![]() |
Past WASP Events November 3, 2009 2:00 pm - 3:20 pm The Autumn quarter WASP event will feature a talk on securing AJAX applications and one on recent security research that includes security considerations for medical devices. Securing AJAX ApplicationsCharlie Reis, GoogleDeveloping secure web applications can be hard, and AJAX can make it harder. This talk will provide an overview of several key topics web developers should know about to avoid common vulnerabilities, from XSS and CSRF to threats posed by JSON. I'll cover basic techniques for defending against these attacks, as well as a few advanced topics emerging from recent research. Bio: Charlie Reis finished his PhD at UW CSE in 2009, and he is now working at Google's Seattle office on Google Chrome. His research focuses on improving web browsers for safely running web-based programs. Tadayoshi Kohno, University of WashingtonTadayoshi Kohno, University of WashingtonImplantable medical devices, such as pacemakers and implantable cardiac defibrillators, can save lives and greatly improve a patient's quality of life. But what are the security considerations about IMDs that signal wirelessly and live inside of a human being? Some of the revelations are surprising-- and chilling. Professor Kohno will talk about his work in this area as well as other security related research. Bio: Tadayoshi Kohno is an Assistant Professor in Computer Science and Engineering. His primary research interests are in computer security and privacy. October 31st, at 2:00, 2008 - 2:00 pm - 4:00 pm For those who missed it, or asked questions that never got answered, please have a look at the public access wiki page, WASP "Threat Modeling" Presentation and Discussion, that I (Anne Hopkins) just put together at https://wiki.cac.washington.edu/x/2Jvi When: Wednesday March 18, 2009 - 2:30 pm The Web Grades Submission project team performed a uniquely thorough Security Review and Threat Analysis of the sensitive and powerful new online Web Grades system. Anne Hopkins, who led the Web Grades Security effort, will:
Securely publishing to MyUW October 31st, at 2:00, 2008 - 2:00 pm - 4:00 pm
Talks:
How Catalyst got out of its identity quagmire using shibbolethWhen: Wednesday March 26, 2008 - 1:30 pm - 3:30 pm
A joint presentation by Catalyst developers and developers from UW Technology's Identity and Access Management group (formerly known as C&C Security Middleware). The presenters will tell their identity management story and how they came to use Shibboleth as their authentication technology. For more information on shibboleth, refer to: http://shibboleth.internet2.edu/
Live! Somebody gets 0wn3d!When: Monday December 10, 2007 - 1:30 pm - 3:30 pm
IOActive will perform a live penetration test of a real UW web application, kindly provided by the department of Academic Personnel Information. The team will then show developers how to fix the problems and learn how to avoid common programming errors with the help of the WASP secure coding guidelines and the upcoming WASP secure code repository. Optional 1 hour session immediately following the above (same location) "Ask the hacker" Q&A session and a chance for face to face interaction with fellow attendees.Click here for the presentation slides from the event. About the WASPWhat is WASP?The Web Application Security Peer Working Group (WASP) is a cross-campus group established under the Office of Information Management to address Web application security at the University of Washington. The WASP aims to become a leader for web application security at the UW and to help push the UW to become a web application security leader within the greater education technology community. |