Shostack + Friends Blog

 

Heading to San Francisco and ready to party for OWASP's 25th

Adrienne Dandy, Shostack + Associates

If by party, you mean obsess over European bureaucracy, train people in the ways of the Force.. umm, threat modeling, and talk about the book until our voices give out. A watercolor image of a robot and human at a San Francisco rooftop pool during a conference. The robot is about to dive in.

In early November, some of our favourite people will descend on San Francisco. OWASP is celebrating its 25th anniversary from November 2–6 at Global AppSec USA, and ThreatModCon is rolling in right behind it on November 6–7. Naturally, we’ll be at both, mostly because we physically cannot resist a room full of people talking about threats. Here's a sneak peek at what we can tell you about what we are (or hope to be) doing. (Spoiler, we'll have some follow-up announcements soon.)

Adam on the main stage, Friday, November 6 at 10:30 am
Adam presents CRA Will Be Cloud-Scale Engineering Change. The EU's Cyber Resilience Act is coming. If you want to sell products in Europe, you'll have to change your engineering processes and documentation in ways that might make you want to weep. If you’ve been treating the CRA as "something for the legal department to sort out," this is the exact hour to find out why you should reconsider that plan. Bring your questions and maybe a strong coffee.
A fireside chat (Minus the Actual Fire, Due to Hotel Permits), time and date TBA
Adam is also hoping to sit down to talk about essential learnings from more than a decade of progress in threat modeling, drawing on concepts central to the second edition of Threat Modeling: Designing for Security in an AI World (dropping in February, but available for preorder now if you like being ahead of the curve). We promise this isn't a shameless book pitch. It’s a genuine conversation about how much the field has fractured since the first edition, how to design securely when AI is actively trying to hallucinate your codebase away, and the questions practitioners keep screaming into the void.
Threat modeling training for an AI world, November 2-4
Of course, we're also looking forward to delivering Threat Modeling Intensive Using AI during OWASP. Covering how to Threat Model and also how to complement those skills with a variety of AI systems, this three-day course is ideal for folks in town for OWASP or Bay Area engineers wanting to master threat modeling.

OWASP's first 25 years are a beautiful story of volunteers arguing productively, writing things down, and giving away what they learn for free. It's the diving board for the pool of how the world talks about application security. Now, as we head into the next 25 years, we’re sharing that diving board with AI. Just please don't push any plugged-in neural nets into any actual water.

While we're here, a quick reminder to secure your spot for our training at OWASP!

Seats are still available for one of our most popular courses, Threat Modeling Intensive Using AI, held in association with OWASP. ICYMI, our software engineer Kris wrote last week about the value of the four-day version we taught at Black Hat.

Register today before the AI takes all the good seats!

Image by Midjourney: "Whimsical watercolor illustration of a hotel rooftop pool during a security conference, San Francisco skyline through glass walls behind, a diving board where a nervous small friendly robot in swim goggles and a conference lanyard stands at the very end, a human colleague in shorts and t-shirt wearing a lanyard beside it holding a towel, Impressionist colorism, watercolor style, clean lines, indigo purple, lime green, bright orange, and red orange palette. "