2010 za con_haroon_meer

79
“Fig Leaf Security” @haroonmeer - 2010 Sunday 17 October 2010

Upload: johan-klerk

Post on 18-Aug-2015

5 views

Category:

Documents


3 download

TRANSCRIPT

Page 1: 2010 za con_haroon_meer

“Fig Leaf Security”@haroonmeer - 2010

Sunday 17 October 2010

Page 2: 2010 za con_haroon_meer

Who am i ?

&Why this talk?

Sunday 17 October 2010

Page 3: 2010 za con_haroon_meer

A chance to meet our heroes!

Sunday 17 October 2010

Page 4: 2010 za con_haroon_meer

like Simple Nomad!

Sunday 17 October 2010

Page 5: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 6: 2010 za con_haroon_meer

thegnome: we expected

Sunday 17 October 2010

Page 7: 2010 za con_haroon_meer

thegnome: we got

Sunday 17 October 2010

Page 8: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 9: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 10: 2010 za con_haroon_meer

this is my rant..

Sunday 17 October 2010

Page 11: 2010 za con_haroon_meer

•The infosec industry• ZA infosec research

Sunday 17 October 2010

Page 12: 2010 za con_haroon_meer

InfoSec: We Suck

Sunday 17 October 2010

Page 13: 2010 za con_haroon_meer

and it’s our fault

Sunday 17 October 2010

Page 14: 2010 za con_haroon_meer

No ?

Sunday 17 October 2010

Page 15: 2010 za con_haroon_meer

Bet on your architecture?

Sunday 17 October 2010

Page 16: 2010 za con_haroon_meer

Write code for a living?

Sunday 17 October 2010

Page 17: 2010 za con_haroon_meer

So we build secure networks, but can’t protect our most prized user

and we write code, that we know cant stand up to security

testing?

Sunday 17 October 2010

Page 18: 2010 za con_haroon_meer

but nobody can write secure code

Sunday 17 October 2010

Page 19: 2010 za con_haroon_meer

Right?

Sunday 17 October 2010

Page 20: 2010 za con_haroon_meer

Wrong!

Sunday 17 October 2010

Page 21: 2010 za con_haroon_meer

<Brief Digression>(sub-rant)

Sunday 17 October 2010

Page 22: 2010 za con_haroon_meer

Do you know these men?

Sunday 17 October 2010

Page 23: 2010 za con_haroon_meer

we hero worship the wrong guys..

Sunday 17 October 2010

Page 24: 2010 za con_haroon_meer

</Brief Digression>(sub-rant)

Sunday 17 October 2010

Page 25: 2010 za con_haroon_meer

but nobody can write secure code

Sunday 17 October 2010

Page 26: 2010 za con_haroon_meer

ok. not (secure and usable)

Sunday 17 October 2010

Page 27: 2010 za con_haroon_meer

Really?

Sunday 17 October 2010

Page 28: 2010 za con_haroon_meer

sendmail vs qmail ?djbdns vs bind ?

Sunday 17 October 2010

Page 29: 2010 za con_haroon_meer

So why did we think otherwise?

Sunday 17 October 2010

Page 30: 2010 za con_haroon_meer

Charlatans

Sunday 17 October 2010

Page 31: 2010 za con_haroon_meer

fig leaves!

Sunday 17 October 2010

Page 32: 2010 za con_haroon_meer

Application Testing..

Sunday 17 October 2010

Page 33: 2010 za con_haroon_meer

“Halting Problem!”

Sunday 17 October 2010

Page 34: 2010 za con_haroon_meer

“patching is a hard” problem

Sunday 17 October 2010

Page 35: 2010 za con_haroon_meer

“patching is a hard” problem

Sunday 17 October 2010

Page 36: 2010 za con_haroon_meer

Management don’t buy in!

Sunday 17 October 2010

Page 37: 2010 za con_haroon_meer

Management don’t buy in!

Sunday 17 October 2010

Page 38: 2010 za con_haroon_meer

AV’s and V’s

Sunday 17 October 2010

Page 39: 2010 za con_haroon_meer

Why the double standard?

Sunday 17 October 2010

Page 40: 2010 za con_haroon_meer

We (seem to) only fight the fights

we can (kinda) win

Sunday 17 October 2010

Page 41: 2010 za con_haroon_meer

aka: “buying what ppl are selling”

Sunday 17 October 2010

Page 42: 2010 za con_haroon_meer

hiding behind our fig leaves..

Sunday 17 October 2010

Page 43: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 44: 2010 za con_haroon_meer

“You & Your Research”

http://www.cs.virgina.edu/~robins/YouAndYourResearch.html

Sunday 17 October 2010

Page 45: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 46: 2010 za con_haroon_meer

So why don’t we do more?

Sunday 17 October 2010

Page 47: 2010 za con_haroon_meer

it’s hard..

Sunday 17 October 2010

Page 48: 2010 za con_haroon_meer

easy to start..(ideas are cheap)

Sunday 17 October 2010

Page 49: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 50: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 51: 2010 za con_haroon_meer

Research Fig Leaves

Sunday 17 October 2010

Page 52: 2010 za con_haroon_meer

Research Fig Leaves

Sunday 17 October 2010

Page 53: 2010 za con_haroon_meer

XXX is lame

Sunday 17 October 2010

Page 54: 2010 za con_haroon_meer

XXX is lame

Sunday 17 October 2010

Page 55: 2010 za con_haroon_meer

Academic masturbation!

Sunday 17 October 2010

Page 56: 2010 za con_haroon_meer

Academic masturbation!

Sunday 17 October 2010

Page 57: 2010 za con_haroon_meer

“doesn’t impress me”

Stephan Fry: Advice to a younger self.

Sunday 17 October 2010

Page 58: 2010 za con_haroon_meer

“doesn’t impress me”

Stephan Fry: Advice to a younger self.

Sunday 17 October 2010

Page 59: 2010 za con_haroon_meer

Distraction

Sunday 17 October 2010

Page 61: 2010 za con_haroon_meer

http://www.acceleratingfuture.com/michael/blog/images/Amusing-Ourselves-To-Death.jpgText

Sunday 17 October 2010

Page 62: 2010 za con_haroon_meer

http://www.acceleratingfuture.com/michael/blog/images/Amusing-Ourselves-To-Death.jpgText

Sunday 17 October 2010

Page 63: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 64: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 65: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 66: 2010 za con_haroon_meer

“Amusing ourselves to Death”Sunday 17 October 2010

Page 67: 2010 za con_haroon_meer

“Amusing ourselves to Death”Sunday 17 October 2010

Page 68: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 69: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 70: 2010 za con_haroon_meer

Sunday 17 October 2010

Page 71: 2010 za con_haroon_meer

No Interesting Problems..

Sunday 17 October 2010

Page 72: 2010 za con_haroon_meer

No Interesting Problems..

Sunday 17 October 2010

Page 73: 2010 za con_haroon_meer

“Work on stuff that matters”

“New Threats to Privacy”

Sunday 17 October 2010

Page 74: 2010 za con_haroon_meer

There are important battles to fight..

Sunday 17 October 2010

Page 75: 2010 za con_haroon_meer

“Don’t just be the guy who tweeted

about it”

Sunday 17 October 2010

Page 76: 2010 za con_haroon_meer

Don’t just fight the fights we can

(kinda)win

Sunday 17 October 2010

Page 77: 2010 za con_haroon_meer

Fight the fights that need fighting

Sunday 17 October 2010

Page 78: 2010 za con_haroon_meer

We need to produce more than we consume..

Sunday 17 October 2010

Page 79: 2010 za con_haroon_meer

We need [email protected]

@haroonmeer

Sunday 17 October 2010