We are proud to announce that after lots of work we are adding a new capability to our IoT Testing portafolio: 2G. With our new cellular network we have full visibility of Voice, SMS and Data transmitted using this technology.

IoT 2G Attack surface

Until now, our clients had to trust the device manufacturers on what what was being transmitted over the 2G interface or perform a full source code analysis. By using our own cellular network in an EMF shielded room or tent, SevenShift now has control of the 2G network, allowing us to see and attack all communications.

SevenShift 2G Network equipment

 

 

Why 2G, in a world where many other faster protocols are available?

Costs are an important factor in IoT, especially consumer IoT, where the manufacturers try to keep the unit cost as low as possible. This allows them to reduce the price on the devices and of course increase their margin.
The initial cost of the modem / communication modules have a great weight in this area, for example we found this pricing overview here, which illustrates the point:

 

SigFox (TD1207R) LoRaWAN (RN2483)
2G
(u-blox SARA G350)
3G
(u-blox SARA U270)
WiFi
(Cypress BCM43362)
11,00 €
12,43 €
11,56 €
29,18 €
10,48 €

 

As you can see, using a 3G modem more than doubles the price of a 2G modem.
The table above is by no means up to date and will vary depending on the manufacturer and unit count, but it gives us a good idea.

What can we do with the new 2G capabilities?

We are now in the position to perform all the tests we are used to perform for other IP based technologies:

  • Create an accurate communication matrix of the device: with whom, why and how it communicates with.
  • Perform Man in the Middle (MiTM) attacks
  • Verify correct use of encryption, including correct usage and validation of SSL / TLS certificates
  • Attack the device via the 2G interface
  • Emulate any GSM network and observe the behavior
  • And much more…

If you want to book 2G tests for your devices, contact us now.

In the dynamic and constantly evolving world of IT, one has to keep learning in order to stay on top of things and remain relevant within their niche. So, it is not a question about whether you should keep honing your skills, but rather, how to go about it.

When it comes to sharpening your skills the quick and easy way, you have the option of attending either conferences or training courses. But aren’t they one and the same thing? Not at all! This article will explain the differences between conferences and training courses, and how each could benefit you.

 

Large conference

What is a Conference?

This is a congregation of like-minded individuals in a profession where they gather to share their opinions and views on a wide array of topics. The atmosphere is typically formal, and the place chosen to be the venue needs to have visual aids in addition to accommodation facilities since conferences may spill over a couple of days. During the conference, experts of the chosen subject are invited to share their knowledge. The participants are also given a chance to do the same. The goal of a conference is to share knowledge.

Characteristics of Conferences

  • Many Opinions and Topics

A conference usually covers a broad range of topics which allows you to choose the ones that are most relevant to you. This ensures that you get to spend your time constructively.

  • Big Picture

Due to the wide range of topics covered in a conference, it might not be possible to get detailed information on each topic. However, you get to see the bigger picture as you will have a good overview of what is happening in the industry. This means you will leave with a lot to look into.

  • Hearing from the Experts

Conferences are where you are most likely to find your industry’s thought-leaders and opinion shapers. They are there to let you in on the latest developments plus what to look out for.

  • You Get to Understand the Industry

Conferences are one of the best ways of getting to meet new people and strengthening your network. There are a lot of networking opportunities in a conference, such as during session breaks and lunch, where you can leave with a few LinkedIn connections.

Additionally, most conferences have exhibitors and sponsors. Thus, if you are in need of new solutions or suppliers, a conference is an excellent place of finding these people and getting special offers.

Who Can Benefit Most from a Conference?

If you are relatively new to an industry, conferences are an excellent way of getting to know what the industry is all about while meeting up with people who are in the same situation as yourself.

You will also get to be updated on the latest happenings in the industry, and what to anticipate. And since they are knowledge sharing platforms, you will become more knowledgeable about your niche.

What are Training Courses?

These are short-term educational training courses that are designed to enhance the participants’ skills in a specific profession or field, where advancements in techniques force individuals to upgrade their skills. Trainings usually comprise of a small group of people, who have come to benefit from experts’ knowledge. They are a type of interactive training where the participants embark on a number of training activities instead of just passively listening to a lecture.

Characteristics of Trainings

  • In-depth and Focused

Trainings tend to major on a singular topic rather than attempt to have an overview of multiple topics. Thus, the training will be much more detailed.

  • Hands-on

Trainings tend to be more practical than other kinds of events. They include group discussions, exercises, and other practical activities that will require you get your hands dirty, so you can implement what you are learning.

  • Small Groups

Due to the specific nature of the training, groups are typically small. This means that each participant is likely to get individualized attention, in addition to being able to communicate with the speaker(s) on a one-on-one basis.

  • Like-minded Individuals

The people you will be training with will be facing the same challenges as yourself. This will allow you to share the experience with each other and form valuable connections.

  • Certification

Most trainings offer a certificate after the course. Thus, they are a good way to boost your accreditations.

Who Benefits the Most from Trainings?

Trainings are good for anyone who wants to learn a particular subject in detail. It enables an individual to be more proficient in their field or niche.

So, which one should you go for: Conferences or Training Courses?

Due to their different purposes, they benefit different individuals. Conferences are good for anyone looking to gather more insight into their industry so as to be aware of what they need to know or do to be ahead in their respective fields. Training Course, however, are for people looking to enhance their skills in a particular subject which will help them gain an edge in the employee marketplace. Thus, a training is excellent for anyone looking to advance their career.

What is SevenShift?

SevenShift is a boutique security consulting firm with a wealth of experience in the worlds of security and Internet of Things (IoT). Our experts have tested numerous IoT devices and Ecosystems over the last couple of years. Our experience in security testing, design, and implementation has helped us provide security solutions for many organizations. Through our hands-on training methods, we help companies to better secure their business and products.

Some of our trainings include:

• IoT Security Bootcamp

This is an IoT hacking class designed for professionals who have an understanding of hacking and IT. It is a 5-day class that covers all the aspects of the Internet of Things’ (IoT) security. Each module begins by first covering the basics before getting into the actual subject. This allows you to understand what things can be hacked, why and how. You will learn by hacking real devices and will be guided by experienced and highly proficient teachers.

In this training, you will first review the architecture of IoT ecosystems and devices, assess their attack surface, test for vulnerabilities, and then hack them.

• IoT Security Compact Bootcamp

This IoT hacking class is designed for pentesters and security experts. It is a 3-day, fast paced class that covers the following topics: IoT devices, cloud, wireless technology such as ZigBee and BLE, radio and mobile components, hardware and software debugging, firmware reverse engineering, and binary exploitation using both standard and unconventional attacks.

• IoT Security Manager Training

With the Internet of Things being one of the biggest digital trends of the century, there is a demand for highly trained and capable managers, who will incorporate this technology into their product strategy. This training will impart you with a high-level understanding of the innovation, implementation, and maintenance of security in this field.

As we get closer to a world where the Internet of Things will dictate our day to day lives, it is imperative that IT professionals are well equipped to handle the potential cyber security threats that may arise. It is estimated that there will be about 20.8 billion interconnected devices, which will generate over 20 zettabytes of data by 2020.

This is why IT experts and business owners should undergo the specific training to ensure they are ready for any cyber security issues to protect their entities.

Visit our training page to book your training now or to learn more about our programs.