Jayson Street - I PWN thee I PWN thee not - DEF CON 27 Social Engineering Village

  Рет қаралды 63,831

DEFCONConference

DEFCONConference

4 жыл бұрын

Attackers love it when defenses fail. Implementing defenses without properly understanding the risks and threats is usually a waste of money and resources. This is a frank discussion of what control failures an attacker looks for when attempting to breach an enterprise, as well as how an effective control can help prevent an attacker from being successful. Jayson will walk through real-world scenarios that have led to successful compromise of different companies through control failures. He will also give detailed analysis of controls that led to his attacks being effectively thwarted. Learn how to understand and assess real-world risks, as well as simple defenses which can be implemented to better protect your organization.
Jayson Street: @jaysonstreet
Jayson E. Street is an author of the “Dissecting the hack: Series”. Also the DEF CON Groups Global Ambassador. Plus the VP of InfoSec for SphereNY. He has also spoken at DEF CON, DerbyCon, GRRCon and at several other ‘CONs and colleges on a variety of Information Security subjects.
*He was a highly carbonated speaker who has partaken of Pizza from Beijing to Brazil. He does not expect anybody to still be reading this far but if they are please note he was chosen as one of Time’s persons of the year for 2006.

Пікірлер: 81
@chrisl8974
@chrisl8974 4 жыл бұрын
Jayson Street should make a shirt that says "Remember the kittens"
@Soggy-In-Seattle
@Soggy-In-Seattle 4 жыл бұрын
I’m always on the lookout for Jayson, wherever I go.
@MH-hr6tu
@MH-hr6tu 3 жыл бұрын
That is the exact opposite of his point.
@agenericaccount3935
@agenericaccount3935 4 жыл бұрын
Watched the d18 and d19 talks. Then this one. I feel like he is at the point where he really really wishes his advice would be heeded more often and it's not as fun as it used to be. Also, he was right about #newbadge
@Manabender
@Manabender 4 жыл бұрын
2:23 "If he approaches you, toss a bag of oreos at him and run. The oreos will distract him."
@ryoki007
@ryoki007 4 жыл бұрын
Another great talk by the king of awkward hugs. Thanks Jayson.
@AK-dp8uy
@AK-dp8uy 4 жыл бұрын
40:00 reminds me of something one of my college profs said "no one remembers the name of a bridge builder unless it falls down"
@sketchyAnalogies
@sketchyAnalogies 4 жыл бұрын
quiz nos what did he teach?
@AK-dp8uy
@AK-dp8uy 4 жыл бұрын
@@sketchyAnalogies one of my ECE classes. Also said "in electrics you do wrong, things go boom, everyone dies" He was very strict about pass fail, no partial credit AT ALL. "Grades like my class. Digital."
@sketchyAnalogies
@sketchyAnalogies 4 жыл бұрын
quiz nos holy moly. I’m actually a EE student. I’m really interested in infosec and physical security as a hobby and a cool thing to understand, but my real passion is with EE. My goal is to design control systems for Walt Disney Imagineering, it perhaps another company.
@DandDskeeto
@DandDskeeto 2 жыл бұрын
Brilliant
@chrisbogausch1831
@chrisbogausch1831 4 жыл бұрын
One of my all time favorite speakers!
@willedsmithmo
@willedsmithmo 4 жыл бұрын
Same 👍
@hexadecimal7512
@hexadecimal7512 4 жыл бұрын
16:50 - "Hi, my name is Werner Brandes, my voice is my passport, verify me" love the Sneakers reference.
@lucasthompson1650
@lucasthompson1650 4 жыл бұрын
Someone gives this talk every year … and nothing ever changes. 😡
@duncanmurphy8085
@duncanmurphy8085 4 жыл бұрын
You can't fix stupidity. Apathy is also hard to fix. Both are the roots of social engineering.
@lucasthompson1650
@lucasthompson1650 4 жыл бұрын
@Duncan Murphy I literally stopped my 74 year old mother from getting scammed just 3 days ago when I overheard her talking on the phone and saying, quite timidly, "Ok, I'll have to grab my laptop from the other room…". Everything I've said to her, over years and years, just went out the window. "Mom, he wasn't from MasterCard because they won't make you login to your computer and web banking, remember?" "Well, he sounded pretty serious." Aargh!😖 Couldn't keep him on the line long enough to get a VPC trap ready for him, unfortunately.😔
@helloofthebeach
@helloofthebeach 4 жыл бұрын
To be fair, there are always new people. By definition, it's an endless battle and this kind of talk is always going to be necessary. People don't learn stuff from nowhere. That said, the thing with your mom is pretty bad.
@burningisis
@burningisis 3 жыл бұрын
Its frustrating, but I think Jayson made a good point with gameification and personalizing the lessons. If an employee knows to click the boxes on the survey every year that you send out, but only apply that to a survey, and they're clicking on links in emails, we're the ones failing the employees by not educating them, not the employees failure to not inherently know all of the tricks the bad actors use. The military drills its soldiers so they will act on instinct, sports teams drill their players to act on instinct. We need to drill our employees so they too will act on instinct. And yes those first few drills will make you want to drive your hand through your forehead with the amount of facepalming you do. You will lose faith in all of humanity with that first group of drills. But you keep drilling, you keep reeducating, you keep teaching. Put out the game, give them a little reward, and you start seeing that instinctual behaviour. Jayson gave a talk about bank employees once. He said that if someone came into a bank in a black ski mask and an uzi, everyone would know what to do. There's that instinct. They know what to do in specific circumstances. The instinct is already there. Its our job to educate, to drill, to hone that instinct to the point where they dont have to think anymore. They act. And they act correctly. And then dont stop drilling once you get the behaviour that you want. You keep drilling, keep honing the instinct so that if something bad does come down the pipe, your users are a part of your security team.
@Freakinkat
@Freakinkat 10 ай бұрын
​@@burningisisconsidering how little shit's people seem to give and how much people seem to give about random small thing's, chances are that this wont happen my friend. Your points valid and does provide some solution with examples, but companies implementing these things is not looking likely to happen
@aeg001
@aeg001 4 жыл бұрын
I fking love Jayson Street
@UntrackedEndorphins
@UntrackedEndorphins 4 жыл бұрын
Always love a Jayson talk
@UntrackedEndorphins
@UntrackedEndorphins 4 жыл бұрын
He sounds extra pissed tho
@MrH4nds
@MrH4nds 4 жыл бұрын
Jayson "It's like" Street
@mildsoup8978
@mildsoup8978 Жыл бұрын
He just got on the F.B.I.'s most meanie list.
@heartles_xyz
@heartles_xyz 3 жыл бұрын
victi- uh, targ- uh, *clients*
@alockworkorange7296
@alockworkorange7296 3 жыл бұрын
He looks so differnt without the mohawk but his voice is so distinguishable
@MalifickSatyrino
@MalifickSatyrino 4 жыл бұрын
1000 points for bloodninja reference!!! omfg!!! bloddninja!!!!
@angina50
@angina50 2 жыл бұрын
Oh I like that Baby. I put on my robe and wizard hat.
@mikhailzaruykin663
@mikhailzaruykin663 4 жыл бұрын
I'm not a sysadmin, and I feel guilty
@maneonanewplanenigga5162
@maneonanewplanenigga5162 4 жыл бұрын
first comment: the awkward hug level of Jayson Street is far exceeding 9000
@HiOctaneVideoShare
@HiOctaneVideoShare 2 ай бұрын
TF? TSA confiscated everything more dangerous than toothpics from me.
@gameglitcher
@gameglitcher 4 жыл бұрын
What i got from this is if you need to protect your information hire a Russian.
@jjpaq
@jjpaq 11 ай бұрын
Cool talk, but can we at least agree that mandatory password reset policies are bullshit and hurt security more than they help? Just another way to guarantee employees either use an easy password, write it down somewhere, or both.
@MrinsaneMr
@MrinsaneMr 4 жыл бұрын
I've been looking for this jerk, I hand him my company on a silver plater and he goes and wrecks my spoke spot!😡😡😡😂🤣
@asperbergers7136
@asperbergers7136 4 жыл бұрын
I was literally almost, innocently shot after being let through by pier(ECP) gate security let me drive my public 96 "tactical (according to reporting rover)" Jeep Grand Cherokee to retrieve some lines to be spliced on a neighboring ship who frankly.. didnt gaf if we drove up on the pier. Yeahhh Circa 2013 Navy bitches!!!!!!!!!
@Jack-pc9sp
@Jack-pc9sp 2 жыл бұрын
@@asperbergers7136 based
@Ihasagrin
@Ihasagrin 4 жыл бұрын
I don't drink because I'm too coked out
@slappy8941
@slappy8941 4 жыл бұрын
Cocaine is nature's pep talk.
@ikaros4203
@ikaros4203 4 жыл бұрын
Epik
@willedsmithmo
@willedsmithmo 4 жыл бұрын
Actually, usually "Pepsi Max'd" when it comes to Jayson 😝
@MrTweetyhack
@MrTweetyhack 11 ай бұрын
you can't smiley emoji in notepad
@kaawan3201
@kaawan3201 9 ай бұрын
he meant ":)"
@freem4nn129
@freem4nn129 4 жыл бұрын
get a drink madman your voice gets way to raspy
@slappy8941
@slappy8941 4 жыл бұрын
What is the way to raspy, and why would you go there?
@ikaros4203
@ikaros4203 4 жыл бұрын
LOL it's kinda sick
@9393jack
@9393jack 4 жыл бұрын
@@slappy8941 wow you're so smart for recognizing a grammar mistake. I bet you try your best every day to make everyone else think you're smarter than you are
@mauer594
@mauer594 4 жыл бұрын
@@9393jack it was pretty funny
@tectubedk
@tectubedk 4 жыл бұрын
He needs more diet coke
@slappy8941
@slappy8941 4 жыл бұрын
This guy is going to lose his voice completely. I'm okay with that.
@youngkappa3562
@youngkappa3562 3 жыл бұрын
I guess every 9years they repeat this speech 😆
@vaderjo
@vaderjo 4 жыл бұрын
Firing an employee over clicking a bullshit link solicited from inside the company is fucked. The rest of your talk was great! Firing is the lazy managers answer ; Nearly everyone can be trained for basic AI tasks
@jjpaq
@jjpaq 11 ай бұрын
Most places have a number of strikes, at least. But if you can't detect a phishing link, whether from inside the company or out (and the real ones may be internal, too), you're a liability to the business.
@HritikV
@HritikV 3 жыл бұрын
He's just shouting the same thing over and over.
@beecee793
@beecee793 8 ай бұрын
It's hard to listen to him scream into the mic. His early talks were really entertaining, but I guess over the years hearing that voice yell about how dumb people are gets kind of old and annoying.
@sammyblaze4234
@sammyblaze4234 4 жыл бұрын
like almost every "hacker" at those cons this guy wastes half of the talk bragging about how stelathy and good they are "you don't want me inside your company with my skillz" and the other half with a tiny bit of information sprinkled with more bragging.
@roren091
@roren091 4 жыл бұрын
I think you missed the point with his talk with like a mile or so. Maybe watch it again and actually listen.
@slappy8941
@slappy8941 4 жыл бұрын
Well they would never have become computer nerds if they had learned social skills.
@forge20
@forge20 4 жыл бұрын
And they never point out the one thing that actually makes them successful: not having the fear of getting caught. Anyone can play off some goofy scheme to hack you if there's no fear. Go in to a place for REAL and try this stupid shit, where if you get caught, you're going to jail. I guarantee you won't just be hangin out in the breakroom, calmly drinkin' a glass of water.
@r3ign0fd3ath3
@r3ign0fd3ath3 4 жыл бұрын
@@forge20 did you really listen? A massive majority of his talk was directed at insider threats (intentional and not), testing your security products to make sure your solutions work as intended and more. Yeah he hits on social engineering. But the point is if someone like him can skip on through, anyone with half a brain and some decent social skills will own companies. If what he is giving is useless information, why is it these basics are ignored at many companies and year after year you hear about breaches or stupid shit like plain text passwords, unpatched systems, or dumb employees opening shifty emails. This needs to be drilled into everyone heads and it's why he and others harp over it over and over and talk about why they own people's shit. Because it's litterally child's play if youre more than halfway motivated and with a bit of skill.
@willedsmithmo
@willedsmithmo 4 жыл бұрын
Dude, he addresses this very issue in this talk kzfaq.info/get/bejne/opd_eauQrZ60moU.html Jayson is awesome, and I've had the pleasure of meeting him a few times too 👍
@forge20
@forge20 4 жыл бұрын
"My badge was just printed on paper" yeah we used to do this where I worked too ... worked great as long as you were actually an employee. If you weren't, security spotted you right away. And that's the problem with 90% of these "hacks".
@willedsmithmo
@willedsmithmo 4 жыл бұрын
Jayson would have almost 100% been able to break in to your company. This was one small example of thousands, and you are WAY over-generalising by saying "these 'hacks'".
Robin Dreeke - Sizing People Up - DEF CON 27 Social Engineering Village
53:48
DEF CON 22 - Jayson E. Street - Around the world in 80 cons
1:00:34
DEFCONConference
Рет қаралды 53 М.
Don't eat centipede 🪱😂
00:19
Nadir Sailov
Рет қаралды 22 МЛН
FOUND MONEY 😱 #shorts
00:31
dednahype
Рет қаралды 8 МЛН
where is the ball to play this?😳⚽
00:13
LOL
Рет қаралды 14 МЛН
Keynote - Jayson E. Street - Hacker Striptease
1:05:07
SAINTCON
Рет қаралды 12 М.
DEF CON 26 - Si, Agent X - Wagging the Tail:Covert Passive Surveillance
47:14
Defcon 21 - Forensic Fails - Shift + Delete Won't Help You Here
47:10
HackersOnBoard
Рет қаралды 635 М.
How much charging is in your phone right now? 📱➡️ 🔋VS 🪫
0:11
Which Phone Unlock Code Will You Choose? 🤔️
0:14
Game9bit
Рет қаралды 10 МЛН
Обманет ли МЕНЯ компьютерный мастер?
20:48
Харчевников
Рет қаралды 178 М.
📱 SAMSUNG, ЧТО С ЛИЦОМ? 🤡
0:46
Яблочный Маньяк
Рет қаралды 1,4 МЛН