I made it to #HackGlasgow this year. I had a ticket for the first one last year, but life got in the way and I think I had to spend the day watching the kids. This time I won the calendar war and got this scheduled in early.
First let me thank the organisers/volunteers, venue (Citizens Theatre), and Bucks Bar for dinner.
The event was like someone asked me what I would want and then someone else did all the work! I am not kidding. I used to go into Bucks Bar when I ran an office in Glasgow round the corner from it regularly because the food is great.
The chosen charity was even Refuweegee. I once entered the Glasgow 10k for them many many moons and two better knees ago. I think they are also absolutely cracking.
I was delighted that several people recognised me even though I haven’t left the house to get to anything like this since COVID. I think in the timeline of stuff I was at the final DC44141 at Glasgow Caledonian University in March 2020. I did a talk about SQL injection a few days before the first COVID lockdown and that was it. Glasgow Defcon did not return after this. In the void has risen Hack Thursday and this is all entirely marvellous.
I am delighted to meet people even though I suffer from chronic not knowing names (even when I ask) and as I have gotten older even more chronic forgetting faces. Even more humbled by people coming up thanking me for being part of their origin stories in some way, and hearing they are now 6 or more years into their careers doing wonderful things. Keep being kind everyone.
Let’s talk about the talks
Redlining the SOC: the need for speed in cyber defense

Gabrielle Hempel made some good points about the problem is not that you need to buy “more shit”. Y’all have enough shit. Stop buying more shit to stack next to the shit that you have already! I grabbed some – probably rough – quotes that I am gonna riff with from this.
“Alerts gathering dust is the issue” – absolutely vital point. The shit you have can detect and raise alerts but these days you have the alert fatigue problem combined with the deluge of potential information which it is hard to triage. When the dwell time was 41 minutes for an incident in the anecdote then a better UI or marginally faster query time in the shit you own to solve this problem is really not going to matter materially to that timeline.
“Assume access” – We still come up against clients mocking the very idea of giving a penetration tester/Redteamer credentials with which to do their testing. “Ha, I thought we paid you to impress us by you getting a password!”. No, you are paying us to do a scope and time limited job where we give you as many recommendations as possible. A pure blackbox pentest is how people did things circa 2005 and really it does not prove very much at all other than you have likely wasted the first day getting an initial foothold instead of getting tangible results from the minute the job started.
Looping back into what Gabby was saying here no threat actor lands into a network without having SOME kind of access. The phishing attack lands on a workstation with the privileges of Betty in accounting. The scenario without any access is when an attacker walks into a building and connects their computer to the network. But this is far less likely than Betty opening a malicious spreadsheet. So. No longer assume you are secure. Assume the threat actor has access at some level and let’s go from there.
“Not IF, when. So prevention should not be your only plan” – absolutely PREACH sister.
“+89% AI enabled adversary activity” – this is the trend.
“AI doesn’t need PERFECT attacks, just cheap ones” – we meat bags might be slow but we are probably trying surgical attacks.
“More attempts, more variables, and less time between attempts.” – the AI threat actors are throwing spam and ham to make omelettes. But eventually they make a salad and all the criminals needed was something to eat for lunch.
“Detect BEHAVIOUR, not INDICATORS” – again this is the huge shift that is occurring. Why is Betty in accounts suddenly working after 8pm when she never worked past 6pm before? Why is she suddenly using PowerShell?
“Automate CONFIDENCE, not SEVERITY” – in the defensive workflow data enrichment of alerts should happen at each stage which meaningfully improve the next part of the pipeline making a decision. Ultimately you are trying to get confidence that the alert is a threat to allow triage.
Scientific Hooliganism: the history of hacking

Liam Follin (gr4y-r0se) with a gloriously wide definition of hacking:
“Subverting the rules of a system, to force the system to behave in a way that its creator did not intend“
Was able to go back thousands of years to records for activities that we would be able to identify are relevant to various hacking service line.
Talking about a grave robber in ancient Egypt and how they overcame tomb security. I’d argue this one does have parallels to physical security testing but also that the definition does not really match does it? The system was the door of the tomb and the robber didn’t so much “subvert” it as smash the damn thing down with copper tools! That aside I do see that the bro was just shimming doors for fun and profit. Even if I wouldn’t be overly keen to hang around with a grave robber lol.
“Hiding a flaw protects the criminal, not the public” – Alfred Charles Hobbs – baller quote that and completely relevant to ethical disclosure now.
Overall a lovely talk about the history of hacking.
The Era of the Self-Propagating Cloud Worm: Dissecting the “Shai-Hulud” Campaigns

Scott McCracken delivered an excellent talk about a worm. I would encourage shortening the title though! How about just “Shai-Hulud the self-propagating cloud worm”.
Supply chain attacks are in vogue these days. This one worked by abusing pre-install scripts used in the node ecosystem. It stole all secrets from any repository the user had access to and even setup reverse shells from the workstations of developers who had been stung by it.
I loved it. All of this reminded me that in a previous life and all the way back in 2018 I did a talk about hacking with git. This was pre GitHub actions and stuff but I was already abusing systems with Git. Had I done this talk 1 year later I may have accidentally told the world how to write Shai-Hulud!
Shai-Hulud absolutely automated the hell out of everything and did it with ruthlessness.
The Hunted Becomes the Hunter: Catching Red Teamers and Pentesters and Spotting Adversarial Patterns

Alex Close & Andy Gill. Another long title lads, could literally be “Spotting Adversarial Patterns” haha. This was one of the more fun talks. Mainly because Andy’s mouth moves faster than the rest of him and ends up with endearingly weird statements at times.
Some excellent points were made. Nice to have the two perspectives.
Farewell Windows 10, glory to Linux! A tragedy in 2 acts

Marie Dubremetz (Helen of Troy). This talk was a real joy because of the theatre of it in particular. I wanted to talk to her after to really ask about the drama side of it. Come on Marie tell me if you were in stage shows?
A very fair point that Windows continues to bloat with each release. That the system requirements keep going up and up but what does the user get from this? If you were to audit how I work today on Windows 11. I will tell you that I typically use the exact same tools that I use today as I did when I started my career with Windows XP in 2005. I would imagine this is true for most professions. That most users just want to access their email, edit some documents/spreadsheets, then have a web browser.
As Marie said, almost nothing added into Windows since XP has materially improved my life. That changes are done via “Forced Integration” i.e. without user consent or desires being taken into account at all. Or as I would put it later at the after party:
“WHYYYY. WHYYYY. WHYYY would you make the search field on the start bar search the goddamn Internet! Why would you do that? There is absolutely no situation in my life where I want to be searching for ‘Add or Remove programs’ and get driven to the Internet? When we wanted notepad.exe to have tabs for like 30 years they eventually did that but baked Co-Pilot into it at the same time? WHY?”
This is an abomination!

The point about how forced obsolescence is driving up e-waste and costs for literally every organisation is also completely valid. Her stat that computers used to have an 11 year lifetime in most organisations and now that is about 3.5 years is absolutely shocking. Completely alarming, given the fact we are already living with the effects of climate change and that other than to serve Microsoft’s profits there is no good reason for forcing so many upgrades.
To a certain degree Marie was absolutely preaching to the choir here. That particular audience is basically all wanting everyone to adopt Linux for everything anyway.
Thought provoking, and excellent presentation.
Fireball Won’t Fix This

Ryan Standbridge.
I need an adult. This young man bullied me and made me do things I was uncomfortable with.
I have often wanted to give D & D a go because I am probably just the kind of nerd for this shit. I don’t know because until this workshop I had never done so.
Anyway I was sort of co-CISO in the scenario which I took really seriously by being on the Golf Course leaving the CFO to deal with everything haha.
That was it.
General Socialising
I am pretty dreadful with names, as I said. I loved chatting to various people with a particularly excellent conversation about Altered Carbon being a highlight. If the booky person sees this you absolutely know who you are and that was lovely!
Had lunch with three fellows out of the venue at the pizza/burger place outside. I couldn’t face the lunch queue and a few other like minds arrived after me.
Lovely to meet Robin, Cary, Miguel and more again. They is good people.
I tried to put a drink in the hand of anyone who spoke or did the whose slide is it anyway thingy at the after party but I’d estimate about 50% success at that. But it did pay out some good chats and that was alright by me.
Over all an excellent day and very much worth it.
I would have loved talking about the drama, catch me next time ;). Never worked in theater but I have taken cabaret courses in Paris in a past life with a dancer from the Crazy Horse. I also did a lot of improv and finally the format is inspired from traditional french 18th century dramas (Corneilles, Racine, Molière…) which I thought was perfect format to convey in a non boring way both the technical facts and the feelings of our community around them. Hope to be able to give this performance again! Anyway thank you for reporting the conference and the talk, let’s hope giving visibility to this subject shows that we, engineers, computer, scientists, hackers, do care about forced obsolescence and that our screams can be heard above. It is great that the #hackglasgow team leaves space to these topics in an original format. The organisers have made sure I had all the info needed to make the show and answer quickly to my questions. Thanks them for that. Thank you as well for adding your example about notepad and search. It adds to microsofts list of crimes. I may use them in future talks, if you agree…
Life is a cabaret! Thanks for finding this and taking the time to reply. Trained or not you had the plan and executed it with confidence!
Talks can be significantly improved with a small amount of theatre and that venue is an actual theatre! Seems mad not to.
I am already thinking about doing a talk next year. My primary thought to add some drama was to light a cigarette on stage. That would actually be genuinely shocking to see a lit cigrarette indoors in Scotland since it was banned in 2005. The bulk of the audience would never have seen a cigarette lit in doors in their entire life.
I thought there was a clause to allow artists to do it on stage so as not to compromise the authenticity of the work. Since I’d be authoring the “work” I could set a slide in the 1990s or something. But.. It turns out that Scottish law does not make the exception for stage performances. In English law (a different legal system) they do.
Getting a fake prop cigarette that is acceptable legally would still be as shocking at the distance to the audience. Then explaining the whole situation would be equally funny. Keeps people awake if you do about a minutes worth of something weird.
Hi!
Thanks Darren who took the time to find my email and reach out to tell there was your article !
I have definitely seen at least one cigaret lit up on stage, it was in France in 2006 (cig was not even banned from inside restaurants yet) for a production at the local publicly subsidized theater. The cig was used by the main character in the dark, all lights off, to make some pattern dancing on the tune of the music “daddy cool”. It is surprising how the incandescent cig could make such effect in the total black on stage.
I would not be surprised if cigarets were still tolerated today in france. I suspect no one would care enough anyway to make a case? Would they in scotland?
I had a different dilemma as to wether or not do all this staging given that I am a woman and that I technically remove clothes on stage. The conclusion of the reflexion was: as long as it genuinely participates to the content delivered that shall not be detrimental to my reputation. In my case I thought since the point of my talk is: microsoft behaves like a Trojan Horse then no one can argue Helen of Troy is not a propos. I imagined it as a more funny way to remind what my talk is about than just living the title of my prensentation as a footnote in the slides. So far so good the critics always seemed positive.
I tested a the staging. In front of family member first who could immediately spot there was a problem with the rythm: originally the play did not start with the poem but transitioned with it which made it difficult to introduce. They could confirm also at early stage if it was a good idea or not.
May I ask what purpose the cig serves? You want to give a nostalgic feeling to the talk? Set it in the 90’s era? Skip the question if you want to keep a surprise.
Marie.
Interesting. Yea it felt natural to the plot and had you just walked out dressed fully like Helen of Troy that would also have been fine but more dramatic the way you did it.
The cigaratte… Well. Currently I have no talk planned. The technical would be whatever I am into at the time. What function it would serve would be to do something stupid at the start or a few minutes in. To bond the audience in laughter and to know it is completely ok to do so. Also because I thought I legally could when I had the idea and I thought it would be funny to just use that law unexpectedly since it isn’t “theatre” its a talk. Being hackers it felt particularly good to be using a law in an unintended way but… It is just straight illegal in Scotland.
It was something along the lines of Gene Wilder’s idea: https://www.youtube.com/shorts/BUX3Hz_SZKw
To date the best bit of staging I have done was to tell people there was no recording of a particular talk at G3C conference. Nobody could take photos because we were talking about real incidents that if you had a bit more time you could probably work out who the customer was. The event organiser knew about that and came out to remind people it couldn’t be recorded or photos taken before I came out. Then about 10 minutes from the end of the talk I pointed up to the back row and said “That guy’s taking Photos!”. Then I stormed out taking the microphone off dramatically picked up my stuff and left. The organisers did not know about this bit and so reacted appropriately to try and stop me all completely in panic.
Then as I got out the door I hit the next slide button and it played a video I had pre-recorded with me calling myself unprofessional. Before finishing the talk pre-recorded. Along with an outtro song showing photos taken during the various places I had to travel to for work. All the unglamorous towns and things like delayed flights, trains, bad breakfasts, bad lunches, lonely dinners etc. The bit of penetration testing that nobody talks about. The song was “Always look on the bright side of life” and then an audience technically gave applause to an empty stage before they left.
Then at the after party so many people thought it was them I pointed at, or that they had seen someone taking photos etc. The organiser forgave me and thought it was funny and I still get people bringing it up like 8 years on.
I like your reference to Gene Wilder catching the full attention of the audience right from the beginning in his case.
Do you watch a lot of stage shows in general? I watch a lot of theatre, musicals. The UK has such amazing venues. But it is above all from burlesque that I get my inspiration. Everything is about teasing the audience in clever ways. Your mise-en-scène was funny! I wish I had seen it. I also find the showing of the bad and unglamorous sides very relatable as an academic and researcher. The unpleasantness of the professional travel we do when we need to sell our publications at conferences. It feels really human to have done that, thank you.
You have a different approach and it is inspiring. I would have been scared that the video doesn’t start or the sound doesn’t come out. How did you make it start? Did you have a clicker or something? That must have taken a lot of work, putting together the video, recording yourself (I guess several times, the first take is never the right one). Everything needs to be tested and re-tested! On my side, I had made a rough draft of this talk 6 months ago for an in-house seminar. And then throughout the semester I added ideas and props recycled from my attic. I wrote the last verses a fortnight before, booked my Eurotunnel and kept reciting the poems over and over while on my hiking holiday in the Glasgow area. I was so panicked at the idea of forgetting my text! There was also all the gestures and slides to sync and not forget. I wanted the lyrics to follow what I am doing, and of course, English not being my mother tongue, I had to struggle with my brain inserting grammatical mistakes.
Most people did not get my cow’rin, tim’rous BSD reference… never mind! Did you? I was surprised how people laughed at the Trojan horse slide and vocally expressed their strong emotions pro-Clippit and anti-Windows 8. HackGlasgow sounds like a very expressive and friendly audience! I do not know if it is specific to Glasgow, or to hack communities.
One of my objectives is to give this talk at as many places as possible throughout this year. While Microsoft keeps postponing the ESU, the end of Windows 10 is still relevant and is a pivotal point where most people can take the opportunity to avoid the friction of switching to Windows 11 and move to Linux instead.