Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Builders Vs. Breakers - Gameshow Edition - BSidesChicago 2011

Builders Vs. Breakers - Gameshow Edition - BSidesChicago 2011

This was the first Builders vs. Breakers presentation from BSidesChicago in 2011. Featuring Jon Rose as the Breaker, Dan Schleiffer as the moderator and Matt Konda as the Builder this was the fun filled presentation that started the Builders Vs. Breakers ball rolling.

Matt Konda

April 16, 2011
Tweet

More Decks by Matt Konda

Other Decks in Programming

Transcript

  1. GameShow  Edi4on • Debate  a  ques4on  –  a  few  minutes

     each • 1-­‐2  Audience  members  provides  input • Audience  Votes • Loser  Drinks • Repeat • Live  tweet  your  ques4ons  to  @buildvsbreak
  2. Breaker • I’m a badass, of course I’ll own it

    High Risk Vulnerabilities Speed and Coverage
  3. Builder “Problem.  Infosec  pros,  pentesters  etc.  are  more interested  in

     #appsec  than  programmers.  How  to change  that?  <  will  not  change” –  Builder’s  Tweet
  4. Breaker “If  you  are  a  developer  and  don’t  know  who

     OWASP  is at  this  point,  it’s  because  you’ve  chosen  not  to.” –  Breaker’s  Tweet
  5. Breaker “…  the  developer  who  did  this  should  be  taken

     out  into the  street  and  beaten  …” –  Breaker  at  Thotcon
  6. Hypothe4cal  System • Time  +  Expense  System  in  RoR •

    Bug  exists  where  a  user  can  approve  their  own expenses  exposed  via  res`ul  call  but  not  in  UI • Business  opportunity  to  make  the  system mul4-­‐tenant  and  sell  to  mul4ple  customers
  7. Real  Goals • Take  hard  stance  on  both  sides  in

     an  adempt to  elicit  audience  par4cipa4on • Get  everyone  to  come  to  the  conclusion  that the  current  model  is  broken • Generate  conversa4on  on  how  we  can  make  it beder
  8. What  are  we  doing? • Cross  between  The  Fixer  and

     MS  SDL • Talking  with  broader  group  of  developers • Cost  /  Value  models (Results  TBD)