BEGIN:VCALENDAR
PRODID;X-RICAL-TZSOURCE=TZINFO:-//Calagator//EN
CALSCALE:GREGORIAN
X-WR-CALNAME:Calagator
METHOD:PUBLISH
VERSION:2.0
BEGIN:VTIMEZONE
TZID;X-RICAL-TZSOURCE=TZINFO:America/Los_Angeles
BEGIN:DAYLIGHT
DTSTART:20140309T020000
RDATE:20140309T020000
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
CREATED;VALUE=DATE-TIME:20140314T024221Z
DTEND;TZID=America/Los_Angeles;VALUE=DATE-TIME:20140402T193000
DTSTART;TZID=America/Los_Angeles;VALUE=DATE-TIME:20140402T180000
DTSTAMP;VALUE=DATE-TIME:20140314T024221Z
LAST-MODIFIED;VALUE=DATE-TIME:20140402T182951Z
UID:http://calagator.org/events/1250465836
DESCRIPTION:Kevin Dyer will be presenting:&#13\;\nHigh-Profile Password D
 atabase Breaches: A Tale of (Avoidable) Blunders&#13\;\n&#13\;\nOver the
  last few years\, password database breaches reported in mainstream&#13\
 ;\npress have increased in frequency and magnitude. There is a typical p
 attern&#13\;\nand service providers\, such as Adobe or Yahoo or Snapchat
 \, fail on at least&#13\;\ntwo fronts: first\, network perimeters and da
 tabases are breached and then\,&#13\;\nimproperly secured user data and 
 passwords are exfiltrated and shared in&#13\;\ncleartext. Even if the fo
 rmer can't be prevented\, there are security best&#13\;\npractices to mi
 tigate the impact of the latter\, which are (seemingly)&#13\;\nignored.&
 #13\;\n&#13\;\nIn this talk\, we'll discuss specific case studies and re
 view the essential&#13\;\nsecurity best practices for storing sensitive 
 user information. The goal is&#13\;\nto show that in every case free\, o
 ff-the-shelf tools are available\, that&#13\;\nwould have mitigated the 
 scope of the breach and (possibly) the onslaught&#13\;\nof negative publ
 icity. As one example\, we'll build intuition for why using&#13\;\nScryp
 t (a memory-hard function) is superior to traditional cryptographic&#13\
 ;\nhash functions for storing passwords.&#13\;\n&#13\;\n&#13\;\nKevin P.
  Dyer is a PhD student at Portland State University. His research&#13\;\
 nfocuses on network security and building protocols resistant to&#13\;\n
 traffic-analysis attacks and censorship. Previously\, Kevin worked as a&
 #13\;\nsoftware engineer in telecommunications security\, web security a
 nd network&#13\;\nsecurity. He holds an MSc in the Mathematics of Crypto
 graphy and&#13\;\nCommunications from Royal Holloway\, University of Lon
 don\, and a BS in&#13\;\nComputer Science with Mathematics from Santa Cl
 ara University.&#13\;\n&#13\;\n&#13\;\n&#13\;\nThe Open Web Application 
 Security Project (OWASP) is a 501c3 not-for-profit worldwide charitable 
 organization focused on improving the security of application software. 
 To sign up for future meeting notes and to discuss security topics with 
 local gurus\, sign up on the OWASP Portland mailing list: &#13\;\n&#13\;
 \n     https://lists.owasp.org/mailman/listinfo/owasp-portland&#13\;\n&#
 13\;\nMeetings are free and open to the public.\n\nTags: security\, owas
 p\, scrypt\, passwords\n\nImported from: http://calagator.org/events/125
 0465836
URL:https://www.owasp.org/index.php/Portland
SUMMARY:OWASP Chapter Meeting
LOCATION:Jive Software: 915 SW Stark St.\, Suite 400\, Portland Oregon 97
 205 United States
SEQUENCE:4
END:VEVENT
END:VCALENDAR
