What DEF CON 34 revealed about the technology behind the physical world

Contributing Analyst: Brian Maroney

Walk through DEF CON 34 long enough and cybersecurity starts looking a lot less like cybersecurity.

There’s a semi-truck. A boat. The new electric Volkswagen ID.Buzz. Hotel locks spread across a table. Cameras, embedded systems, wireless gear, industrial equipment, old computers, arcade machines, lock picks and enough exposed circuit boards to make parts of the convention look more like somebody’s garage than a cybersecurity conference.

None of this is necessarily new to DEF CON. The Car Hacking Village, for example, has been around for years. Lock picking, hardware hacking, wireless security and embedded systems have long been part of the culture.

But seeing all of it together makes something pretty clear:

There aren’t many things left that don’t involve software, connectivity or a computer somewhere inside them.

For the people responsible for protecting a business, that’s important.

Cybersecurity has become much bigger than the network.

DEF CON got a little quieter


DEF CON has never been a quiet place.

Thousands of people are moving between villages. Hardware demos are running. Conversations are happening everywhere. Speakers are presenting within relatively close distance of each other.

This year, DEF CON made one change that I really liked: headphones for the speaking areas.

Instead of every presentation trying to compete with the noise around it, attendees could grab a headset and clearly hear the speaker they wanted to listen to. Another presentation could be happening nearby without drowning it out.

It sounds like a small thing, but it made a huge difference.

You could be standing in the middle of DEF CON with everything happening around you and still hear the person on stage clearly.

The rows of glowing headphones also looked pretty cool.

It was a simple fix to a very DEF CON problem: how do you put this many people, talks and demonstrations into one space without everything competing for the same airspace?

Put on the headphones and keep going.

Because a few aisles away, somebody was probably taking something else apart.

The network isn’t just computers anymore


For years, cybersecurity was pretty easy to picture.

Computers. Servers. Firewalls. Networks.

Protect the endpoints. Protect the data center. Control access.

We still need to do all of that.

There’s just a lot more to protect now.

Walk through DEF CON and you see it immediately.

A modern vehicle has computers, sensors, controllers and software throughout it.

A surveillance camera has firmware, credentials and a network connection.

A piece of industrial equipment isn’t necessarily just a machine.

Something that looks simple from the outside can have processors, radios, software and connections to other systems buried inside it.

That’s where things get interesting for a business.

Your security team might be tracking laptops and servers while operations is installing equipment nobody ever thought to call an endpoint.

Physical security might be installing connected cameras and badge readers.

Facilities might be adding building controls.

Manufacturing might be connecting equipment that used to stand alone.

Another department signs up for a cloud service.

A vendor needs remote access.

Someone connects another device.

Individually, each decision can make perfect sense.

But sooner or later, all of it becomes something the company has to protect.

Whether the security team knew about it or not.

Someone is going to take it apart


One of my favorite things about DEF CON is watching someone become completely obsessed with something most people wouldn’t think twice about.

Why hack a hotel lock?

Why tear apart an embedded device?

Why attack a video game?

Why mess around with a computer that’s several decades old?

Why bring a boat into a hacker conference?

Because the question usually isn’t just:

What does this thing do?

It’s:

What else can I make it do?

That’s a big difference.

Businesses usually look at technology based on what they bought it for.

A camera records video.

A badge reader opens a door.

A controller runs equipment.

A wireless network gets people online.

A vehicle moves people or products.

Someone looking at the same equipment from a security perspective asks different questions.

What does it trust?

What is it connected to?

What happens if I change something?

Can I get it to behave differently?

Can I reach something else through it?

Those questions matter because the manual only tells you what a product is supposed to do.

Security gets interesting when someone ignores the manual.

 

Do you actually know what you own?


That brings up a question every CIO and CISO should be able to answer:

Do you actually know what’s connected to your company?

Not just the laptops.

Not just the servers.

Everything.

The security camera installed three years ago.

The badge system owned by physical security.

The controller running an important process.

The vendor appliance everyone is afraid to touch.

The wireless device sitting in the corner.

The network connection buried inside a piece of equipment.

The system inherited through an acquisition.

The old machine that’s still running because nobody wants to find out what happens if it stops.

None of those things automatically means there’s a security problem.

Not knowing they’re there is the problem.

Asset inventory isn’t exciting.

Nobody is walking into a board meeting bragging about how cool their device inventory is.

But it’s hard to protect something when you don’t know it exists.

You can’t monitor it.

You can’t patch it.

You can’t determine who should have access to it.

And when something goes wrong, that’s a terrible time to discover the business depends on a system nobody on the security team knew about.

 

The old stuff never really goes away


One of the more interesting contrasts at DEF CON was seeing modern hardware sitting next to computers from another era.

At DEF CON, that’s fun.

Inside a business, it’s reality.

Companies don’t replace every piece of technology just because something newer comes along.

Factories can have equipment that runs for decades.

Transportation systems stay in service for years.

Medical devices stick around.

Building systems don’t get replaced every time Microsoft releases a new version of Windows.

And plenty of industrial equipment was built long before anybody thought connecting everything to a network was a good idea.

Why is it still there?

Because it works.

Replacing it might cost millions.

The manufacturer may not support it anymore.

The software controlling it may only run on an operating system everyone wishes had disappeared years ago.

Or nobody wants to reboot it because the last person who really understood it retired.

Meanwhile, the company keeps adding newer technology around it.

That’s something executives need to understand.

The old technology doesn’t disappear when the new technology arrives.

The company ends up owning both.

Sometimes replacing an old system isn’t realistic. That’s fine.

Then the questions become pretty straightforward.

Do we know it’s there?

What can talk to it?

Who can access it?

Can we separate it from things it doesn’t need to communicate with?

Would we notice if something changed?

Old doesn’t automatically mean insecure.

New doesn’t automatically mean secure.

The problem is the thing nobody knows about.

Being connected is convenient. That’s why we do it.


Then there’s wireless.

The Wall of Sheep has been making people think twice about their network habits at DEF CON for years.

One message on the display this year summed it up nicely:

“Just because you’re not on the screen, doesn’t mean you’re not a sheep.”

It’s funny because it’s DEF CON.

But there’s a business lesson underneath it.

Companies want connectivity because connectivity makes work easier.

Employees expect Wi-Fi.

Applications need to talk to other applications.

People want to sign in once instead of remembering 14 passwords.

Vendors need access to equipment.

Employees need to work remotely.

Devices reconnect automatically.

Nobody wants to go back to plugging an Ethernet cable into everything.

The problem isn’t connectivity.

The problem is forgetting what we’ve connected.

A vendor account created for a project three years ago may still work.

A device may automatically join a network because it remembers it.

An application may have access to another application long after anyone remembers why.

A company may have hundreds of these connections.

Attackers don’t need every connection to be bad.

They need one that works.

 

Sometimes you don’t need a computer at all


Then you get to lock picking.

No malware.

No wireless exploit.

No software bug.

Just a lock and somebody interested in understanding how it works.

Lock picking has been part of DEF CON culture for a long time, and it fits perfectly.

The idea isn’t that complicated.

Understand how something works.

Figure out what keeps you out.

See whether you can get around it.

That’s not terribly different from what happens in cybersecurity.

A lock keeps someone out of a room.

A login keeps someone out of a computer.

Companies tend to treat those as completely different problems.

One belongs to physical security.

The other belongs to cybersecurity.

The person trying to get in doesn’t care which department owns the problem.

A company can spend millions protecting its network and still have a poorly secured communications closet.

A server can require multiple forms of authentication while sitting behind a door that’s easy to get through.

A workstation can have great endpoint protection while someone with physical access plugs something directly into it.

And sometimes nobody needs to pick the lock at all.

They just walk behind someone who’s nice enough to hold the door open.

That’s the lesson.

Nobody gets bonus points for attacking your strongest security control.

If the firewall is difficult but the door is easy, the door works just fine.

And it goes both ways.

If someone compromises the system controlling physical access to a building, what started as a cyber problem can suddenly become a physical one.

The CISO doesn’t need to become a locksmith.

But the company does need to understand that physical security and cybersecurity aren’t always separate problems.

 

When cyber problems become business problems


This is where all the cars, locks, cameras, embedded devices and industrial equipment at DEF CON start to matter to people outside the security department.

For years, the easiest way to explain a cyberattack to an executive was through data.

Customer information gets stolen.

Intellectual property gets exposed.

Credentials get compromised.

Financial records get accessed.

All of that still matters.

But software now runs things.

Real things.

Equipment.

Buildings.

Transportation.

Production lines.

Access systems.

A compromised laptop might expose information.

A compromised production system might stop production.

A building system going down might affect the people working inside it.

A transportation system going offline can affect deliveries.

A problem with access controls can affect who can physically enter a facility.

At that point, this isn’t just a cybersecurity problem anymore.

It’s a business problem.

That’s why these conversations can’t stay inside the security department.

The CIO needs to understand them.

Operations needs to understand them.

Physical security needs to understand them.

Risk and compliance need to understand them.

And if shutting down one of these systems can stop the company from doing business, the CEO should understand it too.

The useful question isn’t:

“Can someone hack this?”

Almost anything can have a bad day.

The better question is:

“What happens to the business if this stops working?”

That’s the conversation worth having.

 

Look Around DEF CON


It’s easy to walk around DEF CON and just enjoy how strange the place can be.

There’s a boat inside a hacker conference.

A semi-truck is parked a few aisles away.

Someone is messing with hotel locks.

Someone else is attacking a game.

People are learning to pick locks.

Researchers are tearing into embedded hardware.

Old computers are running alongside modern equipment.

Wireless gear is everywhere.

None of these things is new by itself.

That’s not the story.

The interesting part is seeing all of it in one place.

Technology has worked its way into almost everything businesses use.

Some of it is new.

Some of it is decades old.

Some of it sits in the data center.

Some of it sits in a parking lot.

Some of it hangs from a ceiling.

Some of it controls a door.

And some of it might be running a part of the company nobody thinks about until it stops.

Executives don’t need to become experts in automotive security, lock picking, embedded systems, industrial equipment or wireless hacking.

They do need to know what their company depends on.

What is connected?

Who can access it?

What happens when it fails?

And who owns the problem when it does?

DEF CON 34 didn’t suddenly make cars, boats, locks, cameras or industrial equipment interesting to hackers. People have been taking these things apart for years.

What DEF CON does incredibly well is put all of it in front of you at the same time.

And once you see it together, it’s hard to look at cybersecurity the same way.

 

Cybersecurity is bigger than the network.

Because these days, protecting the network is only part of protecting the business.

 

Conference photography by Brian Maroney.

Related articles