In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security...

17
In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License. (C) 2015 [email protected] Jim Salter Mercenary Sysadmin, Small Business Owner Today's slides can be found at: http://openoid.net/presentations/

Transcript of In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security...

Page 1: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

In The Wake of Ashley Madisoninformation security lessons (hopefully) learned

This presentation is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License.(C) 2015 [email protected]

Jim SalterMercenary Sysadmin,Small Business Owner

Today's slides can be found at:

http://openoid.net/presentations/

Page 2: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

The promise of Ashley Madison

Page 3: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

The reality of Ashley Madison

Page 4: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

This talk is not about ethics in adultery.

(or in video game journalism)

Page 5: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

I will never knowingly “out” anyone.

Page 6: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

How'd I get involved?

Page 7: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

13,038 South Carolinians spent money on Ashley

Madison.

That's about 3 out of every thousand people in SC.

Page 8: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

About 92.5% of them were men.

That's about 5.1 out of every thousand men in SC.

Page 9: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

About 75% of them were men age 25-55.

That's about 1.1 out of every hundred men in SC, age

25-55.

Page 10: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

It gets much, much worse when you only

look at cities.% of males age 25-55:

Charleston: 3.1%Columbia: 3.3%Greenville: 4.9%Lexington: 7.8%Fort Mill: 11.7%

Page 11: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

Every network will eventually fall.

SONY, Apple, AOL, Target, Gawker, IRS,

SC DoR, Twitter...

Page 12: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

What made theAshley Madison breach special?

RISK.

Page 13: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

Speaking of “risk”:let's talk about

netblocks.

Army Research OfficeNetRange: 132.193.0.0 - 132.193.255.255CIDR: 132.193.0.0/16NetName: ARO-NETNetHandle: NET-132-193-0-0-1Parent: NET132 (NET-132-0-0-0-0)NetType: Direct Assignment

Page 14: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

Today's vocabulary word:

pivot

Page 15: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

In a nutshell:

all sites will fall

think about exposure

where can theattacker go next?

Page 16: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

Let's talk about passwords!

Passwords In The Internet Age2:45PM, Citizen Track

openoid

Page 17: In The Wake of Ashley Madison - JRS Systems LLC...In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons

Questions? Comments?

Angry denunciations?