30(ish) days of security - owasp · 20/04/2017  · if you don’t know the answer to a question,...

42
30(ish) Days of Security With Grace and Catherine

Upload: others

Post on 24-Jul-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

30(ish) Days of SecurityWith Grace and Catherine

Page 2: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 3: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 4: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 5: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 6: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 7: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 8: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

�Catherine

� Grace

Page 9: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

“HACKING”

Page 10: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 11: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

“If you want to learn about something, the best way is to

give a talk”- Kanye West

Page 12: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 13: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 14: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 15: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 16: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 17: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

End of Project30 days review

Page 18: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Bonus: Give a talk

Page 19: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Stop

Page 20: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 21: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 22: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 23: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 24: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Graph of Interest

Page 25: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked
Page 26: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Graph of Paranoia

Page 27: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Advice for Mentees

Page 28: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

It’s okay to feel embarrassed

Page 29: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Expect dips in interest, it’s normal

Page 30: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Seek real life success stories

Page 31: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Communicating with mentor about things that are too complicated

Page 32: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Don’t be put off by the haters

Page 33: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Advice for Mentors

Page 34: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Set expectations (#1 reason why people get mad)

Page 35: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Be flexible, allow for tangents and to pursue curiosity

Page 36: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

If you don’t know the answer to a question, or you’re a little fuzzy, then

look it up together

Page 37: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Don’t assume anything about what your mentee knows or has learned

Page 38: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Don’t jump in to save the day

Page 39: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Celebrate learnings!

Page 40: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

Think about the cultural context of your mentee

Page 41: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

tl;dr:✌� 30 Days of Security Testing

Hack Yourself First by Troy Hunt

Interviews

News articles

Page 42: 30(ish) Days of Security - OWASP · 20/04/2017  · If you don’t know the answer to a question, or you’re a little fuzzy, then ... Did you find something challenging that knocked

✨THANK YOU✨

Thank you to:⭐ Pipes ⭐ Lily ⭐ Erica ⭐ @nzkarit ⭐ Kirk / Kim / OWASP ⭐ Assurity ⭐ Enable ⭐

[email protected]@gracenolan.me

@GracieNoLag