[00:00.000 --> 00:01.760] I'm from a country very far away. [00:01.900 --> 00:02.400] I'm from Sweden. [00:03.060 --> 00:05.840] So if I yawn, it's because I'm jet-lagged. [00:06.080 --> 00:06.460] So that's it. [00:07.200 --> 00:09.260] Thank you so much for having me here. [00:09.420 --> 00:12.660] It's actually really cool to be here. [00:12.780 --> 00:15.880] I've been hacking since almost 30 years now. [00:16.780 --> 00:21.460] Back in the day when basically we had modems and not fiber connections and stuff like that. [00:22.640 --> 00:30.780] During my time as an ethical hacker, there was something that struck me, something that was a bit strange, I think. [00:31.220 --> 00:43.040] And that is that the industry itself, with all the smart people that we have, with all the money and products and everything, how come we haven't fixed the problem with cybersecurity? [00:43.400 --> 00:47.980] Why are we still vulnerable against so much stuff out there? [00:48.440 --> 00:57.420] I mean, every time I go to a red team exercise or sometimes like a pen test, I see the same crap over and over and over again. [00:57.420 --> 00:58.600] Why is that? [00:59.400 --> 01:03.160] So I took some time to just sit down and think about this. [01:03.360 --> 01:06.720] Like, what is the actual problem with cybersecurity today? [01:07.100 --> 01:10.300] So this presentation will be basically two parts. [01:10.420 --> 01:19.700] It will be a little bit of a philosophical part, explaining my vision of why we're actually vulnerable and why we are so insecure today. [01:19.700 --> 01:27.740] The second part, I'll try to demonstrate my theories by hacking my Mac OS computer with some... [01:27.740 --> 01:38.160] I wouldn't call it zero days, and I wouldn't really call it exploits, but it's abusing the system in a way that's extremely efficient. [01:38.720 --> 01:50.900] And it's in such a way that everything that I want to show, it's actually built-in functionality in Mac OS today, but you can abuse that functionality to cause some really, really, really big damage. [01:51.640 --> 01:52.800] So who am I? [01:53.260 --> 01:53.960] Well, I'm David. [01:54.440 --> 01:55.400] I'm from Sweden. [01:55.620 --> 01:57.160] I'm born 1981. [01:57.760 --> 01:59.460] I've been hacking for a long time. [01:59.680 --> 02:01.060] I've founded a few companies. [02:02.200 --> 02:03.500] I've written books. [02:03.780 --> 02:05.220] I've just done stuff like that. [02:05.220 --> 02:08.540] But my passion is red teaming and exploit development. [02:09.360 --> 02:19.080] Today, I have my own companies, but I also work for an Icelandic company called Sindes, doing pen tests and we have a SOC and incident response and stuff like that. [02:20.120 --> 02:24.860] And some of the stuff that I'm going to demonstrate today is part of this. [02:25.040 --> 02:35.080] And this is a Swedish television show that me and those other three hackers, we hacked into Swedish companies live on TV. [02:35.820 --> 02:44.220] Not to pull down their pants and say that their security sucked, but to actually show them the consequences of intrusions. [02:44.700 --> 02:50.220] Because we as an industry, we often talk about the new cool vulnerabilities and new cool things out there. [02:50.440 --> 02:58.060] Oh, now there's this race condition in open SSH and it's all dangerous and all scary. [02:58.100 --> 03:08.120] But what is the actual consequences of having a telco being hacked or a hospital or governmental institutions? [03:08.120 --> 03:12.460] What's the consequences on society when there's big breaches? [03:12.460 --> 03:14.660] We talk about password leaks. [03:15.000 --> 03:18.760] That's one consequence, but there's other types of consequences. [03:19.120 --> 03:21.920] In this TV show, we did a pretty cool hack. [03:22.100 --> 03:26.220] We hacked into this governmental institution that handles apartments. [03:26.220 --> 03:29.820] So in the local area where we live, we hacked that company. [03:30.580 --> 03:37.640] And it sounds kind of cool, you know, as a kid, in Sweden at least, when you move away from home, you're put in this queue. [03:37.880 --> 03:41.440] And this queue when you have to wait to get an apartment. [03:41.800 --> 03:45.980] And of course, the fun stuff was to hack that queue and be number one in the system. [03:45.980 --> 03:48.220] So what happened over here? [03:49.000 --> 03:51.500] OK, so we got hacked. [03:51.720 --> 03:52.280] So we did that. [03:52.400 --> 03:53.780] We hacked the queue. [03:53.960 --> 03:56.420] We were number one in the line. [03:56.600 --> 03:58.440] But that wasn't the fun part. [03:59.080 --> 04:14.980] Well, the consequences here is that if you, for example, are a female or a male, but you're running away from domestic violence, you'll be put into a housing that's controlled by the same governmental institution. [04:14.980 --> 04:18.840] And maybe you'll be given a different identity. [04:19.360 --> 04:23.720] So the perpetrator won't find who you are, where you are, where you're located, and so on. [04:24.140 --> 04:32.880] That database took us 40 minutes to get access to with really simple methods, really simple things. [04:33.060 --> 04:41.800] And that is the social consequence or social impact of cybersecurity, that you can do those kind of breaches that actually affect human lives. [04:42.500 --> 04:45.760] And that got me thinking again, why is it like that? [04:45.940 --> 04:52.060] Why have cybersecurity became such a problem that digital problems affect real lives? [04:52.060 --> 04:55.380] And why have we not been better at fixing this problem? [04:56.240 --> 05:01.340] Because where I come from, a lot of people say this, I have nothing to hide. [05:02.080 --> 05:03.320] Who wants to hack me? [05:03.480 --> 05:04.180] I'm not important. [05:05.140 --> 05:17.560] But when you see that, when from a psychology point of view, when you say, I have nothing to hide, no one wants to hack me, I'm not important, you automatically lower the bar, and you just don't give a crap. [05:17.880 --> 05:19.280] Then it's up for grabs. [05:19.480 --> 05:21.900] Then you just basically say, I don't care. [05:22.300 --> 05:23.320] Anyone can hack me. [05:24.120 --> 05:28.420] And that's a problem that you don't understand, that you are part of this. [05:28.580 --> 05:42.820] If you can get hacked, someone can get access to your information, even if that's your password to a Netflix account, or your password to a Spotify account, or whatever kind of basically not important system, that's part of the digital economy. [05:42.920 --> 05:47.340] That's a part of the underground economy that then feeds other types of hackers. [05:47.380 --> 05:54.760] And they buy you, they sell your Netflix account, and they can buy infrastructure that then can do DDoS attacks or any other kind of things. [05:54.880 --> 05:56.800] It is part of that ecosystem. [05:57.520 --> 06:09.720] And we have to understand that as, I mean, I guess everyone in this room understands it, but I'm talking about everyone else out there who are not a security person, who do not think about privacy, who doesn't think about the digital life we live in. [06:10.280 --> 06:15.860] But I want to explain a little bit about how I see computer security, from my experience, from what I've done. [06:16.080 --> 06:17.160] And I started with myself. [06:17.300 --> 06:17.760] This is me. [06:18.580 --> 06:20.380] I love computer security. [06:20.540 --> 06:25.680] I love encryption, firewalls, coding, you know, exploiting stuff. [06:25.680 --> 06:26.540] I love that. [06:26.620 --> 06:28.320] I have a really good passion for that. [06:28.540 --> 06:41.400] The problem is that when I talk about computer security, in general, my friends, my family, other people are not in the industry, they don't get it. [06:41.640 --> 06:43.880] They have no idea what I'm talking about. [06:44.100 --> 06:48.080] They can hear my words, but they don't know what I'm saying. [06:48.300 --> 06:49.680] They don't really know what I'm saying. [06:50.020 --> 07:00.100] And it feels like every time I try to do something good, I try to tell them, for example, simple thing as, do not have the same password everywhere, right? [07:00.660 --> 07:03.660] It seems like no one gives a flying crap. [07:03.820 --> 07:06.140] They don't care about anything. [07:06.740 --> 07:10.100] How do we get the people to actually care about cyber security? [07:10.980 --> 07:11.460] You know? [07:11.660 --> 07:16.000] And I also hear this so many times, that cyber security is expensive. [07:16.980 --> 07:18.700] Cyber security costs a lot of money. [07:18.780 --> 07:20.080] Now, licenses cost money. [07:20.720 --> 07:21.720] Hardware costs money. [07:21.880 --> 07:24.520] But cyber security doesn't really cost that much money. [07:24.780 --> 07:29.780] Because for me, it's a psychology problem. [07:29.900 --> 07:32.100] It's like the way you think, the way you protect yourself. [07:32.340 --> 07:34.940] But we've actually messed up in the industry. [07:36.340 --> 07:41.720] Imagine that a bicycle helmet would cost $500. [07:43.140 --> 07:44.820] Would you buy a bicycle helmet? [07:45.860 --> 07:46.880] Of course not. [07:46.880 --> 07:48.780] Or a fire alarm in your house. [07:49.580 --> 07:50.180] $500. [07:51.180 --> 08:00.440] In the physical world, we figured out that to actually build security in our physical world, we have to have a model that works for everybody. [08:00.840 --> 08:03.840] But cyber security today, it's a luxury. [08:04.360 --> 08:06.980] It's a luxury when it comes to pricing of things. [08:07.140 --> 08:09.480] But it's also luxury when it comes to knowledge. [08:09.940 --> 08:11.760] Very few people actually get it. [08:12.380 --> 08:14.180] And we are part of those few people. [08:14.840 --> 08:18.180] But the rest out there, they don't really get it. [08:18.580 --> 08:19.800] And that is a problem. [08:20.140 --> 08:30.860] And we as an industry, we've been talking about security in a way that actually doesn't really make sense because we've been trying to sell security basically in the wrong way. [08:31.760 --> 08:35.000] Like here, this is kind of what we do with cybersecurity. [08:35.600 --> 08:37.680] We implement multi-factor authentication. [08:37.800 --> 08:39.600] We buy firewalls. [08:39.680 --> 08:40.400] We have antivirus. [08:40.540 --> 08:41.440] We have patch management. [08:41.580 --> 08:42.760] We have all these different things. [08:43.000 --> 08:46.400] But even with all those things, we get hacked. [08:46.820 --> 08:51.340] Kind of like here, what's the actual protection here? [08:51.680 --> 08:56.140] So you have the lock to the stand. [08:57.080 --> 08:59.120] But what does the lock actually secure? [09:00.220 --> 09:01.220] The front wheel. [09:02.040 --> 09:03.460] Not the rest of the device. [09:04.040 --> 09:05.860] And that's how we implement security. [09:06.060 --> 09:10.120] So if you, for example, think that multi-factor authentication is the best thing on the planet. [09:10.660 --> 09:11.960] I would say that you're wrong. [09:12.740 --> 09:14.280] It solves a problem. [09:14.720 --> 09:16.520] But it doesn't solve the problem. [09:17.000 --> 09:18.280] I'll give you one example. [09:18.280 --> 09:23.460] So with multi-factor authentication, we figure out the passwords are bad. [09:24.000 --> 09:24.080] Right? [09:24.820 --> 09:27.120] So we have to have another method. [09:27.340 --> 09:29.800] Instead of just password, we need another method to log in. [09:29.940 --> 09:32.060] So we add another factor for that. [09:33.040 --> 09:36.200] But I don't care if you have 10-factor authentication. [09:36.740 --> 09:40.780] After you logged in, you have a session token that's stored in the application. [09:41.020 --> 09:44.360] If you don't secure that token, then it doesn't really matter. [09:44.760 --> 09:49.760] The only thing that you actually secured is the amount of times you have to log in to be able to access that service. [09:51.160 --> 09:53.420] This is the problem that we're experiencing now. [09:53.560 --> 09:57.640] That we're giving, I shouldn't say false security, but we're telling people this is good. [09:57.880 --> 10:04.340] But we're not telling them how to use that security product or that security service in a way that actually makes sense. [10:04.560 --> 10:09.920] Because there's other things that they have to do besides just installing, for example, multi-factor authentication. [10:10.540 --> 10:11.600] There's other things. [10:11.780 --> 10:16.320] And if you don't do those other things, then you will not achieve the same security as you really want. [10:17.080 --> 10:20.940] And we, as an industry, we keep talking about the cool new stuff. [10:21.300 --> 10:22.700] We talk about AI. [10:23.160 --> 10:26.480] We talk about new types of exploitation techniques. [10:26.860 --> 10:30.940] We talk about different kind of threat actors, APT groups, and so on. [10:31.820 --> 10:41.520] But at the end, if we look at the actual tools and the actual methods that cybercriminals use to compromise systems, they're not really groundbreaking. [10:41.520 --> 10:48.880] That's like the 1%, not even maybe 1% of all the attacks out there are from a zero-day exploit. [10:50.220 --> 10:51.700] It's very simple stuff. [10:52.280 --> 10:56.200] So we have to start talking about where the attack is actually coming from. [10:56.340 --> 11:00.680] Like this guy, how is he going to protect himself if he doesn't understand where the attack is coming from? [11:01.380 --> 11:02.260] He cannot. [11:02.760 --> 11:04.840] It's impossible, right? [11:05.500 --> 11:06.980] And the same thing with us. [11:07.100 --> 11:11.400] If we don't understand where the attack is actually coming from, we cannot really secure ourselves. [11:12.300 --> 11:14.140] And we do good things. [11:14.580 --> 11:27.040] But again, if the solution that we are implementing is not actually designed for the problem that we're trying to solve, like I did this example with the multi-factor authentication, it doesn't give us anything. [11:27.600 --> 11:31.020] Like the person here bought a padlock for this gate. [11:31.500 --> 11:32.760] Nothing wrong with that. [11:32.880 --> 11:36.200] But the padlock is not designed specifically for that gate. [11:36.500 --> 11:38.700] So the person gets zero security. [11:40.020 --> 11:57.160] And this is what I see when I do my pen testing and when I do my red team exercises out there, is that we have implemented a lot of cool things, but no one really understands how that technology works, which actually results that we're having less security than we think we have. [11:57.300 --> 11:58.460] And we get compromised. [11:58.780 --> 12:01.640] And when we get compromised, we're a bunch of crybabies. [12:01.800 --> 12:03.260] We get sad and upset. [12:04.060 --> 12:08.000] And that's my negative view on the cybersecurity industry. [12:08.620 --> 12:11.620] I don't know what you guys, do you agree with my view of the cybersecurity industry? [12:12.140 --> 12:12.860] Yes or no? [12:12.940 --> 12:13.420] Who agrees? [12:13.620 --> 12:14.580] Raise your hand if you agree. [12:15.880 --> 12:23.460] Okay, so more than half of the audience do you agree that what we're doing right now at this moment is basically wrong. [12:23.620 --> 12:28.500] That we have to change the way we do things, because otherwise we will not achieve the result that we want to have. [12:29.580 --> 12:30.620] How do we do that? [12:31.400 --> 12:32.540] How do we fix that? [12:33.700 --> 12:37.800] Well, I think one problem is the way we talk about things. [12:38.120 --> 12:40.600] How we actually communicate about cybersecurity. [12:43.300 --> 12:45.560] And rhetoric is the Swedish word for it. [12:45.640 --> 12:47.140] I don't know the English word for it. [12:47.260 --> 12:48.240] The way we communicate. [12:48.460 --> 12:49.480] What was the English word for it? [12:52.120 --> 12:52.500] Okay. [12:53.640 --> 12:59.420] It's just like, when you talk about, for example, digital transformation, or you talk about things in the security industry. [13:01.380 --> 13:03.340] The problem is that people don't understand it. [13:03.440 --> 13:10.720] And I think this word that I hear all the time, at least in Sweden, oh, we have to do transformation. [13:10.720 --> 13:12.000] We have to be more digital. [13:12.160 --> 13:13.240] We have to evolve. [13:13.420 --> 13:15.780] We have to do things in different ways. [13:15.980 --> 13:21.220] And people talk about DNS and API and stuff that they actually have no idea what they're actually doing. [13:21.820 --> 13:31.760] But for me, technology and specifically transformation is not a question about which technology that you should use in a project or in an implementation. [13:32.340 --> 13:36.200] For me, digital transformation is something completely different. [13:36.460 --> 13:49.180] But in every single discussion that I hear in every development project or at boards and stuff like that, they talk about, oh, should we use this technology or should we do use that technology? [13:49.500 --> 13:53.200] But it's never a conversation about change. [13:53.820 --> 13:55.320] About change management. [13:56.180 --> 14:06.140] Again, with the multi-factor authentication, it could be part of your digital transformation process to add extra security layers inside an organization or to an application or a service. [14:06.880 --> 14:15.580] But if you're not teaching the people about change, about how to use that new feature, that new thing, they have no clue. [14:16.600 --> 14:19.100] And this is really what got me thinking. [14:19.540 --> 14:20.900] Like I have two kids. [14:21.220 --> 14:23.400] My daughter is 15 and my son is 11. [14:23.900 --> 14:29.220] They got their first iPhones when they were about eight years old, almost like that. [14:30.640 --> 14:35.720] And I look at them in the same way as I look at my employees. [14:36.560 --> 14:39.940] And that is when they were eight and they got their first iPhone. [14:41.740 --> 14:45.420] I told them like, oh, now congratulations, you have access to your iPhone. [14:45.860 --> 14:52.940] And the first thing that they did was play video games or look at YouTube or social media and stuff like that. [14:53.420 --> 14:55.380] And I was angry. [14:55.520 --> 14:56.680] I was like, that's not a toy. [14:56.840 --> 14:57.420] It's not a toy. [14:57.500 --> 14:58.000] It's a phone. [14:58.560 --> 15:00.300] They have no idea what a phone is. [15:01.020 --> 15:01.560] Not really. [15:01.640 --> 15:04.580] They don't use the phone that they have to call people. [15:05.480 --> 15:06.280] They don't. [15:06.400 --> 15:10.300] They use it to text and to do social media and stuff like that. [15:10.720 --> 15:14.400] And this is exactly what I'm seeing when I go to organizations. [15:15.220 --> 15:22.080] And we have all these employees that basically have zero training in technology. [15:22.280 --> 15:30.880] And we give them computers and email addresses and VPN connections and phones and stuff without telling them what it is. [15:31.180 --> 15:37.160] They have access to all these different services, but no one actually told them about technology. [15:37.880 --> 15:39.280] They're not like us. [15:39.440 --> 15:43.660] They don't like technology, but they have access to technology. [15:44.680 --> 15:52.860] It's like, imagine a world where you have a lot of cars, but no one is allowed to have a driver's license. [15:53.640 --> 15:57.620] Everything that you're able to secure is the device itself, the car itself. [15:58.940 --> 16:00.580] But no driver's license. [16:02.100 --> 16:04.120] That's how I see our users today. [16:04.360 --> 16:08.420] They don't have the so-called driver's license for their computers, right? [16:09.380 --> 16:16.580] But we're trying to add all these different layers in the technology to build security. [16:17.200 --> 16:19.720] But they have no idea what they're really doing. [16:19.940 --> 16:24.680] They have 100% trust in the technology that the technology would work. [16:25.840 --> 16:35.820] And from a history point of view, when you look at transformation, you look like if you go back in time and you go back way, way, way back, you go back to the Stone Age. [16:36.480 --> 16:37.680] We had transformation. [16:37.940 --> 16:40.580] We didn't have digital transformation, but we had transformation. [16:40.920 --> 16:41.940] We were innovative. [16:42.120 --> 16:43.980] We were creative at the Stone Age. [16:44.120 --> 16:46.900] But the Stone Age lasted about 3.4 million years. [16:47.380 --> 16:54.200] So we as humans, we have 3.4 million years to adopt to the things that we developed, the things that we created. [16:54.640 --> 16:55.920] 3.4 million years. [16:56.240 --> 16:57.060] That's a long time. [16:57.380 --> 17:03.340] And then if you look at the Bronze Age, that's only In the Iron Age, 700 years. [17:04.040 --> 17:14.260] And the Industrial Revolution, which was actually three different revolutions, adding together about 150 years of evolution or transformation. [17:14.800 --> 17:31.740] We did a lot of cool things, but what's happening here with every new time era that we're entering is that it's becoming shorter and shorter and shorter, but we're creating and innovating even more technology because we're accumulating the knowledge from the past into each new era. [17:32.880 --> 17:39.560] And how long has the digital age, digital evolution, digital revolution, call it what you want, how long has that one lasted? [17:39.980 --> 17:41.680] The world that we're in right now. [17:43.280 --> 17:47.080] How long have we had the digital age? [17:49.120 --> 17:49.800] Say again? [17:50.200 --> 17:52.000] 30 years? [17:53.740 --> 17:54.220] 50? [17:54.540 --> 17:55.580] I wouldn't agree with 50. [17:55.760 --> 17:57.780] I'm more like 30, maybe even 25. [17:58.200 --> 18:02.560] Because I'm not talking about when you had a pocket calculator or you had a Commodore 64 at home. [18:02.700 --> 18:03.800] I'm not talking about that time. [18:03.900 --> 18:14.060] I'm talking about when we have the world that we live in right now with emails and services and streaming and that kind of technology. [18:15.180 --> 18:15.660] 2000. [18:16.060 --> 18:17.780] Yeah, but that's about 25 years, right? [18:18.380 --> 18:21.640] So that's when the digital age started, 25 years ago. [18:22.260 --> 18:25.420] Coming from Sweden, we have a company called Volvo. [18:25.560 --> 18:26.340] Maybe you heard about it. [18:26.800 --> 18:28.800] Volvo did a cool thing a few years ago. [18:29.100 --> 18:30.160] Many years ago. [18:30.380 --> 18:32.320] They basically invented the seatbelt. [18:32.880 --> 18:34.760] They enforced the seatbelt in cars. [18:35.020 --> 18:41.620] How many years did it take for Volvo to enforce seatbelts in the car after the car was invented? [18:45.410 --> 18:46.350] 50 years. [18:47.830 --> 18:48.670] So 50 years. [18:48.830 --> 18:52.870] That's twice the time that we lived in the digital era that we live in right now. [18:53.910 --> 19:00.210] When you think about time and transformation, it becomes kind of interesting. [19:00.390 --> 19:05.430] We've only had the digital world that we live in about 25 years. [19:05.710 --> 19:12.910] We here in this room, we're the first generation of people who experience the things that we do right now. [19:13.310 --> 19:14.810] We're the first generation. [19:15.070 --> 19:19.590] A lot of people in this room did not have this kind of technology when you grew up. [19:19.970 --> 19:22.090] We have to learn during this time. [19:22.550 --> 19:30.190] The problem here is that we created something that we are now dependent on. [19:30.910 --> 19:33.570] 100% dependent on this technology. [19:34.390 --> 19:41.050] And not even us, we have full understanding of what this technology actually can do for us and what it is. [19:42.830 --> 19:57.590] And if it took them 50 years to get some kind of easy security in cars, isn't it unrealistic that we should actually have the type of security that we are aiming for in something that we've only had for about 25, 30 years? [20:00.070 --> 20:13.010] Some of the system that's running in our environment, our critical infrastructure today, they are... that system that was developed and created in the 1980s, that's still out there in our infrastructure today. [20:14.050 --> 20:15.650] And we think about it. [20:15.750 --> 20:19.090] When we developed stuff in the 1980s, didn't we do a lot of the wrong things? [20:19.870 --> 20:28.010] The simple things like buffer overflows in code and we had like... there were so... I mean, just access control back in the days was terrible. [20:28.930 --> 20:29.710] Extremely terrible. [20:29.710 --> 20:29.830] Extremely terrible. [20:30.290 --> 20:37.210] And we have system running that really bad, crappy code out there in our infrastructure that we cannot maintain. [20:37.210 --> 20:40.830] We cannot do anything with that because we don't have the knowledge to that. [20:40.930 --> 20:43.210] We already moved on to something else. [20:44.710 --> 20:46.710] That is, I think, a big problem. [20:46.830 --> 20:49.350] And we will look back at our time today. [20:49.350 --> 20:58.830] We will look back at us and say, you know, in the year of 2000 and 2024 or whenever, we were so stupid. [20:59.170 --> 21:01.790] Our users, they could choose their own passwords. [21:04.150 --> 21:05.870] Why do we even allow that? [21:06.250 --> 21:08.110] We just know it's devastating. [21:08.290 --> 21:09.110] We know it's bad. [21:09.590 --> 21:11.010] We haven't figured that out. [21:11.230 --> 21:15.770] So what I'm trying to say is that we just entered the digital era. [21:15.930 --> 21:22.050] And what's fascinating here, I think, is that the digital age that I'm talking about, that's already gone. [21:23.530 --> 21:24.850] NVIDIA messed it up. [21:26.930 --> 21:28.490] No, but now we have AI. [21:29.230 --> 21:34.070] AI will change humanity more than the Internet has ever done. [21:35.270 --> 21:36.070] It will. [21:38.050 --> 21:41.790] We're already moving into the next phase, whatever that is. [21:42.010 --> 21:43.290] I don't even know what that is. [21:43.730 --> 21:46.850] So what we've tried to accomplish here is gone. [21:46.850 --> 21:59.690] And when I was looking at this and thinking about these things, what was also fascinating is that we basically did... [22:00.410 --> 22:03.370] We talked about digital transformation, but we transformed humans. [22:04.530 --> 22:07.390] You can take basically any human... [22:07.930 --> 22:09.270] I don't know what to call it. [22:09.350 --> 22:15.850] Any human emotion, feeling, an artifact that you define as human. [22:16.070 --> 22:22.550] And there will be a digital app or functionality or something for that emotion. [22:23.090 --> 22:24.170] Dating, for example. [22:24.470 --> 22:25.370] How do you date today? [22:26.030 --> 22:30.090] Maybe you'll date at HOPE for these next two days or three days. [22:30.350 --> 22:30.990] I don't know. [22:31.330 --> 22:32.450] Mostly it's digital apps. [22:32.710 --> 22:34.790] It's those kind of, you know, dating apps, right? [22:35.970 --> 22:38.210] Or, I don't know, Facebook, LinkedIn. [22:38.630 --> 22:41.690] I don't know how people date these days, but it's digital. [22:42.070 --> 22:42.250] You know? [22:43.930 --> 22:44.330] Shopping. [22:44.430 --> 22:45.110] Do you shop online? [22:46.990 --> 22:47.570] I do. [22:47.750 --> 22:48.330] All the time. [22:48.770 --> 22:49.490] All the time. [22:49.630 --> 22:50.770] Just shopping online all the time. [22:51.670 --> 22:52.930] I'll skip that one. [22:53.210 --> 22:54.490] I'll save that one for the last one. [22:54.610 --> 22:57.270] I knew that you were like, please, please talk about that one. [22:57.270 --> 23:00.210] But communication, the way we communicate. [23:00.490 --> 23:05.810] I mean, when I look at my children today who are 15 and 11 years old, they don't know how to communicate. [23:06.850 --> 23:07.550] Not really. [23:08.910 --> 23:14.350] They do not know how to actually have eye contact with someone, pick up the phone and order pizza at a pizza place. [23:14.510 --> 23:15.670] They have no idea. [23:15.950 --> 23:19.270] They want to be able to order something in an app or send a text message. [23:19.670 --> 23:22.030] They do not know how that works. [23:22.730 --> 23:25.010] And then we have election and critical infrastructure. [23:25.010 --> 23:26.890] I'm talking about the social impact, everything. [23:27.170 --> 23:35.030] Like, if my kids are sick, I have to go to an app on the phone and tell them, tell the schools and everything that they're sick. [23:35.910 --> 23:38.170] I cannot, I just, there's no other way. [23:38.390 --> 23:43.290] Everything that affects me in my life, there is an app or a website or something. [23:43.810 --> 23:46.210] I mean, try to live a life without an email address. [23:46.570 --> 23:47.330] Have you tried that? [23:48.250 --> 23:48.990] Good luck. [23:50.470 --> 23:52.110] But this is the world that we live in. [23:52.330 --> 23:53.790] And then the way we work. [23:53.790 --> 24:04.010] I mean, COVID-19 really, really took, you know, accelerated that, that, you know, development of working from home and so on. [24:05.590 --> 24:08.730] People in Sweden, at least, they don't work at offices, really. [24:09.750 --> 24:15.530] It's very common that you spend at least half of your time at home, working or remote or wherever we are. [24:15.650 --> 24:16.770] I don't, I don't know where people are. [24:20.690 --> 24:23.270] Maybe consume knowledge is also weird. [24:23.270 --> 24:25.930] My kids, they don't even know how to read. [24:27.590 --> 24:28.570] No, they don't. [24:28.730 --> 24:30.670] They know words, they know letters. [24:31.730 --> 24:33.790] But they don't know how to read a book. [24:34.170 --> 24:39.030] They consume knowledge through TikTok and YouTube and stuff like that. [24:39.030 --> 24:39.810] That's how they learn. [24:40.050 --> 24:41.570] Of course, they know how to read. [24:41.810 --> 24:42.670] They know how to read. [24:43.390 --> 24:44.310] But not really. [24:44.610 --> 24:45.050] They will know. [24:45.170 --> 24:54.310] If I give them a book or I give them a paper with instructions, they have difficulties understanding that stuff that's written in text. [24:55.270 --> 24:57.550] And I'm not saying this is right or wrong. [24:57.670 --> 24:59.750] I'm just saying this is, this is how I see it. [25:00.210 --> 25:02.710] This is my perspective on things. [25:04.710 --> 25:15.210] And I remember a time when, you know, when I was a kid and my parents had guests over, we were sitting at the dining table, talking about whatever kind of nonsense, right? [25:15.510 --> 25:22.510] And I can hear the adults having a conversation, an argument about, I don't know, how far is it from Copenhagen to Stockholm? [25:22.750 --> 25:24.790] I don't know, whatever kind of stupid argument they were having. [25:24.950 --> 25:27.610] And no one knew the answer because no one could Google that stuff. [25:28.350 --> 25:29.130] No one knew. [25:29.870 --> 25:38.870] And they just kept, I mean, it was just like, we didn't know who would win because you couldn't pick up the phone and just Google that stuff and have an answer within a few seconds. [25:39.290 --> 25:44.630] So then, you know, the next time they showed up six months later, then they would actually, someone actually looked it up. [25:44.730 --> 25:46.550] I don't know how, through some book or whatever. [25:46.910 --> 25:52.530] Then you would find out how far it was from Copenhagen to Stockholm or whatever kind of stupid thing they were arguing about, you know? [25:53.410 --> 25:55.190] That's not how we do it today. [25:56.090 --> 25:56.790] Think about yourself. [25:56.970 --> 26:04.330] How many times do you pick up your phone and just Google something when talking about whatever with a friend or a colleague or a family member? [26:04.750 --> 26:05.610] Quite often, right? [26:05.730 --> 26:06.590] We do it all the time. [26:06.870 --> 26:09.650] So we are very dependent on this technology. [26:10.190 --> 26:11.890] And again, my daughter is 15. [26:12.810 --> 26:13.950] The sexual stuff. [26:14.730 --> 26:16.290] This is also weird. [26:16.510 --> 26:20.730] It, you know, growing up, at least in Sweden, I don't know how it is in America. [26:21.110 --> 26:30.130] And sorry if I offend some people talking about this right now, but growing up as, you know, being a teenager in Sweden, you were so full of hormones, you know? [26:30.250 --> 26:31.550] You couldn't really stand still. [26:31.750 --> 26:38.750] That everything that you were thinking about is some kind of nudity or girls or whatever kind of whatever thing that you're into, right? [26:38.890 --> 26:41.170] But you were just full of stuff. [26:41.450 --> 26:44.550] Just, you know, everything that you thought about. [26:44.710 --> 26:47.050] Like, you collected, you summoned your friends. [26:47.050 --> 26:50.370] Like, after school, like, dudes, let's find it. [26:50.370 --> 26:55.750] And in Sweden, there's something called forest porn, okay? [26:56.770 --> 27:02.070] Forest porn is dirty magazines that someone placed somewhere in the forest. [27:02.710 --> 27:06.490] I don't know if you guys have it here in the U.S., but we have it. [27:06.750 --> 27:10.790] And it's like, it was almost like going on a treasure hunt, you know? [27:11.250 --> 27:21.750] You collected your friends and you're like, oh, then those magazines, they've been outside in snow, in rain, in wind for years. [27:22.050 --> 27:25.950] And once you found them, you had no idea what you were actually looking at. [27:26.210 --> 27:26.870] No idea. [27:27.310 --> 27:29.090] You just knew that was the treasure. [27:30.650 --> 27:33.410] And that kind of behavior, we don't have that today. [27:33.810 --> 27:44.050] Because right now, our kids can, again, take up the phones and they will have access to all that kind of material that might be interested if you're a teenager within a few seconds. [27:44.830 --> 27:46.730] Things change in our behavior. [27:46.950 --> 27:52.750] We kind of digitalize the way we work as humans, which I think is a little bit strange. [27:53.370 --> 27:57.150] And then, at the end of the day, we come home. [27:57.810 --> 28:01.030] We're depressed, because our life sucks. [28:01.590 --> 28:04.910] And then we install an app on the phone to talk to a digital shrink. [28:07.150 --> 28:10.030] I don't know if this is a world I want to live in. [28:10.430 --> 28:20.230] But when I think about that, and I try to apply that, you know, on companies and organizations, I feel it is about the same thing, right? [28:20.230 --> 28:23.190] We have really no clue on what we're doing. [28:23.750 --> 28:30.490] And we've basically eliminated something that's really important for us as humans, which is trust. [28:31.650 --> 28:36.870] Because if you look at the type frame, a normal time frame, it's basically a horizontal line. [28:37.390 --> 28:41.110] But for the first time in history, this is how, this is my personal opinion. [28:41.690 --> 28:44.890] We've created a pyramid timeline. [28:45.130 --> 28:47.130] It's not horizontal anymore, it's a pyramid. [28:47.650 --> 28:56.710] And that's because in the 1950s, when we did get these pocket calculators, and we had all these transistor radios and all that stuff that we started to develop things, it was really good. [28:57.130 --> 29:02.590] The digital transformation, the digital history that we have is amazing, because we were able to save lives. [29:02.810 --> 29:06.390] We were able to share, you know, information between borders, between countries. [29:06.390 --> 29:10.550] We were able to share news from whatever country to a different country. [29:11.370 --> 29:13.590] You could share your medical records. [29:13.790 --> 29:15.110] You could share all these different things. [29:15.230 --> 29:17.470] We started to enable people to buy things. [29:17.630 --> 29:21.050] We enabled people to communicate with each other and so on. [29:21.270 --> 29:27.010] But if I ask you today, if I ask you today, do you trust the Internet? [29:28.750 --> 29:29.930] Do you trust it? [29:30.150 --> 29:32.130] Do you think it's a good thing? [29:32.130 --> 29:37.010] Do you have faith in the Internet, in that kind of technology that we live in right now? [29:37.890 --> 29:38.930] 50-50, yeah? [29:39.170 --> 29:41.190] You're doing that and saying 50-50. [29:41.410 --> 29:42.290] That means no. [29:42.810 --> 29:44.110] You said 50-50. [29:44.410 --> 29:45.190] You said... [29:51.340 --> 29:51.820] Yeah. [29:52.860 --> 29:58.920] So we are dependent on something that is basically broken and needs to be fixed. [29:59.460 --> 30:00.840] But we're fully dependent. [30:00.900 --> 30:03.960] As you said, you might not like it, but you just have to use it. [30:05.220 --> 30:08.240] And for me, that's the first time in history that this has ever happened. [30:08.340 --> 30:09.520] That you are part of something. [30:09.640 --> 30:13.260] That you live a life and you're based on something that you really don't... [30:13.260 --> 30:17.020] I don't know if trust is the right word, but it is, you know... [30:17.520 --> 30:20.280] We don't really have faith in the Internet. [30:20.980 --> 30:21.880] Maybe not faith. [30:22.760 --> 30:24.300] That's maybe not the right word either. [30:24.480 --> 30:24.840] It's just... [30:24.840 --> 30:25.800] It's broken. [30:25.800 --> 30:27.320] We have to fix it at least, right? [30:28.180 --> 30:28.560] And... [30:30.560 --> 30:32.840] You know, when you then... [30:32.840 --> 30:36.460] When we just identified that the Internet is broken, it is crap. [30:38.020 --> 30:39.480] What kind of attacks... [30:39.480 --> 30:42.560] What kind of things do we actually define as broken, you know? [30:42.740 --> 30:44.500] Of course, we can talk about privacy. [30:44.680 --> 30:45.940] We can talk about all these different things. [30:46.080 --> 30:50.080] And I guarantee you that a lot of speakers will talk about these things as well. [30:50.080 --> 30:52.260] But how does the hackers actually do it? [30:52.360 --> 30:56.100] What are they actually exploiting to gain access to systems? [30:56.640 --> 30:58.640] And this is something that I think is kind of interesting. [30:59.520 --> 30:59.960] So... [31:00.420 --> 31:00.860] Passwords. [31:00.980 --> 31:02.380] We know that passwords is a problem, right? [31:02.880 --> 31:06.880] We just heard about the RockU2024 database that's released. [31:08.060 --> 31:12.380] But the funny thing with passwords is that we know they're broken. [31:12.520 --> 31:13.600] We don't trust them, really. [31:13.820 --> 31:15.680] But we're, again, fully dependent on them. [31:16.220 --> 31:23.900] And specifically passwords is interesting because they are aligned with policies and other types of soft things that we have there. [31:24.080 --> 31:25.340] I'll cover that later on. [31:25.860 --> 31:29.500] But hackers also exploit platform data, you know? [31:29.640 --> 31:31.920] I'm talking about APIs. [31:32.220 --> 31:35.720] I'm talking about, you know, cloud services and stuff like that. [31:37.100 --> 31:37.580] And... [31:38.620 --> 31:39.420] Device data. [31:39.700 --> 31:41.920] This is, I think, is very interesting, at least. [31:42.140 --> 31:46.480] What would you say if I would tell you that I had a solution to ransomware attacks? [31:48.220 --> 31:49.360] Nah, right? [31:50.000 --> 31:52.820] But when you think about it, I don't have the solution to ransomware attack. [31:53.000 --> 31:53.600] But think about it. [31:54.020 --> 31:58.560] What kind of mechanism is ransomware code dependent on? [31:59.480 --> 31:59.900] Bitcoin. [32:00.540 --> 32:02.280] Bitcoin is not what I'm thinking about. [32:02.460 --> 32:05.620] I'm thinking about stuff like PowerShell or Python and stuff like that. [32:05.620 --> 32:12.860] So in our devices, in my desktop right here, how much has my desktop changed? [32:12.960 --> 32:16.540] From a technical point of view, how much has it changed in the 1980s? [32:17.240 --> 32:17.760] Zero. [32:18.240 --> 32:18.760] Exactly. [32:19.200 --> 32:20.700] It changed zero. [32:21.380 --> 32:23.800] So you still have an underlying operating system. [32:23.900 --> 32:25.400] And then you have a graphical user interface. [32:25.520 --> 32:26.200] And then you have icons. [32:26.400 --> 32:28.740] And then you have the communication layers like Internet and whatever. [32:28.740 --> 32:29.060] Right? [32:31.600 --> 32:36.560] The devices here are not designed for the world that we actually live in right now. [32:37.280 --> 32:38.560] That is a big problem. [32:39.380 --> 32:44.220] If you didn't have the underlying operating system, which very few people actually need. [32:44.320 --> 32:46.420] If you think about everyone else, not the people in this room. [32:46.680 --> 32:48.400] Think about everyone else that works in an office. [32:48.520 --> 32:52.220] How often do you think they open up a terminal and start writing commands in that terminal? [32:53.160 --> 32:53.560] Never. [32:54.440 --> 32:54.840] Exactly. [32:55.140 --> 32:55.340] Never. [32:55.600 --> 32:56.860] So why do we need that? [32:57.020 --> 32:57.840] Why do we even have that? [32:57.840 --> 33:02.480] Why do we give that functionality to all the users when they do not need that? [33:02.700 --> 33:06.680] How many times have you ever heard about a ransom attack on an iPhone or an Android phone? [33:07.600 --> 33:08.040] Never. [33:08.820 --> 33:09.320] Is it different? [33:09.480 --> 33:12.200] These are designed for the world that we live in. [33:13.460 --> 33:15.360] They are designed as apps. [33:15.620 --> 33:17.900] They communicate with APIs and so on. [33:18.020 --> 33:20.780] There's no real terminal that we use here, right? [33:21.380 --> 33:21.780] Not really. [33:22.280 --> 33:23.600] But the computer still has. [33:24.400 --> 33:29.160] And then we also have software, exploits, vulnerabilities. [33:29.600 --> 33:32.700] But the implementations, I think the implementation is very interesting. [33:33.020 --> 33:39.720] Because the way we implement things and the way security is enforced in our organizations are a bit crazy. [33:40.660 --> 33:43.720] Basically, all companies out there, they have a security policy. [33:43.720 --> 33:48.600] And the easiest thing to talk about when it comes to security policies is let's talk about passwords. [33:49.040 --> 33:50.160] Because I think that's just fun. [33:51.060 --> 33:59.480] The typical password policy is that the password should have a capital letter, just numbers, should have special characters and has to be, I don't know, 12 characters long or whatever, right? [34:00.080 --> 34:00.580] That's typical. [34:00.900 --> 34:02.640] Where do you enforce that policy? [34:02.640 --> 34:05.380] Where is that policy actually enforced? [34:05.560 --> 34:07.280] Which technology is it enforcing? [34:07.880 --> 34:11.520] Most likely, the Active Directory or some kind of service. [34:11.700 --> 34:17.320] It's the devices itself that's enforcing the technology that we have to live after. [34:18.280 --> 34:23.120] But again, if you, for example, take this password. [34:23.360 --> 34:24.360] Is this a good password? [34:25.980 --> 34:29.260] No, of course, it's a complete shitty password. [34:30.360 --> 34:37.500] But we told our users that you should have a capital letter, you should have numbers, and you should have special characters. [34:37.860 --> 34:38.740] What do they do? [34:38.840 --> 34:40.480] They do it exactly in that order. [34:41.260 --> 34:45.660] From a pen testing point of view, we know that the capital letter is always the first letter in the password. [34:46.240 --> 34:48.160] Then we say you have to create a password. [34:48.400 --> 34:52.760] So you base your password on a word, not a phrase, a word. [34:53.720 --> 34:56.500] After that word, we tell you to have numbers. [34:57.520 --> 34:59.880] We relate to numbers as years. [35:00.120 --> 35:03.680] So you either have four digits or two digits. [35:04.320 --> 35:08.760] And after that, for some stupid reason, we always put the exclamation mark at the end. [35:09.160 --> 35:10.060] I don't know why. [35:10.640 --> 35:11.120] Always. [35:11.520 --> 35:17.700] And there are some people that think I'm wild and crazy, so I'll have two exclamation marks at the end. [35:18.000 --> 35:21.600] Or the number one after the exclamation mark. [35:22.020 --> 35:27.640] Because we're not teaching the users how to actually live after the policy that we're telling them to do. [35:27.860 --> 35:35.540] So when they type this password and the policy is enforced in the technology, we go, sweet. [35:35.820 --> 35:37.140] That's a valid password. [35:38.000 --> 35:42.220] Because it's according to the policy, it achieves everything that we want to have. [35:42.560 --> 35:45.060] The capital letters and numbers to special characters, etc. [35:49.190 --> 35:51.750] We are so extremely vulnerable out there. [35:52.990 --> 35:53.870] Extremely vulnerable. [35:53.870 --> 36:00.530] And I think it's actually our responsibility as the security industry to actually deal with this. [36:01.790 --> 36:05.530] I don't really have a magic silver bullet for everything. [36:05.850 --> 36:16.310] But I want to spend the last times, the last minutes to demonstrate some attacks that we used in this TV show that I talked about. [36:17.050 --> 36:19.090] And I actually added a few extra. [36:19.530 --> 36:24.110] And it includes, for example, bypassing multi-factor authentication or OTPs or stuff like that. [36:24.950 --> 36:26.610] It's a pretty cool demo. [36:26.790 --> 36:27.970] So I hope everything works. [36:28.190 --> 36:29.070] Because it is live. [36:29.850 --> 36:33.290] So if I mess up, it's part of life, you know? [36:33.670 --> 36:35.050] Who doesn't like a live demo? [36:36.230 --> 36:38.490] So let's go with the terminal here. [36:38.790 --> 36:40.750] Can everyone see what's happening here? [36:41.730 --> 36:42.110] Yeah. [36:42.490 --> 36:48.370] So what I'm also demonstrating here, like, there are a few extra tools that I added to this. [36:48.570 --> 36:52.610] But it's just because I don't want to use any remote connections for everything. [36:52.870 --> 36:56.950] So the tools that I'm using could be installed somewhere else. [36:57.070 --> 36:58.850] They don't have to be stored locally on the machine. [36:59.170 --> 37:02.170] But this is a default, fully up-to-date Mac OS computer. [37:02.170 --> 37:08.230] And the first thing is, when you talk about this, like, the demo that I'm going to do now is a post-exploitation demo. [37:08.390 --> 37:11.330] So I don't care how you gain access to the machine. [37:11.430 --> 37:13.650] Let's say that you used OMG cables. [37:13.810 --> 37:15.490] I don't know how you did it. [37:15.610 --> 37:20.990] But you do have a low privilege account on the machine. [37:21.290 --> 37:23.890] So the first thing that I want to talk about is cookies. [37:24.630 --> 37:28.170] Because we relate to cookies as something that lives inside the browser. [37:28.950 --> 37:30.130] But that's not really true. [37:30.130 --> 37:31.210] We know that. [37:31.670 --> 37:43.110] But we rarely talk about the session tokens that are stored locally in the operating system from normal applications, such as Discord, Slack, Teams, and so on. [37:43.630 --> 37:50.170] That's just normal HTTP cookies also stored in clear text without any encryption locally on the machine. [37:50.630 --> 37:57.710] So once you've popped the machine, you can just take out those session tokens and use them as you want. [37:58.330 --> 37:59.750] And I think that's quite interesting. [38:00.010 --> 38:04.490] I mean, when was the last time you actually logged into Microsoft Teams using your username and password? [38:06.010 --> 38:07.570] Probably not today or yesterday. [38:08.310 --> 38:08.390] No. [38:09.190 --> 38:11.970] Because those session tokens, they have a very long lifetime. [38:12.450 --> 38:13.390] Which I think is interesting. [38:13.630 --> 38:16.430] So you logged in once and then you're just there. [38:16.650 --> 38:17.830] You don't authenticate anymore. [38:18.010 --> 38:19.550] Well, you authenticate with the token, of course. [38:19.690 --> 38:22.790] But they are not encrypted. [38:22.790 --> 38:24.410] The browser actually figured this out. [38:24.590 --> 38:26.950] So the browser cookies, they're encrypted. [38:28.310 --> 38:31.970] But application cookies and application session tokens for applications, they're not encrypted. [38:32.450 --> 38:34.950] They live in SQLite databases locally on the machine. [38:35.130 --> 38:36.690] You can just take them and do whatever you want to do. [38:37.210 --> 38:53.730] And with the demo that we saw in the previous presentation with the socks proxies and so on, some cookies, they are protected with metadata saying that you're not allowed to use this session token if you're not coming from the same IP as, you know, the first time you authenticate it. [38:54.230 --> 39:03.410] So to actually hack that, you know, this amazing hacker tool that just lives in all these macOS machines out there. [39:03.470 --> 39:04.770] Do you know what hacker tool I'm talking about? [39:05.530 --> 39:06.990] Of course, it's open SSH. [39:07.190 --> 39:24.830] You can just, since you have access to the machine, you can just use SSH to do a socks proxy from the compromised machine up to your C2 server somewhere else and use those session tokens from the compromised machine as well, which is very, very neat and very, [39:24.850 --> 39:25.290] very useful. [39:25.770 --> 39:28.810] The other thing is, and I don't know if there's someone from Apple here. [39:29.010 --> 39:35.870] If there is someone from Apple, please come up to me and talk to me about this afterwards, because this is, for me, completely insane. [39:36.410 --> 39:58.500] I don't know how much time you've spent researching the Apple keychain, but the Apple keychain is, when you look at the keychain, the keychain is basically this encrypted database where you put all your super secret credentials, encryption keys, all these different things is placed in the keychain. [39:58.680 --> 40:08.760] So every time you log into a Wi-Fi, you store a password in the browser, or you store a password locally in the system, for example, mail accounts or whatever. [40:08.760 --> 40:13.540] Every time you store something, those credentials are stored in the keychain. [40:13.920 --> 40:25.180] And what's also interesting is if you have the same Apple ID on your phone as you have on your computer, the passwords that you store on this device is also stored locally inside this encrypted database. [40:25.540 --> 40:34.340] But what they've done is they've taken the encrypted key to unlock the keychain and put it inside the keychain. [40:34.340 --> 40:47.240] And the keychain itself is world readable by anyone, any process on the system can read the keychain. [40:47.620 --> 40:54.320] And inside the keychain, you have the encrypted password to unlock the entire keychain. [40:55.040 --> 41:06.920] I don't know why that is, but to put the encryption key to the most secret database that you have on the machine in the same file and make it world readable is stupid. [41:07.820 --> 41:09.820] I don't know how to put it in any other way. [41:09.980 --> 41:17.140] So basically, what you can do is you can extract every single password in clear text that you stored on the machine by cracking one password. [41:17.380 --> 41:30.620] And a Mac OS user, from a psychology point of view, they traditionally put a very bad password locally on the machine, because they think that they will use barometrics like fingerprint to authenticate on the machine. [41:30.840 --> 41:36.120] So they put a shitty password because they say I will never use the password again because I'm going to use my fingerprint instead. [41:36.660 --> 41:44.440] The problem is that, let's say that you and me, we go out and have a party tonight, and you go back home or you go to a hotel, and when you wake up, you have nine fingers. [41:44.880 --> 41:45.740] You lost one finger. [41:45.940 --> 41:46.760] Go out drinking with me. [41:47.160 --> 41:50.920] How are you going to authenticate on the machine if you lost your cool finger? [41:51.900 --> 41:53.740] You have to type the password. [41:56.220 --> 42:10.520] If you look here, you can see that I have extracted one keychain password and 123 infinite passwords, which is VPN accounts and email accounts and so on. [42:10.760 --> 42:14.940] And also, of course, certificates that can be used for VPN connections and other stuff like that. [42:17.640 --> 42:20.760] So, by tracking this, you can access this machine. [42:22.200 --> 42:31.840] So, just using John the Ripper, you'll see the password for my computer here on this machine, this demo machine, is hack the planet. [42:33.200 --> 42:38.180] If I use hack the planet, I can extract all the other passwords that's on the machine. [42:38.900 --> 42:40.160] But it's not that. [42:40.340 --> 42:43.580] Imagine that the password is so strong that you cannot crack it. [42:43.660 --> 42:44.720] It's impossible to crack. [42:44.720 --> 42:51.780] How are you going to trick the user to actually give you a password? [42:52.380 --> 42:54.620] Let me modify the code a little bit here. [42:55.520 --> 42:57.080] Because you don't have something called BankID. [42:58.380 --> 43:02.600] BankID is our national electronic ID application. [43:02.900 --> 43:04.180] And I changed that to Spotify. [43:04.360 --> 43:07.240] Imagine that you're sitting working on the machine and this happens. [43:09.380 --> 43:14.820] On MacGo is you can basically tell any installed application to give you a pop-up of your choice. [43:17.040 --> 43:17.940] I'll do it again. [43:18.560 --> 43:19.860] So, Spotify actually starts. [43:20.140 --> 43:23.060] It says on the window, new software update available. [43:23.220 --> 43:24.220] Enter your password to upgrade. [43:24.760 --> 43:28.420] Whatever I type here, the hacker can get. [43:29.040 --> 43:33.260] So, basically, it's phishing attack, but it's userland phishing. [43:33.560 --> 43:37.980] Phishing is not just through an email or a link or, you know, whatever. [43:38.400 --> 43:40.200] It can also be locally on the machine. [43:40.580 --> 43:47.740] So, if the hacker has access to your machine, they can actually, you know, bring up all these pop-ups, all that stuff on the machine. [43:48.280 --> 43:50.580] But I want to show something else. [43:50.740 --> 43:54.100] And I think this is where it starts getting really, really, really interesting. [43:55.800 --> 43:57.760] I'm logging into my machine. [44:01.020 --> 44:04.440] So, I'm logging into a C2 server that I have somewhere in Sweden, right? [44:07.340 --> 44:10.100] How many of you use a password manager for your password? [44:11.380 --> 44:12.260] Oh, a lot of people. [44:12.380 --> 44:13.760] What about hacking password managers? [44:15.680 --> 44:16.460] Let's try that. [44:22.240 --> 44:23.780] You don't need password managers? [44:23.980 --> 44:25.000] No, but a lot of people do. [44:26.480 --> 44:27.180] Oh, sorry. [44:36.560 --> 44:37.220] Say again? [44:37.600 --> 44:39.500] It's like giving it to you, you think I have it. [44:41.340 --> 44:42.480] This is like giving, yeah. [44:42.660 --> 44:43.900] Everything is a hard question. [44:44.480 --> 44:46.020] But a lot of people use it. [44:46.200 --> 44:47.660] So, I decided to hack it. [44:47.960 --> 44:50.140] The problem is, like, it's just about... [44:50.140 --> 44:50.620] Yeah. [44:54.400 --> 44:54.840] People... [44:54.840 --> 44:55.120] People... [44:55.120 --> 44:55.300] People... [44:55.300 --> 44:55.460] People... [44:55.460 --> 44:55.560] People... [44:57.000 --> 44:57.440] People... [45:01.700 --> 45:02.140] People... [45:03.840 --> 45:06.440] I think this is... you'll see the demo here. [45:06.600 --> 45:08.640] That is not just password managers. [45:09.300 --> 45:12.080] It's a lot of other... yeah, but you'll see this is other cool stuff. [45:12.240 --> 45:13.700] So, you have the password manager. [45:13.860 --> 45:15.260] I'm using Bitwarden right now. [45:15.380 --> 45:15.820] It doesn't matter. [45:17.000 --> 45:18.680] I'm entering my master password. [45:19.580 --> 45:20.920] And I go to demo here. [45:23.560 --> 45:27.140] I'll open up the terminal so we can see it here. [45:29.580 --> 45:35.780] So, basically, what you're seeing here is the output on my command and control server somewhere in Sweden. [45:36.020 --> 45:36.620] I go here. [45:37.800 --> 45:40.860] And when I press copy here, I want to copy this password. [45:40.880 --> 45:44.380] I want to paste it somewhere else in some application or something. [45:47.440 --> 45:50.800] It's now sent directly to the command and control server. [45:50.800 --> 45:57.240] But what's really crazy here is, like, now, if you could see it, I'm opening up Google Authenticator. [45:58.960 --> 45:59.980] Google Authenticator here. [46:00.140 --> 46:04.620] And I'm going to copy one of those tokens here by just clicking on it. [46:04.760 --> 46:05.500] So, I click here. [46:09.500 --> 46:11.620] And now, it's on my C2 server. [46:14.520 --> 46:15.180] Say again? [46:17.120 --> 46:19.200] That is the... that's what I'm exploiting. [46:19.340 --> 46:20.540] That is exactly what I'm using. [46:23.260 --> 46:24.020] Say again? [46:28.680 --> 46:31.180] Yeah, whatever... whatever I copy on the machine. [46:31.400 --> 46:40.240] So, what I'm basically doing is that everything that the machine is ever copying with the system call for copying things can be sent to the server. [46:40.840 --> 46:41.940] And this is built in... [46:42.960 --> 46:44.000] Basically, since... [46:44.000 --> 46:44.880] Since... [46:44.880 --> 46:52.260] If I have the same Apple ID on the phone as on the computer, they enable a feature which is cross-platform copying. [46:52.840 --> 46:55.260] So, it becomes more crazy than that. [46:55.600 --> 46:58.180] So, the last thing that I want to demonstrate is this. [46:59.520 --> 47:07.880] So, it's OTPs, it's passwords, it's whatever I copy on either my phone or my computer, we can steal it like this. [47:07.880 --> 47:09.140] Because that's built in functionality. [47:09.400 --> 47:11.900] There's a program on Mac OS called PB paste. [47:12.600 --> 47:13.340] PB paste. [47:13.540 --> 47:13.900] That's exciting. [47:14.040 --> 47:15.060] That's the only thing that I'm doing. [47:15.500 --> 47:19.120] I'm using PB paste and I'm curling the output to my C2 server. [47:19.820 --> 47:20.880] But I want to take... [47:20.880 --> 47:22.000] I want to take... [47:22.000 --> 47:23.300] Can I take a photo of you guys? [47:23.540 --> 47:26.260] Or is there anyone who doesn't want to be part of the photo? [47:28.120 --> 47:29.080] Look at this. [47:29.280 --> 47:30.640] So, let's go here. [47:33.590 --> 47:35.990] I'm taking a selfie with all you guys. [47:36.210 --> 47:37.170] You can't really see it. [47:39.750 --> 47:42.570] Okay, what I'm doing now on the phone... [47:44.390 --> 47:45.710] It's not just text. [47:45.950 --> 47:48.310] I'm copying this picture that I just took. [47:52.280 --> 47:53.860] Wait, wait for it. [47:59.580 --> 48:00.920] Can you repeat that? [48:03.340 --> 48:04.780] Can I repeat stuff? [48:05.080 --> 48:05.320] Yeah. [48:06.360 --> 48:07.480] The entire presentation? [48:09.720 --> 48:10.280] Okay. [48:10.800 --> 48:12.040] What other people say. [48:12.120 --> 48:12.680] Not what you say. [48:12.860 --> 48:13.580] Oh, what they... [48:13.580 --> 48:14.040] Okay. [48:14.660 --> 48:14.940] Absolutely. [48:15.220 --> 48:15.500] Thank you. [48:16.520 --> 48:19.020] So, it's also copying... [48:19.020 --> 48:20.300] It's whatever I copy. [48:21.240 --> 48:22.300] Whatever I copy. [48:23.720 --> 48:25.060] Which is a little bit crazy. [48:25.220 --> 48:27.640] So, it's pictures and it's texts. [48:27.860 --> 48:28.660] It's whatever. [48:28.660 --> 48:35.500] And I think it just gives us a lot of functionality like inside the operating system that we can abuse. [48:35.820 --> 48:37.300] As I said, it's not really vulnerabilities. [48:37.300 --> 48:42.180] It's just abusing userland functionality to achieve pretty nasty stuff. [48:42.660 --> 48:52.020] So, once the machine gets popped, there's just so many things that you as a hacker can do to take advantage of the system without installing other stuff. [48:52.020 --> 48:52.780] Right? [48:53.620 --> 49:00.640] The basic operating system has so much functionality that we do not really need, that we don't actually need to have access to. [49:01.600 --> 49:07.700] Maybe as a developer, but that's the 1% of people who actually need to have a terminal and do all these different things. [49:07.700 --> 49:15.160] Everyone else just needs to, you know, use an app, log in, do their job, that's it. [49:15.160 --> 49:17.360] And I think that's what we have to do. [49:18.360 --> 49:20.400] That's what we have to aim for. [49:21.480 --> 49:25.660] Because if you look at the digital problems, they now affect the physical world. [49:26.600 --> 49:31.980] And the analog ethics and moral, which I think is interesting, is applied in the digital world. [49:32.260 --> 49:40.420] Which I mean, what I mean with that is, the decisions that we take in the digital world is based on the knowledge that we have from the physical world. [49:40.660 --> 49:43.360] But the digital and the physical worlds are not the same. [49:43.960 --> 49:48.460] But to really solve this, and this is my last slide, is that we have to work together. [49:48.940 --> 49:50.860] We are here now for three days. [49:51.560 --> 49:51.880] Network. [49:52.100 --> 49:55.500] Take this opportunity to actually get to know each other. [49:56.140 --> 49:58.500] And we as an industry have to help each other. [49:58.660 --> 49:59.780] We are not competitors. [50:00.120 --> 50:04.220] We as an industry have to take a collective responsibility to actually fix this. [50:04.520 --> 50:05.520] Not just sell products. [50:05.700 --> 50:08.120] Not just, you know, aim for financial gain. [50:08.360 --> 50:13.940] If you really want to make a difference, we can actually do that by very little things. [50:14.360 --> 50:18.200] We have to focus on what's really important, which is securing the users. [50:18.200 --> 50:20.000] Securing society and all that stuff. [50:21.060 --> 50:22.160] That's what we have to do. [50:22.540 --> 50:24.760] We have to believe the process in transformation. [50:25.160 --> 50:32.400] We will look back at this time in 50 years or 100 years or whatever and say, we were stupid at that time. [50:32.560 --> 50:33.380] We were silly. [50:33.620 --> 50:35.520] We do it today. [50:35.800 --> 50:39.960] The stuff that we developed today is much better than the stuff that we developed 20 years ago. [50:40.180 --> 50:44.820] And the stuff that we will develop in 20 years in the future will be better than the stuff that we produce today. [50:44.820 --> 50:46.880] So we have to believe the process. [50:47.080 --> 50:48.020] It will be better. [50:50.020 --> 50:52.140] And we have to talk about this. [50:52.280 --> 50:58.620] And that's why I flew from Sweden here, is to talk to you about my experience, my thoughts, my stuff that I have. [50:58.860 --> 51:05.880] And I'm really happy to be here to listen and learn from all other experts and, you know, security people out there. [51:06.280 --> 51:07.560] Together we can make a difference. [51:07.800 --> 51:09.560] So thank you so much for having me. [51:10.740 --> 51:11.380] Thank you.