{"id":3830,"date":"2022-03-27T09:06:33","date_gmt":"2022-03-27T14:06:33","guid":{"rendered":"https:\/\/control-h.org\/?p=3830"},"modified":"2022-03-27T09:06:33","modified_gmt":"2022-03-27T14:06:33","slug":"shmoocon-again","status":"publish","type":"post","link":"https:\/\/control-h.org\/index.php\/2022\/03\/27\/shmoocon-again\/","title":{"rendered":"Shmoocon Again"},"content":{"rendered":"\n<p>2022 edition after it was cancelled last year.<\/p>\n\n\n\n<p>As I said in the last entry, I&#8217;m really leaning towards not going again.  I&#8217;ll probably do the Shmooze-a-student, and sell the ticket that comes with it at cost.<\/p>\n\n\n\n<p>Physically, I just can&#8217;t do it anymore.<\/p>\n\n\n\n<p>Reflecting on it, though, notably absent were both the detest of the &#8220;other side&#8221; of US politics, and the self-assured consensus that the participants&#8217; political views were going to make everything okay.<\/p>\n\n\n\n<p>One of the things from the last one was the whole Russian collusion narrative about President Trump.  This was my thinking <\/p>\n\n\n\n<p>There are many people who still believe that stuff.<\/p>\n\n\n\n<p>But there&#8217;s still, too, people who believe that Trump won in 2020.<\/p>\n\n\n\n<p>I think there&#8217;s something about admitting when your initial take on something was incorrect.<\/p>\n\n\n\n<p>It&#8217;s probably not fair to expect a speaker at a convention to come back and say, &#8220;yeah, about that,&#8221; but continued silence from others makes me wonder.<\/p>\n\n\n\n<p>I&#8217;m not saying that you come out and shit on previous speakers&#8217; bits, but you can, at least, revisit a bit later.<\/p>\n\n\n\n<p>But on to the individual talks&#8217; reax&#8230;.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p><a href=\"https:\/\/www.shmoocon.org\/speakers#goahead\" target=\"_blank\" rel=\"noreferrer noopener\">First Up<\/a>&#8230;.<\/p>\n\n\n\n<p>Log capture and analysis.  If a bear splints in a forest, does anybody care?  (That&#8217;s what I typed at the time, and I&#8217;m not sure if that was the correct word.  MacBook Air doesn&#8217;t stay on my belly reliably.)<\/p>\n\n\n\n<p>Part of what I&#8217;m doing in my current role is dealing with implementing a Commercial-Off-The-Shelf product to do log monitoring.  <\/p>\n\n\n\n<p>But, for my situation, there&#8217;s enough multi-layer security that these COTS products aren&#8217;t really useful.<\/p>\n\n\n\n<p>At least, now, I&#8217;m not getting pressured to loosen layers of the security stack to let these commercial products work as designed.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p><a href=\"https:\/\/www.shmoocon.org\/speakers\/#tovpnornottovpnthatisthequestion\">Next up<\/a><\/p>\n\n\n\n<p>I tend to use ProtonVPN because I&#8217;m cheap, and it&#8217;s included with my ProtonMail subscription.<\/p>\n\n\n\n<p>(I went with ProtonMail because I felt better about the Swiss protecting customers&#8217; privacy.  The Swiss government&#8217;s response to Russia gives me a bit of pause, but I still feel better about it than anything in the US, EU, or Soviet Canuckistan&#8230;)<\/p>\n\n\n\n<p>The tagline of this site works in reverse, too.  Anytime you do something online, somebody can probably snoop on it.  Deal with it.  <\/p>\n\n\n\n<p>Temporal connections are tougher to crack, but <em>everything can be cracked..<\/em>  It&#8217;s not a question of if, it&#8217;s a question of when.<\/p>\n\n\n\n<p>The talk went into something about APIs, and I think I started to lose the handle on the talk(s).  Maybe the next part was about a different presentation, altogether?  I don&#8217;t know.<\/p>\n\n\n\n<p>Use modern web API programming techniques for &#8230;?<\/p>\n\n\n\n<p>ARM microcontrollers are ubiquitous.<\/p>\n\n\n\n<p>You can tell from the headers of the binaries.  Mix and match thereafter.<\/p>\n\n\n\n<p>Stepped out because I didn&#8217;t think IU&#8217;d get a lot of benefit out of it, and I wasn&#8217;t feeling well.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p><a href=\"https:\/\/shmoocon.org\/speakers\/#sheep\" target=\"_blank\" rel=\"noreferrer noopener\">Scheep<\/a>.<\/p>\n\n\n\n<p>Reading the description, it sounds a bit like a new form of a honeypot;  something there just for people to fuck with to no avail.<\/p>\n\n\n\n<p>I&#8217;m having flashbacks to when I put a GNU\/Hurd box on a publicly-accessible IPv4 address to see how long it took someone to break in.  With Telnet enabled.<\/p>\n\n\n\n<p>It took a Navy Red Team friend several days, but he eventually cracked the password, get a command shell, then didn&#8217;t know what the fuck to do with it.<\/p>\n\n\n\n<p>Due to technical difficulties, presentation didn&#8217;t start until nearly twenty minutes late.<\/p>\n\n\n\n<p>This is an attempt to create a Web Service, not a regular binary on the host.<\/p>\n\n\n\n<p>Good sandbox for both red and blue teams;  tracks everything<\/p>\n\n\n\n<p>Using a packet sniffer, the developer was able to capture HTTP packets, and assemble an HTTP session.  From that assembled HTTP session, he could start figuring out some things.<\/p>\n\n\n\n<p>Bulk command shove;  no idea who ran which command.<\/p>\n\n\n\n<p>The developer used remote shell over HTTP to sites around the world.<\/p>\n\n\n\n<p>For the Windows stuff, he was operating on the WinSock DLL.  <\/p>\n\n\n\n<p>(When I did some programming, I found that DLL to be, ummm&#8230;ancient.  Maybe it&#8217;s gotten better since I was plunking away on it in 2006.)<\/p>\n\n\n\n<p>He is planning to &#8220;open source&#8221; the code, but Larry Ellison <a href=\"https:\/\/www.bbspot.com\/News\/2000\/9\/jerk_options.html\" target=\"_blank\" rel=\"noreferrer noopener\">executing his jerk options again.  <\/a><\/p>\n\n\n\n<p>It does sound like neat tech.  I&#8217;m not sure I completely understand how it&#8217;s used, but, then, I&#8217;m not a pen tester.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p><a href=\"https:\/\/shmoocon.org\/speakers\/#hackthehemisphere\" target=\"_blank\" rel=\"noreferrer noopener\">This<\/a> one about broadcast satellites.<\/p>\n\n\n\n<p>Yes, this is fascinating stuff for me, with my past in the broadcast industry.<\/p>\n\n\n\n<p>I&#8217;m having flashbacks to cleaning fourteen inches of snow out of a C-Band reciever.<\/p>\n\n\n\n<p>(I ended up buying every jug of windshield washer fluid at the 7-Eleven on the way to the transmitter site, and pouring that over the dish until I could get the dish clear enough to pull a signal again.)<\/p>\n\n\n\n<p>The bit about the higher orbit for spent satellites is fascinating to me.  I kind of had just figured they let them fall out of orbit.  But that they send them higher, so they&#8217;re out-of-the-way explains the ring of space junk.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>Discussion of odd <a href=\"https:\/\/shmoocon.org\/speakers#wordpress\" target=\"_blank\" rel=\"noreferrer noopener\">WordPress plugins that might have security issues.<\/a><\/p>\n\n\n\n<p>I understand it, but this, and the work call that had me watching this over the stream link from my hotel room, really reinforce my commitment to not using anything that&#8217;s not supported directly by a vendor.<\/p>\n\n\n\n<p>Trying to do this stuff in-house is just too fraught with peril for my tasted.<\/p>\n\n\n\n<p>Interesting aside that the totes-didn&#8217;t-used-to-do-evil search company downlinks sites that have WP vulgarities.  I, generally, think that SEO is snake oil, but if that&#8217;s what that formerly not-evil company is doing, well&#8230;<\/p>\n\n\n\n<p>Static front page that gets picked up, then escort users in after they land on the static site with tons of keywords in the HEAD element.<\/p>\n\n\n\n<p>There&#8217;s been a big push the past couple of years to force everything behind SSL.  Maybe it makes sense, now, to put most content back in a place where the search engines can&#8217;t capture it?<\/p>\n\n\n\n<p>The tagline for this blog is, &#8220;everything gets deleted, eventually.&#8221;  I&#8217;m sure there&#8217;s things on the Internet I wrote years ago that don&#8217;t reflect my views today.  Whatever.<\/p>\n\n\n\n<p>As more things get pushed behind paywalls, the less background you can find on someone.  I&#8217;m okay with that.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>EFF presentation on some recent <a href=\"https:\/\/shmoocon.org\/speakers#vanburen\" target=\"_blank\" rel=\"noreferrer noopener\">SCOTUS<\/a> decisions.<\/p>\n\n\n\n<p>One of the things I&#8217;d wanted to write about is looking back at Shmoocons past regarding politics.  <\/p>\n\n\n\n<p>Obama was good for privacy.<\/p>\n\n\n\n<p>Trump was elected due to Russian meddling in 2016.<\/p>\n\n\n\n<p>(I touched about that a bit earlier in this entry; I really shouldn&#8217;t still be annoyed by the one thing from 2020, but I am.  You have to admit you&#8217;ve been wrong when that happens.  This kind of speaks to another thing that&#8217;s been bothering me, lately.  I&#8217;d subscribed to the position that Russia wasn&#8217;t going to invade Ukraine.  I was wrong.  So were the people who helped me form that conclusion.)<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>Watching <a href=\"https:\/\/www.shmoocon.org\/speakers#fuzbbpbaehyrf\" target=\"_blank\" rel=\"noreferrer noopener\">this<\/a> about crypto.<\/p>\n\n\n\n<p>Mubix, when he sees something new, he starts trying to figure out how to misuse something.  (Props!)<\/p>\n\n\n\n<p>If you don&#8217;t include &#8220;crypto is horrible,&#8221; or &#8220;crypto sucks&#8221; when you&#8217;re coding in encryption, it will fail.  <\/p>\n\n\n\n<p>Solarwinds was relatively easy to crack because they used old protections, that was probably what caused the problems.<\/p>\n\n\n\n<p>You can&#8217;t spell cryptography without crime.<\/p>\n\n\n\n<hr class=\"wp-block-separator\"\/>\n\n\n\n<p>I didn&#8217;t write much about the final concluding presentations.  I did watch those, because I&#8217;d already checked out of my hotel room.<\/p>\n\n\n\n<p>Did I have a good time?  Um&#8230;I guess?<\/p>\n\n\n\n<p>I needed to do something like that.  It felt good to get out of my apartment for the first time in basically two years.  <\/p>\n\n\n\n<p>Something to discuss with my &#8220;care team&#8221; soon.  Back to work tomorrow.  The Thursday to Saturday thing kind of works when there&#8217;s not a Monday holiday just after.<\/p>\n\n\n\n<p>Next year&#8217;s is the week after MLK Day, which might make things a bit strange for people.<\/p>\n\n\n\n<p>But that I&#8217;ve not really been going to an office regularly in years makes it kind of a yawner.  I probably could have worked today, if needed.  Whatever.<\/p>\n\n\n\n<p>I&#8217;m just glad it&#8217;s not going to be like 2014, where I got laid off my first day back to work after the conference and the Monday holiday.  <\/p>\n\n\n\n<p>I&#8217;ll omit the curses for that company.  They did sponsor Shmoocon this year.  Needless to say, I didn&#8217;t care to stop by their booth.  <\/p>\n","protected":false},"excerpt":{"rendered":"<p>2022 edition after it was cancelled last year. As I said in the last entry, I&#8217;m really leaning towards not going again. I&#8217;ll probably do the Shmooze-a-student, and sell the ticket that comes with it at cost. Physically, I just can&#8217;t do it anymore. Reflecting on it, though, notably absent were both the detest of [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8],"tags":[],"class_list":["post-3830","post","type-post","status-publish","format-standard","hentry","category-shmoocon"],"_links":{"self":[{"href":"https:\/\/control-h.org\/index.php\/wp-json\/wp\/v2\/posts\/3830","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/control-h.org\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/control-h.org\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/control-h.org\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/control-h.org\/index.php\/wp-json\/wp\/v2\/comments?post=3830"}],"version-history":[{"count":0,"href":"https:\/\/control-h.org\/index.php\/wp-json\/wp\/v2\/posts\/3830\/revisions"}],"wp:attachment":[{"href":"https:\/\/control-h.org\/index.php\/wp-json\/wp\/v2\/media?parent=3830"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/control-h.org\/index.php\/wp-json\/wp\/v2\/categories?post=3830"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/control-h.org\/index.php\/wp-json\/wp\/v2\/tags?post=3830"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}