THE LINEUP

SATURDAY, JUNE 13, 2020

START OF BROADCAST

12:00pm

OPENING REMARKS AND FINANCIAL REPORT

John Terrill and Mark Trumpbour

12:00pm – 12:15pm

4TH PARTY COLLECTIONS OF CLOSE ACCESS OPERATIONS… AND MORE

David Maynor

12:15pm – 1:00pm

MOBILE SIMULATOR

Sophia d’Antoine & Ian Roos

1:05pm – 1:50pm

UNMASKING THE AVENGERS

Elizabeth Wharton & Suchi Pahi

1:55pm – 2:40pm

WASSENAAR YOU SERIOUS? A FIRESIDE CHAT ABOUT EXPLOIT REGULATION

Katie Moussouris

2:45pm – 3:30pm

BACK TO THE BACKDOOR FACTORY

Benjamin Kurtz

3:35pm – 4:25pm

EXPLOITING SEXUAL EXPLOITATION: HOW TO PUNCH ABUSERS IN THE VIRTUAL FACE

The LaBac Collective

4:30pm – 5:15pm

COMPENDIUM OF CONTAINER ESCAPES

Brandon Edwards & Nick Freeman

5:20pm – 6:05pm

PWNIES NOMINATIONS

Justine Bone

6:05pm – 6:20pm

CLOSING CEREMONIES

A Stack of Busticati

6:20pm – 6:45pm

HAPPY “HOUR”

6:45pm – 7:00pm

END OF BROADCAST

7:00pm

Sponsors

NO SPONSORS THIS YEAR. SEE YOU IN 2021!


Bishop Fox
 is the largest private professional services firm focused on offensive security testing. Since 2005, the firm has provided security consulting services to the world’s leading organizations — working with over 25% of the Fortune 100 — to help secure their products, applications, networks, and cloud with penetration testing and security assessments. The company is headquartered in Phoenix, AZ and has offices in Atlanta, GA; San Francisco, CA; New York, NY; and Barcelona, Spain.

Presentations

4th party collections of Close Access Operations… and more

David Maynor

Here’s how David describes his presentation:

“My whole career I have been fascinated with proximity based attacks with vectors like WiFi or Bluetooth. In recent years companies and entrepreneurs have started selling hardware best used for operations to gain access to things close by. I’m in heaven for commercially available professional grade implants and other tools that require physical access. Come learn the lessons I did and what gaps exist as well.”

Mobile SIMulator

A tale of bots, fraud, 347,200 unused SIM cards and 474 iPhones

Sophia d’Antoine and Ian Roos

SIM Cards are clunky and take a while to swap out. That’s really frustrating, why don’t we build an array of activated SIM cards and a hardware device to swap the phone over to a new card quickly and easily. Kinda like a KVM but for SIM cards? Wow what a great idea – oh shoot it’s a fuzzer too? Could someone use this to build better SIM card malware? SIM Cards are a historically overlooked piece of equipment that have been unappreciated by mobile phone assailants for far too long. In this talk we explore SIM cards as an attack vector, delve into the quiet history of SIM exploitation, and take a look at future techniques for attacking this tragically forgotten piece of equipment.

Unmasking the Avengers

Elizabeth Wharton and Suchi Pahi

No longer solely for use by protestors or comic book characters, facial recognition algorithms are racing to adjust for the increased use of facial masks in public. Caught up between protests and COVID are cellular data and biometric data sets, shared with and utilized by law enforcement in often unintended ways. A growing number of public/private partnerships are providing law enforcement access to large data pools. Information that in some cases is incorrect. Your voice may be your password, but what happens when it’s your face and there’s a data breach or the data is wrong. We’ll take a deeper dive into how privately collected location sharing and facial recognition data is being increasingly leveraged by government and law enforcement.

Exploiting Sexual Exploitation: How to punch abusers in the virtual face

The LaBac Collective

Online sexual harassment is one of the most overlooked crimes on both the interwebs and irl. Victims need help, and way fewer resources exist to support them. From cyberstalking cases, to revenge porn posts to deepnude takedowns, LaBac helps victims of abuse defend and prevent targeted attacks.

This talk details our crew’s efforts to flip the table against online abusers. We will outline various tactics used against historical targets, such as technical attacks and policy exploits. We’ll also discuss how you can help punch these abusers in the virtual face.

Back to the Backdoor Factory

Benjamin Kurtz

The Backdoor Factory was a classic tool that injected shellcode into downloaded binaries from a man-in-the-middle attack. We’ve spent a year completely rewriting this in Go as a set of binary modification libraries that you can use in your own code! Join us as we take a tour of the new Backdoor Factory and its expanded capabilities.

Code:

Blog:

Wassenaar You Serious? A Fireside Chat About Exploit Regulation

Katie Moussouris with Ryan Naraine

Join Katie Moussouris and Ryan Naraine for a fireside chat about export controls rearing their ugly heads yet again. We’ll discuss a real-life scenario in which Katie nearly found herself facilitating an illegal international cyber arms deal or three in the Middle East, and how security researchers and even defense-oriented companies can find themselves in hot water when it comes to export control of cyber weapons.

Compendium of Container Escapes

Brandon Edwards and Nick Freeman

Containers are a hot topic, and there’s lots of technical nuance around their operation. In this presentation we will cover vectors and themes for container escapes, from incorrect engine operation, to misconfiguration, to good ol’ fashioned kernel exploitation. So if you’ve ever browsed syzbot output and thought “gee, this one looks easy to trigger, could I get out of a container with it?” (the answer is probably yes), tune in to our talk!

Pwnies Nominations

Justine Bone

It’s the most important award bestowed by the information security community. When you’ve won a Pwnie, you’ll know you’ve earned it, because your peers, the people who really know infosec, fellow leaders and winners of this prestigious award, chose you.

Let’s kick off the summer security season by opening the Pwnies nominations!

The Important People

Justine Bone

As CEO of MedSec, Justine Bone leads a company that conducts vulnerability research on medical devices and health care systems. She has also served as the CISO of Dow Jones and the CSO of Bloomberg LP, among other security posts.

@justinembone

Sophia d’Antoine

I’m the olympic CTF coach and we’re bringing the gold back from Tokyo.

@calaquendi44

Brandon Edwards

Brandon Edwards is a hacker, Summercon attendee and occasional speaker, who works on a team hacking and hardening Linux at Capsule8. He’s excited and honored to be involved in presenting this year, to be part of carrying Summercon onward through the pandemic.

@drraid

Nick Freeman

Nick is part of the Capsule8 research team, where he finds new and unusual ways to misuse (and detect misuse) of Linux systems.

@0x7674

The Labac Collective

LaBac is a hacker collective combatting tech-enabled abuse. LaBac serves on the NYC Cyber Sexual Assault Taskforce, a city-wide initiative dedicated to fighting online sexual exploitation. The LaBac collective curates the Museum of Modern Malware at DEFCON.

@labacdotdev

David Maynor

David Maynor leads the Centurylink Black Lotus Labs Analysis team. Mr. Maynor builds relationships with key organization and intelligence partners, proactively hunting for and disrupting advanced adversaries. Mr. Maynor is an entrepreneur and technical expert with over 20 years experience in research, systems, offensive consulting, and a variety of other security related positions in the private sector.

@Dave_Maynor

Katie Moussouris

Katie Moussouris is the founder and CEO of, Luta Security, a company specializing in creating robust vulnerability disclosure and bug bounty programs. Ms. Moussouris has testified as an expert on bug bounties and the labor market for security research for the US Senate, and has also been called upon for European Parliament hearings on dual-use technology. She created Microsoft’s and the Pentagon’s first bug bounty programs. She was later invited by the US State Department to help renegotiate the Wassenaar Arrangement, during which she successfully helped change the export control language to include technical exemptions for vulnerability disclosure and incident response. She is a coauthor of an economic research paper on the labor market for bugs, published as a book chapter by MIT Press in 2017, and presented on the first system dynamics model of the vulnerability economy and exploit market in 2015, as part of her academic work as a visiting scholar at MIT Sloan School. She is also an author and co-editor of standards ISO 29147 Vulnerability disclosure and ISO 30111 Vulnerability handling processes.

@k8em0

Ryan Naraine

Ryan Naraine is Director, Security Stratcy at Intel Corporation and host of Security Conversations, a podcast series featuring pioneers and newsmakers in the information security industry.

@ryanaraine

Suchi Pahi

Suchi Pahi is a data privacy and cybersecurity lawyer. She was supposed to be a doctor but instead wound up in law school arguing about the CFAA. After years of cybersecurity firefighting on behalf of clients at a law firm, Suchi is currently Director of Privacy and Business Affairs at Rally Health, Inc.

@suchipahi

Ian Roos

Security researcher at Margin Research.
Internally: screaming about security.
Externally screaming about security.
Eternal caffeine addict and literally ran out of coffee this morning.

@ian_roos

Elizabeth Wharton

Elizabeth (Liz) Wharton is a technology-focused business and public policy attorney who has advised researchers, startups, and policymakers at the federal, state, and local level. She is the Chief of Staff at SCYTHE as well as a member of the Technology & Innovation Council with Business Executives for National Security and a member of the DEFCON CFP Review Board. In addition to serving as the former technology attorney for the World’s Busiest Airport, she also hosted the “Buzz Off with Lawyer Liz” podcast.

@lawyerliz

COVID-19 Update

We tried to hold out as long as we could, but due to the realities of the COVID-19 pandemic and its impacts on our beloved New York City, there is simply no responsible way that we can squeeze everyone into Littlefield for Summercon 2020. (We also don’t expect state and local authorities to permit any gatherings of more than 50 people.) So we’re forced to pull the plug on our in-person event.

From a logistical perspective, this means that we’re working with EventBrite to issue full refunds to everyone who bought a ticket. You will see a refund in a few days. Thanks for being patient, and sorry it took us so long to initiate this process. We are, at heart, optimists, and thought we might be able to do this after all. We were wrong.

But just because we can’t be together doesn’t mean we can’t get together. We’ll be announcing details in the next few days of a grand, chaotic, true-to-our-roots virtual event. So even though the novel coronavirus doesn’t want us to come assemble in Brooklyn this year, we’ll still do something exciting, occasionally ridiculous, funny, weird, and memorable. In short, it will be Summercon.

It will also be free. Free (as in beer).

And then onto next year. Once the coast is clear, we’ are committed to gathering at Littlefield again, where we will think back to these profoundly weird times and remember just how insane it got in New York. Until that day, we’ll see you at Virtual Summercon 2020!

Dates for 2020!

We did it! We secured Littlefield for the next installation of Summercon, coming June 12-13, 2020. Get your tickets here

CFP NOW OPEN

The Summercon 2019 CFP is now officially open!

You can submit your proposals here but if you submit before Jan 15th, you can be eligible for a 2019 Summercon Grant. The grants are for $10,000 up front with the only condition being that you must present your research at Summercon in June 2019.

When making a submission, make sure under the “Is this submission for a 2019 grant?” section to select the option “Grant Eligible.” The deadline for submission is Jan 15, 2019.

MEET THE SPEAKER SELECTION COMMITTEE

We are delighted to announce the Summercon 2019 Speaker Selection Committee, chaired by Summercon alumnus Collin Mulliner. Collin has been a part of the Summercon family for years, and has presented on our stage three times (2012, 2013, 2015). He has been chairing the speaker selection process since Summercon 2018.

The full committee is:

  • Collin Mulliner, Chair
  • Nicole Becher
  • Sophia D’Antoine
  • Zach Lanier
  • Quiessence Phillips

Learn more about the people who make Summercon happen on the contact page.

WHAT MAKES A GREAT SUMMERCON PRESENTATION?

With the opening of the Summercon 2019 CFP, we thought we’d provide a few friendly tips for what we think makes a great Summercon presentation. These seven points represent the kinds of things that we are evaluating when we look at CFP proposals.

  1. Technical
    • While we occasionally incorporate talks of a non-technical nature, almost every presentation that shows up at Summercon is deeply technical. They’re not sales pitches, and they’re not about righting social wrongs. So if you’re planning on submitting a talk about why people should buy your company’s particular security snake oil, or why your company has the best culture (and you can too!), consider carefully that we’re not that kind of conference. Try somewhere else.
  2. Novel
    • From time to time, in the interest of getting important content in front of the best audience in the world, we let people present something they’ve already shown at events of lesser stature. But we prefer totally new presentations instead of rehashed talks. New content has a better chance of getting shown on the Summercon stage.
  3. Irreverant
    • While the presentations are technical, the way that successful presentations get their point across is through non-traditional means. This is not the place to read slides. One memorable presentation used an Android-shaped pinata as a prop. Another invited participation through an AA-meeting style format. The sky’s the limit ( within the limits of our code of conduct, of course).
  4. Revels in the Journey
    • If you like talking about the trials and tribulations of research, we are all ears. Even though your final results may be super polished and look effortless, everyone knows you had at least three major setbacks and went down two totally worthless paths before you arrived at a good solution. Share those. People love that, especially our speaker selection committee.
  5. Sticks it to The Man
    • Despite all the sponsorships, corporate attendance, and more buttoned-up nature of Summercon (see our Code of Conduct, which is totally reasonable, by the way), we are still, at heart, a hacker conference. Challenge authority. Show you’re not a patsy for The Man. Engages the Audience
  6. Engages the Audience
    • Summercon speakers are a special breed, because Summercon attendees are a special breed. Prepare to have people call out your mistakes, heckle if you’re less than prepared, and generally push your buttons. But successful presentations channel this misplaced audience enthusiasm. We still fondly recall a choose-your-own-adventure presentation, where randomly selected audience members got to dictate the direction of the talk. Engage your audience, and they won’t turn on you. (This can be good life advice, too.)
  7. Fits into the Allocated Time
    • We cannot overstate this: fill the time, generally 45 minutes of speaking with 10 minutes of Q&A. Our speaker selection committee has been around the block, so if you’re going to try to pretend that a six hour seminar fits into 55 minutes of speaking slot, it’s probably not going to get selected.

The Power of Funding Independent Research

Do you have an idea that will make an important contribution to the information security community? Some of the most important work ever presented at Summercon, through any of a zillion other conferences, journals, or whispered in mall food courts around the world, have been entirely self-funded, independent efforts.

Our Chairman Emeritus, Chris Valasek, has had a long history of doing independent work, and had an idea: what if Summercon could help fund this important vehicle for information security innovation?

After a major restructuring of Summercon, we are proud to announce the Summercon Research Grants Program.

Through our two funds-granting sponsors, Capsule8 and Trail of Bits, Summercon can help you realize your security research dreams. Apply today!

When making a submission, make sure under the “Is this submission for a 2019 grant?” section to select the option “Grant Eligible.” The deadline for submission is Jan 15, 2019.