Mindset Over Skill Set: Got
Hacker Mindset? Testing IoT
Security Shouldn’t Fear You
Santhosh Tuppad
sh-3.2# whoami
I have been a great liar, a thief, physical
infrastructure breaker, web application hacker,
mobile apps hacker, kiosk machine basher, black-hat
hacker, white-hat hacker, trainer, security coach and
blah blah blah!
Why I don’t fear testing anything for
“SECURITY”?
#CORRELATION
Before being a hacker, I experimented and
correlated my experimentation journey to
hacking.
#InternetOf(every)thing
- Connecting the devices like toaster,
toothbrush, refrigerator, lights etc. with each
other in order to establish communication &
perform dangerously insane things.
Things are going to get WORSE. Future is not so cool
considering the risks about 80 billion smart devices by
2025.
#WouldYouBeOkay
Would you be okay if your car speed is controlled by
malicious hacker?
Would you be okay to send heart rate data of your
baby incorrectly to physician? (Man In the Middle)
Would you be okay if someone takes control of your
CCTVs or Cameras installed in your home?
Would you be okay if...
#LearnFromExistingStories
https://github.com/nebgnahz/awesome-iot-hacks
These may scare you!
#ToThinkLikeACriminalIsNotACrime
Practice thinking like a criminal…
Practice more…
Practice MORE...
#MyOpinionForMyself #WebOpensTheDoors
#CloseTheDoorsIfNotRequired
Learn web hacking to understand IoT hacking
better… And then correlate… And identify
specific attacks for IoT hardware/software
ONLY… And Rock!
#MindsetRules #SecurityIsAFeeling
• Disable unnecessary ports on hardware interface.
• Web UI interface to IoT infrastructure is your start.
• Mobile interface? Well, I love *.apk files.
• Insecure hardware/firmware.
• Poorly configured settings. #Question
• Stronger encryption. But, make sure “key” is kept
safe.
• Let the clouds not thunder and rain.
• Test ports are not meant to be in production
• Logging and Alerts.
• Privacy concerns? #GDPR
• Physical Security - People seldom remember this.
#ChoiceIsOurs
There are more black-hat hackers than
white-hat hackers.
We have massive skill shortage.
We care about our generation & upcoming
generations.
Choice is yours… I hope malicious hackers don’t
make a choice for you with IoT hacking.
Disclaimer: If I get more great votes, it doesn’t
mean I hacked the feedback system and voted
for myself. I am a good person.
If you liked my talk, please vote for me at,
#V193
slido.com

More Related Content

PDF
Cyber safety
PPTX
ethical hacking
PPTX
Internet Issues (How to Deal on Internet Security)
PPTX
Ethical hacking and cyber security intro
PPT
the best hacking ppt
PDF
The History of Hacking in 5minutes (for dummie)
PPTX
CYBER ETHICS, CRIMES AND SAFTY
PPT
Ethical hacking presentation
Cyber safety
ethical hacking
Internet Issues (How to Deal on Internet Security)
Ethical hacking and cyber security intro
the best hacking ppt
The History of Hacking in 5minutes (for dummie)
CYBER ETHICS, CRIMES AND SAFTY
Ethical hacking presentation

What's hot (20)

PPSX
Cyber security awareness for students
PPTX
Ethical Hacking & Network Security
PDF
Ethical hacking & Information Security
PPTX
Internet security powerpoint
PPTX
Hacking ppt
PPTX
Ethical hacking
PPTX
National information security education & awareness program
PPT
Cyber Security and Cyber Awareness
PDF
Cyber security awareness presentation nepal
PPTX
presentation on ethical hacking
PPTX
Internet security
PPT
NewIinternet security
PDF
National Life IT Department's Cyber Security Awareness Presentation
PPT
Ethical Hacking and Network Security
PDF
Cyber Security Awareness at Dadar April 25, 2010
ODP
Cyber security awareness
PPTX
Hacking ppt
PPTX
Hacking and Hackers
PPTX
How to hack or what is ethical hacking
Cyber security awareness for students
Ethical Hacking & Network Security
Ethical hacking & Information Security
Internet security powerpoint
Hacking ppt
Ethical hacking
National information security education & awareness program
Cyber Security and Cyber Awareness
Cyber security awareness presentation nepal
presentation on ethical hacking
Internet security
NewIinternet security
National Life IT Department's Cyber Security Awareness Presentation
Ethical Hacking and Network Security
Cyber Security Awareness at Dadar April 25, 2010
Cyber security awareness
Hacking ppt
Hacking and Hackers
How to hack or what is ethical hacking

Similar to Testing IoT Security shouldn't fear you if you have got a hacker mindset - By Santhosh Tuppad - For RTC 2018 (20)

PDF
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)
PPTX
Spirent: The Internet of Things: The Expanded Security Perimeter
PPTX
IoT Cyber+Physical+Social Engineering Attack Security (v0.1.6 / sep2020)
PDF
IoT, Security & the Path to a Solution
PPTX
IoT Security Risks and Challenges
PDF
Hack one iot device, break them all!
PDF
How to Secure IoT Devices_A Guide for Ethical Hackers
PDF
IoT – Breaking Bad
PPTX
Emerging Trends in Cybersecurity by Amar Prusty
PDF
This Time, It’s Personal: Why Security and the IoT Is Different
PPTX
IoT security
PPTX
Domain 7 of CEH Mobile Platform, IoT, and OT Hacking.pptx
PDF
Cybersecurity in the Age of IoT - Skillmine
PPTX
IoT Security: Debunking the "We Aren't THAT Connected" Myth
PDF
逃避可恥還沒有用- 你不可不知的物聯網安全問題與挑戰(Ashley Shen & Belinda Lai)
PDF
IoT Attack Surfaces -- DEFCON 2015
PPTX
Security Testing for IoT Systems
PDF
A History of IIoT Cyber-Attacks & Checklist for Implementing Security [Infogr...
PPTX
Iot Security, Internet of Things
PPTX
IoT Security, Threats and Challenges By V.P.Prabhakaran
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)
Spirent: The Internet of Things: The Expanded Security Perimeter
IoT Cyber+Physical+Social Engineering Attack Security (v0.1.6 / sep2020)
IoT, Security & the Path to a Solution
IoT Security Risks and Challenges
Hack one iot device, break them all!
How to Secure IoT Devices_A Guide for Ethical Hackers
IoT – Breaking Bad
Emerging Trends in Cybersecurity by Amar Prusty
This Time, It’s Personal: Why Security and the IoT Is Different
IoT security
Domain 7 of CEH Mobile Platform, IoT, and OT Hacking.pptx
Cybersecurity in the Age of IoT - Skillmine
IoT Security: Debunking the "We Aren't THAT Connected" Myth
逃避可恥還沒有用- 你不可不知的物聯網安全問題與挑戰(Ashley Shen & Belinda Lai)
IoT Attack Surfaces -- DEFCON 2015
Security Testing for IoT Systems
A History of IIoT Cyber-Attacks & Checklist for Implementing Security [Infogr...
Iot Security, Internet of Things
IoT Security, Threats and Challenges By V.P.Prabhakaran

More from Santhosh Tuppad (13)

PDF
Tools are my servants. and I am the master - By Santhosh Tuppad
PDF
Hacking - Bridging the Gap And Going Beyond to Fight Black-Hat
PDF
Web and mobile security workshop workbook v1 - by santhosh tuppad
PDF
ExpoQA 2018 - Why software security has gotten worse? And what can we do abou...
PDF
The BUZZ Word - Entrepreneur. A Perspective of Santhosh Tuppad
PDF
Agile Testing Days Tutorial (Germany) 2017 - Web and Mobile Security Testing...
PDF
Your users are humans and let's live our promise of securing them
PDF
Test ideas for Login / Authentication and Login Session
PDF
Passion is a free spirit, only you can cage it.
PDF
Software Testing - Heuristics Cheat Sheet
PDF
Santhosh tuppad romanian testing conference 2017 - keynote presentation
PDF
Santhosh Tuppad - Profile - Entrepreneur - Software Tester - Ethical Hacker -...
PDF
Santhosh tuppad - A journey that is fascinating and will be more fascinating ...
Tools are my servants. and I am the master - By Santhosh Tuppad
Hacking - Bridging the Gap And Going Beyond to Fight Black-Hat
Web and mobile security workshop workbook v1 - by santhosh tuppad
ExpoQA 2018 - Why software security has gotten worse? And what can we do abou...
The BUZZ Word - Entrepreneur. A Perspective of Santhosh Tuppad
Agile Testing Days Tutorial (Germany) 2017 - Web and Mobile Security Testing...
Your users are humans and let's live our promise of securing them
Test ideas for Login / Authentication and Login Session
Passion is a free spirit, only you can cage it.
Software Testing - Heuristics Cheat Sheet
Santhosh tuppad romanian testing conference 2017 - keynote presentation
Santhosh Tuppad - Profile - Entrepreneur - Software Tester - Ethical Hacker -...
Santhosh tuppad - A journey that is fascinating and will be more fascinating ...

Recently uploaded (20)

PDF
The influence of sentiment analysis in enhancing early warning system model f...
PPTX
Final SEM Unit 1 for mit wpu at pune .pptx
PPTX
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
PDF
Comparative analysis of machine learning models for fake news detection in so...
PDF
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
Credit Without Borders: AI and Financial Inclusion in Bangladesh
PDF
Improvisation in detection of pomegranate leaf disease using transfer learni...
PDF
OpenACC and Open Hackathons Monthly Highlights July 2025
PDF
A review of recent deep learning applications in wood surface defect identifi...
PPTX
Modernising the Digital Integration Hub
PDF
STKI Israel Market Study 2025 version august
PPTX
Custom Battery Pack Design Considerations for Performance and Safety
PPTX
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
PDF
CloudStack 4.21: First Look Webinar slides
PDF
Five Habits of High-Impact Board Members
PDF
A proposed approach for plagiarism detection in Myanmar Unicode text
PPT
What is a Computer? Input Devices /output devices
PDF
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
PPTX
TEXTILE technology diploma scope and career opportunities
The influence of sentiment analysis in enhancing early warning system model f...
Final SEM Unit 1 for mit wpu at pune .pptx
GROUP4NURSINGINFORMATICSREPORT-2 PRESENTATION
Comparative analysis of machine learning models for fake news detection in so...
Hybrid horned lizard optimization algorithm-aquila optimizer for DC motor
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
Credit Without Borders: AI and Financial Inclusion in Bangladesh
Improvisation in detection of pomegranate leaf disease using transfer learni...
OpenACC and Open Hackathons Monthly Highlights July 2025
A review of recent deep learning applications in wood surface defect identifi...
Modernising the Digital Integration Hub
STKI Israel Market Study 2025 version august
Custom Battery Pack Design Considerations for Performance and Safety
AI IN MARKETING- PRESENTED BY ANWAR KABIR 1st June 2025.pptx
CloudStack 4.21: First Look Webinar slides
Five Habits of High-Impact Board Members
A proposed approach for plagiarism detection in Myanmar Unicode text
What is a Computer? Input Devices /output devices
How ambidextrous entrepreneurial leaders react to the artificial intelligence...
TEXTILE technology diploma scope and career opportunities

Testing IoT Security shouldn't fear you if you have got a hacker mindset - By Santhosh Tuppad - For RTC 2018

  • 1. Mindset Over Skill Set: Got Hacker Mindset? Testing IoT Security Shouldn’t Fear You Santhosh Tuppad
  • 2. sh-3.2# whoami I have been a great liar, a thief, physical infrastructure breaker, web application hacker, mobile apps hacker, kiosk machine basher, black-hat hacker, white-hat hacker, trainer, security coach and blah blah blah!
  • 3. Why I don’t fear testing anything for “SECURITY”?
  • 4. #CORRELATION Before being a hacker, I experimented and correlated my experimentation journey to hacking.
  • 5. #InternetOf(every)thing - Connecting the devices like toaster, toothbrush, refrigerator, lights etc. with each other in order to establish communication & perform dangerously insane things.
  • 6. Things are going to get WORSE. Future is not so cool considering the risks about 80 billion smart devices by 2025.
  • 7. #WouldYouBeOkay Would you be okay if your car speed is controlled by malicious hacker? Would you be okay to send heart rate data of your baby incorrectly to physician? (Man In the Middle) Would you be okay if someone takes control of your CCTVs or Cameras installed in your home? Would you be okay if...
  • 9. #ToThinkLikeACriminalIsNotACrime Practice thinking like a criminal… Practice more… Practice MORE...
  • 10. #MyOpinionForMyself #WebOpensTheDoors #CloseTheDoorsIfNotRequired Learn web hacking to understand IoT hacking better… And then correlate… And identify specific attacks for IoT hardware/software ONLY… And Rock!
  • 11. #MindsetRules #SecurityIsAFeeling • Disable unnecessary ports on hardware interface. • Web UI interface to IoT infrastructure is your start. • Mobile interface? Well, I love *.apk files. • Insecure hardware/firmware. • Poorly configured settings. #Question • Stronger encryption. But, make sure “key” is kept safe. • Let the clouds not thunder and rain. • Test ports are not meant to be in production • Logging and Alerts. • Privacy concerns? #GDPR • Physical Security - People seldom remember this.
  • 12. #ChoiceIsOurs There are more black-hat hackers than white-hat hackers. We have massive skill shortage. We care about our generation & upcoming generations. Choice is yours… I hope malicious hackers don’t make a choice for you with IoT hacking.
  • 13. Disclaimer: If I get more great votes, it doesn’t mean I hacked the feedback system and voted for myself. I am a good person. If you liked my talk, please vote for me at, #V193 slido.com