2015 AppSecUSA 2015 - Wait wait... dont pwn me!

Preview:

Citation preview

#DontPwnMe

Wait wait…Don’t pwn me!

#DontPwnMe

#DontPwnMe

@TSWAlliance

#DontPwnMe

The Rules for Wait Wait… don’t pwn me!

Each correct answer to the initial question is worth 3 points

A wrong answer subtracts 2 points

A pass on a question loses 1 point

A correct answer from an audience member gets allocated 2 points

to the panelist of their choice

3

#DontPwnMe

The Rules for Wait Wait… don’t pwn me!

The moderator may arbitrarily give or take away points at any time

#DontPwnMe

Online News Resources

Pandodaily

Forbes

Brian Krebs

Hacker News

Gizmodo

John McAfee

Ars Technica

Wired

Swift on Security

FBI/CIA/NSA

WSJ

Kim Zetter

TechCo

The Verge

#DontPwnMe

Round One

7

Swift on Security

#DontPwnMe

According to Taylor Swift…

How does OS X connect to the internet?

#DontPwnMe

According to Taylor Swift…

“Cyber war doesn’t determine who is right…”What does it determine?

#DontPwnMe

According to Taylor Swift…

“If Linux is about choice, how come it never let’s me run… <what> ”

#DontPwnMe

Speaking of McAfee…

#DontPwnMe

According to McAfee…

“During my first 100 days in office, I will ask congress to replace the phrase "In God We Trust" with… <what>”

#DontPwnMe

According to McAfee…

Support for my "Hack the planet" platform has been so strong, I'm proposing we change the pledge from "under God" to with… <what>”

#DontPwnMe

According to McAfee…

What makes McAfee giggle like a 12 year old?

Hint: It’s a type of security test

#DontPwnMe

According to McAfee…

Who has John McAfee asked to be his running mate?

#DontPwnMe

Strange but true…

We’ve already done the John McAfee section, so I don’t know where else to go from there.

#DontPwnMe

What’s Wired with Kim Zetter

#DontPwnMe

What’s Wired with Kim Zetter

A vulnerability discovered in a popular remote management system used by thousands of businesses to manage employee mobile phones would allow an attacker to <what>?

#DontPwnMe

How much is estimated to be extorted from ransomware victims each year?

$1 million$5 million$10 million

#DontPwnMe

What’s Wired with Kim Zetter

How can you find out if the NSA or GCHQ spied on you?

#DontPwnMe

What’s Wired with Kim Zetter

In what year did a Russian spy gang start hijacking satellite links?

#DontPwnMe

What’s Wired with Kim Zetter

From the date the data from the Ashley Madison hack was posted, how many days was it before the CEO resigned?

#DontPwnMe

Bluff the Audience

Two 10 year old girls in Stratford, WA did what as part of a science project?

• Built a homemade clock and took it to school• Used a weather balloon to launch R2D2 Lego into space• Hacked into local TicketMaster computer

#DontPwnMe

R2D2 at 78,000 Feet

#DontPwnMe

Bluff the Audience…

The kid that was arrested for bringing a homemade clock to school in Texas was wearing what kind of t-shirt when he was busted?• Hack the Planet• Eat More Bacon• Maker Faire 2015

#DontPwnMe

Bluff the Audience

The Kardasians released a new app last month. What does the app do?

• Allow subscribers to track the sisters in real time• Auto shoots selfie every 15 minutes• Inserts a unique smilie face when you email

#DontPwnMe

I don’t know.

Who the f*ck cares?

#DontPwnMe

Krebs on Security

What is the name of the team who claims they hacked Ashley Madison?

#DontPwnMe

What does the LizardSquad attack tool do?

#DontPwnMe

What internal security technique was used to stop attackers from gaining access to all Target cash registers?

#DontPwnMe

Audience Limerick Challenge

#DontPwnMe

Audience Limerick Challenge

“When I think of something so thrillingAs a concept that’s well worth it's drilling,I talk to my minions, who have strong opinions On infosec, so un****…”

Taylor Swift

#DontPwnMe

Audience Limerick Challenge

“There once was a general who scared usGiving his mistress info she shared up.The case is now done, and he's basically won.With a 40,000 dollar fine for …”

#DontPwnMe

Final Round…

How much more?

#DontPwnMe

How much money was stolen and in what currency?

#DontPwnMe

How did they do it?

#DontPwnMe

What’s the final score?

#DontPwnMe

Thank You to the The Panel

#DontPwnMe

Get a copy of the slides for this

show immediately…

#DontPwnMe

community@sonatype.com