Disabling Encryption to Access Confidential Data

BSidesLV 2018

Presented by: Christopher Simon Hanlon
Date: Wednesday August 08, 2018
Time: 15:30 - 15:55
Location: Proving Ground

For many years, remote Access Systems, Medical Records Systems, SSL Certificate Generation and many other systems rely email for authentication.This presentation explains how to well known weaknesses in opportunistic email encryption can be used toCompromise accountsHijack computersGenerate fraudulent SSL CertificatesAccess confidential medical/financial records.Intercept, hijack, and modify https sessions.Capture bank credentialsPerform social engineering / fraud

Christopher Simon Hanlon


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats