ken johnson matt ahrens - owasp...matt ahrens april 2012 introductions • ken johnson - @cktricky...

46
baking in security sweet, secure, cupcakes ken johnson matt ahrens april 2012

Upload: others

Post on 28-Feb-2021

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

baking in security sweet, secure, cupcakes

ken johnson matt ahrens

april 2012

Page 2: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

introductions

•  ken johnson - @cktricky •  ginger ninja •  not a hugger •  shot a shark in the frickin’ face!.kidding

•  matt ahrens - @matt_ahrens •  background in IR/DF •  breaking or building a security program •  loves craft beer and coffee that resembles tar

Page 3: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

expectations

•  What this talk is about •  Survival Guide? •  Our experience thus far

•  What it isn’t! •  We figured it out!!! <~ FALSE

Page 4: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding
Page 5: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

•  Live in more than 647 markets around the world

•  More than 60 million members worldwide, 25 countries on 6 continents

•  63 million vouchers sold to date

•  Diverse offerings include daily deals, escapes, families, adventures, instant, gourmet

•  Over 4,900 employees worldwide

Updated January 23, 2012

Page 6: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding
Page 7: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

in the beginning!.

Page 8: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

where to start

Page 9: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

psychology

Page 10: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

who to hire

Page 11: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

who to hire

Page 12: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

apprenticeship

Page 13: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

engineer focused

Page 14: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

find the fail

Page 15: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

appsec goals

Page 16: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

alignment

Page 17: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

changes

Page 18: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

changes

Page 19: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

manage communications

Page 20: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

time management

Page 21: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

professional firefighters

Page 22: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

work/life balance

Page 23: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

communication

Page 24: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

communication

24

!

Not. Role. Models.!!

!""#$#%&"'()*+$$,%%-$%.'#)/"$

012)*)*+$3%1$2$45%%16#'21)*+7$8%&9"::%*;$

Page 25: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

tools

Page 26: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

tools

Page 27: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

tools

Page 28: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

friendly advice

Page 29: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

friendly advice

" " " " """

!Do NOT call someone’s baby ugly!

Page 30: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

Have a SOLUTION!

…don’t just say no

Page 31: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

compliance is tangible

Page 32: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

fail fast

Page 33: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

"   Failed tests are better than none at all"

"   Realize a failed test quickly"

"   Don’t push it to the brink"

know when to quit, don’t be afraid

Page 34: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

incidents

Page 35: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

incidents

Page 36: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

incidents

Page 37: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

incidents

"Define what constitutes “AppSec”"

Page 38: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

key wins

Page 39: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

"   Developer security tools""   Strong “Political Security”""   Super smart engineering

team"

key wins

Page 40: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

key wins

"   great security team""   Ninja “Ops” Team""   Everyone is HUNGRY to

win"

Page 41: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

prove it

Page 42: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

prove it

Page 43: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

wishlist

Page 44: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

wishlist

Page 45: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

Questions?

Page 46: ken johnson matt ahrens - OWASP...matt ahrens april 2012 introductions • ken johnson - @cktricky • ginger ninja • not a hugger • shot a shark in the frickin’ face!.kidding

Thank you, Stay Hungry!