<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.csclub.uwaterloo.ca/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Yd2dong</id>
	<title>CSCWiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.csclub.uwaterloo.ca/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Yd2dong"/>
	<link rel="alternate" type="text/html" href="https://wiki.csclub.uwaterloo.ca/Special:Contributions/Yd2dong"/>
	<updated>2026-04-09T08:56:40Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.44.0</generator>
	<entry>
		<id>https://wiki.csclub.uwaterloo.ca/index.php?title=Security_Workshops&amp;diff=3495</id>
		<title>Security Workshops</title>
		<link rel="alternate" type="text/html" href="https://wiki.csclub.uwaterloo.ca/index.php?title=Security_Workshops&amp;diff=3495"/>
		<updated>2013-09-26T15:01:28Z</updated>

		<summary type="html">&lt;p&gt;Yd2dong: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In light of the orwellian nightmare we&#039;ve built ourselves into, now is a good time for the CSClub to pick up the slack it usually picks and teach people how to be safe out there. &lt;br /&gt;
&lt;br /&gt;
=Topics, and slides=&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This information is fuzzy and subject to change. Do not trust it.&lt;br /&gt;
&lt;br /&gt;
sharvey, m4, and nguenthe are adminning this term&#039;s series&lt;br /&gt;
&lt;br /&gt;
Though the topics are diverse, the ones we will favour actually running are seminars that are short, to the point, and give a specific skill(set).&lt;br /&gt;
&lt;br /&gt;
Note: might be worth organizing this better by theme -sharvey&lt;br /&gt;
&lt;br /&gt;
* sharvey on &#039;&#039;Why Should You Care About Security and Privacy&#039;&#039; &lt;br /&gt;
* ?????? on &#039;&#039;Storytime: Snowden Roundup&#039;&#039; (sharvey might be able to get some people from CrySP to discuss this; perhaps a panel followed by a Q&amp;amp;A?)&lt;br /&gt;
* ?????? on &#039;&#039;Storytime: [http://en.wikipedia.org/wiki/Weev Weev]&#039;&#039;&lt;br /&gt;
* ?????? on &#039;&#039;Storytime: Kevin Mitnick&#039;&#039;&lt;br /&gt;
* nguenthe on &#039;&#039;[http://www.cypherpunks.ca/otr OTR]&#039;&#039; -- or IanG if we can get him!&lt;br /&gt;
* ?????? on &#039;&#039;Time Machines&#039;&#039; (Google-hacking, pleaserobme.com, etc)&lt;br /&gt;
* ?????? on &#039;&#039;Security Proofs: How Many Joules does the NSA Have?&#039;&#039;&lt;br /&gt;
* ?????? on &#039;&#039;Full Disk Encryption&#039;&#039; (zablache maybe)&lt;br /&gt;
* ?????? on &#039;&#039;SSH&#039;&#039;&lt;br /&gt;
* [mailto:stephen.palmateer@gmail.com Stephen Palmateer] of KWLUG on &#039;&#039;Tor&#039;&#039; (vs i2p vs Freenet vs /r/darknet?)&lt;br /&gt;
* yd2dong on &#039;&#039;Tunnelling, Mix Networks, and VPNs&#039;&#039; -- he&#039;s done original research on this area, would discuss censorship techniques (for example, DPI filters), how to defeat them, and significant additional hurdles for anti-censorship compared to simply protecting against eavesdropping. (live demos of blocking from China)&lt;br /&gt;
* ?????? on &#039;&#039;Your Wifi Network is Insecure&#039;&#039; (cover: aircrack-ng and reaver. maybe nmap and metasploit)&lt;br /&gt;
* [mailto:silver@callysto.com Sean Howard] on &#039;&#039;How your ISP owns you&#039;&#039; (UW grad, ex Watsfic president, currently working for sentex.ca, knows details of Bell&#039;s network infrastructure and where the chokepoints are)&lt;br /&gt;
* [http://cybersecurityinstitute.ca/ The Canadian Cybersecurity Institute] on &#039;&#039;Social Exploits&#039;&#039; (this person is via Sean Howard. Seems legit.)&lt;br /&gt;
* nablack and sjcglads with a security demo + open ended question session&lt;br /&gt;
* sjcglads on &#039;&#039;Secrets of a DDoS&#039;&#039;&lt;br /&gt;
* wlritchi on &#039;&#039;Reversing SBeam and pnwing ur phone&#039;&#039;&lt;br /&gt;
* mtrberzi on &#039;&#039;GPG, Keyservers, and You&#039;&#039; and with a keysigning party to boot&lt;br /&gt;
* v2buterin on &#039;&#039;Bitcoin and Bitmessage&#039;&#039; (maybe? pretty please?)&lt;br /&gt;
* IST Security:&lt;br /&gt;
** [mailto:pmatlock@uwaterloo.ca Patrick Matlock] on some combination or subset of oauth, identity, data privacy ([https://uwaterloo.ca/secretariat/policies-procedures-guidelines/policy-8 Policy 8]), and web pentesting&lt;br /&gt;
*** csrf&lt;br /&gt;
*** script injections&lt;br /&gt;
*** ....&lt;br /&gt;
** [mailto:tlabach@uwaterloo.ca Terry Labach] on [http://ist.uwaterloo.ca/~tlabach/safer/ safer web browsing]&lt;br /&gt;
** [mailto:cpbell@uwaterloo.ca Colin Bell]?&lt;br /&gt;
* Sapphyre?&lt;br /&gt;
* Hatguy!&lt;br /&gt;
* ?????? on &#039;&#039;Passwords&#039;&#039; (touch on [http://xkcd.com/936/ security proofs], hashapass/pwdhash, alternatives to passwords (biometrics, one time pads, challenge-response, ssh keys), NOT SHARING YOUR DAMN PASSWORDS ACROSS SITES (cite: the ps3 attack, the [linkedin attack], the [http://techcrunch.com/2009/12/14/rockyou-hack-security-myspace-facebook-passwords/ rockyou attack] ([http://www.tomshardware.com/news/imperva-rockyou-most-common-passwords,9486.html super] [http://reusablesec.blogspot.ca/2010/01/more-analysis-of-rockyou-password-list.html interesting] [http://blog.jimmyr.com/Password_analysis_of_databases_that_were_hacked_28_2009.php analysis], myspace&#039;s hack, FaithWriters, purerave.com&#039;s attempt at better security that made it worse, the ....) and how to use jacktheripper/[http://hashcat.net/hashcat/ hashcat])&lt;br /&gt;
* ?????? on &#039;&#039;Browser Fingerprinting&#039;&#039;&lt;br /&gt;
* ?????? on &#039;&#039;Filesystem Forensics and the Dangers of Log-Structured Data Storage&#039;&#039; (live demo!) (zablache maybe)&lt;br /&gt;
* ?????? on &#039;&#039;SSL: It&#039;s Broken&#039;&#039;&lt;br /&gt;
* ?????? on &#039;&#039;Storytime: Exporting &amp;quot;Munitions&amp;quot;&#039;&#039;&lt;br /&gt;
* ?????? on &#039;&#039;Stegonography&#039;&#039; (might be able to get sharvey&#039;s SO to cover this)&lt;br /&gt;
* ?????? on &#039;&#039;Digital Watermarks&#039;&#039;&lt;br /&gt;
* ?????? on &#039;&#039;Getting root in 5 minutes with physical access&#039;&#039; (cover how to boot single-user in all versions of Windows, OS X, Linux, and when that fails how to pull a drive and crack the password with l0phtcrack (Win32) or simply editing /etc/shadow (*nix). also the [https://citp.princeton.edu/research/memory/ compressed air-&amp;gt;frozen RAM] and Firewire-DMA attacks)&lt;br /&gt;
* ?????? on &#039;&#039;What is Identity&#039;&#039; (maybe toss this out to WPIRG?) with info on how sites and overlords (facebook, google) identify you, and how to split your identity digitally&lt;br /&gt;
* ?????? on &#039;&#039;Physical Security&#039;&#039; ([http://lockwiki.com/index.php/Main_Page locks], safes, etc.)&lt;br /&gt;
* ?????? on &#039;&#039;Crypto: terms, definitions, and why software still sucks&#039;&#039;&lt;br /&gt;
* ?????? on &#039;&#039;Entropy and Randomness and why you shouldn&#039;t trust your router&#039;&#039;&lt;br /&gt;
* ?????? on &#039;&#039;Network things&#039;&#039; (ARP, DNS, etc.)&lt;br /&gt;
* ?????? on &#039;&#039;Side Channels&#039;&#039; (sharvey&#039;s SO will probably do this)&lt;br /&gt;
&lt;br /&gt;
And remember kids, &#039;&#039;&#039;&#039;&#039;educational-use only&#039;&#039;&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
=WPIRG cross promotion=&lt;br /&gt;
&lt;br /&gt;
[http://wpirg.org WPIRG] wants to cross-promote a &amp;quot;privacy forum&amp;quot; with us. They are imagining as an expert panel + QA session, during November. Probably the ideal distribution is csc events on the technical side (&amp;quot;how to shot pgp&amp;quot;, &amp;quot;how to make tls go&amp;quot;, &amp;quot;wat is passwurd&amp;quot;) with WPIRG on the human-scale and politics side, with advertising to both of our cohorts for all events. Some ideas for expert participants:&lt;br /&gt;
* [https://cs.uwaterloo.ca/~iang/ Ian Goldberg] (sharvey)&lt;br /&gt;
* [http://www.michaelgeist.ca/tags/privacy Michael Geist]&lt;br /&gt;
* ????&lt;br /&gt;
* Terry Labach (this sort of thing is, actually, directly within his job description)&lt;br /&gt;
* [http://thoughtcrime.org Marlie Moxinspike]&lt;br /&gt;
* UofT Citizen Lab People&lt;br /&gt;
&lt;br /&gt;
=Related work and Telling Evidence=&lt;br /&gt;
&lt;br /&gt;
====Related Work====&lt;br /&gt;
[https://ssd.eff.org/ EFF&#039;s Surveillance Self-Defense Guide]&lt;br /&gt;
&lt;br /&gt;
[https://www.encrypteverything.ca/ Pirate Party&#039;s EncryptEverything]&lt;br /&gt;
&lt;br /&gt;
https://citizenlab.org/ @ UofT&lt;br /&gt;
&lt;br /&gt;
[http://cm.bell-labs.com/who/ken/trust.html Ken Thompson - Reflections on Trusting Trust]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.jbonneau.com/publications.html&lt;br /&gt;
&lt;br /&gt;
====Evidence====&lt;br /&gt;
http://readwrite.com/2010/08/04/google_ceo_schmidt_people_arent_ready_for_the_tech&lt;br /&gt;
&lt;br /&gt;
====IMPORTANT MEDIA====&lt;br /&gt;
3 Dead Trolls in a Baggie - The Privacy Song&lt;br /&gt;
MC Frontalot - Secrets from the Future&lt;br /&gt;
&lt;br /&gt;
[http://www.xkcd.com/538/ XKCD: Security]&lt;br /&gt;
[http://xkcd.com/936/ XKCD: Password Strength]&lt;br /&gt;
&lt;br /&gt;
=Past by Term=&lt;br /&gt;
===Fall 2013===&lt;br /&gt;
...&lt;/div&gt;</summary>
		<author><name>Yd2dong</name></author>
	</entry>
</feed>