SLIDE 1 “Fig Leaf Security”
@haroonmeer - 2011
SLIDE 2
#disclaimer
SLIDE 3
Who am i ? & Why this talk?
SLIDE 4
SLIDE 6
like Simple Nomad!
SLIDE 7
SLIDE 8
thegnome: we expected
SLIDE 9
thegnome: we got
SLIDE 10 this is my rant..
beard
SLIDE 11
- The infosec industry
- ZA infosec research
SLIDE 12
InfoSec: We Suck
SLIDE 13
and it’s our fault
SLIDE 14
No ?
SLIDE 15
Bet on your architecture?
SLIDE 16
Write code for a living?
SLIDE 17 So we build secure networks, but can’t protect our most prized user and we write code, that we know cant stand up to security testing?
SLIDE 18
but nobody can write secure code
SLIDE 19
Right?
SLIDE 20
Wrong!
SLIDE 21 <Brief Digression>
(sub-rant)
SLIDE 22
Do you know these men?
SLIDE 23
we hero worship the wrong guys..
SLIDE 24 </Brief Digression>
(sub-rant)
SLIDE 25
but nobody can write secure code
SLIDE 26
(secure and usable)
SLIDE 27
Really?
SLIDE 28
sendmail vs qmail ? djbdns vs bind ?
SLIDE 29
So why did we think otherwise?
SLIDE 30
Charlatans
SLIDE 31
fig leaves!
SLIDE 32
Application Testing..
SLIDE 33
“Halting Problem!”
SLIDE 34
“patching is a hard” problem
SLIDE 35
Management don’t buy in!
SLIDE 36
AV’s and V’s
SLIDE 37
Why the double standard?
SLIDE 38
We (seem to) only fight the fights we can (kinda) win
SLIDE 39
aka: “buying what ppl are selling”
SLIDE 40
hiding behind our fig leaves..
SLIDE 41 http://blog.thinkst.com/2011/03/our-upcoming-security-apocalypse.html
SLIDE 42 “You & Your Research”
http://www.cs.virgina.edu/~robins/YouAndYourResearch.html
SLIDE 43
SLIDE 44
So why don’t we do more?
SLIDE 45
it’s hard..
SLIDE 46
easy to start.. (ideas are cheap)
SLIDE 47
SLIDE 48
Research Fig Leaves
SLIDE 49
XXX is lame
SLIDE 50
Academic masturbation!
SLIDE 51 “doesn’t impress me”
Stephan Fry: Advice to a younger self.
SLIDE 52
Distraction
SLIDE 53 http://www.acceleratingfuture.com/ michael/blog/images/Amusing- Ourselves-To-Death.jpgText
SLIDE 54
SLIDE 55 “Amusing ourselves to Death”
SLIDE 56
SLIDE 57
No Interesting Problems..
SLIDE 58 “Work on stuff that matters” “New Threats to Privacy”
SLIDE 59
There are important battles to fight..
SLIDE 60
“Don’t just be the guy who tweeted about it”
SLIDE 61
Don’t just fight the fights we can (kinda)win
SLIDE 62
Fight the fights that need fighting
SLIDE 63
We need to produce more than we consume..
SLIDE 64 We need you
haroon@thinkst.com @haroonmeer