- 21
- 10 895
BSides Tallinn
Приєднався 4 жов 2021
Bsides Tallinn 2024 - Taavi Eomäe (There's nothing new except forgotten old)
There's nothing new except forgotten old: Abusing email and defending against it
Email is a ubiquitous part of everyday life, yet its inner workings and future developments often remain distant. Things being overlooked has left plenty of opportunities for abuse. It's up to us to pay a little bit of attention to more than just deliverability.
And even though email is being described on Wikipedia as something that "was conceived in the late-20th century", it's still constantly evolving to better adapt to the 21st century. There are both old and new approaches available that help make things more (in)secure.
This talk covers recent larger vulnerabilities involving DKIM, DMARC and BIMI, currently available methods for improving email security and teases of what's being planned for the future.
Some parts of this talk are also partially covered here: www.zone.ee/blogi/2024/05/17/bimi-and-dmarc-cant-save-you/
Taavi Eomäe
Enthusiast trying to improve (email) security for everyone at night, Cybersecurity specialist at Zone Media OÜ during day. Recently worked on remediating large-scale issues with DKIM, (Associate) Member of CA/Browser Forum's S/MIME working group, proud discoverer of vulnerabilities such as CVE-2023-40440 in Apple Mail.
Email is a ubiquitous part of everyday life, yet its inner workings and future developments often remain distant. Things being overlooked has left plenty of opportunities for abuse. It's up to us to pay a little bit of attention to more than just deliverability.
And even though email is being described on Wikipedia as something that "was conceived in the late-20th century", it's still constantly evolving to better adapt to the 21st century. There are both old and new approaches available that help make things more (in)secure.
This talk covers recent larger vulnerabilities involving DKIM, DMARC and BIMI, currently available methods for improving email security and teases of what's being planned for the future.
Some parts of this talk are also partially covered here: www.zone.ee/blogi/2024/05/17/bimi-and-dmarc-cant-save-you/
Taavi Eomäe
Enthusiast trying to improve (email) security for everyone at night, Cybersecurity specialist at Zone Media OÜ during day. Recently worked on remediating large-scale issues with DKIM, (Associate) Member of CA/Browser Forum's S/MIME working group, proud discoverer of vulnerabilities such as CVE-2023-40440 in Apple Mail.
Переглядів: 151
Відео
Bsides Tallinn 2024 - Jarrad Pemberton & Tormi Tuuling ( Saturday Night Phishing Show)
Переглядів 72Місяць тому
Agenda of BSides Tallinn 2024 - 2024-agenda.tallinn.bsides.ee/bsides-tallinn-2024/schedule/ Join Jarrad Pemberton and Tormi Tuuling, SOC Engineers at Wise, as they walk through how threat actors can leverage verified advertising services to phish your customers. They'll be discussing the tactics of these threat actors, and the Ads transparency movement in today's advertising focused internet la...
Bsides Tallinn 2024 - Elliot Ward (Action Anomalies: A hackers guide to Github Actions)
Переглядів 146Місяць тому
Check out the full agenda of the event in 2024 here - 2024-agenda.tallinn.bsides.ee/bsides-tallinn-2024/talk/FWUPHS/ In the DevOps era of frequent releases, CI tools such as Github actions are powerful platforms to enable secure and rapid software releases, but what additional attack surface do these often privileged components come with? This talk covers a recent research project from Snyk Sec...
Bsides Tallinn 2024 - Keynote speaker Iceman
Переглядів 100Місяць тому
Christian Herrmann Christian Herrmann, better known throughout the hacker community as “Iceman”, is a co-founder of RRG and helped produce many of the most common RFID research tools available today including the Proxmark3 RDV4, and Chameleon Mini. He is an RFID hacking and Proxmark3 evangelist, serving the RFID community as both forum administrator and major code-contributor alongside other co...
Bsides Tallinn 2024 - Lyra Rebane (Web security is fun)
Переглядів 4,2 тис.Місяць тому
Web security is fun (or how I stole your Google Drive files) - pretalx.com/bsides-tallinn-2024/talk/9QNXX7/ This talk is about a vulnerability in Google Drive. But it's also a talk about web security concepts, how services can be made to interact in unintended ways, and how a few seemingly harmless flaws can be chained to defeat security boundaries. See also: Slides - docs.google.com/presentati...
Bsides Tallinn #3 - Mackenzie Jackson - "The attacker's guide to exploiting credentials & secrets "
Переглядів 434Рік тому
Exposed secrets like API keys and other credentials are the crown jewels of organizations but continue to be a persistent vulnerability within security. The majority of security breaches leverage secrets at some point during the attack path. This presentation sheds light on the various methods used by attackers to discover and exploit these secrets in different technologies. This guide will inc...
Bsides Tallinn #3 Jani Kenttala - "Vendors weighted and some found wanting"
Переглядів 87Рік тому
Vendors weighted and some found wanting - DIY for your digital supply chain This year NCSC-FI ran a free campaign to help Finnish companies to identify their digital supply chain, poke the identified vendors about potential security lapses and rate the vendors based on their response. I was there to facilitate this work and will walk you through how you could do this yourself in three easy step...
Bsides Tallinn #3 Stefano Amorelli Credit cards tech and threats - how hackers pay with your money
Переглядів 214Рік тому
Ever wondered what makes your payment cards tick? Who's lurking in the shadows, ready to wreak havoc on your transactions? Let's dive into the fascinating world of payment card technology, exposing both its inner workings, secrets, and how some gentlemen are trying to mess with these systems (and you). Stefano Amorelli Stefano Amorelli, cybersecurity advocate and technology leader, brings his e...
Bsides Tallinn #3 - Soya Aoyama: "Ransomware Protection Full Of Holes"
Переглядів 94Рік тому
Find out more here - tallinn.bsides.ee/2023/ In the fall of 2017, in response to the WannaCry outbreak, Microsoft implemented Ransomware Protection in Windows 10 as a countermeasure. The basis of Ransomware Protection of Windows is Controlled Folder Access, but this feature is full of holes and many researchers have pointed out various flaws. However, Microsoft says that it is a Defense-in-dept...
Bsides Tallinn #3 - Afterevent - Jeopardy (3 teams)
Переглядів 55Рік тому
Enjoy Infosec Jeopardy at the main stage.
Bsides Tallinn #3: Tormi Tuuling, Silver Saks "Scam Message Service"
Переглядів 442Рік тому
Remember how you used to send messages on mobile phones before Whatsapp or Signal? There was a thing called SMS which was limited to 160 characters. Well, for some weird reason, everyone decided to start using it for….everything, including critical security features such as MFA. This is Wise’s war story about how our SMS bill got bigger than our AWS bill because of this. Dive deep into the worl...
BSides Tallinn #2: Thaddeus E. Grugq - Minions vs. GRU
Переглядів 1,6 тис.2 роки тому
BSides Tallinn #2: Thaddeus E. Grugq - Minions vs. GRU
BSidesTLL: Javvad Malik - Shelfware, threat intel & social engineering. Why tech is not the answer
Переглядів 862 роки тому
This session is a cumulation of several years of research into security products, defensive strategies and threat intelligence. Defenders have a dilemma in how they should be protecting their organisations. Which tools bring about the best return on investment, and which ones are most likely to simply sit on the shelf collecting dust? Examining threat intelligence, we’ll delve into the root cau...
BSides Tallinn #2: Peeter Marvet - Logs don't lie, even if most of them are lost in L7 DDoS
Переглядів 1662 роки тому
Legacy means we used to dig into the seconds, and millisecond if needed. So you have faaancy Cloudflare in front of your faaancy K8S and you mostly survived the L7 DDoS because CF took the load after 40 seconds thanks to triggering a rule "origin responds with error500" (e.g "I'm very dead and baring my delicate bits, go find a next guy to harrass") and the cluster magically recovered? Great su...
BSides Tallinn #2: Floris Ladan - Prioritising your security work using MITRE ATT&CK
Переглядів 4232 роки тому
With so many attack vectors and so many detective and preventive measures available, security practitioners are swamped with decisions on what security measures to prioritise and deploy. Enabling and deploying everything available can be counterproductive and overwhelming, leading to ineffective operations with unhappy analysts and with employees rebelling against too many controls. How do you ...
BSides Tallinn #2: Mikko Kenttäla - My Journey to find vulnerabilities in macOS
Переглядів 1742 роки тому
BSides Tallinn #2: Mikko Kenttäla - My Journey to find vulnerabilities in macOS
Rob Dyke - Never Disclose - Until Broken Cyber Law is Fixed | BSides Tallinn 2021
Переглядів 1443 роки тому
Rob Dyke - Never Disclose - Until Broken Cyber Law is Fixed | BSides Tallinn 2021
Nikos Mantas: How occult ransomware gangs will sacrifice your domain admin | BSides Tallinn 2021
Переглядів 2233 роки тому
Nikos Mantas: How occult ransomware gangs will sacrifice your domain admin | BSides Tallinn 2021
Bsides Tallinn #1 Paršovs: Estonian Electronic Identity Card and its Security Challenges
Переглядів 4903 роки тому
Bsides Tallinn #1 Paršovs: Estonian Electronic Identity Card and its Security Challenges
Bsides Tallinn #1 - Laura Kankaala: Vastaamo - When trust falls apart
Переглядів 1,4 тис.3 роки тому
Bsides Tallinn #1 - Laura Kankaala: Vastaamo - When trust falls apart