Greetings PDXDevOps,
James Bohem and I will be giving a talk next Monday:
http://calagator.org/events/1250464204
Talk abstract and bios below. Hope to see you there.
Cheers,
tim
====
Application security is a moving target, but the Open Web Application
Security Project (OWASP) is here in Portland to help you write and
deploy applications securely. James and Tim will walk you through
all of the free resources made available by OWASP to developers,
application architects, and information security professionals.
As an example of how OWASP can help you, we'll touch on a few of the
finer points of secure web session management, covering the variety of
surprising ways in which an attacker can conduct man-in-the-middle
attacks on SSL-protected web traffic if sites are not configured
properly.
Q&A will follow.
Tim has been taking deep technical dives in security for over a decade
as an application security specialist and vulnerability researcher.
Tim resides in Oregon and works at VSR where he helps to secure his
customers' environments through penetration testing, training, and
forensics investigations. His past security research has culminated
in the release of several responsibly disclosed vulnerabilities in
popular software products. Tim also develops and maintains several
open source digital forensics tools as well as Bletchley, an
application cryptanalysis toolkit.
James is the focal point for the security program at WebMD Health
Services, which includes a large web-based application with millions
of users, as well as other security technologies and the security and
risk management program for this 400+ person division of WebMD based
in Portland. His previous background includes 15 years in security
consulting, focusing on application security, design, and technical
compliance with a range of regulations and standards. In addition, he
has experience developing large distributed applications,
microkernels, the UNIX kernel, and international software standards
for open systems.