53
@alecmuffett @alecmuffett www.alecmuffett.com green lane security www.greenlanesecurity.com www.greenlanesecurity.com you and your phone are a huge threat to the net

You and Your Phone are Huge Threats to the Net

Embed Size (px)

Citation preview

Page 1: You and Your Phone are Huge Threats to the Net

@alecmuffett

@alecmuffettwww.alecmuffett.com

green lane securitywww.greenlanesecurity.com

www.greenlanesecurity.com

you and your phone area huge threat to the net

Page 2: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

...but not in the way you may think

Page 3: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

1: You

Page 4: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

knowledge & memory

Page 5: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

example: you & phone numbers

Page 6: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

nowadays your phone helps you remember phone numbers

so you can ignore the phonebook

Page 7: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

example: you & IP addresses

Page 8: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

your computer is not yetbypassing DNS for you

Page 9: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

2: Your Phone

Page 10: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

(my phone)

Page 11: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

samsung galaxy S2

Page 12: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

(I used to sysadmin for universitieswhich had less CPU power)

Page 13: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

networking

Page 14: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

GPRS, 3G, HSDPA/+, Wifi

Page 15: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

Page 16: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

Page 17: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

Mon Jan 9 21:40:05 82.xx.xx.xx Vigor[4294967295] <Info>: DoS smurf Block 31.106.0.240 -> 82.xx.xx.xx PR icmp len 20 84 icmp 0/8

Mon Jan 9 21:40:11 82.xx.xx.xx Vigor[4294967295] <Info>: DoS smurf Block 31.106.0.240 -> 82.xx.xx.xx PR icmp len 20 84 icmp 0/8

Page 18: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

Page 19: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

Page 20: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

Page 21: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

Your phone is...

Page 22: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

powerful enough to be a server

Page 23: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

thoroughly connected

Page 24: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

but underutilised.

Page 25: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

So what?

Page 26: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

threat 1: censorship

Page 27: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

domain filtering

Page 28: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

UAE, Saudi, Ireland...

Page 29: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

DNS domain seizure

Page 30: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

newzbin2, dajaz1, ...

Page 31: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

threat 2: network isolation

Page 32: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

“divided we stand”

Page 33: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

restricted ingress & egress= easier control

= simpler censorship

Page 34: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

direct communication= disintermediation= harder to block

Page 35: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

so why is your phone NAT’ed?

Page 36: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

not security,else you need to avoid wifi

Page 37: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

your phone is NAT’ed and firewalledinstead for another reason:

Page 38: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

“because it’s what peoplecurrently expect”

Page 39: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

summary

Page 40: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

in three sentences:

Page 41: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

“why can’t I ping your phone?”

Page 42: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

“you’d do more with full connectivity...”

Page 43: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

network access is not the same asnetwork connectivity

Page 44: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

until this changes,you and your phone are promoting

inferior methods of network connectivity

Page 45: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

ie: you are part of the problem

Page 46: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

solutions?

Page 47: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

technologies•IPv6

• no more scarcity of addresses• no more argument for NAT

• NAT is not a security mechanism• NAT is not a firewall

Page 48: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

“a /48 is big enough for anyone?”*281,474,976,710,656 devices in your home?

Page 49: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

technologies•Alternatives to DNS

• several out there• “.p2p” domain project

• also better DNS (i.e. DNSSEC)• Unloved by censors• SOPA would forbid

Page 50: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

technologies•Tor

• ignores DNS internally• “.onion” domain

Page 51: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

but the real solution

Page 52: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

demand change.

Page 53: You and Your Phone are Huge Threats to the Net

@alecmuffett www.greenlanesecurity.com

(fin)