Lessons from “the Snowden Affair” @haroonmeer September 2014
What this talk is not
IT DOESN’T MATTER
BUGSY CRISSCROSS A-PLUS GUMFISH LFS-2 BULLRUN DYNAMO CROSSBEAM ACRIDMINI GURKHASSWORD LHR BULLSEYE EBSR CROSSEYEDSLOTH AGILEVIEW HACIENDA LIFESAVER BUMBLEBEEDANCE EDGEHILL CRUMPET AGILITY HAMMERMILL LITHIUM BYSTANDER EINSTEIN CRYOSTAT AIGHANDLER HAPPYFOOT LOCKSTOCK BYZANTINEANCHOR ELATE CRYPTOENABLED AIRBAG HAWKEYE LONGHAUL BYZANTINEHADES ELEGANTCHAOS CULTWEAVE AIRGAP/COZEN HC12 LONGRUN CADENCE ENDUE CUSTOMS AIRWOLF HEADMOVIES LONGSHOT CANDYGRAM ENTOURAGE CYBERCOMMANDCONSOLE ALLIUMARCH HIGHCASTLE LOPERS CANNONLIGHT EVENINGEASEL CYCLONE ALTEREGOQFD HIGHLANDS LUMP CAPTIVATEDAUDIENCE EVILOLIVE DANCINGBEAR ANCESTRY HIGHTIDE LUTEUSICARUS CARBOY EWALK DANCINGOASIS ANCHORY HOLLOWPOINT MADCAPOCELOT CASPORT EXCALIBUR DAREDEVIL ANTICRISISGIRL HOMEBASE MAGNETIC CASTANET EXPOW DARKFIRE ANTOLPPROTOSSGUI HOMEPORTAL MAGNUMOPUS CCDP FACELIFT DARKQUEST APERTURESCIENCE HOMINGPIGEON MAINCORE CDRDIODE FAIRVIEW DARKTHUNDER AQUADOR HUSHPUPPY MAINWAY CERBERUS FALLOUT � ARTEMIS HUSK MARINA CERBERUSSTATISTICSCOLLECTION FASCIA DEADPOOL ARTIFICE IBIS MAUI CHALKFUN FASHIONCLEFT DEVILSHANDSHAKE ASPHALT ICE MESSIAH CHANGELING FASTSCOPE DIALD ASSOCIATION ICREACH METROTUBE CHAOSOVERLORD FATYAK DIKTER ASTRALPROJECTION ICREAST METTLESOME CHASEFALCON FET DIRTYEVIL AUTOSOURCE IMP MINERALIZE CHEWSTICK FISHBOWL DISCOROUTE AXLEGREASE INCENSER MINIATUREHERO CHIPPEWA FOGGYBOTTOM DISHFIRE BABYLON INDRA MIRAGE CHOCOLATESHIP FORESTWARRIOR DISTANTFOCUS BALLOONKNOT INSPECTOR MIRROR CIMBRI FOXACID DISTILLERY BANYAN INTELINK MOBILEHOOVER CINEPLEX FOXSEARCH DIVERSITY BEARSCRAPE INTERQUAKE MONKEYROCKET COASTLINE FOXTRAIL DOCKETDICTATE BEARTRAP IRONSAND MONSTERMIND COBALTFALCON FRA DOGCOLLAR BELLTOPPER ISHTAR MOONLIGHTPATH CONDUIT FREEFLOW DOGHANDLER BERRYTWISTER JACKKNIFE MOONPENNY CONJECTURE FREEZEPOST DRAGGABLEKITTEN BERRYTWISTER+ JAZZFUSION MOUTH CONTRAOCTAVE FRONTO DRAGON'SSHOUT BINOCULAR JAZZFUSION+ MTI CONVEYANCE FRUITBOWL DROPMIRE BIRDSONG JEDI MUGSHOT CORALINE FUNNELOUT DRTBOX BIRDSTRIKE JEEPFLEA MURPHYSLAW CORALREEF FUSEWIRE DRUID BLACKHEART JILES MUSCULAR COTRAVELER GALAXY PACKAGEGOODS BLACKPEARL JTRIG MUSKETEER OCTSKYWARD GAMUT PANOPLY BLARNEY JTRIGRADIANTSPLENDOUR MUSTANG OILSTOCK GARLICK PARCHDUSK BLUEANCHOR JUGGERNAUT MUTANTBROTH OLYMPIA GENESIS PATHFINDER BLUEZEPHYR KAMPUS MYSTIC OMNIGAT GENTE PBX BOMBAYROLL KEYRUT NAMEJACKER ONEROOF GEOFUSION PHOTONTORPEDO BOTANICREALTY KOALAPUNCH NCSC ONIONBREATH GHOSTMACHINE PICASSO BOUNDLESSINFORMANT LADYLOVE NEBULA OPTICNERVE GILGAMESH PINWALE BRANDYSNAP LANDINGPARTY NEVIS ORANGEBLOSSOM GLASSBACK
What do we learn from it ?
What should we do differently?
Caveat: It’s a short talk
Best begin at..
http://www.theguardian.com/world/2013/jun/06/nsa- phone-records-verizon-court-order
http://www.washingtonpost.com/investigations/us-intelligence-mining-data- from-nine-us-internet-companies-in-broad-secret-program/ 2013/06/06/3a0c0da8-cebf-11e2-8845-d970ccb04497_story.html
The extent of the leak?
How many documents?
http://www.reuters.com/article/2013/11/14/us-usa-security-nsa- idUSBRE9AD19B20131114
http://www.reuters.com/article/2013/11/14/us-usa-security-nsa-idUSBRE9AD19B20131114
http://world.time.com/2013/10/14/greenwald-on-snowden-leaks-the-worst-is-yet-to-come/
http://www.bbc.com/news/uk-25205846
They had no idea what he had
Would You ?
Are your execs properly trained ?
http://www.theguardian.com/environment/2014/jan/30/snowden- nsa-spying-copenhagen-climate-talks
http://www.theguardian.com/environment/2014/jan/30/snowden- nsa-spying-copenhagen-climate-talks
http://www.theguardian.com/uk/2013/jun/16/gchq-intercepted- communications-g20-summits
http://www.theguardian.com/uk/2013/jun/16/gchq-intercepted- communications-g20-summits
Attackers like that don’t care about me / us
http://www.spiegel.de/international/europe/british-spy-agency- gchq-hacked-belgian-telecoms-firm-a-923406.html
https://gigaom.com/2014/02/01/nsa-and-gchq-hacked-belgian- cryptographer-report/
https://gigaom.com/2014/02/01/nsa-and-gchq-hacked-belgian- cryptographer-report/
https://firstlook.org/theintercept/2014/09/14/nsa-stellar/
http://www.spiegel.de/international/world/snowden- documents-indicate-nsa-has-breached-deutsche- telekom-a-991503.html
These guys were collateral damage
Does collaboration protect you from getting hacked?
http://www.washingtonpost.com/world/national-security/nsa-infiltrates-links-to-yahoo-google-data-centers-worldwide-snowden-documents-say/ 2013/10/30/e51d661e-4166-11e3-8b74-d89d714ca4dd_story.html
How many times were they spotted ?
Complete failure of detection & compartmentalisation
http://www.verizonenterprise.com/DBIR/
The good news is…
Do sophisticated attackers exist ?
not estonia not headline sophisticated
not estonia
http://blog.thinkst.com/p/cyberwar-why-your-threat-model-is.html
http://blog.thinkst.com/p/cyberwar-why-your-threat-model-is.html
Do sophisticated attackers exist ?
This is profoundly important
Device Based Security Anti Virus Pen Tests
we said victory accomplished
Device based Security
Anti Virus http://www.wired.com/2012/06/internet-security-fail/
Anti Virus http://www.wired.com/2012/06/internet-security-fail/
Pen Tests http://blog.thinkst.com/2012/03/penetration-testing-considered-harmful.html
We are not modelling the right threats
Were all the attacks novel?
Nope.. Not even the ANT stuff
Many of these techniques were previously demonstrated
Why didn't you know about them?
talk graph - tscapes Q2 - 116 Security Events 257 conference days
http://thinkst.com/ts/free
Will the leaks make things better or worse?
Intelligence reforms may or may not happen.. � but, from the point of view of sophisticated attacks
Courage is Contagious
life imitates..
Caveat
This doesn’t apply to everyone!
biggest mistake is thinking you are all the same.. http://blog.thinkst.com/2013/01/your-companies-security-posture-is.html
Summary If everything is important, nothing is • important Your execs need training! • Sophisticated attackers do exist • It’s obvious the emperor has no clothes. • Things are going to get a lot worse for a • bit
Summary of Summary Understand your threat model Understand the space
@haroonmeer http://thinkst.com/ts/free
Recommend
More recommend