Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

8/19/2014
06:01 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Q&A: DEF CON At 22

DEF CON founder Jeff Moss, a.k.a. The Dark Tangent, reflects on DEF CON's evolution, the NSA fallout, and wider security awareness.

DEF CON 22, held earlier this month in Las Vegas, saw a 25% jump in the number of attendees over last year -- a whopping 15,000 people converging on what is considered the world's largest hacker conference. Dark Reading executive editor Kelly Jackson Higgins sat down with DEF CON founder Jeff Moss, a.k.a. The Dark Tangent, to get his take on this year's show, the NSA, and the reality that cyberattacks are inevitable. Here is an excerpt from that interview:

Jeff Moss
(Source: hackerphotos.com)
Jeff Moss
(Source: hackerphotos.com)

Dark Reading: What is the biggest difference you see in this year's DEF CON than in years past?

Jeff Moss:  There's an energy difference. Last year, it was right at the beginning of Snowden, so there was lots of frustration or tension, on why do we bother trying to defend anything if you can just get a court order. There's a lot more optimism [this year].

Dark Reading: Last year, you made the fairly controversial request that the feds not attend DEF CON given the air of distrust amid the leaked NSA documents showing the scope of the agency's spying operations. Feds were back at DEF CON this year. What's different?

Moss: They are engaged in a very healthy [way], involved in contests [for example]. There's not a recruiting booth from the NSA. The NSA has not figured out its narrative yet. The challenge for the intel community, NSA folks, etc., is to figure out what their message is and how they can re-engage with this community.

We don't want the bad guys to break into our SCADA [systems]. We just need to figure out how we are going to work together [with the intelligence community] and repair that broken trust... I'm hoping by next year, they have a coherent story to tell our community.

Dark Reading: Any chance you'd have the new NSA director keynote here again like former NSA director Keith Alexander did in 2012?

Moss: It would be a huge risk or a huge opportunity for them. They would have to have a good story.

We have unlimited resources there [at the NSA] for capturing unlimited traffic. I'd like to see a cost-benefit analysis. Now that forces them to go to Congress and have to justify [the traffic capture]. That forces some discipline. I don't doubt it was working [for legitimate intelligence-gathering]... but a less invasive [approach is best].

Dark Reading: What's new at DEF CON this year?

Moss: We now have a privacy Village. That's been a theme since day one. We have an industrial controls Village, and it's amazing what they built there. We had the expansion of the Hardware Hacking Village.

On the fun side, we had a DEF CON badge counterfeiting contest. I wanted to know how the hell they're doing it [so the contest was added this year]. If you can counterfeit the badge and then teach your techniques to others, that's really cool.

All of the contests and tracks were full. There [were] a lot of [people] demanding how do we capture these [attackers]... what strategies do we use detecting them. There was a healthy defensive conversation here.

Dark Reading: What is the biggest mindset change in the industry now from your perspective?

Moss: There's a mindset shift: It was an IT problem to keep everyone secure and if they break in, it's an IT failure. Now it's if they're going to break in, what are you going to say? You need to have a communications plan ready, an incident response team, legal, are you going to sue or call the cops. You have big decisions to make if you go to the feds or not. What information do you have to tell the CEO or CIO or CFO. If it reaches this level, do I wake the CEO up?

There's cross-departmental communications. They all feel like they're involved now. That's so much more healthy than saying I'm hired to be the security guy in the security department.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
8/20/2014 | 11:55:42 AM
Re: More Than Just Cost Benefit
Jeff has great insight and perspective on this topic with his role in the security community, his meeting Gen. Alexander at DEF CON in 2012, and his work on the Homeland Security Advisory Council. 
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
8/20/2014 | 11:48:49 AM
More Than Just Cost Benefit
I agree with Jeff Moss that I'd like to see the NSA have to justify to Congress why it needs unlimited budget to do unlimited information capture. Even more importantly, I'd like to see Congress push back hard on the need for unlimited information capture. I think it's posionous to a democracy to have that kind of unlimited surveillance.
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Deliver a Deadly Counterpunch to Ransomware Attacks: 4 Steps
Mathew Newfield, Chief Information Security Officer at Unisys,  12/10/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19604
PUBLISHED: 2019-12-11
Arbitrary command execution is possible in Git before 2.20.2, 2.21.x before 2.21.1, 2.22.x before 2.22.2, 2.23.x before 2.23.1, and 2.24.x before 2.24.1 because a "git submodule update" operation can run commands found in the .gitmodules file of a malicious repository.
CVE-2019-14861
PUBLISHED: 2019-12-10
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the (poorly named) dnsserver RPC pipe provides administrative facilities to modify DNS records and zones. Samba, when acting as an AD DC, stores DNS records in LDAP. In AD, the default permiss...
CVE-2019-14870
PUBLISHED: 2019-12-10
All Samba versions 4.x.x before 4.9.17, 4.10.x before 4.10.11 and 4.11.x before 4.11.3 have an issue, where the S4U (MS-SFU) Kerberos delegation model includes a feature allowing for a subset of clients to be opted out of constrained delegation in any way, either S4U2Self or regular Kerberos authent...
CVE-2019-14889
PUBLISHED: 2019-12-10
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence...
CVE-2019-1484
PUBLISHED: 2019-12-10
A remote code execution vulnerability exists when Microsoft Windows OLE fails to properly validate user input, aka 'Windows OLE Remote Code Execution Vulnerability'.