filmov
tv
DEF CON Safe Mode Crypto and Privacy Village - Per Thorsheim - Hacking like Paris Hilton

Показать описание
Simswap attacks has increased in recent years, with several high-profile cases in the media showing very fast & effective ways of duping people or getting access to valuable accounts . All the way back in 2006 Paris Hilton got accused of hacking into the voicemail of Lindsay Lohan, while similar scandals has been observed since then in other countries as well.
Asking around in my home country of Norway, neither simswap attacks or voicemail hacking seemed to be known among most infosec people, or at least not part of anyone's risk analysis. So I decided to take a closer look.
The results were shocking at many levels, from technical levels to political decisions & apathy. Several million customers of 3 different carriers in 3 countries were exposed to potential voicemail hacking for up to 13 years. A fake business card was enough to do a simswap & hijack the number of a famous female blogger, while credential stuffing against a mobile carrier allowed for account hijacking of women who used SMS 2FA with their accounts at various services.
This talk will explain what I found, what I did, and how it changed carriers, government agencies, politics & law.
Asking around in my home country of Norway, neither simswap attacks or voicemail hacking seemed to be known among most infosec people, or at least not part of anyone's risk analysis. So I decided to take a closer look.
The results were shocking at many levels, from technical levels to political decisions & apathy. Several million customers of 3 different carriers in 3 countries were exposed to potential voicemail hacking for up to 13 years. A fake business card was enough to do a simswap & hijack the number of a famous female blogger, while credential stuffing against a mobile carrier allowed for account hijacking of women who used SMS 2FA with their accounts at various services.
This talk will explain what I found, what I did, and how it changed carriers, government agencies, politics & law.
DEF CON Safe Mode Crypto and Privacy Village - Emily Crose - Fun with FOIA
DEF CON Safe Mode Crypto and Privacy Village -Kelley Robinson- What if we had TLS for phone numbers?
DEF CON Safe Mode Blockchain Village - Peiyu Wang - Exploit Insecure Crypto Wallet
DEF CON Safe Mode Crypto and Privacy Village - Per Thorsheim - Hacking like Paris Hilton
DEF CON Safe Mode Crypto and Privacy Village - Mansi Sheth - How to store sensitive info in 2020?
DEF CON Safe Mode Blockchain Village - Ryan Rubin - Is DeFi Ready for Prime Time
DEF CON Safe Mode - Christopher Wade - Beyond Root
DEF CON Safe Mode Crypto and Privacy Village - Zhanna Malekos Smith - Fear Uncertainty and Doubt
DEF CON Safe Mode Blockchain Village - Martin Abbatemarco - 7 Phases Of Smart Contract Hacking
DEF CON Safe Mode Crypto and Privacy Village - Hanno Böck - STARTTLS is Dangerous
DEF CON Safe Mode Blockchain Village - Ron Stoner - Securing The Cosmos
DEF CON Safe Mode Blockchain Village - Peter Kacherginsky - Keynote
DEF CON Safe Mode - Elie Bursztein - A Hacker’s Guide to Reducing Side Channel Attack Surfaces
DEF CON Safe Mode Crypto and Privacy Village - Cathy Gellis, Riana Pfefferkorn - Fireside Chat
DEF CON Safe Mode - The Dark Tangent and Lostboy - Welcome to DEF CON Safe Mode and Badge Talk
DEF CON Safe Mode Red Team Village - Travis Palmer - Passwd Cracking Beyond 15 Chars, Under $500
DEF CON Safe Mode - Joshua Maddux - When TLS Hacks You
DEF CON Safe ModeBlockchain Village - Peiyu Wang - Exploit Insecure Crypto Wallet
DEF CON Safe Mode Crypto and Privacy Village - Porter Adams and Emily Stamm - Online Voting
DEF CON Safe Mode - Michael Stay - How we recovered XXX,000 in Bitcoin from an encrypted zip file
DEF CON Safe Mode Monero Village - zkao - Bitcoin Monero Atomic Swaps
DEF CON Safe Mode Blockchain Village - Peter Kacherginsky - Attacking & Defending Blockchain No...
DEF CON Safe Mode Voting Village - Michael A Specter - The Ballot is Busted before the Blockchain
DEF CON Safe Mode Blockchain Village - Josh McIntyre - Chaintuts - Bitcoin Address Generator
Комментарии