Perimeter
7/23/2010
05:10 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Security BSides Grows, But Not Too Much

The security "unconference" is back in Vegas, and this time the setting is a gated private resort with multiple swimming pools and a sand beach, and the number of attendees signed up so far for the free -- yes, free -- event has doubled. But that doesn't mean Security BSides will lose the intimate vibe that its organizers envisioned and encouraged when they first launched it in Las Vegas a year ago.

The security "unconference" is back in Vegas, and this time the setting is a gated private resort with multiple swimming pools and a sand beach, and the number of attendees signed up so far for the free -- yes, free -- event has doubled. But that doesn't mean Security BSides will lose the intimate vibe that its organizers envisioned and encouraged when they first launched it in Las Vegas a year ago.It won't be quite as cozy as last year, where there were about 40 to 100 people tops at one time at the smaller "hacker house" the BSides organizers rented. So far close to 400 attendees are expected for this year's event. But BSides won't pack hundreds of attendees in a room like Black Hat USA and Defcon, which are headlining the security conferences in Sin City next week. "There will still be plenty of rooms where you can continue the conversation," notes Jack Daniel, one of the founders and organizers of BSides. It's those side conversations that security folk thrive on, even at the bigger events.

Even BSides can't escape the over-the-top Vegas culture, though, Daniel notes, like this year's more elaborate venue (think waterfalls, cabanas, and water slide). Perhaps the most profound difference between BSides this year and its first year is that it's attracting a bit broader audience. And it's not just an alternative forum anymore for those presentations that didn't make the cut at Black Hat and Defcon -- many of the BSides presentations were submitted before Black Hat announced which talks it had selected.

Neither BSides' organizers nor Jeff Moss, founder of Black Hat, which is expecting some 4,700 attendees, see the two events as direct competitors. But the reality is that BSides runs on the same days as Black Hat's briefings, July 28 to 29, and there will be scheduling conflicts for potential attendees. BSides will offer shuttle buses from Caesars for any Black Hat attendees who want to check it out, as well as from the Riviera Hotel for the Defcon crowd, many of which start showing up later in the week for that event.

Daniel and other BSides organizers worry about balancing BSides' growing attendee list with keeping it from getting too big -- and well, conference-y. "We want to make sure the informal stays informal, but we don't want to turn anyone away," says Daniel, who is community development manager for Astaro. BSides this past year has held meetings in San Francisco (during the RSA Conference) Boston (during SOURCE), Denver, and Austin, for example.

Chris Nickerson, one of the BSides organizers, and CEO of Lares Consulting, says he thinks the security industry in general has gotten too big. He sees smaller conferences like BSides as providing a better forum for fostering the passion of security pros and the intimate feel of a smaller crowd, he says. There's still a need for bigger events, he says -- it's just that the smaller ones can have a bigger impact.

Among the big names speaking at this year's event is HD Moore, who will demonstrate how a misconfiguration by developers using the VxWorks operating system found in many embedded systems has left various VoIP equipment and switches, DSL concentrators, industrial automation systems for SCADA environments, and Fibre Channel switches, at risk. Other talks include building bridges between hackers and business, and building better network diagrams for security purposes.

Because it's free, BSides attracts a more diverse crowd, its organizers say. "It's a melting pot of the hacker, businessperson and someone passing by to check it out," Nickerson says.

But a private resort in Vegas isn't free nor is the food, beer, shuttles, and other expenses it takes to run BSides, so the unconference does rely on corporate sponsors for those costs.

-- Kelly Jackson Higgins, Senior Editor, Dark Reading Follow Kelly (@kjhiggins) on Twitter: http://twitter.com/kjhiggins Kelly Jackson Higgins is Executive Editor at DarkReading.com. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?