Shmoocon Again

2022 edition after it was cancelled last year.

As I said in the last entry, I’m really leaning towards not going again. I’ll probably do the Shmooze-a-student, and sell the ticket that comes with it at cost.

Physically, I just can’t do it anymore.

Reflecting on it, though, notably absent were both the detest of the “other side” of US politics, and the self-assured consensus that the participants’ political views were going to make everything okay.

One of the things from the last one was the whole Russian collusion narrative about President Trump. This was my thinking

There are many people who still believe that stuff.

But there’s still, too, people who believe that Trump won in 2020.

I think there’s something about admitting when your initial take on something was incorrect.

It’s probably not fair to expect a speaker at a convention to come back and say, “yeah, about that,” but continued silence from others makes me wonder.

I’m not saying that you come out and shit on previous speakers’ bits, but you can, at least, revisit a bit later.

But on to the individual talks’ reax….


First Up….

Log capture and analysis. If a bear splints in a forest, does anybody care? (That’s what I typed at the time, and I’m not sure if that was the correct word. MacBook Air doesn’t stay on my belly reliably.)

Part of what I’m doing in my current role is dealing with implementing a Commercial-Off-The-Shelf product to do log monitoring.

But, for my situation, there’s enough multi-layer security that these COTS products aren’t really useful.

At least, now, I’m not getting pressured to loosen layers of the security stack to let these commercial products work as designed.


Next up

I tend to use ProtonVPN because I’m cheap, and it’s included with my ProtonMail subscription.

(I went with ProtonMail because I felt better about the Swiss protecting customers’ privacy. The Swiss government’s response to Russia gives me a bit of pause, but I still feel better about it than anything in the US, EU, or Soviet Canuckistan…)

The tagline of this site works in reverse, too. Anytime you do something online, somebody can probably snoop on it. Deal with it.

Temporal connections are tougher to crack, but everything can be cracked.. It’s not a question of if, it’s a question of when.

The talk went into something about APIs, and I think I started to lose the handle on the talk(s). Maybe the next part was about a different presentation, altogether? I don’t know.

Use modern web API programming techniques for …?

ARM microcontrollers are ubiquitous.

You can tell from the headers of the binaries. Mix and match thereafter.

Stepped out because I didn’t think IU’d get a lot of benefit out of it, and I wasn’t feeling well.


Scheep.

Reading the description, it sounds a bit like a new form of a honeypot; something there just for people to fuck with to no avail.

I’m having flashbacks to when I put a GNU/Hurd box on a publicly-accessible IPv4 address to see how long it took someone to break in. With Telnet enabled.

It took a Navy Red Team friend several days, but he eventually cracked the password, get a command shell, then didn’t know what the fuck to do with it.

Due to technical difficulties, presentation didn’t start until nearly twenty minutes late.

This is an attempt to create a Web Service, not a regular binary on the host.

Good sandbox for both red and blue teams; tracks everything

Using a packet sniffer, the developer was able to capture HTTP packets, and assemble an HTTP session. From that assembled HTTP session, he could start figuring out some things.

Bulk command shove; no idea who ran which command.

The developer used remote shell over HTTP to sites around the world.

For the Windows stuff, he was operating on the WinSock DLL.

(When I did some programming, I found that DLL to be, ummm…ancient. Maybe it’s gotten better since I was plunking away on it in 2006.)

He is planning to “open source” the code, but Larry Ellison executing his jerk options again.

It does sound like neat tech. I’m not sure I completely understand how it’s used, but, then, I’m not a pen tester.


This one about broadcast satellites.

Yes, this is fascinating stuff for me, with my past in the broadcast industry.

I’m having flashbacks to cleaning fourteen inches of snow out of a C-Band reciever.

(I ended up buying every jug of windshield washer fluid at the 7-Eleven on the way to the transmitter site, and pouring that over the dish until I could get the dish clear enough to pull a signal again.)

The bit about the higher orbit for spent satellites is fascinating to me. I kind of had just figured they let them fall out of orbit. But that they send them higher, so they’re out-of-the-way explains the ring of space junk.


Discussion of odd WordPress plugins that might have security issues.

I understand it, but this, and the work call that had me watching this over the stream link from my hotel room, really reinforce my commitment to not using anything that’s not supported directly by a vendor.

Trying to do this stuff in-house is just too fraught with peril for my tasted.

Interesting aside that the totes-didn’t-used-to-do-evil search company downlinks sites that have WP vulgarities. I, generally, think that SEO is snake oil, but if that’s what that formerly not-evil company is doing, well…

Static front page that gets picked up, then escort users in after they land on the static site with tons of keywords in the HEAD element.

There’s been a big push the past couple of years to force everything behind SSL. Maybe it makes sense, now, to put most content back in a place where the search engines can’t capture it?

The tagline for this blog is, “everything gets deleted, eventually.” I’m sure there’s things on the Internet I wrote years ago that don’t reflect my views today. Whatever.

As more things get pushed behind paywalls, the less background you can find on someone. I’m okay with that.


EFF presentation on some recent SCOTUS decisions.

One of the things I’d wanted to write about is looking back at Shmoocons past regarding politics.

Obama was good for privacy.

Trump was elected due to Russian meddling in 2016.

(I touched about that a bit earlier in this entry; I really shouldn’t still be annoyed by the one thing from 2020, but I am. You have to admit you’ve been wrong when that happens. This kind of speaks to another thing that’s been bothering me, lately. I’d subscribed to the position that Russia wasn’t going to invade Ukraine. I was wrong. So were the people who helped me form that conclusion.)


Watching this about crypto.

Mubix, when he sees something new, he starts trying to figure out how to misuse something. (Props!)

If you don’t include “crypto is horrible,” or “crypto sucks” when you’re coding in encryption, it will fail.

Solarwinds was relatively easy to crack because they used old protections, that was probably what caused the problems.

You can’t spell cryptography without crime.


I didn’t write much about the final concluding presentations. I did watch those, because I’d already checked out of my hotel room.

Did I have a good time? Um…I guess?

I needed to do something like that. It felt good to get out of my apartment for the first time in basically two years.

Something to discuss with my “care team” soon. Back to work tomorrow. The Thursday to Saturday thing kind of works when there’s not a Monday holiday just after.

Next year’s is the week after MLK Day, which might make things a bit strange for people.

But that I’ve not really been going to an office regularly in years makes it kind of a yawner. I probably could have worked today, if needed. Whatever.

I’m just glad it’s not going to be like 2014, where I got laid off my first day back to work after the conference and the Monday holiday.

I’ll omit the curses for that company. They did sponsor Shmoocon this year. Needless to say, I didn’t care to stop by their booth.

Shmoo 6

Scheep.

Reading the description, it sounds a bit like a new form of a honeypot; something there just for people to fuck with to no avail.

I’m having flashbacks to when I put a GNU/Hurd box on an publicly-accessible IPv4 address to see how long it took someone to break in. With Telnet enabled.

It took a Navy Red Team friend several days, but he eventually cracked the password, got a command shell, then didn’t know what the fuck to do with it.

Due to technical difficulties, presentation didn’t start until nearly twenty minutes late.

This is an attempt to create a Web Service, not a regular binary on the host.

Good sandbox for both red and blue teams; tracks everything

HTTP capture signatures.

Bulk command shove; no idea who ran which command.

Remote shell over http to sites around the world.

For the Windows stuff, he was operating on the WinSock dll. When I did some programming, I found it ummm…ancient. Maybe it’s gotten better since I was plunking away on it in 2006.

He is planning to “open source” the code, but Larry Ellison executing his jerk options again.

It does sound like neat tech. I’m not sure I completely understand how it’s used, but, then, I’m not a pen tester.

Own The Con 16

Discussion of how long Bruce and Heidi have been married. Sixteen years this summer. My wife and I have been together fifteen in a few years (but only married for evelven).

I remember back in the day bringing my then-girlfriend with me just so they could come close to selling out. 2008-ish?

For potential speakers, you need to follow directions exactly. (I wrote the beginnings of a talk in probably about 2010. I had about 40 minutes of speaking, and half a slide deck. I started going through potential questions from an audience, and got to one I couldn’t answer….and it was a question that really related to the heart of the presentation….so I gave up, and just bought a ticket.)

The ticket sales glut has kind of ended after they put the kibosh on second-hand ticket sales.

That actually makes me feel a bit better about my tentative intention at this point to do the Shmooze-A-Student again. If I’m financially able, I’ll buy a ticket for a kid, and sell my ticket to someone else.

Physically, I can’t do this anymore. Much of what I did yesterday was sitting in my hotel room watching the stream.

Naturally when I was younger, I really appreciated the new experiences that came along with being in DC. The novelty has more than worn off.

They saved a lot of money this year by not having the drink-a-palooza on Saturday night.

You know, I don’t think I’ve ever been to one of those. But they’re really not earning money on any of this, and are paying taxes on it.

(I’ll avoid going in go off on my bit about income taxes. More than half of the people who file don’t pay any income taxes. Payroll taxes are not taxes; they are contributions to the bankrupt Ponzi schemes that are Social Security and Medicare)

Close up was a potential giveaway of a (Dude-your-gettin-a) Dell server.

I have no place for toys like that anymore, unfortunately. And if I was going to get a nondescript Dell server, I think I’d like something with an Italic processor.

But they’re loud as hell.

I swear I’ll get many of the notes on other talks up over the next few days. As I said, I really don’t have the energy to do this con stuff anymore.

Shmoo Eight

Discussion of odd WordPress plugins that might have security issues.

I understand it, but this, and the work call that had me watching this over the stream link from my hotel room, really reinforce my commitment to not using anything that’s not supported directly by a vendor.

Trying to do this stuff in-house is just too fraught with peril for my tasted.

Interesting aside that the totes-didn’t-used-to-do-evil search company downlinks sites that have WP vulgarities. I, generally, think that SEO is snake oil, but if that’s what that formerly not-evil company is doing, well…

Static front page that gets picked up, then escort users in after they land on the static site with tons of keywords in the HEAD element.

2022 Talk 1

https://www.shmoocon.org/speakers/#tovpnornottovpnthatisthequestion

I tend to use ProtonVPN because I’m cheap, and it’s included with my ProtonMail subscription.

The tagline of this site works in reverse, too. Anytime you do something online, somebody can probably snoop. Deal with it.

Temporal connections are tougher to crack, but everything can be cracked.. It’s not a question of if, it’s a question of when.

Sure Happy It’s Thursday

S.H.I.Thursdays, everybuddy. *quack*quack*

I’m really happy I didn’t end up a zookeeper.

Especially, now, where instead of going to a crappy little station somewhere to be a minor local celeb, but I really prefer where I am.

Obviously I don’t like having MS. It was more than a little dismaying learning that an old journaling friend was diagnosed the past fall.

Things change, but you can always leave.

I unsubscribed from a few podcasts after what happened with Russia and Ukraine. I emailed Kennedy to tell her I wouldn’t be watching episodes where she’s got those people as guests.

One of them lost the debate I went to see in NYC, and I’ve written about here before.

But you also can sorta go back again. So I’ll go to the TWUUG meeting tonight before I do extra work. Party.

Suddenly Saturday

I really didn’t feel like working yesterday, but I did. I also ended up working last night to address an operational issue that arose over the work day.

Since then, minus about four hours of sleep, I’ve been watching what’s going on in Ukraine.

Many of the information sources I’ve been consuming the past couple of years were completely wrong.

There’s just no other way to put it. I was convinced that the Russians would try to invade.

And they did.

And there’s been near silence about it.

Checking his Twitter feed, pretty much nothing over the past two days, save a link to fucking Antiwar.com.

Calling back to the late, great P.J. O’Rourke, Give War A Chance.

I’m too frazzled to write terribly coherently right now.

But there’s lots of things where I’d signed-up for something that’s proving to be untrue.

Back On Track

Maybe.

Very, very, very long week. That, and about five ounces of Gin and Tonic, caused me to sleep through part of it. Oops. I hope I wasn’t snoring, and if I was, I hope that the mic was muted. Good discussion at the end of where we got into a little about what I think is the um, trying to figure out the politest way to say this, maladjusted view of foreign policy of some in the libertarian movement.

(I know, I know, I can’t say that because I’m not the one defining what is 2022 Libertarianism, but, well, I’ve been here for a while, and read and argued many sides of an issue…..but, hey, that’s not libertarianism, because and I fucking wrote what libertarianism is based on my narrow reading list from the RON PAUL 2008 campaign….)

In other news, things are a lot calmer, otherwise, this week, thankfully.

I should make a to-do list for the next few months.

Next month is Shmoocon. I need to figure out what I want to see.

April, I hope I’ll be able to travel down to see my mom’s new house. This week was spent trying to get her set up with a new iPhone, as her provider cut off the cellular network her old phone used.

May is another medical procedure.

June may be figuring out what to do if I end up being unemployed at the end of that month.

No idea with the rest of the year, except that I do want to go to the Super-spreader event in Mexico in the Winter.

Sunday With

There’s a Sportsball game or something today. Hat-tip to Bald Bryan.

I guess what annoys me is the admonition that goes along with it. So you don’t care about Football. Great. Many people do. If you don’t want to participate in the hoopla surrounding, go do what you’d like to do. Or make some money serving the people who do care.

I admit I’ve mocked people in the past for engaging in activities I don’t understand. I know I said a few things about the people camped out outside of the theaters when Star Wars came out in 1999

I had a job back then. If I didn’t, I could have done something.t

At the same time, I was still such a stickler for following THE RULES back then, I probably would have never even considered doing anything ummm, outside them. There’s a “No soliciting” sign in the theatre parking lot. Okay, and? Who would I have been hurting, really, by providing for those people with interests that differ from my own?

Kind of feeds in to what’s going on with the truckers blocking all sorts of shit right now. They don’t like THE RULES, and, by just doing what they can, they’re really fucking things up for the PM up there.

Yah, sorry. We’re not leavin’.

The autocorrect in Safari is kind of annoying.

But, being such a stickler for following rules, no matter how stupid they are, worked for me well for a long time. Following them feeds into my obsessive side.

The compulsive side, on the other hand, is writing. Obviously, I’ve managed to stay pretty sparse over here since I finished NoJoMo. I am writing episode recaps over at Back At Again, but that’s about it.

I hope this week is rather low-stress, as opposed to last week.