Pwn2Own

Pwn2Own Winner Tells Apple, Microsoft & Adobe to Find Their Own Bugs
If you feed a man, he eats for a day. If you teach him to phish, he eats everyday.
Pwn2Own Winner Tells Apple, Microsoft & Adobe to Find Their Own Bugs
If you feed a man, he eats for a day. If you teach him to phish, he eats everyday.
Today while in a Salesforce.com demo, I showcased that SSL (the "S" in https) can be stripped away using a classic man-in-the-middle attack.
Luckily, the Salesforce.com team were good sports about it. We discussed alternative access control via IP Address filtering and tokens. This occured over Don Julio 42.
Remember, if your on a public network at Starbucks or the airport, traffic can be sniffed. This means content and passwords.
I have some video recording I will do later this week to show you how.
I am in a meeting with the management team of Salesforce.com. Salesforce is a software as a service (also known as SaaS) company. You can access the application using only your browser. All the infrastructure and data are managed by Salesforce.
SaaS is an example of Cloud Computing. What questions do you have about Cloud Computing ? We are having a security discussion this afternoon. Please send me your questions by email, Twitter, or smoke signal.
I am giving a 7 minute speech tomorrow about Wi-Fi Security. The challenge is to crack WEP before AC/DC's Highway to Hell ends... I'll post the video/slide deck by Thursday along with a step by step guide on how to cut through WEP like a hot knife through butter.
Who runs the largest cloud network online?
Is it Microsoft?
Is it Google?
Wrong, it is the Conflicker worm.