Steve Poole is a Developer Advocate, DevOps practitioner and a long time Java developer, leader and evangelist. He’s been working on Java SDKs and JVMs since Java was less than one year old.
Mother Nature vs Java - the security face off
Mother Nature has had millenia to build up it’s defences to the many potential hazards and attacks it may face. So given it’s wisdom and expertise on this subject, what can we as software developers learn from it and bring back to the evolution of our own application’s security? In this session we’ll explore where software and biology overlap when it comes to security and lessons we can learn from nature to improve our own application security.
Java and Ransomware - what’s in it for you?
Want to make some money? A little bitcoin on the side? In this session we’ll take you through a few of the ways that Ransomware works.
Java Security Jumpstart Workshop
Introductions
Cyber Attacks and the Developer
Introduction to the current state of cyber attacks. Motivations, objectives, methodologies.
Changing the mindset of the developer. Examples and discussions on how individuals, communities and open source projects get attacked and exploited.
Learning from the Log4Shell saga.
Hands-on demonstration, analysis and discussion of the many ways that the vulnerability can be exploited.
Better coding for more secure software
Series of hands-on exercises with sample code and discussion afterwards
Covers most of the 7 pernicious kingdoms
Dealing with Java serialisation
How serialisation works and how it’s exploited.
How to write safter Java code
Alternatives to Java Serialisation
Introduction to microstream with hands-on
Software Supply chain
New government directives that will affect how software is produced and consumed
The SBOM forcing function:
how open source communities are affected.
Why your build pipelines will need turbo-charging
Advanced guidance on selecting open source projects -its more than functionality
Hands-on review of related open-source tools that should be on your list now
Commercial interlude and why good intelligence is vital
Snyk / Sonatype portfolios
Wrap up