78
Security Not Guaranteed Or, how to hold off the bad guys for another day. A Presentation for B-Sides CLE

A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Security Not Guaranteed

Or, how to hold off the bad guys for another day.

A Presentation for B-Sides CLE

Page 2: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

This Talk is NOT About...

A. Protecting Against Three Letter Agencies (KGB,

FSB, CIA, NSA, FBI, DOJ)

B. Protecting Against a Targeted Attack

C. Protecting Your Corporation

D. How The Cloud Is Evil And Should Be Avoided At All

Costs™

Page 3: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Would it surprise you if...

Page 4: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

67% of consumers...

Don’t have password protection on their devices.

(Sophos, August 2011)

Page 5: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Now, this isn’t a problem in itself...

But, it can be disastrous if

your device is LOST or,

STOLEN.

Page 6: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

All devices can be Password Protected

Page 7: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

{ 9/10 }

The estimated number of break-in attempts that would be thwarted if

people simply locked their computers.

Page 8: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

And, it doesn’t have to be too complicated.

Page 9: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

The password:

do graze irk

has 49 bits of entropy.

Page 10: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

It’s also a password that can be remembered, in

some way.

Page 11: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

And it can be typed fairly quickly.

Page 12: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

It really takes about as much effort as:

password1234

But, is far more secure.

Page 13: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Now, you’re probably wondering about

fingerprint unlocks:

My Friend Taylor Swift will talk about that.

Page 14: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important
Page 15: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Used the hilarious ‘Swift on Security’.

Page 16: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Passwords are a start.

Page 17: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

How do you keep your passwords together?

Page 18: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Believe it or not…

Some people still use pencil, and paper, or try to

keep it in their heads.

Page 19: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

There are a lot of good password managers.

Page 20: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Raise your handif you’re using KeePass.

Page 21: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

KeePass is very popular.

Page 22: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

KeePass is also probably not secure.

Page 23: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

The French ANSSI Did an Audit...

Page 24: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

And it checked out.

Page 25: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

There’s a little more to it though.

Page 26: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

KeePass has a lot of problems.

Page 27: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Which really apply to all of these.

Page 28: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Password managers are flawed.

Page 29: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

It doesn’t often matter to the consumer which manager they use.

Page 30: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Just as long as it works.

For consumers stuff like LastPass is a good start.

Page 31: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Just as long as it’s not a notebook.

Page 32: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Mr. T. pities the fool who doesn’t have a password

manager.

Page 33: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Used Mr. T. in a Serious Presentation

Page 34: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Mentioning passwords...

Page 35: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Device encryption is an important security tool.

Page 36: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Many people fail to encrypt even the most

important data.

Page 37: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Or, overlook critical points.

Page 38: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

You can encrypt almost anything.

Page 39: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Desktops, phones, tablets; OS X, Windows,

Linux, even BSD.

Page 40: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Device encryption starts fights.

Page 41: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

If you do it, do it right.

Page 42: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Hurricane Labs gave a presentation last year

with pointers we all should know.

Page 43: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Self encrypting, is self decrypting.

Page 44: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Make sure the password is requested on boot.

Page 45: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Sometimes built in tools are the best you’ve got.

Page 46: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

It’s still just a deterrent.

Page 47: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important
Page 48: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Clichéd Use of XKCD in a Serious Presentation

Page 49: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Enough about passwords.

Page 50: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Let’s talk about two-factor

authentication.

Page 51: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

First off, what is it?

Page 52: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important
Page 53: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Now we know what it is...

Page 54: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Let’s talk about why.

Page 55: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

It’s mostly to make your password half-useless.

Page 56: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

There are many different “tokens”.

Page 57: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

The Text Message

Page 58: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

The App

Page 59: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important
Page 60: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

The RSA Token

Page 61: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

The Hardware Token

Page 62: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important
Page 63: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important
Page 64: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Malicious Program Protection

Page 65: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important
Page 66: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Securi-Tay’s actually a little wrong there.

Page 67: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

There are different kinds of threats, and different

solutions.

Page 68: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Anti-Malware Versus

Anti-Virus

Page 69: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

It helps consumers to understand the threats

out there.

Page 70: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

It helps to have multiple lines of defense.

Page 71: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

There are some fairly decent products.

Page 72: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

And, some questionable services.

Page 73: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Product choice starts fights.

Page 74: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

There are different measures of success.

Page 75: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Nothing’s perfect.

Page 76: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Remember how we said we don’t like Kaspersky?

Page 77: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Fin.

Page 78: A Presentation for B-Sides CLE Security Not another day ...co-op.antiochcollege.edu/wp-content/uploads/2017/... · Presentation. Mentioning passwords... Device encryption is an important

Resources page is at:j.mp/SecurityNotGuaranteed