SlideShare a Scribd company logo
1 of 41
Download to read offline
Open solutions, smarter people




                           Security

   You are also part of the game




This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
Open solutions, smarter people




                        Who is that guy?
•   Bert Desmet
•   23 years old
•   Fedora – Ambassador, mentor, packager
•   Loadays – Co organizer
•   Numius – System Engineer, Consultant
•   Devnox – Developer, System Engineer
Open solutions, smarter people




                         Today's topics
•   I'm a good hacker.
•   Why I love USB sticks.
•   Remember your password?
•   Shhhhhhht!
Open solutions, smarter people




I am a good hacker.
Open solutions, smarter people




No tech hacking?
Open solutions, smarter people




Shoulder surfing
Open solutions, smarter people




Dumpster diving
Open solutions, smarter people




Social engineering
Open solutions, smarter people




Taking pictures
Open solutions, smarter people




Why I love USB sticks.
Open solutions, smarter people




They are easy
Open solutions, smarter people




And small
Open solutions, smarter people




              They are easily..
• Forgotten
• Stolen
Open solutions, smarter people




                   Some thoughts about it
•   Encrypt your sensitive data
•   Never put passwords on your system
•   Use the intranet
•   Never leave your portable gear alone
•   Never forget your gear
Open solutions, smarter people




                             Some statistics
• 53% of UK workers lost portable devices
   – >50% at a drinking venue
       • Taxis and public transport
• 1 lost data record cost more than $187
   – 70% indirect cost
       •   Lost costumers
Open solutions, smarter people




Remember your password?
Open solutions, smarter people




                How to choose a password
•   Avoid using dictionary words
•   Use special characters and numbers
•   Change your password every month
•   Blah blah blah
Open solutions, smarter people




                How to choose a password
•   Avoid using dictionary words
•   Use special characters and numbers
•   Change your password every month
•   Blah blah blah
Open solutions, smarter people




                          Entropy
• H : Entropy
• N : Possible symbols
• Length of string




                         H= L∗log2 N
Open solutions, smarter people




                          Example time!
• This is.obviously a.bad passw0rd:-(
    – L : 35
    – W : 94
    – H : ±230
• PrXyc.N(n4k77#L!eVdAfp9
    – L : 23
    – W : 94
    – H : ±151
Open solutions, smarter people




                  Time to crack a password
• [[Guesses before string is found = 2H]]
• This is.obviously a.bad passw0rd:-(
    – 2230 = 1.72543659 × 1069
    – 1000 guesses /s = 5.5 x 1058 years
• PrXyc.N(n4k77#L!eVdAfp9
    – 2151 = 2.85449539 × 1045
    – 1000 guesses /s = 9 × 1034 years
Open solutions, smarter people




Password Strenght
Open solutions, smarter people




                             Lastpass
• Fully encrypted
• Generate extremely hard passwords
• Choose a good master password!
Open solutions, smarter people




                            Some tips
• Never store passwords on pc
• Never use autologin
Open solutions, smarter people




Shhhhhhhht!
Open solutions, smarter people




I want you to shut up!
Open solutions, smarter people




               Security through obscurity
• Don't tell anyone
• Security based on secrecy
Open solutions, smarter people




                     Kerckhoffs' doctrine
• Security can't depend on secrecy
Open solutions, smarter people




                           Reality
• There are always leaks
    – By accident
    – Deliberately
• Try to keep 'secrets'
Open solutions, smarter people




Wait! There is more!
Open solutions, smarter people




In a perfect world..
Open solutions, smarter people




There is always a hole.
Open solutions, smarter people




I like onions
Open solutions, smarter people




                      Multi Level Security
• Multiple systems
• Building fort Knox
• You are the first line of defense
Open solutions, smarter people




Extra! Extra!
Open solutions, smarter people




Something you have..
Open solutions, smarter people




Yubikey
Open solutions, smarter people




  I preach.
And I practice.
Open solutions, smarter people




                                         Questions?
• Bert Desmet
• Security, you are also part of the game




•   Mail: Bert@devnox.eu
•   Twitter: @bdesmet_
•   Website: http://blog.bdesmet.be
•   Website: http://www.devnox.eu
•   This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
Open solutions, smarter people




                                                         Sources
•   Chess game: http://www.flickr.com/photos/seeminglee/1479932683/
•   Closed vault: http://www.flickr.com/photos/mstyne/3654056683/
•   Open vault: http://www.flickr.com/photos/spotsgot/156025944/
•   Onion: http://www.flickr.com/photos/inferis/107293622/
•   Laptop + usb stick: http://www.flickr.com/photos/wstryder/2780310027/
•   New York Public Library: http://www.flickr.com/photos/paul_lowry/2616820493/
•   Statistics on loosing gear: http://www.securestix.com/bad_news.php
•   Shoulder surfing: http://www.flickr.com/photos/bonzoesc/209474964/
•   Dumpster: http://www.flickr.com/photos/urbanjacksonville/1803065217/
•   Telephone call: http://www.flickr.com/photos/lst1984/994531885/
•   Taking pictures: http://www.flickr.com/photos/glenpooh/708845839/
•   Xkcd joke: http://xkcd.com/936/
•   Shut up: http://www.flickr.com/photos/lorenia/934705558/
•   3way handhake: http://media.photobucket.com/image/3%20way%20handshake/Haley_Bug/Mission%20Trip%20Choir%20Tour%202006/100_0087.jpg?o=1
•   Yubikey: http://www.flickr.com/photos/thofle/3206443137/
•   Special thanks to: Johnny Long
Open solutions, smarter people

More Related Content

Viewers also liked

догадина&белова1
догадина&белова1догадина&белова1
догадина&белова1guestfb2102
 
Boeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case studyBoeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case studyMuthu Kumaar Thangavelu
 
SESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao AndroidSESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao AndroidRafael Sakurai
 
Social Training Project for Merchandisers
Social Training Project for MerchandisersSocial Training Project for Merchandisers
Social Training Project for MerchandisersRussel C. Arida
 
Semantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical ReportSemantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical ReportMuthu Kumaar Thangavelu
 
Why You Should Partner With Colonial Life
Why You Should Partner With Colonial LifeWhy You Should Partner With Colonial Life
Why You Should Partner With Colonial Lifedonnadwyer
 
Measures of corporate performance
Measures of corporate performanceMeasures of corporate performance
Measures of corporate performanceSamahAdra
 
Bp business and information strategy alignment
Bp   business and information strategy alignmentBp   business and information strategy alignment
Bp business and information strategy alignmentMuthu Kumaar Thangavelu
 

Viewers also liked (10)

догадина&белова1
догадина&белова1догадина&белова1
догадина&белова1
 
Boeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case studyBoeing rocketdyne radical innovation case study
Boeing rocketdyne radical innovation case study
 
SESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao AndroidSESTINFO 2011 Apresentacao Android
SESTINFO 2011 Apresentacao Android
 
Social Training Project for Merchandisers
Social Training Project for MerchandisersSocial Training Project for Merchandisers
Social Training Project for Merchandisers
 
Semantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical ReportSemantic web design for www.data.gov.sg - Technical Report
Semantic web design for www.data.gov.sg - Technical Report
 
Why You Should Partner With Colonial Life
Why You Should Partner With Colonial LifeWhy You Should Partner With Colonial Life
Why You Should Partner With Colonial Life
 
Buckmann labs KM case study
Buckmann labs KM case studyBuckmann labs KM case study
Buckmann labs KM case study
 
Human Capital Management
Human Capital ManagementHuman Capital Management
Human Capital Management
 
Measures of corporate performance
Measures of corporate performanceMeasures of corporate performance
Measures of corporate performance
 
Bp business and information strategy alignment
Bp   business and information strategy alignmentBp   business and information strategy alignment
Bp business and information strategy alignment
 

Similar to Security, you are also part of the game

Preservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanitiesPreservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanitiesDorothea Salo
 
Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)Ellen Grove
 
Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)Frank Garofalo
 
27 Ways To Be A Better Developer
27 Ways To Be A Better Developer27 Ways To Be A Better Developer
27 Ways To Be A Better DeveloperLorna Mitchell
 
27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)Ivo Jansch
 
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovationImmerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovationPaulJervisHeath
 
introduction.pptx
introduction.pptxintroduction.pptx
introduction.pptxsecurework
 
2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdf2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdfTony Khánh
 
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...Duncan Campbell
 
Low Cost Assistive Technology Solutions
Low Cost Assistive Technology SolutionsLow Cost Assistive Technology Solutions
Low Cost Assistive Technology Solutionswill wade
 
Dark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 CryptographyDark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 CryptographyMarcus Leaning
 
Fall 2011 Parent Tech Conference
Fall 2011 Parent Tech ConferenceFall 2011 Parent Tech Conference
Fall 2011 Parent Tech Conferencetim wojcik
 
Dark Patterns in UX
Dark Patterns in UXDark Patterns in UX
Dark Patterns in UXNomensa
 
Don't let assumptions kill good ideas
Don't let assumptions kill good ideasDon't let assumptions kill good ideas
Don't let assumptions kill good ideasLauren Liss
 
Solving Problems with Web 2.0
Solving Problems with Web 2.0Solving Problems with Web 2.0
Solving Problems with Web 2.0Dorothea Salo
 

Similar to Security, you are also part of the game (20)

So i got an Arduino now what
So i got an Arduino now whatSo i got an Arduino now what
So i got an Arduino now what
 
Preservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanitiesPreservation and institutional repositories for the digital arts and humanities
Preservation and institutional repositories for the digital arts and humanities
 
Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)Hacking is a mindset, not a skillset (agile ottawa)
Hacking is a mindset, not a skillset (agile ottawa)
 
Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)Brainstorming in an Agile World (Esri DevSummit 2015)
Brainstorming in an Agile World (Esri DevSummit 2015)
 
27 Ways To Be A Better Developer
27 Ways To Be A Better Developer27 Ways To Be A Better Developer
27 Ways To Be A Better Developer
 
27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)27 Ways To Be A Better Developer (PHPBenelux 2011)
27 Ways To Be A Better Developer (PHPBenelux 2011)
 
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovationImmerse, Imagine, Invent, Articulate: A framework for disruptive innovation
Immerse, Imagine, Invent, Articulate: A framework for disruptive innovation
 
C1 into to ai
C1 into to aiC1 into to ai
C1 into to ai
 
introduction.pptx
introduction.pptxintroduction.pptx
introduction.pptx
 
The art of AI Art
The art of AI ArtThe art of AI Art
The art of AI Art
 
2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdf2016-How-to-give-a-great-research-talk.pdf
2016-How-to-give-a-great-research-talk.pdf
 
Artificial intelligence
Artificial intelligenceArtificial intelligence
Artificial intelligence
 
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
Beyond Brainstorming: Innovation for Everyone (Global Scrum Gathering Singapo...
 
Low Cost Assistive Technology Solutions
Low Cost Assistive Technology SolutionsLow Cost Assistive Technology Solutions
Low Cost Assistive Technology Solutions
 
Dark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 CryptographyDark Side of the Net Lecture 2 Cryptography
Dark Side of the Net Lecture 2 Cryptography
 
Fall 2011 Parent Tech Conference
Fall 2011 Parent Tech ConferenceFall 2011 Parent Tech Conference
Fall 2011 Parent Tech Conference
 
Dark Patterns in UX
Dark Patterns in UXDark Patterns in UX
Dark Patterns in UX
 
Agile tricks
Agile tricksAgile tricks
Agile tricks
 
Don't let assumptions kill good ideas
Don't let assumptions kill good ideasDon't let assumptions kill good ideas
Don't let assumptions kill good ideas
 
Solving Problems with Web 2.0
Solving Problems with Web 2.0Solving Problems with Web 2.0
Solving Problems with Web 2.0
 

Recently uploaded

Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024The Digital Insurer
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘RTylerCroy
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdflior mazor
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationRadu Cotescu
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)wesley chun
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Miguel Araújo
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)Gabriella Davis
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...apidays
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?Igalia
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherRemote DBA Services
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024The Digital Insurer
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationSafe Software
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsRoshan Dwivedi
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MIND CTI
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024The Digital Insurer
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Drew Madelung
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century educationjfdjdjcjdnsjd
 

Recently uploaded (20)

Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)Powerful Google developer tools for immediate impact! (2023-24 C)
Powerful Google developer tools for immediate impact! (2023-24 C)
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024MINDCTI Revenue Release Quarter One 2024
MINDCTI Revenue Release Quarter One 2024
 
Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024Manulife - Insurer Innovation Award 2024
Manulife - Insurer Innovation Award 2024
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 

Security, you are also part of the game

  • 1. Open solutions, smarter people Security You are also part of the game This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
  • 2. Open solutions, smarter people Who is that guy? • Bert Desmet • 23 years old • Fedora – Ambassador, mentor, packager • Loadays – Co organizer • Numius – System Engineer, Consultant • Devnox – Developer, System Engineer
  • 3. Open solutions, smarter people Today's topics • I'm a good hacker. • Why I love USB sticks. • Remember your password? • Shhhhhhht!
  • 4. Open solutions, smarter people I am a good hacker.
  • 5. Open solutions, smarter people No tech hacking?
  • 6. Open solutions, smarter people Shoulder surfing
  • 7. Open solutions, smarter people Dumpster diving
  • 8. Open solutions, smarter people Social engineering
  • 9. Open solutions, smarter people Taking pictures
  • 10. Open solutions, smarter people Why I love USB sticks.
  • 11. Open solutions, smarter people They are easy
  • 12. Open solutions, smarter people And small
  • 13. Open solutions, smarter people They are easily.. • Forgotten • Stolen
  • 14. Open solutions, smarter people Some thoughts about it • Encrypt your sensitive data • Never put passwords on your system • Use the intranet • Never leave your portable gear alone • Never forget your gear
  • 15. Open solutions, smarter people Some statistics • 53% of UK workers lost portable devices – >50% at a drinking venue • Taxis and public transport • 1 lost data record cost more than $187 – 70% indirect cost • Lost costumers
  • 16. Open solutions, smarter people Remember your password?
  • 17. Open solutions, smarter people How to choose a password • Avoid using dictionary words • Use special characters and numbers • Change your password every month • Blah blah blah
  • 18. Open solutions, smarter people How to choose a password • Avoid using dictionary words • Use special characters and numbers • Change your password every month • Blah blah blah
  • 19. Open solutions, smarter people Entropy • H : Entropy • N : Possible symbols • Length of string H= L∗log2 N
  • 20. Open solutions, smarter people Example time! • This is.obviously a.bad passw0rd:-( – L : 35 – W : 94 – H : ±230 • PrXyc.N(n4k77#L!eVdAfp9 – L : 23 – W : 94 – H : ±151
  • 21. Open solutions, smarter people Time to crack a password • [[Guesses before string is found = 2H]] • This is.obviously a.bad passw0rd:-( – 2230 = 1.72543659 × 1069 – 1000 guesses /s = 5.5 x 1058 years • PrXyc.N(n4k77#L!eVdAfp9 – 2151 = 2.85449539 × 1045 – 1000 guesses /s = 9 × 1034 years
  • 22. Open solutions, smarter people Password Strenght
  • 23. Open solutions, smarter people Lastpass • Fully encrypted • Generate extremely hard passwords • Choose a good master password!
  • 24. Open solutions, smarter people Some tips • Never store passwords on pc • Never use autologin
  • 25. Open solutions, smarter people Shhhhhhhht!
  • 26. Open solutions, smarter people I want you to shut up!
  • 27. Open solutions, smarter people Security through obscurity • Don't tell anyone • Security based on secrecy
  • 28. Open solutions, smarter people Kerckhoffs' doctrine • Security can't depend on secrecy
  • 29. Open solutions, smarter people Reality • There are always leaks – By accident – Deliberately • Try to keep 'secrets'
  • 30. Open solutions, smarter people Wait! There is more!
  • 31. Open solutions, smarter people In a perfect world..
  • 32. Open solutions, smarter people There is always a hole.
  • 33. Open solutions, smarter people I like onions
  • 34. Open solutions, smarter people Multi Level Security • Multiple systems • Building fort Knox • You are the first line of defense
  • 35. Open solutions, smarter people Extra! Extra!
  • 36. Open solutions, smarter people Something you have..
  • 37. Open solutions, smarter people Yubikey
  • 38. Open solutions, smarter people I preach. And I practice.
  • 39. Open solutions, smarter people Questions? • Bert Desmet • Security, you are also part of the game • Mail: Bert@devnox.eu • Twitter: @bdesmet_ • Website: http://blog.bdesmet.be • Website: http://www.devnox.eu • This work is licensed under a Creative Commons Attribution-ShareAlike 3.0 Unported License.
  • 40. Open solutions, smarter people Sources • Chess game: http://www.flickr.com/photos/seeminglee/1479932683/ • Closed vault: http://www.flickr.com/photos/mstyne/3654056683/ • Open vault: http://www.flickr.com/photos/spotsgot/156025944/ • Onion: http://www.flickr.com/photos/inferis/107293622/ • Laptop + usb stick: http://www.flickr.com/photos/wstryder/2780310027/ • New York Public Library: http://www.flickr.com/photos/paul_lowry/2616820493/ • Statistics on loosing gear: http://www.securestix.com/bad_news.php • Shoulder surfing: http://www.flickr.com/photos/bonzoesc/209474964/ • Dumpster: http://www.flickr.com/photos/urbanjacksonville/1803065217/ • Telephone call: http://www.flickr.com/photos/lst1984/994531885/ • Taking pictures: http://www.flickr.com/photos/glenpooh/708845839/ • Xkcd joke: http://xkcd.com/936/ • Shut up: http://www.flickr.com/photos/lorenia/934705558/ • 3way handhake: http://media.photobucket.com/image/3%20way%20handshake/Haley_Bug/Mission%20Trip%20Choir%20Tour%202006/100_0087.jpg?o=1 • Yubikey: http://www.flickr.com/photos/thofle/3206443137/ • Special thanks to: Johnny Long