A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

31
A Place to Hang Our Hats Security Community and Culture @NotDomenic

description

Contrary to popular belief and media depictions, hacking is a social endeavor. By examining the evolution of various hacking groups and collectives over the years, we can glean valuable insight into the structure of today’s hacking space and security culture. From white hat companies to prison, we look at how innovation in exploits and anonymity have reformed and regrouped the hacking clubs of yore. DOMENIC RIZZOLO DUO SECURITY Domenic Rizzolo is a Security Research Intern in the Duo Labs division of Duo Security, studying Math and Complex Systems at the University of Michigan. He’s very interested in what exploring security and hacking culture from an historical context can tell us about modern security issues. He has no hat, as he is a very recent addition to the Duo Security team and the infosec community. Generally, he is interested in analytic solutions to social science problems.

Transcript of A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Page 1: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

A Place to Hang Our Hats

Security Community and Culture@NotDomenic

Page 2: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Full Disclosure

Page 3: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo
Page 4: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo
Page 5: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo
Page 6: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

The Alpha and the OmegaKevin Mitnick was the first and only hacker, lead Anon to glory, took down the FBI, made Tor untraceable, and hacked the alien mothership on the 4th of July.

Page 7: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo
Page 8: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

while author != tech_literate: if narrative < truth and news_day == slow: story = facts.sensationalized() + scare_factor print headline.cyber() + story else: print repackaged_content.rand()

Let’s Make an Algorithm!!

Page 9: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

(Sidebar)

Terms to avoid:● “Cyber”.*● Console Cowboys● Authentification● Cracker (confusion)

Page 10: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo
Page 11: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Out of the Fire, Into the Flame War

● LOD & MOD● DOJ & over-curious young people● Lulzsec & Anonymous● Groups like w00w00, l0pht, [insert group

you’re outraged I didn’t include]

Page 12: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Guiding Question

Are we seeing significant changes and declines in hacker culture and the size of the hacking community?

Maybe?

Page 13: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth Led to Decline

Proposal: Growth in the security community has changed its values and makeup.

● Corporate Growth● Law Enforcement Growth● Growth in Field Population

Page 14: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth

Page 15: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth

Page 16: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo
Page 17: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth: FBI

● FBI Alone saw >350% growth in Intelligence Officers (support, non-special agents) in 90’s○ 1992: 224○ 2000: 1027

Page 18: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo
Page 19: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth: NSA

● 11,000+ new employees between 2001-2013

● Fort Meade Facility > Pentagon

● budget_nsa *= 2● Private contracting companies

○ Pre-2001: ~150 companies○ 2010: ~ 500 companies

Page 20: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth

Page 21: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth

Page 22: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth: Punishment

● Congress and Lobbies push:○ CFAA○ USA PATRIOT Act○ DMCA

Page 23: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth: Punishment

Page 24: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth of InfoSec: Decline of Goups?

● With a growth in both backing of and leaning on security infrastructure, disclosure has become more frequent

● Wouldn’t we expect to see more hacking collectives?

Page 25: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth: C****-Crime

● Organized crime, sometimes even state-sponsored, have taken on some l33t haxors as assets.

● Dark Net, Botnets, Anonymity Tools disincentivize strong open group collaboration

● Major busts: Just one leak

Page 26: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Growth: Responsible Disclosure

● Old Crackers, Sneakers now have avenues to pursue legitimate “cracking”, “sneaking”○ More profitable ones too: Biggest bug bounties now

worth 3.877+ ISS’s● Growing up, settling down, torrenting hacker

children● Less teenage angst

Page 27: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Enter Enterprise● Students &

youngins’ pursuing entrepreneurial and app “hacks”

Page 28: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Omnipresent: Troll & Co

Page 29: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Omnipresent: Troll & Co

Page 30: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Thank You’s

● Zach Lanier ● Chris Czub● Vikas Kumar● Mark Stanislav● Jon Oberheide● Tyler Shields● Your patience for n00bs

Page 31: A Place to Hang Our Hats: Security Community and Culture by Domenic Rizzolo

Q & (Hopefully) A