] Read right to the SMS messages, you know, insert some nasty things about Bob's wife in the phone, you know, in his messages or something. [22:19.280 --> 22:21.980] Pull out those one-time pin numbers. [22:22.340 --> 22:26.480] You know, if you see them online doing his transaction, you might be able to snag something before. [22:26.780 --> 22:44.140] I've talked with a couple of people who've audited systems like this, and they had to basically sneak a sniffer into the office and wait for the executive whose normal thing was to check his stocks and check his bank accounts for the end of day to get the code and then prove to him that, [22:44.260 --> 22:51.920] hey, you know, there's a portion in this loop that is vulnerable that I can get in, get this passcode, get to the website and do something before you do. [22:52.720 --> 22:53.580] How are we doing on time? [22:53.740 --> 22:54.040] All good. [22:55.920 --> 23:08.480] Some models of phone, if you connect on, I think it's RF-com 17, channel 17, you actually get an AT command prompt, like the old modem AT commands. [23:08.780 --> 23:11.140] You can issue commands directly to the phone. [23:12.140 --> 23:24.280] This gets interesting when you start applying it to things like premium rank calls, you know, 1-900 numbers and stuff like that, because Bob now has to explain the nine-hour phone call to Madame Wipsalot fun-time party line on the company dime. [23:25.560 --> 23:29.120] So, a little video here that explains this. [23:29.440 --> 23:31.100] Hopefully we've got audio on the laptop here. [23:33.740 --> 23:34.620] Get back there. [23:36.720 --> 23:37.880] Why are you not playing? [23:41.720 --> 23:42.440] There we go. [23:42.980 --> 23:43.480] There we go. [23:46.220 --> 23:54.560] Sources have reported that Britain is in the grip of a high-tech crime wave, and one of the latest targets is one of our closest friends, the mobile phone. [23:54.560 --> 23:57.160] It's sensational, but it gets the point across. [24:01.990 --> 24:10.530] Experts have discovered a security flaw in some of the most popular Bluetooth-enabled phones that allows others to hack into your handset and take control of it. [24:11.150 --> 24:17.310] Our hustlers are going to demonstrate for our hidden cameras just how vulnerable your phone can be to a silent attack. [24:18.090 --> 24:20.350] This is the Bluetooth scam. [24:21.370 --> 24:34.570] The problem with some Bluetooth phones is you can make an unauthorized connection to the phone and effectively take over the phone, read the contents out, so the phone book, SMS messages, even actually make calls with it. [24:34.790 --> 24:36.810] So, how does the Bluetooth hack work? [24:37.050 --> 24:39.370] Our hustlers are going to demonstrate it here. [24:40.050 --> 24:42.530] Jess and Paul's phones have their Bluetooth turned on. [24:42.530 --> 24:45.330] Alex uses his mobile pocket PC. [24:46.250 --> 24:54.490] Because of a security flaw in Jess's phone, he is able to locate the Bluetooth signal, hack directly into the handset and take control of it. [24:54.830 --> 24:57.950] Now he can make a call from Jess's phone to Paul's phone. [24:57.950 --> 25:00.890] This technique is known as Blue Jacking. [25:01.550 --> 25:07.550] The Bluetooth Hustle works by using the Bluetooth feature on mobile phones. [25:07.770 --> 25:12.350] It's a very modern, very useful, very easy piece of technology. [25:12.650 --> 25:15.490] They can connect to your phone without you knowing it. [25:15.790 --> 25:19.050] Your phone will not even show that it's connected to something. [25:20.310 --> 25:22.530] They're now ready to test it on the public. [25:24.830 --> 25:28.370] Alex has set his pocket computer to search for Bluetooth signals. [25:30.150 --> 25:33.230] Now he's pinpointed a mark with an enabled handset. [25:33.670 --> 25:35.190] He can go for the hack. [25:36.610 --> 25:39.670] Now he's in and making a call using the Mark's phone. [25:40.250 --> 25:42.150] But where's the actual scam here? [25:42.490 --> 25:45.610] It's in the number that Alex is calling from the Mark's phone. [25:46.170 --> 25:51.190] Our hustlers have set up their own premium rate line where calls are charged at £1.50 a minute. [25:51.950 --> 25:56.270] So, this guy is having the money taken from his pocket, but he's totally oblivious. [25:56.630 --> 26:06.050] And if the Mark doesn't realise his phone is calling the Hustlers premium line, during his journey between Manchester and Liverpool, he will lose £75 in call charges. [26:06.430 --> 26:06.830] Ouch. [26:07.430 --> 26:11.410] So, if Alex spends some time here, he can really take home the bacon. [26:12.670 --> 26:19.810] In an hour, he manages to target 20 phones with an average call time of 15 minutes, making him a grand total of £500. [26:21.010 --> 26:26.510] Our hustlers have proved for those with the technology and the know-how, this is a really money-spinning scam. [26:26.810 --> 26:33.970] The simplest and best way to protect yourself against this scam is just simply to keep your Bluetooth turned off unless you're actually using it. [26:34.090 --> 26:40.830] If you do not switch off the Bluetooth feature on your phone when you're not using it, you're in danger of somebody finding a way in. [26:44.970 --> 26:47.290] So, as you can tell, that's from Britain. [26:47.810 --> 26:52.790] But Bluetooth over there is just so much more popular, it's absolutely crazy. [26:53.430 --> 27:06.310] But it gets the point across that if you set up a phone number on, you know, some name that nobody's ever going to want to contest because it's so embarrassing, they're just going to pay it, you can probably make a fair bit of money. [27:06.310 --> 27:08.230] And that's kind of a terrifying thing. [27:08.390 --> 27:09.030] It's that easy. [27:10.690 --> 27:18.110] And besides, who's going to be able to prove that, you know, it wasn't Bob that actually made that phone call, that it was somebody else controlling Bob's phone? [27:19.150 --> 27:19.770] Makes you think. [27:21.770 --> 27:24.610] More Bluetooth threats centered around the headsets. [27:25.370 --> 27:27.870] Most headsets don't have any sort of input. [27:28.070 --> 27:28.830] They don't have a screen. [27:28.950 --> 27:30.750] They don't have, you know, more than one or two buttons. [27:31.210 --> 27:37.850] So, the only pin number that is necessary to connect is built in, and it's, you know, 0000 or 1234. [27:39.250 --> 27:41.010] There's no way to change that. [27:41.910 --> 27:47.390] So, you can use certain attacks like Blue Bump, which would disconnect the headset from the phone. [27:47.890 --> 27:50.390] It automatically would go back into discoverable mode. [27:51.090 --> 27:55.590] You could then connect to the headset and turn around and start listening to Bob's conversations. [27:56.650 --> 27:59.750] Or, if you want to get really mean, you can start injecting audio. [28:00.350 --> 28:07.610] This also applies to built-in car headsets, where it uses the stereo system to do Bluetooth. [28:07.870 --> 28:21.690] So, you can imagine if you were following along behind Bob and his CTO and they're having a conversation, you know, you could literally have a bug in that car by connecting to the Bluetooth headset built in and listen back in the car, you know, three car lengths back. [28:23.830 --> 28:33.770] Now, you can all... I've seen this a number of times, where somebody will go into a board meeting or something, take out their phone, turn it off out of courtesy, but they won't turn off the headset. [28:34.310 --> 28:40.550] They'll take it off, put it in a pocket, or just leave it on and look really silly with this blinking blue light that just distracts everybody. [28:42.530 --> 28:43.310] But think about it. [28:43.570 --> 28:48.970] If this thing has gone back to discoverable mode, it's a little bug. [28:49.090 --> 28:52.730] It's a bug in the boardroom broadcasting everything that's said. [28:53.490 --> 29:02.750] And I know that there's some military specifications that say that if you're in a classified meeting or something like that, you have to take your phone out, take the battery out, and put it in front of you. [29:02.750 --> 29:11.810] I cannot find... and correct me if I'm wrong, but I cannot find any regulations that talk about the headsets, because a lot of the headsets, you can't take the battery out. [29:13.730 --> 29:14.210] So... [29:14.210 --> 29:19.750] But I really like the idea of injecting audio because there are so many people who... [29:20.430 --> 29:28.250] you get these schizophrenic situations, and, you know, you'd really like to pull the old real genius situation. [29:32.310 --> 29:34.870] But you end up with... [29:35.430 --> 29:36.030] There we go. [29:37.150 --> 29:37.970] Have we got an idea on that? [29:39.690 --> 29:40.110] Uh... [29:40.110 --> 29:40.470] Come on. [29:42.110 --> 29:43.430] So what are you doing tonight? [29:45.510 --> 29:46.270] Uh... nothing. [29:46.390 --> 29:47.470] Do you want to go to a party? [29:47.870 --> 29:48.470] With me? [29:48.770 --> 29:49.070] Yeah. [29:49.290 --> 29:51.350] We could just go to my place before and hang out. [29:51.490 --> 29:52.470] Yeah, that sounds awesome. [29:52.570 --> 29:53.070] Hold on. [29:54.510 --> 29:55.350] Oh, uh... [29:55.350 --> 29:56.370] I thought you were talking about this. [29:56.370 --> 29:59.090] You can't always be smooth, but your beer should be. [29:59.090 --> 30:03.150] With a specially lined can to seal in the taste, Keystone light is always smooth. [30:03.490 --> 30:04.410] Even when you're numb. [30:04.630 --> 30:06.030] I'm really sorry about what just happened. [30:06.510 --> 30:06.910] I don't believe it. [30:06.950 --> 30:07.790] Oh, that's cool. [30:07.930 --> 30:08.430] I feel embarrassed. [30:08.790 --> 30:09.170] Just a second. [30:09.670 --> 30:10.190] Oh, man. [30:13.330 --> 30:14.470] I hate headsets. [30:15.350 --> 30:15.710] And... [30:15.710 --> 30:20.250] Like, I have one for when I'm driving, but, you know, you put it on, you make your call, you take it off. [30:20.450 --> 30:28.450] It's... when you're standing on Dunkin' Donuts or something like that, and there's that little blue light flashing in you, it's like, how special are you that you have to get that phone call in the next five seconds? [30:28.750 --> 30:31.450] It's like, just take the things off, please, or else... [30:31.450 --> 30:34.530] I have this dream of being able to do this en masse. [30:35.290 --> 30:45.390] I would absolutely love to find, like, a room full of bankers or something like that at some big meeting, you know, disconnect all their phones, connect up to all their headsets at once, and go, I know where you hid the money. [30:45.870 --> 30:47.070] I just see who runs. [30:49.310 --> 30:52.670] You know, put that in there and just rattle the cage a bit. [30:54.090 --> 30:55.510] This is a new addition. [30:56.910 --> 31:05.070] Well, leveraging through Bob's phone and his SMSs, we find some certain messages that get our interest. [31:05.330 --> 31:09.950] And these messages have a five-digit number prefix. [31:09.950 --> 31:15.310] And judging by the content within the message, you could probably figure out what the device is. [31:16.310 --> 31:20.250] There are some things that should just not be wirelessly enabled. [31:23.050 --> 31:26.890] By default, according to the manufacturer, these devices are not discoverable. [31:26.890 --> 31:29.030] But who thought this was a good idea? [31:32.960 --> 31:34.240] Have we figured it out yet? [31:42.380 --> 31:44.280] A Bluetooth-enabled vibrator. [31:45.440 --> 31:53.760] It pairs with a cell phone, and as it receives these specially coded text messages, each character of the message creates a certain motion. [31:58.650 --> 32:00.350] So let's get the innuendo out of the way. [32:11.960 --> 32:12.720] We're all good. [32:13.600 --> 32:14.560] Any suggestions? [32:16.740 --> 32:17.180] Okay. [32:20.870 --> 32:28.770] Basically, teledildonics, which is the study of, like, long-distance sex, seriously, they have not looked at security in a lot of cases. [32:28.770 --> 32:30.030] It's kind of terrifying. [32:31.830 --> 32:34.530] This is kind of an extreme example of a bad idea. [32:46.300 --> 32:48.280] But seriously, though, think about it. [32:48.380 --> 32:56.200] If they haven't spent time thinking about security, they think that this is just a good idea for, you know, some sort of remote stimulation. [32:57.300 --> 33:00.900] What about if we hijack Bob's phone and send messages on his behalf? [33:01.700 --> 33:06.520] Or if we're near enough to his wife, we can connect to the device directly and send messages ourselves. [33:07.440 --> 33:09.000] Does that count as a sexual assault? [33:10.000 --> 33:14.780] What implication does that have if, oh, honey, thanks for sending me that message at 7 p.m. [33:14.940 --> 33:15.220] last night? [33:15.220 --> 33:16.900] I didn't send that. [33:17.700 --> 33:20.220] Well, think about what would that do to relationships? [33:20.700 --> 33:24.380] That could get really awkward, weird, and probably disastrous. [33:25.280 --> 33:25.880] You know? [33:26.580 --> 33:37.080] I'm just thinking from a purely technical standpoint, if it's reacting to the characters available in an SMS, what about non-printable characters, control characters, things like that? [33:37.300 --> 33:40.880] You know, is there the possibility for physical harm with something like this? [33:41.800 --> 33:42.740] Buffer overflow. [33:44.800 --> 33:46.800] I'm adding that to the previous slide. [33:47.880 --> 33:49.240] It's a buffer overflow. [33:51.540 --> 33:54.100] This is actually something to consider. [33:54.260 --> 34:07.440] You know, we're moving into an era where we're on that really slick slope of the curve that this technology is showing up in, you know, all over the place, that should this be wirelessly enabled? [34:07.880 --> 34:09.460] Nobody seems to be asking that question. [34:09.680 --> 34:12.960] It might seem like a good idea, but, you know, is it? [34:14.060 --> 34:17.880] Seriously, I would love if somebody could, like, front the cash to get one of these things. [34:18.000 --> 34:18.540] They ain't cheap. [34:18.900 --> 34:19.800] What's it like to think? [34:21.320 --> 34:21.940] Shut up. [34:25.010 --> 34:25.390] No. [34:26.050 --> 34:34.090] But if something like this could show up in, like, DEFCON Wireless Village or something like this, tear it apart, fuzz it, like, see what the implications are of this. [34:34.090 --> 34:42.110] Now, I think it'd actually be very telling to see how this other new field has not thought about security. [34:43.430 --> 34:46.330] So, how do you stop Bluetooth threats in general? [34:46.830 --> 34:47.770] Just turn off Bluetooth. [34:48.330 --> 34:51.290] Like, how many of you use Bluetooth on a regular basis? [34:52.710 --> 34:55.790] How many of you find you have really crappy battery life when you do? [34:56.590 --> 34:58.810] So, turn off the Bluetooth and you get better battery life. [34:59.030 --> 35:02.470] You know, if you're not using it, then just, you know, turn it off. [35:02.910 --> 35:04.730] Change the default pin if you can. [35:05.130 --> 35:10.190] Some new headsets you can actually plug into a USB and actually interact with them and change the pins. [35:11.410 --> 35:13.970] But in general, most headsets, it's a default. [35:14.190 --> 35:24.190] I like what Motorola has done where it's only discoverable and will accept connections when you've held down the button for a few seconds, and it puts it in discoverable mode for 60 seconds. [35:25.350 --> 35:31.290] If possible, limit access to what parts of the device, you know, a connected device can get to. [35:31.650 --> 35:37.850] You know, does somebody need access to your phone book if you're just trying to exchange a business card or, you know, to your SMSs or something like that? [35:37.990 --> 35:43.750] If you can limit exactly what they're capable of, you won't have nearly as much fear if somebody is using this. [35:45.590 --> 35:52.190] And just, in general, consider the security implications of bringing these devices into, you know, a possibly secure environment. [35:53.170 --> 35:58.570] I know a lot of governments and militaries probably thought of this, but there's probably some companies that haven't. [35:59.130 --> 36:02.450] And hopefully, talks like this will get some of that attention there. [36:03.870 --> 36:04.930] Let's go after his keys. [36:07.290 --> 36:10.070] Bob has one of those RFID prox cards for his office. [36:10.410 --> 36:15.770] Carries it on a lanyard, sitting on his belt, you know, along with his, you know, the other side of it is his picture ID. [36:17.430 --> 36:21.690] If you really want an interesting talk, check out Johnny Long's No-Tech Hacking. [36:21.790 --> 36:26.290] He has a whole section on being able to photograph and replicate those badges. [36:27.830 --> 36:32.830] You know, how many of you actually use these at the office and have them accessible all the time? [36:33.510 --> 36:33.950] Right? [36:34.670 --> 36:41.510] How many of you know that a lot of those, if you haven't set them up in about the last five years, their legacy system can be easily cloned? [36:42.810 --> 36:43.690] Just a few of you. [36:45.430 --> 36:46.270] CQ.CX. [36:47.250 --> 36:49.190] Jonathan Westhugh has built a neat device. [36:49.310 --> 36:51.830] This is actually just his first version. [36:52.010 --> 36:53.510] He's actually refined it beyond. [36:53.750 --> 37:02.950] But essentially, what it is, is you push one button, it waves it in front of an RFID tag, it copies the number, push the other button, emulates it, and reads it back. [37:03.630 --> 37:14.390] So I just go up and behind the boss, you know, the head of the company, or the other person who has entire access to a building, a janitor, go, hey, how are you doing? [37:14.490 --> 37:15.210] Good job, beep. [37:15.970 --> 37:16.890] I now have his key. [37:17.170 --> 37:19.990] I go up to the door, beep, lets me in. [37:20.630 --> 37:20.850] What's that? [37:21.010 --> 37:21.670] Tiger team. [37:21.910 --> 37:23.050] Tiger team kind of stuff. [37:24.550 --> 37:30.390] And suddenly, the boss is going into the office at 3 o'clock in the morning and rummaging around in the R&D department. [37:31.030 --> 37:32.410] Everything is going to track back to him. [37:33.050 --> 37:35.970] Now, this is where you need to have multiple factors of authentication. [37:35.970 --> 37:48.030] If you have a security guard standing there too that sees somebody he, you know, doesn't recognize using the boss's ID, you know, they might actually stop them, you know, provided it's not just some little minimum wage job where it's there for show. [37:49.910 --> 37:58.510] Traditional keys are vulnerable too, because a lot of people will have their RFID badge, they'll have their ID badge, and, you know, the lanyard with all the keys on it. [38:00.230 --> 38:06.730] Photographing these keys, if you can do it surreptitiously, can actually reveal what the bidding is and how to replicate these keys. [38:07.110 --> 38:20.910] If you know the kind of lock that's in the door, if it's a Schlagweiser, Quickset, or, you know, higher-end, whatever, you can actually photograph and see the bidding, the bumps on the key, and know what the code is for that door. [38:21.850 --> 38:28.370] This gets really interesting when you start involving things like, oh, Safety of Democracy, with the Diebold now... [38:29.170 --> 38:30.750] What the heck's their new name? [38:31.230 --> 38:31.770] Mouses? [38:32.070 --> 38:32.470] Premier. [38:32.770 --> 38:34.570] Premier Election Systems, that's what it is. [38:35.470 --> 38:43.070] They got caught with their pants down a couple of years ago where, through their online store, you could order additional keys for the Diebold machines. [38:43.890 --> 38:45.510] But this is the actual photo. [38:45.730 --> 38:51.050] That's the actual bidding of every key for every machine out there. [38:51.190 --> 38:52.830] And it was on their web store. [38:55.030 --> 38:58.970] So, what happened was this guy saw this, and he's like, I recognize those keys. [38:59.810 --> 39:03.350] That's the same as what we used to use at the mini bars in the hotel I used to work at. [39:03.450 --> 39:04.850] I might have a few blanks around. [39:06.110 --> 39:17.830] Take, you know, gets the blanks, takes a look at this bidding, gets out a file, you know, files down to what he thinks is the approximation, sends it to some of these guys doing audits on these machines, and lo and behold... [39:20.390 --> 39:21.990] I have all sorts of fun of the videos here. [39:21.990 --> 39:25.670] You know, this is a key that never... [39:25.670 --> 39:27.130] Not from Diebold, hand cut. [39:28.030 --> 39:28.810] First drive. [39:32.760 --> 39:34.860] That's the memory card access slot. [39:35.550 --> 39:38.130] That gets access to the memory card that stores all the votes. [39:39.940 --> 39:40.480] So... [39:40.480 --> 39:41.860] Bob's passport. [39:42.520 --> 39:44.590] Bob travels internationally a lot. [39:44.900 --> 39:50.110] There are some implications, particularly if he's got the new RFID passports which have this little logo on them. [39:50.260 --> 39:51.220] How many of you have those? [39:52.840 --> 39:53.550] Most of you. [39:53.840 --> 39:54.400] A few of you. [39:55.040 --> 39:55.540] You will... [39:55.540 --> 40:00.920] Basically, there's no way to not get one in the near future because they're federally mandated. [40:00.940 --> 40:01.820] That's the new design. [40:02.630 --> 40:05.240] The encryption on these things is not very strong. [40:05.860 --> 40:07.760] They're also very easily read. [40:08.760 --> 40:22.020] The tinfoil hat solution that they came up with because when they put these out for like a request for comments, there's like 2,000 comments all against and like two for it. [40:22.550 --> 40:28.610] So, what their compromise was was, okay, we'll still have the RFID, but we'll put a metal foil layer in the front and back cover. [40:30.780 --> 40:35.260] Now, this seems like a good idea, except that it's self-defeating. [40:39.690 --> 40:51.210] I don't know if you can see, but down in the corner, the passport with the metal foil in it naturally wants to pop open about an inch, which is enough to read the data from it. [40:52.710 --> 41:01.970] So, their tinfoil hat actually is self-defeating because it increases the stiffness in the cover and it naturally wants to pop open. [41:03.730 --> 41:06.290] So, and let me just run that video once again. [41:06.510 --> 41:10.630] And you can see, he pushes it down, the data stream stops. [41:11.370 --> 41:13.290] Now it's reading, stops. [41:14.910 --> 41:15.910] Then it starts reading. [41:17.230 --> 41:18.750] Then he pushes it down again and it stops. [41:20.490 --> 41:35.870] So, if you've got this thing in a purse or a loose pocket or something like that, the whole point of the tag of the tinfoil hat to not be able to be read to have the passport not be able to be read until it's actually presented at a border is negated. [41:38.790 --> 41:44.290] There's all sorts of implications and conspiracy theories about the RFID and the passports. [41:44.530 --> 41:47.630] You have to admit, there's a very short range on these things. [41:47.870 --> 41:51.390] So, it's not like somebody's going to be reading, you know, across this room sort of thing. [41:51.470 --> 41:52.490] It has to be right next to you. [41:52.770 --> 41:55.830] The encryption could be better. [41:55.830 --> 42:02.430] They say it's a fairly long key, except that they're using factors like the passport number, which are sequential. [42:02.910 --> 42:05.730] Birth dates, which there's a very limited key space. [42:06.130 --> 42:11.190] And other bits of information that you can really narrow down the available amount of key space on these things. [42:12.270 --> 42:18.290] The other thing that is of interest, I've actually talked to the number two man in charge of passports with the U.S. [42:18.450 --> 42:18.810] State Department. [42:19.770 --> 42:28.270] There is actually no rule that says if your RFID-enabled passports RFID chip doesn't work, that they have to refuse you access to the border. [42:28.610 --> 42:35.810] You'll get increased scrutiny, but it is still a valid legal document for its... was it ten years down here? [42:36.690 --> 42:37.450] Canada's five. [42:38.530 --> 42:42.970] For ten years, that passport is still good, even if the RFID doesn't work. [42:43.390 --> 42:49.250] So, liberal application of a hammer, you know, can negate a lot of the possible issues with this. [42:49.490 --> 42:51.090] By the way, it will flee. [42:53.050 --> 42:54.550] I fell really hard. [42:58.370 --> 42:58.770] Yeah. [43:00.650 --> 43:08.810] The other thing is that... the other conspiracy theory is that, you know, oh, they'll be able to pick Americans out of a crowd for, you know, suicide bombings and stuff like this. [43:08.810 --> 43:17.930] And if anybody's ever traveled internationally to odd corners of the world, you'll generally find that most Westerners tend to stick out like a sore thumb. [43:18.170 --> 43:23.250] So, I don't need to see your passports, know that, yeah, you're probably not from around here. [43:24.310 --> 43:24.810] So... [43:26.010 --> 43:27.250] Bob has other duties. [43:27.550 --> 43:30.030] Like probably a lot of other salesmen, he works trade shows. [43:30.870 --> 43:38.290] Bob's sales depend on demos being available, working properly, showing that, you know, how wonderful they are. [43:39.690 --> 43:47.210] What happens if you have widgets that are, you know, wirelessly controlled with unauthenticated, unencrypted commands? [43:47.930 --> 43:50.510] Don't try this at home because these guys actually got banned. [43:57.970 --> 43:59.590] I don't want to try it again. [44:26.760 --> 44:27.700] Last picture. [44:43.200 --> 44:44.020] Guitar Hero. [44:51.940 --> 44:58.260] So this is where we bring on the Dancing Girls to keep you entertained for a few minutes while we just get things together. [45:05.850 --> 45:11.370] I think we are going to ignore this screen and we are going to get going on the rest, so I do apologise for the technical pitch. [45:11.910 --> 45:15.530] Let's take a look at what he got up to on his trip to Vegas. [45:17.850 --> 45:21.130] Hey Jeremy, thanks for your camera phone and thanks for your credit card. [45:21.370 --> 45:25.850] I am going to do my death and respect your money wisely and show off what your phone can do for your conference in Vegas. [45:26.470 --> 45:28.210] Mid-air, two to zero. [45:28.870 --> 45:30.690] Just lost picture one more time. [45:34.950 --> 45:37.530] One, two, three, go! [45:38.490 --> 45:42.650] And there are places that you know what you are witnessing here is broadband history. [45:59.240 --> 46:06.880] Now, that was Gizmodo going to CES show back in January and make magazine and give him a big handful of TV-B-Gones. [46:08.260 --> 46:10.240] So, infrared, something we all know. [46:10.500 --> 46:12.780] And this was, you know, the year of the television. [46:12.780 --> 46:15.840] So, there's like plasmas and LCDs everywhere. [46:16.360 --> 46:20.120] And, you know, all of these guys are wanting to show off how wonderful their product is. [46:20.580 --> 46:26.980] But, if it keeps turning off and randomly failing, it makes you wonder how many sales they may have lost because of something like that. [46:26.980 --> 46:32.180] And you have to... I don't encourage anybody to try this because, you know, look at that Motorola guy. [46:32.440 --> 46:36.120] He was standing there trying to do his job, sell his product. [46:36.900 --> 46:40.140] And, you know, some guy in the front row is screwing around with him. [46:40.260 --> 46:41.840] It's like, that's just not cool. [46:41.920 --> 46:42.320] I'm sorry. [46:42.920 --> 46:45.160] I mean, the big wall of TV is okay. [46:45.480 --> 46:45.880] That's one thing. [46:45.980 --> 46:50.300] You're actually causing somebody grief and, you know, possible lost sales and stuff like that. [46:50.620 --> 46:52.320] That's just not kosher with me. [46:52.320 --> 46:52.740] I'm sorry. [46:53.820 --> 47:00.660] Now, if you're also at a trade show, typically these guys will have laptops with them for demos, etc. [47:01.300 --> 47:05.860] This is a situation I found myself in at ShmooCon a few years ago. [47:06.800 --> 47:12.200] An unknown vendor had a laptop showing off their product, a very expensive product. [47:13.900 --> 47:16.780] I was standing in line waiting for registration to start. [47:17.240 --> 47:20.140] And, you know, I get bored easily. [47:20.140 --> 47:25.440] And I'm standing there waiting for registration to open, like, looking at their product. [47:25.600 --> 47:26.440] And I'm like, oh, that's interesting. [47:26.560 --> 47:29.680] And they got all these little USB hubs that they're giving away. [47:29.740 --> 47:30.440] They light up. [47:30.560 --> 47:32.660] And they've got them all daisy-chained together. [47:32.660 --> 47:35.580] And they need to provide power to show that they light up. [47:35.680 --> 47:37.860] So, I had them plug into the demo laptop. [47:39.440 --> 47:41.320] So, I fish it out of my pocket. [47:41.320 --> 47:44.780] And I find that I have my USB switchblade with me. [47:46.360 --> 47:57.380] Basically, what this does is upon insertion in an XP system or earlier, it auto-executes and dumps all of the passwords to the drive out of memory. [47:57.820 --> 48:00.320] It basically runs like a CD auto run. [48:01.080 --> 48:05.400] So, I had a couple of friends distract the sales guy. [48:05.880 --> 48:07.120] They've got all these hubs there. [48:07.380 --> 48:07.580] Click. [48:09.540 --> 48:09.940] Click. [48:10.440 --> 48:13.860] And I had an entire dump of all the passwords they have on the system on here. [48:15.000 --> 48:17.500] I'm not content to just go neener, neener, neener. [48:17.760 --> 48:18.720] You know, look what I got. [48:19.300 --> 48:20.340] I go for show. [48:20.700 --> 48:23.200] If you're going to make a point, you've got to make it big. [48:24.160 --> 48:29.160] So, borrowed a projector, took the log, scrubbed the passwords. [48:29.160 --> 48:31.000] It was just only the first couple of characters. [48:31.200 --> 48:32.500] I'm not a complete jerk. [48:34.640 --> 48:36.440] Borrowed a projector, set up my laptop. [48:37.960 --> 48:41.560] The booth next to them was this guy down here, actually. [48:41.940 --> 48:51.400] We spun around one of their signs and used it as a screen and proceeded to project the passwords on the screen right beside the booth of the unnamed company. [48:52.100 --> 48:59.420] And then I stood up on a chair and basically made the pronouncement that, ladies and gentlemen, remember that you are a security conference and you have to secure your ports. [48:59.680 --> 49:02.120] Not just your network ports, but your USB ports. [49:03.280 --> 49:05.040] And proceeded to explain what I had done. [49:05.640 --> 49:15.800] The best part was that the woman who was manning the booth at the time, her cohort had actually gone off to lunch and had been warning her, you know, don't connect to the network. [49:15.960 --> 49:17.360] There's a bunch of evil hackers around here. [49:17.440 --> 49:18.420] You don't know what they'll do your thing. [49:18.920 --> 49:20.320] And it was his laptop I got. [49:22.740 --> 49:27.760] Lesson learned, he basically had to report back that there was an incident. [49:27.980 --> 49:30.460] But it was a marketing laptop, so they were doing it right. [49:30.560 --> 49:33.600] It was a marketing laptop before it got connected back to the corporate network. [49:33.600 --> 49:34.500] It got scrubbed. [49:34.940 --> 49:39.800] So the only thing that was on there was, like, his personal passwords versus, like, MSN and stuff like that. [49:40.480 --> 49:44.860] But you have to think that a lot of these passwords were identical for various uses. [49:45.580 --> 49:49.020] One of these could theoretically also cover corporate assets too. [49:49.820 --> 49:55.940] So even though it never actually touched the corporate network, there's, you know, some conjecture you can make out of that. [49:57.400 --> 50:03.400] The major repercussion of this was that the guy had to admit publicly that he had done this and gotten owned. [50:04.160 --> 50:07.760] He also had to wear a big foam cowboy hat for an entire day as punishment too. [50:10.120 --> 50:11.400] So what have we done to Bob? [50:11.780 --> 50:14.580] We pwned his laptop, pwned his data, his cell phone. [50:14.580 --> 50:19.640] We pwned his wife, his keys, his demos, his ability to work. [50:20.380 --> 50:23.660] And this is all without touching the guy, just sitting across a woman in a room. [50:25.840 --> 50:28.320] So suggestions of your own, I'd love to hear them. [50:28.720 --> 50:30.280] I've got just a couple of minutes left. [50:30.920 --> 50:32.480] Anybody got anything right off the top of your head? [50:33.840 --> 50:34.080] Yep. [50:34.620 --> 50:37.560] We've got a microphone here. [50:40.710 --> 50:49.300] And also I'd like to know what you might be doing to help your users, you know, deal with this in terms of education or locking their devices down. [50:49.960 --> 50:51.140] I'm very curious about that. [50:51.140 --> 50:52.040] Well, I'm not a security pro. [50:52.190 --> 50:56.320] I just tell everybody I know and work with to take anything that transmits off. [50:56.540 --> 51:01.980] But are you familiar with the PRC 343 personal roll radio? [51:02.500 --> 51:03.020] No. [51:03.460 --> 51:04.980] Okay, it's a piece of military equipment. [51:05.290 --> 51:05.880] That's why. [51:06.190 --> 51:11.000] It's an inter-squad radio used by troops in the squad. [51:11.000 --> 51:13.750] It runs on the 2.4 gigahertz frequency. [51:14.040 --> 51:15.320] There are two families. [51:15.500 --> 51:17.440] One runs at 50 milliwatts. [51:17.620 --> 51:19.980] One runs at 100 milliwatts. [51:20.190 --> 51:23.120] It also uses Bluetooth for the push-to-talk sequence. [51:23.460 --> 51:23.980] Oh, thank you. [51:25.460 --> 51:30.640] You can get deactivated units on eBay and then reassemble them and make them work. [51:31.000 --> 51:32.060] That could be interesting. [51:33.060 --> 51:34.320] That's all I have to say. [51:34.770 --> 51:35.480] Thank you. [51:39.340 --> 51:44.060] If you don't mind finding that how to secure your Wi-Fi slide again real quick. [51:44.710 --> 51:48.900] While you're finding the Wi-Fi slide, you mentioned Motorola headsets. [51:49.650 --> 51:52.140] I actually love Motorola cell phones. [51:52.400 --> 51:54.080] How many people like their Motorola phone? [51:54.840 --> 52:02.580] I think it's great because as a frequent flyer, I find that when we land, Motorola automatically enables discoverability for the first 60 seconds. [52:02.800 --> 52:03.320] When you turn it on. [52:03.480 --> 52:05.320] As soon as you turn on the phone, it's discoverable. [52:05.420 --> 52:07.280] So the first thing I do when I turn my phone on... [52:08.680 --> 52:09.980] I look for all of you. [52:11.320 --> 52:11.980] I do too. [52:13.180 --> 52:14.760] The stopping Wi-Fi threats. [52:16.840 --> 52:17.420] There you go. [52:17.500 --> 52:17.720] There you go. [52:18.960 --> 52:19.960] I love Tor. [52:20.180 --> 52:28.000] I thanked one of the developers earlier today in his talk, but that doesn't stop you putting your pretty face on all of the emails because that stuff's incoming. [52:28.340 --> 52:30.760] You can still attack the laptop. [52:30.960 --> 52:32.240] You just can't command the middle of the data. [52:32.380 --> 52:32.500] Yeah. [52:33.120 --> 52:33.560] And... [52:33.560 --> 52:34.500] It's better than nothing. [52:34.920 --> 52:35.880] It is better than nothing. [52:35.900 --> 52:36.220] That's great. [52:36.460 --> 52:38.540] You also mentioned the firewall several times. [52:39.300 --> 52:42.340] There's a really great misnomer about firewalls. [52:42.400 --> 52:43.600] Everybody thinks, oh, I have a firewall. [52:43.760 --> 52:44.140] I'm safe. [52:44.420 --> 52:48.200] When you connect to the corporate network, you can still use file and print sharing. [52:48.820 --> 52:52.040] Your files are still accessible because it's on the local area network. [52:52.260 --> 52:58.180] Unless your firewall is configured to block people on the local area network, you're out there. [52:58.360 --> 52:59.360] You have no firewall. [53:00.040 --> 53:05.620] So just those of you that think your local area network is safe, I hope your Wi-Fi is turned off. [53:05.880 --> 53:06.080] All right. [53:06.480 --> 53:09.420] I just want to say a few things before I get punted here. [53:10.120 --> 53:11.300] Huge thanks to Rob T. [53:11.420 --> 53:12.640] Firefly, wherever he is. [53:12.760 --> 53:13.840] He did the artwork for Bob. [53:14.160 --> 53:16.760] I have no artistic skills, so thank you very much. [53:17.460 --> 53:20.000] And also, I am trying to finance this trip. [53:20.000 --> 53:26.260] So I have sets of WPA cracking tables with me, the 33 gig sets, nine DVDs, 50 bucks. [53:26.520 --> 53:27.240] I have them with me. [53:28.040 --> 53:30.440] I'm trying to basically pay for my way home. [53:30.660 --> 53:33.780] So I'll have them with me all weekend if you can help me out. [53:35.600 --> 53:37.040] Did you have a suggestion there? [53:38.300 --> 53:46.420] I was just wondering if there have been any real-world cases of people attacking smartphones, 3G edge network, that type of thing? [53:47.320 --> 53:49.000] No, not that I'm aware. [53:49.120 --> 53:53.200] Like through the Bluetooth and that, but usually not through like the 3G connection or anything like that. [53:54.880 --> 54:02.700] Blackberries though, if somebody could find a way to take the network down on command, you know those simpering piles of goo that people become when they can't get their Blackberry emails? [54:03.640 --> 54:07.420] You know, to be able to create that on command, I think, would be a truly evil thing. [54:13.340 --> 54:14.060] One minute. [54:14.260 --> 54:14.480] All right. [54:14.560 --> 54:20.740] The Google thing that was mentioned earlier, I believe it was actually the complete opposite of a secure system. [54:20.860 --> 54:28.140] It was actually Google's attempt at an Internet accelerator like Net Zero does, where it caches your Internet connections for you. [54:28.220 --> 54:32.560] But this led to a lot of websites, people being logged into each other's sessions. [54:32.560 --> 54:32.940] Okay. [54:33.360 --> 54:37.880] What I've seen looking around here is a lot of people on their Gmail accounts. [54:39.120 --> 54:40.080] Yeah, side-jacking. [54:40.320 --> 54:42.820] A lot of people who could get their session cookies grabbed. [54:43.320 --> 54:46.560] Like I said, this is by no means a complete and exhaustive list. [54:46.780 --> 54:52.840] So, I'm going to be out here and I'm going to probably head down to the mezzanine level if anybody wants to talk further, but I've got to get out of the way here. [54:53.420 --> 54:54.040] Have a good night. [54:54.180 --> 54:54.400] Thank you. [54:54.400 --> 55:21.920] Thank you.