InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB....

17

Transcript of InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB....

Page 1: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin
Page 2: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

InfoSec Philosophies for the Corrupt Economy

By Lawrence Munro VP, SpiderLabs

Page 3: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

Who am I?

• Herder of Cats (VP) at SpiderLabs • Former Director, B-Sides London• Post-grad at Oxford University• Former Penetration Tester and Social Engineer• Red && Blue Team Strategist• Fanboy (I won’t embarrass them!)• @pentesticles / @themunrobot

Page 4: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

What AM I on about?

Page 5: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

What AM I on about?

Page 6: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

What AM I on about?

Page 7: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

Corruption (noun)/kəˈrʌpʃ(ə)n/Dishonest or fraudulent conduct by those in power, typically involving bribery.

Page 8: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

Developed-world Assumptions

Page 9: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

Cognitive Biases in Security Models

Illusion of Control The tendency to overestimate one's degree of influence over other external events.

Page 10: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

Last Time in Lagos

Page 11: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

Black Hat Greece

Page 12: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

Pay-for-Pass Audits

Page 13: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

The Venn of Hackers

Grey Hat

Black Hat White Hat

Black Hat

This Guy

Page 14: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

How Can We Mitigate?

Page 15: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

What We Definitely Do?

• Pay market rates or above to ensure borderline cases are somewhat mitigated• Social responsibility• Work with local law enforcement and governments to protect

staff• Discourage witch hunts

Page 16: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

Some Thoughts…

• Is this our future, where privacy and security are commodities?• Will organised security devolve after reaching maturity?• By propagating these corrupt systems, do you become

part of them? • Should large organisations be more socially responsible?

Page 17: InfoSec Philosophies for the - Black Hat Briefings · HAHAHAHA!!! I GUESS r SHOULD KEEP DAY JOB. GOOD LUCK WITH THAT black hat LISA #BHU A . Ouallam Niamey Filingué Bouza Birnin

Q&A