https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

Security


Diversity to Drones: Black Hat Speakers Weigh in On Top Security Trends

  • Written by Nicole Henderson
  • July 27, 2017
In the 20 years since the first Black Hat conference in 1997, security hacks have become incredibly cheap to initiate, increasingly expensive and complex to mitigate, and have more real-world consequences than ever before.

Brought to you by IT Pro

 

In the 20 years since the first Black Hat conference in 1997, security hacks have become incredibly cheap to initiate, increasingly expensive and complex to mitigate, and have more real-world consequences than ever before, according to speakers and attendees at this year’s conference.

The first day of sessions at the conference, which runs until Thursday at the Mandalay Bay in Las Vegas, not only touched on new technology but also the human element of security. Facebook chief security officer Alex Stamos shifted the lens on hackers themselves in his keynote session on Wednesday morning, urging them to reflect on their empathy for users.

Here’s a look at the keynote and other highlights from day one at Black Hat conference.

Facebook CSO: Hackers Need to Work on Empathy

Facebook chief security officer Alex Stamos kicked off the Black Hat conference on Wednesday with a keynote that called on attendees – which include security practitioners, vendors, academics and others – to go beyond finding bugs and the next zero-day and recognize the potential human harm of less interesting security issues like phishing and spam.

According to a report by ThreatPost, Stamos said that the community “is not yet living up to its potential. We’ve perfected the art of finding problems over and over without addressing root issues. We need to think carefully about what to do about it downstream after discovery.” He said that the security community tends to shy away from areas that create real harm, such as instances of abuse like doxing.  

“The security community has the tendency to punish those who implement imperfect solutions in an imperfect world,” Stamos said, according to ThreatPost. “We have no empathy. We don’t have the ability to put ourselves in the shoes of people we are trying to protect.”

If you want to watch the full keynote, you can do so on Facebook here. (Stamos’ presentation starts at 45:42)

Diversity in Cybersecurity Needs to Be Priority

Stamos addressed the issue in his keynote and offline as others in the community continued to discuss how important it is to foster diversity in cybersecurity.

Many believe that diversity is critical in ensuring that different minds come together to solve the complex security problems of the future. But in the last few years since Black Hat has been focusing on bringing more sessions and panels together on the topic, the diversity numbers have not seen a drastic improvement; instead, they’ve essentially flat lined, according to Kelly Jackson Higgins, executive editor at Dark Reading, who put together a panel on Wednesday called “Making Diversity a Priority in Security.”

The panel focused on real-world examples of how organizations are hiring diverse candidates, which actually starts right in the job description. Jackson Higgins describes during Charles Tendell Show podcast how many security job descriptions are not geared towards finding a diverse pool of candidates. Companies and advocates in the security community are trying to change this with internship programs to help underrepresented communities get their foot in the door.

New Hacks Range from Cheap to Critical (Infrastructure)

The human element to security may be interesting and topical, but this is a technology conference, and the sessions on technology are plentiful.

This is no surprise to anyone who works in security, but it’s insanely cheap to hack stuff. I mean, if you know what you’re doing, you basically only need a USB key; or as a panel at Black Hat on Wednesday showed attendees, a $10 SD card reader.

“Dumping firmware from hardware, utilizing a non-eMMC flash storage device, can be a daunting task with expensive programmers required, 15+ wires to solder (or a pricey socket), and dumps that contain extra data to allow for error correction. With the growing widespread use of eMMC flash storage, the process can be simplified to 5 wires and a cheap SD card reader/writer allowing for direct access to the filesystem within flash in an interface similar to that of using an SD card.”

Researchers also discussed on Wednesday a new flaw in the cryptographic protocol in 3G and 4G networks, which can be exploited using a low-cost setup.

Elsewhere, security experts showed attendees how a home-built ultrasound/sound emitting system can be used to launch attacks towards VR products, including smartphones and drones.

DIY projects and drones may seem small-time, but there are all kinds of attacks that have serious real-world security consequences, particularly when it comes to critical infrastructure.

Principal security consultant at IOActive Ruben Santamarta spoke Wednesday about how radiation monitoring devices, used in critical infrastructure like nuclear power plants and at the borders, are being exploited. Jason Staggs, a security researcher at the University of Tulsa, explained how wind farm control networks can be attacked to influence wind farm operations, which are becoming a leading source for renewable energy.

 

Tags: Agents Cloud Service Providers MSPs VARs/SIs Security

Most Recent


  • SMB
    New Comcast Business SD-WAN Solutions Put Focus on SMBs
    The solutions appeal to smaller businesses that don't necessarily need site-to-site connectivity.
  • Cybersecurity research
    ConnectWise MSP Report: Cybercriminals to Heavily Target MSPs in 2023
    MSPs will remain the target of supply chain and critical infrastructure attacks.
  • online survey
    Kaseya MSP Survey: Growing Importance of Automation, Cybersecurity Remains Top Challenge
    MSPs will need to be up to speed on their security offerings to meet SMB demand.
  • Cloud Roundup
    Google Cloud Lashes Out at Microsoft, New Hurdle for Broadcom-VMware
    This cloud computing wrap-up showcases some big news and happenings at more under-the-radar cloud firms.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • zero trust security
    Leveraging Partner Expertise to Build a Zero-Trust Strategy
  • Drive revenue
    Proofpoint Protect: Rising Vendor, Partner Revenues Amid COVID-19
  • Growth plan
    N-able Empower Day 1: How to Grow Your Business
  • Acquisition
    Private Equity Firms Snapping Up ExtraHop in $900 Million Acquisition

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Enterprise Connect 2023 Expo Hall: RingCentral, VMware, Five9, Cisco, More

March 31, 2023

HP’s Head of Global Channel Strategy Talks Program Changes, Poly Opportunity

March 31, 2023

Is the Gap Widening Between Superagents and Mom-and-Pop Shops?

March 31, 2023

Industry Perspectives

View all

Co-innovation Is Needed to Effect Energy Transformation

March 31, 2023

AI Spells the End of End User Security

March 30, 2023

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Kaseya, Post-Acquisition, Expanding ‘Well-Regarded’ Datto Partner Program

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

March 23, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Twitter

ChannelFutures

The shortage of talent in the tech industry gives women a great opportunity to build a career in tech says… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Check out our images from the expo floor at #EnterpriseConnect: @Microsoft @Zoom @GoTo @Cisco @googlecloud @ujetcx… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Learn about @comcastbusiness and some of the trends partners are seeing with #SMB customers. @craigschlagbaum… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

🤔 Interested in expanding on your brand or building a business from square one? @SkySwitchSays explains everythin… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Energy transformation and climate change calls for innovation now @VMware #channelpartners #energycrisis #technews… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Predictions are important when shaping your 2023 expectations & goals. #ChannelFutures is here to help out. We aske… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

Mary Beth Walker on @HP adapting its partner program in response to partner feedback, and what latest launches mean… twitter.com/i/web/status/1…

March 31, 2023
ChannelFutures

.@ConnectWise report shows cybercriminals will continue heavily targeting #MSPs in 2023. dlvr.it/Slnlrj https://t.co/eEY0pMLJaQ

March 31, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X