DEFCON 28 Wrap Up

  • August 12, 2020

DEFCON, the world’s largest hacking convention and always one of the highlights of my year, was last weekend and, of course, remote. I missed being in Vegas with tens of thousands of hackers, but there were still some fantastic talks and conversations over Discord.

A quick “Top Five” highlights:

  1. If your password is eight characters or less, you essentially don’t have a password. With a small amount of money and a few hours, eight character passwords can be broken with a fair amount of ease. Your password should be at least 12 characters.

  2. That wifi security camera you bought off Amazon for $40 is completely insecure and shares your video, credentials, and even location, with other cameras unencrypted.

  3. Two-factor authentication is an important security measure for every account you have, but it can be beaten with a good phishing attempt. You can’t sleep on phishing just because of 2FA!

  4. The disinformation campaign to instill doubt in mail-in voting is real and huge. Researchers have seen preparations for “time and place” digital attacks since 2017 that can shut off internet or power to voting locations on election day…but then COVID-19 hit and those kinds of attacks don’t work if everyone voted by mail! Since the pandemic has started various nation states launched campaigns to poison the public’s belief in mail-in voting so they can get people back to the polls on election day and back in the target radius of their attacks.

  5. I passed my FCC radio Technician exam!

Related Posts

The Top Five Highlights of Defcon 27

I love Defcon. For years, since I was a young script kiddie in high school, I had attending Defcon, the crazy huge hacker convention held every year in Las Vegas, on my bucket list. Now, Defcon 27 was my third Defcon and I seem to enjoy the conference more every year.

Read more

Amazon Dash Buttons are Awesome For Everything but Buying Stuff

Sell a wifi-enabled button to buy stuff on Amazon? Sure you’d have to make sure you can’t easily modify the button so that people can buy them and not buy stuff on Amazon with them, but that shouldn’t be too hard. Amazon had barely started selling their $5 “Dash Buttons” before this post on Medium showed up: “How I Hacked Amazon’s $5 WiFi Button to track Baby Data”.

Read more

Alexa, Lets Play Jeopardy!

I’ve been playing around with my new Amazon Echo and writing up some “Skills” for the Amazon Alexa voice assistant and so far so good! What I’ve got above is a link to a YouTube video I did demoing a “Jeopardy” skill. It’s not fully baked in that you can’t play a complete game of Jeopardy, but you can choose a category, get a question, and it will keep score for you.

Read more