sex, lies & instant messenger v3

Post on 29-Nov-2014

515 Views

Category:

Technology

3 Downloads

Preview:

Click to see full reader

DESCRIPTION

 

TRANSCRIPT

sex, lies and instant messenger @alecmuffett

sex, lies, & instant-messenger

@alecmuffettwww.alecmuffett.com

green lane securitywww.greenlanesecurity.com

v3.0

sex, lies and instant messenger @alecmuffett

What should come of this?

sex, lies and instant messenger @alecmuffett

When using the Webfor private communication...

sex, lies and instant messenger @alecmuffett

be aware1) what can go wrong unexpectedly?

sex, lies and instant messenger @alecmuffett

be aware2) what risks you protecting against?

sex, lies and instant messenger @alecmuffett

be aware3) what must you do/not do?

sex, lies and instant messenger @alecmuffett

Goal“Keep control of your data.”

sex, lies and instant messenger @alecmuffett

disclaimer (1)Almost all examples appearing in this work

are fictitious. Any resemblance to real events or to real persons, living or dead,

is probably coincidental.

sex, lies and instant messenger @alecmuffett

disclaimer (2)Advice given here is necessarily

incomplete; information security is a huge discipline and a full set of risks cannot be

conveyed in 30 minutes.

sex, lies and instant messenger @alecmuffett

1) what can go wrong unexpectedly?

sex, lies and instant messenger @alecmuffett

passwords!

sex, lies and instant messenger @alecmuffett

do not use secrets as passwords!

sex, lies and instant messenger @alecmuffett

my history• Crack

• First “smart” password cracker• 1991..96

• http://tinyurl.com/2jnzpy

• CrackLib• password checking library

• 1994..now

sex, lies and instant messenger @alecmuffett

issuepasswords are secret, but...

sex, lies and instant messenger @alecmuffett

issue...secrets make bad passwords

sex, lies and instant messenger @alecmuffett

passwordsguessable

sex, lies and instant messenger @alecmuffett

000000 1 1111 11111 111111 11111111 112233 123 123123 123321 1234 12345 123456 1234567 12345678 123456789 123abc 123qwe 1q2w3e 1q2w3e4r 222222 55555 654321 666666 7777 7777777 a aaaaaa abc123 adidas admin amanda andrew angel angel1 angels anthony apple asdf asdfasdf asdfgh ashley asshole austin baby bailey

banana bandit baseball batman benjamin biteme blabla blahblah blessed blessing blink182 bubbles buster canada cassie charlie cheese chelsea chicken chris christ church cocacola compaq computer cookie cool corvette creative dakota dallas daniel danielle david destiny dexter diamond digital dragon eminem

emmanuel enter faith flower foobar football football1 forever forum freedom friend friends fuckoff fuckyou fuckyou1 gateway genesis george ginger god google grace green guitar hahaha hallo hannah happy hardcore harley heaven hello hello1 helpme hockey hope hotdog hunter ilovegod iloveyou iloveyou! iloveyou1 iloveyou2 internet james jasmine jason jasper jennifer jessica jesus jesus1 john john316 jordan jordan23 joseph joshua junior justin killer kitten knight letmein london looking love lovely loving lucky maggie master matrix matthew maverick maxwell

merlin michael michelle mickey microsoft mike monkey mother muffin mustang mylove myspace1 nathan nicole nintendo none nothing onelove online orange pass passw0rd password password1 peace peaches peanut pepper phpbb pokemon poop power praise prayer prince princess purple qazwsx qwert qwerty qwerty1 rachel rainbow red123 richard robert rotimi samantha sammy samuel saved scooby scooter secret shadow shalom silver single slayer smokey snoopy soccer soccer1 sparky spirit startrek starwars stella summer sunshine superman taylor test testing testtest thomas thunder tigger trinity trustno1 victory viper welcome whatever william

winner wisdom zxcvbnm

250 top passwords - http://goo.gl/xPCq

sex, lies and instant messenger @alecmuffett

“You’ll never guess my password,it’s in Klingon!”

sex, lies and instant messenger @alecmuffett

sex, lies and instant messenger @alecmuffett

passwordsbrute-forceable

sex, lies and instant messenger @alecmuffett

from: AAAA

sex, lies and instant messenger @alecmuffett

to: zzzzzzzzzzzz

sex, lies and instant messenger @alecmuffett

via:t5gn9LF$*RJ#

sex, lies and instant messenger @alecmuffett

more than 1,000,000 guesses/second!

sex, lies and instant messenger @alecmuffett

sometimes more than9 billion guesses/second

sex, lies and instant messenger @alecmuffett

google:

imhoff password cracking

hashcat performance

sex, lies and instant messenger @alecmuffett

however...

sex, lies and instant messenger @alecmuffett

passworda window into your mind?

sex, lies and instant messenger @alecmuffett

passwordreveals something about you?

sex, lies and instant messenger @alecmuffett

passwordreflects your tastes?

sex, lies and instant messenger @alecmuffett

passwordis known to your spouse?

sex, lies and instant messenger @alecmuffett

also• reuse = self-incrimination

• ...which is bad...• ...more later...

sex, lies and instant messenger @alecmuffett

basic password discipline• use a password management tool

• use 12/more random characters• use different passwords at each website

• never reuse passwords• never share passwords• change annually/more often

• change when someone discovers one!

sex, lies and instant messenger @alecmuffett

next: instant messenger!

sex, lies and instant messenger @alecmuffett

do not Skype IM with your lover!

sex, lies and instant messenger @alecmuffett

Skype• peer to peer architecture

• robust, replicated, flexible• excellent security

• ...unless you’re up against the USA• ...or China• ...or maybe the UK

sex, lies and instant messenger @alecmuffett

virtually impossible to expungea recent conversation

sex, lies and instant messenger @alecmuffett

deletion can make things worsemessages resurrect from the dead!

sex, lies and instant messenger @alecmuffett

(zombie data is not good)

sex, lies and instant messenger @alecmuffett

Avoid XMPP with a lover...• Also called Jabber Protocol• Implementations:

• GoogleChat• Some Facebook chat• Other systems

sex, lies and instant messenger @alecmuffett

XMPP• Initial message is multicast

• sent to all logged-in instances• eg: “hello sexy”

• ...also arrives on the home PC• ...whilst you are at work

sex, lies and instant messenger @alecmuffett

Other IM systems?• Not really wise...

• AIM now multicast• YIM likewise

• Go for something simple• Avoid specialist IM-client software• Use web-based systems

sex, lies and instant messenger @alecmuffett

next: social media!

sex, lies and instant messenger @alecmuffett

do not Twitter with your lover!

sex, lies and instant messenger @alecmuffett

typos of doom!

sex, lies and instant messenger @alecmuffett

D alice can i have you for dinner?

sex, lies and instant messenger @alecmuffett

@alice can i have you for dinner?

sex, lies and instant messenger @alecmuffett

...and, worse...

sex, lies and instant messenger @alecmuffett

D bob Nude! http://twitpic.com/b0gu5

sex, lies and instant messenger @alecmuffett

Twitter App Risks• Third-party apps get access to DMs

• Twitter clients...• Web Apps...

• Proliferation of data is unwise• more backups• more caches• more access

sex, lies and instant messenger @alecmuffett

do not Facebook your lover!

sex, lies and instant messenger @alecmuffett

too easy to get wrong

sex, lies and instant messenger @alecmuffett

Dropping Hints

homepage displays with whom you communicate frequently

sex, lies and instant messenger @alecmuffett

“Transitive trust”friends-of-friends may not be friends

sex, lies and instant messenger @alecmuffett

Tommy Jordan!

YouTube Video:Facebook Parenting: For the troubled teen

sex, lies and instant messenger @alecmuffett

Facebook Software EcologyFacebook is not really Facebook

sex, lies and instant messenger @alecmuffett

Analogyif you want to be private,

don’t throw your diaryinto a pub full of gossips and journalists

sex, lies and instant messenger @alecmuffett

next: phones!

sex, lies and instant messenger @alecmuffett

do not smartphone with your lover!

sex, lies and instant messenger @alecmuffett

massive comedy potential

sex, lies and instant messenger @alecmuffett

iPhone screenlock

sex, lies and instant messenger @alecmuffett

applications which pop-upalerts above the screenlock

sex, lies and instant messenger @alecmuffett

Locked?

sex, lies and instant messenger @alecmuffett

punchline:

sex, lies and instant messenger @alecmuffett

Don’t combine this with Skype

sex, lies and instant messenger @alecmuffett

do not go gaming with your lover!

sex, lies and instant messenger @alecmuffett

MMORPGs• EQ• SecondLife• EVE Online• Warhammer• WoW

• etc...

sex, lies and instant messenger @alecmuffett

held to lower standard than IM

sex, lies and instant messenger @alecmuffett

heavily-integrated software• game• webcam• voice

• third party stuff• Ventrillo• Mumble• ...

sex, lies and instant messenger @alecmuffett

game logs• logfiles are...

• comprehensive• disparate• spattered all over the hard drive

• ...and therefore hard to remove

sex, lies and instant messenger @alecmuffett

next...

sex, lies and instant messenger @alecmuffett

Geolocation can hurt you!

sex, lies and instant messenger @alecmuffett

avoid sharing geolocation• Foursquare, Twitter, etc

• “...but your Twitter messages saidthat you were in Essex?”

sex, lies and instant messenger @alecmuffett

Do you have an in-car GPS?...and do you know how to wipe it?

sex, lies and instant messenger @alecmuffett

next, an obvious thing that’s often missed:

sex, lies and instant messenger @alecmuffett

do not send porny naked picturesof yourselves, to each other

sex, lies and instant messenger @alecmuffett

homebrew porn• webcam temporary copy

• potentially restorable

sex, lies and instant messenger @alecmuffett

homebrew porn• desktop copy

• backup/time machine copy• image-management tool copy

sex, lies and instant messenger @alecmuffett

homebrew porn• IM server copy

• or: duplicate Skype transfers• plus: transfer logs

sex, lies and instant messenger @alecmuffett

homebrew porn• remote copies

• remote backup/time machine• remote image-management tool

sex, lies and instant messenger @alecmuffett

homebrew porn• Took it with iPhone?

• backed up to iTunes• backed up to iCloud?

sex, lies and instant messenger @alecmuffett

homebrew porn• boyfriend’s archive copies

• ...for sharing when you break up

sex, lies and instant messenger @alecmuffett

do not use the family computer

sex, lies and instant messenger @alecmuffett

there’s a reason it’s calleda family computer

sex, lies and instant messenger @alecmuffett

do not use work-related hardware

sex, lies and instant messenger @alecmuffett

work hardware• not your machine

• thus: “not your data”• may be taken from you

• eg: bankruptcy, fired, updated• old hardware auctioned

• automated backups?• network access logged?

sex, lies and instant messenger @alecmuffett

summary

sex, lies and instant messenger @alecmuffett

If you are going to live a double lifethen please do it right.

sex, lies and instant messenger @alecmuffett

2) what risks are you protecting against?

sex, lies and instant messenger @alecmuffett

(apart from spouses and lawyers)

sex, lies and instant messenger @alecmuffett

recreational computer forensics!

sex, lies and instant messenger @alecmuffett

for teh lulz!

sex, lies and instant messenger @alecmuffett

Things Geeks Do• Enumerate all possible URLs:•tinyurl•bit.ly•is.gd•t.co

• ...and save the good ones

sex, lies and instant messenger @alecmuffett

Things Geeks Do• Trawl...

• Picasa• Twitpic• Yfrog

• ...to much the same ends

sex, lies and instant messenger @alecmuffett

Things Geeks Do• buy hardware from Ebay

• undelete data files • desktops• laptops• printers (!)• storage

• hard disks• thumb drives• SD cards

sex, lies and instant messenger @alecmuffett

Things Geeks Do• buy phones from Ebay

• restore deleted SMS• retrieve e-mail passwords

sex, lies and instant messenger @alecmuffett

Find hardware in the street...

sex, lies and instant messenger @alecmuffett

...investigate it...

sex, lies and instant messenger @alecmuffett

...discover secrets.

sex, lies and instant messenger @alecmuffett

Your challenge is to make that hard

sex, lies and instant messenger @alecmuffett

3) what must you do/not do?

sex, lies and instant messenger @alecmuffett

do use separate identities,do not link identities!

sex, lies and instant messenger @alecmuffett

create a disposable identity,start with an e-mail address

sex, lies and instant messenger @alecmuffett

use a fake, boring, common pseudonym

• good• edward wilson• carole smith

• bad• sexxxy4UinBasingstoke• anything else that’s unique

sex, lies and instant messenger @alecmuffett

is this legal?• probably breaking terms of service

• is it criminal to lie?• maybe...

sex, lies and instant messenger @alecmuffett

idea:Use a disposable Gmail accountto set up a fake Yahoo account

or vice-versa.

sex, lies and instant messenger @alecmuffett

do not bookmark your secret identity

sex, lies and instant messenger @alecmuffett

do use a random password• never used before• never use anywhere else• keep the password in your brain

sex, lies and instant messenger @alecmuffett

do not store the secret identity passwordin your normal password manager!

sex, lies and instant messenger @alecmuffett

do minimise data proliferation,do not leave footprints!

sex, lies and instant messenger @alecmuffett

do not access your secret identityfrom your normal phone

sex, lies and instant messenger @alecmuffett

iPhone• All backed up by iTunes:

• SMS• call logs• geolocation (see recent press)

• ...possibly password protected• You’re using a different password, yes?

sex, lies and instant messenger @alecmuffett

Android• basically ditto

• ...but backed up on Google instead

sex, lies and instant messenger @alecmuffett

Do not access your secret identityusing your normal laptop “login”

sex, lies and instant messenger @alecmuffett

avoid intermingled filestore

put no pseudonym filesamongst personal files

sex, lies and instant messenger @alecmuffett

set up different “users”• keep sensitive files in one place

• ...hopefully• ...mostly• ...except for logs

sex, lies and instant messenger @alecmuffett

set up encrypted hard disks

resistant to post-Ebay forensics;do this prior to any usage

sex, lies and instant messenger @alecmuffett

use browsers which supportprivate browsing modes, and

which delete cookies/history on exit

sex, lies and instant messenger @alecmuffett

Example workflow:

sex, lies and instant messenger @alecmuffett

Chrome

“day-to-day”

sex, lies and instant messenger @alecmuffett

Safari• Guests and visitors• Logging into a website without

logging-out of Facebook first

sex, lies and instant messenger @alecmuffett

Firefox• Ideal for...

• porn• shagging• dubious e-mail links• security malware research

sex, lies and instant messenger @alecmuffett

technical reference

sex, lies and instant messenger @alecmuffett

browser settings (1)• clear cookies on exit• clear history on exit• don't accept 3rd-party cookies• block popups

sex, lies and instant messenger @alecmuffett

browser settings (2)• don't save form input• don't save history• switch off autosuggest• set to private browser mode

• ...permanently, if possible• else auto/delete cookies on exit

sex, lies and instant messenger @alecmuffett

plugins / similar• Flash Player

• Visit the security settings panel• purge Flash cookies and sites• set Flash db size to zero

• HTML5 settings• set HTML5 db size to zero• watch for other/new issues

sex, lies and instant messenger @alecmuffett

Firefox extensions• Tor

• better: Tor Browser Bundle

•SSL Everywhere•NoScript•RequestPolicy•AdBlock Plus•Ghostery

sex, lies and instant messenger @alecmuffett

Adium / Pidgin for IM• use OTR encryption

• not the same as OTR in GoogleChat!• solves the point-to-point chat issue

• beware local logfiles

sex, lies and instant messenger @alecmuffett

remember:

sex, lies and instant messenger @alecmuffett

all this also applies to your phone

sex, lies and instant messenger @alecmuffett

speaking of phones...

sex, lies and instant messenger @alecmuffett

use a PAYG dumbphone• pay cash (where possible)• top-up with cash• enable PIN lock• avoid ...

• paper billing• web integration

sex, lies and instant messenger @alecmuffett

use voice calls

sex, lies and instant messenger @alecmuffett

do not leave voicemails

sex, lies and instant messenger @alecmuffett

wipe your SMS messages regularly

sex, lies and instant messenger @alecmuffett

dumbphone SMS• lowest common denominator

• messages still logged on backend• but overall exposure is less

sex, lies and instant messenger @alecmuffett

if you must use smartphone• do not link this phone to your usual

Google Account

sex, lies and instant messenger @alecmuffett

if you must use smartphone• check out:

• WhatsApp• TigerText• ...other SMS replacements

• take time to understand how they work

sex, lies and instant messenger @alecmuffett

finally...

sex, lies and instant messenger @alecmuffett

decommission old hardware• computers

• DBAN - Darik’s Boot & Nuke• Free suicide pill / CDROM for PCs

• phones• Remove SIM

• SMS may be on SIM as well as phone!• Check whether factory reset actually works

• if not, smash it & drive a car over it repeatedly

sex, lies and instant messenger @alecmuffett

bottom lines• the more copies of data exist

• the harder it is to remove them• when data escapes your control

• it's available forever

sex, lies and instant messenger @alecmuffett

when mistakes happen...• clean up calmly• do not amplify the mistake

sex, lies and instant messenger @alecmuffett

remember• your lover has the same data

• but may not be taking care of it• educate them gently

• his/her systems will also one day be sold on eBay

sex, lies and instant messenger @alecmuffett

So why must you actually know all this?

sex, lies and instant messenger @alecmuffett

Well...

sex, lies and instant messenger @alecmuffett

- shagging

sex, lies and instant messenger @alecmuffett

- journalists and sources

sex, lies and instant messenger @alecmuffett

- employees and whistleblowers

sex, lies and instant messenger @alecmuffett

- activists in repressive regimes

sex, lies and instant messenger @alecmuffett

- good data hygiene

sex, lies and instant messenger @alecmuffett

- separating work and home data/life

sex, lies and instant messenger @alecmuffett

sex, lies and instant messenger @alecmuffett

Future

sex, lies and instant messenger @alecmuffett

...?

sex, lies and instant messenger @alecmuffett

bonne chance

top related