BSidesBoise 2024
We're back!
April 27, 2024
9am - 5pm
Doors open at 8:30
We have extremely limited reserved parking available. Because of the limited quantity, we've randomly selected a number of attendees for those spots and reached out to them specifically with parking information.
We are working on getting more parking, and if we are successful we will let you know immediately! Unfortunately, at the moment the closest parking available on Boise State campus is in the Lincoln Garage, unless you have a permit issued by the school to park elsewhere.
Lincoln Garage starts at $3/hour, and a full day is $25.
9:00 - 9:15 Opening Remarks
9:20 - 9:45 SOC: Zero to One, One to Many (25 min)
9:50 - 10:00 Break (10 min)
10:00 - 10:55 Home Networking Basics (55 min)
11:00 - 11:55 Introduction to Physical Security Attacks (55 min)
12:00 - 1:00 Lunch (60 min)
1:00 - 1:30 Break (Villages and Socializing) (30 min)
1:30 - 1:55 Cybersecurity Education Pathways in Idaho (25 min)
2:00 - 2:55 Practical AI for Small Business (55 min)
3:00 - 3:30 Break (30 min)
3:30 - 3:25 Unique Challenges of Health Care Cybersecurity (25 min)
4:00 - 4:55 Exploiting a Google 0-Day (55 min)
5:00 - 5:15 Closing Remarks
Open all day!
Soldering
Build a PC
Virtual CTF Challenge
Lock picking
David Green
9:20 - 9:55, 25 minutes
Slide deck available
Traditionally, a Security Operations Center is seen as a cost-center. It doesn't have to be this way. This talk will approach building a modern SOC that provides tangible (dollar) value to the business while also maintaining the standard of excellence security practitioners expect. It explores building a SOC from first principles in terms of capabilities, priorities, and processes that will lead to measurable outcomes you can use to prove the value provided.
BinBuddha
10:00 - 10:55, 55 minutes
Slide deck available
WiFi optimization and cabling to selecting the right router hardware, coupled with practical tips for securing and enhancing your network's performance. Additionally, we'll touch on integrating Home Assistant for home automation, ensuring your smart home is both efficient and secure. This condensed overview aims to provide attendees with a foundational understanding of home networking and the steps to take towards a smarter, more secure home environment.
Shelby Spencer
11:00 - 11:55, 55 minutes
Slide deck available
Join Shelby Spencer, a seasoned Red Teamer with over a decade of industry experience, in an informative talk at the upcoming security conference. This presentation delves into prevalent physical security vulnerabilities that are common within commercial environments, featuring live demonstrations of these exploits using a miniaturized security door. The talk focuses on high-impact, high-success, low-skill style attacks, and the session aims to equip physical red-teamers and businesses with crucial awareness of these attacks. In addition to showcasing attacks, Spencer will address proactive defensive measures that companies can adopt to thwart these threats. Don't miss this opportunity to enhance your understanding of practical security concerns and fortify your organization against potential breaches.
Dr. Sin Ming Loo
1:30 - 1:55, 25 minutes
Slide deck available
You are interested in cybersecurity. How do you get started? What kinds of informal learning are available? What about certifications? Are there formal cybersecurity education pathways that lead to degrees? Join me to learn about cybersecurity education pathways.
Noah Riley
2:00 - 2:55, 55 minutes
In this session, I will delve into how small businesses can practically apply AI technologies. Attendees will gain insights on adopting AI to improve efficiency and competitiveness, focusing on general strategies for easy integration and long-term benefits. I will also discuss overcoming common barriers to AI adoption in a small business setting.
Rob Fischer
3:30 - 3:55, 25 minutes
A brief presentation discussing the unique challenges of health care cybersecurity including the tension between HIPAA compliance and staff usability; older devices outside of mainstream patching and support; and the critical consideration of patient safety as a counterbalance to quarantining efforts.
Aeden Murray
4:00 - 4:55, 55 minutes
Shadowscape researchers found and were able to successfully exploit a 0-day in Google Looker that allowed RLS bypassing. Would be interesting to share the approach and correspondence process between Google.
A huge thank you to Boise State University for providing the venue!