By Anonymous CowardPosted Friday 8th August 2008 08:15 GMT
I always enjoy Dan Goodin's articles, and now that Black Hat's on, it's like Christmas at El Reg ...
Back on topic:
Three days to set up a VPN (or indeed any encrypted secure communication or storage) is a problem! If it's going to achieve significant use, it needs to be a five minute operation - about where the frustration limit is for most users these days.
Of course, compatibility is also vital, both for end points to connect to and paths to transmit through.
Ye. My arse. They wanted to show off about how l33t they were. How much public notice dose Blackhat get? Outside the tec/security comunity, who know these dangers all to well, Im guessing non.
Do on to you as you do on to others, nothing wrong with what the Journalists did it's all in line with the event, so what are they whining about? The Journalists shouldn't be tried under the laws, hope they slate the Black Hat events.
Well I would agree this wouldn't educate the public except how incompetent even Black Hat conference organisers are and journalists of *tech publications* are about security.
If the conference can't stop someone just surfing details off their network that should be unavailable to the snooper, then the **** Black Hat **** conference is not about security. Probably just a way to get an international jollie.
By Dunstan VavasourPosted Friday 8th August 2008 10:28 GMT
No, they absolutely should have been kicked out. If there is to be consensual network penetration, it is essential that the boundaries for that consensual activity are respected. Taking the activity outside the agreed zone fundamentally undermines the safeguards, and changes the activity from valuable "lab work" to something illegal.
By Anonymous CowardPosted Friday 8th August 2008 11:40 GMT
I'm just guessing, but could it be that most of the time was spend setting up the server side of things? You know, the thingi-mah-jig (technical term) on the receiving end back at Vulture Central?
Science bloke, because so few people know how to properly configure a thingi-mah-jig these days.
By Adam ConnellyPosted Friday 8th August 2008 12:37 GMT
I figure that the conference is called "Black Hat", so stuff like this should be expected. I don't think the organisers should have kicked the guys out since what they did was presumably in the spirit of the event.
Whether they get charged or not depends on the police, I guess, and if they do - tough.
Re: Pot, Kettle, Blackhat... and @Mark Re: Bad Form #
By The Other StevePosted Friday 8th August 2008 13:34 GMT
Why go to all that trouble when as any fule kno, by far the easiest way to sniff traffic on a wired ethernet switch is to have at it with a shed load of wonky arp packets ? *
Hell, if you can spoof the gateway's MAC to FF:FF:FF:FF:FF:FF (or often times, just set the I/G bit high) you don't even have to forward the packets. You can only see the outbound traffic, but that's enough for capturing passwords in the clear)
Bit noisy mind.
Shit, maybe they just couldn't figure out the massively outdated dependencies to get dsniff to compile, journos eh ?
What a terrible shock it must have been to the BlackHat attendees and organisers to discover that not everyone plays by the rules or accepts the boundaries laid down for them by others.
OTOH bouncing them was the right thing to do, the last thing the BH organisers need is people committing actual crimes. It's the perfect excuse for the event to be shut down by the numerous law enforcement personnel lurking around the place.
* Yes yes, there's ways to spot and mitigate this, but you have to reckon that any network configures thusly would also have noticed a fraudulent DHCP server.
blackhat infered the wired network was safe. They were wrong, hence they are but hurt and kicked out the reporters. They should have secured their physical network. Why would you allow DHCP... from a client port? Hell they should have the reporters use an internal (to black hat) VPN with assigned usernames/passwords, MAC address filtering, port assignment etc. If you're going to break all the security(black hatters), you should be held to work within the crap-pile you've created.
Don't think for a minute that the presenters at BH don't sniff, test and send non-standard packets to public computers! Dear god, even BH has an EULA now....
Comments on: Rogue reporters kicked out of conference for network snooping
And there's the rub ... #
By Anonymous Coward Posted Friday 8th August 2008 08:15 GMT
"educate the public" #
By Paul Posted Friday 8th August 2008 08:21 GMT
hypocritical #
By Gary Posted Friday 8th August 2008 08:26 GMT
3 days to configure OpenVPN #
By Anonymous Coward Posted Friday 8th August 2008 08:26 GMT
3 days? #
By Colin Morris Posted Friday 8th August 2008 09:38 GMT
Why the need to kick them out ? #
By Marius Poenar Posted Friday 8th August 2008 09:44 GMT
re: "educate the public" #
By Mark Posted Friday 8th August 2008 10:01 GMT
Bad Form #
By Dunstan Vavasour Posted Friday 8th August 2008 10:28 GMT
Re: Bad Form #
By Mark Posted Friday 8th August 2008 11:00 GMT
3 days to set up a VPN... #
By Anonymous Coward Posted Friday 8th August 2008 11:40 GMT
Pot, Kettle, Blackhat... and @Mark Re: Bad Form #
By Anonymous Coward Posted Friday 8th August 2008 12:25 GMT
RE: Bad Form #
By Adam Connelly Posted Friday 8th August 2008 12:37 GMT
Re: Pot, Kettle, Blackhat... and @Mark Re: Bad Form #
By Mark Posted Friday 8th August 2008 13:25 GMT
DHCP server ? Meh! #
By The Other Steve Posted Friday 8th August 2008 13:34 GMT
Why all the Fuss? #
By John Uhercik Posted Friday 8th August 2008 16:43 GMT
Dont stick the postit note on the monitor #
By Anonymous Coward Posted Friday 8th August 2008 18:32 GMT
hello #
By Bounty Posted Friday 8th August 2008 18:33 GMT
Sounds #
By heystoopid Posted Friday 8th August 2008 20:59 GMT
Hackers Hacked..Who would have guessed? #
By rick buck Posted Tuesday 12th August 2008 05:43 GMT