3 ms·
Let me get this straight. A bunch of company executives/founders (37/150) provided physical access to their phones -- turned off I hope -- for the duration of t
by eftychis 4y ago
Let me get this straight. A bunch of company executives/founders (37/150) provided physical access to their phones -- turned off I hope -- for the duration of the event?
And they should be proud of that? The phones used to cf. provide 2FA access to their company.
As someone commented: I am jokingly curious if they would do the same thing at DEF CON. Or provide that phone to a LEO/DoJ without a warrant.
- bhawks 4y agoIn my experience it is not surprising at all. Without a vocal and engaging security advocate and a shared belief in the sensitive nature of the company's data and processes - all devices in the employee's possession are insecure. If you think with a security mindset you probably work in security.
- yao420 4y agoI’ve worked in security for 10 years at startups to faangs and have even presented at defcon a couple of times and don’t see the concern. I take my iPhone and regular laptop to defcon for a decade. What is the worst that can happen? Everything is ssl with hsts so even if they own the wifi connection they can’t eavesdrop. Do you expect someone to launch an apple zero day?
- hackernewds 4y agoI could send a login OTP to the phone number and read the 6 digit OTP on the lock screen (most don't disable this). I've worked in netsec for 2 years and know the weakest link to connected security is usually the users
- ipaddr 4y agoAt defcon? Seems like a place that will test your security.