A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo
-
Upload
duo-security -
Category
Technology
-
view
78 -
download
0
description
Transcript of A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo
A Place to Hang Our Hats
Security Community and Culture@NotDomenic
Full Disclosure
The Alpha and the OmegaKevin Mitnick was the first and only hacker, lead Anon to glory, took down the FBI, made Tor untraceable, and hacked the alien mothership on the 4th of July.
while author != tech_literate: if narrative < truth and news_day == slow: story = facts.sensationalized() + scare_factor print headline.cyber() + story else: print repackaged_content.rand()
Let’s Make an Algorithm!!
(Sidebar)
Terms to avoid:● “Cyber”.*● Console Cowboys● Authentification● Cracker (confusion)
Out of the Fire, Into the Flame War
● LOD & MOD● DOJ & over-curious young people● Lulzsec & Anonymous● Groups like w00w00, l0pht, [insert group
you’re outraged I didn’t include]
Guiding Question
Are we seeing significant changes and declines in hacker culture and the size of the hacking community?
Maybe?
Growth Led to Decline
Proposal: Growth in the security community has changed its values and makeup.
● Corporate Growth● Law Enforcement Growth● Growth in Field Population
Growth
Growth
Growth: FBI
● FBI Alone saw >350% growth in Intelligence Officers (support, non-special agents) in 90’s○ 1992: 224○ 2000: 1027
Growth: NSA
● 11,000+ new employees between 2001-2013
● Fort Meade Facility > Pentagon
● budget_nsa *= 2● Private contracting companies
○ Pre-2001: ~150 companies○ 2010: ~ 500 companies
Growth
Growth
Growth: Punishment
● Congress and Lobbies push:○ CFAA○ USA PATRIOT Act○ DMCA
Growth: Punishment
Growth of InfoSec: Decline of Goups?
● With a growth in both backing of and leaning on security infrastructure, disclosure has become more frequent
● Wouldn’t we expect to see more hacking collectives?
Growth: C****-Crime
● Organized crime, sometimes even state-sponsored, have taken on some l33t haxors as assets.
● Dark Net, Botnets, Anonymity Tools disincentivize strong open group collaboration
● Major busts: Just one leak
Growth: Responsible Disclosure
● Old Crackers, Sneakers now have avenues to pursue legitimate “cracking”, “sneaking”○ More profitable ones too: Biggest bug bounties now
worth 3.877+ ISS’s● Growing up, settling down, torrenting hacker
children● Less teenage angst
Enter Enterprise● Students &
youngins’ pursuing entrepreneurial and app “hacks”
Omnipresent: Troll & Co
Omnipresent: Troll & Co
Thank You’s
● Zach Lanier ● Chris Czub● Vikas Kumar● Mark Stanislav● Jon Oberheide● Tyler Shields● Your patience for n00bs
Q & (Hopefully) A