<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Safelight Security Advisors &#187; Events</title>
	<atom:link href="http://safelightsecurity.com/news/category/events/feed/" rel="self" type="application/rss+xml" />
	<link>http://safelightsecurity.com</link>
	<description>Enabling organizations to proactively manage information security risks</description>
	<lastBuildDate>Thu, 26 Aug 2010 16:46:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>OWASP Boston Lighting Talk:  Cross Site Scripting, Reflected and Persistent</title>
		<link>http://safelightsecurity.com/news/2010/05/28/owasp-boston-lighting-talk-cross-site-scripting-reflected-and-persistent/</link>
		<comments>http://safelightsecurity.com/news/2010/05/28/owasp-boston-lighting-talk-cross-site-scripting-reflected-and-persistent/#comments</comments>
		<pubDate>Fri, 28 May 2010 17:12:06 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://safelightsecurity.com/?p=462</guid>
		<description><![CDATA[In the second installment of Safelight’s Lightning Talk series, Rob Cheyne will present the basics of cross-site scripting (XSS) at OWASP Boston.

He will cover the two primary methods of XSS attack, reflected and persistent, as well as provide detailed demonstrations that show how an attacker would use these methods in the real world. 
As part of [...]]]></description>
			<content:encoded><![CDATA[<p>In the second installment of Safelight’s Lightning Talk series, Rob Cheyne will present the basics of cross-site scripting (XSS) at <a href="http://www.owasp.org/index.php/Boston" target="blank">OWASP Boston</a>.

<p>He will cover the two primary methods of XSS attack, reflected and persistent, as well as provide detailed demonstrations that show how an attacker would use these methods in the real world.</p> 
<p>As part of the demo, Rob will go beyond proof of concept and present an example of a &#8220;weaponized&#8221; JavaScript that could be used to steal another user&#8217;s session information.</p> 
<p>Rob will also offer practical tips for defending against cross-site scripting flaws in your own applications.</p>
 
<p>When: June 2, 2010</p>

<p>Time: 6:30 p.m.</p>

<p>Where: Microsoft offices at the Waltham Weston Corporate Center, 201 Jones Rd., Sixth Floor Waltham, MA<p>

]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/05/28/owasp-boston-lighting-talk-cross-site-scripting-reflected-and-persistent/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safelight Headlines OWASP Boston with Monthly Lightning Talk Series</title>
		<link>http://safelightsecurity.com/news/2010/05/05/safelight-headlines-owasp-boston-with-monthly-lightning-talk-series/</link>
		<comments>http://safelightsecurity.com/news/2010/05/05/safelight-headlines-owasp-boston-with-monthly-lightning-talk-series/#comments</comments>
		<pubDate>Wed, 05 May 2010 19:33:01 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://safelightsecurity.com/?p=404</guid>
		<description><![CDATA[IT Security Education Key to Defending Against 
OWASP Top 10 Most Critical Web Application Vulnerabilities


In the first of the Safelight Security Advisors Lightning Talk Series, CEO Rob Cheyne will discuss “An Introduction to SQL Injection,” at the Open Web Application Security Project (OWASP) Boston chapter meeting, Monday, May 3.  

Rob will cover the methodology [...]]]></description>
			<content:encoded><![CDATA[<p><em>IT Security Education Key to Defending Against 
OWASP Top 10 Most Critical Web Application Vulnerabilities</p></em>


<p>In the first of the Safelight Security Advisors Lightning Talk Series, CEO Rob Cheyne will discuss “An Introduction to SQL Injection,” at the Open Web Application Security Project (OWASP) Boston chapter meeting, Monday, May 3.</p>  

<p>Rob will cover the methodology used by professional attackers, along with detailed demonstrations of one of the most common and dangerous OWASP Top 10 issues.</p>

<p>After demonstrating how SQL injection can be used to run system commands and gain root access on a database server, Rob will provide practical tips for defending against SQL injection flaws.</p>

<p>Safelight’s Lightning talks are designed for members newer to OWASP interested in understanding the basics of web application security, although everyone should feel free to attend.</p>

<p>When: 	
May 3, 2010, with subsequent meetings typically the first Wednesday of the month<p>
6:30 – 7:00 p.m. Networking
7:00 – 9:00 p.m. Main Presentations
<a href="https://lists.owasp.org/mailman/listinfo/owasp-boston" target="_blank">Join the Boston mailing list.</a> <p>


]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/05/05/safelight-headlines-owasp-boston-with-monthly-lightning-talk-series/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Join Us at the RSA 2010 Conference</title>
		<link>http://safelightsecurity.com/news/2010/02/19/join-us-at-the-rsa-2010-conference/</link>
		<comments>http://safelightsecurity.com/news/2010/02/19/join-us-at-the-rsa-2010-conference/#comments</comments>
		<pubDate>Fri, 19 Feb 2010 17:21:54 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=184</guid>
		<description><![CDATA[RSA 2010 Conference
March 1-3
Moscone Center
San Francisco, CA

Join Safelight at Booth #2058 to see the latest in information security training, including our newest online learning programs.  Attend our customer presentation, Banking on Security Education with State Street Bank’s Vice President Jeff Richard, and cocktail reception from 6:00 -8:00 p.m. at The St. Regis Hotel to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://rsaconference.com/2010/usa/" target="blank">RSA 2010 Conference</a></p>
<p>March 1-3</p>
<p>Moscone Center</p>
<p>San Francisco, CA</p>

<p>Join Safelight at <a href="http://www.mapyourshow.com/shows/index.cfm?Show_ID=RSA10" target="_blank">Booth #2058</a> to see the latest in information security training, including our newest online learning programs.  Attend our customer presentation, <a href="http://securityadvisors.com/rsaevent" target="_blank">Banking on Security Education</a> with State Street Bank’s Vice President Jeff Richard, and cocktail reception from 6:00 -8:00 p.m. at The St. Regis Hotel to hear how this leading financial institution rolled out a comprehensive security training program for thousands of developers worldwide.  You must <a href="http://securityadvisors.com/rsaevent">register for this event</a> in advance in order to attend.]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/02/19/join-us-at-the-rsa-2010-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Webcast: &#8220;New Technology Wearing Hand-Me-Down Vulns&#8221;</title>
		<link>http://safelightsecurity.com/news/2010/02/10/webcast-new-technology-wearing-hand-me-down-vulns/</link>
		<comments>http://safelightsecurity.com/news/2010/02/10/webcast-new-technology-wearing-hand-me-down-vulns/#comments</comments>
		<pubDate>Wed, 10 Feb 2010 21:51:17 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=115</guid>
		<description><![CDATA[Safelight’s CEO Rob Cheyne will present a webcast for the Microsoft SDL Pro Network community on “New Technology Wearing Hand-Me-Down Vulns,” February 25, 2010 from 1:00-1:30 p.m. EDT.  

Using a web service as an example, Rob will demonstrate how classic vulnerabilities can crop up in new technologies and how applying SDL principles can help [...]]]></description>
			<content:encoded><![CDATA[Safelight’s CEO Rob Cheyne will present a webcast for the Microsoft SDL Pro Network community on “New Technology Wearing Hand-Me-Down Vulns,” February 25, 2010 from 1:00-1:30 p.m. EDT.</p>  

<p>Using a web service as an example, Rob will demonstrate how classic vulnerabilities can crop up in new technologies and how applying SDL principles can help build secure systems.  <a href="https://www2.gotomeeting.com/register/469030554">Register</a> for the Webcast.  

]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/02/10/webcast-new-technology-wearing-hand-me-down-vulns/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safelight Named Member of Microsoft SDL Pro Network</title>
		<link>http://safelightsecurity.com/news/2010/02/02/safelight-named-member-of-microsoft-sdl-pro-network/</link>
		<comments>http://safelightsecurity.com/news/2010/02/02/safelight-named-member-of-microsoft-sdl-pro-network/#comments</comments>
		<pubDate>Tue, 02 Feb 2010 14:30:38 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=104</guid>
		<description><![CDATA[At BlackHat DC 2010, Safelight Security Advisors today became a training member of Microsoft’s Security Development Lifecycle (SDL) Pro Network. Microsoft created the SDL Pro Network to help development organizations adopt the SDL and address the challenges of embedding security and privacy into their software and development culture. As one of seven new members and [...]]]></description>
			<content:encoded><![CDATA[At <a href="http://www.blackhat.com/html/bh-dc-10/bh-dc-10-home.html" target="_blank">BlackHat DC 2010</a>, Safelight Security Advisors today became a training member of Microsoft’s Security Development Lifecycle (SDL) Pro Network. Microsoft created the <a href="http://www.microsoft.com/security/sdl/getstarted/pronetwork.aspx" target="_blank">SDL Pro Network</a> to help development organizations adopt the SDL and address the challenges of embedding security and privacy into their software and development culture. As one of seven new members and the only training company selected among the latest group, Safelight joins a select network of industry leaders specializing in application security with significant experience in secure development lifecycle methodologies.</p>

<p>“Microsoft is happy to have SafeLight join the SDL Pro Network.  We believe training is a cornerstone to the SDL and SafeLight can help train developers on secure coding practices,” said David Ladd, Principal Security Program Manager, Microsoft’s Trustworthy Computing Group.</p>

<p>As part of the SDL Pro Network, Safelight looks forward to continuing the mission of training students on a disciplined process that’s proven to reduce vulnerabilities and lower the total cost of development. Safelight’s instructor-led and online learning programs helps companies incorporate security best practices into their development initiatives, offering security education courses that cover all phases of the SDL:
<ul>
	<li>Introduction to the Microsoft Development Lifecycle</li>
	<li>Application Security Fundamentals</li>
	<li>Architecting Secure Systems</li>
	<li>Language-Specific &amp; Language-Agnostic Secure Coding</li>
	<li>Testing for Secure Systems</li>
	<li>Managing a SDL (for project managers and team leaders)</li>
	<li>Risks of Insecure Applications (for business owners and executives)</li>
</ul>
Visit Safelight’s SDL Pro Network page at <a href="http://securityadvisors.com/sdl" target="_blank">http://securityadvisors.com/sdl</a> to learn more about our offerings.</p>

Read Microsoft’s announcement on the new SDL Pro Network members in their <a href="http://www.microsoft.com/presspass/events/blackhat" target="_blank">press room.</a>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2010/02/02/safelight-named-member-of-microsoft-sdl-pro-network/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Rob Cheyne Presenting at CSI 2009</title>
		<link>http://safelightsecurity.com/news/2009/08/31/rob-cheyne-presenting-at-csi-2009/</link>
		<comments>http://safelightsecurity.com/news/2009/08/31/rob-cheyne-presenting-at-csi-2009/#comments</comments>
		<pubDate>Mon, 31 Aug 2009 20:52:05 +0000</pubDate>
		<dc:creator>Kim Novino</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=57</guid>
		<description><![CDATA[Safelight’s CEO Rob Cheyne will present, “Banking on Education: A Case Study on Developer Security” at CSI 2009 on Tuesday, October 27, 2009 from 9:45-10:45 a.m.

Learn how Safelight Security Advisors helped a major U.S. bank create security training for its internal developers: both employees and contractors located in multiple countries. Attendees will learn ways to [...]]]></description>
			<content:encoded><![CDATA[<p>Safelight’s CEO Rob Cheyne will present, “<a href="https://www.cmpevents.com/CSI36/a.asp?option=C&amp;V=11&amp;SessID=9826">Banking on Education: A Case Study on Developer Security</a>” at CSI 2009 on Tuesday, October 27, 2009 from 9:45-10:45 a.m.</p>

<p>Learn how Safelight Security Advisors helped a major U.S. bank create security training for its internal developers: both employees and contractors located in multiple countries. Attendees will learn ways to shift the mindset of this critical audience, leaving with ideas they can start to implement themselves.</p>

<p>CSI 2009 features a comprehensive program, covering 18 main topic areas, to provide the security knowledge needed to succeed in today&#8217;s environment. To attend, visit <a href="http://csiannual.com/">http://csiannual.com</a>.</p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/08/31/rob-cheyne-presenting-at-csi-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Business vs. Security: Let&#8217;s get ready to rumble!!!</title>
		<link>http://safelightsecurity.com/news/2009/03/09/business-vs-security-lets-get-ready-to-rumble/</link>
		<comments>http://safelightsecurity.com/news/2009/03/09/business-vs-security-lets-get-ready-to-rumble/#comments</comments>
		<pubDate>Mon, 09 Mar 2009 13:36:35 +0000</pubDate>
		<dc:creator>Rob</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[business]]></category>
		<category><![CDATA[community]]></category>
		<category><![CDATA[conference]]></category>
		<category><![CDATA[questions]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[source]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=50</guid>
		<description><![CDATA[I am currently preparing for the Business vs. Security panel that I am moderating at the Source:Boston conference on Wednesday, March 11th from 4:15-5:30pm.

You can read about it here .  Click the link that says &#34;The end of our rope: the ongoing tug-o-war between business and security&#34;, The gist is that we get two [...]]]></description>
			<content:encoded><![CDATA[<p>I am currently preparing for the Business vs. Security panel that I am moderating at the <a title="Source:Boston" href="http://sourceconference.com" target="_blank" title="Source:Boston">Source:Boston</a> conference on Wednesday, March 11th from 4:15-5:30pm.</p>

<p>You can read about it <a title="here" href="http://sourceconference.com/index.php/source-boston-2009/boston-2009-sessions" target="_blank" title="here">here</a> .  Click the link that says &quot;The end of our rope: the ongoing tug-o-war between business and security&quot;, The gist is that we get two business people and two security people together, and they discuss the finer points of managing business and security requirements in real-world environments.  Many of us have been there.  Security people have a notoriously difficult time convincing the business that security is important, and business folks are just trying to run the company and often view security as a speed bump.</p>

<p>I&#8217;m very excited to moderate this panel two years in a row.  It is relatively rare to get security and business people together at one table with the sole purpose of discussing how security impacts real-world decisions.  As they say on TV, &quot;Let&#8217;s get ready to rumble!&quot;</p>

<h2>How you can help</h2>
<p>Below are some examples of questions I could ask the panelists.  I have a much longer list, but I think it would be much more interesting to open this up to the security community.  So, given this opportunity, what questions would YOU like me to ask the panelists?</p>

Sample questions:
<ul>
	<li>When you are &#8217;selling&#8217; security, how do you get appropriate attention when you are talking about what MIGHT happen instead of things that ARE happening?  You are essentially asking people to spend money on a problem that &quot;THEY DON&#8217;T HAVE&quot;.  How do you justify the expense?</li>
	<li>Whose responsibility IS it to manage security?</li>
	<li>With security, it is possible to spend an unknown amount of money on an intangible problem.  What is the right amount to spend?</li>
	<li>As an industry, security people tend to NOT be very good at communicating security concepts to NON security people.   How do you communicate technical security concepts to business people in a way that they get it?</li>
</ul>

<p>See you at the conference!<br />
&#8211;rob</p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/03/09/business-vs-security-lets-get-ready-to-rumble/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Paul Hinkle presenting at SD West on March 13th</title>
		<link>http://safelightsecurity.com/news/2009/01/14/paul-hinkle-presenting-at-sd-west-on-march-13th/</link>
		<comments>http://safelightsecurity.com/news/2009/01/14/paul-hinkle-presenting-at-sd-west-on-march-13th/#comments</comments>
		<pubDate>Wed, 14 Jan 2009 18:31:00 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Events]]></category>
		<category><![CDATA[In the News]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=33</guid>
		<description><![CDATA[Banking on Education: A Case Study on Developer Security Training


Speaker:  Paul  Hinkle (Chief Technology Officer, Safelight Security Advisors)
Date/Time: Friday (March 13, 2009)   1:30pm — 3:00pm
Track: Security
Presentation Format: 90-minute Case Studies
Audience level: All


Presentation Abstract
Four years in the making, State Street Bank has created a pioneering security education program for its internal developers: [...]]]></description>
			<content:encoded><![CDATA[<h2>Banking on Education: A Case Study on Developer Security Training</h2>

<p>
<span class="bodytext"><strong>Speaker: </strong> <a class="bodytext" href="https://www.cmpevents.com/SDw9/a.asp?option=G&amp;V=3&amp;id=628826" rel="nofollow">Paul  Hinkle</a> (Chief Technology Officer, Safelight Security Advisors)</span><br />
<strong>Date/Time: </strong><span class="bodytext">Friday</span> (March 13, 2009)   1:30pm — 3:00pm<br />
<strong>Track: </strong><span class="bodytext">Security</span><br />
<strong>Presentation Format: </strong><span class="bodytext"><em>90-minute </em>Case Studies</span><br />
<strong>Audience level: </strong>All
</p>

<h3>Presentation Abstract</h3>
<p>Four years in the making, State Street Bank has created a pioneering security education program for its internal developers: both employees and contractors located in multiple countries. This case study will discuss how to properly implement an internal security training program. It will discuss the unique challenges State Street faced, how they were addressed, and the process the company went through to create a successful training program that is now mandatory for all staff involved in systems development worldwide.</p>

<p>Please email <a href="mailto:info@securityadvisors.com">info@securityadvisors.com</a> for a discount code to receive $100 off the lowest price.</p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2009/01/14/paul-hinkle-presenting-at-sd-west-on-march-13th/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Safelight Trains Government Security Leaders at Conference on California&#8217;s Future</title>
		<link>http://safelightsecurity.com/news/2008/05/05/safelight-trains-government-security-leaders-at-conference-on-californias-future/</link>
		<comments>http://safelightsecurity.com/news/2008/05/05/safelight-trains-government-security-leaders-at-conference-on-californias-future/#comments</comments>
		<pubDate>Tue, 06 May 2008 00:54:23 +0000</pubDate>
		<dc:creator>Mike</dc:creator>
				<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/?p=11</guid>
		<description><![CDATA[Paul Hinkle, Safelight CTO, will be presenting at the Conference on California's future on May 12-16, 2008...]]></description>
			<content:encoded><![CDATA[<h2>Educates IT and developers on latest threats and how to secure Web applications</h2>

<p><strong>What:</strong> <a href="http://www.govtech.com/events/silo.php?id=128081" target="_blank">Conference on California&#8217;s Future</a><br />
When: May 12-16, 2008
</p>

<p>Sacramento Convention Center<br />
1400 J Street Sacramento, California 95814</p>

<p><strong>Instructor:</strong> Paul Hinkle, CTO, Safelight Security Advisors</p>


<h2>Security Training</h2>

<h3><a href="http://www.govtech.com/events/class.php?id=128081&amp;event_id=261697" target="_blank">Threat Update</a></h3>

<p>Monday, May 12, 2008, 9:00 a.m. &#8211; 12:00 p.m.</p>
<p>Audience: IT network administrators and managers</p>
<p>The news is full of stories of stolen laptops, hacked databases and identity theft on a massive scale. From social engineering and spam, to directed attacks and virtualized rootkits, learn how different threats may impact the overall security posture of your organization. This half-day course brings you up to date with the latest attack methods, and anticipates some of the changes the industry expects in the near future.  <a href="http://www.govtech.com/events/class.php?id=128081&amp;event_id=261690"></a></p>

<h3><a href="http://www.govtech.com/events/class.php?id=128081&amp;event_id=261690" target="_blank">Securing your Web Applications</a></h3>
<p>Monday, May 12, 2008, 1:30 p.m. &#8211; 4:30 p.m.</p>
<p>Audience: application developers, project managers and business analysts</p>
<p>According to Acunetix (a vendor of Web application scanning tools), 70% of applications they reviewed contained high or medium ranked security vulnerabilities. Learn how to develop more secure applications using simple, repeatable steps. This introductory half-day session includes: demonstrations of key attacks, step-by-step analysis of those attacks and solid countermeasures that any development team can use in its Web environment.</p>
]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2008/05/05/safelight-trains-government-security-leaders-at-conference-on-californias-future/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Conference Mashups</title>
		<link>http://safelightsecurity.com/news/2008/04/10/conference-mashups/</link>
		<comments>http://safelightsecurity.com/news/2008/04/10/conference-mashups/#comments</comments>
		<pubDate>Thu, 10 Apr 2008 04:02:54 +0000</pubDate>
		<dc:creator>Amitabh Handa</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Events]]></category>

		<guid isPermaLink="false">http://www.securityadvisors.com/wp/?p=8</guid>
		<description><![CDATA[I am out at the RSA Conference this week, and like every year, I am stunned by...]]></description>
			<content:encoded><![CDATA[<p>I am out at the RSA Conference this week, and like every year, I am stunned by the number of product vendors selling &#8220;silver bullet&#8221; technology solutions to solve all of life&#8217;s security problems.  Seeing the make-up of the expo floor, you would think that you can just throw lots of technology at a problem in order to make it go away.  Given that real solutions always incorporate people, process and technology, it always amazes me that most vendors pretty much ignore the first two.<span id="more-8"></span></p>

<p>The talks are decent, but this year there are 17 tracks!!! It is incredibly difficult to figure out which talks to go to &#8211; and if you don&#8217;t get into a talk early enough, there is a strong possibility that you will get locked out (this has already happened to me twice!).  Apparently the fire marshall cracked down because standing in the back of the room is no longer allowed.</p>

<p>All this make me wish that there were more conferences like the Source conference in Boston.  Full disclosure &#8211; I am on the Source advisory board, so I am clearly biased!  However, Source was small, intimate, and you could actually interact with most of the attendees and speakers during the week.  The talks were as good if not better than anything I&#8217;ve seen out here so far.  In some ways it is like a combination of RSA and Black Hat talks.  There were excellent business talks like the CEO Panel, and there were also great technical talks like James Atkinson&#8217;s terrifying discussion of physical security issues and Roger Dingledine&#8217;s TOR talk.  And of course there was Dan Geer&#8217;s excellent keynote and the L0pht panel, which were the highlights of the show for me.  All in all, it really was a blast, and I can&#8217;t wait for next year&#8217;s Source conference.</p>

<p>In the meantime, I&#8217;ve been enjoying the &#8220;real&#8221; RSA conference, which takes place in the bars after hours.  Last night a ton of ex-@stake folks descended upon the Westin Market Street bar, a pre-cursor to Thursday night&#8217;s iSec event at Tres Agaves.</p>]]></content:encoded>
			<wfw:commentRss>http://safelightsecurity.com/news/2008/04/10/conference-mashups/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
