{"id":123933698,"date":"2020-11-07T18:16:00","date_gmt":"2020-11-07T18:16:00","guid":{"rendered":"https:\/\/danconn.dev\/blog\/2020\/11\/07\/beercon-2\/"},"modified":"2024-07-28T21:19:25","modified_gmt":"2024-07-28T21:19:25","slug":"beercon-2","status":"publish","type":"post","link":"https:\/\/danconn.dev\/blog\/2020\/11\/07\/beercon-2\/","title":{"rendered":"BeerCon 2"},"content":{"rendered":"<h2 class=\"wp-block-heading\">A fun filled virtual day of talks facilitated by The Beer Farmers and friends<\/h2><h3 class=\"wp-block-heading\">Hold my Beer\u2026\u2026\u2026. Con2<\/h3><p>Just over a week ago I, and 27 other rookie speakers took part in a 2 day virtual conference put on by <a href=\"https:\/\/www.linkedin.com\/company\/thebeerfarmers\">The Beer Farmers<\/a> called BeerCon2. The Beer Farmers are, in their own words, \u201cInfoSec rock gods and shitposters of global fame\u201d and I tend to agree. Many of them play instruments and at least two had successful careers in the music industry &#8211; making them bona fide rock gods! However, this hugely understates the amount of good that they do within the community. Their slogan is #HereForYou &#8211; unlike some cybersecurity vendors that <a href=\"https:\/\/youtu.be\/GPmMGKDJ4QY\">\u201cTake Your Security Seriously\u201d<\/a> Here For You is really what The Beer Farmers are. Members have changed over their time, but the current band members comprise <a href=\"https:\/\/appsecbloke.ghost.io\/author\/mike\/\">Mike Thompson<\/a>, <a href=\"https:\/\/twitter.com\/phat_hobbit\">Ian Thornton-Trump<\/a>, <a href=\"https:\/\/scottmcgready.co.uk\">Scott McGready<\/a>, <a href=\"https:\/\/blog.sean-wright.com\">Sean Wright<\/a>, and <a href=\"https:\/\/johnopdenakker.com\">John Opdenakker<\/a>. Every one of the current and previous members are a force for good in the industry, in my humble opinion.<\/p><p>Along with the Infosec Happy Hour, (a cathartic weekly bit of fun infosec therapy, every Friday during lockdown), The Beer Farmers created BeerCon2 because, with the current pandemic, the chances for new speakers to get a chance to speak at conferences has significantly reduced. I for, one, am incredibly thankful they gave us rookies an opportunity and the rest of this will be a rundown of things from my perspective of giving my first cybersecurity talk.<\/p><h3 class=\"wp-block-heading\">Your 1st time might be daunting<\/h3><p>The Beer Farmers had mentioned BeerCon2 and explained the reasons why. I thought this was an amazing initiative. Then they asked, \u201cwell where is your CFP\u201d? I was quite stunned at this. <\/p><p>Although I\u2019d worked in dev for a long time and worked to bring security practices into my dev role, alongside my studies, I didn\u2019t think anyone would want to listen to anything I had to say. They were all very good at pushing me into giving my first talk on tech, let alone cyber, and I\u2019m very grateful they did. All I can say to anyone thinking about it but is unsure\u2026. DO IT. <\/p><p>Send that CFP in. If someone else else has spoken about it, then still\u2026 DO IT. <\/p><p>You have an interesting standpoint to share and no one else will have the same experience as you. <\/p><h3 class=\"wp-block-heading\">The Talk: Using OPSEC And Social Engineering As AWOL (A Way of Life)<\/h3><p>Looking at previous talks from them I thought of something that I thought would be fun and something that I had lived. So I chose a narrative around many years of DJing in night clubs while underage and some of the stories from that time. Well, what\u2019s that got to do with cybersecurity? It\u2019s kinda OPSEC and social engineering. In a way\u2026. Not really! A tenuous link, but at least it was something I thought I could talk about!<\/p><figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/danconn.dev\/blog\/wp-content\/uploads\/2024\/07\/24707436-206a-48d0-8384-cc11ea1a6aba_2450x1382.png\" alt=\"\"\/><\/figure><p>One thing that interested me when learning about social engineering was how you need to build trust in order to attack. I thought that if you think about chains of trust in humans, it\u2019s a bit like how certificates are trusted in Public Key Infrastructure (PKI). If you poison a Root Certificate Authority (CA), then other CAs will accept the poisoned certificate which can lead to things that should not be trusted, to being so. Let\u2019s consider that humans also have this tree of trust, a Human Key Infrastructure (HKI), perhaps. By using social engineering techniques, you can poison this HKI too meaning that you are trusted to do things that you shouldn\u2019t be. In this example it\u2019s being let into nightclubs underage, and getting to DJ at them. But it could also be someone in a business wishing to undertake corporate espionage.<\/p><p>Here\u2019s a link to the talk if you fancy watching it:<\/p><figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"BeerCon2 - Day 1 - Dan Conn\" width=\"500\" height=\"281\" data-cookieconsent=\"preferences, statistics, marketing\" data-src=\"https:\/\/www.youtube.com\/embed\/Fdc_BwB3NII?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><div class=\"cookieconsent-optout-preferences cookieconsent-optout-statistics cookieconsent-optout-marketing\"><\/div>\n<\/div><\/figure><h3 class=\"wp-block-heading\">The support acts are important<\/h3><p>In the run up to the event there was a Slack channel where we could ask questions, arrange rehearsals via Zoom, and just be really supportive of each other. It was a lovely introduction to a new experience. Along with the support we had for each other, there was also a team of mentors and roadies who were so incredibly helpful. I think it\u2019s important to mention them and I hope to remain friends with all of them:<br\/><br\/><a href=\"https:\/\/dfirsec.nl\/author\/lennaert\/\">Lennaert Oudshoorn<\/a><strong>, <\/strong><a href=\"https:\/\/twitter.com\/ddsgerard\">Gerrard Barrett<\/a>, David McKenzie, <a href=\"https:\/\/bores.com\/about\/\">James Bore<\/a>, <a href=\"https:\/\/twitter.com\/RoseSecOps\">Zo\u00eb Rose<\/a>, <a href=\"https:\/\/twitter.com\/ClaireTills\">Claire Tills<\/a>, and <a href=\"https:\/\/twitter.com\/safesecs\">Sam Humphries<\/a><\/p><p>I also had a huge amount of support from someone I\u2019ve never met but definitely consider a friend, <a href=\"https:\/\/red-goat.com\/blog\/\">Lisa Forte<\/a>. I was honoured that she gave me permission to include her story of harassment within the cyber security industry as part of my talk. Although working in tech I have seen various isms and examples of toxic culture, I can not fathom why men (it almost always is men), especially someone in charge of security, can harass someone in this nature. I hope this is something that stops soon. Although Lisa was not an offical BeerCon2 mentor, she ran through my slides and gave me great advice to prepare me for my first talk, and I\u2019m incredibly grateful for the time she gave.<\/p><p>Further to this <a href=\"https:\/\/twitter.com\/cybersecstu\">Stu Peck<\/a> was also kind enough to run through my slides and give permission for his quote on OPSEC to be used. <\/p><p>Final mentions of support go to <a href=\"https:\/\/www.pwndefend.com\">Dan Card<\/a>, <a href=\"https:\/\/twitter.com\/ghostinthecable\">Dan Ward<\/a>, <a href=\"https:\/\/twitter.com\/FLAnderson\">Francis Anderson<\/a>, and <a href=\"https:\/\/twitter.com\/WH_Y\">Andy Holmes<\/a>. These people truly are Infosec Twitter at their best. Danurday &#8211; every Wednesday a selection of us called Dan (and Andy under the name DanHy) say Happy Danurday &#8211; daft but something in this tough times gives me such a happy smile. Team Crofting &#8211; all of us trying to do exercise and replace our surname with Croft &#8211; Francis Croft, Andy Croft, Dan Croft, Lisa Croft! Daft yes. But combined with Zoom chats, talks, text messages from these and all the people above, I get a great sense of belonging, togetherness and happiness while all the world goes through some terrible horrible stuff.<\/p><p>Roadies, support, friends. Thank you \u2665<\/p><h3 class=\"wp-block-heading\">The show finale<\/h3><p>That\u2019s enough of me. There were 27 other speakers over the two days and although I couldn\u2019t watch all of the talks at the time, I am catching up with them now they\u2019re added to a YouTube channel. <br\/>Check out the full playlist here: <\/p><p><a href=\"https:\/\/youtube.com\/playlist?list=PLlo54QX--Ad5Rt9Kf2ZkV2kMUQGcbw48P\">BeerCon2 Playlist<\/a><\/p><p>I cannot stress how amazed I am that everyone in this playlist was their first time speaking. It truly was an inspiring event and hopefully they long continue.<\/p>","protected":false},"excerpt":{"rendered":"<p>A fun filled virtual day of talks facilitated by The Beer Farmers and friends<\/p>\n","protected":false},"author":2,"featured_media":147072146,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55],"tags":[158,13,151,156,154,114,157],"class_list":["post-123933698","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-talks","tag-beercon-2","tag-cyber-security","tag-opsec","tag-opsec-as-awol","tag-persec","tag-the-beer-farmers","tag-underage-drinking"],"_links":{"self":[{"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/posts\/123933698","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/comments?post=123933698"}],"version-history":[{"count":2,"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/posts\/123933698\/revisions"}],"predecessor-version":[{"id":147072339,"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/posts\/123933698\/revisions\/147072339"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/media\/147072146"}],"wp:attachment":[{"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/media?parent=123933698"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/categories?post=123933698"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/danconn.dev\/blog\/wp-json\/wp\/v2\/tags?post=123933698"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}