- 58
- 125 439
BsidesOrl Youtube
United States
เข้าร่วมเมื่อ 4 มิ.ย. 2017
B-Sides Orlando's Official TH-cam Channel! Come hack with us on October 18th and 19th for BSides Orlando 2024 - bsidesorlando.org/
BSIDESORL Career Talks - 9/25 - Networking Utilizing LinkedIn
BSIDESORL Career Talks - 9/25 - Networking Utilizing LinkedIn
มุมมอง: 50
วีดีโอ
BSides Orlando Byte Size 2021 Announcement
มุมมอง 5533 ปีที่แล้ว
Announcement regarding BSides Orlando 2021 Byte Sized Announcement Call for Participants - bsidesorlando2021.busyconf.com/proposals/ More info here: bsidesorlando.org/bsides-orlando-byte-sized-2021/ Music & Video Stock footage provided by Videvo, downloaded from www.videvo.net" Summer Feelings by MegaEnx | soundcloud.com/megaenx Music promoted by www.free-stock-music.com Creative Commons Attrib...
BountyCraft - The Panel Chloe Messdaghi, Jason Haddix, Rey Bango
มุมมอง 924 ปีที่แล้ว
BountyCraft - The Panel Chloe Messdaghi, Jason Haddix, Rey Bango
iOS Game Hacking: All the fun of reverse engineering and none of the job opportunities! Kevin Colley
มุมมอง 5K4 ปีที่แล้ว
iOS Game Hacking: All the fun of reverse engineering and none of the job opportunities! Kevin Colley
What We Do In the Shadows: Going “Dark” with Consumer Electronics - Timothy Kusajtys
มุมมอง 2554 ปีที่แล้ว
What We Do In the Shadows: Going “Dark” with Consumer Electronics - Timothy Kusajtys
I graduated from InfoSec... Now what? - Noel Pamias
มุมมอง 1454 ปีที่แล้ว
I graduated from InfoSec... Now what? - Noel Pamias
Office 365 Incident Response - Alex Parsons
มุมมอง 7284 ปีที่แล้ว
Office 365 Incident Response - Alex Parsons
Social Forensication: A Multidisciplinary Approach to Successful Social Engineering - Joe Gray
มุมมอง 884 ปีที่แล้ว
Social Forensication: A Multidisciplinary Approach to Successful Social Engineering - Joe Gray
Logging Pitfalls and How to Abuse Them - Kevin Kaminski
มุมมอง 644 ปีที่แล้ว
Logging Pitfalls and How to Abuse Them - Kevin Kaminski
Winter is Coming… Prepare for your next big incident with open source tools - Andrew Donahoe
มุมมอง 514 ปีที่แล้ว
Winter is Coming… Prepare for your next big incident with open source tools - Andrew Donahoe
B-Sides Orlando 2019 - Closing Cermony - Ean Meyer
มุมมอง 1045 ปีที่แล้ว
B-Sides Orlando 2019 - Closing Cermony - Ean Meyer
B-Sides Orlando 2019 - Opening Cermony - Ean Meyer
มุมมอง 685 ปีที่แล้ว
B-Sides Orlando 2019 - Opening Cermony - Ean Meyer
The Seduction of the Cloud - When Employees Misbehave - Andrew von Ramin Mapp
มุมมอง 1405 ปีที่แล้ว
The Seduction of the Cloud - When Employees Misbehave - Andrew von Ramin Mapp
KEYNOTE - Cross-Node Networking: Bridging the Devops and Security Communities - Ian Coldwater
มุมมอง 4795 ปีที่แล้ว
KEYNOTE - Cross-Node Networking: Bridging the Devops and Security Communities - Ian Coldwater
I got loyalty, got royalty inside my DNA - Marcus Carey
มุมมอง 6435 ปีที่แล้ว
I got loyalty, got royalty inside my DNA - Marcus Carey
The Silver Tongue vs The Iron Fist - Deviant Ollam
มุมมอง 29K5 ปีที่แล้ว
The Silver Tongue vs The Iron Fist - Deviant Ollam
Weaponizing Corporate Intel - Mike Felch and Beau Bullock
มุมมอง 7405 ปีที่แล้ว
Weaponizing Corporate Intel - Mike Felch and Beau Bullock
Joe Gray - Dear Blue Team: Forensic Advice for Security Engineers, System Admins, and more!
มุมมอง 2196 ปีที่แล้ว
Joe Gray - Dear Blue Team: Forensic Advice for Security Engineers, System Admins, and more!
Chad Seaman and Rory Smith - WireX - why shady apps lead to hot pockets
มุมมอง 1266 ปีที่แล้ว
Chad Seaman and Rory Smith - WireX - why shady apps lead to hot pockets
Kevin Cody - Enhancing Application Security: Understanding and Utilizing Browser Security Features
มุมมอง 926 ปีที่แล้ว
Kevin Cody - Enhancing Application Security: Understanding and Utilizing Browser Security Features
Avani Desai - Obsolescence to Relevance - A World When Technology Outpaces Humans
มุมมอง 2176 ปีที่แล้ว
Avani Desai - Obsolescence to Relevance - A World When Technology Outpaces Humans
Mike Felch and Beau Bullock - OK Google, How do I Red Team GSuite?
มุมมอง 1.1K6 ปีที่แล้ว
Mike Felch and Beau Bullock - OK Google, How do I Red Team GSuite?
Dave Switzer and Jonathan Echavvarria - The Trap House Making Your House as Paranoid as You Are
มุมมอง 1496 ปีที่แล้ว
Dave Switzer and Jonathan Echavvarria - The Trap House Making Your House as Paranoid as You Are
Bryan Smith - The Things Network - IoT for Fun and Profit
มุมมอง 746 ปีที่แล้ว
Bryan Smith - The Things Network - IoT for Fun and Profit
Wow, Full sail is a real, physical place?
Is possible to make own server for game like ark survival mobile?
🎉
good soup 🗿
Bad talk. Hot speakers
"Zoom-Zoom-Ahhh-Beep-Beep," @ 28:38, "... Because this is my lane and I am Square in the middle of it and I will honk my horn right on your bumper if you try to slow down this conversation." O', That is Scrumdiddlyum-Viva-La-Apropriatious!
Why does Chompy sound like Strongbad? :D
What are you Coach Z over here? :)
Thanks Ean and team for the update. I love the idea of doing this format. And Chompy is my boy 🐊
This sounds good... looking forward to hear more!
Hot off the press - bsidesorlando.org/bsides-orlando-byte-sized-2021/
!!
I'm super excited 😆
Thanks Ean! We appreciate your continuous effort in bringing the best content.
40:20 “my friend works at offsec” 😆ye ok buddy i’m sure that’s tru
Thank you for this, Dev! I've not been back to DC since 6 because I just knew after I came out it would not be alright. Maybe after the world starts turning again I'll go back!
I love Deviant Ollam
Love you back 👍💚
"Silos are for grain" is underrated! I'm sad that it didn't seem to get the reaction from the audience it should have 😅
11:20 - Dang people just dig the hole deeper when they get in trouble with the law. That's why the FIRST thing your lawyer always always always always always always says is "Do not say even one word until I get there!" And yet, that gap between your being put in the interrogation room your lawyer's arrival can determine whether you go home that night or sleep in a cell...
That, and anything you say to the cops that incriminates you they can testify to; anything you say that clears you is hearsay and inadmissible.
Ean!!!
Oh Lord, this is gonna be so awesome! :D
Meh, could do without all the virtue signaling. We get it, dude. Unconscious bias training good, ya'll racist, "marginalized peoples" are wise elder people like the elves from lord of the rings, if they tell you something it shall not be questioned. You can really tell when the intersectional cult brainwashing took hold if you go through Deviant Ollam's video history. Always the most unhappy (and racist) people are the ones constantly whining about "anti-racist/sexism/whateverism" and all the other intersectional culty stuff. See how he feels a pathological need to disparage "cis-het white dudes" and fetishize "POC trans differently abled inuit lesbians" or whatever, it's because intersectional critical race theory is deeply white supremacist. It's white savior syndrome to the max.
You sound upset. Do you need help opening your juice box?
Did she call him Olaf
That's how Ollam is pronounced.
@@MarvinCZ exactly. 👍
the military rights thing sure has context in late 2020
Ignorant and uneducated. I had lots of faith in deviant ollam, but he’s put his ego and lack of education on display by bashing whites and implying all of them act the same and are privileged.
"bashing whites" 🙄
What about people that had already purchased tickets back in February?
Keep my donation, send a shirt!
Really missing actual cons and hanging out with friends again. :(
There are instructions on the Eventbrite page that will allow you to transfer your ticket or save it for the 2021 event.
“That cable is way too old to fit in that box” he says as there is clearly a hole that fits with that cable
Great talk!
Best talk I've heard in a while
Love it
Sound is atrocious. Can't listen to this seemingly highly interesting topic.
Mental aikido requires mental agility and not everyone has that.
Then they have no business doing security work. If you cannot de-escalate stressful situations, then security work (including police work) is not for you and you should find a different profession.
So far this gentleman has made serious errors in the law. And is going to walk into an obstruction of justice charge.. be advised.
... explain?
@@lagweezle Persons who refuse to report evidence of a crime and are not themselves sovereign such as the Military or the Indian nations are committing at minimum obstruction of justice. NOTICE THAT HE NEGLECTS TO MENTION THAT NEITHER OF THESE ENTITIES IS ACTUALLY A PRIVATE ORGANIZATION. Moreover, any attempt to investigate said crime, under color of law, including unlawful detention is actionable both criminally and civilly. If a reasonable person would not consider themselves free to leave they are in defacto custody.. and thus allowed full due process protection. Doubt me at your own risk. A private venue is only allowed to detain a person as long as necessary to secure police involvement.... and are strongly cautioned against conducting investigations particularly if they are dealing with someone who knows the law.. You can ask them to leave... but if you have reasonable suspicion that a crime has been committed you risk an obstruction charge if you do. Likewise if you ask poorly framed questions,leading questions etc, you lack qualified immunity. The police exist for a reason.
@@marcgrundfest1495 Sure, security needs to always be cognizant of the tort of false imprisonment. Threatening or using force or physical restraint (such as locks and man-traps) opens up a big can of liability, and security absolutely does need to get police involved. But "Can you tell me what's going on?" and "I need you to pack your stuff and leave" are not imprisonment. Otherwise in the US and other countries that aren't authoritarian shitholes, there is a right to refrain from talking to police. Obstruction of justice is limited to things like threatening witnesses, destroying evidence, and assaulting a process server or court officer. Investigation is legal - it's the "under color of law" part that's not. Security totally can ask questions - or just sit there quietly and let an unruly patron explain and explain and explain. Qualified immunity doesn't exist for private security - they're not government agents - so I don't know why you're bringing that up. I want you to sit down and think real hard about why it's important for the military to be subordinate to civil authorities. No it's not "sovereign." Yikes!
@@jordanrodrigues8265 If you detain without legal authority..you are kidnapping. If you detain with legal authority you are required to honor the bill of rights. If you do not then without qualified immunity you are walking into a legal issue. In many jurisdictions security has limited arrest powers confired by the state..at which point they are agents of the state, and can not violate due process. If you claim that you have powers that you do not..you are violating the law. Meanwhile if you witness a crime and do not report it ,if you ask a suspected criminal to leave ,or if you actively obstruct a police investigation by refusing to contact authorities..you are in legal jeopardy. If you decide to simply ask someone to leave ...it had better be because you have no credible belief of unlawful conduct. If you degrade a felony complaint to a request to leave ,you had better hope there are no additional victims. Shopping malls ,in particular are notorious for actively discouraging police reports , so do many police departments( see NYC comstat fraud for example) ,because of the bad publicity..but police have qualified imunity , private security does not The military is a separate sovereign .its called the UCMJ and its why members of the armed services can be tried under UCMJ and civil law for the same offense...its called the dual sovereign theory. The same judicial slight of hand occurs when you are charged under both state and federal law. The distinction between obstruction of a police investigation, and obstruction of justice is valid, but you don't want to be charged with either. DO NOT COVER UP EVIDENCE of CRIMINAL ACTS ,especially Violent crimes. If you chose to investigate on your own, and compromise the states ability to prosecute ,you, unlike the police do not have protection .. Now do as you please..
sorry dev i love you brother but when i hear privilege i tune out and when you mention cis hat white guys or whatever and mention diversity your talk totally falls apart you went full on sjw and started throwing out insults at people without even trying to understand their pov negating everything you said before about deescalating and basically your whole talk . I am not saying I condone their behavior but you throwing insults at them just makes you look weak and a bit childish. Now I dont think thats really you but in that moment you slipped up and let your emotions get the best of you . Here is what I think about privilege and diversity the only truly privileged people in this day and age are the filthy rich and politicians it has nothing to do with skin color or gender unless we are talking affirmative action which is a form of privilege that everyone should despise because it is inherently and by own definition racist and or sexist . now hear me out affirmative action is basically saying you are not good enough to make it on based on merit because you are a woman or black or whatever so we lower the standards to help you out ... however you look at it , it is super degrading . and secondly the only diversity i give a shit about is diversity of thought . just because a group of people looks diverse does not equally mean they have diversity of thought . just because a group of people look the same IT DOES NOT mean they all think the same . Most people talking about diversity are judging a book by its cover and so do you in this talk . Now I get it most of us are guilty of prejudice in one form or another its basic human nature but maybe you should rewatch this talk and refine it before you give it again because you contradict yourself quite a lot . I know this has a ton of mistakes in it but i do my best english is my fourth language after all and i know it seems like i am trying to bash you but thats not it this is meant to be constructive criticism . I might seem harsh or rude at times but I am just being honest about what i think without a filter . I still enjoy your work and I am not one of those people who hate someone just because they disagree on something . Have a good one Dev hope you come to germany this year . Crusho
That's a LOT of typing for someone who's not saying anything
I love how people who talk about "diversity of thought" immediately dismiss thoughts they disagree with. Deviant literally explained how people who have experienced different things will look at situations differently. Your experiences and preconceived notions shape how you perceive the world and respond to it, that's not a crazy concept. Dude literally explained how valuing people's different experiences results in diversity of thought, and you ignored it because he used words you don't like.
Although I wish the sound on this were better, this is a fantastic video. I have seen these exact attack scenarios across multiple industries. These types of compromises are absolutely detrimental and is usually the last thing IR thinks of looking for. I have seen forwarding rules, in addition to O365 accounts, set on VoIP phones, Network MFPs, and Fax Machines. The amount of data loss including proprietary, confidential, and exposing information is so damaging. Thank you again B-Sides for always providing the community with this amazing information. Setting those DLP's and end-user permissions/alerts are crucial!!
Thanks for all of the great info. I'm a firemen and we use some of these techniques to enter buildings on low priority calls.
Did u really fly-in on an ultralight?
Olaf?
en.m.wiktionary.org/wiki/ollam apparently its a gaelic word, i learned something today
A good friend of mine, Patrick Harrington, used to work on trains doing catering (and security - go figure). He told me that he'd have a drunken/unruly customer, and when the train pulled into the next station, he'd say, "Hey, no problem, let's definitely talk about this. Let's step off the step and get some air, man. Whereby the offender would step off the train, Patrick would close the door, and say, "bye!" and pull away. The train was zipping along before the shocked ex-passenger even had a second to react.
How do you descalate with people who lack FTA?
The only thing is, this kinda ass kissing I can pick up in about 20 microseconds. I just say, "Cut the bullshit and get me the president!"
Prince George to Obama at 14:33: th-cam.com/video/0_m8AmAm-XE/w-d-xo.html at 1:59
god bless this absolute lad
>this isn't SJW stuff, this is the DoJ Does the DoJ define skin color as power, or are you projecting your own biases onto the term? After all, white progressives have an out-group bias, so your cop analogy is backward half of the time. I get that you want to be helpful, but if you don't know what you're talking about, you will only create new, larger problems. You may risk anti-black bias without solid guidelines, but you risk *codifying* anti-white bias when you generalize blind assumptions. You go from "someone *might* be racist," which is bad, to "everyone *must* be racist," which is far worse on it's face, but the true problem actually runs much deeper; for example, the alt-right aren't some secret Nazis emboldened by Trump, they're non-racists who grew up and realized that no one else was playing by the rules, and so decided to forego the rules themselves. Likewise, you also run into the issue of self-fulfilling prophecy, after all, even accounting for over-charging, black people are much more likely to resist arrest, and I have yet to hear of an explanation beyond having been told that police just want to kill black people. Accidentally instilling persecutory delusions is a bad thing.
So... All the nazi flags at alt-right gatherings are a coincidence?
Omg Deviant said trans rights :D
Unfortunately some extremely widely adopted CoC documents are written and designed to maximize escalation and destroy whatever community gets fooled into adopting them verbatim. Not because the purported goals are wrong, but because the rules cause too much random or arbitrary enforcement, like a 0.0000001% alcohol limit.
Just so I understand the alcohol one: Was there a zero-tolerance rule in the CoC? Or did staff interpret some other rule as implying that any amount of alcohol warrants being reprimanded/thrown out? (And then only enforced it selectively?) I haven't seen a CoC yet that mentions anything about intoxication. At least DEFCON, C3, Bsides, or even kawaiicon don't. I'm not a teetotaler & don't like being patronized just as much as the next hacker, but I guess I can picture situations where a con decides that codifying a no-alcohol-allowed rule is better than not, and a limit of 0 would be preferrable to "0.5‰BAC, and we have to deploy breathalyzers to check" or "_too_ drunk, as decided by staff's gut feeling/'common sense'" (which I'd call arbitrary).
More generally, the CoCs I like focus on stuff like having designated reporting mechanisms so random staff isn't overwhelmed with situations they're not trained to deal with ; making basic goals like "everyone should be able to feel safe" explicit _and_ fleshing out what this means in practice, including some explicit "don't"s ; and what happens when you break those rules. Having clear rules and e.g. saying "you get one warning, then you get thrown out" _up front_ to get everybody on the same page seems much more conduicive to deescalation _in the moment,_ then leaving that up for debate.
It's important that conventions routinely review and update their codes of conduct, and do their best to make them positive documents. It's a lot of work to be sure, and having the document is only one side of things. But I'd much rather a convention have a subpar code of conduct than none. It shows a step forward, a concern for attendees.
Thanks @DeviantOllam for this. Just a thought, there are more communities with their own rules above and beyond the criminal justice system. The first example I thought of was lawyers. They have their local bar association or law society to deal with breaches of professional standards of conduct. (Or so TV leads me to believe). While the consequences for breaking rules may not lead to jail, they can always kick you out of the club.
Same thing with a lot of certified professions: Doctors, engineers, teachers, architects, social workers and to be a few.
Coffeegonewrong: Isn’t that exactly what he said when he talked about the military, tribal courts, and defcon? Did you miss that part of the keynote, or did you want to bolster his point by showing even more organizations which have non-criminal codes conduct? Just wondering.
L.A.O. SpeedWagon I wanted to give more examples I knew of.
I wish you could test the 'security' at the Doral golf resort.
Macnutz420 Why?
@@laospeedwagon3023 Googled it, owned by Trump. Probably a sh!thole.
Been having a Deviant marathon. You do good work man. A smart man with a big heart. The world needs more people like ya 🐨👯
While I enjoy the technical talks more, I think this is the most important talk you've given yet.
Thank you. :-)
@@DeviantOllam Thank you.
Dang, this talk changed my life. Thanks, Olaf.
great talk. so simple anyone could do it, but corrupt politicians and higher ups dont want to give people an option. because their primary goal is control not deescalation.