<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>onelittlewindow</title>
	<atom:link href="http://onelittlewindow.org/blog/?feed=rss2" rel="self" type="application/rss+xml" />
	<link>http://onelittlewindow.org/blog</link>
	<description>A blog about security, writing, and presence</description>
	<lastBuildDate>Mon, 20 Feb 2012 21:32:52 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>AppSec DC, and why you should be there.</title>
		<link>http://onelittlewindow.org/blog/?p=303</link>
		<comments>http://onelittlewindow.org/blog/?p=303#comments</comments>
		<pubDate>Mon, 20 Feb 2012 20:28:52 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[AppSecDC]]></category>
		<category><![CDATA[collaboration]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[Federal]]></category>
		<category><![CDATA[information security]]></category>
		<category><![CDATA[meetups]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[OWASP AppSec]]></category>
		<category><![CDATA[SCADA]]></category>
		<category><![CDATA[web people]]></category>
		<category><![CDATA[Web Security]]></category>
		<category><![CDATA[Conferences]]></category>
		<category><![CDATA[ICS]]></category>
		<category><![CDATA[Washington DC]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=303</guid>
		<description><![CDATA[When we first held AppSec DC in 2009, I had just come back from a two-year jaunt (job-wise) away from the world of information security. I’d long been a proponent of the fact Washington DC should have the best Information Security community in the world. I didn’t want to lose touch with either the DC or the greater InfoSec community while I was dabbling in online collaboration and presence, so I made a point of focusing on participating in community outside of work, and became active in a variety of meet-ups and organizations across different technology sectors. AppSec DC was ...]]></description>
			<content:encoded><![CDATA[<p>When we first held AppSec DC in 2009, I had just come back from a two-year jaunt (job-wise) away from the world of information security. I’d long been a proponent of the fact Washington DC should have the best Information Security community in the world. I didn’t want to lose touch with either the DC or the greater InfoSec community while I was dabbling in online collaboration and presence, so I made a point of focusing on participating in community outside of work, and became active in a variety of meet-ups and organizations across different technology sectors. AppSec DC was a chance to try to cross boundaries, and get people from many different communities talking in the same conversation about Application Security.</p>
<p>&nbsp;</p>
<p>One of the important missions that the OWASP board charged us with for the first AppSec DC was to reach out to the federal government, to try to establish channels for dialog, and put forth all that OWASP has to offer. Even though it is based in the DC locale, the US Government has national and global implications in everything it does, so that’s not an insignificant mission. In working with our team putting the conference together, I realized two things: That although reaching out to the government would be a long term project, it was absolutely imperative in the emerging threat environment -– but also that there are a lot of people in DC outside of the federal government who also are having an amazing impact on technology, with much further reaches than just the surrounding area, and that we should include them as well.</p>
<p>&nbsp;</p>
<p>AppSec DC is now in its third iteration, and over the past three years, we have tried to make inroads to many parties in DC and beyond who should be involved in this dialog. We’ve solidified reaching out to the government, but we’ve also worked on reaching out to the startup and web community in DC. The Washington DC Metropolitan area has been a tech leader since the first dotcom boom, and even with hard economic times, the area is generating startups, new companies, and talent at an astonishing rate. To reflect that in our content, Dan Geer, CTO of In-Q-Tel, a government incubator for innovative research and development will be keynoting our conference this year. Ken Johnson and Matt Ahrens from Living Social will be discussing how they implemented an Application Security in an environment with 1500% growth in less than two years, and Neil Matatall from Twitter talking about an OWASP project he leads that helps developers write more secure code. Mobile applications are driving a lot of the next generation of the Internet. We will also have Jeff Six, O’Reilly author of “Application Security for the Android Platform,” as well as an entire track on Mobile Application Security, and training on a variety of topics that assist developer in all environments, be it how to develop secure mobile app, assess apps, or just how to code securely in general.</p>
<p>&nbsp;</p>
<p>This year, we are also trying to recognize a change that is happening inside of OWASP. In the past year, a need for an ampersand between the “Web” and “Application” has been made blatantly obvious. OWASP has long been generating content where 95% of it applies to all fields of application security, but some have dismissed it because of the word “Web” in the title. In an effort to support getting our message out to all application security practitioners, this year AppSec DC has expanded our offerings to include the world of Critical Infrastructure &amp; Control Systems.  We’ll be featuring presentations on how Application Security affects Smart Grid/AMI, ICS, and other pieces of Critical Infrastructure.</p>
<p>&nbsp;</p>
<p>While the scope of the conversation and its impact is increasing, we can’t really grow that dialog without more participants. We would like you to bring your voice to the table. As a non-profit, OWASP provides the training and conference at a fraction of comparable industry events, with ease of access at a state of the art facility in downtown DC. We hope that you will be able to join us this year, and for many years to come.</p>
<p>&nbsp;</p>
<p>Website: <a href="http://appsecdc.org/">http://appsecdc.org</a></p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=303</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blog Reboot, as well.</title>
		<link>http://onelittlewindow.org/blog/?p=280</link>
		<comments>http://onelittlewindow.org/blog/?p=280#comments</comments>
		<pubDate>Sun, 12 Feb 2012 15:48:11 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[blogging]]></category>
		<category><![CDATA[personal]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=280</guid>
		<description><![CDATA[You may be wondering where the heck that last post came from if you are one of the five people who still has this in your RSS feed. Well, I figured it&#8217;s time to do a blog reboot as well. Having seen the amazing outpouring of creativity around me recently amongst my friends and peers and people I observe, both in the traditional creative arts and in those fighting the good fight in the infosec world, I&#8217;ve often felt humble and insignificant. Words are the only real creative tool I&#8217;ve got &#8212; be they written or spoken, it&#8217;s my weapon ...]]></description>
			<content:encoded><![CDATA[<p>You may be wondering where the heck that last post came from if you are one of the five people who still has this in your RSS feed. Well, I figured it&#8217;s time to do a blog reboot as well. Having seen the amazing outpouring of creativity around me recently amongst my friends and peers and people I observe, both in the traditional creative arts and in those fighting the good fight in the infosec world, I&#8217;ve often felt humble and insignificant. Words are the only real creative tool I&#8217;ve got &#8212; be they written or spoken, it&#8217;s my weapon of choice, but as time has gone on, they are more and more unused on the public stage (outside of work, that is). So I&#8217;m just going to start putting them out there again. This blog used to be specifically focused on a few things, and some of them ended up being things I couldn&#8217;t really talk as much about as I wanted to &#8212; so it eventually silenced itself. I&#8217;m going to repurpose it for all things me (though Infosec is still high on the list).</p>
<p>I caught myself the other day giving a profound, eloquent, two hour synopsis of the state of internet consumers with regards to information security to someone&#8217;s aunt when we were sitting at the dining room table in their house. It came naturally, almost as a gut reflex &#8212; but at the same time, it required precious time and energy. I regarded it (and still regard it) as important to have done, but I wish I had recorded myself. I&#8217;ve always been a believer in thinking globally and acting localy &#8212; having a blog has always seemed an act of supreme ego &#8212; who really cares what you have to say &#8212; but if I&#8217;m going to put out that level of effort, why not try to communicate more broadly? Hell, if so many people who have useless things to say will do it, why not join back in as at least a voice of mediocre quality?</p>
<p>Words are my tool, but so few people really read for real anymore &#8212; that too bears consideration. It takes effort to create real words (even bad ones), and it takes effort to really read them as well. It&#8217;s easier to create and consume bite-style media in all forms, and be a living router in the meme-flow than to stop and voice or parse a true opinion. Or you&#8217;re doing it in a reflexive, responsive, spur of the moment forum in a media that forces the rules of ad-hoc conversation without preparation, but is asynchronous, and communicates non of the signals and nuances that come with in person conversation. People misinterpret, mischaracterize, act like asshats with impunity via the shield of distance and anonymity, Godwin&#8217;s law is revoked, and you move on to the next think to &#8220;like&#8221; or dislike.</p>
<p>WordPress seems the tool (for my words &#8212; get it?) to stick with for now &#8212; it&#8217;s amazing where this phenomenal framework has gotten to in terms of being a poor man&#8217;s content management system &#8212; empowering the internet masses who will spend the effort to learn a bit more than the average facebook user to make truly amazing things in a time frame that is actually practical to undertake in the modern world if you are not a full time developer. But really, I&#8217;m still attracted to the name &#8212; blogs are where real words go (in addition to a lot of crappy ones, yes) in the modern era &#8212; that or more archaic forms. But the power of new media can&#8217;t be ignored, so I probably need to jazz this thing up a little bit. We&#8217;ll see what comes. We have many conferences, projects, and trips ahead this year at our little household, hopefully there is room for some more words amidst it all.</p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=280</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Genesis Reboot at Synetic Theater</title>
		<link>http://onelittlewindow.org/blog/?p=277</link>
		<comments>http://onelittlewindow.org/blog/?p=277#comments</comments>
		<pubDate>Sun, 12 Feb 2012 15:47:05 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Theater]]></category>
		<category><![CDATA[Synetic]]></category>
		<category><![CDATA[Washington DC]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=277</guid>
		<description><![CDATA[Last night, we had the privilege of seeing Genesis Reboot at the Synetic Theater. In one word, it&#8217;s brilliant. The mention of Synetic often brings up superlatives amongst those who love them in the DC theatre community &#8212; and sometimes antipathy in those who don&#8217;t, who decry their theatre without words as being dance, not theatre (though I really argue that dance can tell stories just fine &#8212; as Synetic always proves. You see my side in the argument). Well, toss that argument aside, because theatre parents extraordinaire Paata &#38; Irina have allowed Ben Cunis, his brother Peter Cunis, and ...]]></description>
			<content:encoded><![CDATA[<p><a href="https://www.boxofficetickets.com/go/event?id=142635"><img class="alignright" title="Genesis Reboot" src="https://www.knuckleheads.net/link4/b29.jpg" alt="" width="200" height="275" /></a>Last night, we had the privilege of seeing <a title="Genesis Reboot" href="http://www.synetictheater.org/mainstage/genesisreboot.html" target="_blank">Genesis Reboot</a> at the <a title="Synetic Theater" href="http://www.synetictheater.org/" target="_blank">Synetic Theater</a>. In one word, it&#8217;s brilliant.</p>
<p>The mention of Synetic often brings up superlatives amongst those who love them in the DC theatre community &#8212; and sometimes antipathy in those who don&#8217;t, who decry their theatre without words as being dance, not theatre (though I really argue that dance can tell stories just fine &#8212; as Synetic always proves. You see my side in the argument). Well, toss that argument aside, because theatre parents extraordinaire Paata &amp; Irina have allowed Ben Cunis, his brother Peter Cunis, and other co-conspirators (such as Clint Herring from <a href="http://www.hamiltoncarver.com/cast-and-crew.php" target="_blank">Hamilton Carver</a> fame, among many other things), to do something that no one can argue is brilliant, original, theatre. And it even has words.</p>
<p>It was unsettling, after three seasons of going to see shows there, hearing actual dialog coming from that stage. It almost seemed a taboo being broken &#8212; you could almost feel the audience shifting with discomfort &#8212; that this was not right, that this was not what they came here for. But as it unfolded, and the discomfort of dialogue faded away, what came to life was amazing. Ben (who authored the script with his brother as well as directing the show) and his actors and designers took the power of the tradition of Synetic (there was no way, outside of the dialog, of ever thinking this was NOT one of their shows, from the staging, to the lighting, music, costumes, and of course the breathtaking ability of those actors to speak in the language of movement), and built something mighty on top of it with their words.</p>
<p>And it was not a small project &#8211; just re-imagining the creation myth of one of the worlds largest religions, that&#8217;s all &#8212; and doing so in a manner that portrayed that initial death of innocence in a manner many times more gut-wrenching than any church scripture could ever be. You leave the theater holding back tears, feeling punched in the gut, and yet grateful for having seen such a great creative transformation and journey. And, obviously, you want more.</p>
<p>This play is part of an experimental series by Synetic Theater. As such, it is only running for a VERY short time. I urge you to stop what you are doing right now, look at your calendar, and buy tickets immediately. Due to other bookings, I don&#8217;t think there is any way that they can hold it over, and after the crowd reaction last night, I&#8217;m hoping that it will be sold out for most of the run of the show. Do not miss this.</p>
<p>Show description here: <a href="http://www.synetictheater.org/mainstage/genesisreboot.html">http://www.synetictheater.org/mainstage/genesisreboot.html</a></p>
<p>Tickets here: <a href="http://www.synetictheater.org/mainstage/genesisreboot.html">https://www.boxofficetickets.com/go/event?id=142635</a></p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=277</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AppSec DC Update</title>
		<link>http://onelittlewindow.org/blog/?p=270</link>
		<comments>http://onelittlewindow.org/blog/?p=270#comments</comments>
		<pubDate>Fri, 02 Oct 2009 18:00:27 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[AppSecDC]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[OWASP AppSec]]></category>
		<category><![CDATA[web people]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=270</guid>
		<description><![CDATA[Most of my time these days is going into AppSecDC. So I thought I&#8217;d share a bit of a shameless plug here that I just sent out to the conference mailing list: People are registering, hotel rooms are being booked, classes are being enrolled in, and we&#8217;re just over a month out! First off, if you haven&#8217;t registered or approached us about volunteering yet, today is the LAST day for early bird registration. The link for registration is here Secondly, if you are interested in volunteering, and haven&#8217;t contacted us about it yet, please contact Jon Rose, who is handling ...]]></description>
			<content:encoded><![CDATA[<p>Most of my time these days is going into <a href="http://appsecdc.org" target="_blank">AppSecDC</a>. So I thought I&#8217;d share a bit of a shameless plug here that I just sent out to the conference mailing list:</p>
<p>People are registering, hotel rooms are being booked, classes are being enrolled in, and we&#8217;re just over a month out!</p>
<p>First off, if you haven&#8217;t registered or approached us about volunteering yet, today is the LAST day for early bird registration.</p>
<p>The <a href="http://guest.cvent.com/i.aspx?4W,M3,26bc4c77-e1ef-4bad-be46-eb7b0124276c" target="_blank">link for registration is here</a></p>
<p>Secondly, if you are interested in volunteering, and haven&#8217;t contacted us about it yet, please contact <a href="mailto:jroseATowaspDOTorg">Jon Rose</a>, who is handling the volunteer coordination these days. He will be sending out a volunteer information packet in the next few days that should have answers to some of your questions, and he should be able to hook you up with getting &#8220;signed up&#8221; for specific positions.</p>
<p>Also, got Web 2.0? If so, we&#8217;re out there, and need your help. Follow, join, repost, talk about, and all those other good things. Every bit of extra visibility gives people who don&#8217;t know about the conference a chance to join in and participate!</p>
<p>Follow <a href="http://twitter.com/AppSecDC09" target="_blank">@AppSecDC09</a> on Twitter!</p>
<p>Join the event on <a href="http://www.facebook.com/event.php?eid=131893746514" target="_blank">Facebook</a>, <a href="http://events.linkedin.com/OWASP-AppSec-DC-2009/pub/85151" target="_blank">Linked In</a>, or <a href="http://upcoming.yahoo.com/event/4207188/" target="_blank">Upcoming</a> !!</p>
<p>If you can, publish the event to your profile about it on whatever service, and tell your friends!</p>
<p>Look for more announcement soon. Next week, we&#8217;ll be highlighting some of the training options, and talking about what&#8217;s going on with our panels and some of our other events.</p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=270</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Podcast Love</title>
		<link>http://onelittlewindow.org/blog/?p=267</link>
		<comments>http://onelittlewindow.org/blog/?p=267#comments</comments>
		<pubDate>Thu, 01 Oct 2009 21:11:39 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[OWASP]]></category>
		<category><![CDATA[OWASP AppSec]]></category>
		<category><![CDATA[podcast]]></category>
		<category><![CDATA[web people]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=267</guid>
		<description><![CDATA[I (among others) are appearing in a few podcasts this week. Amrit Williams interviewed me for his &#8220;Beyond the Perimeter&#8221; podcast, where in several parts I discuss AppSecDC, OWASP, and web application security. The first of these is up today, the others will follow next Tuesday and Thursday. BTP is also on iTunes. Jim Manico, host of the wildly successful OWASP podcast, was nice enough to have a bunch of us over for some friendly banter about security inside the beltway a while back. You can hear that as of today, or if you subscribe through iTunes, you can get ...]]></description>
			<content:encoded><![CDATA[<p>I (among others) are appearing in a few podcasts this week.</p>
<p><a href="http://techbuddha.wordpress.com/" target="_blank">Amrit Williams</a> interviewed me for his &#8220;<a href="http://blogs.bigfix.com/beyondtheperimeter/" target="_blank">Beyond the Perimeter</a>&#8221; podcast, where in several parts I discuss <a href="http://appsecdc.org" target="_blank">AppSecDC</a>, <a href="http://www.owasp.org">OWASP</a>, and web application security. The <a href="http://blogs.bigfix.com/beyondtheperimeter/2009/09/29/episode-53-web-applications-need-security-too-part-1/" target="_blank">first of these is up today</a>, the others will follow next Tuesday and Thursday. BTP is also on <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=306107448" target="_blank">iTunes</a>.</p>
<p><a href="http://www.manico.net/">Jim Manico</a>, host of the wildly successful <a href="http://www.owasp.org/index.php/OWASP_Podcast" target="_blank">OWASP podcast</a>, was nice enough to have a bunch of us over for some friendly banter about security inside the beltway a while back. <a href="http://www.owasp.org/index.php/Podcast_42" target="_blank">You can hear that as of today</a>, or if you subscribe through <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=300769012" target="_blank">iTunes</a>, you can get it <a href="http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=300769012" target="_blank">there as well</a>. This features myself, Matt Fisher of <a href="http://www.piscis-security.com/" target="_blank">Piscis Security</a>, <a href="http://sintixerr.wordpress.com/" target="_blank">Jack Whitsitt</a>, Dan Philpott of <a href="http://fismapedia.org/index.php?title=Main_Page" target="_blank">Fismapedia</a> and <a href="http://www.guerilla-ciso.com/">Guerilla-CISO</a>. <a href="http://www.guerilla-ciso.com/archives/author/admin" target="_blank">Mike Smith</a> of <a href="http://www.guerilla-ciso.com/">Guerilla-CISO</a> just missed us, and will be on another episode coming out soon!</p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=267</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AppSec DC 2009 &#8212; Interview w/ NovaInfosecPortal</title>
		<link>http://onelittlewindow.org/blog/?p=262</link>
		<comments>http://onelittlewindow.org/blog/?p=262#comments</comments>
		<pubDate>Fri, 11 Sep 2009 15:27:14 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[General]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=262</guid>
		<description><![CDATA[You may have noticed a lot of blank space here recently. Most of that is due to focusing on the upcoming national OWASP conference, AppSecDC. I recently was interviewed by Erin Paquette of NovaInfosecPortal about the upcoming AppSec DC conference. The italics are me. The original article is here. NovaInfosecPortal has been nice enough to let me reproduce the interview on this blog as well. What can people expect from this year’s AppSec compared to previous years? AppSec, like a lot of OWASP and Web App Sec in general, is still growing into full maturity. This year’s AppSec will be ...]]></description>
			<content:encoded><![CDATA[<p>You may have noticed a lot of blank space here recently. Most of that is due to focusing on the upcoming national OWASP conference, AppSecDC.</p>
<p>I recently was interviewed by Erin Paquette of <a href="http://www.novainfosecportal.com/" target="_blank">NovaInfosecPortal</a> about the upcoming AppSec DC conference. The italics are me.</p>
<p>The original article is <a href="http://www.novainfosecportal.com/2009/09/09/interview-about-appsec-dc-with-owasps-doug-wilson/" target="_blank">here</a>. NovaInfosecPortal has been nice enough to let me reproduce the interview on this blog as well.</p>
<p><strong>What can people expect from this year’s AppSec compared to previous years? </strong></p>
<p><em>AppSec, like a lot of OWASP and Web App Sec in general, is still growing into full maturity. This year’s AppSec will be the biggest conference that OWASP has done to date, and probably the biggest Web Application Security conference in the world. Bigger is not always better, but I think that the size and scope this year have allowed us to get a real wealth of speakers and talent to take part in this event. The conference itself hasn’t been influenced by events in Washington, so much as current events influenced the choice by OWASP to have the event IN Washington itself. The OWASP board charged us with creating a quality conference, which they would have done regardless of location, but they especially targeted the DC Metropolitan area because of the many things that OWASP has to offer to the federal government, combined with the rapidly emerging importance of Web AppSec to the federal space at the same time.</em></p>
<p><em>Cyber Security is a big concern across the boards inside the beltway, but let’s face it — network security is a more mature field. There are more solutions and people ready to provide those solutions on that front, whereas the Web App Sec field is still somewhat immature in the federal space. Thus an organization such as OWASP that is developing practical tools and guides that can be used to build solutions for little or no cost in that space is invaluable to the government . . . if the government is aware that it is there, and how it can be utilized. We really hope that a lot of federal decision makers, at high and low levels, take advantage of the opportunity of having OWASP’s national gathering right in the middle of DC, so they can become acquainted with what we have to offer.</em></p>
<p><strong>Is AppSec still looking for volunteers? If so, what do you need the most help with, and how should people go about getting involved?</strong></p>
<p><em>AppSec is always looking for volunteers. OWASP is a non-profit, and aside from specific vendors hired to come in and fulfill some contracts (such as catering), almost none of the people working the conference from the OWASP side will be paid. We are doing it because we are passionate about what OWASP stands for, and because we want to pull off an excellent conference. We’ll need help to do that, and are looking for equally passionate people to help out.</em></p>
<p><em>What we mainly need is people to staff the days of the show: Obviously, this is a trade off, because if you are working the show, you will miss out on part or all of the content that attendees get to appreciate, but you will be helping the event happen, and without that, no one would get to see the content. All of the organizers and our “Arch Minions” as we have taken to calling them (lead volunteers) are willing to make that sacrifice. However, we will have many positions that need filling that can be staffed for part of the conference, and we invite people who want to help out, or who want to see only part of the conference on the cheap to sign up and help make this event happen. You’ll get the opportunity to see some of the talks, and work the rest of the event. We’ll need folks for registration, badge checking, speaker and trainer assistance, facilities liaisons, and much more. If you are interested, you can contact myself or one of the other organizers via our OWASP emails (fairly easy to dig up), or by emailing infoATappsecdcDOTorg.</em></p>
<p><em>Another thing we will always need more of are sponsors. Sponsorships are important to the depth of our conference. Without sponsors, we can still provide the fundamental conference, but sponsorship dollars help OWASP and help us put on a better conference, with more perks and benefits for the attendees, which make for a more enjoyable overall experience. So every additional sponsor we sign up will add to the quality of the experience for everyone attending. If you are interested in sponsoring, or know an organization that would be a good fit, please <a href="http://www.owasp.org/index.php/Main_Page">contact us</a>.</em></p>
<p><strong>While AppSec places a heavy focus on people who are already in the field, you also make AppSec open to students. What do you hope college students in particular will get out of AppSec, and how do you think it will influence them when they graduate and enter the field?</strong></p>
<p><em>The biggest thing I think that anyone wants to get out of a conference like AppSec is to learn new things, and interact with other people who are knowledgeable in their field. I think that that is also a lot of what drives students in any discipline, and AppSec will provide an excellent learning environment to properly motivated individuals. My hope is that we will attract people who are developers and are curious about security, or people who are studying a standard IS/IT/IA track and want to learn more about application security. One of the most powerful people for making effective change in application security in any organization is a security conscious developer. Right now, that’s a rare animal, but someone who has development skills and security knowledge has the best of both worlds, and is in a very good position to look for great career opportunities, even in a “down market.” My hope is that we can take people who are aware of the concept of security, but haven’t really prioritized it, and make them re-evaluate how important it is, and eventually just include it in how they go about creating applications in the future. That’s the ultimate goal of Web App Sec, really — having a world where all developers are security conscious, and security is considered from the first inkling of putting a project together.</em></p>
<p><em>Recently, Mark Bristow (another organizer) and I gave a talk at the DC PHP Users Group on Web Application Security 101, and how the OWASP Top Ten applied to it. We got a fairly warm reception, and I felt good about it. But a week or so later, I was at a store near the University of Maryland College Park campus, and someone stopped me coming out the door. It was a person who had seen the talk at the DC PHP group — but was also a CS student at Maryland. He was really excited about the talk, and really wanted to know more, and to attend the conference. That made me feel much better than just “good” — that one bit of outreach had possibly taken someone who was going into the field of application development, and made them aware of something that could reshape their entire career for the better. We had made them start to prioritize security in what they did, and having them be excited about it on top of it. That’s awesome! I think that’s why we want to encourage students, and that’s what they can get out of it above and beyond what they learn at the training or talks.</em></p>
<p><em>In the press release for this year’s AppSec, you say “AppSec DC is a unique opportunity for federal decision makers and key technologists to become familiar with OWASP and the resources it has to offer.” AppSec has a heavy mix of both private and public sector speakers this year. Why do you feel it is especially timely for the private and public sectors to learn where each other is coming from?</em></p>
<p><em>One of the things about Web Application Security is that it’s a really big problem to try and solve. It affects everyone who uses the internet, and potentially even those who don’t. At a time where the government is trying to tackle the gigantic issues of protecting National Critical Infrastructure and securing IT resources across the government, the main access method to both control of infrastructure and information (i.e. the “Web”) is the most important thing to focus on. Only by working together and collaborating will we be able to make inroads on this massive problem, and both sides have resources that the other do not.</em></p>
<p><em>If we wait for the government to figure out all the expertise that has been developed in the private sector, or if we wait for the private sector to have the reach and impact of the government, we’re doomed. However, if the government reaches out to  the public and private companies and groups (such as OWASP) who are already focused in this area, it can be a winning situation all round. The government (and the citizens!) of many countries, not just the United States, can have more confidence in the stability of their infrastructure and their government resources, while the governments provide growth opportunities for companies and organizations that provide the expertise. I think that every day we do NOT have this sort of collaboration in place is one where we get further and further away from the constantly moving target of creating more secure web applications for all walks of life.</em></p>
<p><strong>You also go on to say that, “OWASP’s mission and community align closely with the goals set forth by the US Chief Information Officer: transparency, engagement of staff, reduction of cost, and innovation in technology. OWASP can enable the government to attain these goals in the pursuit of securing critical technologies that depend on the web.” Which tracks at this year’s AppSec would you recommend for government employees who want to reach the goals you outlined?</strong></p>
<p><em>It really depends on the employees role within the government. I like to feel that we have something for everyone. For those who are new to OWASP, and/or those who focus on high level decision making, we have several tracks that talk about some of our core ideas, as well as steps to apply security at a process or management level. Tracks such as the OWASP and the SDLC track on the first day, and the Process, Metrics, and Compliance track on the second day all have a wide variety of talks that will provide value to decision makers, managers, and development team leaders, or anyone who wants to get an overview of how you can apply good web application security practices to your organization’s current efforts. Conversely, we’re not letting our technical specialists down. The Tools track, the Web 2.0 track, the OWASP track, The Attack and Defend track, and pieces of all the other tracks will appeal to engineers who are developing or attacking applications and want to know what’s new and on the cutting edge. A large number of our speakers are experienced presenters, with previous talks at AppSec, Black Hat, Defcon, Shmoocon, and others under their belts.</em><br />
<strong><br />
Do you feel that some of the training courses offered on the 10th and 11th would be good for government employees who want to learn about application security more deeply, but might not have a technical background?</strong></p>
<p><em>Again, it will depend on their role. We have good courses for technical and non-technical people who are interested in Web App Sec. For leaders and managers, we have the Threat Modeling Express course from Security Compass, and Leading the Development of Secure Applications from Aspect Security. Both of those courses are designed for non-technical decision makers, and both are being taught by experts from top companies in the field. If an attendee is interested in learning a bit more about the technical process, we have a variety of courses deal with “how to learn to test” in various arenas, such as the Samurai Web Testing Framework class from Inguardians, and the Applying the OWASP Testing Guide with the OWASP Live CD course taught by Matt Tesauro (creator and project lead on the Live CD). These courses will probably require a little more technical knowledge, but will teach some of the fundamentals of how to test a web application and walk users through some of the steps involved in the process.</em></p>
<p><strong>And lastly, what would you say to those who are still sitting on the fence about attending AppSec? </strong></p>
<p><em>I’d say that this is a great opportunity for everyone interested or affected by Web Application Security, but especially those located near Washington DC. DC has a huge population of people who are interested in security, and an even bigger population who should be and are affected daily by decisions that are made (or not made) regarding security. AppSecDC offers a very inexpensive, extremely valuable learning and networking opportunity which is unlike anything else ever offered in the District. If you are not from DC, it’s a chance to come and see the infosec climate in the Nation’s Capital, and interact with government employees and those who work with them, at the same time listening to and learning from some of the top minds in Web Application Security from around the world. This is the biggest OWASP event, and likely the biggest Web Application Security Event ever held. Considering the price tag (especially with OWASP membership discount and early bird registration discounts), it should be a very simple decision when you see the value that you will get for your investment.</em></p>
<p><em>As an additional incentive to out of towners, our location is right in the middle of downtown at the Walter E. Washington Convention Center, and our host hotel, the Grand Hyatt Washington has been nice enough to extend our convention rate through the weekend, so if you are coming in from out of town, you can stay the weekend and see the sites of the nation’s capital as well.</em></p>
<p>Please go check out the AppSecDC Website at http://appsecdc.org , and let me know if you have any questions.</p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=262</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CapSec and OWASP DC</title>
		<link>http://onelittlewindow.org/blog/?p=257</link>
		<comments>http://onelittlewindow.org/blog/?p=257#comments</comments>
		<pubDate>Tue, 28 Jul 2009 16:58:19 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[CapSecDC]]></category>
		<category><![CDATA[OWASP]]></category>
		<category><![CDATA[web people]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=257</guid>
		<description><![CDATA[CapSec&#8217;s &#8220;Not at Black Hat&#8221; Edition is tomorrow night at Stetsons&#8217;s. You can come down and pretend you&#8217;re at the reception &#8212; the drinks are more expensive but the food is cheaper (if you consider the cost to get in the door). CapSec DC Wednesday July 29th 5:00 PM Stetson’s 1610 U St NW Washington DC 20009 Next Wednesday, OWASP DC will be having  chapter meeting at GWU. Dan Cornell of the Denim Group will be speaking on Vulnerability Management in an Application Security World, and Mike Smith of Deloitte will be speaking on SCAP and integration with Web Application ...]]></description>
			<content:encoded><![CDATA[<p>CapSec&#8217;s &#8220;Not at Black Hat&#8221; Edition is tomorrow night at Stetsons&#8217;s. You can come down and pretend you&#8217;re at the reception &#8212; the drinks are more expensive but the food is cheaper (if you consider the cost to get in the door).</p>
<p><a href="http://upcoming.yahoo.com/event/3082240/" target="_blank"><strong>CapSec DC<br />
Wednesday July 29th 5:00 PM</strong></a></p>
<p><strong><a href="http://www.washingtonpost.com/ac2/wp-dyn?node=cityguide/profile&amp;id=792265" target="_blank">Stetson’s</a><br />
<a href="http://maps.google.com/maps?q=1610+U+St+NW+Washington+DC+20009&amp;ie=UTF8&amp;oe=utf-8&amp;z=16&amp;iwloc=addr" target="_blank">1610 U St NW<br />
Washington DC 20009</a></strong></p>
<p>Next Wednesday, OWASP DC will be having  chapter meeting at GWU. Dan Cornell of the Denim Group will be speaking on Vulnerability Management in an Application Security World, and Mike Smith of Deloitte will be speaking on SCAP and integration with Web Application Security. I&#8217;ll also be giving an update on the upcoming AppSec DC 2009, which is only a few months away now!</p>
<p><a href="http://upcoming.yahoo.com/event/4129351/" target="_blank">OWASP DC August Meeting<br />
Wednesday August 5, 2009 at 6:30pm</a><br />
George Washington University, Duques Hall Rm 553D<br />
<a href="http://maps.google.com/maps?q=2201+G+St.+Washington,+District+of+Columbia+20037&amp;oe=utf-8&amp;client=firefox-a&amp;ie=UTF8&amp;split=0&amp;gl=us&amp;ei=5C1vSuWTOJW8NrPXgdUI&amp;z=16&amp;iwloc=A" target="_blank">2201 G St.<br />
Washington, District of Columbia 20037</a></p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=257</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Not At Black Hat? &#8212; CapSec DC</title>
		<link>http://onelittlewindow.org/blog/?p=252</link>
		<comments>http://onelittlewindow.org/blog/?p=252#comments</comments>
		<pubDate>Wed, 22 Jul 2009 21:34:52 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[CapSecDC]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=252</guid>
		<description><![CDATA[It appears that along with the Refreshes, Bar Camps, Meetups and Tweetups, a new craze is sweeping the nation. Convention attendance is down in light of the recession, and so many security practitioners who would normally be making the trip to Vegas this year to enjoy the wonders of Black Hat and DefCon are not. So, join us and them (in the DC Metro Area at least) at DC&#8217;s &#8220;Not at Black Hat/Not in Vegas&#8221; meetup, aka CapSec! Yes, we could have done something on the weekend, but with all that time free that you would have spent watching weirdos ...]]></description>
			<content:encoded><![CDATA[<p>It appears that along with the Refreshes, Bar Camps, Meetups and Tweetups, a new craze is sweeping the nation.</p>
<p>Convention attendance is down in light of the recession, and so many security practitioners who would normally be making the trip to Vegas this year to enjoy the wonders of Black Hat and DefCon are not.</p>
<p>So, join us and them (in the DC Metro Area at least) at DC&#8217;s &#8220;Not at Black Hat/Not in Vegas&#8221; meetup, aka CapSec! Yes, we could have done something on the weekend, but with all that time free that you would have spent watching weirdos and tourists in Vegas, I&#8217;m sure you&#8217;ve already planned something else.</p>
<p>It appears that someone in Atlanta <a href="http://www.andyitguy.com/blog/?p=786" target="_blank">already beat me to doing a blog post about this</a> although we had a save the date one on the <a href="http://capsecdc.org/blog/2009/07/16/capsec-july-not-in-vegas-edition/" target="_blank">CapSec blog last week</a>. <a href="https://twitter.com/rybolov" target="_blank">@rybolov</a> mentioned it first for DC on twitter, he should get props too.</p>
<p>CapSec DC, special &#8220;Not at Black Hat&#8221; edition:</p>
<p><a href="http://upcoming.yahoo.com/event/3082240/" target="_blank"><strong>CapSec DC<br />
Wednesday July 29th 5:00 PM</strong></a></p>
<p><strong><a href="http://www.washingtonpost.com/ac2/wp-dyn?node=cityguide/profile&amp;id=792265" target="_blank">Stetson’s</a><br />
<a href="http://maps.google.com/maps?q=1610+U+St+NW+Washington+DC+20009&amp;ie=UTF8&amp;oe=utf-8&amp;z=16&amp;iwloc=addr" target="_blank">1610 U St NW<br />
Washington DC 20009</a></strong></p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=252</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>CapSec DC for June. Same place, new time!</title>
		<link>http://onelittlewindow.org/blog/?p=250</link>
		<comments>http://onelittlewindow.org/blog/?p=250#comments</comments>
		<pubDate>Mon, 22 Jun 2009 20:07:16 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[CapSecDC]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=250</guid>
		<description><![CDATA[We&#8217;re going to try to start a little early this week for CapSec, so that some of the folks who get off gov jobs early can come by without having to spend all evening in the city. We’re going to start at 5 PM on the back deck, and we may migrate upstairs later, depending on how the evening is going. CapSec DC Wednesday June 24th 5:00 PM Stetson’s 1610 U St NW Washington DC 20009 Hope to see you there!]]></description>
			<content:encoded><![CDATA[<p>We&#8217;re going to try to start a little early this week for CapSec, so that some of the folks who get off gov jobs early can come by without having to spend all evening in the city.</p>
<p>We’re going to start at 5 PM on the back deck, and we may migrate upstairs later, depending on how the evening is going.</p>
<p><a href="http://upcoming.yahoo.com/event/2974640/" target="_blank"><strong>CapSec DC<br />
Wednesday June 24th 5:00 PM</strong></a></p>
<p><strong><a href="http://www.washingtonpost.com/ac2/wp-dyn?node=cityguide/profile&amp;id=792265" target="_blank">Stetson’s</a><br />
<a href="http://maps.google.com/maps?q=1610+U+St+NW+Washington+DC+20009&amp;ie=UTF8&amp;oe=utf-8&amp;z=16&amp;iwloc=addr" target="_blank">1610 U St NW<br />
Washington DC 20009</a></strong></p>
<p>Hope to see you there!</p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=250</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Web App Sec 101 tonight at DC PHP</title>
		<link>http://onelittlewindow.org/blog/?p=247</link>
		<comments>http://onelittlewindow.org/blog/?p=247#comments</comments>
		<pubDate>Wed, 10 Jun 2009 14:27:34 +0000</pubDate>
		<dc:creator>Doug Wilson</dc:creator>
				<category><![CDATA[web people]]></category>
		<category><![CDATA[Web Security]]></category>

		<guid isPermaLink="false">http://onelittlewindow.org/blog/?p=247</guid>
		<description><![CDATA[Mark and Doug will be speaking this evening, giving another version of our Web App Sec 101 talk, at the DC PHP Developer&#8217;s group: When: Wednesday, June 10th, 2009 @ 7:00 pm Where: 702 H Street, NW, Suite 300, Washington, D.C. 20001 It&#8217;s in the Greenpeace offices in Chinatown, I believe. Come by if you are interested, or in the area!]]></description>
			<content:encoded><![CDATA[<p>Mark and Doug will be speaking this evening, giving another version of our Web App Sec 101 talk, at the DC PHP Developer&#8217;s group:</p>
<p><strong></strong>When: Wednesday, June 10th, 2009 @ 7:00 pm<br />
Where: 702 H Street, NW, Suite 300, Washington, D.C. 20001</p>
<p>It&#8217;s in the Greenpeace offices in Chinatown, I believe.</p>
<p>Come by if you are interested, or in the area!</p>
]]></content:encoded>
			<wfw:commentRss>http://onelittlewindow.org/blog/?feed=rss2&#038;p=247</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

