Showing posts with label speaking. Show all posts
Showing posts with label speaking. Show all posts

Monday, July 20, 2026

OWASP Global AppSec EU 2026 - Achievement Unlocked

When Mireia Cano and I received the confirmation that our paired talk "Security Champions: Lessons from Opposite Trenches" was accepted at one of the largest OWASP events, the OWASP Global AppSec EU conference, we were speechless. This was too good to be true! We knew the journey there would be very stressful, given the short time left from getting accepted to the conference taking place, and given our lives already had super busy plans for us. And yet, we simply couldn't resist. We fought our way through and overcame every hurdle on the way. We knew why we did it and it was worth it in the end. And Mireia, I'm truly grateful you pulled through together with me! Would we repeat this very stressful experience? Most likely not! But this time, it worked out even better than we hoped for. Here's how the conference went overall.

 


Welcome to Vienna

Vienna was this year's location for the conference which used to move across Europe, and it seems OWASP will stay there for a few years. For me it was a great opportunity to visit the city which isn't that far away from home yet I've never been there.

So I've visited Vienna for the first time, exactly during a period Europe faced an extreme heat wave. The city was burning hot and I was extremely happy that the hotel I chose had working air conditioning and was in walking distance from the conference venue.

Mireia arrived a bit later, and once settled in, we used the time for practicing our talk. I mean, how else could it be. Paired talks are extremely tricky to get right and done well if you don't want to simply patch two half-talks done by two different people in two different styles together and hope for the best. (Nope, that's definitely not how we wanted to do this.) This was our first time to practice in person, and we really needed that opportunity.

Once the duty was done, we enjoyed the rest of the (still very hot) evening over a nice dinner and then called it a day. We knew we would need the energy for what was to come.


First Conference Day

Good thing our talk was scheduled for the second day only, which meant I could fully dive into the experience and check things out on day one. 

That day started with a special breakfast for me. Now, if you know me, I'm neither the breakfast type of person nor am I fully awake at that time of day. This one, however, was too good not to opt in for. It was the "Women in AppSec Breakfast" co-hosted by Tanya Janca, Juliane Reimann, Kim Wyuts, and Marisa Fagan. I mean, how could I miss this chance not only meeting those folks I only knew from social media but also meeting a bunch of other women in my area? I usually love seeing a smaller group of folks first before encountering the whole crowd at a conference, and this one promised to create a safe enough space to make real connections. Turns out, it really did! I met lots of amazing women this morning and we happened to bump into each other again and again during the event. Many thanks to Michelle Mariam Philip, Margot Schepens, Eden Yardeni, Liel and Tina! This pre-conference session truly made me feel welcome from the start and it seems the others were happy about this opportunity just as well.

Here are the sessions I've joined during the rest of the day.

  • Keynote: "The Reinvention of Software Engineering" by Hannah Foxwell. Hannah presented her view on how the software world is changing due to latest AI tooling. She stated that with agentic development, speed of development is outpacing speed of decisions - and yet we really shouldn't just build anything because we can, but something that is worth building. We also need to have the means to ensure safety as things are speeding up. People do and will always matter, so invest in them and broaden their skills.
  • "Why AppSec Fails at Scale (and How to Fix It)" by Eduard Thamm. As Eduard shared, AppSec fails at scale when you keep managing findings instead of designing systems that make secure behavior the easiest path. Preach! Lots of gems in this talk. Like: Security advice that ignores delivery pressure will be routed around - the system rewards shipping fast and often. Haven't we seen that over and over again? Not only with security but all kinds of aspects that make good quality software? Eduard asked everyone to move from findings to mechanisms to make the secure behavior the default. Hear, hear.
  • "Authorization Is Where Your App Goes to Lie" by Eden Yardeni. Eden rightfully pointed out that broken access control issues just keep showing up and stick around among the most common vulnerabilities. Why? Because they're often bound to business logic and hence depend a lot on the underlying intentions of features. It's not straightforward for any application to tell who should be allowed to do what - rather the opposite. Eden's answer to this? Use policy engines so "your product owner's intention compiles into policy as code". Helpful for threat modeling, too!
  • "Retiring CVE Chasing: Defending Against Application Exploit Techniques" by Idan Elor. Idan appealed to the audience that we need to start defending against the underlying techniques instead of just running after getting vulnerabilities fixed (have I already shared how often we're seeing this one?). If we build technique-level controls and detect exploitation attempts, we can cover whole classes at once. Idan presented the application attack matrix to help - a community-driven framework mapping tactics, techniques and procedures against modern applications, which can be used for threat modeling and in architecture reviews.
  • "This Build can Break You - Evil Runners and eBPF for Detection" by Reinhard Kugler. Reinhard shared how different CI/CD runners handle things differently and hence show different attack vectors - yet usually they are highly privileged and a valuable target. How to see what happens in the Kernel space? The answer is eBPF code running in a virtual machine in the Kernel. You can attach functions to a trigger like a syscall, trace event or network call and hence detect malicious activities. As Reinhard said, observability is the first step of defense!
  • Book Signing: Alice and Bob Learn Application Security Tanya Janca. Well, I simply had to seize this opportunity. Tanya had been the most influential person in my security career so far, and by far. I've literally only seen my way into security because of her. Knowing she would be at the conference, I kept looking for an opportunity to talk with her, at least shortly to thank her for her work. At breakfast, this opportunity did not show up and I didn't want to impose. Then, at one of the earlier talks that day, I happened to sit front row (as usual) and prepare my sketchnote for the following talk. I was talking with another person next to me, when someone suddenly turned around to us. It was Tanya! We happened to have a quick chat where I blurted out I was in security because of her making security accessible, and also nervously revealed we'll also have a talk the next day. I was super happy this happened and happened naturally. I still wanted to go to her book signing, now even more (I obviously had her book of course already, yet a physical signed copy is just something truly special). And Tanya remembered me and wished us good luck for the talk. Honestly a true fan-girling moment. Stay tuned, this story continues!
  • "The Devil is in the Defaults - what to do about XSS" by Frederik Braun. Cross-site scripting has been the number one CWE for over 10 years. The measures we have to defend against it still aren't as widely used as they should. Like the Content Security Policy - it's shocking how few websites actually make good use of it. Trusted types are great as they treat all HTML parsing as harmful unless proven otherwise - but they also need to be enabled through a CSP directive (which we know only few even use), and, very unfortunately, they ignore context during HTML parsing. Here comes the HTML sanitizer API to the rescue! It will never allow XSS - guaranteed by the browser and as part of HTML standard. I love that Frederik left with a hope-instilling note: we indeed can fix XSS.

During the day, it was really pleasant to run into some folks I already knew from other conferences! Like Clemens Hübner who Mireia and I met at the Open Security Conference 2025. Or Irfan Qadoos whom I met at both BSides Munich and security meetups. Just loved catching up with both again. The world is small and you never know where you'll meet again.

The official program ended already by 16:15 CEST which I was absolutely not used to from other conferences. Of course, networking events are super crucial and lots of stuff was planned on that end, not only socializing at the venue but also dinners and sightseeing offered by various sponsors. Well, not for Mireia and me this time, because obviously we had to use this last opportunity to practice our talk and make it work for the next day. Lucky us, we could still use the venue for the first dry run so we had a "close to real" practice environment. As things closed down at the venue, we had to move out and do the second run at our accommodation. Once we had a good enough feeling, we called it a day. I took the remaining time of the evening to enjoy a really lovely dinner at a Chinese restaurant offering as authentic as one can get Sichuan food. It was absolutely delicious and just good for the soul after a long stressful period of months. Especially as the very next day, it was on.

 

Second Conference Day

The second day, how else could it be, I was rather late for the first session yet made it just in time. I knew ahead of time I most likely won't be able to join many things next to our own talk, yet in the end I managed to catch a few sessions still. 

  • Keynote: "We Live in the Future: The Death and Rebirth of Application Security" by Gadi Evron. Gadi reminded us that things keep changing and we have to keep changing with them. For example, we cannot trust security configurations anymore when agents can just change them. The perimeter shifted to the endpoint agent, yet security controls don't cover them yet. Gadi raised a big question: English is the new programming language - yet how do we secure English?
  • Book Signing: Threats: What Every Engineer Should Learn From Star Wars with Adam Shostack. Yes, I just had to go to this book signing as well. Of course I had Adam's book as well already. But remember, a signed physical copy is a special thing! Also, you never know what will happen. I just loved that Adam noticed my Star Trek shirt and complimented me on it. Well, that's one of the many reasons I love wearing such shirts. They are a great way to find your kin and have lovely conversations. Just like with Adam this time. Thanks a bunch for that!
  • "Keep It Between Us: Manipulating Humans for Better AppSec (Ethically)" by Nariman Aga-Tagiyev. Nariman focused this talk on human motivation - what makes us do things? What are we actually driven by, how much does this reason come from the outside, and how sustainable is it? He reminded us that with some reinforcement, behavior will become a habit, and we can make use of this in our AppSec programs. Make it obvious, make it attractive, make it easy, make it satisfying. Or: Invert all of the above. The invisible side of AppSec and the secret plan is to convert activities into habits. We can start with writing down what the current good and bad habits are around a problematic behavior we observe.
  • "Security Champions: Lessons from Opposite Trenches" by Mireia Cano and me. It was time. We went on stage. The show was on. Have I said paired talks are a special kind of a challenge? This time, we attempted role plays on stage to convey our messages and have a red thread throughout the talk. Well, it was risky - these role plays could have come across as very cringe and over the top. You can't imagine how happy we were when we received lots of amazing feedback afterwards exactly on those theatrical role plays! Seems we hit just the right note and they indeed helped make the topics tangible and relatable with folks. We pulled through, it was our best version of the talk, and you don't know how happy I am that this was recorded! The relief was real afterwards. We really did it! Time to celebrate. That being said, what did we talk about? Well, Mireia came from the security side, having gathered plenty of experience with designing and running security champions programs with everything that could go wrong and what helps to make them go well and evolve. And I lived that champions experience myself for three years before going fully into security, now running a security champions program myself! We've found four key aspects that truly made the difference for such programs. The slides are already out, yet to get the full experience, you'll have to wait a couple of months until the recording is released.
  • "Using CTFs as a Community of Practice Content Machine" by Marco Macala, Florian Schier, and Christian Buchinger. In this talk, they described the security community they built, what worked and what didn't. Very fitting talk to come just after ours! Marco, Florian and Christian advised to keep the monthly sessions light, comedic and consistent. To make them engaging for different backgrounds. To have open discussions, give people free rein for content. And, what I especially love: there should be no grandstanding from security. So much this, seen this way too often as well! All this made them discover CTFs as a perfect opportunity to increase awareness and skills. They encouraged folks to keep them very basic and limiting the effort to set them up. Especially: education over competition, approachable for everyone! That really resonated with me and my current approaches to CTFs, especially when giving such sessions during open space conferences.
  • "Insecurity as Code: How Modern Software Scaled the Attack Surface" by Igor Stepansky. Igor explained how applications aren't the only attack surface anymore - it's everything around them as well, while everyone is already drowning in findings. Due to AI tooling, alerts are exploding - yet are they even valid? Igor reminded us: You're not behind, you're buried! It's about reliably finding the 1% truly critical. To triage on reachability and business impact and then patch those fast, focusing on what matters. And instead of fixing more findings, we should remove the attacker's leverage. This!

During the day, even though the excitement of the upcoming talk was there, I once again had opportunity to meet folks. Like Frederik Braun whom I was connected with via social media yet we never had a chance to talk before. Or Lars Hermerschmidt whom I heard about through a friend working at the same company. Or Ali Kabiri who was immensely kind helping me out with my (super cool) OWASP badge by getting me an extension for it. Also meeting folks I met before, like Michael Helwig. Really enjoyed all those conversations.

The conference approached its closing, and with that came a very special moment for me. Remember that Tanya Jana wished me good luck for our talk? Well. It happened to turn out that she was attending the same last talk as I was. As I was finishing up my sketchnote, she was coming to the front, chatting with the speaker. While I collected all my stuff, she saw me and asked how our talk went. We started to talk and, as it happens, went to the conference closing together. She was going to sit front row - as I usually do the same, I had no problem joining her. Sitting next to her, chatting, and really enjoying our conversation. This way, I also found out that the conference provided slim-fit conference t-shirts for the first time this year - and I have to thank Tanya for relentlessly trying to make the offering more diverse (no, unisex is not the solution here).

The closing was done. The room emptied. I looked around, and found Clemens with a few folks and joined them. I met Mariia Denysenko this way, realizing we're from the same location - a lovely encounter! It was also a pleasure to meet Michael Koppmann who enabled this whole conference by leading the team of volunteers and relentlessly working behind the scenes.

Then it was time to say goodbye and close this chapter. I had a nice dinner in the area. Calmed down a bit. Prepared for the next day - I was adamant to go sightseeing despite the heat. I thoroughly enjoyed doing exactly that after sleeping in the next day (I love art and art galleries are a great air-conditioned place by nature). The day afterwards, it was time to go home.

My first proper OWASP event was as big as they get. It was a good one in itself. It was a really great one because of the people. And it was definitely a huge achievement unlocked moment for Mireia and me!

Saturday, June 13, 2026

Elbsides 2026 - A Welcoming First Time

This year I had my first opportunity to go to Elbsides, the BSides of Hamburg. I had heard lots of folks recommend this conference and I was eager to experience it myself. It's been a lovely couple of days for sure!

On arriving in Hamburg, I met a dear friend for dinner. Really enjoyed the conversations, the tasty food, and in general taking a break after some wildly packed months. It was just what I needed before diving fully into the conference experience.

 

Workshop Day

With batteries recharged, I made my way to the workshop venue. What a warm welcome from the organizers! I knew two of them already from BSides Munich the last years, so it was really nice to catch up.

Then it was time for my own workshop: "Secure Development Lifecycle Applied - How to Make Things a Bit More Secure than Yesterday Every Day". I've given this session plenty of times now, each time to a different kind of audience. The participants I had this time were just great - they happily grouped up, engaged with the hands-on exercises, were eager to bring up even more ideas and try things out together. They truly made my job an easy one! In general, each time I repeat a workshop, I just love to see how different people approach a task and find different things. We can learn so much from each other. At the end of the workshop, participants shared a ton of feedback with me which is invaluable - much appreciated! That's how I knew the time flew by and people couldn't fathom how fast a 4 hour workshop could be over again. This was truly a good start to the conference for me.

Lunch was conveniently served right at the venue, so we could use the time effectively to enjoy the food and also exchange experiences. In the afternoon, I joined a half-day workshop myself: "Exploiting and Securing AI Applications on AWS" by Anne Stein and Robert von Massow. All too relevant these days. No matter if we like generative and agentic AI tooling or not, we have to deal with their outcome and impact at the least. What I really appreciated in this workshop was that the trainers acknowledged this situation. They also were really clear on what kinds of safeguards we can build and where we are at a lost stake due to the probabilistic nature of the beast. In specifics, they emphasized to make the tools that AI agents can call as descriptive as possible to control them via deterministic means as much as possible. AI models, however, can still go rogue on their own terms, so we need to build with this risk as a given. Any guardrails we add are probabilistic as well and hence aren't predictable either. The other part of this workshop I really appreciated was that we had plenty of interactive hands-on exercises to interact with a complex enough and at the same time simple enough system of an LLM having a set of tools available. We practiced both how to exploit the system and get the LLM to do what we wanted, and also how to constrain their reach through making the tools more restrictive, including classics like input validation. I paired up with another participant which was just perfect for the hands-on nature - we came up with more ideas this way and indeed managed to find our ways past the guards, also outside the foreseen path.

The workshop day was over. In the evening, I met a dear community friend I haven't seen for a while. They happened to show me around Hamburg and we had perfect weather for a bit of sightseeing! I love it when these occasions turn up at conferences. After long conversations and a really nice dinner, it was time for me to catch some sleep and get ready for the main conference day.

 

Conference Day

This BSides is a one-track conference. Which comes with benefits: no need to decide where to go, no fear of missing out, no issues trying to change rooms if the schedule is tight! Everyone experiences the same program. Which also means, you'll experience something you wouldn't have chosen otherwise. This really allows for serendipity and insights you would have likely missed. Sure, it might be that you're listening to a talk that's really not relevant for you - but that could happen also if you chose it yourself as you never know how the talk will turn out for real. This time, I did appreciate only having one track as it made sketchnoting easier.

  • Keynote: "Secrets don’t age well: Cyber, Kyber, Quantum and the encryption time bombs" by Natalie Kilber. Quantum computing is one of those areas I haven't learned much about so far. So Natalie's keynote was welcome to introduce a few concepts, in specifics given that cryptography is something most of us don't directly work on, but most of us for sure need to make use of. And in software, we need to prepare for migrating towards quantum. Also, this was the first time I heard about a cryptographic bill of materials (CBOM)!
  • "Harvest Now, Decrypt Later: Bringing Post-Quantum Cryptography to SSH" by Leon Rickert. More quantum! Leon shared a hybrid PQC approach, increasing security through redundancy by having a classical secret and a PQC secret combined in a shared hybrid session key. This could be just the first step in a gradual migration you hoped for. We also need to keep the context of our system in mind, some environments are heavily resource-constrained so performance matters a lot.
  • "Ghost in the Hiring Machine: Catch Fake Personas Before They’re Hired" by Michael Reimsbach and Rishi. This talk comes timely, following all the news where imposters had been hired by companies, thinking these folks were legit applicants. Michael and Rishi showed up what companies can do before a hiring decision in order to figure out whether a person is not who they claim to be, using a whole set of OSINT tools. I love that they also emphasized personal security and reminded us to protect ourselves and applying OSINT defensively.
  • "‘We Have Always Been at War With Eastasia’: Attacks Against Web Archives" by Robin Kirchner. Very interesting talk on how web archives can get targeted by malicious actors, trying to evade or deceive them. Robin presented the techniques that work most of the times that we need to be aware of.
  • "When Trust Breaks Under Pressure" by René Lößner. René shared sound advice on what you can do when confronted with information that is intended to manipulate you into unfortunate actions - and how to even detect that this is happening to you. Remember the FATE and SIFT acronyms.
  • "Let Him Cook! Hacking the Meatmeet BBQ Probe" by Julian (dead1nfluence). That talk was a fun ride of following the rabbit hole of "how does this tool work under the hood". Guess what, it ended up in lots of CVEs getting reported. 
  • "The Map of Artificial Treasures: What to Automate in Security - and Why?" by Michael Helwig. Michael looked at the various options we have using AI systems, how they differ, and what makes more sense to use for which use case. Because not every hammer is for every nail.
  • "Pull the Plug: Kernel-Level Surgery to Blind EDRs" by André Lima. This was a really interesting dive into tricking Windows EDR systems to let your bad driver go through without getting blocked, or even logged. 
  • "I Let My Pi5 Hack: Building a 0$ AI Pentesting Agent" by Nithin Ravi. I really appreciate how Nithin started with the differentiation that AI is not the same as automation and that a lot of things can be automated well without the usage of any AI. AI tooling can be good for what it's actually good at. His journey on how to use low budget tools to build a pen testing agent, however, resulted in the following conclusion: no, you truly don't need AI for everything.
  • "Your Traffic Is Lying to You" by Lisa Fröhlich. Lisa pointed out that the vast ratio of web traffic coming from bots these days and how they go undetected by traditional monitoring systems in the age of AI. We can still learn what's going on - yet only if we truly know our actual valid traffic.
  • "Still Out of Sight? The NIS-2 Reality Check in German SMEs" by Younes Ahmadzei. I've enjoyed Younes' previous version of this talk at BSides Munich 2025. Now that NIS-2 is in effect, how did things change? Unfortunately, nothing much changed as of now. Companies are still behind, while they could have used this opportunity to their own benefit. I love how he concluded that cyber resilience is not created by paper but by empowered companies and active synergies.
  • "The Illusion of Finishability" by Juliane Reimann. This talk was my absolute highlight of the conference. Juliane taught us what's behind our human need for closure, and how people experience this need very differently. Some yearn for closure, others try to avoid closure for as long as possible. This alone explains so much of what I experience every day interacting with various people and also when observing very distinct decision cultures within different teams and companies! Juliane of course also tied this to what we see in security, from statements to behavior and also systems we can use to meet our own needs for closure in a healthy way. 
  • "Keynote: Who comes next?" by Brian Hein and Constantin Jacob. This talk looked at how the threat intelligence community handled things in the past, building tight networks based on the iron principle of KMT: know you, met you, trust you. The problem is, this doesn't fit anymore to today's world of communication and we're loosing the next generation. We need to put in intentional effort to include and grow the next ones after us - and that applies to any community beyond threat intelligence. 

By the way, all of these talks had been recorded and will at some point be published by Elbsides, so that's going to be your chance to check them out yourself. 

The conference closed with a dedicated space for socializing with the community. Afterwards, it was time for speakers dinner. The organizers kindly invited us to really nice food and drinks together in a relaxed atmosphere. It was a great evening among great people, sharing experiences when working in teams but also with many other teams, how to truly help others and make an impact, learning more about wind energy and what's needed to build and maintain these farms, and much more. What a great closure to a great conference.

I went home with my heart full, new connections in my network, ideas sparking. What else can I want from a conference. If you have a chance to join a future Elbsides, seize that opportunity! You won't regret it.

Saturday, November 22, 2025

BSides Munich 2025 - On First Times

I've been to BSides Munich for the last three years, and it's been a pleasure each time. So while it wasn't my first time to attend the conference, there were other first times to be celebrated. It's been my first time giving a workshop at a security conference. It's been my first time as a session chair for speakers. It's been my first time that I've been together with the other half of my team at a conference. And for one of them it's even been their very first conference! That alone is already making my year. Especially as that specific teammate dove into the full experience, connecting with folks, joining a dinner group in the evening, exchanging experience. Just love it when good things happen.

 

Workshop Day

My day started out with meeting some known and new people on my way to the venue (we all ended up at a slightly wrong address at first, which was rather a connecting experience). On entering the (actual) building, there were more folks to greet. Some from other conferences, some from BSides Munich the last years. Grabbing a quick breakfast, it was time to start learning together.

In the morning, I joined the half day workshop "Cloud-Native Chaos: Hacking CI/CD and Cloud Environments" by Samuel Hopstock and Daniel Schwendner. This was a  really cool session and an actual workshop, fully hands-on and even exploratory! I know it's literally in the name of a "workshop", yet at times they end up as lectures instead of actual interactive hands-on learning sessions. So this was a really nice experience. We formed a group of three to tackle our task: given a practice app, gain full access to the Kubernetes cluster it's running on. The challenge was on! I loved that we had decent time to really try ourselves, not too many spoilers but help when needed. Perfect combination. I'm not going to spoil this workshop and the attack path we discovered, yet we could really make use of leftovers, misconfigurations, and oversights all the way. It was very interesting to see for myself how easy it can be to escape a Docker container to the host. It's different to know about it theoretically and to actually see it and especially to do it yourself. Another aha moment for me was to learn how to upgrade a non-interactive reverse shell to an interactive one - super useful for my next CTF sessions. 

After great conversations over lunch, it was time for the afternoon workshops. First, I joined "Developing Universal AI Agents for Static Code Analysis via MCP" by Sunil Kumar. My own workshop had been moved to a later slot and this one was the only session fitting in before. Good thing it was also on a topic I know I need to learn more about. Admittedly, I couldn't fully focus with my own workshop coming up right afterwards, yet it did showcase how MCP servers are built and configured, and demonstrated how they could be used afterwards. More to dive into for sure.

Then it was time for my own workshop "Secure Development Lifecycle Applied - How to Make Things a Bit More Secure than Yesterday Every Day". It was not set up for a good start - there was no break scheduled in between the two workshops, and people joining both definitely needed some time to breathe. To add to this, I learned about yet another scenario how things can go wrong when presenting. This time, the projector and my laptop both decided to connect shortly at first, but when I attempted to mirror the screen instead of extending it they said enough is enough - we're not working together any longer. Luckily, it's not my first rodeo so it didn't bother me (what a nice surprise to be calm for change), plus showing my screen was anyways only a nice bonus for my workshop. We found a quick solution, and once people were back from their break we could finally start. But well, that definitely cut as around 15min from the already short time. People told me afterwards they definitely wanted more time, it was flying for them! They had fun trying their hands on the exercises and there was more to explore. While some things are not in my hands, I'm taking this as a very positive signal.

The workshops were done and yet not everyone was ready to call it a day. My dear CTF team Mireia Cano and Martin Schmidt, one of my colleagues and I all headed for dinner to extend the conversations and have a nice conclusion for the day. 

 

Conference Day

Already at the beginning of the day, I've met many familiar faces and we all prepared together for a busy day ahead full of talks, conversations and insights. Here are the sessions I attended.

  • Keynote: "The art of saying NEIN (in security)" by Martin Brunner. Cybersecurity is a lot about trust, and we need to learn how to say "no" more often, especially from a defender's standpoint. Also, this talk made a new connection across domains: What we have in security with attackers, defenders and victims resembles the drama triangle with persecutor, rescuer and victim a lot. So also here, you can only stop playing the game. In general, Martin encouraged us to be very intentional what you say yes to, what you say not to, and why.
  • "Fantastic clear-text passwords and where to collect them" by Stephan Berger. This talk showed up a lot of interesting ways how to get your hands-on passwords on Windows systems. Easily. Honestly, too easily. Stephan reminded us that you often don't need fancy new tools, you just need to take the time instead and get your hands dirty.
  • "Structuring (cyber) incident root-cause investigations: a practical walk-through" by João Collier de Mendonca. This was a nice demonstration how incidents look in a very real scenario and what constraints come with it. Like in the medical and healthcare domain. Also, I'm curious to check out the mentioned DFIQ framework of forensic questions and approaches.
  • "Trust Issues: How Gen Z Attackers Hack Without Exploits" by Tom Barnea. Tom explained how Gen Z aims for the weakest link: the human. They are hacking trust as this is way easier than hacking systems. Going for everyday unsuspicious tooling and activities which evades traditional defenses is not only smart but also efficient. We need to rethink and change our approaches accordingly. 
  • "Translating mobile app security lessons to the Flutter stack" by Samuel Hopstock. Having worked with ReactNative apps, I was curious how Flutter differentiates when it comes to security. It wasn't very surprising yet still pretty interesting to hear the answer: Flutter apps are just mobile apps and show the same issues as any other mobile app, so we can use the same approaches to find weaknesses. 
  • "In Scope, Out of Sight Why NIS-2 Isn’t Landing in German SMEs" by Younes Ahmadzei. A lot of comnpanies are in scope of the new regulation. Nearly none of them are aware of this fact. And even if they are, they still lack understanding on what it actually means to them and what they have to do - such uncertainty can be paralyzing. 
  • "Why I Go to the Dark Web Every Day" by Alex Holden. Alex shared super interesting stories on what he learned when trying to gain the trust of cybercriminals, where they work, what they think. He emphasized that if you don’t know what’s going on on the dark web you have to assume the worst in case of breaches (e.g. you won’t notice that an attack is going on and how it ended, if the attacker aborted or pulled through). Also, corporate data is extremely valuable, and it’s everywhere in the supply chain - we tend to forget about this aspect. We better know our enemies and threats to stay ahead. 
  • "The Perks and Perils of Persistence: AWS Attacker Techniques" by Oisín B. This talk shared lots of tangible actions that attacker will try, how discoverable such attacks are, how we can spot them and what we can do to prevent these paths. It was targeted on AWS, yet the core ideas are transferable to other cloud providers. 
  • "Turning Off the Internet: Technical Tactics of State-Scale Censorship and Shutdowns" by Reza Sharifi. A lot of people witness shutdowns way more than others - they are reality nonetheless. Censorship thrives where the network is centralized as central points create control points. The tactics and techniques applied differ, however, based on which layer of the stack they target. This talk could have gone easily for a lot longer, there's a lot to talk about on this topic.
  • "NTLM reflection is dead, long live NTLM reflection: Story of an accidental Windows RCE" by Guillaume André and Wilfried Bécard. Here's a story of how the researchers found a trivial logic vulnerability allowing authenticated RCE - by accident. They couldn't believe it at first, yet in the end had to emphasize in this talk: high-impact, simple and stable logical vulnerabilities still exist.
  • "Cloud IR: A Rapid Guide for AWS, Azure & GCP" by Erblind Morina. It doesn't come to any surprise, yet sometimes we need to hear messages on repeat: lack of logging means limited evidence. Visibility and logging coverage are key for incident response. Erblind encouraged us to start using the incident response cheat sheet of our cloud provider and to check out the Incident Response Hierarchy of Needs
  • Keynote: "Oops, I pwned it again!" by David Elze. I love it when people share failure stories and what they learned from them. We all have failure stories - and some are more epic than others. David shared five situations where things went awry and the lessons they gained from them. Including the last: sometimes we do have to take certain risk that comes with the nature of our job.  

For two of these talks, I've also had the honor to support as session host. I tried to find the speakers already beforehand, yet I didn't spot them in the crowd. This meant we could only check in shortly before their talk on what they needed regarding setup, timekeeping, introduction and so on. And then it was already on! Welcoming the audience to the room, having them seated, getting their attention, and having them cheer. Welcoming the speakers to the stage, getting them briefly introduced and then out of their way. During the talk, keeping track of time and signaling notes according to speaker needs. Afterwards, coordinating questions from the crowd, ensuring the program schedule can be maintained. Thanking the speakers, making sure they got what they needed. And a few more things, huge kudos to BSides Munich organizers for preparing a comprehensive cheat sheet upfront for session chairs! They also went the extra mile and prepared both bio notes for the speaker introduction as well as potential fallback questions for each talk in case the audience wasn't ready to engage. All this went pretty well. Once again I found myself in a situation where I was glad to have been doing public speaking engagements for so many years by now, and where the respective skills gained really pay off.

The additional challenge I had: how to do sketchnotes while also being a session chair? Well, I dared to go full in, and it did turn out to be pretty stressful. I also missed parts of the talks and my sketchnotes don't do them justice. But well, I learned that's part of doing sketchnotes anyways. There are constraints and you have to live with them. Whatever you have on paper in the end you have, whatever you didn't note you didn't. It's a perception and interpretation of the talk anyways and you just do what you can do in the specific moment. I also learned over the years that I'm doing this, that no matter whether I like how a specific sketchnote turned out or not, it might still help others and it's usually appreciated by speakers. So I'm sharing them anyways.

The conference day was over super fast, with the packed schedule and lots of conversations and also duties to fulfill. Also on this day, not everyone was ready to leave just yet and instead hang around and stayed for a while, still enjoying each other's company. 

Then it was time to join the organizers and my fellow speakers to go to the speakers dinner. We concluded the day with a really delicious meal among great people. We made new connections, we exchanged our favorite licorice products, conference venue struggles, insights on local security communities, and much more. As you do.

Thank you everyone for making this yet another great conference! Won't be my last BSides Munich for sure.

Saturday, November 16, 2024

BSides Munich 2024 - We Belong

Last year, I've attended my first security conference with BSides Munich. It was an awesome experience connecting with the community. This year, it was clear to me to come back as participant. Yet when the call for papers started, I figured: why not try my chances? I dared to submit my brand-new talk "A Security Champion’s Journey - How to Make Things a Bit More Secure than Yesterday Every Day" to BSides Munich. You can imagine my joy when it was indeed accepted! So, here's my recap from this year's conference as participant and speaker.

 

Workshop Day

Tickets for this conference are usually quickly gone, so I made it a point to decide on my workshops early on and then grab the tickets as soon as they went online. It worked! This time, I decided to go for two half-day workshops.

In the morning, I joined "Backdoors & Breaches: Simulating Cyber Security Incidents" by Klaus-E. Klingner. I wanted to give the Backdoors & Breaches card game a try for quite a while, so here was my chance. Klaus started setting the scene describing how classic incident response simulations can be tedious and require a lot of preparation effort. In contrast, using game-based learning, like playing a round of Backdoors & Breaches, can be done very quickly and provide playful insights. Backdoors & Breaches is designed based on the tabletop role-playing game Dungeons & Dragons. Instead of a game master, you have an incident master. They choose the attack scenario that led to the incident, which the group has to figure out - how did the attackers manage to compromise the system, move deeper, maintain persistence in the system, and finally exfiltrate data? What happened? The group has procedures they can use to find out more about what happened - yet depending on how they roll the dice, they won't always succeed! There's a bit more to it, just check out the complete rules for yourself. What a fun game; it led to really insightful conversations in my group. There are expansion packs already enabling further scenarios, and you can also play it online, either using Klaus' version or the official one.

In the afternoon, I participated in the "How to Hack your Web Application" workshop by Janosch Braukmann. I really liked his introductory web app hacking challenges offering simple yet not uncommon mistakes to exploit. A really nice hands-on connection to the topic, allowing him to gauge the context of the audience just as well. It made his point very clear: don't trust anything coming from the client side, it's not in our hands. We've walked through the OWASP Top 10 together and how to mitigate the respective risks. Then it was time for practice again: we got our hands on a vulnerable web application he provided for the duration of the workshop. It's usually insightful and fun to see what people find and what approaches they come up with to do so. Practice didn't stop here, how do we prevent these issues in the first place? The most effective and simplest way Janosch has seen so far are malicious user stories: user stories from a malicious actor's point of view. We then just need to flip the acceptance criteria to build an implementation that prevents the threat actor from being successful with their attempt. This can easily be done along with any usual ideation and refinement activities as part of the development life cycle that teams tend to be used to. Even though I've heard the content before, I like joining these workshops in order to get surprised of what I didn't know yet, and to learn about different approaches to convey the respective concepts and skills to folks.

All in all, the workshops were great. Even better, this day already granted space to check in with people! It was awesome to meet Claudius Link again in person, my Open Security Conference (osco) co-organizer fellow. It's been great to re-connect with a few folks I've met at last year's BSides. And I really enjoyed getting to know Yin Yin Wu-Hanke and Lisa Aichele!


Conference Day

The day started very early for me. Being a local meant commuting to the venue, and being a speaker meant showing up at 7:30 am for the tech setup check. If you've met me, you know I'm a night owl, so this hurt quite a bit. And yet I was excited to have this opportunity at re-connecting with the community and also presenting my own content at the event. 

This conference has an amazing organizer team and so many people volunteered to help and ensure it's running smoothly. Many thanks to all of you for creating and holding this space for us! This year's main organizer was Sneha Rajguru. When she opened the conference officially, she emphasized that this event is for all of us in all our diversity, and her words stuck with me: "You belong." Last year was my first BSides. This year, I've really felt I do belong indeed. We all do. 

Overall, BSides Munich had once again a lot to offer. More than I could try out myself! A hardware hacking village, a CTF, a retro-gaming area, the sponsors exhibition, and more. I mostly focused on the talks myself, while at times taking a break to chat with folks in between. Here are the presentations I've attended.

Finally, a huge shout-out to lots of amazing people I've connected with during the day! I really appreciated meeting Van Nguyen, Clara Kowalsky, Sujaritha, Dagmar Swimmer, Morton Swimmer, Tobias Schuster, Julien Reisdorffer, Konstantin Weddige, Stuart McMurray, and Rudolf Kaertner whom I've first met at osco this year.

At the end of the day, the organizers invited all speakers to a fabulous speakers dinner where we enjoyed great food in great company. What an amazing closing for the day.


BSides Munich 2025

One thing is for sure, I'll do what I can to make it to BSides Munich next year as well! If you have the opportunity, seize it to experience it for yourself. Maybe even submit a proposal to share your own stories with the community, or offer to be a volunteer. It's been a great event once again this year and I'm happy to have been part of it.

Need more reasons to join? The recordings for this year had already been published! Have a look by taking the direct links from this year's agenda, and check out past years' recordings on the BSides Munich YouTube channel.

See you in 2025!