household infosec in a post-sony era

39
Household INFOSEC in a Post-Sony Era Steve Loughran [email protected] @steveloughran

Upload: steve-loughran

Post on 08-Jan-2017

232 views

Category:

Software


0 download

TRANSCRIPT

Page 1: Household INFOSEC in a Post-Sony Era

Household INFOSECin a Post-Sony Era

Steve [email protected]@steveloughran

Page 2: Household INFOSEC in a Post-Sony Era
Page 3: Household INFOSEC in a Post-Sony Era

Data IntegrityData Privacy

Data AvailabilityResource Control

Page 4: Household INFOSEC in a Post-Sony Era

Don’t upset a nation state

Page 5: Household INFOSEC in a Post-Sony Era

Worry about drive-by

Page 6: Household INFOSEC in a Post-Sony Era
Page 7: Household INFOSEC in a Post-Sony Era

How to Quantify Risk?

Vulnerability

Priv

acy

(lack

of)

Page 8: Household INFOSEC in a Post-Sony Era

(1, 0)

Page 9: Household INFOSEC in a Post-Sony Era

(11, 1)

Page 10: Household INFOSEC in a Post-Sony Era

(*, 11)

Page 11: Household INFOSEC in a Post-Sony Era

Firefox (8, 2)

Page 12: Household INFOSEC in a Post-Sony Era

Chrome: (8, 10)

Page 13: Household INFOSEC in a Post-Sony Era

IE 11 Use to D/L Firefox or Chrome

Page 14: Household INFOSEC in a Post-Sony Era

Flash (9->10, 4)

Page 15: Household INFOSEC in a Post-Sony Era
Page 16: Household INFOSEC in a Post-Sony Era

Vulnerability

Priv

acy

(lack

of)

Page 17: Household INFOSEC in a Post-Sony Era

—LG TV

iPad— —iPhone—PS4-Airplay Amplifier

trouble—

Page 18: Household INFOSEC in a Post-Sony Era

LG TV

(?, 8)

Page 19: Household INFOSEC in a Post-Sony Era

doctorbeet.blogspot.co.uk (?, 10)

Page 20: Household INFOSEC in a Post-Sony Era

(?, 0)

Page 21: Household INFOSEC in a Post-Sony Era
Page 22: Household INFOSEC in a Post-Sony Era

Vulnerability

Priv

acy

(lack

of)

Page 23: Household INFOSEC in a Post-Sony Era

DD-WRT

New Netgear Firewall

CRITICAL

DMZ

USB

...

Page 24: Household INFOSEC in a Post-Sony Era

(?, 11)SQL vulnerability?

Other?

Page 25: Household INFOSEC in a Post-Sony Era

(5,11)iPhone + Google photos

Page 26: Household INFOSEC in a Post-Sony Era

(3,11)

Page 27: Household INFOSEC in a Post-Sony Era

(9, >7)( ?, >7)

Page 28: Household INFOSEC in a Post-Sony Era

Game over

Page 29: Household INFOSEC in a Post-Sony Era

Vulnerability

Priv

acy

(lack

of)

Page 30: Household INFOSEC in a Post-Sony Era

We must fix this in our code

Page 31: Household INFOSEC in a Post-Sony Era

All external data is malicious

All remote interactions leak privacy

Page 32: Household INFOSEC in a Post-Sony Era

C++

C

Page 33: Household INFOSEC in a Post-Sony Era

new URL(“http://www.starcon.net.kp”) .toString()

java.net.URL (>2, >2)

Page 34: Household INFOSEC in a Post-Sony Era

def objectFile[T: ClassTag]( path: String, minPartitions: Int): RDD[T] = withScope { sequenceFile(path, classOf[NullWritable], classOf[BytesWritable], minPartitions) .flatMap(x => Utils.deserialize[Array[T]]( x._2.getBytes, Utils.getContextOrSparkClassLoader))}

SparkContext (0, 9)

Page 35: Household INFOSEC in a Post-Sony Era

OSS everywhere ==> target

Page 36: Household INFOSEC in a Post-Sony Era

Apache & github keys

Page 37: Household INFOSEC in a Post-Sony Era

apt-get upgradebrew upgrademvn installnpm updateyum updatepip installdocker pull…

(?, ?)

build dependencies

We need to address this!

Page 38: Household INFOSEC in a Post-Sony Era

Isolation: containers?

Authentication: PGP validate mvn…

Audit logs

Page 39: Household INFOSEC in a Post-Sony Era

Questions?