PaulDotCom mailing list archives

How not to get pwned at Defcon


From: nberthaume at gmail.com (Nicholas B.)
Date: Tue, 14 Jul 2009 14:21:11 -0400

I an entirely read-only approach when on-site heres how I plan on
approaching it:

On my laptop if:
Disable hard drives in bios, change bootorder to optical media first
and only, set bios password, use my choice of live cd, disable
wireless and tether to my evdo adaptor via usb.

When accessing anything external from the laptop:
SSH out via public key with key from a thumb-drive that's set to read
only and has a pass-phrase protected key and tunnel to a trusted box
only with a pre-accepted and verified host key from the thumb drive.


Current thread: