Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Security conferences versus practical knowledge
Don Parker, 2007-07-18

Since computers became mainstream in the early to mid-nineties a whole ecosystem has developed around them, in order to maintain that humble computer. The various parts of that ecosystem range from the companies who make computers to the software companies who program for them.

Comments Mode:
Security conferences versus practical knowledge 2007-07-19
Anonymous
I think you have missed the point of a security conference. There are tons of ways that a Windows admin can attain knowledge on how to maintain there network. Many training company's focus on just this type of training and many Universities now offer this type of education.

A security conference like Black Hat for example, tends to draw people who are think outside of the box with the application. They are looking at how hackers, crackers or attackers are breaking to application. What new attack vectors are being exploited, new tools used, new 0-days being released etc.

When I first started attending Blackhat 4 years ago I was lost. But, it pointed me in a direction to help me better focus my research and learning. Now, when I attend a talk, I can follow along, and gain tons of knowledge that helps me evaluate risk of new vulnerabilities. You see, being able to see someone exploit a hole in something and have them explain how it works helps me understand the relevance of a threat to my infrastructure.

Remember that theoretical attacks soon become practical attacks vectors and the time that they become tooled up is rapidly dereasing. 10 years ago many of these attacks could only be performed by an leet crew of hackers. Now, with tools like metasploit (which was released at Blackhat) it is becoming easier to pwn systems.

My opinion is that your paper really missed the mark. More people should attend these conferences so they can see just how easy these attacks are to perform and understand there relevance. Maybe then, company's will spend more on training our admins and engineers in security awareness, and risk management.

My 2 cents.

Tim Wright

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/columns/449/34627#34627
Why I go to security conferences 2007-07-20
Anonymous







 

Privacy Statement
Copyright 2008, SecurityFocus