Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.
Save Your SpotTogether with BOSCH we invite you to a full day of learning more about the intersection of mobility and code. Get to know more about how modern mobility is defined by an intricate interplay of hardware and software and how cars are not only connected to the road, but also to the cloud.
Coding the Future of Mobility features a variety of talks and a workshop, that give you valuable insights into the world of mobility - wether you join in-person or online.
Together with Bosch we invite you to a full day of learning more about the intersection of mobility and code. Get to know more about how modern mobility is defined by an intricate interplay of hardware and software and how cars are not only connected to the road, but also to the cloud.
Coding the Future of Mobility features a variety of talks and a workshop, that give you valuable insights into the world of mobility - wether you join in-person or online.
Security is a hot topic right now, with ransomware and nation-state hacking in the newspapers on AT LEAST a weekly base. This can include millions of damages for exceptional cases, and hot-patching systems at an absurdly fast pace. In this talk, I will talk about some of the current challenges for development projects and developers in general, and how to keep an overview on what is going on security-wise.
Martin did his PhD at TU Vienna on digital forensics back in the days and is now assessing security risks for development projects at Bosch. He is interested in everything related to digital security and online privacy and is a proven expert in automotive security.
"Shift Left" is a common buzzword when it comes to evolving one's software development lifecycle towards security. However, many engineers struggle with such process-oriented issues and shy away from the effort.
OWASP SAMM is a framework with the goal of making one's own SDLC measurable and is especially for Devs & Ops (and everyone in between), who are used to working hands-on, an exciting and exceedingly interesting introduction to process-oriented thinking.
Mathias Tausig is a skilled mathematician and has professional experience as a security officer, developer and SysAdmin. He works as a university lecturer for IT security and as a security consultant at SBA Research for penetration testing, training and threat modeling. As a speaker he was among others at heise devSec, sec4dev, Linuxwochen, RIOT-OS Summit and the CCC Easterhegg.
Navigating the world of secure software development is hard. There is a lot of noise and not enough time to investigate everything thoroughly. Make your life and the lives of your colleagues easier by building a world-class DevSecOps automation pipeline. Automate feedback delivery in a way that makes sense. It doesn’t have to be hard; automate the pain away!
Kyle Suero: Before joining Snyk as a Senior Security Advocate, Kyle was a Systems Administrator, Full Stack Engineer, Developer Evangelist, and AppSec Engineer. He graduated from the Rochester Institute of Technology Computing Security program with a concentration in Forensics & Malware and an immersion in Philosophy. While traveling North America as a Developer Evangelist for the global hackathon community, Kyle developed a passion for teaching developers about the field of security. In his free time, he serves as a member of the board of advisors to Open@RIT and TechTogether.
Brian Clark: Brian is a web developer with a focus on JavaScript. He shares a lot of his expertise online through his live streams and content. He covers topics like application development, security, tools and more.
In this session we focus on CI/CD pipelines deployed via AWS managed services, such as CodeBuild, CodeDeploy and CodePipeline. And we demonstrate how small decisions can have a significant impact on the security of the CI/CD pipeline, even to the point where the trustworthiness of the pipeline is broken (a poisoned pipeline).
CodeBuild’s functionality can be abused to allow developers to bypass existing security controls implemented as part of the SDLC environment, such as peer code review, code approval processes, segregation of duties and secrets management. This can introduce a, perhaps, unforeseen vector for exfiltrating application secrets, tampering with the application and, potentially, taking full control of the deployment servers by executing commands using elevated privileges.
Due to the shared responsibility model, this is mostly an AWS customers’ challenge. Moreover, customers will be open to the risk even when following AWS samples, tutorials, and, even managed services that help simplify and automate the setup of CI/CD pipelines in the cloud environment, such as CodeStar.
In this session we want to explain and warn DevSecOps and Cloud communities about this pipeline poisoning risk in particular, so that it can be taken into account for securing CI/CD pipelines in the cloud. And, in general, showcase the new challenges and considerations that cloud solutions bring to those adopting the cloud.
Asier has been part of the Cyber & Privacy team of PwC Belgium since he joined in September 2017 after finishing his studies. As a member of the technical security and risk management team, Asier is strongly focused on the technical aspects of application security and secure software development.
He graduated with high honors in Computer Science at Mondragon University in Spain and continued his studies with a master’s degree in Computer Systems and Networks at Chalmers University in Sweden. He specialized in computer security and distributed systems and finished his studies with a Master Thesis in application security at KU Leuven University in Belgium.
At PwC he has been involved in application vulnerability assessments, secure architecture reviews, secure source code reviews and cloud security assessments. He holds the ISC² CSSLP and AWS and Azure certificates for security and development. Asier is part of the PwC Expert Track members and is focusing on the development of his technical skills in the areas of cloud security with a strong interest for application security and secure development.
To many developers, security can be a treacherous territory. Recurring bugs and context switching can lead to burnout. As we work together to deliver better products faster, how can we empower developers and help them become Secure Code Superstars.
Stefania Chaplin’s experience within Cybersecurity, DevSecOps and OSS governance means she's helped countless organisations understand and implement security throughout their SDLC. As a python developer at heart, Stefania is always optimising and improving efficiency wherever she goes by scripting & automating processes and creating integrations. Stefania is passionate about DevSecOps and cybersecurity, having spoken at many conferences including; RSA Conference, ADDO, OWASP, JavaZone, Women in DevOps etc. She is also an active member of OWASP DevSlop, hosting their technical shows.