Pages

Saturday, November 22, 2025

BSides Munich 2025 - On First Times

I've been to BSides Munich for the last three years, and it's been a pleasure each time. So while it wasn't my first time to attend the conference, there were other first times to be celebrated. It's been my first time giving a workshop at a security conference. It's been my first time as a session chair for speakers. It's been my first time that I've been together with the other half of my team at a conference. And for one of them it's even been their very first conference! That alone is already making my year. Especially as that specific teammate dove into the full experience, connecting with folks, joining a dinner group in the evening, exchanging experience. Just love it when good things happen.

 

Workshop Day

My day started out with meeting some known and new people on my way to the venue (we all ended up at a slightly wrong address at first, which was rather a connecting experience). On entering the (actual) building, there were more folks to greet. Some from other conferences, some from BSides Munich the last years. Grabbing a quick breakfast, it was time to start learning together.

In the morning, I joined the half day workshop "Cloud-Native Chaos: Hacking CI/CD and Cloud Environments" by Samuel Hopstock and Daniel Schwendner. This was a  really cool session and an actual workshop, fully hands-on and even exploratory! I know it's literally in the name of a "workshop", yet at times they end up as lectures instead of actual interactive hands-on learning sessions. So this was a really nice experience. We formed a group of three to tackle our task: given a practice app, gain full access to the Kubernetes cluster it's running on. The challenge was on! I loved that we had decent time to really try ourselves, not too many spoilers but help when needed. Perfect combination. I'm not going to spoil this workshop and the attack path we discovered, yet we could really make use of leftovers, misconfigurations, and oversights all the way. It was very interesting to see for myself how easy it can be to escape a Docker container to the host. It's different to know about it theoretically and to actually see it and especially to do it yourself. Another aha moment for me was to learn how to upgrade a non-interactive reverse shell to an interactive one - super useful for my next CTF sessions. 

After great conversations over lunch, it was time for the afternoon workshops. First, I joined "Developing Universal AI Agents for Static Code Analysis via MCP" by Sunil Kumar. My own workshop had been moved to a later slot and this one was the only session fitting in before. Good thing it was also on a topic I know I need to learn more about. Admittedly, I couldn't fully focus with my own workshop coming up right afterwards, yet it did showcase how MCP servers are built and configured, and demonstrated how they could be used afterwards. More to dive into for sure.

Then it was time for my own workshop "Secure Development Lifecycle Applied - How to Make Things a Bit More Secure than Yesterday Every Day". It was not set up for a good start - there was no break scheduled in between the two workshops, and people joining both definitely needed some time to breathe. To add to this, I learned about yet another scenario how things can go wrong when presenting. This time, the projector and my laptop both decided to connect shortly at first, but when I attempted to mirror the screen instead of extending it they said enough is enough - we're not working together any longer. Luckily, it's not my first rodeo so it didn't bother me (what a nice surprise to be calm for change), plus showing my screen was anyways only a nice bonus for my workshop. We found a quick solution, and once people were back from their break we could finally start. But well, that definitely cut as around 15min from the already short time. People told me afterwards they definitely wanted more time, it was flying for them! They had fun trying their hands on the exercises and there was more to explore. While some things are not in my hands, I'm taking this as a very positive signal.

Post by @lisihocke@mastodon.social
View on Mastodon

The workshops were done and yet not everyone was ready to call it a day. My dear CTF team Mireia Cano and Martin Schmidt, one of my colleagues and I all headed for dinner to extend the conversations and have a nice conclusion for the day. 

 

Conference Day

Already at the beginning of the day, I've met many familiar faces and we all prepared together for a busy day ahead full of talks, conversations and insights. Here are the sessions I attended.

For two of these talks, I've also had the honor to support as session host. I tried to find the speakers already beforehand, yet I didn't spot them in the crowd. This meant we could only check in shortly before their talk on what they needed regarding setup, timekeeping, introduction and so on. And then it was already on! Welcoming the audience to the room, having them seated, getting their attention, and having them cheer. Welcoming the speakers to the stage, getting them briefly introduced and then out of their way. During the talk, keeping track of time and signaling notes according to speaker needs. Afterwards, coordinating questions from the crowd, ensuring the program schedule can be maintained. Thanking the speakers, making sure they got what they needed. And a few more things, huge kudos to BSides Munich organizers for preparing a comprehensive cheat sheet upfront for session chairs! They also went the extra mile and prepared both bio notes for the speaker introduction as well as potential fallback questions for each talk in case the audience wasn't ready to engage. All this went pretty well. Once again I found myself in a situation where I was glad to have been doing public speaking engagements for so many years by now, and where the respective skills gained really pay off.

The additional challenge I had: how to do sketchnotes while also being a session chair? Well, I dared to go full in, and it did turn out to be pretty stressful. I also missed parts of the talks and my sketchnotes don't do them justice. But well, I learned that's part of doing sketchnotes anyways. There are constraints and you have to live with them. Whatever you have on paper in the end you have, whatever you didn't note you didn't. It's a perception and interpretation of the talk anyways and you just do what you can do in the specific moment. I also learned over the years that I'm doing this, that no matter whether I like how a specific sketchnote turned out or not, it might still help others and it's usually appreciated by speakers. So I'm sharing them anyways.

The conference day was over super fast, with the packed schedule and lots of conversations and also duties to fulfill. Also on this day, not everyone was ready to leave just yet and instead hang around and stayed for a while, still enjoying each other's company. 

Then it was time to join the organizers and my fellow speakers to go to the speakers dinner. We concluded the day with a really delicious meal among great people. We made new connections, we exchanged our favorite licorice products, conference venue struggles, insights on local security communities, and much more. As you do.

Thank you everyone for making this yet another great conference! Won't be my last BSides Munich for sure.

Post by @lisihocke@mastodon.social
View on Mastodon

No comments:

Post a Comment