Skip to content
AppSec PodcastThe Application Security Podcast — home
21 min

Robert Hurlbut -- Blackhat Security Conference

With Robert Hurlbut

Conferences and Community

What should an application security professional take away from a conference famous for spectacular hacks? Robert Hurlbut shares his experience at Black Hat, including the relationship between Black Hat and DEF CON and what each offers developers and people entering security.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 7 chapters
  1. 00:00Robert’s Black Hat conference takeawaysAudio
  2. 02:05Black Hat and DEF CON explainedAudio
  3. 03:52What AppSec practitioners can learn at the conferencesAudio
  4. 05:55Alex Stamos’s keynote and security fundamentalsAudio
  5. 09:41Inclusion and diversity in the security communityAudio

About this episode

What should an application security professional take away from a conference famous for spectacular hacks? Robert Hurlbut shares his experience at Black Hat, including the relationship between Black Hat and DEF CON and what each offers developers and people entering security. Chris and Robert unpack Alex Stamos’s keynote message about neglected fundamentals, the limits of celebrating only advanced attacks, and the importance of a more inclusive security community. They discuss welcoming newcomers, learning from people with different backgrounds, and making the most of hallway conversations. This episode captures a particular moment in the conferences’ history while offering practical advice about participation: come ready to learn, meet people, and bring useful ideas back to your everyday work.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Robert Hurlbut:
Robert Hurlbut

Resources
Black Hat
DEF CON

Actionable

From this conversation

  1. Learn defensive techniques at conferences

    They certainly can learn about what else is going on out there in the security world.

    4:08
  2. Study attacks and defenses together

    But again, I think it comes out to balance, understanding both sides, understanding how we could work together.

    9:07
  3. Attend newcomer orientation

    Certainly, I went to one session, it was called Day Zero, which was all about— and that was the eve before Black Hat started— and that was all about trying to help people who are new to Black Hat, help them understand the history.

    13:31
Transcript · 21 min conversation

0:05Chris RomeoThe Application Security Podcast. Here we go. Hey folks, Chris here. On this episode of the Application Security Podcast, we're going to talk with Robert about his experiences attending the Black Hat Security Conference a few weeks ago. He's going to explain to us some of the application security-specific things that he saw and heard about, and also talk about the Alex Stamos keynote, which was pretty interesting to a lot of people across the industry. So we hope you enjoy this readout, and we'll be back next week with another interview. Hey folks, welcome to this episode of the Application Security Podcast where Robert and I will be talking about some of Robert's experiences attending what some people affectionately refer to as hacker summer camp, but I like to call Black Hat and DEF CON. Robert, how was your experience in the desert? Are you a Las Vegas fan?

1:23Robert HurlbutNot exactly a fan. It's an interesting place to be. I don't actually mind the heat. I grew up in the Midwest, so I don't mind that. In fact, I like it a little bit better than the Midwest where I grew up. It was very humid. In the desert, it's not that. It's a dry heat. It's very hot. There were some days that were 106 Fahrenheit.

1:49Chris RomeoWow.

1:50Robert HurlbutI can remember that very well. But at the same time, I found that where I was in different hotels, you basically can stay in the hotels and walk from place to place to place and not really go out very much. And so, that's good too.

2:05Chris RomeoThe thing I hate about Las Vegas, the list is long and I know this isn't a travel podcast, but the fact that it can take to get from the front door to your room in the hotel it can take upwards of 15 minutes to walk that distance, find the elevators, and make your way up. So the casinos are definitely set up to capture your money from a gambling perspective. And I guess I'm personally the type of person who likes to keep my money close to my pocketbook. So maybe I'm wondering if maybe folks don't all know what Black Hat is and DEF CON kind of as a side conversation of that. Why don't you start by just laying out a foundation of what is this Black Hat thing?

2:51Robert HurlbutWell, in particular this year, there was a couple of key events for Black Hat. In particular was 20 years celebrating.

3:01Chris RomeoSo this is a security conference, right?

3:03Robert HurlbutIt is a security conference, and DEF CON is actually 25 years this year. So that came first, in which several people got together and, you know, hackers talking about security and What does it mean to be a hacker? And that sort of thing. Then eventually Black Hat evolved as— evolved as sort of the business end, if you will, of security and talking about how do we talk about these things from the perspective of business and married with hacking and so on. Both had some special events, 20 and 25 years. But they're both Black Hat and DEF CON, they're both security conferences that take place in Las Vegas.

3:52Chris RomeoSo do I have to be a hacker to get anything out of this, or is there something in these conferences for the application security professional or newbie or somebody who's trying to get some— is to establish themselves in the world of AppSec?

4:08Robert HurlbutI think so, in terms of certainly this year. I think there was more emphasis, especially this year, on AppSec, or at least defense, and thinking about not just breaking things, breaking into things, but actually also defending. That's where I think that AppSec could get some value. They certainly can learn about what else is going on out there in the security world. Sometimes we are just thinking about protecting our perimeter and the kind of code that we write in order to be secure. but don't always understand all the attacks or all the possible ways that somebody may be able to break in. I think there's some value there in learning how others think in security.

4:57Chris RomeoThat makes sense to me. I would agree with you that it's important for somebody who is focused on application security to understand what those attacks are. You might not be as good at pulling them off as somebody who's a full-time penetration tester, but you're going to be somewhere kind of in between the full-time penetration tester and somebody who knows nothing about individual attacks.

5:23Robert HurlbutRight. And also the other thing is I see some talks that were focused on cross-site scripting attacks. I mean, again, that's an AppSec, essentially an AppSec attack.

5:35Chris RomeoYeah, we own that. We should have a trademark. on that as the AppSec professionals of the world.

5:41Robert HurlbutRight. So those are those kinds of talks that were there as well. But, you know, again, a lot of focus on how do we attack, how do we break things, how do we get in, a lot of that. But again, the AppSec world can learn a lot from that as well. Yeah.

5:55Chris RomeoSo I wasn't there, and, uh, but I did read a lot about what was happening at the conference this year. And I know that you said you had a chance to hear Alex Stamos from Facebook, who— he's the CSO, Chief Security Officer, at Facebook. I know you said you had a chance to hear his keynote that he did. And I've been fond of his work over the years. When I was working at a big tech company, I was able to bring him in as a speaker at an internal conference where he did a talk about how the company that I worked for's products didn't work for his current— where he was working because they couldn't keep up even though this was a really big tech company. So, I realized that he's a He's a good speaker and he has a message that resonates. So what did you take away from the Alex Stamos keynote and how can we tie that back into the world of AppSec?

6:46Robert HurlbutWell, just as I was mentioning, some of the things that he focused on was, you know, talking about how do we get here? Again, celebrating 20 years for Black Hat in particular. He was talking about How did we get here? We focused on a lot of hacking. We focused on a lot of ways to break into things, zero days, all those very sexy, interesting things that we seem to like and are attracted to. But one of the things he kept bringing back attention to was, what are the fundamentals though? What is going on in the everyday world, especially in the world of data breaches and other kinds of things that are happening in the security world? There are fundamental things that are happening like the password problems and other things that are related to that in terms of the fundamentals. What are the fundamentals and what do we need to think about in terms of defense? That was one key thing or one interesting thing I thought that he kept bringing out was we may think that we're ahead of everybody, we know how to attack and all this stuff, but you know, there are some things that we need to also think about in terms of defense. So that was one thing that I thought was interesting that got brought out.

8:04Chris RomeoYeah, and that's an interesting point to think about here. And I think he's spot on. I mean, I've been in this industry for 20 years, and I guess I've been in this industry as long as Black Hat has existed. I've only been there one time for the conference, but we, as an industry, as a group of people, we have focused so heavily on the offensive side, And the cool factor and the wow factor of, like you said, of 0-days and vulnerability research. And that's been kind of what's seen as the most important pieces. And I know, you know, you're in the AppSec world just like I am. It's almost like we're reaching a point where there's almost more people's eyes opening to the fact that the offensive side, yes, it's important, But there's all these other pillars that have to also be just as strong as your offensive capabilities within a given company or your ability to hack into your own applications because of the risks and things that are out there.

9:07Robert HurlbutRight. I mean, again, it's important to understand both sides, I think. And, you know, we can't just simply defend if we don't know what are the potential attacks. So, we need to understand those as well. But again, I think it comes out to balance, understanding both sides, understanding how we could work together. It's not about one is more important than the other, but there's that balance and understanding the importance of each in terms of being able to move forward on building better and secure systems. Yeah.

9:41Chris RomeoSo did you take anything else away from Stamos, the Stamos keynote effort?

9:47Robert HurlbutWell, one other thing he mentioned which has been an issue at these conferences at times is diversity, getting more and more people, women and other people who are involved in security to have a voice and to be welcome. That's been an interesting area in terms of— and you see it on Twitter as well— in terms of just making sure that people are welcome. to conferences like this. And so that was another thing that he also touched on briefly as well.

10:17Chris RomeoYeah, that certainly is something that is getting a lot of attention across our industry, and it's something that we do need to pay— at least on the safety side. Like, it's terrible to hear about incidents that are happening at these conferences where women are harassed or Any number of scenarios that are happening here that are just terrible any place that they happen. But the fact that they're happening within the confines of our industry and something that we should be able to control better is really just a terrible thing. So, we do have a lot of work to go in that area. And I think a lot of conferences are starting to go to, like, to end up with a more diverse panel of people that are actually speaking, they're going to a double-blind setup. Yeah. Just like the world of academia uses. And so, that's the idea where you submit, when you're on the conference committee, you're reviewing the talks that you have to judge, but you have no idea who they came from. And they just give you the name of the talk and then the description and no information about the speaker at all. So, you're making your, you don't have any idea if this person's an accomplished speaker or if they're brand new. And there's none of those kind of biases that can kind of throw you off as to whether it's somebody that you want to choose just because they're an industry-renowned name. The ideas have to stand up for themselves and I'm a big proponent of that idea.

11:47Robert HurlbutYeah, same here. Again, I think that— and I agreed with August Stamos' points there that we need to not cause all that kinds of friction to say, oh, these people are not allowed or different— we don't want that. We don't want you here. cause some problems. Instead, allow some inclusion here, allow some diversity into not only the talks but also for those who are there, and not just feel like, okay, I'm, I'm a woman, but am I with somebody? That's the only reason why— reason I'm here, you know. That, that's wrong. That's just wrong. And that's— I feel very strongly about that as well.

12:28Chris RomeoYeah, I also saw there was a little bit of controversy about some InfoSec newbie kind of group or something. Did you hear— did you see anything or hear anything about that around the conference?

12:40Robert HurlbutAbout, uh, those who are new?

12:43Chris RomeoAnd, and yeah, but there was some— I guess there was some group that was like abusing people. But so, I mean, I guess that's, that's kind of a, a whole separate issue. But we, we can talk about the fact that there are— there is a need to bring more and more people into our industry. And conferences is a great place to do that. It's a great place for people to be able to get out and network that are new to the industry and, and meet people and look for people that can actually help to mentor them. And that needs to be a bigger part of what we do from a conference perspective, any conferences. And, you know, Robert, just like I do, you go to conferences all over the country and we get to see different, different styles of things that are being done. And I just, I just see conferences as a place where we could do a lot more for the new folks to the industry. Regardless of where they're coming from.

13:31Robert HurlbutRight. I do know of a few people that were trying to be very helpful to those who are new. Certainly, I went to one session, it was called Day Zero, which was all about— and that was the eve before Black Hat started— and that was all about trying to help people who are new to Black Hat, help them understand the history. That's where I got some of the history. I mean, there were some holes they actually filled in for me on how it got started and where it's going and that sort of thing. And I think that was great just to try to help those who, you know, even after 20 years, there are going to be some people that are there for the very first time. And what do they need to know about? What do they need to look for? What— how can they get the best things out of that conference for them that they can take home with them and apply to their own situations?

14:19Chris RomeoYeah, definitely. So one of the things that I think is always interesting about going to a conference If you follow a lot of security people on Twitter, you'll see this conversation about this thing called HallwayCon. And so HallwayCon is just the idea that conferences, one of the primary things that you should get out of going to a conference is actually meeting people and reconnecting with people that you've known in the past and having conversations, but also meeting new people that are at different levels in the industry and being open to conversations and things. How was your HallwayCon experience in the desert?

15:00Robert HurlbutIt was good. It was good. I met several people as well as see some of my friends that were there. We would, you know, just take a lunch or we would just sit down for a moment, catch up, see what's going on. That's always great just to see different people and what they're doing and meet new people as well. You know, just strike up a conversation and say, hey, what are you working on? They may be working in network security or just some IT and just trying to learn more about security. We can talk and say, hey, I'm also interested in security. Mine is AppSec. Here's what I do, and just exchange some ideas. What are you getting out of the conference? What are you getting out of the conference? That sort of thing. That's really, really helpful as well. Not just the briefings and learning the latest hacks, but also just meeting with the people in the hallways, as you call it, the hallway con.

15:51Chris RomeoYeah.

15:52Robert HurlbutI think it was really, really effective. It's really helpful for me, and I made some great connections there while I was there.

15:57Chris RomeoYeah, it's also a great place to find future guests for the Application Security Podcast.

16:03Robert HurlbutAbsolutely.

16:05Chris RomeoAnd folks, you'll get to hear some of those people that Robert connected with in the desert as future guests here in the coming months on the podcast here. So, I guess, Robert, I saw a couple different stories that came out of this, and if our listeners will know my disdain for the news highlights, podcast show, but I'll just mention a couple of them. We're not going to talk in great detail, but if you are at all curious about what are some of the big things that were announced at Black Hat as far as research and you want to go do some more research on them, I'll give you my list of a couple of things that I thought were pretty interesting that I did some reading on even though I wasn't able to be there and participate. So one of the ones I thought was pretty cool is there was a guy who created a robot safe cracker. So this safe has like 3 dials on it. He created a robot that could then guess the actual combination, and then he found some flaws in the overall safe itself that allowed him to get the crack— the time to crack the safe combinations down to 1 hour and 13 minutes maximum with this robotic device. So that's something people can take a look at. There was some research on the radio— some radioactivity sensors about how some folks Some researchers figured out how they could send fake data and bad— and basically confuse radioactivity sensors to cause them to not be able to do their job at like nuclear power plants and things. Um, some more research on the Tesla side. Tesla's, uh, is a car that's— or a set of cars that has a lot of software driving what they do. And one of the cool things about them is they are very responsive to security researchers. So Some folks found some more vulnerabilities in Tesla cars that Tesla actually patched before Black Hat. Car wash hack. So, Billy Rios found a car— this is one that was really scary to me, Robert.

17:57Robert HurlbutMe too.

17:57Chris RomeoThere's these automated car washes out there that are connected to the internet. There's no people that work in them, and they figured out they could compromise them and take over the actual machines that were operating inside of the car wash, and they could close the doors on the car wash by, you know, through software. They can lock somebody in there. They could, they could bash their person's car with one of the robotic arms in the car wash by taking control of it. So crazy, crazy stuff. But, you know, we don't have time on this podcast to dive into each of those stories. But I just wanted to throw those out there for folks because each of those individual things— well, maybe not the robot safecracker, we'll throw that one out. But the radioactivity sensors, the Tesla problems, the car wash hacks. All of these things, their root cause, application security problems. So it all comes back around to our favorite topic here, application security. The car wash hack, they had implemented authentication. They had problems in their authentication setup that allowed the researchers to bypass the radioactivity sensors. They weren't using encryption or authentication of the actual traffic going back and forth, so people could spoof and—

19:13Robert HurlbutYeah.

19:14Chris RomeoThey could also just fill the traffic up with noise, and the control points had no idea which ones were the correct and legitimate messages and which ones were coming from a spoof source. And then Tesla also, it's all software in those cars, so they had some specific vulnerabilities that allowed remote access into the cars. But once again, they're application security vulnerabilities. It all comes— that's going to be my new motto, Robert. It all comes back to AppSec.

19:44Robert HurlbutAbsolutely. Excellent.

19:46Chris RomeoAll right. Well, folks, that is it for this episode. I will tell you that Robert and I will both be hanging around in the next couple of months at the ISC² Security Congress in Austin, Texas, as well as the OWASP AppSec USA conference. And we would love to meet anybody who actually listens to our podcast. and maybe even interview you if you're going to be available at those events. If you know anybody that you think would be an interesting interview for us, we'd love it if you would, on Twitter, tweet @AppSecPodcast and call out whoever, whomever you might suggest that we could interview on the AppSec front. We thank you for listening, and we hope you have a wonderful day. Thanks for listening to the Application Security Podcast. Security Podcast.

20:41Robert HurlbutOur intro music is 8-Bit Kung Fu by Boring and TJ, and the outro is Southern Delight by Stefan Kartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

3,543 words · transcript by assemblyai

More on Conferences and Community

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.