{"id":65,"date":"2008-09-24T08:43:55","date_gmt":"2008-09-24T13:43:55","guid":{"rendered":"http:\/\/www.webadminblog.com\/?p=65"},"modified":"2008-09-24T09:51:04","modified_gmt":"2008-09-24T14:51:04","slug":"day-1-keynote-owasp-appsec-nyc-2008","status":"publish","type":"post","link":"https:\/\/www.webadminblog.com\/index.php\/2008\/09\/24\/day-1-keynote-owasp-appsec-nyc-2008\/","title":{"rendered":"Day 1 Keynote &#8211; OWASP AppSec NYC 2008"},"content":{"rendered":"<p>I&#8217;m currently at the OWASP AppSec 2008 Conference in New York City and am listening to the keynote presentation shared by the board of OWASP.\u00a0 Starting off is Jeff Williams, Chair of OWASP.\u00a0 He talked about OWASP&#8217;s mission, what we&#8217;re currently working on, and offered the following suggestions on how to take OWASP into the future:<\/p>\n<p>1) Prioritize<\/p>\n<ul>\n<li>You can&#8217;t &#8220;hack&#8221; code secure.<\/li>\n<li>Use risk metrics.<\/li>\n<\/ul>\n<p>2) Set a useful research agenda<\/p>\n<ul>\n<li>Don&#8217;t spend time searching for obscure vulnerabilities<\/li>\n<li>Create tools that verify that software does the <strong>RIGHT<\/strong> thing instead of just looking for problems.<\/li>\n<\/ul>\n<p>3) Turn application security from a black art to a science<\/p>\n<ul>\n<li>OWASP in School program<\/li>\n<li>Translating OWASP Top 10 and various books and projects into other languages.<\/li>\n<li>Printing guides, books, and manuals for cost of printing.\u00a0 Free downloads online.<\/li>\n<\/ul>\n<p>4) We can enable secure coding<\/p>\n<ul>\n<li>Breaking things is easy, try creating something secure and tell people how you did it.<\/li>\n<li>Check out the OWASP Enterprise Security API Project<\/li>\n<li>Increased visibility (software should provide info on who built it, what libraries they used, etc)<\/li>\n<\/ul>\n<p>5) Make application security into a movement<\/p>\n<ul>\n<li>Evangelize application security<\/li>\n<li>Show people what an application security program looks like<\/li>\n<\/ul>\n<p>Next up was Dave Wichers.\u00a0 He talked about the OWASP goals of improving quality and support.\u00a0 OWASP is publishing a &#8220;desk reference&#8221; guide on application security.\u00a0 Community outreach is a huge focus of OWASP.\u00a0 Over 100 chapters around the world.\u00a0 Dave is the Conference Chair and helps to organize these conferences.\u00a0 Let him know if you&#8217;re interested in putting one on.<\/p>\n<p>Tom Brennan, head of NY\/NJ chapter and OWASP Board Member starts talking about over 10,000 members on the mailing list and over 120 chapters involved in OWASP effort.\u00a0 Says you should get involved in OWASP!<\/p>\n<p>Next up is Dinis Cruz, another board member, who says he comes up with all sorts of crazy ideas for OWASP.\u00a0 Helped come up with the OWASP Grants ideas when the Belgium chapter had extra money in the bank.\u00a0 OWASP Spring of Code 2007 sponsored 26 projects at $125,000.\u00a0 Summor of Code 2008 has 31 grants and they are focusing on quality with reviewers, project managers, etc.\u00a0 OWASP has given out over $250,000 in grants since the Seasons of Code project started.\u00a0 Then he started talking about the OWASP EU Summit happening in Portugal in 2008 in November.\u00a0 Nice hotel by the seafront.\u00a0 Go to meet all of the guys who are influential in OWASP.\u00a0 Coming up with a bunch of training courses that are completely OWASP related and mostly done by our leaders.\u00a0 Lots of working sessions to start discussing projects and set the AppSec agenda for 2009.\u00a0 Five nights at a 5 star hotel for 300 Euros if you share a room or 600 euros if you want a single.\u00a0 It&#8217;s a deal!\u00a0 If you&#8217;re at the conference, they&#8217;re giving out free books.<\/p>\n<p>Last up is Sebastian Deleersnyder who compares OWASP to Second Life.\u00a0 A lot of people doing this as a second job, but it&#8217;s also a virtual community.\u00a0 Asks chapter leaders to stand up and everyone gives them a hand.\u00a0 *pats self on the back*\u00a0 End of keynote.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;m currently at the OWASP AppSec 2008 Conference in New York City and am listening to the keynote presentation shared by the board of OWASP.\u00a0 Starting off is Jeff Williams, Chair of OWASP.\u00a0 He talked about OWASP&#8217;s mission, what we&#8217;re currently working on, and offered the following suggestions on how to take OWASP into the [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[127],"tags":[76,128,626,129,12,622],"class_list":["post-65","post","type-post","status-publish","format-standard","hentry","category-owasp-appsec-nyc-2008","tag-application","tag-appsec","tag-conferences","tag-keynote","tag-owasp","tag-security"],"aioseo_notices":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_shortlink":"https:\/\/wp.me\/pfI0c-13","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts\/65","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/comments?post=65"}],"version-history":[{"count":4,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts\/65\/revisions"}],"predecessor-version":[{"id":76,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/posts\/65\/revisions\/76"}],"wp:attachment":[{"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/media?parent=65"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/categories?post=65"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.webadminblog.com\/index.php\/wp-json\/wp\/v2\/tags?post=65"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}