Follow us on RSS or Twitter for the latest updates.

August 8, 2011

DefCon: The World’s Largest Hackers Conference


r-DEFCON-HACKER-CONFERENCE-large570
Hackers compete in a digital capture the flag game at the DefCon conference

There are so many ways to get hacked at the world’s largest hacker conference.

A hacker could bump against your pocket with a card reader that steals your credit card information. Or a hacker might eavesdrop on your Internet traffic through an unsecured Wi-Fi network. Or a hacker might compromise your cell phone while you charge it in the hotel’s public phone-charging kiosk.

The Internet connection here has been dubbed "the world’s most hostile network." You might want to avoid the A.T.M.'s, too.

Welcome to DefCon, where thousands of the world's best code crackers gather each year to discuss the latest hacking techniques -- then occasionally try them out on each other.

More than 10,000 hackers and security experts have descended upon the Rio Hotel and Casino in Las Vegas this weekend for three days of lectures and contests.

Admission to DefCon, now in its 19th year, is $150, far less than Black Hat, a cybersecurity conference held earlier this week at nearby Caesar’s Palace that cost around $1,500.

At both conferences, hackers can make a name for themselves by demonstrating how they found security flaws in technology that most observers would consider well-protected or harmless.

At DefCon this year, there are presentations on how to hack office printers, wireless water meters, smart phones, laptop batteries and the network used at correctional facilities to open and close prison doors.

For the paranoid, there is a presentation on how to destroy data if you're "convinced that the black helicopters are incoming and ruthless feds are determined to steal your plans for world domination," according to the conference program.

The conference also offers more than 50 games and contests to challenge hackers. In one room, techno music thumps over loud speakers as teams of hackers hunched over laptops try to steal files from each other in a game called "Capture the Flag."

Another game gives contestants five minutes to hack into a voting machine. Yet another contest, called "Crack Me If You Can," challenges teams to crack as many passwords as possible in 48 hours; the winner gets $600.

Some DefCon attendees complained Friday on Twitter that A.T.M.'s inside the convention hotel were out of service. To some, this was no surprise. After all, hacker Barnaby Jack demonstrated at Black Hat last year how to hack into an A.T.M. Two years ago, a malicious A.T.M. was placed at DefCon and stole data from conference attendees before it was detected.

Some companies see the hacker conference as a place to scout for new talent. In June, Facebook hired George Hotz, the young hacker who gained notoriety in 2007 for "jailbreaking" Apple's iPhone, getting around the phone's software controls.

Companies exposed for weak security are not the only ones being embarrassed at DefCon. If a conference attendee logs on to her email account, for example, using an unsecured wireless network, her username and password are posted on an electronic board known as the "Wall of Sheep."

Brian Markus, chief executive of Aries Security, said his company runs the "Wall of Sheep" to teach a lesson on Internet security. He compared using unsecured networks to the free-love ethic of the 1960s and 1970s when many people had unprotected sex.

"Today, everybody is connected and they need to go out and get protection because the environment has changed," Markus said.

Most DefCon attendees are particularly cautious about security, going so far as to use only their online nicknames at the conference. Many attendees are young, wear dark clothes and sport a wide range of hairstyles -- including mohawks -- with enough hair colors represented to match a Crayola box.

Not everyone here is a hacker, though. Employees of federal agencies also attend, giving panel discussions and inspiring a traditional game among hackers at DefCon called “Spot the Fed.”

Friday's program included a beer-chilling contest, where contestants competed to cool beer that had been sitting in the hot desert sun. Two participants, Chris McMinn and Chris Lopez, built an 11-foot-long contraption from aluminum and steel pipes that they said cools beer from 90 degrees to 40 degrees in four seconds.

They did not win the contest, but they didn't seem to care.

"We did it more for the glory," Lopez said. "All of our science teachers would be very proud."

McMinn added: "Where else would you chill beer for sport?"

Author: dfgdfg,

Zero-Day Flaw in Games discovered by 10-year-old Hacker


DefCon-hacker
A 10-year-old hacker who goes by the pseudonym CyFi revealed today at DefCon 19 a zero-day exploit in games on iOS and Android devices that independent researchers have confirmed as a new class of vulnerability. The girl from California first discovered the flaw around January 2011 because she "started to get bored" with the pace of farm-style games.

CyFi said, "It was hard to make progress in the game, because it took so long for things to grow. So I thought, 'Why don't I just change the time?'" Most of the games she discovered the exploit in have time-dependent factors. For example, planting corn might take 10 real-time hours to mature in the game. Manually advancing the phone or tablet's clock forced the game further ahead than it really was, opening up the exploit.

She is not revealing at this time which games are affected because of reasonable disclosure, thus giving the vendors that make the affected games a chance to respond.

While many games will detect and block this kind of manipulation, CyFi said that she discovered some ways around those detections. Disconnecting the phone from Wi-Fi made it harder to stop, as did making incremental clock adjustments.

CyFi's mother, who must remain anonymous to protect her daughter's identity, said that at the end of CyFi's presentation at DefCon Kids they would offer a $100 reward to the young hacker who found the most games with this exploit over the following 24 hours. The reward is sponsored by AllClearID, a identity protection company that is also sponsoring the DefCon Kids. This is the first year of DefCon Kids programming at the conference, a reflection of the fact that members of the hacking community are getting older and raising families.

Already an artist who has performed an improvised, 10-minute-long spoken word piece in front of 1,000 people at the San Francisco Museum of Modern Art, a Girl Scout, and a state-ranked downhill skier, CyFi revealed that she was only a little bit nervous about having to speak in front of the 100 or so expected attendees. She admitted that while it was probably different publicly speaking about a topic with such a specific focus, it would be hard for her to imagine what those differences might be. "Well, I haven't done it yet," she said.

Author: dfgdfg,

Categories: , ,