Today started like most other defcon days, up, eat, rush to the conference center with tons of other people, and see what you can see.
This morning started off with an interesting talk from Samet Can Tasci who presented on Shadow Webhooks:Hunting for Dangling Event Listeners in Enterprise Workspaces. This talk offered a structured way to review Slack, Teams, Jira, et al. For previously configured web hooks that were no longer replying securely and may or may not operate with proper authentication/authorization.
From here, I dashed over to the NIXos Community to listen to a great talk from the author of frazaria.com entitled “How to Piss Off Your Nix Friends”. He raised several great points, including that “community growth is & should not be a goal”. Growth for the sake of growth is a cancer. Specialized tools will and must afford their audience with points of differentiation, or risk becoming diluted into the pool of thousands of other Linux distros. He also raised some good points around AI as a configuration tool and its responsible use, and gave a pretty self-aware indictment of the military industrial complex, but pleaded to take American PRs on their merits instead of dismissing them outright because of our closeness to said military industrial complex.
Moving on, I got to hear the Zagrodnik couple from Madison, Wisconsin discuss how they started their DefCon group, some of the pitfalls of doing so, the creation of their non-profit, and the ultimate founding of WISCON, a Wisconsin based cyber-security conference celebrating its inaugural event. Highlights from this talk included:
- recruit people who believe in the mission. Not just technical people or “valuable” people.
- Shared values over technical skills
- governance bylaws to protect your board
- beg for money
- and be ready to talk or teach when no one else will. This was part of the encouragement I needed to start scheduling monthly meetups again, as the last failed mini-con had really taken the wind out of my sales.
Catching back up with xRichless and his new found friend “Alex”, we had the opportunity to sit in on a talk from EFF’s Cooper CyberTiger Quintin, trivia host expert and lead Technologist on the EFF’s RayHunter project. It was great to hear from him and the others at the round table and even more exciting to know that he and Colonel Panic have a talk in the morning on using low-cost hardware to perform anti-surveillance.
Next up, we headed to Social Engineering Village, probably second only to Red Team village in popularity. After standing in line for a while, xR, Alex, and I were finally granted admittance. Just in time too, Megan Squire from F-Secure was giving a talk on 3 things that Scammers know that Social Engineers Don’t. In short, she identified 3 techniques that social engineers aren’t practicing, but would improve their success rates. Notably:
- Awareness Hijacking - using someone’s awareness of a scam to draw them into another scenario. E.g.; Calling a person as a bank or LEO to help them protect their money since they know about scammers trying to take it.
- Complexity-as-Crucible - using overly complex explanations and scenarios to overwhelm the target, then offer relief by being the guru who rescues them. (Google, “Byzantine Premium” or “Guru Effect”
- First Wins - Gamblers who collect wins early in a game are more likely to keep playing, let your mark “win” a few times, be wrong and allow them to correct. You’re reinforcing their own biases about their intelligence, and building good rapport.
Finally, after a great day of talks, we decided to hit up vendor hall one last time. On the way, we ran through sticker table, after sticker table, after sticker table. And needless to say, we have more stickers than we could ever possibly need, but far less than we want. Of note today was a sticker with NFC tags embedded in it, several Hackers stickers, and a TSA Toilet Camera in use sticker.
With the sticker tables behind us, we headed to Vendor hall, where we all spent more money than we meant to, but far less than we wanted to. And it was a good chance to up my EFF subscription. Also, notable mention, Phreeli phone provider was at the con taking payment for a years subscription at 10% off AND not collecting any customer info. Meaning, if you bought a sim card today, in cash, you could register it to a Signal account, and have a completely private wireless subscription experience, at least that’s the claim. I had a chance to talk with Nicholas Merrill at length today, and he was upfront about what police could and could not get with a subpoena. It was refreshing to here him acknowledge the limitations and successes of their design and offerings.
One more day, wonder what it will bring!