devnexus 2016: wait! wait! don't pwn me!

78
#DontPwnMe Wait! Wait! Don’t pwn me! The Security News Game Show

Upload: seniorstoryteller

Post on 18-Jan-2017

154 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Wait! Wait! Don’t pwn me!The Security News Game Show

Page 2: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

#DontPwnMe@TSWAlliance

Page 3: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

The Rules• Each correct answer to the initial question is

worth 3 points• A wrong answer subtracts 2 points• A pass on a question loses 1 point• A correct answer from an audience member

gets allocated 2 points to the panelist of their choice

Page 4: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

The moderator may arbitrarily give or take away points at any time

The Rules

Page 5: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

We need a volunteer to keep score.

The Rules

Page 6: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

To get a copy of the slidesimmediately…

[email protected]

Page 7: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Online News Resources

Page 8: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 9: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Researchers have found a way to take down the power grid through something in your home. What is it?

Page 10: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 11: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

On February 5, 2016, a UN Working Group on Arbitrary Retention declared a specific internet celebrity is being held illegally. Who is it?

Page 12: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 13: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

What should you do to keep the NSA Hacker Chief out of your system?

Page 14: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 15: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

At the Enigma Security Conference in San Francisco, Nicholas Weaver talked about a system that could do what?

(Hint: It competes on a miniature scale with a three letter agency.)

Page 16: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 17: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Two power distribution companies in what country said hackers had hijacked their systems to cut power to more than 80,000 people.

Page 18: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 19: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Name one of the top five biggest security threats of 2016 according to Wired.

Page 20: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

• Extortion Hacks• Attacks that change or manipulate data• Chip-and-Pin Innovations• The Rise of the IoT Zombie Botnet• More Backdoors

Page 21: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Name one of the five comics you must read before seeing DeadPool.

Page 22: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Deadpool Vol. 3 #1-33 (1997-1999)Cable & Deadpool #1-6 (2004)Deadpool Max #1-12 (2010-2011)Uncanny X-Force Vol. 1 #25-35 (2011-2012)Deadpool Vol. 5 #13-19 (2013)

Page 23: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 24: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Valentine’s Day saw major hacks against which, major merchant group?

Page 25: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 26: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

“Man Admits To Laundering $19.6 Million in Hacking, Telecom Fraud Scam”. What did he do?

Page 27: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 28: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

What health care company had the largest breach of 2015, exposing the personal data of over 80,000,000 patients?

Page 29: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 30: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

According to James Clapper, US Director of National Intelligence, this is the next surveillance frontier.

Page 31: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 32: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 33: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Which of the major movie stream providers got called out by Symantec for malware, scams and phishing schemes?

Amazon Prime VideoNetflixHulu

Page 34: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 35: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Which non-browser based application was hit with the latest malvertising scam?

Page 36: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 37: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

What percentage of mobile apps have at least one high security risk flaw?

Page 38: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 39: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 40: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

What percentage of ID theft can be attributed to tax refund fraud?

23%34%47%

Page 41: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 42: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Oracle confirmed it’s next major release of Java will no longer do what?• Completely hose your browser during

an important live meeting• Plug directly into your browser• Be compatible with Windows 7 or less• Call home to Oracle with no notice

Page 43: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 44: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

What major grocery chain got hacked with skimmers at the self-service checkout kiosks?

• Safeway• Piggly Wiggly• Albersons

Page 45: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 46: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

ComfortLink thermostats come with a “interesting” hole in their security. What is it?• Hardcoded passwords• Cross-frequency interference to your

local wireless network• All devices have the same default

password

Page 47: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 48: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

How are fraudsters tapping Kohl’s for cash through the “Kohl’s Cash” program?

Page 49: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 50: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 51: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Women are considered better coders… if they do this one, specific thing.

Page 52: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 53: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

What’s the most nonsensical way to brick your iPhone, iPad or iPad touch?• Pinch photos so small, machine

crashes and won’t reboot• Set the date to 1 January 1970• Connect to an unknown service to

download a “patch”

Page 54: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 55: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

“Error 53” on an iPhone 6 has a lot of people pissed off. What does it do?

Page 56: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 57: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 58: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

After the announcement of WebSense being acquired by Ratheon, what did scammers send as email to WebSense employees?

Page 59: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 60: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

PhishMe just raised $13 million in funding. What do they do?

Page 61: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 62: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Name one of the top three phishing trends for 2016.

Page 63: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Trend 1: Consolidation of TargetsTrend 2: Explosive Chinese Phishing GrowthTrend 3: Plunging Phishing Uptimes

Page 64: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 65: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Disney recently requested to be able to fly drones in their own amusement parks. What snag did they hit?

Page 66: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 67: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

What happened when a Chinese TV station replaced its meteorologist with a chatbot?

Page 68: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 69: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Sadly, a computer just beat a master player at one of the most complex board games. What game?

Page 70: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 71: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Biggest Stories of the Week

Page 72: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Samsung want customers to stop doing what with their TVs?

Page 73: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 74: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Final question:

Hackers are holding what company’s network hostage for $3.6 million?

Page 75: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Page 76: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

What is the final score?

Page 77: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

To get a copy of the slidesimmediately…

[email protected]

Page 78: DevNexus 2016: Wait! Wait! Don't pwn me!

#DontPwnMe

Thank You!