My friend Scott pointed out the towels in most hotels now have RFID tags to help with inventory control:

I also knew that my RSA Conference badge would have an RFID tag in it so it could be scanned on the expo floor:

Since I never leave home without my Proxmark3 in my assault pack it was time to get to work:

What I found out next is something I wasn’t expecting that made this whole thing a lot more interesting.
Using the Proxmark I was able to tell the hotel towel and my RSA tag uses the same MIFARE Ultralight C tags:

So from there I was able to clone my RSA pass to my hotel towel since the towel had a re-writeable tag.
I will be demoing the walkthrough of this at First in Amsterdam in April.
So now I am at the point where you can scan my towel and get the same UID. Which will allow me to have people scan my towel and get the same information they would have gotten off my badge.
Which allows me to quote one of my favorite lines from the Hitchhikers Guide.

*No hotel towels have been permanently harmed and will be returned to my room with the correct UID rewritten to them.
Blog Posts
The FBI has recently sued Apple to make them unlock the iphone of the San Bernardino Shooter (Here is Apple’s response.).
The reason Apple needs help is because the phone has “Erase All Data After 10 Failed Passcode Attempts” turned on. Without that feature the government would have just built this robot to brute force the password and this wouldnt have been an issue:

What this means for the general public is that we now know that the FBI can not bypass this setting so if you care about your privacy you should enable it.
Doing so is fairly easy:
Settings > Touch ID & Passcodes > Erase Data > Enable.

While this is a “dangerous” setting getting the phone to actually erase the data is actually pretty hard. You have to wait through the following timeouts so that your toddler (or a malicious jerk) will not accidently erase your phone:

You get used to seeing this screen a lot:

After the 10th attempt this happens:
I have been meaning to pick up a Proxmark3 for the last couple of months to round out my RFID testing kit (while waiting for the chameleon mini to be released this summer).
The problem is that most of the known suppliers are selling the Proxmark3 for around $420. I then found that Elechouse has their internal version of the Proxmark3 V2 for only $200 ($220 with a battery to make it truly portable).
So of course I ordered and built one:

Building it was fairly simple and Chris Merrett has an awesome github package put together to make installing it on OSX painless.
Once built and tested cloning HID Prox Cards (which open most corporate doors) is this easy:

I am really looking forward to getting this out into the wild and showing people why they shouldn’t trust their door locks at their business or in their hotel room.
Crashsafari.com is a website that overloads the browser with a self-generating text string which populates the address bar. After about 20 seconds or so it will force an iPhone to reboot, while significantly heating it up as the smartphone tries to handle the code of the site.
The code of the website appears to generate an ever-increasing string of characters, which becomes harder and harder for the browser to load, likely resulting in a memory issue and forcing the reboot of the device.
I pulled the source of the website broke it down to its smallest operable part and put it here (dont be a jerk).
I have been to Top Golf for 3 different events this year and was always amazed by their RFID technology and have always left wondering “What is in a Top Golf golfball?”.
So when I saw a few “Top Golf” golf balls in the $1 ball bin at a golf store I bought them and decided to answer that question.

That little “passive EPC Gen 2 ultrahigh-frequency (UHF) RFID” tag is what makes TopGolf so awesome. Now all I need to do is invest in a UHF RFID reader to see what is actually on the tag.
Protip: Sawing a golf ball in half is a lot harder than it sounds.
I have become more and more interested in hardware security lately and while I have been having a lot of fun learning about RFID Security I knew the next logical step would be to try to learn how to use a software-defined radio.
After doing a lot of reading and research over the last couple of weeks I came to learn that the best way to learn SDR is with a ~$20 HD DVB-T from Realtek called the RTL2832U.
The RTL-SDR blog sells an “upgraded” RTL-SDR on Amazon for $25 that I picked up and really like.

Some of the projects I have started to explore include:
Tracking Airplanes Using Dump1090:

Decoding and Tracking TPMS:

RTLSDR-Scanner for general scanning:

I have a lot more to learn with this setup but I can easily see that this will quickly turn me into dropping a few hundred dollars into a HackRF so that I can transmit as well as receive.
At the start of every month I pick a quote I like and hang it at my desk and try to use it to guide my thought process for the month and I thought I would share them here as I was cleaning off my desk for the year.
Here are the quotes I used in 2015:
January:
There is nothing more deceptive than an obvious fact.
– Doyle
February:
Never confuse movement with action.
– Hemingway
March:
You must either modify your dreams or magnify your skills.
– Jim Rohn
April:
Courage is grace under pressure.
– Hemingway
May:
The most formidable weapon against errors of every kind is reason.
– Thomas Paine
June:
If I panic, everyone else panics.
– Kobe Bryant
July:
Take time to deliberate, but when the time for action has arrived, stop thinking and go in.
– Napoleon
August:
I shouldn’t be near Vegas and have money in my pocket.
-Adam Sandler
(Let’s just say I had a lot of fun at BSides, Blackhat and Defcon this year.)
September:
If you ask me anything I don’t know, I’m not going to answer.
– Yogi Berra
October:
Everything we hear is an opinion, not a fact. Everything we see is a perspective, not the truth.
– Marcus Aurelius
November:
In any moment of decision, the best thing you can do is the right thing. The next best thing is the wrong thing. The worst thing you can do is nothing.
– Theodore Roosevelt
December:
Have a strategic plan. It’s called doing things.
– Herb Kelleher
…and yes I know doing this now apparently makes me dumb.
From time to time I have the need to test or verify a web application vulnerability through the TOR network using BurpSuite. The easiest way to do this to use the pre-bundled TOR Browser.
Configuration is fairly easy:
- Download, Install and Start the TOR Browser:

- Verify that the SOCKS proxy is started on 127.0.0.1:9150

- Configure Burp (Options > Connections > Upstream Proxy Servers)

- Then…

(Legally with proper permission of course!)
Pro Tips:
TorBrowser has to stay running while using Burp.
Verify the Proxy is still active if you have to restart Burp.
The TOR network runs slow sometimes.
Some web hosts block TOR traffic.
Dry clean only.
Last month I got a new iPhone. This month I realized I forgot my Xbox One password when I tried to log in to download some Games With Gold.
I didnt think this would be a problem. I forget and rest passwords all the time.
So I go through the normal steps and have it send me an email:

Then I get this screen:

Did I mention I got a new phone? When you get a new phone the authenticator app resets and you have to add back your account so I click I dont know.

I have to take responsibility for this. I didn’t save a recovery code on my mac so I click no and I get this screen:

This is where this goes off the rails for me. 30 days To reset my Xbox account because I enabled 2FA?
So I call Xbox support and Jacqueline says there is nothing they can do and I have to wait until January to reset my account password.
How does this make any sense? Without 2FA I could have reset my password in 30 seconds with no problem but since I enabled it I wont be able to use my Xbox for a month?
Microsoft couldn’t text me a one time password, or give me a call or email an alternative email? Someone decided 30 days was the right answer?
Microsoft you are doing account management wrong. If you need me I will be buying a PS4.
UPDATE: After 2 hours and 43 minutes on the phone and zero help from any Microsoft staff I was able to find out that you can get a new recovery code for 2FA on the actual XBoxOne console:

After I did that I was able to reset my password and disable 2FA.
On Wednesday night I tweeted this:
If you are using TrueCrypt you should stop. Hashcat is now optimized to crack TrueCrypt volumes. https://t.co/voBdtKuuHW
— Jerry Gamblin (@JGamblin) December 10, 2015
I started getting retweets and replies like this on Friday from people I respect (and a bunch from people I don’t know):
@JGamblin this is a non sequitur. there are valid reasons to stop using TC, but Hashcat isn't one of them.
— Kyle Maxwell (@kylemaxwell) December 11, 2015
https://twitter.com/averagesecguy/status/674768017864134657
So people REALLY like TrueCrypt or I didn’t make my point articulately enough. In case I didnt make my point well enough I will try to lay it out here.
3 Reasons Why I Think You Should Stop Using TrueCrypt:
The developer stopped maintaining it, took down the webpage and replaced it with this.
“WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues“.

I think that this reason should be more than enough to get 99% of people to stop using it.
The latest version of HashCat includes support for TrueCrypt volumes.
If you are using good passphrases (most people don’t) it really isnt a big deal but it does lower the level of complexity for hacking a TrueCrypt volume with a weak password from a medium-high skill level (Think Security Professional) to downloading kali and following instructions (Think Help Desk Analyst).
The developer stopped maintaining it, took down the webpage and replaced it with this.
“WARNING: Using TrueCrypt is not secure as it may contain unfixed security issues“.

There are many other open source and paid alternatives that you can evaluate and pick the best one for you. So unless you have an amazingly valid reason to not move off of TrueCrypt you should move off it as soon as possible.