42
PUBLIC//NSI//ORNCON//YESFORN By Ron Williams & Hyun Seo TAKE BACK CONTROL IN A POST-SNOWDEN WORLD

Take Back Control in a Post-Snowden World

Embed Size (px)

Citation preview

Page 1: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

By Ron Williams & Hyun Seo

TAKE BACK CONTROL INA POST-SNOWDEN WORLD

Page 2: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

The content and tools mentioned in this workshop are for educational purposes only.

We do not endorse or promote any specific products or tools.

Any opinions expressed are our own and are not intended to reflect the views of our employer.

Page 3: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Ron WilliamsArchitect, IBM Security

Hyun SeoDesigner, IBM Security

Page 4: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Our mission...

Page 5: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

SecurityBeing free from danger and/or threat.

Page 6: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

AnonymityWithout any name acknowledged, as that of author, contributor, or the like.

Page 7: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

PrivacyBeing free from unwanted or undue intrusion or disturbance in one’s life or affairs.

Page 8: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

We are not deliberately hiding anything when we seek out private places for reflection or conversation. We keep private journals, sing in the privacy of the shower, and write letters to secret lovers and then burn them. Privacy is a basic human need.

“Bruce Schneier, Schneier on Security ”

Page 9: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Page 10: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Government, Personal,Commercial, Criminal.

Page 11: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Anytime you share information, you lose control over it.

Page 12: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Legitimate* and illegitimate surveillance.Employer, government (local, state, federal) agencies, criminals.

*Within the bounds of existing law.

Page 13: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Automated surveillance techniques are not perfect.Profiles (of employees, citizens) are developed from incomplete data.

Page 14: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

GovernmentSurveillance

Page 15: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

If I’m not doing anything wrong, why should I care about government surveillance?

Page 16: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

December 7th, 1941

Page 17: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

“NATIONAL SECURITY”

Page 18: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Page 19: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Lavabit

Page 20: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

The government is constrained by law.

Page 21: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

The government is constrained by law. Today.

Page 22: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Page 23: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

CommercialSurveillance

Page 24: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

If you’re not paying for the product, you’re the product.

Page 25: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

CommercialSocial Media

Aggregation & Analysis of User Data

Monetization of Analysis

Product Services

User market data

Retail optimization

Who

What

Why

Page 26: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Employee

Browser activityInformation access and usage Compliance monitoringSocial Media usagePhone voice monitoring

Employee MonitoringWho

What

Why Business Security

Page 27: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Crime as a Service

Page 28: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

BOT-NETOPERATOR

MALWAREAUTHORS

VULNERABILITYRESEARCHERS

BOT-NET

cCommercesales &

marketingservice catalog

advertisingfinance

counter-surveillance

Servicesddos

spambot-net C&C

malware deliverykey logging

surveillancecredential theft

espionage

CaaS CONSUMER

Page 29: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Reducing yourdigital footprint

Page 30: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Three can keep a secret, if two are dead.“Benjamin Franklin ”

Page 31: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

AndroidEmail

Voice & SMS

IM

Mail Services

S/MIME, PGP

Signal

ChatSecure

ProtonMail, Tutanota, GhostMail

Page 32: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

iOSEmail

Voice & SMS

IM

Mail Services

S/MIME

Facetime, iMessage, Signal

iMessage

ProtonMail, Tutanota, GhostMail

Page 33: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Traditional PC’sText & Files

IM

Mail Services

S/MIME, PGP

Off-the-record XMPP Protocol

ProtonMail, Tutanota, GhostMail

Page 34: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

NetworkRouter

Software

VPN

Passphrase

DNS

Don’t rent your router

Install an open source firmware

OpenVPN

Strong passphrase, disable “WPS”

OpenNIC, FreeDNS

Page 35: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Digital Hygiene

Page 36: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Page 37: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

AndroidDevice

Search

Browser

VPN

Other

Disable Backup, Turn off Location, Info Collection, and radios

DuckDuckGo, Disconnect.Me

ORFox & ORBot, Firefox

Anonymous VPN

Try to be “Google Play”-free

Page 38: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

iOSDevice

Search

Browser

VPN

Disable iCloud Backup, Turn off Location, Info Collection, and radios

DuckDuckGo, Disconnect.Me

Safari, Firefox

Anonymous VPN

Page 39: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Traditional PC’sDevice

Search

Browser

VPN

Disable cloud backup, turn off location, Info Collection, and radios

DuckDuckGo, Disconnect.Me

Safari, Firefox, Chromium

Anonymous VPN

Page 40: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Citizenfour & No Place To Hide

privacytools.io

Page 41: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

Thank you!

https://www.linkedin.com/in/rbwilliams https://www.linkedin.com/in/[email protected]@us.ibm.com

Page 42: Take Back Control in a Post-Snowden World

PUBLIC//NSI//ORNCON//YESFORN

http://pastebin.com/byUPX6WmAdditional Information