in the wake of ashley madison - jim salter

17
In The Wake of Ashley Madison information security lessons (hopefully) learned This presentation is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License. (C) 2015 [email protected] Jim Salter Mercenary Sysadmin, Small Business Owner Today's slides can be found at: http://openoid.net/presentations/

Upload: it-ology

Post on 20-Jan-2017

239 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: In the Wake of Ashley Madison - Jim Salter

In The Wake of Ashley Madisoninformation security lessons (hopefully) learned

This presentation is licensed under a Creative Commons Attribution-NonCommercial-ShareAlike 3.0 Unported License.(C) 2015 [email protected]

Jim SalterMercenary Sysadmin,Small Business Owner

Today's slides can be found at:

http://openoid.net/presentations/

Page 2: In the Wake of Ashley Madison - Jim Salter

The promise of Ashley Madison

Page 3: In the Wake of Ashley Madison - Jim Salter

The reality of Ashley Madison

Page 4: In the Wake of Ashley Madison - Jim Salter

This talk is not about ethics in adultery.

(or in video game journalism)

Page 5: In the Wake of Ashley Madison - Jim Salter

I will never knowingly “out” anyone.

Page 6: In the Wake of Ashley Madison - Jim Salter

How'd I get involved?

Page 7: In the Wake of Ashley Madison - Jim Salter

13,038 South Carolinians spent money on Ashley

Madison.

That's about 3 out of every thousand people in SC.

Page 8: In the Wake of Ashley Madison - Jim Salter

About 92.5% of them were men.

That's about 5.1 out of every thousand men in SC.

Page 9: In the Wake of Ashley Madison - Jim Salter

About 75% of them were men age 25-55.

That's about 1.1 out of every hundred men in SC, age

25-55.

Page 10: In the Wake of Ashley Madison - Jim Salter

It gets much, much worse when you only

look at cities.% of males age 25-55:

Charleston: 3.1%Columbia: 3.3%Greenville: 4.9%Lexington: 7.8%Fort Mill: 11.7%

Page 11: In the Wake of Ashley Madison - Jim Salter

Every network will eventually fall.

SONY, Apple, AOL, Target, Gawker, IRS,

SC DoR, Twitter...

Page 12: In the Wake of Ashley Madison - Jim Salter

What made theAshley Madison breach special?

RISK.

Page 13: In the Wake of Ashley Madison - Jim Salter

Speaking of “risk”:let's talk about

netblocks.

Army Research OfficeNetRange: 132.193.0.0 - 132.193.255.255CIDR: 132.193.0.0/16NetName: ARO-NETNetHandle: NET-132-193-0-0-1Parent: NET132 (NET-132-0-0-0-0)NetType: Direct Assignment

Page 14: In the Wake of Ashley Madison - Jim Salter

Today's vocabulary word:

pivot

Page 15: In the Wake of Ashley Madison - Jim Salter

In a nutshell:

all sites will fall

think about exposure

where can theattacker go next?

Page 16: In the Wake of Ashley Madison - Jim Salter

Let's talk about passwords!

Passwords In The Internet Age2:45PM, Citizen Track

openoid

Page 17: In the Wake of Ashley Madison - Jim Salter

Questions? Comments?

Angry denunciations?