Article count:16428 Read by:87919360

Hottest Technical Articles
Exclusive: A senior executive of NetEase Games was taken away for investigation due to corruption
OPPO is going global, and moving forward
It is reported that Xiaohongshu is testing to directly direct traffic to personal WeChat; Luckin Coffee is reported to enter the US and hit Starbucks with $2, but the official declined to comment; It is reported that JD Pay will be connected to Taobao and Tmall丨E-commerce Morning News
Yu Kai of Horizon Robotics stands at the historical crossroads of China's intelligent driving
Lei Jun: Don't be superstitious about BBA, domestic brands are rising in an all-round way; Big V angrily criticized Porsche 4S store recall "sexy operation": brainless and illegal; Renault returns to China and is building a research and development team
A single sentence from an overseas blogger caused an overseas product to become scrapped instantly. This is a painful lesson. Amazon, Walmart, etc. began to implement a no-return and refund policy. A "civil war" broke out between Temu's semi-hosted and fully-hosted services.
Tmall 3C home appliances double 11 explosion: brands and platforms rush to
Shareholders reveal the inside story of Huayun Data fraud: thousands of official seals were forged, and more than 3 billion yuan was defrauded; Musk was exposed to want 14 mothers and children to live in a secret family estate; Yang Yuanqing said that Lenovo had difficulty recruiting employees when it went overseas in the early days
The app is coming! Robin Li will give a keynote speech on November 12, and the poster reveals a huge amount of information
It is said that Zhong Shanshan asked the packaged water department to sign a "military order" and the entire department would be dismissed if the performance did not meet the standard; Ren Zhengfei said that it is still impossible to say that Huawei has survived; Bilibili reported that employees manipulated the lottery丨Leifeng Morning News
Account Entry

A story of a practitioner, dreaming back to Las Vegas

Latest update time:2017-08-05
    Reads:

Editor's note from Leifeng.com: As the two most famous hacker conferences in the world, Black Hat and Defcon are the top conferences that many security professionals aspire to attend.

Leiphone.com invited senior white hat Hu Zhonghong (ID: bobylive) to take us to the scene to find out. As a core member of Armyzer0 and the webmaster of Firefly, Hu Zhonghong went to the scene in 2010. This time, he went as a white hat who submitted a first-blood vulnerability to BSRC. He is currently focusing on the design of enterprise-level security architecture solutions and IoT security architecture solutions.

When spring has a perfect ending, midsummer is about to begin in the gardenia. Everything is just right in July. The city is like a child with a high fever. The sun is always unwilling to set above the head. The tail of spring is hidden in the moving green leaves. The streets are still filled with hot air. Everything seems familiar. Sitting on the plane to Las Vegas, the fields, villages and time are constantly flying in front of me. In a trance, it seems to have returned to the spiritual journey many years ago. This is the hands and feet of time, and the story of memories. I once again remembered what I once said: Why not give yourself one last chance, run towards the ideal that may never be reached, and die on the road.

So, I embarked on the path of spiritual practice again, and in the name of safety, I once again set out towards my ideal.

To many people, Las Vegas is a desert miracle full of decadence and debauchery. Many years ago, when I was still young, I also labeled this city as such. However, due to two important conferences, this city has a different meaning. They are Black Hat and Defcon, which are the top conferences that countless practitioners in the security field aspire to.

This city, filled with the smell of alcohol and money, has become mysterious again due to the arrival of pilgrims from the security industry around the world.

The fatigue of flying cannot erase the yearning in the hearts of the practitioners. When they set foot on this land, they are greeted not only by the hot air mixed with the smell of sand, but also by the ideal that is within reach. No matter how many years have passed, every practitioner who comes here is young, full of the pursuit of advanced technology, and all the footsteps are the melody of youthful enthusiasm.

For someone obsessed with top security technology, every visit is of great significance. Everything I see seems to have just been salvaged from the sediment of memory, familiar yet full of the old and dilapidated flavor of history. However, the topics of the conference are so fresh and shocking. Every person standing on the podium is a hero who dominates the security world for a while. Everyone's ideal is to become such a person. After picking up the luggage, you can see the shuttle bus provided by HP for the Black Hat conference when you walk out of the airport. The bus is full of practitioners who come here to "learn from the scriptures". Everyone is looking forward to the most cutting-edge and top security technology. Because we are all learners, we had a great conversation during the period.

After getting on the car, we set off for the hotel where we were staying - Bellagio.

Bellagio, also known as Bellagio, is a high-end hotel, casino and shopping mall under the MGM Group. Facing the hotel is an artificial lake, so Bellagio is also the only resort hotel in the area with a large fountain. The fountain of Bellagio Hotel can be seen in any movie involving the gambling city.

Right above the hotel lobby is the famous stained glass ceiling, created by the famous artist Daru Zhiguli. Each glass flower is blown by hand, and it is a continuous piece, which is very spectacular.

It was already dark when we met the beautiful lady Garfield from Baidu Security BSRC. After running around for nearly a whole day, everyone looked a little tired, so we didn't plan our itinerary and prepared to go out for dinner.

As soon as we left the hotel, we caught up with a beautiful and spectacular musical fountain show. We stopped for a while to watch it. The hotel was brightly lit in the night, the streets were bustling and lively, the cheers of tourists and the hawking of merchants were in our ears, and the spectacular fountain also relieved a lot of fatigue.

After a casual walk, we had an authentic American fried chicken and French fries at a nearby restaurant. Although the local food is not as rich as that in China, it is also quite flavorful. The seemingly simple fried chicken is tender inside and crispy outside, which is plain and sophisticated. After the meal, everyone chatted together and discussed the schedule of the next few days' meeting. There were also some other high-sounding talks, which was very pleasant.

Due to the long journey, the group said goodbye after returning to the hotel, ending the simple itinerary of the first day.

The next day, everyone got up early and went to the main venue of Black Hat, Mandalay Bay Hotel. The hotel is located in the south of Las Vegas and is remote, so the group took a car to go there.

The hotel has the best swimming pool and artificial beach in Las Vegas. The magnificent exterior is a completely different world inside. Probably no one would have thought that such a place is the palace that countless people who seek safety seekers yearn for.

The venue was not difficult to find. After entering the hotel and following the crowd for about 2 minutes, we arrived at the entrance of the main venue of Black Hat. When we saw the familiar banners, everyone was filled with excitement. It is the dream of every security practitioner to be able to communicate with many top security experts in the industry. It can not only broaden your horizons, but also improve your own technical level.

I roughly looked through the conference agenda manual, which covers security issues in many fields such as Web security, smart cars, IoT, industrial control systems, etc. In recent years, topics such as IoT have frequently appeared at the conference. Black Hat is known as the temple of the security industry, and it must have its outstanding features. It has won this honor precisely because it can present high-quality topics that keep pace with the times.

Photography was not allowed at the conference venue, so we put away our equipment and started listening to the topic. We chose an industrial control system security topic. Currently, the domestic industrial control security architecture is still very immature and not highly concerned. Even in developed countries, it is still in the development stage and is not very popular.

In the security research in recent years, I have transformed from the initial research on Web security and client security to security architecture design and security solution design. I hope to learn from the experience of industrial control security experts from the topics, and then explore a more mature and reliable industrial control security architecture.

The topic detailed major industrial control security incidents in history, such as Stuxnet, Black Energy and other viruses that destroyed national energy infrastructure. The topic was very interesting because the speaker focused on how to perceive this type of network attack, and how to alert and protect against it, and boldly speculated on future attack methods and trends.

In my opinion, the security industry is developing gradually in constant confrontation. While we are researching new attack methods, we are also learning new defense methods. The two complement each other. Where there is attack, there must be defense. Therefore, such a comprehensive and multi-faceted analysis topic is very beneficial.

After the topic, the group went to the first floor to visit the exhibition hall of security vendors. Many world-renowned security vendors displayed their leading technologies, such as Cisco's ETA traffic analysis technology, RSA's identity authentication management technology, etc. It can be said that "a hundred flowers bloom" and it was eye-catching.

Before I knew it, the busy and exciting day was over. I dragged my tired body back to the hotel, but my brain was still excitedly replaying the day's scenes. I fell asleep with full expectations, ready to greet the arrival of tomorrow.

To be continued



Latest articles about

Database "Suicide Squad" 
Exclusive: Yin Shiming takes over as President of Google Cloud China 
After more than 150 days in space, the US astronaut has become thin and has a cone-shaped face. NASA insists that she is safe and healthy; it is reported that the general manager of marketing of NetEase Games has resigned but has not lost contact; Yuanhang Automobile has reduced salaries and laid off employees, and delayed salary payments 
Exclusive: Google Cloud China's top executive Li Kongyuan may leave, former Microsoft executive Shen Bin is expected to take over 
Tiktok's daily transaction volume is growing very slowly, far behind Temu; Amazon employees exposed that they work overtime without compensation; Trump's tariff proposal may cause a surge in the prices of imported goods in the United States 
OpenAI's 7-year security veteran and Chinese executive officially announced his resignation and may return to China; Yan Shuicheng resigned as the president of Kunlun Wanwei Research Institute; ByteDance's self-developed video generation model is open for use丨AI Intelligence Bureau 
Seven Swordsmen 
A 39-year-old man died suddenly while working after working 41 hours of overtime in 8 days. The company involved: It is a labor dispatch company; NetEase Games executives were taken away for investigation due to corruption; ByteDance does not encourage employees to call each other "brother" or "sister" 
The competition pressure on Douyin products is getting bigger and bigger, and the original hot-selling routines are no longer effective; scalpers are frantically making money across borders, and Pop Mart has become the code for wealth; Chinese has become the highest-paid foreign language in Mexico丨Overseas Morning News 
ByteDance has launched internal testing of Doubao, officially entering the field of AI video generation; Trump's return may be beneficial to the development of AI; Taobao upgrades its AI product "Business Manager" to help Double Eleven丨AI Intelligence Bureau 

 
EEWorld WeChat Subscription

 
EEWorld WeChat Service Number

 
AutoDevelopers

About Us Customer Service Contact Information Datasheet Sitemap LatestNews

Room 1530, Zhongguancun MOOC Times Building,Block B, 18 Zhongguancun Street, Haidian District,Beijing, China Tel:(010)82350740 Postcode:100190

Copyright © 2005-2024 EEWORLD.com.cn, Inc. All rights reserved 京ICP证060456号 京ICP备10001474号-1 电信业务审批[2006]字第258号函 京公网安备 11010802033920号