Top Hacks from Black Hat and DEF CON 2021

Hacker Summer Camp 2021 adopted a hybrid format this year, as the restrictions imposed by the ongoing coronavirus epidemic meant that the majority of participants to Black Hat and DEF CON tuned in online rather than turning up in Las Vegas.


CATCH UP Black Hat 2021: Zero-days, ransoms, supply chains, oh my!


Tools, techniques, and (hybrid) procedures

Security researchers made up for the lack of audience interaction by showing that – like the athletes competing at this month’s Olympics and Paralympics – they could go faster, higher, and stronger together.

Still catching up on the proceedings?

Attacking Let’s Encrypt

At Black Hat, researchers from the Fraunhofer Institute for Secure Information Technology showed how the security controls introduced with Let’s Encrypt’s multi-perspective validation feature might be abused.
Circumventing these controls, which were introduced in February 2020 in response to earlier attacks, makes it possible for attackers to get digital certificates for web domains they do now own, offering a springboard for phishing attacks or other scams.
By introducing packet loss or latency to connections to some of the nameservers, an attacker could force the system to rely on a nameserver of their choice – downgrading the security offered by multiperspective validation.
The work shows that domain validation, though it enjoys advantages because it is low cost and lends itself to automation, is not yet secure and needs to be refined in order to become more effective as a barrier to fraud.
Stories
Stories
Powered by ray.do
Back

Hey There, I'm Jake

I love to make music, travel, and meet new people.

I built this website because I wanted to share my adventures with family and friends in a more intimate way than just sharing to social media.

It's an archive of my adventures and travels, but it's also a free template you can clone and use for yourself to start building your online brand.

Subscribe below to keep up with my most recent adventures.
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
About Matt