BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Scaling the Security Researcher to Eliminate OSS\n  
  Vulnerabilities Once and For All\n   When: Saturday\, Aug 13\, 10:00 - 10
 :45 PDT\n   Where: Caesars Forum - Academy 401-410\, 421 (Track 3) - [1]Ma
 p\n\n   SpeakerBio:Jonathan Leitschuh \, OSS Security Researcher - Dan Kam
 insky\n   Fellowship @ HUMAN Security\n   Jonathan Leitschuh is a Software
  Engineer and Software Security\n   Researcher. He is the first ever Dan K
 aminsky Fellow. Jonathan is best\n   known for his July 2019 bombshell Zoo
 m 0-day vulnerability disclosure.\n   He is amongst the top OSS researcher
 s on GitHub by advisory credit.\n   Heâ€™s both a GitHub Star and a GitHub
  Security Ambassador. In 2019 he\n   championed an industry-wide initiativ
 e to get all major artifact\n   servers in the JVM ecosystem to formally d
 ecommission the support of\n   HTTP in favor of HTTPS only. In his free ti
 me he loves rock climbing\,\n   surfing\, and sailing his Hobie catamaran.
 \n\n   This work is sponsored by the new Dan Kaminsky Fellowship which\n  
  celebrates Danâ€™s memory and legacy by funding OSS work that makes\n   t
 he world a better (and more secure) place.\n\n   Twitter: [2]@JLLeitschuh\
 n\n   Description:\n   Hundreds of thousands of human hours are invested e
 very year in\n   finding common security vulnerabilities with relatively s
 imple fixes.\n   These vulnerabilities arenâ€™t sexy\, cool\, or new\, weâ
 €™ve known about\n   them for years\, but theyâ€™re everywhere!\n\n   The 
 scale of GitHub & tools like CodeQL (GitHub's code query language)\n   ena
 ble one to scan for vulnerabilities across hundreds of thousands of\n   OS
 S projects\, but the challenge is how to scale the triaging\,\n   reportin
 g\, and fixing. Simply automating the creation of thousands of\n   bug rep
 orts by itself isnâ€™t useful\, & would be even more of a burden\n   on vo
 lunteer maintainers of OSS projects. Ideally the maintainers\n   would be 
 provided with not only information about the vulnerability\,\n   but also 
 a fix in the form of an easily actionable pull request.\n\n   When facing 
 a problem of this scale\, what is the most efficient way to\n   leverage r
 esearcher knowledge to fix the most vulnerabilities across\n   OSS? This t
 alk will cover a highly scalable solution - automated bulk\n   pull reques
 t generation. Weâ€™ll discuss the practical applications of\n   this techn
 ique on real world OSS projects. Weâ€™ll also cover\n   technologies like 
 CodeQL & OpenRewrite (a style-preserving refactoring\n   tool created at N
 etflix & now developed by Moderne). Letâ€™s not just\n   talk about vulner
 abilities\, letâ€™s actually fix them at scale.\n\n   '\n\n   1. https://d
 efcon.outel.org/consolidated_page.html#CaesarsAcademyBR\n   2. https://twi
 tter.com/JLLeitschuh\n\n\n
DTEND:20220813T174500Z
DTSTART:20220813T170000Z
LOCATION:DC - Caesars Forum - Academy 401-410\, 421 (Track 3)
SUMMARY:Scaling the Security Researcher to Eliminate OSS Vulnerabilities On
 ce and For All
END:VEVENT
END:VCALENDAR
