Running Away from Security: Web App Vulnerabilities and OSINT Collide
- Micah Hoffman
- Tuesday, February 16th, 7:15pm - 8:15pm
Lately it seems like more and more of our lives are being sucked into the computer world. There are wrist-sensors for tracking our steps, phone apps that plot our workouts on maps, and sites to share our healthy-eating and weight loss progress. When people sign up for these sites, they usually use pseudonyms or the sites give them a unique numbered ID to keep their information "private".
How hard would it be to connect a person's step-counting, diet history, and other info on these health sites to their real lives? Are businesses using these sites for non-fitness purposes?
This talk will show weaknesses in several web applications used for health and exercise tracking and reveal [spoiler alert] how trivial it is to find the real people behind the "private" accounts.
Bonus Sessions
The following bonus sessions are open to all paid attendees at no additional cost. There are many different types of events that fall into these categories:
- SANS@Night: Evening presentations given after day courses have ended. This category includes Keynotes.
- Special Events: SANS-hosted events and other non-technical recreational offerings. This category includes, but is not limited to, Receptions and Information Tables.
Monday, February 15
Session | Speaker | Time | Type |
---|---|---|---|
General Session - Welcome to SANS | Dr. Eric Cole | Monday, February 15th, 8:15am - 8:45am | Special Events |
Malware Analysis for Incident Responders: Getting Started | Lenny Zeltser | Monday, February 15th, 7:15pm - 9:15pm | Keynote |
Tuesday, February 16
Session | Speaker | Time | Type |
---|---|---|---|
Running Away from Security: Web App Vulnerabilities and OSINT Collide | Micah Hoffman | Tuesday, February 16th, 7:15pm - 8:15pm | SANS@Night |
Hactivism: Online Protest, Real-World Consequences | Cindy Murphy | Tuesday, February 16th, 8:15pm - 9:15pm | SANS@Night |
Wednesday, February 17
Session | Speaker | Time | Type |
---|---|---|---|
Debunking the Complex Password Myth | Keith Palmgren | Wednesday, February 17th, 7:15pm - 8:15pm | SANS@Night |
The 14 Absolute Truths of Security | Keith Palmgren | Wednesday, February 17th, 8:15pm - 9:15pm | SANS@Night |
Thursday, February 18
Session | Speaker | Time | Type |
---|---|---|---|
Hunting for Indicators of Compromise with Free/Open Source Tools (Practical Kung-Fu) | Ismael Valenzuela | Thursday, February 18th, 7:15pm - 8:15pm | SANS@Night |