What you will learn
- Why validating input and output is so critical
- Why authentication isn't the same as authorisation and where it often goes wrong
- and... er... which smart adult toys not to use
Session Speakers
Ken Munro
Partner – Pen Test Partners, UK
IoT security is something of a conundrum. The team at Pen Test Partners publish independent research in to the security of numerous smart devices, exposing poor security practice by device manufacturers. Sadly, it’s often consumers that are the victims of this inattention to security.
Ken looks after vulnerability disclosure at Pen Test Partners and influences government policy on IoT cyber security. Whilst some disclosures are successful, the majority are a train wreck. Watching vendors try to ignore contact from researchers, fumble or try to silence the process led him to working with regulators in an effort to fix the problems at source. He considers carrot and stick are the only way to resolve smart product security.
The work of his team on My Friend Cayla, the vulnerable talking kids doll, was cited as one of the catalysts for California Senate Bill 327, regulating IoT security for California residents. He’s briefed US government departments and spoken at TEDx, DEF CON villages, RSA, Black Hat, BSides and numerous other security events. If you want his attention, just market your smart device as ‘unhackable’. Ken is also a member of the CVE Board.
Session Co-Speaker
Jo Dalton
Associate Partner – Pen Test Partners, UK
Jo has worked in Cyber Security for over 15 years and has co-ordinated thousands of assurance and testing projects with clients around the globe. Jo can easily translate areas of serious business risk into relatable topics, while demonstrating how they can be reduced or avoided. From the challenges of the unregulated IoT market to the dangers of remote working on trains; Jo has an informed opinion. Jo speaks publicly; and blogs on various channels on the wider issues of SCADA and ICS Risks, Security Awareness, IoT Security, Cyber Security involving Children and Family. She has spoken at a range of events e.g. EEMUA Industrial Cyber Security Seminar, IP EXPO Manchester, and StocExpo Europe.
Stay in the Loop
We want to ensure you never miss important announcements, updates and special offers from EuroSTAR.