If you're interested, most people would agree that when you connect to a defcon wifi network you should probably be... cautious. Let's face it, Defcon is to RSA from an info-risk pov as walking in downtown NY at 1am is to walking around the North/South Korean DMZ at 1am. Both are hazardous, but one of them is just plain insane.

Now watch this:

That's the 'so what'.

And keep in mind that most ppl are still using the same passwords on multiple sites.



The issue is, that's not my call. I'm a professional, I travel to the US on business. In doing so, I bring data that is not mine with me. Corporate emails, credentials that could cause a CNN moment if mishandled, etc.

Those data are stored under cryptographic control, using two factor authentication. It is not mine to decide if it's acceptable to hand it over to anyone.

So now I need to take further steps to ensure I have access to the data required when I travel internationally to my corporate HQ, which increases the cost of doing business.

My company will never move their HQ out of the US, but others may decide at some point that it'll cost them less in the long run.


Also the caps on penalties are more reasonable here, making the "Pay us 5000, or we'll sue you for 1,000,000" threat ineffective. The max for non-commercial infringement up here is 5k. Since that's the max, in most circumstances, the judge would prove a much lower cost, say 100-200$.

Quoting directly: "(b) in a sum of not less than $100 and not more than $5,000 that the court considers just, with respect to all infringements involved in the proceedings for all works or other subject-matter, if the infringements are for non-commercial purposes."

The copyright trolls haven't been too interested since then.

background if you're interested:

Honest question - how does he (and you I suppose by extension) feel about Libraries. They effectively cause the same issue for authors at a smaller scale (although maybe larger in aggregate, (not having firm numbers on ebook piracy rates vs traditional library use), especially since some libraries (my local included) offer ebook borrowing services.

After I got nailed making a left shortly after getting my license, I started thinking about left-turns and how much more dangerous they are then right turns. There's so many more things to account for, and more chances for other people to make errors that force me to take hazardous countermeasures. A NYC study showed they are 3 times more dangerous then right hand turns. So now unless doing the right would take me way out of my way, I do that instead.

Remember, two wrongs don't make a right, but three rights make a left :)


The one that always got me was the RSA booth at Blackhat - I mean, Blackhat is in VEGAS. If you want that sort of thing, you can get it with fewer lines any number of places. But one year they had people lining up to pose with women dressed in biker costumes at the RSA booth.

Seemed a little bit like bringing icecubes to Alaska.


I don't know. There's precedent.

In every subway station in my town there's a big red button that kills all power to the rails. Hitting that button would be a major PITA for everyone, but yet, it sits there, red and inviting, and somehow humans manage NOT to press the red button, years of D&D evidence to the country notwithstanding.

Humans can be trusted with (limited) power.

I vote we don't terminate all of them. We should keep at least 7 as historical landmarks.

I wear an android watch so that I have a "Hey, look at your phone" or "Hey, get to your next meeting" reminder that's not disruptive. The fact that my time is on my wrist is a nice side effect, but mostly it avoids me having to take my phone out of my pocket in social and business situations where it would be disruptive or frowned upon.

Looking at your watch is a LOT more socially acceptable in certain circumstances then pulling your phone out.

