Jayson Street - I PWN thee I PWN thee not - DEF CON 27 Social Engineering Village

  Рет қаралды 65,875

DEFCONConference

DEFCONConference

Күн бұрын

Пікірлер: 83
@wardrich
@wardrich Ай бұрын
He awkwardly hugs everybody because he's set a pattern and he's wearing an RFID and NFC antenna outfit all the time. And of he's not, up your game Jayson! 😂♥️
@agenericaccount3935
@agenericaccount3935 4 жыл бұрын
Watched the d18 and d19 talks. Then this one. I feel like he is at the point where he really really wishes his advice would be heeded more often and it's not as fun as it used to be. Also, he was right about #newbadge
@Soggy-In-Seattle
@Soggy-In-Seattle 5 жыл бұрын
I’m always on the lookout for Jayson, wherever I go.
@MH-hr6tu
@MH-hr6tu 4 жыл бұрын
That is the exact opposite of his point.
@AK-dp8uy
@AK-dp8uy 4 жыл бұрын
40:00 reminds me of something one of my college profs said "no one remembers the name of a bridge builder unless it falls down"
@sketchyAnalogies
@sketchyAnalogies 4 жыл бұрын
quiz nos what did he teach?
@AK-dp8uy
@AK-dp8uy 4 жыл бұрын
@@sketchyAnalogies one of my ECE classes. Also said "in electrics you do wrong, things go boom, everyone dies" He was very strict about pass fail, no partial credit AT ALL. "Grades like my class. Digital."
@sketchyAnalogies
@sketchyAnalogies 4 жыл бұрын
quiz nos holy moly. I’m actually a EE student. I’m really interested in infosec and physical security as a hobby and a cool thing to understand, but my real passion is with EE. My goal is to design control systems for Walt Disney Imagineering, it perhaps another company.
@DandDskeeto
@DandDskeeto 3 жыл бұрын
Brilliant
@ryoki007
@ryoki007 4 жыл бұрын
Another great talk by the king of awkward hugs. Thanks Jayson.
@chrisl8974
@chrisl8974 4 жыл бұрын
Jayson Street should make a shirt that says "Remember the kittens"
@Manabender
@Manabender 5 жыл бұрын
2:23 "If he approaches you, toss a bag of oreos at him and run. The oreos will distract him."
@lucasthompson1650
@lucasthompson1650 5 жыл бұрын
Someone gives this talk every year … and nothing ever changes. 😡
@duncanmurphy8085
@duncanmurphy8085 5 жыл бұрын
You can't fix stupidity. Apathy is also hard to fix. Both are the roots of social engineering.
@lucasthompson1650
@lucasthompson1650 5 жыл бұрын
@Duncan Murphy I literally stopped my 74 year old mother from getting scammed just 3 days ago when I overheard her talking on the phone and saying, quite timidly, "Ok, I'll have to grab my laptop from the other room…". Everything I've said to her, over years and years, just went out the window. "Mom, he wasn't from MasterCard because they won't make you login to your computer and web banking, remember?" "Well, he sounded pretty serious." Aargh!😖 Couldn't keep him on the line long enough to get a VPC trap ready for him, unfortunately.😔
@helloofthebeach
@helloofthebeach 4 жыл бұрын
To be fair, there are always new people. By definition, it's an endless battle and this kind of talk is always going to be necessary. People don't learn stuff from nowhere. That said, the thing with your mom is pretty bad.
@burningisis
@burningisis 4 жыл бұрын
Its frustrating, but I think Jayson made a good point with gameification and personalizing the lessons. If an employee knows to click the boxes on the survey every year that you send out, but only apply that to a survey, and they're clicking on links in emails, we're the ones failing the employees by not educating them, not the employees failure to not inherently know all of the tricks the bad actors use. The military drills its soldiers so they will act on instinct, sports teams drill their players to act on instinct. We need to drill our employees so they too will act on instinct. And yes those first few drills will make you want to drive your hand through your forehead with the amount of facepalming you do. You will lose faith in all of humanity with that first group of drills. But you keep drilling, you keep reeducating, you keep teaching. Put out the game, give them a little reward, and you start seeing that instinctual behaviour. Jayson gave a talk about bank employees once. He said that if someone came into a bank in a black ski mask and an uzi, everyone would know what to do. There's that instinct. They know what to do in specific circumstances. The instinct is already there. Its our job to educate, to drill, to hone that instinct to the point where they dont have to think anymore. They act. And they act correctly. And then dont stop drilling once you get the behaviour that you want. You keep drilling, keep honing the instinct so that if something bad does come down the pipe, your users are a part of your security team.
@Freakinkat
@Freakinkat Жыл бұрын
​@@burningisisconsidering how little shit's people seem to give and how much people seem to give about random small thing's, chances are that this wont happen my friend. Your points valid and does provide some solution with examples, but companies implementing these things is not looking likely to happen
@hexadecimal7512
@hexadecimal7512 5 жыл бұрын
16:50 - "Hi, my name is Werner Brandes, my voice is my passport, verify me" love the Sneakers reference.
@chrisbogausch1831
@chrisbogausch1831 5 жыл бұрын
One of my all time favorite speakers!
@willedsmithmo
@willedsmithmo 5 жыл бұрын
Same 👍
@alockworkorange7296
@alockworkorange7296 3 жыл бұрын
He looks so differnt without the mohawk but his voice is so distinguishable
@UntrackedEndorphins
@UntrackedEndorphins 4 жыл бұрын
Always love a Jayson talk
@UntrackedEndorphins
@UntrackedEndorphins 4 жыл бұрын
He sounds extra pissed tho
@mildsoup8978
@mildsoup8978 Жыл бұрын
He just got on the F.B.I.'s most meanie list.
@MrH4nds
@MrH4nds 5 жыл бұрын
Jayson "It's like" Street
@aeg001
@aeg001 4 жыл бұрын
I fking love Jayson Street
@mikhailzaruykin663
@mikhailzaruykin663 5 жыл бұрын
I'm not a sysadmin, and I feel guilty
@heartles_xyz
@heartles_xyz 3 жыл бұрын
victi- uh, targ- uh, *clients*
@maneonanewplanenigga5162
@maneonanewplanenigga5162 5 жыл бұрын
first comment: the awkward hug level of Jayson Street is far exceeding 9000
@HiOctaneVideoShare
@HiOctaneVideoShare 8 ай бұрын
TF? TSA confiscated everything more dangerous than toothpics from me.
@gameglitcher
@gameglitcher 5 жыл бұрын
What i got from this is if you need to protect your information hire a Russian.
@asperbergers7136
@asperbergers7136 5 жыл бұрын
I was literally almost, innocently shot after being let through by pier(ECP) gate security let me drive my public 96 "tactical (according to reporting rover)" Jeep Grand Cherokee to retrieve some lines to be spliced on a neighboring ship who frankly.. didnt gaf if we drove up on the pier. Yeahhh Circa 2013 Navy bitches!!!!!!!!!
@Jack-pc9sp
@Jack-pc9sp 3 жыл бұрын
@@asperbergers7136 based
@slappy8941
@slappy8941 5 жыл бұрын
This guy is going to lose his voice completely. I'm okay with that.
@freem4nn129
@freem4nn129 5 жыл бұрын
get a drink madman your voice gets way to raspy
@slappy8941
@slappy8941 5 жыл бұрын
What is the way to raspy, and why would you go there?
@ikaros4203
@ikaros4203 5 жыл бұрын
LOL it's kinda sick
@9393jack
@9393jack 4 жыл бұрын
@@slappy8941 wow you're so smart for recognizing a grammar mistake. I bet you try your best every day to make everyone else think you're smarter than you are
@mauer594
@mauer594 4 жыл бұрын
@@9393jack it was pretty funny
@tectubedk
@tectubedk 4 жыл бұрын
He needs more diet coke
@MrinsaneMr
@MrinsaneMr 5 жыл бұрын
I've been looking for this jerk, I hand him my company on a silver plater and he goes and wrecks my spoke spot!😡😡😡😂🤣
@MrTweetyhack
@MrTweetyhack Жыл бұрын
you can't smiley emoji in notepad
@kaawan3201
@kaawan3201 Жыл бұрын
he meant ":)"
@jjpaq
@jjpaq Жыл бұрын
Cool talk, but can we at least agree that mandatory password reset policies are bullshit and hurt security more than they help? Just another way to guarantee employees either use an easy password, write it down somewhere, or both.
@Ihasagrin
@Ihasagrin 5 жыл бұрын
I don't drink because I'm too coked out
@slappy8941
@slappy8941 5 жыл бұрын
Cocaine is nature's pep talk.
@ikaros4203
@ikaros4203 5 жыл бұрын
Epik
@willedsmithmo
@willedsmithmo 5 жыл бұрын
Actually, usually "Pepsi Max'd" when it comes to Jayson 😝
@florencetown4024
@florencetown4024 4 ай бұрын
20:00
@MalifickSatyrino
@MalifickSatyrino 5 жыл бұрын
1000 points for bloodninja reference!!! omfg!!! bloddninja!!!!
@angina50
@angina50 3 жыл бұрын
Oh I like that Baby. I put on my robe and wizard hat.
@HritikV
@HritikV 4 жыл бұрын
He's just shouting the same thing over and over.
@vaderjo
@vaderjo 5 жыл бұрын
Firing an employee over clicking a bullshit link solicited from inside the company is fucked. The rest of your talk was great! Firing is the lazy managers answer ; Nearly everyone can be trained for basic AI tasks
@jjpaq
@jjpaq Жыл бұрын
Most places have a number of strikes, at least. But if you can't detect a phishing link, whether from inside the company or out (and the real ones may be internal, too), you're a liability to the business.
@youngkappa3562
@youngkappa3562 3 жыл бұрын
I guess every 9years they repeat this speech 😆
@beecee793
@beecee793 Жыл бұрын
It's hard to listen to him scream into the mic. His early talks were really entertaining, but I guess over the years hearing that voice yell about how dumb people are gets kind of old and annoying.
@sammyblaze4234
@sammyblaze4234 5 жыл бұрын
like almost every "hacker" at those cons this guy wastes half of the talk bragging about how stelathy and good they are "you don't want me inside your company with my skillz" and the other half with a tiny bit of information sprinkled with more bragging.
@roren091
@roren091 5 жыл бұрын
I think you missed the point with his talk with like a mile or so. Maybe watch it again and actually listen.
@slappy8941
@slappy8941 5 жыл бұрын
Well they would never have become computer nerds if they had learned social skills.
@forge20
@forge20 5 жыл бұрын
And they never point out the one thing that actually makes them successful: not having the fear of getting caught. Anyone can play off some goofy scheme to hack you if there's no fear. Go in to a place for REAL and try this stupid shit, where if you get caught, you're going to jail. I guarantee you won't just be hangin out in the breakroom, calmly drinkin' a glass of water.
@r3ign0fd3ath3
@r3ign0fd3ath3 5 жыл бұрын
@@forge20 did you really listen? A massive majority of his talk was directed at insider threats (intentional and not), testing your security products to make sure your solutions work as intended and more. Yeah he hits on social engineering. But the point is if someone like him can skip on through, anyone with half a brain and some decent social skills will own companies. If what he is giving is useless information, why is it these basics are ignored at many companies and year after year you hear about breaches or stupid shit like plain text passwords, unpatched systems, or dumb employees opening shifty emails. This needs to be drilled into everyone heads and it's why he and others harp over it over and over and talk about why they own people's shit. Because it's litterally child's play if youre more than halfway motivated and with a bit of skill.
@willedsmithmo
@willedsmithmo 5 жыл бұрын
Dude, he addresses this very issue in this talk kzbin.info/www/bejne/omKyd3uVfZ2DoLM Jayson is awesome, and I've had the pleasure of meeting him a few times too 👍
@forge20
@forge20 5 жыл бұрын
"My badge was just printed on paper" yeah we used to do this where I worked too ... worked great as long as you were actually an employee. If you weren't, security spotted you right away. And that's the problem with 90% of these "hacks".
@willedsmithmo
@willedsmithmo 5 жыл бұрын
Jayson would have almost 100% been able to break in to your company. This was one small example of thousands, and you are WAY over-generalising by saying "these 'hacks'".
Robin Dreeke - Sizing People Up - DEF CON 27 Social Engineering Village
53:48
From Small To Giant 0%🍫 VS 100%🍫 #katebrush #shorts #gummy
00:19
快乐总是短暂的!😂 #搞笑夫妻 #爱美食爱生活 #搞笑达人
00:14
朱大帅and依美姐
Рет қаралды 14 МЛН
Симбу закрыли дома?! 🔒 #симба #симбочка #арти
00:41
Симбочка Пимпочка
Рет қаралды 6 МЛН
Мама у нас строгая
00:20
VAVAN
Рет қаралды 12 МЛН
Keynote - Jayson E. Street - Hacker Striptease
1:05:07
SAINTCON
Рет қаралды 18 М.
The Science Behind Human Hacking (Social Engineering) - Christopher Hadnagy
37:38
Tor Did NOT Get Hacked, UP Smartphone Looks Like a Honeypot
29:08
Mental Outlaw
Рет қаралды 159 М.
DEF CON 31 Recon Village - Joe Gray - Oh! The OSINT You Can Do!
24:03
DEFCON - The Full Documentary
1:50:57
The Documentary Network
Рет қаралды 830 М.
DEF CON 30 - Sam Bent - Tor - Darknet Opsec By a Veteran Darknet Vendor
48:29
From Small To Giant 0%🍫 VS 100%🍫 #katebrush #shorts #gummy
00:19