Loading…
BSidesSF 2017 has ended
Sched is temporarily in maintenance Read-Only mode. You can continue using the event and personal schedule, but will not be able to make any changes. We apologize for the inconvenience.

Check our Status Page for updates →
Sunday February 12, 2017 12:25pm - 12:55pm PST

Embedded devices (including the so-called Internet of Things) pose unique problems for those responsible for managing and assessing their security.  The devices tend to be less transparent and more tightly integrated than typical software and generally lack the host-based security controls (privilege separation, host firewalls, etc.) found on desktop or server applications.  This talk will cover some of the unique constraints for threat modeling and assessing these devices, then walk through an assessment of a VoIP phone and discuss the issues found there, including potential mitigations that can be applied if a device cannot be updated.

Speakers
DT

David Tomaschik

Senior Security Engineer, BSidesSF CTF Organizer
David is a Senior Security Engineer on the Google Offensive Security team and has been helping to organize the BSidesSF CTF for 7 years. He focuses on red teaming, embedded device security, web security, and security education.

https://www.twitter.com/matir
Sunday February 12, 2017 12:25pm - 12:55pm PST
BuzzWorks
Feedback form is now closed.

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!