The fourth iteration of the local hacker/security conference has grown even larger, and for a change it was not dominated by Sensepost talks (though this was not by design, just impact of the landscape and MWR seems to have taken over somewhat). I missed the bulk of the first talk (as I had some things to do in the morning), and the rest of the program was interesting. More details on the website.
As per previous conferences, ZACON was held once again at UJ's monstrous concrete jungle in Auckland Park. The lecture theatre was quite nice though, with impressive AV facilities. The demographic spread of ZACON is interesting; in terms of gender (the number of ladies in the room could be counted on one hand), age, race etc. There was a distinct lack of corporate guys; a pity in that the forum is great for knowledge sharing. I do know that there were students from UJ and UP, which does skew the demographics a bit.
I have only captured the talks I found interesting.
Glenn Wilkinson's talk mirrored a similar talk at RSA Europe, on exploiting WiFi AP search requests. The differentiator however, was the ability to chain the systems together (instead of offline systems like the Pineapple). There are some interesting applications of the approach - both good and bad; an it was certainly an interesting discussion.
Simeon Miteff's talk on the security challenges on very high speed networks was quite interesting, especially as it has applicability beyond the research network into modern datacentres. I think the solution is really in segregation - not all connectivity is high speed, and it may be better to focus on the interconnects to slower networks and not focus on securing the high speed networks.
Ross Simpson's talk on hacking games focused a lot on memory hacks; but the discussion point was really in client side validation. Whenever the system does client side validation, these values are stored in memory, and thus potentially can be bypassed. What was particular interesting, is that some very popular modern games (examples were shown on iOS) that use a client-server model can be exploited because they use client side validation. It is true that ioS memory hacks for client-server applications would need jail breaking, but there are some interesting attacks exploiting save files on the device that can work on non jailbroken devices.
Andrew MacPherson's talk on physical access control vulnerabilities was amazing. Starting with the traditional locks and lockpicking, the really cools stuff were the demos on magstripes (with a good background on magstripes) and RFID tags. One of the most impressive talks, especially given the widespread use of magstripes as RFID tags - not only for access control but for all sorts of other uses.
Jacques Louw's talk on using software defined radios for attacks was a continuation of the radio theme. The bulk of the talk was rehashing theory from a long time ago, but the application to utility meters and GSM was very cool (and frightening, when considering the social impact for smart metering).
Schalk Heunis' talk was different, focusing on home alarm systems; and reverse engineering the system using Audrino. While there are attack perspective; there are very cool implications for home automation. The House4Hack team have some interesting work in this regard.
About Me
- alapan
- I ramble about a number of things - but travel experiences, movies and music feature prominently. See my label cloud for a better idea. All comnments and opinions on this blog are my own, and do not in any way reflect the opinions/position of my employer (past/current/future).
27 October 2012
20 October 2012
Most Dangerous Cities in the World
A Mexican think tank, as released a study on the most dangerous cities in the world, and Johannesburg is on no 50 on the list. The data is compiled from crime statistics from 2011, although it seems that murder rate per capita is the key determinant. A short story on the list, in English is available on BusinessInsider.
It is interesting that so few countries make contributions to the list, and all but two of those countries are in the Americas. These lists are off course influenced by the availability of data, and I do think it will change if more crimes are taken into account.
I thought that the crime rate could potentially be linked to the Gini index - which looks at the degree of income equality in the world (full list here). While there is some link - it is certainly not a high degree of correlation. Southern African countries dominate in terms of income inequality, but only South Africa has a reputation for high crime rates.
| Country | No. of Cities | Gini Index (Inequality) |
|---|---|---|
| Brazil | 14 | 16 |
| Colombia | 5 | 10 |
| El Salvador | 1 | 34 |
| Guatemala | 1 | 11 |
| Honduras | 2 | 9 |
| Iraq | 1 | n/a |
| Jamaica | 1 | 42 |
| Mexico | 12 | 18 |
| Panama | 1 | 17 |
| Puerto Rico | 1 | n/a |
| South Africa | 4 | 2 |
| USA | 4 | 43 |
| Venezuela | 3 | 71 |
17 October 2012
Google's Datacentres
Wired has some amazing articles on Google's datacentres and the computing power behind it all.
Very interesting reading!
15 October 2012
Melting Pot
It had been a long time since my previous visit to London - about 6 years I think. The Olympics hasn't really changed the city - other than the remnants on the billboards. It remains old and grimy in some places; and new and shiny in others. It is a testament to the sheer longevity of the city.
One thing that has noticeably changed, is that it is an even bigger melting pot. The high volume of Indian immigrants is well known, but it is only in this trip that I noticed all the other shades of accents - the Polish (or some other Eastern European) receptionist, the Caribbean assistant at the Tube station, various main stream European languages, Chinese, Malay etc. And these aren't even the tourists.
I still don't like the weather, but I do love the melting pot.
13 October 2012
Movie: Haywire
It is a spy/action thriller featuring some top notch actors in Michael Fassbender, Ewan McGregor, Michael Douglas and Antonio Banderas, about on a female mercenary who is framed by her employer. It's a nice story, with a fairly realistic story (no amazing gadgets, people get hurt it fights) but nothing spectacular.
Movie: Father of Invention
It has been a while since I have watched a movie featuring Kevin Spacey. The movie features a successful inventor (who makes money from infomercials) who has just got out of prison. It is partly a story about his search to reclaim his mojo as a inventor; but ultimately it becomes a feel good soppy movie about family values. The brilliance of Usual Suspects this ain't.
For the Lack of a Conductor
The Heathrow connect from London made a surprising, last minute cancelation and stopped the station before the airport. At this point there were three options, take the next train, take the bus or take a taxi. The latter two options wouldn't be supported by the train company; and the last minute change was very perplexing.
It was particularly perplexing that the options were not communicated by the train drivers or the station; but rather by a young apprentice of the train company who had just got off and similarly inconvenienced. Apparently, the cause of the delay - the lack of a conductor to check tickets; apparently a requirement for all Heathrow trains. And even more alarming - this is not an irregular occurrence; but something that is quite frequent (the missing conductor and thus the cancelation of a train). Apparently, this is most frequent on early morning trains to and from Heathrow.
So, if you don't have 30 minutes to spare waiting for the next train (and are willing to pay double); get the express. The affliction of missing conductors apparently does not affect the express.
It was particularly perplexing that the options were not communicated by the train drivers or the station; but rather by a young apprentice of the train company who had just got off and similarly inconvenienced. Apparently, the cause of the delay - the lack of a conductor to check tickets; apparently a requirement for all Heathrow trains. And even more alarming - this is not an irregular occurrence; but something that is quite frequent (the missing conductor and thus the cancelation of a train). Apparently, this is most frequent on early morning trains to and from Heathrow.
So, if you don't have 30 minutes to spare waiting for the next train (and are willing to pay double); get the express. The affliction of missing conductors apparently does not affect the express.
11 October 2012
Hacking Virtual Worlds
Jason Hart had a brilliant talk on different techniques to hack virtual worlds. His key message was, as virtualization had taken off, the CIA principles for security have been completely ignored and many of the old vulnerabilities have not only resurfaced; they are even easier to exploit.
Not all of the talk was specifically focused on cloud. Using a Pineapple he showed how easy it is to intercept and decode passwords (even when they are encrypted). After that, accessing systems, virtual or not, is not a big issue.
But his attack techniques on virtualization platforms were the most illuminating - from accessing VMWare's vCenter via cracking the MD5 password; to exploiting the fact that robot.txt files aren't respected in public cloud services (and thus susceptible to google hacking).
It was not a failure of technology (although the Pineapple did exploit protocol weaknesses), but failure to follow basic principles.
Not all of the talk was specifically focused on cloud. Using a Pineapple he showed how easy it is to intercept and decode passwords (even when they are encrypted). After that, accessing systems, virtual or not, is not a big issue.
But his attack techniques on virtualization platforms were the most illuminating - from accessing VMWare's vCenter via cracking the MD5 password; to exploiting the fact that robot.txt files aren't respected in public cloud services (and thus susceptible to google hacking).
It was not a failure of technology (although the Pineapple did exploit protocol weaknesses), but failure to follow basic principles.
Active Defense
Another buzzword at the conference is Active Defense. Introduced by Francis deSouza in his keynote on day 1, it is based on the idea that wars are not only won by defending, but also by attacking and eliminating threats. The concept is off course controversial and the legal, technical and ethical challenges have been raised by a number of latter speakers.
This morning, Josh Corman raised the idea of resurrecting Letters of Marque as a means of regulating active defense. I am not convinced that this approach will solve the legal and ethical challenges.
Letters of Marque, were granted by European monarchs to sanction specific pirates and allow them to carry out their piracy (usually as long as it was not in their backyard). Effectively, it was state sanctioned criminals; and the idea to enable Letters of Marque for cyber attacks will open a Pandora's box.
This morning, Josh Corman raised the idea of resurrecting Letters of Marque as a means of regulating active defense. I am not convinced that this approach will solve the legal and ethical challenges.
Letters of Marque, were granted by European monarchs to sanction specific pirates and allow them to carry out their piracy (usually as long as it was not in their backyard). Effectively, it was state sanctioned criminals; and the idea to enable Letters of Marque for cyber attacks will open a Pandora's box.
Josh Corman's HD Moore's Law
Since yesterday's keynote by Josh Corman, HD Moore's Law has become some sort of a mantra by the other speakers at the conference.
It's a brilliant argument; instead of focusing on compliance as a minimum baseline, the minimum baseline should be, can you get compromised by default/basic settings of Metasploit? The ease of use of Metasploit and since its widely available, it makes it an easily exploited attack vector. It also aligns to the US RSA Conference talk on metrics that commented that the basic metric of security is "hackability", or how easy is it to hack you.
It's a brilliant argument; instead of focusing on compliance as a minimum baseline, the minimum baseline should be, can you get compromised by default/basic settings of Metasploit? The ease of use of Metasploit and since its widely available, it makes it an easily exploited attack vector. It also aligns to the US RSA Conference talk on metrics that commented that the basic metric of security is "hackability", or how easy is it to hack you.
10 October 2012
Live RAT Dissection
Uri Fleyder (RSA) and Uri Rivner (Biocatch)'s presentation yesterday on the use of remote administration tools, coupled with "man in the browser" attacks is probably the most alarming threat exploitation I have seen recently.
The attack first exploits browser vulnerabilities through drive-by-downloads to infect the target machine. I suppose a drive-by-download is not even necessary - other vectors could also be exploited. Once the target machine is infected, the attacker can make use of a remote administration tool (RAT) to carry out an attack using the target machine. Through the use of "man in the browser" attack, the attacker intercepts browser activities, such as banking (or e-commerce or any other activity), and thus can not only capture data in realtime but can also take control over the browser and show false messages (such as longer login times, false redirections etc).
The beauty of this attack, is that the attack is completely out of the target user's machine, and tokens are actually also compromised in this attack (through the use of redirections). And there are very few countermeasures ...
09 October 2012
RSA Conference Europe: Day 1 Keynotes
There was an overall theme to the first three keynotes - a need to change the security models from (perimeter) defense based to "intelligence based" model. Art Coviello (Chairman, RSA) introduced the theme, with a focus on changing security to be more agile, contextual, risk based and the need to share and analyse information on scale.
Tom Heisner (President, RSA) followed expanding the themes, with an insightful comment on the Moore's law equivalence in security; the cost of attacks have reduced while the complexity of attacks have increased. Both speakers were hugely critical of compliance based regulatory regimes which are sometimes contradictory, and often provide a false sense of security.
Francis deSouza (Symantec) followed the theme with a focus on the need to be more "militaristic" in IT security. His argument was that you can't win a battle on purely defense, and security strategies and solutions need to consider the whole campaign and not just point vectors. In this regard, defense mechanisms also need to be "great" and not just good to be effective.
Adrienne Hall (Microsoft GM for trustworthy computing) focused mainly on cloud adoption, though was a bit out of sync on the earlier theme. Hugh Thompson, was also out of sync, but did raise a different perspective - security solutions currently are a "one size fits all" solution, and are not catered for individuals, so are either too complex or too simple; and are basically both ineffective. To create a security profile that is really personalized will be difficult, but would be a very interesting approach in becoming more secure.
Tom Heisner (President, RSA) followed expanding the themes, with an insightful comment on the Moore's law equivalence in security; the cost of attacks have reduced while the complexity of attacks have increased. Both speakers were hugely critical of compliance based regulatory regimes which are sometimes contradictory, and often provide a false sense of security.
Francis deSouza (Symantec) followed the theme with a focus on the need to be more "militaristic" in IT security. His argument was that you can't win a battle on purely defense, and security strategies and solutions need to consider the whole campaign and not just point vectors. In this regard, defense mechanisms also need to be "great" and not just good to be effective.
Adrienne Hall (Microsoft GM for trustworthy computing) focused mainly on cloud adoption, though was a bit out of sync on the earlier theme. Hugh Thompson, was also out of sync, but did raise a different perspective - security solutions currently are a "one size fits all" solution, and are not catered for individuals, so are either too complex or too simple; and are basically both ineffective. To create a security profile that is really personalized will be difficult, but would be a very interesting approach in becoming more secure.
Chill Man
I caught the slower train from Heathrow to Paddington, which stops at a few local stations along the way. It was surprisingly quick to clear immigrations (last experience at Heathrow, over an hour, yesterday 5 minutes), so I had some time before I could check in to my hotel.
The first stop after Heathrow, two heavily tattooed men dressed in tatty clothes got on, and hung by the door. Shortly thereafter, the conductor came through checking tickets, which these men didn't have. I was quite surprised, as were the two men, on the conductor's reaction. After a hushed (but still audible) chat on why they didn't have tickets, the conductor simply asked the two men to take a seat and relax. The men were so startled, that the conductor had to repeat himself, "chill man".
I am not sure why this small incident should stick in my mind ... are these instances of understanding officialdom so rare?
The first stop after Heathrow, two heavily tattooed men dressed in tatty clothes got on, and hung by the door. Shortly thereafter, the conductor came through checking tickets, which these men didn't have. I was quite surprised, as were the two men, on the conductor's reaction. After a hushed (but still audible) chat on why they didn't have tickets, the conductor simply asked the two men to take a seat and relax. The men were so startled, that the conductor had to repeat himself, "chill man".
I am not sure why this small incident should stick in my mind ... are these instances of understanding officialdom so rare?
07 October 2012
Symphonic Rocks 2012
The second year in Jo'burg wasn't as well attended, with a number of free seats. Carnival City, as a venue probably contributes to that, but the crowd did seem a lot more diverse than last year. The combination of the 65 piece Cape Town Pops Orchestra and leading SA pop/rock artists is not only great music, but as Ard Matthews put it so eloquently, a great way to preserve a dying art, an contribute to enhancing our culture.
After a short overture, aKing started the proceedings in rocking style with two of their popular radio hits. It was a good start, though the next singer ChianoSky, didn't continue the momentum. Her dance hits for well with the orchestration, but her squeaky voice just irritated me.
A noticably slimmer Zolani Mahola (of Freshlyground fame) was the best performer of the first half, getting great applause and support from the crowd, and there was even dancing in the stands! Freshlyground's music lends itself to orchestration, and I think it would be great if they released a full album backed by an orchestra!
Van Coke Cartel's Afrikaans metal worked with the orchestra, although at times the electric guitar riffs did overpower the orchestra. They kept the energy going, into the next act, Toya Delazy, whose dance pop hits were more well suited for the orchestra.
Ed Matthews confessed to being a "soppy rocker", and belted out two of his solo love ballads followed by the classic "What he means", which seemed to get the whole audience singing. Tumi & The Volume closed the first half, though I found his voice to be overpowered by the instruments.
The second half started with a medley of theme songs from James Bond franchise (cleverly following a Heineken ad featuring Daniel Craig); which got a rousing applause from the audience. Andy Mac, the organizer behind Symphonic Rocks was next with his band Macstanley. Andy makes a good MC (better than the actual MC) and did a good job in introducing everyone on the stage (and the credit for being the head honcho). I haven't really been a fan of Macstanley (or Flat Stanley in their previous incarnation) and they were certainly blown away by the acts that followed.
Fokofpolisiekar should make a symphonic Afrikaans metal album. More than anyone else in the show, their ballads were perfectly pitched with the orchestra and was a truly amazing result. Their standard, "Hemel op die Plateland"was amazing with the symphony and got everyone headbanging.
Multi SAMA winner Zahara was next, and the success of the show was evident in how all the headbangers just switched to jiving along. She has an amazing voice, and it was a great to see her perform live.
Mi Casa played an interesting set, where there didn't seem to be any break between the songs (as would be expected from a electro-dance group). The trumpet playing of Mo-T was impressive, and fitted well into the arrangements.
Ed Rowland, the lead singer of Collective Soul was the last performer. I have seen Collective Soul before, but I am not really acquainted with their music. It was a great performance and a fitting end to the show.
As a final comment, perhaps future shows should consider reducing the number of artists in favor of giving them longer sets. And move the show closer!
23 September 2012
Movie: Beasts of the Southern Wild
It is a strange movie - but one with an incredible imagination, and absolutely stunning acting performances; and a moral story about the devastating impact of climate change. Set in a poor community near New Orleans, the story revolves around a young girl, Hushpuppy, her eccentric father who is trying to teach her how to survive and some strange events that take place during, what seems to be a hurricane. I don't think I really understood some part of the story (like the aurochs), but the acting performances were incredible.
09 September 2012
Buskaid 2012
This year, Buskaid's annual concert was sold out - the first time in the three years I have been going to Buskaid. It's a good thing I bought tickets early (which ironically meant that I almost forgot about it)! The concerts are an interesting mix - classical music by often less heralded composers interwoven with jazz/pop songs; and finished off with kwela and dancing (with the instruments) - something I doubt you will ever see at other classical music concerts.
The concert started off with pieces from Rameau's opera, Castor et Pollux. The program notes, that Rameau has become somewhat of a tradition with the Buskaid, and it was an energetic start to the concert. Due to a recording malfunction, the pieces were played again at the end - with ample encouragement from the crowd!
The second piece, was one of the highlights of the concert. A previous Buskaid concert, was the first time I had heard a live performance of music from "The Black Mozart", Chevalier de Saint-George. This year, the two senior violinists, Kabelo Monnathebe and Simiso Radebe, in the group (both studying at the Royal Academy of Music in London) performed the Allegro of the Symphony Concertante in G major. It is a stunning piece, especially how the violins feed off the rest of the orchestra, and how they blend into each other; and it was a captivating performance by the soloists.
Czech composer, Leoš Janáček's Idyll for String Orchestra was a bit of a let down after the Symphony Concertante - it felt like a filler piece; and I would have preferred a full performance of the Symphony Concertante instead. It was followed by two vocal pieces (Send in the Clowns, and At Last, both from old musicals), sung by viola player Mathapelo Matabane; who certainly has a voice that complements the style of the songs. The last piece, before the interval was the last movement (Marcia) from Swedish composer Dag Wirén's Serenade for String Orchestra. It is a very lively piece that I haven't heard before (though it is supposed to be very popular). I am not a big fan of Handel, so the first piece after the break (Suite from Terpsichore) wasn't that interesting.
Kabelo Monnathebe's performance of Nigun, by Ernest Bloch was the highlight of the evening for me. Part of a bigger work, Baal Shem, it is a dedication to Bloch's Jewish Roots, and Nigun is itself a religious piece. The piece itself is wonderful - it sounds religious, but it sounds like a story that wants to burst out. A story of triumph, of despair, of happiness and a whole lot more. It is a piece that requires mastery of the violin, and it was a brilliant performance, receiving a rousing applause at the end.
The last "official" piece (before the rerun of the Rameau, and the kwela pieces) was the "world premiere" of Karl Jenkin's Soweto Suite for Strings. It is not a completely new suite - but is rather assembled from Karl Jenkin's two big hits - The Armed Man and Stabat Mater. The pieces work surprisingly well together, and it is interesting to hear them without the choral and other orchestral accompaniments (although there were a few drums).
Beyond showing the musical talent of South Africa, Buskaid is a positive push on how transformation can take place; and a triumph of skill and perseverance over simple affirmative action. However, while it Buskaid has been wildly successful, it is facing a massive financial shortfall should the Lotto money not be renewed. In that it requires support - and support for more than just attending concerts and buying CDs, and I plan to add my pledge to the ring.
That said, Buskaid is now effectively a thorough bred music school - and perhaps it is time that it also spans its wings. With highly competent performers and teachers, perhaps it should also consider doing lessons that are paid for. After all, while it is true that the vast majority of its students are from disadvantaged backgrounds; there are also students who are from advantaged backgrounds who wishes to learn and improve playing string instruments. Perhaps the solution should also encompass teaching, for profit, to the advantaged students that can afford the lessons? Yes, it may be a different track to how Buskaid started, but it could be an important step to a brighter, and more integrated future ...
30 August 2012
Joshua Bell - JPO's 3rd Season, 6th Week
American violinist, Joshua Bell, is undoubtedly the biggest classical music star to have graced the JPO (at least since I have been going to the JPO). Playing to a full house, it was a masterful performance of
The concert started with a performance by the JPO academy, which seemed to be a medley of pieces. It felt a bit tentative, though it is difficult to judge without knowing much about the piece.
The first JPO piece was the ovurture to Carl Maria von Weber's "Der Freichütz". It was a fun piece, interesting to listen to, enough to want to listen to the whole piece.
The piece before the break was Mendelssohn's "Midsummer Night's Dream", linked to Shakespeare's play; though not completely aligned. I know the play only at a high level, and the music didn't align completely to the play; do it was difficult to get the story from the music.
Joshua Bell is playing at the JPO tonight and then in Cape Town. If there are tickets left, it is very worthwhile to go.
The concert started with a performance by the JPO academy, which seemed to be a medley of pieces. It felt a bit tentative, though it is difficult to judge without knowing much about the piece.
The first JPO piece was the ovurture to Carl Maria von Weber's "Der Freichütz". It was a fun piece, interesting to listen to, enough to want to listen to the whole piece.
The piece before the break was Mendelssohn's "Midsummer Night's Dream", linked to Shakespeare's play; though not completely aligned. I know the play only at a high level, and the music didn't align completely to the play; do it was difficult to get the story from the music.
Joshua Bell is playing at the JPO tonight and then in Cape Town. If there are tickets left, it is very worthwhile to go.
22 August 2012
Movie: The Dark Knight Rises
Christopher Nolan's Batman trilogy has to be the finest superhero movie series to date. Across all the spheres, the beautiful cinematography, the great acting, impressive story writing and dialogue; each movie has been a great movie first, before being a great superhero movie. Like a proper trilogy, The Dark Knight Rises, builds upon the earlier stories and characters - not only in the growth of Bruce Wayne/Batman, but also the supporting characters such as Commissioner Gordon and Gotham itself.
The story has a bigger political undertone, especially of Bane's "uprising"; but the ultimate link to why Bane actually targets Gotham is tenuous, at best. It is probably one of the biggest plot holes (next to how Batman gets back to Gotham after his "exile"), especially as Batman has for all intent retired at the beginning of the movie. That aside, the pacing of the story, the characters (especially Bane and Anne Hathaway's Catwoman) and the construct of the "prison" of Gotham City is superb.
I have only two, relatively minor, issues with the film. Firstly, Bane's (and sometimes Batman's) speech was sometimes inaudible - but that could have been to do with the theater (and my hearing). Secondly, the very final scene with the coffee shop - did spoil the overall ending sequence. The entire trilogy has not shrunk away from making bold statements on heroism; the last scene was just unnecessary.
15 August 2012
Movie: Sound of My Voice
It is billed as a psychological thriller, though IMO, the movie misses the mark quite a bit. Similar to the book/movie K-Pax in a way, Sound of My Voice revolves around a documentary filmmaker couple who infiltrate a cult around a woman who claims to be from the future. There is no real proof given on why she should be believed, and the movie sort of devolves into a weird exploration of mysticism. There are some other threads that also take place, but they are not really tied together making the plot even more confusing. In the end, it tries to be interesting, but just fails.
14 August 2012
The Reluctant Fundamentalist
I bought Mohsin Hamid's "A Reluctant Fundamentalist" at the last Exclusive's sale, only because I didn't finish the book while I was "browsing". It is a gripping tale - one of those that you don't want to put down. It is a combination of a great conversational writing style, witty humour and a great plot - of a young Pakistani man, who succeeds in the top echelons of US academia, is highly successful in a competitive financial services but gives it all away as he becomes disillusioned with western politics. It is a highly entertaining read, and at the same time pushes the question on why fundamentalism (of all types) start out in the first place.
Subscribe to:
Posts (Atom)



