<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=MichaelCoates</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=MichaelCoates"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/MichaelCoates"/>
		<updated>2026-05-20T07:32:53Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=230172</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=230172"/>
				<updated>2017-06-01T00:00:34Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Our next  event */ Updated events and leaders&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Bay Area Chapter Board = &lt;br /&gt;
Interested in finding out more? Will contact your with information on the first in person chapter board discussion in San Francisco&lt;br /&gt;
&lt;br /&gt;
Submit your info here: https://goo.gl/forms/ScPCPrlDiQaUZ6cs2&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit http://www.meetup.com/Bay-Area-OWASP/ for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
We hold regular events across the OWASP Bay Area. &lt;br /&gt;
&lt;br /&gt;
Check out our meetup page for upcoming events:&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*Travis McPeak - Chapter Leader &lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* William Bengtson &lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:United_States]]&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=May_9,_2017&amp;diff=229500</id>
		<title>May 9, 2017</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=May_9,_2017&amp;diff=229500"/>
				<updated>2017-05-09T17:06:34Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Meeting Location: &lt;br /&gt;
&lt;br /&gt;
'''VIRTUAL'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
Face to face meeting held in EWART room at the Belfast Hilton&lt;br /&gt;
&lt;br /&gt;
'''AGENDA'''&lt;br /&gt;
This is the VIRTUAL packet that is provided to everyone at the same time to review, make comments and be prepared for the meeting. There is no paper handout for the meeting.&lt;br /&gt;
&lt;br /&gt;
 CALL TO ORDER&lt;br /&gt;
&lt;br /&gt;
 CHANGES TO THE AGENDA&lt;br /&gt;
&lt;br /&gt;
 APPROVAL OF MINUTES&lt;br /&gt;
- Approval of prior [https://docs.google.com/document/d/1aPmftVZH3-G96J6-wrpynwwZhBHtREe5a7g8owVYUag prior meeting mins]&lt;br /&gt;
&lt;br /&gt;
 REPORTS&lt;br /&gt;
[https://drive.google.com/a/owasp.org/file/d/0BxI4iTO_QojvWFZTbFJ4SFEwX1hYUDNpSDYya3dZR2drOW9R/view?usp=sharing March 2017 Board Financial Summary]&lt;br /&gt;
&lt;br /&gt;
[https://drive.google.com/a/owasp.org/file/d/0BxI4iTO_Qojva19fV2tueUlrWTFoX2tDMVpFR0FWR2g2TDk0/view?usp=sharing March 2017 Summary Balance Sheet with Ratios] &lt;br /&gt;
&lt;br /&gt;
OWASP Foundation is managed by the [https://www.owasp.org/index.php/About_OWASP#Employees_and_Contractors Operations Director] who provides a monthly roll-up report in collaboration of all staff members, contractors and efforts being managed by the [https://www.owasp.org/index.php/About_OWASP#Employees_and_Contractors back office team.]  A link to the monthly operational report can be found here:  [https://owasp.blogspot.com/2017/05/owasp-operations-update-for-may-2017_5.html REPORT]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 OLD BUSINESS&lt;br /&gt;
&lt;br /&gt;
Affirmation of actions from last meeting [https://www.owasp.org/index.php/Board recorded material, votes and actions] [Board]&lt;br /&gt;
 NEW BUSINESS&lt;br /&gt;
* Community correspondence [Tom Brennan]&lt;br /&gt;
* [https://docs.google.com/document/d/1T7xJ35isxZDGxJbF1eVwpzAdkkD0Prwszy1kstxgZeU/edit Proposal to have Foundation run AppSecs].  [Matt Konda]&lt;br /&gt;
* Chapters guidance [TJ]&lt;br /&gt;
* Executive Director Search [Johanna Curiel]&lt;br /&gt;
* AppSec Global Events [Tom Brennan]&lt;br /&gt;
&lt;br /&gt;
* OWASP Summit request for 85K USD to get extra people to the summit and have a professional operations team in place (see email 8-May-2017). (Seba, Dinis, Francois)&lt;br /&gt;
* Owasp learning gateway $100k full time staff. - Hire full time staff member to build out the learning gateway. [https://docs.google.com/document/d/1fGDmxz7cuEkr_xMt_kp6Nb0uacQhvJ_9ymjYR77yqkk/edit]&lt;br /&gt;
* Owasp grant initiative $100k full time staff - Hire full time grant writer to work on grants for OWASP. [https://docs.google.com/document/d/1szWjXG_grUHZJryD_45XeC3DJF1qOifQjQRZxEJ5znY/edit]&lt;br /&gt;
* OWASP BLT development and marketing $5k, (12 monthly prizes of $100, $1200 + development) [https://docs.google.com/document/d/1aNyq43_gHq8cKMDGtlqTC6H-pv71lH7mNsMgg1WPpy4/edit]&lt;br /&gt;
* Owasp project kickstart. $10k - $100 to 100 projects to use Coderbounty on 2-5 of their Github tasks to get coding done. [https://docs.google.com/document/d/1ogGUjtHiSimzrnnXnEeCsAHn0qtAJ56S6cD7q_swlK4/edit]&lt;br /&gt;
* Owasp innovation lab $250k [https://docs.google.com/document/d/1J4lBJabLu8YWX6sDgwmGnfDP7tI2OVIH1jmkRnKyKrs/edit]&lt;br /&gt;
* Grant engine / Spurri $50k - development [https://docs.google.com/document/d/1payALh8RjuKAXi30m56hUiXgTzgYhuXm8B3QVqo1whU/edit]&lt;br /&gt;
* OWASP Hackathon sponsor $5k sponsor a hackathon with prizes and food for 2017 focused on OWASP [https://docs.google.com/document/d/13wCZgLugpjJS-5WcH3zn-n9ADZRke3GhNEP7EvjNi6Q/edit]&lt;br /&gt;
* Fundraiser events / membership drive $300 per month $3,600 - Have a monthly membership drive / fundraiser, $300 for food and drinks.[https://docs.google.com/document/d/1mZGhTo_tD_Ap-K-4qkI2sj8t8hPafzi6XVyVBrZ9Oac/edit]&lt;br /&gt;
* Volunteer portal project $50k - development of website.[https://docs.google.com/document/d/11o01Vw7tD6L9WKFIGmS8SKFr575V-aVUhNs61q1NORQ/edit]&lt;br /&gt;
* $30k for APAC tour $10k stipend for leaders Send 3 people with $10k stipend each. [https://docs.google.com/document/d/11o01Vw7tD6L9WKFIGmS8SKFr575V-aVUhNs61q1NORQ/edit]&lt;br /&gt;
* OWASP Mentor Initiative with HQ NY $6,000 [https://docs.google.com/document/d/1FS50Z9KUb-GKUG3GEMLfGT9SBxg6UfUuRiymO6ASqnQ/edit]&lt;br /&gt;
* OWASP Organizational Development Initiative with HQ Brooklyn $50,000 [https://docs.google.com/document/d/15kDHJRMkXIep27oB9YKLV7k51ErbafY5y8JKuc5g_f0/edit]&lt;br /&gt;
'''&amp;lt;u&amp;gt;OWASP ByLaw Update Proposal [JS]&amp;lt;/u&amp;gt;'''&lt;br /&gt;
&lt;br /&gt;
ByLaw amendment created by Josh Sokol, Bil Corry, and Jason Li.  Update [https://www.owasp.org/index.php/OWASP_Foundation_ByLaws Section 3.03 of the OWASP ByLaws] to read:&lt;br /&gt;
&lt;br /&gt;
... Attendance in person or virtually by board members is required at no less than 75% of the total meetings each year and shall be highly encouraged to meet in person at least once annually at a date to be announced and agreed upon. '''To be considered as &amp;quot;attended&amp;quot;, the board member must attend at least 90% of the meeting, starting at the published scheduled time until the published end time or the meeting is adjourned (whichever is earlier).''' Attendance is tabulated by the Executive Director or delegate within seven days after every scheduled meeting for the purpose of determining if the 75% attendance requirement has been met, and the tabulation is based upon the entire calendar year. ...&lt;br /&gt;
&lt;br /&gt;
 COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 ADJOURNMENT&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_AppSensor_Project&amp;diff=229018</id>
		<title>OWASP AppSensor Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_AppSensor_Project&amp;diff=229018"/>
				<updated>2017-04-23T06:31:32Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: Fixed broken external link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:120px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Appsensor-header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=OWASP_Project_Stages#tab=Flagship_Projects]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP AppSensor ==&lt;br /&gt;
&lt;br /&gt;
The AppSensor project defines a conceptual framework and methodology that offers prescriptive guidance to implement [https://www.owasp.org/index.php/ApplicationLayerIntrustionDetection intrusion detection and automated response] into applications.&lt;br /&gt;
&lt;br /&gt;
The project offers a comprehensive guide and a reference implementation. These resources can be used by architects, developers, security analyst and system administrators to plan, implement and monitor an AppSensor system.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
If you walk into a bank and try opening random doors, you will be identified, led out of the building and possibly arrested. However, if you log into an online banking application and start looking for vulnerabilities no one will say anything. This needs to change!  As critical applications continue to become more accessible and inter-connected, it is paramount that critical information is sufficiently protected. We must also realize that our defenses may not be perfect. Given enough time, attackers can identify security flaws in the design or implementation of an application. &lt;br /&gt;
&lt;br /&gt;
In addition to implementing layers of defense within an application, we must identify malicious individuals before they are able to identify any gaps in our defenses. The best place to identify malicious activity against the application is within the application itself. Network based intrusion detection systems are not appropriate to handle the custom and intricate workings of an enterprise application and are ill-suited to detect attacks focusing on application logic such as authentication, access control, etc. This project delivers a framework which can be used to build a robust system of attack detection, analysis, and response within an enterprise application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Detect and Respond to Attacks from Within the Application ==&lt;br /&gt;
&lt;br /&gt;
=== Detection ===&lt;br /&gt;
AppSensor defines over 50 different detection points which can be used to identify a malicious attacker.&lt;br /&gt;
=== Response===&lt;br /&gt;
AppSensor provides guidance on how to respond once a malicious attacker has been identified. Possible actions include: logging out the user, locking the account or notifying an administrator. More than a dozen response actions are described.&lt;br /&gt;
===Defending the Application===&lt;br /&gt;
An attacker often requires numerous probes and attack attempts in order to locate an exploitable vulnerability within the application. By using AppSensor it is possible to identify and eliminate the threat of an attacker before they are able to successfully identify an exploitable flaw.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Citations==&lt;br /&gt;
&lt;br /&gt;
* [http://www.crosstalkonline.org/ CrossTalk], The Journal of Defense Software Engineering&lt;br /&gt;
** Creating Attack-Aware Software Applications with Real Time Defenses, Vol. 24, No. 5, Sep/Oct 2011&lt;br /&gt;
&lt;br /&gt;
* Norwegian University of Science and Technology in Tronheim&lt;br /&gt;
** [https://brage.bibsys.no/xmlui/handle/11250/252956 AppSensor: Attack-Aware Applications Compared Against a Web Application Firewall and an Intrusion Detection System], Thomassen P, 2012&lt;br /&gt;
&lt;br /&gt;
*US Department of Homeland Security&lt;br /&gt;
** [https://buildsecurityin.us-cert.gov/swa/topics/resilient-software/ Resilient Software]&lt;br /&gt;
** [https://buildsecurityin.us-cert.gov/swa/resources Software Assurance Resources]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP AppSensor is free to use. &lt;br /&gt;
&lt;br /&gt;
=== Guide ===&lt;br /&gt;
The guide is licensed under the [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
=== Reference Implementation ===&lt;br /&gt;
The reference implementation is licensed under the [http://opensource.org/licenses/MIT MIT License], which is a permissive (commercial-friendly) license only requiring you to include a copy of the license upon distribution or copying.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;copy; OWASP Foundation&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is AppSensor? ==&lt;br /&gt;
&lt;br /&gt;
Detect and respond to attacks from within the application. This project includes both a well documented idea (the Guide) and a reference implementation (the Code). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Intro for Developers ==&lt;br /&gt;
&lt;br /&gt;
[[File:Appsensor-developer-small.jpg|link=https://www.owasp.org/index.php/File:Appsensor_intro_for_developers.pdf]]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/File:Appsensor_intro_for_developers.pdf Two-sided US Letter or A4]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== AppSensor Website ==&lt;br /&gt;
&lt;br /&gt;
[[File:Appsensor-website-small.jpg|link=http://appsensor.org/]]&lt;br /&gt;
&lt;br /&gt;
See the [http://appsensor.org/ AppSensor website] for an introduction and quick start instructions.&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
[[File:Appsensor-cisobriefing-small.jpg|link=https://www.owasp.org/index.php/File:Appsensor-ciso-briefing.pdf]]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/File:Appsensor-ciso-briefing.pdf 12-page US Letter booklet]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Founder ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:MichaelCoates Michael Coates] [mailto:michael.coates@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves] [mailto:dennis.groves@owasp.org @]&lt;br /&gt;
* [https://www.owasp.org/index.php/User:John_Melton John Melton] [mailto:john.melton@owasp.org @]&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] [mailto:colin.watson@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[:Category:OWASP_ModSecurity_Core_Rule_Set_Project|OWASP ModSecurity Core Rule Set]]&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* OWASP AppSensor Guide v2 EN&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Owasp-appsensor-guide-v2.pdf PDF]&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Owasp-appensor-guide-v2.doc DOC]&lt;br /&gt;
** [http://www.lulu.com/shop/owasp-foundation/appsensor-guide/paperback/product-21608107.html Hard copy]&lt;br /&gt;
* OWASP AppSensor Reference Implementation&lt;br /&gt;
** [https://github.com/jtmelton/appsensor v2 Code]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* [25 Sep 2015] [http://appsecusa2015.sched.org/event/09495faf5cced352cb4a2acc16ce9158#.VaOSoHhfk2w Presentation] at AppSec USA 2015&lt;br /&gt;
* [27 Jul 2015] [https://www.owasp.org/index.php/File:Owasp-appensor-guide-v2.doc AppSensor Guide v2.0.2] published&lt;br /&gt;
* [09 Jun 2015] AppSensor Code v2.1.0 [https://github.com/jtmelton/appsensor/releases/tag/v2.1.0 released]&lt;br /&gt;
* [20 May 2015] Working session at [http://2015.appsec.eu/project-summit/ OWASP Project Summit] - Code&lt;br /&gt;
* [19 May 2015] Working session at [http://2015.appsec.eu/project-summit/ OWASP Project Summit] - Documentation&lt;br /&gt;
* [09 Apr 2015] [https://www.owasp.org/index.php/File:Appsensor-ciso-briefing.pdf CISO Briefing] booklet published&lt;br /&gt;
* [22 Feb 2015] Proposal for [https://www.owasp.org/index.php/GSoC2015_Ideas#OWASP_AppSensor Google Summer of Code 2015]&lt;br /&gt;
* [13 Feb 2015] [https://www.owasp.org/index.php/File:Appsensor_intro_for_developers.pdf Introduction for Developers] flyer published&lt;br /&gt;
* [13 Feb 2015] AppSensor project awarded OWASP flagship status&lt;br /&gt;
* [28 Jan 2015] AppSensor Code v2.0.0 final [https://github.com/jtmelton/appsensor/releases/tag/v2.0.0 released]&lt;br /&gt;
&lt;br /&gt;
== Code Repository ==&lt;br /&gt;
* AppSensor v2 https://github.com/jtmelton/appsensor (Current)&lt;br /&gt;
* Note: LEGACY AppSensor v1 https://code.google.com/p/appsensor/&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
[[File:AppSensor2_small.jpg|link=]]&lt;br /&gt;
&lt;br /&gt;
The [http://www.lulu.com/shop/owasp-foundation/appsensor-guide/paperback/product-22290600.html AppSensor Guide] and [http://www.lulu.com/shop/owasp-foundation/appsensor-ciso-briefing/paperback/product-22121723.html CISO Briefing] can be purchased at cost as print on demand books.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
== Volunteers ==&lt;br /&gt;
&lt;br /&gt;
All OWASP projects rely on the voluntary efforts of people in the software development and information security sectors. They have contributed their time and energy to make suggestions, provide feedback, write, review and edit documentation, give encouragement, make introductions, produce demonstration code, promote the concept, and provide OWASP support. They participated via the project’s mailing lists, by developing code, by updating the wiki, by undertaking research studies, and through contributions during the AppSensor working session at the OWASP Summit 2011 in Portugal and the AppSensor Summit at AppSec USA 2011. Without all their efforts, the project would not have progressed to this point, and this guide would not have been completed.&lt;br /&gt;
&lt;br /&gt;
{| cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
*Josh Amishav-Zlatin&lt;br /&gt;
*Ryan Barnett&lt;br /&gt;
*Simon Bennetts&lt;br /&gt;
*Joe Bernik&lt;br /&gt;
*Rex Booth&lt;br /&gt;
*Luke Briner&lt;br /&gt;
*Rauf Butt&lt;br /&gt;
*Juan C Calderon&lt;br /&gt;
*Fabio Cerullo&lt;br /&gt;
*Marc Chisinevski&lt;br /&gt;
*Robert Chojnacki&lt;br /&gt;
*Michael Coates&lt;br /&gt;
*Dinis Cruz&lt;br /&gt;
*Sumanth Damaria&lt;br /&gt;
*August Detlefsen&lt;br /&gt;
*Ryan Dewhurst&lt;br /&gt;
*Sean Fay&lt;br /&gt;
&lt;br /&gt;
   | align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
*Timo Goosen&lt;br /&gt;
*Dennis Groves&lt;br /&gt;
*Randy Janida&lt;br /&gt;
*Chetan Karande&lt;br /&gt;
*Eoin Keary&lt;br /&gt;
*Alex Lauerman&lt;br /&gt;
*Junior Lazuardi&lt;br /&gt;
*Benjamin-Hugo LeBlanc&lt;br /&gt;
*Jason Li&lt;br /&gt;
*Manuel López Arredondo&lt;br /&gt;
*Bob Maier&lt;br /&gt;
*Jim Manico&lt;br /&gt;
*Sherif Mansour Farag&lt;br /&gt;
*John Melton&lt;br /&gt;
*Mark Miller&lt;br /&gt;
* Rich Mogull&lt;br /&gt;
*Craig Munson&lt;br /&gt;
&lt;br /&gt;
   | align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
*Louis Nadeau&lt;br /&gt;
*Giri Nambari&lt;br /&gt;
*Erlend Oftedal&lt;br /&gt;
*Jay Reynolds&lt;br /&gt;
*Chris Schmidt&lt;br /&gt;
*Sahil Shah&lt;br /&gt;
*Eric Sheridan&lt;br /&gt;
*John Steven&lt;br /&gt;
*Raphael Taban&lt;br /&gt;
*Alex Thissen&lt;br /&gt;
*Don Thomas&lt;br /&gt;
*Christopher Tidball&lt;br /&gt;
*Stephen de Vries&lt;br /&gt;
*Kevin W Wall&lt;br /&gt;
*Colin Watson&lt;br /&gt;
*Mehmet Yilmaz&lt;br /&gt;
&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
==OWASP Summer of Code 2008==&lt;br /&gt;
The AppSensor Project  was initially supported by the [https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008 OWASP Summer of Code 2008], leading to the publication of the book AppSensor v1.1.&lt;br /&gt;
&lt;br /&gt;
==Google Summer of Code 2012==&lt;br /&gt;
Additional development work on [http://www.google-melange.com/gsoc/project/google/gsoc2012/edil/60002 SOAP web services] was kindly supported by the [http://www.google-melange.com/gsoc/program/home/google/gsoc2012 Google Summer of Code 2012].&lt;br /&gt;
&lt;br /&gt;
==OWASP Code Sprint 2015==&lt;br /&gt;
Development work was also supported by the [https://www.owasp.org/index.php/Summer_Code_Sprint2015 OWASP Summer Code Sprint 2015].&lt;br /&gt;
&lt;br /&gt;
== Other Acknowledgements ==&lt;br /&gt;
The project has also benefitted greatly from the generous contribution of time and effort by many volunteers in the OWASP community including those listed above, and contributors to the OWASP ESAPI project, members of the former OWASP Global Projects Committee, the OWASP Board, OWASP staff and support from the OWASP Project Reboot initiative. The v2 code and documentation were conceived during the AppSensor Summit held during AppSec USA 2011 in Minneapolis.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
Please join the project's mailing lists to keep up-to-date with what's going on, and to contribute your ideas, feedback, and experience:&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo/owasp-appsensor-project General project]&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo/owasp-appsensor-dev Code development]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Current activities ==&lt;br /&gt;
&lt;br /&gt;
=== Non code ===&lt;br /&gt;
&lt;br /&gt;
* Update AppSensor Guide to keep in step with code changes and improvements to ideas ([http://lists.owasp.org/pipermail/owasp-appsensor-project/2015-February/000855.html see discussion and editable list of changes])&lt;br /&gt;
* Create demo&lt;br /&gt;
* Develop training materials&lt;br /&gt;
&lt;br /&gt;
=== v2 Code ===&lt;br /&gt;
&lt;br /&gt;
The current code being worked on is located on [https://github.com/jtmelton/appsensor GitHub]&lt;br /&gt;
&lt;br /&gt;
The code has been fully rewritten. &lt;br /&gt;
v2.0.0 final was released in late January 2015.&lt;br /&gt;
v2.1.0 final was released in June 2015.&lt;br /&gt;
v2.2.0 final was released in September 2015&lt;br /&gt;
&lt;br /&gt;
The main reason for the rewrite was to allow a client-server style model as opposed to requiring AppSensor be fully embedded in the application. You can now have a central server collecting events from multiple applications and performing analysis. These front-end applications can be in any language as long as they speak rest/soap. There's been a host of other changes, but this was the primary one. A number of starter ideas for coding, user interface and documentation have been outlined via the mailing list at [http://lists.owasp.org/pipermail/owasp-appsensor-project/2014-March/000682.html 17th March 2014].&lt;br /&gt;
&lt;br /&gt;
if you want to work on ANYTHING, please let jtmelton[@]gmail.com know.&lt;br /&gt;
&lt;br /&gt;
== Code Roadmap ==&lt;br /&gt;
&lt;br /&gt;
=== Q4 2015 (2.0) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;Jan - v 2.0.0 final release &amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
&lt;br /&gt;
=== Q4 2014 (2.0) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;Oct - v 2.0.0 release candidate&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Jan 2015 (delay due to bug) - v 2.0.0 final &amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Additional unit tests&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Move appsensor.org site over from static html to python&amp;lt;/strike&amp;gt; -&amp;gt; NOT NECESSARY&lt;br /&gt;
* &amp;lt;strike&amp;gt;Finish up user documentation at appsensor.org&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
&lt;br /&gt;
=== June 2015 (2.1) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;Add at least 1 attack emitter for DEVOPS visualization (JMX -&amp;gt; SNMP, syslog, SNMP, .. something)&amp;lt;/strike&amp;gt; ([https://github.com/jtmelton/appsensor/issues/19 github issue]) -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Sample application / demo&amp;lt;/strike&amp;gt; ([https://github.com/jtmelton/appsensor/issues/9 github issue]) -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Finish up developer documentation on github and appsensor.org&amp;lt;/strike&amp;gt; ([https://github.com/jtmelton/appsensor/issues/12 github issue]) -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Preparation for GSOC 2015 submission&amp;lt;/strike&amp;gt; -&amp;gt; DONE - see [[GSoC2015_Ideas]] - Update - OWASP not selected&lt;br /&gt;
&lt;br /&gt;
=== September 2015 (2.2) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;First version of administration UI for appsensor (monitoring UI) (github issues [https://github.com/jtmelton/appsensor/issues/10 here] and [https://github.com/jtmelton/appsensor/issues/11 here])&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
&lt;br /&gt;
=== January 2016 (2.3) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;Get CI server (cloudbees?) setup ([https://github.com/jtmelton/appsensor/issues/15 github issue])&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
* Video demo of setting up appsensor (screen capture) (related to sample apps)&lt;br /&gt;
* New detection point implementations ([https://github.com/jtmelton/appsensor/issues/8 github issue])&lt;br /&gt;
* AOP examples of detection point implementations&lt;br /&gt;
&lt;br /&gt;
=== May 2016 (2.4) === &lt;br /&gt;
* Trend monitoring implementation ([https://github.com/jtmelton/appsensor/issues/6 github issue])&lt;br /&gt;
* Additional integrations for reporting (graphite, ganglia -&amp;gt; see list supported by codahale metrics)&lt;br /&gt;
&lt;br /&gt;
== Past activities ==&lt;br /&gt;
&lt;br /&gt;
'''September 2015''' Final release v2.2.0 code&lt;br /&gt;
&lt;br /&gt;
'''June 2015''' Final release v2.1.0 code&lt;br /&gt;
&lt;br /&gt;
'''April 2015''' CISO Briefing booklet published&lt;br /&gt;
&lt;br /&gt;
'''February 2015''' Introduction for Developers flyer published&lt;br /&gt;
&lt;br /&gt;
'''January 2015''' Final release v2.0.0 code&lt;br /&gt;
&lt;br /&gt;
'''May 2014''' Finalisation and publication of the AppSensor Guide v2.0&lt;br /&gt;
&lt;br /&gt;
'''November, 2013''' - AppSensor 2.0 hackathon, and document writing &amp;amp; review at AppSecUSA 2013, New York&lt;br /&gt;
&lt;br /&gt;
'''2012-2013''' - Active Development of next AppSensor book&lt;br /&gt;
&lt;br /&gt;
'''September, 2011''' - AppSensor Summit at AppSec USA 2011, Minneapolis&lt;br /&gt;
&lt;br /&gt;
'''September, 2010''' - Presented at AppSecUSA [http://www.slideshare.net/michael_coates/real-time-application-defenses-the-reality-of-appsensor-esapi-5181743 slides]&lt;br /&gt;
&lt;br /&gt;
'''June, 2010''' - Active ESAPI Integration Underway&lt;br /&gt;
&lt;br /&gt;
'''November, 2009''' [http://www.owasp.org/images/0/06/Defend_Yourself-Integrating_Real_Time_Defenses_into_Online_Applications-Michael_Coates.pdf OWASP DC, November 2009]&lt;br /&gt;
&lt;br /&gt;
'''2009''' v1.2 in the works, demo application in development &lt;br /&gt;
&lt;br /&gt;
'''May, 2009''' - AppSec EU Poland - Presentation ([http://www.owasp.org/images/b/b7/AppsecEU09_MichaelCoates.pptx PPT]) ([http://blip.tv/file/2198771 Video]) &lt;br /&gt;
&lt;br /&gt;
'''January, 2009''' - v1.1 Released - Beta Status &lt;br /&gt;
&lt;br /&gt;
'''November, 2008''' - AppSensor Talk at OWASP Portugal &lt;br /&gt;
&lt;br /&gt;
'''November, 2008''' - v1.0 Released - Beta Status &lt;br /&gt;
&lt;br /&gt;
'''April 16, 2008''' - Project Begins&lt;br /&gt;
&lt;br /&gt;
= Detection Points =&lt;br /&gt;
&lt;br /&gt;
Below are the primary detection points defined within AppSensor. These are just the titles; the document contains descriptions, examples and considerations for implementing these detection points. &lt;br /&gt;
&lt;br /&gt;
 '''[http://www.owasp.org/index.php/AppSensor_DetectionPoints Detailed Detection Point Information Here] '''&lt;br /&gt;
&lt;br /&gt;
 '''[http://www.owasp.org/index.php/AppSensor_ResponseActions Response Action Information Here]'''&lt;br /&gt;
&lt;br /&gt;
'''Summary of Information'''&lt;br /&gt;
'''Detection Categories:''' &lt;br /&gt;
&lt;br /&gt;
RE - Request&lt;br /&gt;
&lt;br /&gt;
AE - Authentication&lt;br /&gt;
&lt;br /&gt;
SE - Session&lt;br /&gt;
&lt;br /&gt;
ACE - Access Control&lt;br /&gt;
&lt;br /&gt;
IE - Input&lt;br /&gt;
&lt;br /&gt;
EE - Encoding&lt;br /&gt;
&lt;br /&gt;
CIE - Command Injection&lt;br /&gt;
&lt;br /&gt;
FIO - File IO&lt;br /&gt;
&lt;br /&gt;
HT - Honey Trap&lt;br /&gt;
&lt;br /&gt;
UT - User Trend&lt;br /&gt;
&lt;br /&gt;
STE - System Trend&lt;br /&gt;
&lt;br /&gt;
RP - Reputation&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Signature Based Event Titles''' &lt;br /&gt;
&lt;br /&gt;
ID Event&lt;br /&gt;
&lt;br /&gt;
RE1 Unexpected HTTP Command&lt;br /&gt;
&lt;br /&gt;
RE2 Attempt to Invoke Unsupported HTTP Method&lt;br /&gt;
&lt;br /&gt;
RE3 GET When Expecting POST&lt;br /&gt;
&lt;br /&gt;
RE4 POST When Expecting GET&lt;br /&gt;
&lt;br /&gt;
RE5 Additional/Duplicated Data in Request&lt;br /&gt;
&lt;br /&gt;
RE6 Data Missing from Request&lt;br /&gt;
&lt;br /&gt;
RE7 Unexpected Quantity of Characters in Parameter&lt;br /&gt;
&lt;br /&gt;
RE8 Unexpected Type of Characters in Parameter&lt;br /&gt;
&lt;br /&gt;
AE1 Use Of Multiple Usernames&lt;br /&gt;
&lt;br /&gt;
AE2 Multiple Failed Passwords&lt;br /&gt;
&lt;br /&gt;
AE3 High Rate of Login Attempts&lt;br /&gt;
&lt;br /&gt;
AE4 Unexpected Quantity of Characters in Username&lt;br /&gt;
&lt;br /&gt;
AE5 Unexpected Quantity of Characters in Password&lt;br /&gt;
&lt;br /&gt;
AE6 Unexpected Type of Character in Username&lt;br /&gt;
&lt;br /&gt;
AE7 Unexpected Type of Character in Password&lt;br /&gt;
&lt;br /&gt;
AE8 Providing Only the Username&lt;br /&gt;
&lt;br /&gt;
AE9 Providing Only the Password&lt;br /&gt;
&lt;br /&gt;
AE10 Adding POST Variable&lt;br /&gt;
&lt;br /&gt;
AE11 Missing POST Variable&lt;br /&gt;
&lt;br /&gt;
AE12 Utilization of Common Usernames&lt;br /&gt;
&lt;br /&gt;
SE1 Modifying Existing Cookie&lt;br /&gt;
&lt;br /&gt;
SE2 Adding New Cookie&lt;br /&gt;
&lt;br /&gt;
SE3 Deleting Existing Cookie&lt;br /&gt;
&lt;br /&gt;
SE4 Substituting Another User's Valid Session ID or Cookie&lt;br /&gt;
&lt;br /&gt;
SE5 Source IP Address Changes During Session&lt;br /&gt;
&lt;br /&gt;
SE6 Change Of User Agent Mid Session&lt;br /&gt;
&lt;br /&gt;
ACE1 Modifying URL Argument Within a GET for Direct Object Access Attempt&lt;br /&gt;
&lt;br /&gt;
ACE2 Modifying Parameter Within a POST for Direct Object Access Attempt&lt;br /&gt;
&lt;br /&gt;
ACE3 Force Browsing Attempt&lt;br /&gt;
&lt;br /&gt;
ACE4 Evading Presentation Access Control Through Custom POST&lt;br /&gt;
&lt;br /&gt;
IE1 Cross Site Scripting Attempt&lt;br /&gt;
&lt;br /&gt;
IE2 Violation of Implemented White Lists&lt;br /&gt;
&lt;br /&gt;
IE3 Violation Of Implemented Black Lists&lt;br /&gt;
&lt;br /&gt;
IE4 Violation of Input Data Integrity&lt;br /&gt;
&lt;br /&gt;
IE5 Violation of Stored Business Data Integrity&lt;br /&gt;
&lt;br /&gt;
IE6 Violation of Security Log Integrity&lt;br /&gt;
&lt;br /&gt;
EE1 Double Encoded Character&lt;br /&gt;
&lt;br /&gt;
EE2 Unexpected Encoding Used&lt;br /&gt;
&lt;br /&gt;
CIE1 Blacklist Inspection for Common SQL Injection Values&lt;br /&gt;
&lt;br /&gt;
CIE2 Detect Abnormal Quantity of Returned Records&lt;br /&gt;
&lt;br /&gt;
CIE3 Null Byte Character in File Request&lt;br /&gt;
&lt;br /&gt;
CIE4 Carriage Return or Line Feed Character In File Request&lt;br /&gt;
&lt;br /&gt;
FIO1 Detect Large Individual File &lt;br /&gt;
&lt;br /&gt;
FIO2 Detect Large Number of File Uploads&lt;br /&gt;
&lt;br /&gt;
HT1 Alteration to Honey Trap Data&lt;br /&gt;
&lt;br /&gt;
HT2 Honey Trap Resource Requested&lt;br /&gt;
&lt;br /&gt;
HT3 Honey Trap Data Used&lt;br /&gt;
&lt;br /&gt;
'''Behavior Based Event Titles'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
UT1 Irregular Use of Application&lt;br /&gt;
&lt;br /&gt;
UT2 Speed of Application Use&lt;br /&gt;
&lt;br /&gt;
UT3 Frequency of Site Use&lt;br /&gt;
&lt;br /&gt;
UT4 Frequency of Feature Use&lt;br /&gt;
&lt;br /&gt;
STE1 High Number of Logouts Across The Site&lt;br /&gt;
&lt;br /&gt;
STE2 High Number of Logins Across The Site&lt;br /&gt;
&lt;br /&gt;
STE3 Significant Change in Usage of Same Transaction Across The Site&lt;br /&gt;
&lt;br /&gt;
RP1 Suspicious or Disallowed User IP Address&lt;br /&gt;
&lt;br /&gt;
RP2 Suspicious External User Behavior&lt;br /&gt;
&lt;br /&gt;
RP3 Suspicious Client-Side Behavior&lt;br /&gt;
&lt;br /&gt;
RP4 Change to Environment Threat Level&lt;br /&gt;
&lt;br /&gt;
= Media =&lt;br /&gt;
&lt;br /&gt;
== Introductory Briefings ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
| align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; | Developers&lt;br /&gt;
|&lt;br /&gt;
| align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; | Architects&lt;br /&gt;
|&lt;br /&gt;
| align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; | CISOs&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Appsensor-developer-small.jpg|link=https://www.owasp.org/index.php/File:Appsensor_intro_for_developers.pdf]]&lt;br /&gt;
| width=&amp;quot;20&amp;quot; |&lt;br /&gt;
| align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Appsensor_crosstalk_small.jpg|link=http://www.crosstalkonline.org/storage/issue-archives/2011/201109/201109-Watson.pdf]]&lt;br /&gt;
| width=&amp;quot;20&amp;quot; |&lt;br /&gt;
| align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Appsensor-cisobriefing-small.jpg|link=https://www.owasp.org/index.php/File:Appsensor-ciso-briefing.pdf]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The CISO briefing is also available to [http://www.lulu.com/shop/owasp-foundation/appsensor-ciso-briefing/paperback/product-22121723.html buy at cost in print].&lt;br /&gt;
&lt;br /&gt;
== AppSensor Website ==&lt;br /&gt;
&lt;br /&gt;
[[File:Appsensor-website-large.jpg|link=http://appsensor.org/]]&lt;br /&gt;
&lt;br /&gt;
http://appsensor.org/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code ==&lt;br /&gt;
&lt;br /&gt;
*v2 [https://github.com/jtmelton/appsensor Github Code]&lt;br /&gt;
* (LEGACY) v1 [http://code.google.com/p/appsensor/ Google Code]&lt;br /&gt;
&lt;br /&gt;
== AppSensor Guide ==&lt;br /&gt;
&lt;br /&gt;
* OWASP AppSensor Guide &lt;br /&gt;
** v2.0 EN&lt;br /&gt;
*** [https://www.owasp.org/index.php/File:Owasp-appsensor-guide-v2.pdf PDF]&lt;br /&gt;
*** [https://www.owasp.org/index.php/File:Owasp-appensor-guide-v2.doc DOC]&lt;br /&gt;
*** [http://www.lulu.com/shop/owasp-foundation/appsensor-guide/paperback/product-21608107.html Print on demand at cost hard copy]&lt;br /&gt;
** v1.1 EN&lt;br /&gt;
*** [https://www.owasp.org/images/2/2f/OWASP_AppSensor_Beta_1.1.pdf PDF]&lt;br /&gt;
*** [https://www.owasp.org/images/b/b0/OWASP_AppSensor_Beta_1.1.doc DOC]&lt;br /&gt;
&lt;br /&gt;
== Presentations ==&lt;br /&gt;
&lt;br /&gt;
[http://www.brighttalk.com/webcast/20680 Automated Application Defenses to Thwart Advanced Attackers (Slides &amp;amp; Audio)]&lt;br /&gt;
&lt;br /&gt;
July, 2010 - OWASP London (UK) - [http://www.owasp.org/index.php/File:Owasp-london-20100715-appsensor-3.pdf Real Time Application Attack Detection and Response with OWASP AppSensor]&lt;br /&gt;
&lt;br /&gt;
June, 2010 - OWASP Leeds/North (UK) - OWASP AppSensor - The Self-Aware Web Application&lt;br /&gt;
&lt;br /&gt;
June, 2010 - Video presentation - [http://michael-coates.blogspot.com/2010/06/online-presentation-thursday-automated.html Automated Application Defenses to Thwart Advanced Attackers]&lt;br /&gt;
&lt;br /&gt;
November, 2009 -  AppSec DC - [http://www.owasp.org/images/0/06/Defend_Yourself-Integrating_Real_Time_Defenses_into_Online_Applications-Michael_Coates.pdf Defend Yourself: Integrating Real Time Defenses into Online Applications]&lt;br /&gt;
&lt;br /&gt;
May, 2009 - [http://www.owasp.org/download/jmanico/owasp_podcast_51.mp3 OWASP Podcast #51]&lt;br /&gt;
&lt;br /&gt;
May, 2009 - AppSec EU Poland - [https://www.owasp.org/images/b/b7/AppsecEU09_MichaelCoates.pptx Real Time Defenses against Application Worms and Malicious Attackers]&lt;br /&gt;
&lt;br /&gt;
November, 2008 - [https://www.owasp.org/images/7/77/Presentation_AppSensor.ppt OWASP Summit Portugal 2008 PPT]&lt;br /&gt;
&lt;br /&gt;
==Video Demos of AppSensor==&lt;br /&gt;
&lt;br /&gt;
[http://www.youtube.com/watch?v=8ItfuwvLxRk Detecting Multiple Attacks &amp;amp; Logging Out Attacker]&lt;br /&gt;
&lt;br /&gt;
[http://www.youtube.com/watch?v=CekUMk_VRV8 Detecting XSS Probes]&lt;br /&gt;
&lt;br /&gt;
[http://www.youtube.com/watch?v=LfD4y67qdWE Detecting URL Tampering]&lt;br /&gt;
&lt;br /&gt;
[http://www.youtube.com/watch?v=1D6nTlmYjhY Detecting Verb Tampering]&lt;br /&gt;
&lt;br /&gt;
==Source Documents / Artwork==&lt;br /&gt;
&lt;br /&gt;
* Guide&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Owasp-appensor-guide-v2.doc Word (content only)], DOC 11Mb&lt;br /&gt;
** [https://4ed64fe7f7e3f627b8d0-bc104063a9fe564c2d8a75b1e218477a.ssl.cf2.rackcdn.com/appsensor-guide-2v0-owasp.zip Word, images, Lulu covers, diagrams], ZIP 96Mb&lt;br /&gt;
* Introduction for Developers&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Appsensor-intro-for-developers-a4.zip A4 Illustrator and PDF exports], ZIP 19Mb&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Appsensor-intro-for-developers-usletter.zip US letter Illustrator and PDF exports], ZIP 19Mb&lt;br /&gt;
* Poster&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Owasp-appsensor-poster-a1.zip A1 Illustrator and PDF export] ZIP, 18Mb&lt;br /&gt;
&lt;br /&gt;
= Project About =&lt;br /&gt;
{{:Projects/OWASP_AppSensor_Project | Project About}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;}} &amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|AppSensor Project]] &lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]] &lt;br /&gt;
[[Category:OWASP_Document]] &lt;br /&gt;
[[Category:OWASP_Download]] &lt;br /&gt;
[[Category:SAMM-EH-3]] &lt;br /&gt;
[[Category:SAMM-SA-2]] &lt;br /&gt;
[[Category:SAMM-VM-3]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=February_8,_2017&amp;diff=226178</id>
		<title>February 8, 2017</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=February_8,_2017&amp;diff=226178"/>
				<updated>2017-02-08T23:19:07Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: Added bullets&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
February 8, 2017, 15:00-16:30 PST&lt;br /&gt;
&lt;br /&gt;
Meeting Location: &lt;br /&gt;
&lt;br /&gt;
'''VIRTUAL'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Notice of Recording&lt;br /&gt;
Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== AGENDA ===&lt;br /&gt;
This is the VIRTUAL packet that is provided to everyone at the same time to review, make comments and be prepared for the meeting. There is no paper handout for the meeting.&lt;br /&gt;
&lt;br /&gt;
=== CALL TO ORDER ===&lt;br /&gt;
*Quorum is needed of (4) elected board members to begin. Ideally votes on motions as example will be conducted of ALL board members for the record in the event of a tie the chair's vote decides)&lt;br /&gt;
&lt;br /&gt;
=== CHANGES TO THE AGENDA ===&lt;br /&gt;
*At the start of the meeting the entire agenda will be reviewed. Anything not on the agenda will not be heard and will have to wait until the next scheduled meeting.  Submissions should be available (5) working days before the meeting and a alert should be posted to the [https://lists.owasp.org/listinfo/owasp-board owasp-board mailing list] for public record&lt;br /&gt;
&lt;br /&gt;
=== APPROVAL OF MINUTES ===&lt;br /&gt;
- Approval of prior [https://docs.google.com/document/d/1aPmftVZH3-G96J6-wrpynwwZhBHtREe5a7g8owVYUag prior meeting mins]&lt;br /&gt;
&lt;br /&gt;
=== REPORTS ===&lt;br /&gt;
OWASP Foundation daily operations is managed by the [https://www.owasp.org/index.php/About_OWASP#Employees_and_Contractors Operations Director] who provides a [https://owasp.blogspot.com/2017/02/owasp-operations-update-for-february.html monthly roll-up report] in collaboration of all staff members, contractors and efforts being manged by the [https://www.owasp.org/index.php/About_OWASP#Employees_and_Contractors back office team.]  This month's operational report was published on the OWASP blog as the  [https://owasp.blogspot.com/2017/02/owasp-operations-update-for-february.html OWASP Operations Update for February 2017]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;$Committees&amp;gt; should provide a written/verbal report of progress since the last meeting&lt;br /&gt;
&lt;br /&gt;
=== OLD / UNFINISHED BUSINESS ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;$insert anything that did not get resolved and that is being tracked, updated or to be discussed and by who&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Officer acknowledgements - Brennan&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/About_OWASP#Form_990_Documents 990 Filings] 2014 &amp;amp; 2015 - Brennan&lt;br /&gt;
&lt;br /&gt;
* [Josh] PROPOSAL: An OWASP Foundation Board member is elected to a two-year term. A Board member may run again for re-election at any point in the future, but may serve no more than two two-year terms in any ten year period. Current Board members would be allowed to complete their current term. This would encourage new ideas and renewed energy on the OWASP Board of Directors and keep elections from being a popularity contest where incumbents may be difficult to displace.&lt;br /&gt;
&lt;br /&gt;
Current OWASP Foundation Bylaws:&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/e/e1/OWASPByLawsOfficial-25Sept2015CLEAN.pdf&lt;br /&gt;
&lt;br /&gt;
Section 2.02 currently reads:&lt;br /&gt;
&lt;br /&gt;
:: Each Board member will serve for a term of 2 years. The term will begin effective January 1 following the election period. An individual is limited to 4 consecutive 2 year terms effective January 1, 2014. The role of the Board Members shall be elected by the Board of Directors at the first meeting following the election of the Board of Directors. If the election of officers shall not be held at such meeting, such election shall be held as soon thereafter as conveniently may be. Each officer shall hold that role until the next election has been completed.&lt;br /&gt;
&lt;br /&gt;
MOTION: Revise Section 2.02 to read:&lt;br /&gt;
&lt;br /&gt;
:: Each Board member will serve for a term of 2 years. The term will begin effective January 1 following the election period. A Board member may run again for re-election at any point in the future, but may serve no more than two two-year terms in any ten year period. The role of the Board Members shall be elected by the Board of Directors at the first meeting following the election of the Board of Directors. If the election of officers shall not be held at such meeting, such election shall be held as soon thereafter as conveniently may be. Each officer shall hold that role until the next election has been completed.&lt;br /&gt;
&lt;br /&gt;
This new rule would take effect with the 2017 election and the directors elected for the 2018/2019 term.&lt;br /&gt;
&lt;br /&gt;
* [Josh] Scheduled Board Meeting Discussion: I would like to request that the meeting scheduled for Wednesday, April 12th be moved to either Tuesday, April 11th or Thursday, April 13th at the same time.  I will be coaching a soccer game at the currently scheduled date and time.  Also, the timezone for June 7 is listed as CEST.  Is that intentional?  I ask because every other timezone is listed in PST or PDT.  I shouldn't have an issue if it is, but I at least wanted to verify that is the case. Lastly, the September 19th meeting says &amp;quot;in Orlando at AppSecEU&amp;quot;, but the October 11th meeting also says &amp;quot;at AppSecUSA&amp;quot; and is in EST.  Which is it? Are the times still correct for both? https://www.owasp.org/index.php/Board#The_OWASP_Foundation_Inc..2C_Global_Board_of_Directors&lt;br /&gt;
&lt;br /&gt;
MOTION:&lt;br /&gt;
* Vote for having a Team as ED conformed by Kate, Matt Tesauro and Tom Papas&lt;br /&gt;
* Vote to hire VM services to help prepare the Board meetings better&lt;br /&gt;
* Vote/Approve Budget Items for 2017&lt;br /&gt;
* Vote/Approve [https://docs.google.com/document/d/1zRae5MufvbaIyOd0YL-lOkenzz_3ACZl1zBL11yUxo8/edit new membership model]&lt;br /&gt;
* Vote on strategic goals for 2017&lt;br /&gt;
&lt;br /&gt;
====Strategic Goals 2017====&lt;br /&gt;
* Goal Appsec Training: [https://docs.google.com/document/d/1cT3trTdmYNcz7sH4ENHcR9ujE51qRHx-dDrELIpSnKU/edit?ts=589a2d9b Appsec Training 2017]&lt;br /&gt;
&lt;br /&gt;
=== NEW BUSINESS ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;$insert anything that is NEW business to be heard by the elected officials&amp;gt; Please add your item to the list by editing this wiki page and adding the subject line or link to the item to be discussed&lt;br /&gt;
&lt;br /&gt;
* [Michael] Proposal for OWASP 2017 Objective - AppSec Trainings - [https://docs.google.com/document/d/1cT3trTdmYNcz7sH4ENHcR9ujE51qRHx-dDrELIpSnKU/edit# Proposal Link]&lt;br /&gt;
* [Konda] Proposed Updated 2017 Meeting Schedule - [https://docs.google.com/spreadsheets/d/1kol0PTc0P2hu6xkmkG7umPnNjLGw06Wou56Ee_575rg/edit#gid=0 Proposed Schedule]&lt;br /&gt;
&lt;br /&gt;
=== COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS ===&lt;br /&gt;
This is for open discussion that does NOT require a vote however is educational and informative from anyone who has something to add for the good of the Foundation.&lt;br /&gt;
&lt;br /&gt;
=== ADJOURNMENT ===&lt;br /&gt;
We will determine the next date/time of the offical meeting if different from the posted agenda.  Any changes to the offical date/time/location will also be posted to the [https://lists.owasp.org/listinfo/owasp-board OWASP-BOARD LIST]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/Board NEXT MEETING]&lt;br /&gt;
&lt;br /&gt;
##&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=February_8,_2017&amp;diff=226090</id>
		<title>February 8, 2017</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=February_8,_2017&amp;diff=226090"/>
				<updated>2017-02-07T20:36:33Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: indents for readability&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
February 8, 2017, 15:00-16:30 PST&lt;br /&gt;
&lt;br /&gt;
Meeting Location: &lt;br /&gt;
&lt;br /&gt;
'''VIRTUAL'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== AGENDA ===&lt;br /&gt;
This is the VIRTUAL packet that is provided to everyone at the same time to review, make comments and be prepared for the meeting. There is no paper handout for the meeting.&lt;br /&gt;
&lt;br /&gt;
=== CALL TO ORDER ===&lt;br /&gt;
*Quorum is needed of (4) elected board members to begin. Ideally votes on motions as example will be conducted of ALL board members for the record in the event of a tie the chair's vote decides)&lt;br /&gt;
&lt;br /&gt;
=== CHANGES TO THE AGENDA ===&lt;br /&gt;
*At the start of the meeting the entire agenda will be reviewed. Anything not on the agenda will not be heard and will have to wait until the next scheduled meeting.  Submissions should be available (5) working days before the meeting and a alert should be posted to the [https://lists.owasp.org/listinfo/owasp-board owasp-board mailing list] for public record&lt;br /&gt;
&lt;br /&gt;
=== APPROVAL OF MINUTES ===&lt;br /&gt;
- Approval of prior [https://docs.google.com/document/d/1aPmftVZH3-G96J6-wrpynwwZhBHtREe5a7g8owVYUag prior meeting mins]&lt;br /&gt;
&lt;br /&gt;
=== REPORTS ===&lt;br /&gt;
OWASP Foundation daily operations is managed by the [https://www.owasp.org/index.php/About_OWASP#Employees_and_Contractors Operations Director] who provides a [https://owasp.blogspot.com/2017/02/owasp-operations-update-for-february.html monthly roll-up report] in collaboration of all staff members, contractors and efforts being manged by the [https://www.owasp.org/index.php/About_OWASP#Employees_and_Contractors back office team.]  This month's operational report was published on the OWASP blog as the  [https://owasp.blogspot.com/2017/02/owasp-operations-update-for-february.html OWASP Operations Update for February 2017]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;$Committees&amp;gt; should provide a written/verbal report of progress since the last meeting&lt;br /&gt;
&lt;br /&gt;
=== OLD / UNFINISHED BUSINESS ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;$insert anything that did not get resolved and that is being tracked, updated or to be discussed and by who&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Officer acknowledgements - Brennan&lt;br /&gt;
&lt;br /&gt;
- [https://www.owasp.org/index.php/About_OWASP#Form_990_Documents 990 Filings] 2014 &amp;amp; 2015 - Brennan&lt;br /&gt;
&lt;br /&gt;
- [Josh] PROPOSAL: An OWASP Foundation Board member is elected to a two-year term. A Board member may run again for re-election at any point in the future, but may serve no more than two two-year terms in any ten year period. Current Board members would be allowed to complete their current term. This would encourage new ideas and renewed energy on the OWASP Board of Directors and keep elections from being a popularity contest where incumbents may be difficult to displace.&lt;br /&gt;
&lt;br /&gt;
Current OWASP Foundation Bylaws:&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/e/e1/OWASPByLawsOfficial-25Sept2015CLEAN.pdf&lt;br /&gt;
&lt;br /&gt;
Section 2.02 currently reads:&lt;br /&gt;
&lt;br /&gt;
:: Each Board member will serve for a term of 2 years. The term will begin effective January 1 following the election period. An individual is limited to 4 consecutive 2 year terms effective January 1, 2014. The role of the Board Members shall be elected by the Board of Directors at the first meeting following the election of the Board of Directors. If the election of officers shall not be held at such meeting, such election shall be held as soon thereafter as conveniently may be. Each officer shall hold that role until the next election has been completed.&lt;br /&gt;
&lt;br /&gt;
MOTION: Revise Section 2.02 to read:&lt;br /&gt;
&lt;br /&gt;
:: Each Board member will serve for a term of 2 years. The term will begin effective January 1 following the election period. A Board member may run again for re-election at any point in the future, but may serve no more than two two-year terms in any ten year period. The role of the Board Members shall be elected by the Board of Directors at the first meeting following the election of the Board of Directors. If the election of officers shall not be held at such meeting, such election shall be held as soon thereafter as conveniently may be. Each officer shall hold that role until the next election has been completed.&lt;br /&gt;
&lt;br /&gt;
This new rule would take effect with the 2017 election and the directors elected for the 2018/2019 term.&lt;br /&gt;
&lt;br /&gt;
- [Josh] Scheduled Board Meeting Discussion: I would like to request that the meeting scheduled for Wednesday, April 12th be moved to either Tuesday, April 11th or Thursday, April 13th at the same time.  I will be coaching a soccer game at the currently scheduled date and time.  Also, the timezone for June 7 is listed as CEST.  Is that intentional?  I ask because every other timezone is listed in PST or PDT.  I shouldn't have an issue if it is, but I at least wanted to verify that is the case. Lastly, the September 19th meeting says &amp;quot;in Orlando at AppSecEU&amp;quot;, but the October 11th meeting also says &amp;quot;at AppSecUSA&amp;quot; and is in EST.  Which is it? Are the times still correct for both? https://www.owasp.org/index.php/Board#The_OWASP_Foundation_Inc..2C_Global_Board_of_Directors&lt;br /&gt;
&lt;br /&gt;
=== NEW BUSINESS ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;$insert anything that is NEW business to be heard by the elected officials&amp;gt; Please add your item to the list by editing this wiki page and adding the subject line or link to the item to be discussed&lt;br /&gt;
&lt;br /&gt;
* [Michael] Proposal for OWASP 2017 Objective - AppSec Trainings - [https://docs.google.com/document/d/1cT3trTdmYNcz7sH4ENHcR9ujE51qRHx-dDrELIpSnKU/edit# Proposal Link] &lt;br /&gt;
&lt;br /&gt;
=== COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS ===&lt;br /&gt;
This is for open discussion that does NOT require a vote however is educational and informative from anyone who has something to add for the good of the Foundation.&lt;br /&gt;
&lt;br /&gt;
=== ADJOURNMENT ===&lt;br /&gt;
We will determine the next date/time of the offical meeting if different from the posted agenda.  Any changes to the offical date/time/location will also be posted to the [https://lists.owasp.org/listinfo/owasp-board OWASP-BOARD LIST]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/Board NEXT MEETING]&lt;br /&gt;
&lt;br /&gt;
##&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=February_8,_2017&amp;diff=226089</id>
		<title>February 8, 2017</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=February_8,_2017&amp;diff=226089"/>
				<updated>2017-02-07T20:34:01Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: Adding AppSec Trainings Proposal for vote&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
February 8, 2017, 15:00-16:30 PST&lt;br /&gt;
&lt;br /&gt;
Meeting Location: &lt;br /&gt;
&lt;br /&gt;
'''VIRTUAL'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== AGENDA ===&lt;br /&gt;
This is the VIRTUAL packet that is provided to everyone at the same time to review, make comments and be prepared for the meeting. There is no paper handout for the meeting.&lt;br /&gt;
&lt;br /&gt;
=== CALL TO ORDER ===&lt;br /&gt;
*Quorum is needed of (4) elected board members to begin. Ideally votes on motions as example will be conducted of ALL board members for the record in the event of a tie the chair's vote decides)&lt;br /&gt;
&lt;br /&gt;
=== CHANGES TO THE AGENDA ===&lt;br /&gt;
*At the start of the meeting the entire agenda will be reviewed. Anything not on the agenda will not be heard and will have to wait until the next scheduled meeting.  Submissions should be available (5) working days before the meeting and a alert should be posted to the [https://lists.owasp.org/listinfo/owasp-board owasp-board mailing list] for public record&lt;br /&gt;
&lt;br /&gt;
=== APPROVAL OF MINUTES ===&lt;br /&gt;
- Approval of prior [https://docs.google.com/document/d/1aPmftVZH3-G96J6-wrpynwwZhBHtREe5a7g8owVYUag prior meeting mins]&lt;br /&gt;
&lt;br /&gt;
=== REPORTS ===&lt;br /&gt;
OWASP Foundation daily operations is managed by the [https://www.owasp.org/index.php/About_OWASP#Employees_and_Contractors Operations Director] who provides a [https://owasp.blogspot.com/2017/02/owasp-operations-update-for-february.html monthly roll-up report] in collaboration of all staff members, contractors and efforts being manged by the [https://www.owasp.org/index.php/About_OWASP#Employees_and_Contractors back office team.]  This month's operational report was published on the OWASP blog as the  [https://owasp.blogspot.com/2017/02/owasp-operations-update-for-february.html OWASP Operations Update for February 2017]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;$Committees&amp;gt; should provide a written/verbal report of progress since the last meeting&lt;br /&gt;
&lt;br /&gt;
=== OLD / UNFINISHED BUSINESS ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;$insert anything that did not get resolved and that is being tracked, updated or to be discussed and by who&amp;gt;&lt;br /&gt;
&lt;br /&gt;
- Officer acknowledgements - Brennan&lt;br /&gt;
&lt;br /&gt;
- [https://www.owasp.org/index.php/About_OWASP#Form_990_Documents 990 Filings] 2014 &amp;amp; 2015 - Brennan&lt;br /&gt;
&lt;br /&gt;
- [Josh] PROPOSAL: An OWASP Foundation Board member is elected to a two-year term. A Board member may run again for re-election at any point in the future, but may serve no more than two two-year terms in any ten year period. Current Board members would be allowed to complete their current term. This would encourage new ideas and renewed energy on the OWASP Board of Directors and keep elections from being a popularity contest where incumbents may be difficult to displace.&lt;br /&gt;
&lt;br /&gt;
Current OWASP Foundation Bylaws:&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/images/e/e1/OWASPByLawsOfficial-25Sept2015CLEAN.pdf&lt;br /&gt;
&lt;br /&gt;
Section 2.02 currently reads:&lt;br /&gt;
&lt;br /&gt;
Each Board member will serve for a term of 2 years. The term will begin effective January 1 following the election period. An individual is limited to 4 consecutive 2 year terms effective January 1, 2014. The role of the Board Members shall be elected by the Board of Directors at the first meeting following the election of the Board of Directors. If the election of officers shall not be held at such meeting, such election shall be held as soon thereafter as conveniently may be. Each officer shall hold that role until the next election has been completed.&lt;br /&gt;
&lt;br /&gt;
MOTION: Revise Section 2.02 to read:&lt;br /&gt;
&lt;br /&gt;
Each Board member will serve for a term of 2 years. The term will begin effective January 1 following the election period. A Board member may run again for re-election at any point in the future, but may serve no more than two two-year terms in any ten year period. The role of the Board Members shall be elected by the Board of Directors at the first meeting following the election of the Board of Directors. If the election of officers shall not be held at such meeting, such election shall be held as soon thereafter as conveniently may be. Each officer shall hold that role until the next election has been completed.&lt;br /&gt;
&lt;br /&gt;
This new rule would take effect with the 2017 election and the directors elected for the 2018/2019 term.&lt;br /&gt;
&lt;br /&gt;
- [Josh] Scheduled Board Meeting Discussion: I would like to request that the meeting scheduled for Wednesday, April 12th be moved to either Tuesday, April 11th or Thursday, April 13th at the same time.  I will be coaching a soccer game at the currently scheduled date and time.  Also, the timezone for June 7 is listed as CEST.  Is that intentional?  I ask because every other timezone is listed in PST or PDT.  I shouldn't have an issue if it is, but I at least wanted to verify that is the case. Lastly, the September 19th meeting says &amp;quot;in Orlando at AppSecEU&amp;quot;, but the October 11th meeting also says &amp;quot;at AppSecUSA&amp;quot; and is in EST.  Which is it? Are the times still correct for both? https://www.owasp.org/index.php/Board#The_OWASP_Foundation_Inc..2C_Global_Board_of_Directors&lt;br /&gt;
&lt;br /&gt;
=== NEW BUSINESS ===&lt;br /&gt;
&lt;br /&gt;
&amp;lt;$insert anything that is NEW business to be heard by the elected officials&amp;gt; Please add your item to the list by editing this wiki page and adding the subject line or link to the item to be discussed&lt;br /&gt;
&lt;br /&gt;
* [Michael] Proposal for OWASP 2017 Objective - AppSec Trainings - [https://docs.google.com/document/d/1cT3trTdmYNcz7sH4ENHcR9ujE51qRHx-dDrELIpSnKU/edit# Proposal Link] &lt;br /&gt;
&lt;br /&gt;
=== COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS ===&lt;br /&gt;
This is for open discussion that does NOT require a vote however is educational and informative from anyone who has something to add for the good of the Foundation.&lt;br /&gt;
&lt;br /&gt;
=== ADJOURNMENT ===&lt;br /&gt;
We will determine the next date/time of the offical meeting if different from the posted agenda.  Any changes to the offical date/time/location will also be posted to the [https://lists.owasp.org/listinfo/owasp-board OWASP-BOARD LIST]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/Board NEXT MEETING]&lt;br /&gt;
&lt;br /&gt;
##&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=223539</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=223539"/>
				<updated>2016-11-19T22:48:35Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Mentorship Program */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Bay Area Chapter Board = &lt;br /&gt;
Interested in finding out more? Will contact your with information on the first in person chapter board discussion in San Francisco&lt;br /&gt;
&lt;br /&gt;
Submit your info here: https://goo.gl/forms/ScPCPrlDiQaUZ6cs2&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
[https://www.meetup.com/Bay-Area-OWASP/events/233591691/ September 7, 2016 - San Francisco]&lt;br /&gt;
&lt;br /&gt;
Check out our meetup page for upcoming events:&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Travis McPeak&lt;br /&gt;
* William Bengtson &lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:United_States]]&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=223538</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=223538"/>
				<updated>2016-11-19T22:48:17Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Bay Area Chapter Leaders */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Bay Area Chapter Board = &lt;br /&gt;
Interested in finding out more? Will contact your with information on the first in person chapter board discussion in San Francisco&lt;br /&gt;
&lt;br /&gt;
Submit your info here: https://goo.gl/forms/ScPCPrlDiQaUZ6cs2&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
[https://www.meetup.com/Bay-Area-OWASP/events/233591691/ September 7, 2016 - San Francisco]&lt;br /&gt;
&lt;br /&gt;
Check out our meetup page for upcoming events:&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Travis McPeak&lt;br /&gt;
* William Bengtson &lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
== Mentorship Program ==&lt;br /&gt;
* OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
* First meeting will be held on December 1 &lt;br /&gt;
** Complete the following form [https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
** Then [http://www.meetup.com/Bay-Area-OWASP/ RSVP for the meetup]&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:United_States]]&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=November_8,_2016&amp;diff=223188</id>
		<title>November 8, 2016</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=November_8,_2016&amp;diff=223188"/>
				<updated>2016-11-08T22:59:13Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===Time===&lt;br /&gt;
* Date/Time:  November 8, 1800 EST [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=11&amp;amp;day=08&amp;amp;hour=22&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter]&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
&lt;br /&gt;
*Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
*Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
::- [https://docs.google.com/a/owasp.org/document/d/119FJ2G2EdsVnz8vnxWv0Ee0G3uWMTSVqyxt_1CVrHiY/edit?usp=sharing September meeting minutes]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative: List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chair's Report - Matt Konda ===&lt;br /&gt;
* Draft of [https://docs.google.com/document/d/1ZgZotdu3TglKCiyOxyQVwS16YDJj0qmEkdYz0LT7hf4/edit Strategic Goals for 2017]&lt;br /&gt;
* Turned on [https://owasp.recruiterbox.com/jobs/fk062sn ED Job Description] *this needs a budget and a call for canidate campaign/recruitment*&lt;br /&gt;
* Draft of [https://docs.google.com/a/owasp.org/document/d/1eH-0WTRBa-x21GNsGZqOiokP0fO6oBKK8OOj3sjnhP8/edit?usp=sharing OWASP Staff Training Policy]&lt;br /&gt;
* Moved Co-Marketing Agreements back to Kate&lt;br /&gt;
* Belfast Contracts and Moved Away from Troy &lt;br /&gt;
* OWASP Glue Project&lt;br /&gt;
&lt;br /&gt;
=== Vice Chair's Report - Josh Sokol ===&lt;br /&gt;
TBA&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Andrew van der Stock ===&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report -Tobias Gondrom ===&lt;br /&gt;
Nothing to report&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Tom Brennan, Michael Coates, and Tobias Gondrom ===&lt;br /&gt;
&lt;br /&gt;
* Coates - Chapters&lt;br /&gt;
TBA&lt;br /&gt;
&lt;br /&gt;
* Carter - Governance&lt;br /&gt;
TBA&lt;br /&gt;
&lt;br /&gt;
* Brennan - Projects&lt;br /&gt;
Matt T., has been recruited, hired and empowered to drive the job description that was [https://www.owasp.org/images/a/a1/OWASP_Project_Coordinator-FabioTobiasAug25.pdf written]. Good job to him and the staff for working together on key objectives.  Next is the website effort, budget was allocated and removed. This is a issue and needs discussion of issue and solution.  Invest in owasp and budget appropriately as one does with a 2M business.&lt;br /&gt;
&lt;br /&gt;
-2017 Project Summits&lt;br /&gt;
&lt;br /&gt;
- Industry moving&lt;br /&gt;
pubilc/private, m&amp;amp;a, opensource&lt;br /&gt;
&lt;br /&gt;
Project Flows&lt;br /&gt;
- Examples [https://www.owasp.org/index.php/OWASP_Project_Inventory#tab=Labs_Projects Labs Current], [https://github.com/opendxl/opendxl-client-python/blob/master/LICENSE OpenDXL], [https://github.com/zaproxy/zaproxy/ ZAP Proxy] and [http://www.bugheist.com/ BugHeist] models of open source and other [http://events.linuxfoundation.org/sites/events/files/slides/lfcs15_hall.pdf Open Source business models]&lt;br /&gt;
&lt;br /&gt;
- Local project chapters&lt;br /&gt;
&lt;br /&gt;
==Staff Reports==&lt;br /&gt;
==Staff Reports==&lt;br /&gt;
** [https://docs.google.com/a/owasp.org/document/d/12Php1gJuT7lednfKxdv9QegLeVjFHW2xmnVwOsUgmU8/edit?usp=sharing Director/Operations Update] - Kate&lt;br /&gt;
** Financial Update - Andrew/Tom&lt;br /&gt;
** [https://docs.google.com/document/d/1ZY3AEF53AlYwh-6hCqO6W47_9r6ALxe2g9FYSyuAyaQ/edit?usp=sharing Event Manager Report] - Laura Grau&lt;br /&gt;
** [https://docs.google.com/a/owasp.org/presentation/d/1I7z1smEAtKIYV2_5lASuQJZcG51F5znfo-p9WKNxOc8/edit?usp=sharing| Project_Coordinator_Update] - Claudia Casanovas &amp;amp; Matt Tesauro &lt;br /&gt;
** [https://docs.google.com/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit?usp=sharing Community Manager Report]- Tiffany Long &lt;br /&gt;
** [https://www.owasp.org/index.php/October_2016_Membership_Report October 2016 Membership Report] - Kelly Santalucia&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
&lt;br /&gt;
* [http://lists.owasp.org/pipermail/owasp-board/2016-October/017563.html Request for 150K USD seed fund for the OWASP-DevSecCon Summit in April 2017 in the UK] &lt;br /&gt;
* Policy on OWASP Staff Training&lt;br /&gt;
* Strategic Goals&lt;br /&gt;
* What does a future OWASP look like? Directional aspirations and impacts to type of ED [Michael]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additional Notes to 150K Seed Fund:&amp;lt;br&amp;gt;&lt;br /&gt;
We are gathering a team with ample experience in organizing owasp (and other) events, including the last 2 owasp summits.&amp;lt;br&amp;gt;&lt;br /&gt;
By focusing on the content and outcome objectives we are creating the necessary momentum for this summit.&amp;lt;br&amp;gt;&lt;br /&gt;
In parallel we are putting in motion the logistics for this summit (venue, catering, sponsoring, ...)&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
We will definitely try to make this a &amp;quot;budget-neutral&amp;quot; event, by:&amp;lt;br&amp;gt;&lt;br /&gt;
1) having people cover their participation themselves&amp;lt;br&amp;gt;&lt;br /&gt;
2) having sponsors that cover part of the costs&amp;lt;br&amp;gt;&lt;br /&gt;
3) tapping into the under-used chapter and project funds&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
At this stage we want to be sure to have the support from the board &amp;amp; staff and have a &amp;quot;seed-fund&amp;quot; of 150K USD.&amp;lt;br&amp;gt;&lt;br /&gt;
I count on your (and the complete board) to support this new summit.&amp;lt;br&amp;gt;&lt;br /&gt;
Seba &amp;amp; Dinis&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
Election results:  &lt;br /&gt;
&lt;br /&gt;
The three open board seats shall be filled by: &lt;br /&gt;
Andrew van der Stock&lt;br /&gt;
Matt Konda&lt;br /&gt;
Johanna Curiel&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: [https://www.owasp.org/index.php?title=December_14,_2016 December 14 2016 1500-1630 PST] [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=12&amp;amp;day=14&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Agenda&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Extra points==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=221099</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=221099"/>
				<updated>2016-09-08T00:20:12Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Bay Area Chapter Board */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Bay Area Chapter Board = &lt;br /&gt;
Interested in finding out more? Will contact your with information on the first in person chapter board discussion in San Francisco&lt;br /&gt;
&lt;br /&gt;
Submit your info here: https://goo.gl/forms/ScPCPrlDiQaUZ6cs2&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
[https://www.meetup.com/Bay-Area-OWASP/events/233591691/ September 7, 2016 - San Francisco]&lt;br /&gt;
&lt;br /&gt;
Check out our meetup page for upcoming events:&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
== Mentorship Program ==&lt;br /&gt;
* OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
* First meeting will be held on December 1 &lt;br /&gt;
** Complete the following form [https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
** Then [http://www.meetup.com/Bay-Area-OWASP/ RSVP for the meetup]&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:United_States]]&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=221098</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=221098"/>
				<updated>2016-09-07T23:52:20Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Bay Area Chapter Board = &lt;br /&gt;
Interested in finding out more?&lt;br /&gt;
&lt;br /&gt;
Submit your info here: https://goo.gl/forms/ScPCPrlDiQaUZ6cs2&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
[https://www.meetup.com/Bay-Area-OWASP/events/233591691/ September 7, 2016 - San Francisco]&lt;br /&gt;
&lt;br /&gt;
Check out our meetup page for upcoming events:&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
== Mentorship Program ==&lt;br /&gt;
* OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
* First meeting will be held on December 1 &lt;br /&gt;
** Complete the following form [https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
** Then [http://www.meetup.com/Bay-Area-OWASP/ RSVP for the meetup]&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:United_States]]&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=220737</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=220737"/>
				<updated>2016-08-25T17:57:52Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Our next  event */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
[https://www.meetup.com/Bay-Area-OWASP/events/233591691/ September 7, 2016 - San Francisco]&lt;br /&gt;
&lt;br /&gt;
Check out our meetup page for upcoming events:&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
== Mentorship Program ==&lt;br /&gt;
* OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
* First meeting will be held on December 1 &lt;br /&gt;
** Complete the following form [https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
** Then [http://www.meetup.com/Bay-Area-OWASP/ RSVP for the meetup]&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:United_States]]&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=July_1,_2016&amp;diff=218411</id>
		<title>July 1, 2016</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=July_1,_2016&amp;diff=218411"/>
				<updated>2016-06-29T18:46:58Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Reports */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;===Time===&lt;br /&gt;
*Date/Time:  July 1, 2016/6pm-9pm CEST&lt;br /&gt;
* [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=05&amp;amp;day=18&amp;amp;hour=14&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter]&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
[http://www.marriott.com/hotels/travel/romau-rome-marriott-park-hotel/ Rome Marriott-Park Hotel]&lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
July 1, 2016 Meeting Minutes&lt;br /&gt;
::- TBA&lt;br /&gt;
&lt;br /&gt;
May 18, 2016 Meeting Minutes:&lt;br /&gt;
::- https://docs.google.com/document/d/14uLi51kUGcmqIfjZJ0WEe2WZO4_-lUabdPBS4XSz7V0/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
* OWASP Website Project draft report - post comments on the draft&lt;br /&gt;
https://docs.google.com/document/d/1OWo4Er61iK2ySwoJsuCHw9ManGHjiMURuRiQUmMVSuY/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative: List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chair's Report - Matt Konda ===&lt;br /&gt;
* Developer Initiatives:  Chicago Coder Conference, Goto; Chicago, TechNexus Panel on Security, Chicago FTW Start with Security Panel&lt;br /&gt;
* Organizational&lt;br /&gt;
** Staff meetings&lt;br /&gt;
** Hiring follow through for STC&lt;br /&gt;
* Minimal Bill payments&lt;br /&gt;
* 1:1 with staff at AppSecEU&lt;br /&gt;
&lt;br /&gt;
=== Vice Chair's Report - Josh Sokol ===&lt;br /&gt;
* I've got nothing major to report here so let's save the time for some of the bigger discussions that we need to have.&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Andrew van der Stock ===&lt;br /&gt;
&lt;br /&gt;
From January to around at least April, OWASP had operational reserves far less than the target operational reserve target of six months. This is due to a lack of revenue, unbudgeted expenses, and a split model that favors one strategic goal over all others. Luckily, the success of AppSec EU has made a recovery possible, and provides breathing room until this is resolved. &lt;br /&gt;
&lt;br /&gt;
Unfortunately, the 2016 draft budget was never finished, and it was not approved. We need to approve a revised 2016 budget. There will be a budget working party held in Rome to get through this out of cycle budgeting process that will hopefully put in a reasonable budget for the rest of the year until planning can start again at the October face to face board meeting. &lt;br /&gt;
&lt;br /&gt;
I have created a set of financial motions that address revenue, such as a membership fee increase, additional membership classes, a training program, and to invest $250k of our unused earmarked funds in a structured investment program. These measures will collectively increase our membership, particularly in the developing economies, and improve our bottom line by over $100k per year, with an additional $60-75k over five years from investing the earmarked funds. &lt;br /&gt;
&lt;br /&gt;
We will need to work together on structural reform that addresses the profit splitting more equitably so that future operational reserves do not go below six months, and so we can invest in all of our strategic goals, and not just one. This is not optional, because there is a risk that a future AppSec conference does not do well, as happened in 2012, this could bring OWASP down. We need to address this structural reform so that we can grow to a $5m per year organisation, which has far different issues than we do today.&lt;br /&gt;
&lt;br /&gt;
*Josh Comment: AppSecUSA 2012 was the highest grossing AppSec conference ever held at the time.  Not sure where this comment comes from, but it is wrong.&lt;br /&gt;
&lt;br /&gt;
=== Chapters - Michael Coates === &lt;br /&gt;
* Working with Tiffany regarding concerns over a specific chapter election&lt;br /&gt;
* Waiting on Sooryen information before further chapter outreach&lt;br /&gt;
&lt;br /&gt;
== Financial information ==&lt;br /&gt;
&lt;br /&gt;
* June financial package&lt;br /&gt;
::- TBA&lt;br /&gt;
&lt;br /&gt;
* 2016 Draft Budget&lt;br /&gt;
::- TBA&lt;br /&gt;
&lt;br /&gt;
== Financial motions ==&lt;br /&gt;
&lt;br /&gt;
* Motion to invest a portion of unused funds in a ladder CD arrangement&lt;br /&gt;
::- https://docs.google.com/document/d/1cZOMYzaRnWW_oQd4ON7kBNQcmlx3V4u33Szm8jH2cgU/edit#&lt;br /&gt;
&lt;br /&gt;
* Motion to approve changes to FY17 membership rates&lt;br /&gt;
::- https://docs.google.com/a/owasp.org/document/d/1RBy7yRl-qVo49lDL1JeKmhwLElcazrJ7tY4OO5Wwb6U/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
* Motion to add a developing nation membership class of $USD 20 annually&lt;br /&gt;
::- https://docs.google.com/a/owasp.org/document/d/14OBSW4kcsFsuEGyGg1K8UXkuoYQAzdY49gvXmkUiYyg/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
* Motion to establish a pay anything membership class, eliminate honorary membership and establish an annual Paul Ritchie Memorial Award&lt;br /&gt;
::- https://docs.google.com/a/owasp.org/document/d/1GTcff47NFDgFCnnFTvaEehdecc-TU2PWjAqc9x470Vw/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
* Motion to create an OWASP open training platform&lt;br /&gt;
::- https://docs.google.com/document/d/1dZ-6eJyNj5iiTTo9AS5NC77PYwOF0D9aTHz8dmcJGJ0/edit#&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report - ########## ===&lt;br /&gt;
&lt;br /&gt;
* Need to assign this role to a current board member to fill vacancy - [http://www.nonprofitlawblog.com/duties-of-the-secretary-of-a-nonprofit-corporation/ why]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Tom Brennan, Michael Coates, and Tobias Gondrom ===&lt;br /&gt;
&lt;br /&gt;
* Coates - Chapters&lt;br /&gt;
&lt;br /&gt;
* Gondrom - Governance&lt;br /&gt;
&lt;br /&gt;
* Brennan - Projects&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/a/owasp.org/document/d/1lz4Yb2byWSbayRmpKksHhR_fHJ3eoL8aWMZMEpfnIXg/edit?usp=sharing Rollup Report]&lt;br /&gt;
** Financial Update - [Link| Board Summary Combined] [Link| Combined Balance Sheet]&lt;br /&gt;
** Director Update - Kate Hartmann - see rollup report above&lt;br /&gt;
** Project Coordinator Update -DRAFT[https://docs.google.com/a/owasp.org/presentation/d/1jeTYCaTRw-lqJV0q3OpYiTZCrAwf4T9fKiMjqHccm44/edit?usp=sharing| Claudia Aviles Casanovas Update]&lt;br /&gt;
** Membership Update - [https://www.owasp.org/index.php/May_2016_Membership_Report Membership Report] Kelly Santalucia Update]&lt;br /&gt;
** [Link| Conference Manager Report] - Laura Grau&lt;br /&gt;
** IT Update - [Link| IT Status Report as of 2016-05-17] - Matt Tesauro&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
* Motion to create Regional Advisory Councils - Please read final draft. Vote held over from January 2016&lt;br /&gt;
::- https://docs.google.com/document/d/16y0acWfeZ_skcO27D-conivvlbSqPbAC1xTY5UfJi_4/edit&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
&lt;br /&gt;
* Status of filed Trademarks with the USPO and discussion about brand usage and resources&lt;br /&gt;
::- https://www.owasp.org/index.php/Marketing/Resources&lt;br /&gt;
&lt;br /&gt;
* Co-Marketing Agreements with other conferences&lt;br /&gt;
::- https://www.owasp.org/index.php/Owasp_Conference_Management_System&lt;br /&gt;
::- https://www.owasp.org/index.php/Category:OWASP_AppSec_Conference&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
&lt;br /&gt;
* Approve a 2016 Budget &lt;br /&gt;
::- Draft budget forthcoming (AJV)&lt;br /&gt;
&lt;br /&gt;
* Motion to appoint a replacement secretary for the remainder of 2016&lt;br /&gt;
::- https://docs.google.com/a/owasp.org/document/d/1ir9P0kz7HQuJqOEpgL4r2yKwLQCR47gLswvliaqzyak/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
* Motion to appoint a casual vacancy on the OWASP Global Board for the remainder of 2016&lt;br /&gt;
::- https://docs.google.com/a/owasp.org/document/d/1ukMZJ9MdCITjT1t_IWC4pxKZKcqATOu-yFpZ1ruddrc/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
* Motion to invest a portion of unused funds in a ladder CD arrangement&lt;br /&gt;
::- https://docs.google.com/document/d/1cZOMYzaRnWW_oQd4ON7kBNQcmlx3V4u33Szm8jH2cgU/edit#&lt;br /&gt;
&lt;br /&gt;
* Motion to approve changes to FY17 membership rates&lt;br /&gt;
::- https://docs.google.com/a/owasp.org/document/d/1RBy7yRl-qVo49lDL1JeKmhwLElcazrJ7tY4OO5Wwb6U/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
* Motion to add a developing nation membership class of $USD 20 annually&lt;br /&gt;
::- https://docs.google.com/a/owasp.org/document/d/14OBSW4kcsFsuEGyGg1K8UXkuoYQAzdY49gvXmkUiYyg/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
* Motion to establish a pay anything membership class, eliminate honorary membership and establish an annual Paul Ritchie Memorial Award&lt;br /&gt;
::- https://docs.google.com/a/owasp.org/document/d/1GTcff47NFDgFCnnFTvaEehdecc-TU2PWjAqc9x470Vw/edit?usp=sharing&lt;br /&gt;
&lt;br /&gt;
* Motion to create an OWASP open training platform&lt;br /&gt;
::- https://docs.google.com/document/d/1dZ-6eJyNj5iiTTo9AS5NC77PYwOF0D9aTHz8dmcJGJ0/edit#&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: [https://www.owasp.org/index.php?title=July_27,_2016 July 27th]&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=217829</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=217829"/>
				<updated>2016-06-10T05:28:24Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Our next  event */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/231790630/ June 28, 2016 - Foster City]&lt;br /&gt;
&lt;br /&gt;
Check out our meetup page for upcoming events:&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
== Mentorship Program ==&lt;br /&gt;
* OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
* First meeting will be held on December 1 &lt;br /&gt;
** Complete the following form [https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
** Then [http://www.meetup.com/Bay-Area-OWASP/ RSVP for the meetup]&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:United_States]]&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=May_18,_2016&amp;diff=216983</id>
		<title>May 18, 2016</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=May_18,_2016&amp;diff=216983"/>
				<updated>2016-05-17T21:54:46Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Updated from Members at Large - Tom Brennan, Michael Coates, and Tobias Gondrom */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[link Meeting Recording]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
*Date/Time:  May 18, 2016, 07:00am-08:30am PDT &lt;br /&gt;
* [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=05&amp;amp;day=18&amp;amp;hour=14&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter]&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
May 18, 2016 Meeting Minutes:&lt;br /&gt;
&lt;br /&gt;
April 20, 2016 Meeting Minutes: https://docs.google.com/document/d/1iCSz7o7twwh-Rqhab7V8bI8XveZXbn8goe6qv8ita2U &amp;lt;br/&amp;gt;&lt;br /&gt;
March 16, 2016 Meeting Minutes: https://docs.google.com/document/d/1xGrNduAoAf2cZ9Xgup431SbZw-qjL5JZqukHIfWTyBI&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative: List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chair's Report - Matt Konda ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Vice Chair's Report - Josh Sokol ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Andrew van der Stock ===&lt;br /&gt;
* Financial Package available here:  [https://drive.google.com/a/owasp.org/file/d/0BxI4iTO_QojvN2t3Y2NabzRhbUVnWEs1X3IxQWRQZElNbmc0/view?usp=sharing 2016 March Financial Report]&lt;br /&gt;
&lt;br /&gt;
[https://drive.google.com/a/owasp.org/file/d/0BxI4iTO_QojvT0lNMi1kci1pZlNaaGNYNVdOTVBrS0ItWkQ0/view?usp=sharing 3.31.16 Board Summary Combined] &lt;br /&gt;
&lt;br /&gt;
[https://drive.google.com/a/owasp.org/file/d/0BxI4iTO_QojvMVhLTHpKZnE4cm1LVUxaOWJUWHdieXBKLVhv/view?usp=sharing 3.31.16 Combined Balance Sheet]&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report - Jim Manico  ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Tom Brennan, Michael Coates, and Tobias Gondrom ===&lt;br /&gt;
&lt;br /&gt;
 Coates - Chapters&lt;br /&gt;
&lt;br /&gt;
 Gondrom - Governance&lt;br /&gt;
&lt;br /&gt;
 Brennan - Projects&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/a/owasp.org/document/d/1lz4Yb2byWSbayRmpKksHhR_fHJ3eoL8aWMZMEpfnIXg/edit?usp=sharing Rollup Report]&lt;br /&gt;
** Financial Update - [https://drive.google.com/a/owasp.org/file/d/0BxI4iTO_QojvT0lNMi1kci1pZlNaaGNYNVdOTVBrS0ItWkQ0/view?usp=sharing 3.31.16 Board Summary Combined] [https://drive.google.com/a/owasp.org/file/d/0BxI4iTO_QojvMVhLTHpKZnE4cm1LVUxaOWJUWHdieXBKLVhv/view?usp=sharing 3.31.16 Combined Balance Sheet]&lt;br /&gt;
** Director Update - Kate Hartmann - see rollup report above&lt;br /&gt;
** Project Coordinator Update -[https://docs.google.com/a/owasp.org/presentation/d/1IV-38LAd7SDg3S8McFTIJ-fresSqQl0RBk36UPfqg_Q/edit?usp=sharing| Claudia Aviles Casanovas Update]&lt;br /&gt;
** Membership Update - [https://www.owasp.org/index.php/April_2016_Membership_Report Kelly Santalucia Update]&lt;br /&gt;
** [https://docs.google.com/a/owasp.org/document/d/1qU5YYJ4ETplIEY2vGriuxXdKua7QGAvknK4q9Ni87Yc/edit?usp=sharing| Conference Manager Report] - Laura Grau&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* * Andrew van der Stock - Succession planning. Discussion &amp;amp; Vote [10 minutes]&lt;br /&gt;
** vote needed - please see reading material above for the motion&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
AppSec Middle East&lt;br /&gt;
- [Proposal https://docs.google.com/presentation/d/1K9JZ5-jBfWedDgjuN4QftP5UDxFS6GQ6Jr5SaVgKrCQ/edit?usp=sharing]&lt;br /&gt;
- [Event Discussion https://www.owasp.org/index.php/Category:OWASP_AppSec_Conference] AppSec Global / Regional&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time:  F2F June - Date/Time TBD&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=216914</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=216914"/>
				<updated>2016-05-16T00:20:49Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Our next  event */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/230159088/ May 18, 2016 - San Francisco]&lt;br /&gt;
&lt;br /&gt;
Check out our meetup page for upcoming events:&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
== Mentorship Program ==&lt;br /&gt;
* OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
* First meeting will be held on December 1 &lt;br /&gt;
** Complete the following form [https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
** Then [http://www.meetup.com/Bay-Area-OWASP/ RSVP for the meetup]&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
[[Category:United_States]]&lt;br /&gt;
[[Category:California]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=February_17,_2016&amp;diff=209131</id>
		<title>February 17, 2016</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=February_17,_2016&amp;diff=209131"/>
				<updated>2016-02-17T22:36:46Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Updates from Members at Large */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
* [https://www.dropbox.com/s/9v88xcox5rb6pkc/2016-01-13%2016.09%20OWASP%20Board%20Meeting.wmv?dl=0 Recording of 13 January 2016 OWASP Board Meeting]&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
* February 17, 2016, 15:00-16:30 PST - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=02&amp;amp;day=17&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
* [https://docs.google.com/a/owasp.org/document/d/1J9BZ2DIgItMpajbAaPGzA1HcbkVQ5SKzfLUFDa06H4s/edit?usp=sharing Feb.17 Minutes template]&lt;br /&gt;
* [https://docs.google.com/document/d/1NgJB0B98pP2-THUMks0fNf_yZmGsDKs_uCJMsAYuZ-Y/edit Jan.2016 Meeting Minutes for Approval]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
1.  [https://docs.google.com/document/d/1PvNeEWgoO1w51VhHLwqqSgo0mBh-RvmSFUKMTz4QrYg/edit?pref=2&amp;amp;pli=1#heading=h.lw77ixr6kxi Proposal from Johanna on OWASP-Project-Review Updates &amp;amp; Incentives]&lt;br /&gt;
*  Should Project Task Force be 'relaunched' as Project-Review-Committee with same Committee 2.0 procedures and authority?&lt;br /&gt;
*  Some questions in the proposal may be resolved at Committee level, without needing board motion &amp;amp; approval. (P.Ritchie interpretation)&lt;br /&gt;
* [https://docs.google.com/document/d/1QPaSEgNOkfOkk8L4X-PDT2WA9ya1E6braN5-JfgEzMQ/edit?usp=sharing  Summary of Questions &amp;amp; response from Johanna dated Feb.10, 2016]&lt;br /&gt;
&lt;br /&gt;
2.  &amp;gt;&amp;gt; READ Staff Status reports below, including Detail Financial Report for 2015 through December 2015 in Excel format.  P&amp;amp;L,  A/R,  A/P, Balance Sheet with cash balances for Foundation &amp;amp; Chapters &amp;amp; Projects&lt;br /&gt;
&lt;br /&gt;
3.[https://www.owasp.org/index.php/Help_Secure_Owasp_assests Help Secure OWASP assets initiative, contributions from volunteers ]&lt;br /&gt;
* Which companies or individuals can contribute to help manage Wiki &amp;amp; mailing list with maintenance and patching?&lt;br /&gt;
* Status of Bug Bounty management services for projects and other OWAPS assists as the WIKI - through Barter Deals with service providers&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
Open Meeting - Start Recording, List attendees and Agenda update (only if last-minute changes are needed) (5 min)&lt;br /&gt;
* Approve minutes from January 13, 2016.&lt;br /&gt;
&lt;br /&gt;
== Actionable Agenda Topics ==&lt;br /&gt;
&lt;br /&gt;
* TO DO&lt;br /&gt;
* Review, discuss, act on Johanna proposal.  See reading material above.&lt;br /&gt;
&lt;br /&gt;
== Discussion Topics ==&lt;br /&gt;
* OWASP Infrastructure Transformation. AJV. &lt;br /&gt;
&lt;br /&gt;
* Help Secure OWASP assets &lt;br /&gt;
https://www.owasp.org/index.php/Help_Secure_Owasp_assests&lt;br /&gt;
&lt;br /&gt;
== Misc. Topics  (10-15 Minutes) ==&lt;br /&gt;
* Temperature on Training + Leader Summit&lt;br /&gt;
* Second 5K sponsor package as outlined here:  https://docs.google.com/document/d/1NG8C27_RuNmwfTnrUE_-gB5IyHlmTYo1lv-CTXo25p8/edit&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
* Matt K:  Action / Update on search for OWASP Compliance officer&lt;br /&gt;
&lt;br /&gt;
* Paul R:  Action - Need clarification.  Under financial proposal #3 &amp;amp; 4.  Do 'Projects' require 2 leaders, or just 1 leader and 1 other active participant?  Various emails recommend the latter.  Staff recommends 1 leader plus 1 active participant for definition of active project.&lt;br /&gt;
**  See Oct. 14, 2015 Votes here.  https://www.owasp.org/index.php/OWASP_Board_Votes&lt;br /&gt;
&lt;br /&gt;
**  Chapters are being managed with a 2 leader requirement.&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* TO DO&lt;br /&gt;
* See Johanna new Project Review proposal above.&lt;br /&gt;
&lt;br /&gt;
== Action Item Follow-Up ==&lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1LtYN2QSCUBSM53_M0HGAISqiGiXbxO9k8LXv2ZoIVgQ/edit?usp=sharing  2016 Action Item Status from Past BoD Meetings]&lt;br /&gt;
** This is new excel sheet showing AI as either OPEN or Closed with status for monthly Board reporting&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Matt Konda ===&lt;br /&gt;
*  Identified compliance team.  (Fiona, Bil, Richard)&lt;br /&gt;
*  ED annual review underway.  (Feedback solicited, reviewing materials)&lt;br /&gt;
*  Handoff from Tobias.&lt;br /&gt;
*  Financials call with Andrew and Virtual&lt;br /&gt;
*  Talked to 6 potential sponsors.&lt;br /&gt;
*  Participated in Project call.&lt;br /&gt;
*  Wrote sponsor letter for AppSecEU&lt;br /&gt;
*  Discussion with Kate about Training + Leader Summit and software sponsor tier.&lt;br /&gt;
*  Weekly one on one call.&lt;br /&gt;
Detail here:  https://trello.com/b/YWY4pf8I/global-board&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Josh Sokol ===&lt;br /&gt;
*TODO&lt;br /&gt;
=== Treasurer Report - Andrew van der Stock ===&lt;br /&gt;
&lt;br /&gt;
I have had a kick off meeting with Paul, Alison, Matt, and Tom Pappas (our CFO) from Virtual to discuss a financial handover. &lt;br /&gt;
&lt;br /&gt;
This meeting went well, and filled in a number of gaps for me. The main action items from my point of view are:&lt;br /&gt;
&lt;br /&gt;
* Establishing an OWASP archive for our financial and other corporate records that is accessible by Alison so we don't lose the lot if something happened to Alison's residence or computer. This applies primarily to our old records, which we need to keep for 7 years, but aren't necessarily used daily. &lt;br /&gt;
* Ensuring that our FY15 year is closed out and our annual report is ready on time. This seems to be in hand, but I will keep on eye on things.&lt;br /&gt;
* Paul is considering moving our accounts to a better financial institution as our current one requires us to use yet another payment service. This should improve our visibility of bills and make reconciliation easier. I support this move, as it should improve our transparency and reduce costs.  &lt;br /&gt;
* Once we have final reconciliation and the FY15 books are closed, I will ask my wife (a CPA) to look over the records to ensure things are okay. &lt;br /&gt;
&lt;br /&gt;
Additionally, I asked about a line of credit that I heard was being established. Apparently there is something happening here. My main concern is that it shows up on the books so we can make sure we don't get into trouble by using it for operational expenditure unnecessarily. I understand the need for it, but we could easily get into trouble if we are paying bills on credit without a supporting income.&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report - Jim Manico  ===&lt;br /&gt;
*TODO&lt;br /&gt;
=== Updates from Members at Large  ===&lt;br /&gt;
* Michael Coates (Chapters)&lt;br /&gt;
** Focus areas for investment into chapters this year include:&lt;br /&gt;
*** Chapter Leader Call by region (work with staff)&lt;br /&gt;
*** Chapter speaker rating system&lt;br /&gt;
*** Centralized chapter speaker recommendation system&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director Status Report for 17 Feb 2016   [https://docs.google.com/document/d/131tVN6DamrOat1Io4ez3Nn4nVc_1iekeiEoUGhhTpf4/edit?usp=sharing Exec.Director Status Report - 17Feb2016]&lt;br /&gt;
** [https://docs.google.com/spreadsheets/d/1OdiijD2toRgkhIKupbrFMqAEZSBH_NrTxHxkKe7XDzM/edit?usp=sharing  Detail 2015 Financial Report through Dec. 2015 in Excel Format]  Note:  These are PRELIMINARY numbers and will be final once the 2015 Books are officially 'closed' by Accounting firm approx. Mar 1, 2016&lt;br /&gt;
* Membership &amp;amp; Business Liaison Report - Kelly Santalucia [https://www.owasp.org/index.php/January_2016_Membership_Report January Membership Report] [https://docs.google.com/a/owasp.org/document/d/1GTC7FT1VYGird1gnKXwbziyOAUYDqNkm9HwPHPnXFc4/edit?usp=sharing Strategic Goal #2 Report and CodeMash 2016 update]&lt;br /&gt;
* Event Manager Report - Laura Grau [https://www.owasp.org/images/5/5b/February2016ConferenceManagerReport.pdf February Report]&lt;br /&gt;
* Operations Report - Kate Hartmann [https://docs.google.com/a/owasp.org/document/d/1gM66GBHD1y_Q3s9x_mz6hGASRhVM8nXQIwnE1TUYYyU/edit?usp=sharing report]&lt;br /&gt;
* Project Coordinator Report - Claudia Casanovas [https://docs.google.com/a/owasp.org/presentation/d/1bPsEydCrPZ_Xwm639h2GTjC1V7YCPawCoT-cjVnDEAs/edit?usp=sharing Report]&lt;br /&gt;
* Community Manager Report -Noreen Whysel [https://docs.google.com/a/owasp.org/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit?usp=docslist_api Report]&lt;br /&gt;
* IT Update from Matt T.&lt;br /&gt;
** MediaWiki has been updated 3 times since AppSec USA 2015 (Sept. 2015)&lt;br /&gt;
** Upgrade to Mailman 3.0 &amp;amp; server delayed due to Website demands from CalifAppSec Team 'emergency',  AppSec USA &amp;amp; AppSec EU website builds.&lt;br /&gt;
** Some dead and inactive email lists cleaned out.  Generally low priority re: other demands.&lt;br /&gt;
** 10 hours /month is completely too little for demands from Community, especially for breakage &amp;amp; repair after Matt sets items up for community use. (Matt has details &amp;amp; examples)&lt;br /&gt;
**  Net, net Paul now working with staff and Matt T to define how to add resource with 'Matt level access' to cover more common community support needs, vs. Infrastructure/domain/server admin to remain with Matt T.   &lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
* TODO&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
* Willing to shift to March 15?&lt;br /&gt;
* Next meeting date/time: [[March 16, 2016]], 16:00-17:00 PST - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=03&amp;amp;day=16&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152  TimeZone Converter ]&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Board&amp;diff=206036</id>
		<title>Board</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Board&amp;diff=206036"/>
				<updated>2016-01-07T20:40:34Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Upcoming 2016 Meetings */ fixed ugly links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
= About the OWASP Board =&lt;br /&gt;
&lt;br /&gt;
== Current OWASP Global Board 2016 ==&lt;br /&gt;
&lt;br /&gt;
* [[User:Tgondrom|Tobias Gondrom]]  Hong Kong - tobias.gondrom(at)owasp.org&lt;br /&gt;
* [[User:Jsokol|Josh Sokol]] Texas, USA - josh.sokol(at)owasp.org&lt;br /&gt;
* [[User:brennan|Tom Brennan]]  New Jersey - tomb(at)owasp.org &lt;br /&gt;
* [[Matt Konda]]  Chicago, USA - matt.konda(at)owasp.org&lt;br /&gt;
* [[User:MichaelCoates|Michael Coates]] -  California, USA - michael.coates(at)owasp.org&lt;br /&gt;
* [[Andrew van der Stock]]  Australia - vanderaj(at)owasp.org&lt;br /&gt;
* [[User:Jmanico|Jim Manico]]  Hawaii - jim(at)owasp.org&lt;br /&gt;
&lt;br /&gt;
== OWASP Board Elections ==&lt;br /&gt;
=== 2015 Election ===&lt;br /&gt;
[https://www.owasp.org/index.php/2015_Global_Board_of_Directors_Election 2015 Board Election]&lt;br /&gt;
=== 2014 Election ===&lt;br /&gt;
[https://www.owasp.org/index.php/2014_Board_Elections 2014 Board Election]&lt;br /&gt;
=== 2013 Election ===&lt;br /&gt;
[https://www.owasp.org/index.php/2013_Board_Elections 2013 Board Election]&lt;br /&gt;
=== 2012 Election ===&lt;br /&gt;
[https://www.owasp.org/index.php/Membership/2012_Election 2012 Board Election]&lt;br /&gt;
=== 2011 Election ===&lt;br /&gt;
[https://www.owasp.org/index.php/Membership/2011Election 2011 Board Election]&lt;br /&gt;
=== 2009 Election ===&lt;br /&gt;
[https://www.owasp.org/index.php/Board_Election_2009 2009 Board Election]&lt;br /&gt;
&lt;br /&gt;
= Agenda for 2016 Meetings =&lt;br /&gt;
&lt;br /&gt;
* Teleconference Information: **CHECK MEETING INFORMATION**&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/International_Toll_Free_Calling_Information International Toll Free Calling Info]&lt;br /&gt;
&lt;br /&gt;
* [https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracking]&lt;br /&gt;
* Meeting Template found [https://www.owasp.org/index.php/Board-Meeting-template here]&lt;br /&gt;
&lt;br /&gt;
== Upcoming 2016 Meetings ==&lt;br /&gt;
&lt;br /&gt;
* [[January 13, 2016]], 16:00-17:30 PST - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=01&amp;amp;day=14&amp;amp;hour=00&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[February 17, 2016]], 15:00-16:30 PST - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=02&amp;amp;day=17&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[March 16, 2016]], 16:00-17:00 PST - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=03&amp;amp;day=16&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152  TimeZone Converter ]&lt;br /&gt;
* [[April 20, 2016]], 16:00-17:00 PDT - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=04&amp;amp;day=20&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[May 18, 2016]],  07:00-08:30 PDT - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=05&amp;amp;day=18&amp;amp;hour=14&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[July 1, 2016]], 18:00-21:00 CEST, in Rome at AppSecEU - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=07&amp;amp;day=01&amp;amp;hour=16&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[July 27, 2016]], 07:00-08:00 PDT - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=07&amp;amp;day=27&amp;amp;hour=14&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[August 24, 2016]], 16:00-17:00 PDT - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=08&amp;amp;day=24&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[September 21, 2016]] 07:00-08:30 PDT - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=09&amp;amp;day=21&amp;amp;hour=14&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[October 14, 2016]], at AppSecUSA 18:00 - 21:00 EDT - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=10&amp;amp;day=14&amp;amp;hour=22&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[November 9, 2016]], 15:00-16:30 PST - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=11&amp;amp;day=09&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[November 30, 2016]], 15:00-16:30 PST - placeholder only optional if needed - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=11&amp;amp;day=30&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
* [[December 14, 2016]], 15:00-16:30 PST - [http://www.timeanddate.com/worldclock/meetingdetails.html?year=2016&amp;amp;month=12&amp;amp;day=14&amp;amp;hour=23&amp;amp;min=0&amp;amp;sec=0&amp;amp;p1=224&amp;amp;p2=24&amp;amp;p3=263&amp;amp;p4=78&amp;amp;p5=37&amp;amp;p6=102&amp;amp;p7=152 TimeZone Converter ]&lt;br /&gt;
&lt;br /&gt;
= Board Communication =&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Foundation_ByLaws ByLaws]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/Governance/Conflict_of_Interest_Policy Conflict of Interest Policy and Signed Conflict Statements]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://docs.google.com/a/owasp.org/folder/d/0BxI4iTO_QojvNW9jaXFyWGZwR28/edit Weekly Board/Staff Communication Documents]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.google.com/calendar/embed?src=owasp.org_d1dcflbc5oul9nji1ftc3pjji8@group.calendar.google.com&amp;amp;ctz=Pacific/Honolulu OWASP Board Calendar]&lt;br /&gt;
&lt;br /&gt;
== Best practices ==&lt;br /&gt;
&lt;br /&gt;
Note: these best practices are merely a collection of procedures deemed good process for a board. '''They are not binding''' and have not been voted on or ratified by the board to this date. Online: [http://www.rulesonline.com/rror--00.htm http://www.rulesonline.com/rror--00.htm]&lt;br /&gt;
&lt;br /&gt;
=== Best Practices for Board conduct:===&lt;br /&gt;
We consider it best practices for our board to follow in spirit the &amp;quot;Robert's Rules of Order&amp;quot;.&lt;br /&gt;
* That means that board votes require a motion brought forth by one board member and to be seconded by an other board member. &lt;br /&gt;
** A motion should be specific, unique, and concise. It should include all the relevant details, be unambiguous, and leave as little room for interpretation as possible. &lt;br /&gt;
* After the motion has been seconded the board may discuss the issue and / or vote on it. &lt;br /&gt;
&lt;br /&gt;
A board member makes a motion and the board waits for your motion to be seconded. With few exceptions, all motions need to be seconded by another member of the Board. This is to ensure that the Board does spend its time effectively and not evaluating a proposal which only one member favors. &lt;br /&gt;
* In a formal setting, they will say something along the lines of &amp;quot;I second the motion,&amp;quot; or even just &amp;quot;I second.&amp;quot;&lt;br /&gt;
* In certain cases, such as when a general consensus is apparent, the presiding officer can choose to skip this step and move on to the next one.&lt;br /&gt;
&lt;br /&gt;
= Archive and Voting History =&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Board_History Historical Board Members by Year]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Board_Votes Historical Board Votes]&lt;br /&gt;
&lt;br /&gt;
=== Past OWASP Boards ===&lt;br /&gt;
[[Board-2014]]&lt;br /&gt;
&lt;br /&gt;
[[Board-2013]]&lt;br /&gt;
&lt;br /&gt;
[[Board-2012]]&lt;br /&gt;
&lt;br /&gt;
[[Board-2011]]&lt;br /&gt;
&lt;br /&gt;
== Archive for 2015 Meetings ==&lt;br /&gt;
* [[December 9, 2015]], 15:00-17:00 PST &lt;br /&gt;
* [[November 18, 2015]], 14:00-15:30 PST&lt;br /&gt;
* [[November 4, 2015]], 12:00-13:30 PST&lt;br /&gt;
* [[October 14, 2015]], 14:00-15:00 PDT&lt;br /&gt;
* [[September 25, 2015]] at AppSecUSA 18:00 - 20:00 PST&lt;br /&gt;
* [[August 12, 2015]], 16:00-17:00 PST&lt;br /&gt;
* [[July 22, 2015]], 14:00-15:00 PDT&lt;br /&gt;
* [[June 24, 2015]], 14:00-15:00 PDT&lt;br /&gt;
* [[May 22, 2015]],  18:00-20:00 CEST in Amsterdam @ AppSec-EU , 9:00am-11:00am PST;&lt;br /&gt;
* [[April 29, 2015]], 12:00-13:00 PST&lt;br /&gt;
* [[March 25, 2015]], 12:00-13:00 PST &lt;br /&gt;
* [[February 11, 2015]], 16:00-17:00 PST&lt;br /&gt;
* [[January 14, 2015]], 9am-10am PST&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Archive for 2014 Meetings ==&lt;br /&gt;
* [[December 10, 2014]], 9am-10am PST&lt;br /&gt;
* [[November 12, 2014]], 9am - 10am PST&lt;br /&gt;
* [[October 8, 2014]], 9am-10am PST&lt;br /&gt;
* [[September 16, 2014]], 6pm - 9pm MST, In person at Appsec USA &lt;br /&gt;
* [[August 13, 2014]], 9am-10am PST&lt;br /&gt;
* [[July 9, 2014]], 9am-10am PST&lt;br /&gt;
* [[June 27, 2014]], 8am - 4 pm BST, In person at AppSec Europe&lt;br /&gt;
* [[April 30, 2014]],9am - 12pm PST&lt;br /&gt;
* [[March 3, 2014]], 7am - 10am PST&lt;br /&gt;
* [[February 24, 2014]], 8am - 10am PST&lt;br /&gt;
&lt;br /&gt;
== Archive for 2013 Meetings ==&lt;br /&gt;
&lt;br /&gt;
*[[December 9, 2013]]&lt;br /&gt;
&lt;br /&gt;
* December 2, 2013 - Special Board Meeting - [https://docs.google.com/spreadsheet/ccc?key=0ApZ9zE0hx0LNdGdJZ1BIaEZkc2V1QV81NmJ4dnI0R1E&amp;amp;usp=sharing 2014 Budget] walk through, Q &amp;amp; A (no meeting notes)&lt;br /&gt;
&lt;br /&gt;
*[[November 22, 2013]] - In person meeting at AppSec USA - New York, NY&lt;br /&gt;
&lt;br /&gt;
* November 11, 2013 - cancelled due to in person meeting on Nov. 22&lt;br /&gt;
&lt;br /&gt;
*[[October 14, 2013]]&lt;br /&gt;
&lt;br /&gt;
*[[September 9, 2013]]&lt;br /&gt;
&lt;br /&gt;
*[[In person meeting at AppSec EU - Hamburg, Germany; August 19-24]]&lt;br /&gt;
&lt;br /&gt;
* August 12, 2013 - canceled due to in person meeting on Aug 19&lt;br /&gt;
&lt;br /&gt;
*[[July 8, 2013]]&lt;br /&gt;
&lt;br /&gt;
*[[June 10, 2013]]&lt;br /&gt;
&lt;br /&gt;
*[[May 31, 2013]]&lt;br /&gt;
&lt;br /&gt;
*[[May 13, 2013]]&lt;br /&gt;
&lt;br /&gt;
*[[April 8, 2013]]&lt;br /&gt;
&lt;br /&gt;
*[[March 11, 2013]]&lt;br /&gt;
&lt;br /&gt;
*[[February 11, 2013]]&lt;br /&gt;
&lt;br /&gt;
*[[January 14, 2013]]&lt;br /&gt;
&lt;br /&gt;
== Archive for 2012 Meetings ==&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracking]&lt;br /&gt;
&lt;br /&gt;
OWASP Foundation [https://www.owasp.org/images/a/ae/2012ByLawsFINAL.pdf ByLaws]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/Global_Committee_Pages Global Committees] &lt;br /&gt;
&lt;br /&gt;
*[[January 9, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[February 6, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[February 15, 2012]] &lt;br /&gt;
&lt;br /&gt;
*[[March 12, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[April 5, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[May 14,2012]]&lt;br /&gt;
&lt;br /&gt;
*[[June 11, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[July 11, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[Aug 13, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[Sept 10, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[Oct 8, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[Oct 24, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[Nov 12, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[Nov 26, 2012]] - 2013 Budget Focused&lt;br /&gt;
&lt;br /&gt;
*[[Dec 10, 2012]]&lt;br /&gt;
&lt;br /&gt;
*[[Dec 27, 2012]] - 2013 Budget Focused&lt;br /&gt;
&lt;br /&gt;
== Archive for 2011 Meetings ==&lt;br /&gt;
&lt;br /&gt;
*[[January 3, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[March 7, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[April_4_2011]]&lt;br /&gt;
&lt;br /&gt;
*[[May_2_2011]]&lt;br /&gt;
&lt;br /&gt;
*[[June 6, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[July 11, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[August 8, 2011]] &lt;br /&gt;
&lt;br /&gt;
*[[September 6, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[September 20, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[September 22, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[October 10, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[November 14, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[December 5, 2011]]&lt;br /&gt;
&lt;br /&gt;
== Minutes for 2011 Meetings ==  &lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/OWASP_Board_Votes Board Votes Historical]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
*[[Minutes January 3, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes March 8, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes April 4, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes May 2, 2011]]&lt;br /&gt;
&lt;br /&gt;
*[https://docs.google.com/a/owasp.org/document/d/1VD9ZHEwht9tmM8FKEQ6DBrtmL_gTAhSSnQhiFXYkJ7I/edit?hl=en_US&amp;amp;authkey=CIavkP4B June 6 2011]&lt;br /&gt;
&lt;br /&gt;
*[https://docs.google.com/a/owasp.org/document/d/1VMwYrP6owtZ-SchBxUcWTIF-ITvzUX8PjUkLPwr2ipg/edit?hl=en_US&amp;amp;authkey=CIGTx5sD July 11 2011]&lt;br /&gt;
&lt;br /&gt;
*[https://docs.google.com/a/owasp.org/document/d/1CLu9aQpS7LdeX87rJ5N9cuJ-RGGVzDWf34l6gdMml7M/edit?hl=en_US&amp;amp;authkey=CI-U5qEP August 8, 2011]&lt;br /&gt;
&lt;br /&gt;
*[https://docs.google.com/a/owasp.org/document/d/1HM32VcvWb0hizD5_mhWMULLaouzuRgA3ZYjODRZwyAs/edit?hl=en_US September 6, 2011]&lt;br /&gt;
&lt;br /&gt;
*[https://docs.google.com/a/owasp.org/document/d/1Y-8tZisUZM5ZKP8AxJqvkiNtFanVFM0m--bMG2PZ3ww/edit October 10, 2011]&lt;br /&gt;
&lt;br /&gt;
*[https://docs.google.com/a/owasp.org/document/d/13-aHX2pSUXjCP8ivsbls6u1VX1BVSYewyMUH8LI7zpQ/edit November 14, 2011]&lt;br /&gt;
&lt;br /&gt;
== Archive for 2010 Meetings ==&lt;br /&gt;
*[[January 5, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[February 2, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[March 2, 2010]] &amp;lt;span style=&amp;quot;color:blue&amp;quot;&amp;gt;Postponed until March 9, 2010&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
*[[April 6, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[May 4, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[June 7, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[July 12, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[August 2, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[September 8, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[October 11, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[November 9, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[December_6_2010]]&lt;br /&gt;
&lt;br /&gt;
== Archive of 2010 Meetings ==&lt;br /&gt;
&lt;br /&gt;
*[[Jan 5, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[Feb 2, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[March 2, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes April 6, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes May 11, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes June 7, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes July 12, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes October 11, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes November 9, 2010]]&lt;br /&gt;
&lt;br /&gt;
*[[Minutes_December_6,_2010]]&lt;br /&gt;
&lt;br /&gt;
*[[OWASP Board Meetings January Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings February Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings March Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings April09 Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings May09 Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings June 09 Agenda]]&lt;br /&gt;
*[[OWASP Board Meeting July 7, 2009 Agenda]]&lt;br /&gt;
*[[OWASP Board Meeting August 4, 2009 Agenda]]&lt;br /&gt;
*[[OWASP Board Meeting September 1, 2009 Agenda]] &lt;br /&gt;
*[[OWASP Board Meeting October 6, 2009 Agenda]]&lt;br /&gt;
*[[OWASP Board Meeting November 10, 2009 Agenda]]&lt;br /&gt;
*[[OWASP Board Meeting December 1, 2009 Agenda]]&lt;br /&gt;
&lt;br /&gt;
== Archive of 2009 Meetings ==&lt;br /&gt;
* [[OWASP Board Meetings 01-06-09]]&lt;br /&gt;
* [[OWASP Board Meetings 02-03-09]]&lt;br /&gt;
* [[OWASP Board Meetings 03-10-09]]&lt;br /&gt;
* [[OWASP Board Meetings April 09]]&lt;br /&gt;
* [[OWASP Board Meetings May 09]]&lt;br /&gt;
* [[OWASP Board Meetings June 09]]&lt;br /&gt;
* [[OWASP Board Meeting July 09]]&lt;br /&gt;
* [[OWASP Board Meeting August 09]]&lt;br /&gt;
* [[OWASP Board Meeting September 09]]&lt;br /&gt;
* [[OWASP Board Meeting October 09]]&lt;br /&gt;
* [[OWASP Board Meeting December 09]]&lt;br /&gt;
&lt;br /&gt;
== Archive for 2008 Meetings ==&lt;br /&gt;
*[[OWASP Board Meetings March Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings April Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings May Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings June Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings July Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings August Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings September Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings October Agenda]]&lt;br /&gt;
*[[OWASP Board Meetings December Agenda]]&lt;br /&gt;
&lt;br /&gt;
== Archive of 2008 Meetings ==&lt;br /&gt;
* [[OWASP Board Meetings 2-7-08]]&lt;br /&gt;
* [[OWASP Board Meetings 3-6-08]]&lt;br /&gt;
* [[OWASP Board Meetings 5-6-08]]&lt;br /&gt;
* [[OWASP Board Meetings 6-3-08]]&lt;br /&gt;
* [[OWASP Board Meetings 8-14-08]]&lt;br /&gt;
* [[OWASP Board Meetings 9-2-08]] &lt;br /&gt;
* [[Owasp Board Meetings 10-07-08]]&lt;br /&gt;
* [[Owasp Board Meetings 11-07-08]]&lt;br /&gt;
* [[Owasp Board Meetings 12-02-08]]&lt;br /&gt;
&lt;br /&gt;
= Board Focus Ideas  =&lt;br /&gt;
&lt;br /&gt;
== First suggested priority of Board  from Paul ==&lt;br /&gt;
* What are the top 5 &amp;quot;Initiatives&amp;quot; we want or believe the OWASP Community should be focusing on in 2016-2017? (Areas that should receive our time effort &amp;amp; money.)&lt;br /&gt;
* Intent here is to stimulate a Board level &amp;amp; Community discussion about strategic goals, and then actionable objectives that.....a) align with mission of OWASP, and b) stimulate enough interest at Community level to cause volunteers to engage &amp;amp; participate, and c) produce output of value and benefit to owasp community on a Global basis.&lt;br /&gt;
&lt;br /&gt;
== Projects Ideas==&lt;br /&gt;
&lt;br /&gt;
* Project Review &amp;amp; Project Platform - good progress, keep it going. We need &amp;quot;more&amp;quot; volunteer engagement to provide more diverse review.&lt;br /&gt;
* New Project Ideas. Where is industry going, where will it be in 5 years? OWASP should suggest projects that we need and find team to build them!&lt;br /&gt;
* Project Summit support &amp;amp; funding&lt;br /&gt;
* International Chapter / Region support &amp;amp; funding for projects&lt;br /&gt;
* Hire full or part time technical writer to help with project (from Simon, flagship project lead)&lt;br /&gt;
* a platform for funding pull requests / contributions to projects - this could be a way to financially reward folks for contributing. I know ZAP recently experimented with this - not sure how it went, but we have money - might be a good way to spend it (maybe leveraging something like the bithub idea https://whispersystems.org/blog/bithub/). I would want the ability to personally remove myself from the ability of receiving payment. (from John Melton, flagship project lead)&lt;br /&gt;
* help with applying for grants - including letting us know of available grants and helping us do the paperwork if necessary&lt;br /&gt;
* make inter-project recommendations - since you sit at a level where you see various projects, maybe make recommendations for areas where multiple projects could collaborate for added value  (from John Melton, flagship project lead)&lt;br /&gt;
* project of the month - this may already happen, but if not, maybe the newsletter could feature a project every month, including information like a project overview, an audio interview with the project leader(s), a list of priority tasks for people to help with, etc.  (from John Melton, flagship project lead)&lt;br /&gt;
* get access to available free tools - I've actually seen several tools that are available for use within OWASP, though I hear about them haphazardly. It would be good if there were a single resource for leads to know what was available. Thinking of things like: free licenses of paid software (intellij, webex) or access to products/services (surveymonkey, AWS, GCE or Azure credits) that could be useful to the project  (from John Melton, flagship project lead)&lt;br /&gt;
* conducting surveys - We do surveys periodically, and I fill them out. Joanna has used them to good effect. We might be able to make that more regular and get good data on our projects.&lt;br /&gt;
* &amp;quot;help wanted&amp;quot; site - We use github issues on our project. However, one thing I hear repeatedly is project leaders saying they need help, and owasp members asking how to help. It seems like we could put up a &amp;quot;jobs&amp;quot; board of some kind to connect folks within the community for things like this. We could probably connect this to $ in some way if we wanted to. I imagine there's a tool out there that already does this too.  (from John Melton, flagship project lead)&lt;br /&gt;
* continue and expand &amp;quot;summer of code&amp;quot; programs - I believe these programs add lots of value. Not only do they get practical things done on the projects, but they give us good visibility, get people involved in the projects (many continue to contribute), give us good press in the community, and invigorate the mentors as well.  (from John Melton, flagship project lead)&lt;br /&gt;
&lt;br /&gt;
== Training ==&lt;br /&gt;
* Training is OK now....but what do we want to do here?  Business as usual?&lt;br /&gt;
* Update current project level training docs, or&lt;br /&gt;
* Begin some form of Curriculum for Academic use?&lt;br /&gt;
&lt;br /&gt;
== Advocacy==&lt;br /&gt;
* Liaison with other Orgs&lt;br /&gt;
** ID those Developer groups and go to their conferences &amp;amp; meetings&lt;br /&gt;
** ...just a few, but caution is to approach 1-2 at a time and get an outcome&lt;br /&gt;
* Regulatory policy (lobbying).  OK, if its is a hot topic to some....then BoD should encourage it and help first set of people get that WG started and  provide small set of guidelines on Advocacy vs. Lobbying.&lt;br /&gt;
* Crank out true press releases or blogs say on quarterly basis when we have couple public releases.&lt;br /&gt;
* Consider WG and provide small set of guidelines on Advocacy vs. Lobbying.&lt;br /&gt;
&lt;br /&gt;
== Community Portals ==&lt;br /&gt;
* Should be our goto destination for owasp community to access for current &amp;amp; relevant info on OWASP activities.   &lt;br /&gt;
* Focused WG to take action on Wiki Cleanup &amp;amp; ease of use. &lt;br /&gt;
* Consider funding larger wiki cleanup and migration effort (Jim)&lt;br /&gt;
&lt;br /&gt;
== Marketing ==&lt;br /&gt;
* General PR &amp;amp; Marketing the OWASP Story - Promote ourselves more!&lt;br /&gt;
* Crank up a Recruiting program - Both Corporate &amp;amp; Individual.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=203650</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=203650"/>
				<updated>2015-11-20T22:27:25Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Mentorship Program */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
Bay Area Mentorship Program - Meeting #1&lt;br /&gt;
&lt;br /&gt;
San Francisco&lt;br /&gt;
&lt;br /&gt;
December 1&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
== Mentorship Program ==&lt;br /&gt;
* OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
* First meeting will be held on December 1 &lt;br /&gt;
** Complete the following form [https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
** Then [http://www.meetup.com/Bay-Area-OWASP/ RSVP for the meetup]&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=203642</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=203642"/>
				<updated>2015-11-20T17:55:17Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! &lt;br /&gt;
&lt;br /&gt;
Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
== Our next  event ==&lt;br /&gt;
Bay Area Mentorship Program - Meeting #1&lt;br /&gt;
&lt;br /&gt;
San Francisco&lt;br /&gt;
&lt;br /&gt;
December 1&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/226890416/? More info on meetup.com]&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
= Mentorship Program =&lt;br /&gt;
OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=203641</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=203641"/>
				<updated>2015-11-20T17:53:58Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&lt;br /&gt;
= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings are posted on meetup! Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for all chapter event information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/ OWASP Bay Area Meetup] - All events can be found here&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
OWASP AppSecUSA was held in San Francisco in September, 2015 - the biggest OWASP conference to date!&lt;br /&gt;
&lt;br /&gt;
Chapter meetings can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
==== 2014 Past Events ====&lt;br /&gt;
* December 2014 - San Francisco @ Mozilla&lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
** Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
** Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
* August 2014 - San Francisco @ Lookout &lt;br /&gt;
** OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
** Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
** Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
*May 2014 - Redwood City @ Evernote &lt;br /&gt;
** OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
** Arshad Noor - CTO, StrongAuth&lt;br /&gt;
** Rich Tener - Director of Security, Evernote&lt;br /&gt;
* March 2014 - San Francisco @ Stripe&lt;br /&gt;
** OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
** Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
* Feb 2014 - San Jose @ Jillians&lt;br /&gt;
** OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
** Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
*Feb 2014 - Special Free Training Event&lt;br /&gt;
** OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
** Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
*Jan 2014 - San Jose @ F5&lt;br /&gt;
** OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
** Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
==== 2013 Past Events ====&lt;br /&gt;
*Dec 2013 - San Francisco @ Twilio&lt;br /&gt;
** OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
** Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
*Nov 2013 - San Francisco @ LendingClub&lt;br /&gt;
** OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
** Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
* Sept 2013 - Mt View @ Shape Security&lt;br /&gt;
** OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
** Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
*July 2013 - Berkeley @ University of Berkely&lt;br /&gt;
** OWASP Presentation Meeting&lt;br /&gt;
** An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
** &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Neal Mueller&lt;br /&gt;
* Astha Singhal&lt;br /&gt;
* Katherine Carpenter&lt;br /&gt;
* Siva Yenamareddy&lt;br /&gt;
&lt;br /&gt;
= Mentorship Program =&lt;br /&gt;
OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
* [http://lists.owasp.org/mailman/listinfo/owasp-bayarea Bay Area Mailing List]&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=October_14,_2015&amp;diff=202132</id>
		<title>October 14, 2015</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=October_14,_2015&amp;diff=202132"/>
				<updated>2015-10-14T18:43:01Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[https://www.dropbox.com/s/3r1kvgds37667sb/2015-09-25%2018.23%20OWASP%20Board%20Meeting.wmv?dl=0  Recording of 25 September 2015 OWASP Board Meeting]&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
&lt;br /&gt;
Oct 14 OWASP Board meeting, Start-time is 14:00-15:00 PDT&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairman's Report - Tobias Gondrom ===&lt;br /&gt;
* structuring of meetings (assign durations to each point) - 1min&lt;br /&gt;
* remove the section on chairman's and role reports and move to a topic based agenda (3min)&lt;br /&gt;
* Start of Budgeting for 2016 discussion &amp;amp; timeline (2min)&lt;br /&gt;
* start of review of Strategic Goals for 2015 and Discussion on Strategic Goals for 2016 - timeline (2min)&lt;br /&gt;
* evotes procedure: how many days should we wait between second of motion to give all board members time to raise discussion?&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Josh Sokol ===&lt;br /&gt;
* Working on new policies to encourage spending down of chapter and project funds.  Proposal under new business.&lt;br /&gt;
* Working on a Bylaw change to address Board member attendance policy.  Proposal under new business. &lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Fabio Cerullo ===&lt;br /&gt;
*  Topic 1&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report - Matt Konda  ===&lt;br /&gt;
* Participated in Project Summit&lt;br /&gt;
* Working on DevOps oriented projects including: &lt;br /&gt;
** Tool&lt;br /&gt;
** Documentation&lt;br /&gt;
* Working on developer documentation.&lt;br /&gt;
* OWASP asked back to Chicago Coder Conference&lt;br /&gt;
* Presented at QA Testing conference and submitted for QUEST a national conference.&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Michael Coates, Andrew van der Stock &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
* Update on bylaws - Andrew van der Stock&lt;br /&gt;
* Update on Education strategic goal - Andrew van der Stock&lt;br /&gt;
* Update on scope of wiki update project and problem - Jim Manico&lt;br /&gt;
* Update on project summit participation and value - Jim Manico&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/a/owasp.org/document/d/1QXar2090ZexvXtvkP8iwL_JVNy66ijp4rfZiTWW9mcY/edit?usp=sharing October Report P.Ritchie]&lt;br /&gt;
** [https://www.dropbox.com/s/yfpk4bs3mq1xhmr/OWASP%20September%202015%20Finance%20report.pptx?dl=0 Summary ppt of Sept &amp;amp; YTD P&amp;amp;L &amp;amp; Balance sheet]&lt;br /&gt;
** [https://www.dropbox.com/s/viirt8h53t60aqh/Sept%202015%20Financial%20Pkg%20preliminary.xlsx?dl=0Financial Detail Excel format Sept &amp;amp; YTD 2015 P&amp;amp;L, Balance Sheet, US/EU]&lt;br /&gt;
** [https://docs.google.com/a/owasp.org/spreadsheets/d/1PwgdwPRpC2T4UVcGxIIgIiIShh-pUlMS_YcsKPdn9xs/edit?usp=sharing 2015 Q4 Goals &amp;amp; Deliverables for Ops Staff in Table format]&lt;br /&gt;
&lt;br /&gt;
Items below are from Sept. BoD meeting, To be updated.&lt;br /&gt;
&lt;br /&gt;
** Community Manager Update - Noreen Whysel [https://docs.google.com/a/owasp.org/presentation/d/1t48k4vX8qy6BCvfUkfmjXDoaB4uBXF8lwWCLzucy_dA/edit?usp=sharing Strategic Goals &amp;amp; Metrics for Chapters / Volunteer Program &amp;amp; More]&lt;br /&gt;
** Director Update - Kate Hartmann - [https://docs.google.com/document/d/1zw0G37qWpnsgujaC1ZkM-zCn08_UifmFrBfvhM0W3Yw/edit?usp=sharing Kate Hartmann Update]&lt;br /&gt;
** Project Coordinator -Claudia Aviles Casanovas Update - [https://docs.google.com/a/owasp.org/presentation/d/1nmBJTQfFuVUoam1awAK6GkCgePbNlW-qCe1xLsLQW4E/edit?usp=sharing October Status Report]&lt;br /&gt;
** Membership Update - [https://www.owasp.org/index.php/September_2015_Membership_Report Membership Report]&lt;br /&gt;
** IT Update:   [https://docs.google.com/a/owasp.org/document/d/19yTS4fVNllsrXrT8fc3XafuEJF0DPbhe02ZZ1XOupfs/edit?usp=sharing OWASP IT Infrastructure Fall 2015 - Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* [Josh Sokol] - [https://www.owasp.org/index.php/Proposal_for_2015-09-25_OWASP_Board_Meeting Policy to Encourage Spending of Chapter Funds]&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* [Jim Manico] - Benchmark Project Controversy &lt;br /&gt;
** Concerns about the OWASP Benchmark Project brand usage from certain vendors&lt;br /&gt;
** Concerns about the OWASP project approval process&lt;br /&gt;
** Input from Simon B: http://lists.owasp.org/pipermail/owasp-board/2015-October/016254.html&lt;br /&gt;
** Questions on Conflict of Interest to Benchmark project [http://lists.owasp.org/pipermail/owasp-benchmark-project/2015-October/000029.html Questions from Michael Coates] [http://lists.owasp.org/pipermail/owasp-benchmark-project/2015-October/000031.html Responses from Project Leader Dave Wichers]&lt;br /&gt;
* [Tobias Gondrom] - New Proposal: Building on Michael's and your comment about rewarding active projects. I very much like that idea! And I would have a friendly additional proposal.&lt;br /&gt;
** Proposal 11: Any project newly reaching lab status receives a one-time extra USD500 into their project account. Any project newly reaching flagship status receives a one-time extra USD1000 into their project account.&lt;br /&gt;
* [Josh Sokol] - Proposal to Eliminate &amp;quot;At Large&amp;quot; Board Positions&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Main_Page&amp;diff=201369</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Main_Page&amp;diff=201369"/>
				<updated>2015-09-30T21:47:06Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:7pt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Header --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%;background-color:#C4D7ED;border:1px solid #183152&amp;quot;&lt;br /&gt;
|style=&amp;quot;width:56%;color:#000&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:280px;border:solid 0px;background:none&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;width:280px;text-align:center;color:#000&amp;quot; |&lt;br /&gt;
&amp;lt;IfLanguage Is=&amp;quot;en&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:162%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;'''Welcome to [[About The Open Web Application Security Project|OWASP]]'''&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;quot;top:+0.2em;font-size: 95%&amp;quot;&amp;gt;the free and open software security community&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/IfLanguage&amp;gt;&lt;br /&gt;
&amp;lt;IfLanguage Is=&amp;quot;es&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:162%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;'''Bienvenido a [[About The Open Web Application Security Project/es|OWASP]]'''&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;quot;top:+0.2em;font-size: 95%&amp;quot;&amp;gt;la comunidad libre y abierta sobre seguridad en aplicaciones&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/IfLanguage&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Special Links --&amp;gt;&lt;br /&gt;
|style=&amp;quot;width:110px;font-size:95%;color:#000&amp;quot;|&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_Dependency_Check Dependency Check]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project ZAP Proxy]&lt;br /&gt;
*[https://www.owasp.org/index.php/Cheat_Sheets Cheat Sheets]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Top Ten Project|Top 10]]&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_OWTF OWTF]&lt;br /&gt;
*[[:Category:OWASP_Application_Security_Verification_Standard_Project |ASVS]]&lt;br /&gt;
*[[:Category:Software_Assurance_Maturity_Model|SAMM]]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Guide Project|Development Guide]]&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_AppSensor_Project AppSensor]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Testing Project|Testing Guide]]&lt;br /&gt;
*[https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project ModSecurity Ruleset]&lt;br /&gt;
|style=&amp;quot;width:110px;font-size:95%&amp;quot;|&lt;br /&gt;
*'''[[:Category:OWASP_Project|More...]]'''&lt;br /&gt;
&lt;br /&gt;
|} &amp;lt;!-- End Banner --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
{|style=&amp;quot;width:100%;background:none;&amp;quot;&lt;br /&gt;
|style=&amp;quot;font-size:95%;text-align:left;color:#000&amp;quot;|[[About The Open Web Application Security Project|About]] '''·'''  [[Searching|Searching]] '''·''' [[Tutorial|Editing]] '''·''' [[How to add a new article|New Article]]  '''·'''  [[OWASP Categories]]&lt;br /&gt;
|style=&amp;quot;font-size:95%;padding:10px 0;margin:0px;text-align:right;color:#000&amp;quot;|  [[Special:Statistics|Statistics]]  '''·'''  [https://www.owasp.org/index.php?title=Special:Recentchanges&amp;amp;limit=100&amp;amp;hidebots=0 Recent Changes]&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Main Content --&amp;gt;&lt;br /&gt;
{|style=&amp;quot;width:100%;border-spacing:8px;margin:0px -8px&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Start of left-column --&amp;gt;&lt;br /&gt;
|class=&amp;quot;MainPageBG&amp;quot; style=&amp;quot;width:50%;border:1px solid #cedff2;background-color:#f5faff;vertical-align:top&amp;quot;|{{Main Left Panel}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Start of right-column --&amp;gt;&lt;br /&gt;
|class=&amp;quot;MainPageBG&amp;quot; style=&amp;quot;width:50%;border:1px solid #cedff2;background-color:#f5faff;vertical-align:top&amp;quot;|{{Main Right Panel}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- End of Main Content --&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ __NOEDITSECTION__&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=200589</id>
		<title>File:AppSecUSA-1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=200589"/>
				<updated>2015-09-15T05:23:48Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: MichaelCoates uploaded a new version of &amp;amp;quot;File:AppSecUSA-1.png&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=200498</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=200498"/>
				<updated>2015-09-14T01:21:34Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Chapter Meetings =&lt;br /&gt;
&lt;br /&gt;
Bay Area OWASP Chapter meetings and posted on MEETUP! Please visit [http://www.meetup.com/Bay-Area-OWASP/ http://www.meetup.com/Bay-Area-OWASP/] for more information.&lt;br /&gt;
&lt;br /&gt;
[[File:2015AppSecUSA-SF.png|400px|thumb|alt=Register Now!|link=https://2015.appsecusa.org]]&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
RSS of all public bay area events (it only contains the next event so don't worry if it's empty when you subscribe)&lt;br /&gt;
&lt;br /&gt;
http://www.eventbrite.com/rss/user_list_events/22961305858&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
==== 2015 Past Events ====&lt;br /&gt;
Can be found on the [http://www.meetup.com/Bay-Area-OWASP/ meetup page]&lt;br /&gt;
&lt;br /&gt;
==== December 2014 - San Francisco @ Mozilla ====&lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
* Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
&lt;br /&gt;
====  August 2014 - San Francisco @ Lookout ==== &lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
* Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
&lt;br /&gt;
====  May 2014 - Redwood City @ Evernote ==== &lt;br /&gt;
OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Arshad Noor - CTO, StrongAuth&lt;br /&gt;
* Rich Tener - Director of Security, Evernote&lt;br /&gt;
&lt;br /&gt;
==== March 2014 - San Francisco @ Stripe ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - San Jose @ Jillians ====&lt;br /&gt;
OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - Special Free Training Event ====&lt;br /&gt;
OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
&lt;br /&gt;
Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
&lt;br /&gt;
==== Jan 2014 - San Jose @ F5====&lt;br /&gt;
OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
&lt;br /&gt;
==== Dec 2013 - San Francisco @ Twilio ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
&lt;br /&gt;
==== Nov 2013 - San Francisco @ LendingClub ====&lt;br /&gt;
OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
&lt;br /&gt;
==== Sept 2013 - Mt View @ Shape Security====&lt;br /&gt;
OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
&lt;br /&gt;
==== July 2013 - Berkeley @ University of Berkely====&lt;br /&gt;
OWASP Presentation Meeting&lt;br /&gt;
&lt;br /&gt;
* An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
* &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
* Ben Hagen&lt;br /&gt;
* Neal Mueller&lt;br /&gt;
*[mailto:teresa.ann.stevens2009@gmail.com Teresa Stevens] &lt;br /&gt;
&lt;br /&gt;
= Mentorship Program =&lt;br /&gt;
OWASP Bay Area is launching a mentorship program to match university students and those new to the application security field with established AppSec professionals. &lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1AYOgpqJ6hRYL_kURX5x5DrG6kdDweiQupJvOQZHV2gs/edit Submit your information] if you're interested in participating.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=198527</id>
		<title>File:AppSecUSA-1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=198527"/>
				<updated>2015-08-07T01:34:05Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: MichaelCoates uploaded a new version of &amp;amp;quot;File:AppSecUSA-1.png&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=August_12,_2015&amp;diff=198374</id>
		<title>August 12, 2015</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=August_12,_2015&amp;diff=198374"/>
				<updated>2015-08-04T17:24:08Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[link:addme Meeting Recording]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
16:00pm - 17:00pm Pacific Time Zone&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[link:addme Meeting Minutes]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Tobias Gondrom ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Fabio Cerullo ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report - Matt Konda  ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Michael Coates, Andrew van der Stock &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [link:addme Rollup Report P.Ritchie]&lt;br /&gt;
** Financial Update - [link:addme Monthly &amp;amp; YTD Financials]&lt;br /&gt;
** Ops Director Update - Kate Hartmann - [link:addme Kate Hartmann Update]&lt;br /&gt;
** Community Manager Update - [link:addme  Manager Report]&lt;br /&gt;
** Project Coordinator Upate - [link:addme  Project  Report]&lt;br /&gt;
** Membership Update - [link:addme Membership Report]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* add items&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* [name of person adding topic] - topic&lt;br /&gt;
** [vote needed | discussion topic]&lt;br /&gt;
* [Michael] - Hourly contractor for wiki housekeeping&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Main_Page&amp;diff=198118</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Main_Page&amp;diff=198118"/>
				<updated>2015-07-30T01:29:14Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:7pt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
[[File:AppSecUSA-1.png |link=https://2015.appsecusa.org/ ]]&lt;br /&gt;
&amp;lt;!-- Header --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%;background-color:#C4D7ED;border:1px solid #183152&amp;quot;&lt;br /&gt;
|style=&amp;quot;width:56%;color:#000&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:280px;border:solid 0px;background:none&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;width:280px;text-align:center;color:#000&amp;quot; |&lt;br /&gt;
&amp;lt;IfLanguage Is=&amp;quot;en&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:162%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;'''Welcome to [[About The Open Web Application Security Project|OWASP]]'''&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;quot;top:+0.2em;font-size: 95%&amp;quot;&amp;gt;the free and open software security community&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/IfLanguage&amp;gt;&lt;br /&gt;
&amp;lt;IfLanguage Is=&amp;quot;es&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:162%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;'''Bienvenido a [[About The Open Web Application Security Project/es|OWASP]]'''&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;quot;top:+0.2em;font-size: 95%&amp;quot;&amp;gt;la comunidad libre y abierta sobre seguridad en aplicaciones&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/IfLanguage&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Special Links --&amp;gt;&lt;br /&gt;
|style=&amp;quot;width:110px;font-size:95%;color:#000&amp;quot;|&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_Dependency_Check Dependency Check]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project ZAP Proxy]&lt;br /&gt;
*[https://www.owasp.org/index.php/Cheat_Sheets Cheat Sheets]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Top Ten Project|Top 10]]&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_OWTF OWTF]&lt;br /&gt;
*[[:Category:OWASP_Application_Security_Verification_Standard_Project |ASVS]]&lt;br /&gt;
*[[:Category:Software_Assurance_Maturity_Model|SAMM]]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Guide Project|Development Guide]]&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_AppSensor_Project AppSensor]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Testing Project|Testing Guide]]&lt;br /&gt;
*[https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project ModSecurity Ruleset]&lt;br /&gt;
|style=&amp;quot;width:110px;font-size:95%&amp;quot;|&lt;br /&gt;
*'''[[:Category:OWASP_Project|More...]]'''&lt;br /&gt;
&lt;br /&gt;
|} &amp;lt;!-- End Banner --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
{|style=&amp;quot;width:100%;background:none;&amp;quot;&lt;br /&gt;
|style=&amp;quot;font-size:95%;text-align:left;color:#000&amp;quot;|[[About The Open Web Application Security Project|About]] '''·'''  [[Searching|Searching]] '''·''' [[Tutorial|Editing]] '''·''' [[How to add a new article|New Article]]  '''·'''  [[OWASP Categories]]&lt;br /&gt;
|style=&amp;quot;font-size:95%;padding:10px 0;margin:0px;text-align:right;color:#000&amp;quot;|  [[Special:Statistics|Statistics]]  '''·'''  [https://www.owasp.org/index.php?title=Special:Recentchanges&amp;amp;limit=100&amp;amp;hidebots=0 Recent Changes]&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Main Content --&amp;gt;&lt;br /&gt;
{|style=&amp;quot;width:100%;border-spacing:8px;margin:0px -8px&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Start of left-column --&amp;gt;&lt;br /&gt;
|class=&amp;quot;MainPageBG&amp;quot; style=&amp;quot;width:50%;border:1px solid #cedff2;background-color:#f5faff;vertical-align:top&amp;quot;|{{Main Left Panel}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Start of right-column --&amp;gt;&lt;br /&gt;
|class=&amp;quot;MainPageBG&amp;quot; style=&amp;quot;width:50%;border:1px solid #cedff2;background-color:#f5faff;vertical-align:top&amp;quot;|{{Main Right Panel}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- End of Main Content --&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ __NOEDITSECTION__&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=198117</id>
		<title>File:AppSecUSA-1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=198117"/>
				<updated>2015-07-30T01:04:41Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: MichaelCoates uploaded a new version of &amp;amp;quot;File:AppSecUSA-1.png&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=198035</id>
		<title>File:AppSecUSA-1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=198035"/>
				<updated>2015-07-28T17:19:53Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: MichaelCoates uploaded a new version of &amp;amp;quot;File:AppSecUSA-1.png&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=197907</id>
		<title>File:AppSecUSA-1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=197907"/>
				<updated>2015-07-24T23:42:11Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: MichaelCoates uploaded a new version of &amp;amp;quot;File:AppSecUSA-1.png&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=197906</id>
		<title>File:AppSecUSA-1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=197906"/>
				<updated>2015-07-24T23:40:51Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: MichaelCoates uploaded a new version of &amp;amp;quot;File:AppSecUSA-1.png&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Main_Page&amp;diff=197904</id>
		<title>Main Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Main_Page&amp;diff=197904"/>
				<updated>2015-07-24T21:55:28Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: Adding AppSecUSA Banner as previously discussed w/planners &amp;amp; board&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:7pt;&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div align=&amp;quot;center&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;/div&amp;gt;&amp;lt;/div&amp;gt;&lt;br /&gt;
[[File:AppSecUSA-1.png |link=https://2015.appsecusa.org/buy/ ]]&lt;br /&gt;
&amp;lt;!-- Header --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%;background-color:#C4D7ED;border:1px solid #183152&amp;quot;&lt;br /&gt;
|style=&amp;quot;width:56%;color:#000&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:280px;border:solid 0px;background:none&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|style=&amp;quot;width:280px;text-align:center;color:#000&amp;quot; |&lt;br /&gt;
&amp;lt;IfLanguage Is=&amp;quot;en&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:162%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;'''Welcome to [[About The Open Web Application Security Project|OWASP]]'''&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;quot;top:+0.2em;font-size: 95%&amp;quot;&amp;gt;the free and open software security community&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/IfLanguage&amp;gt;&lt;br /&gt;
&amp;lt;IfLanguage Is=&amp;quot;es&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:162%;border:none;margin: 0;color:#000&amp;quot;&amp;gt;'''Bienvenido a [[About The Open Web Application Security Project/es|OWASP]]'''&amp;lt;/div&amp;gt;&amp;lt;div style=&amp;quot;top:+0.2em;font-size: 95%&amp;quot;&amp;gt;la comunidad libre y abierta sobre seguridad en aplicaciones&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;/IfLanguage&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Special Links --&amp;gt;&lt;br /&gt;
|style=&amp;quot;width:110px;font-size:95%;color:#000&amp;quot;|&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_Dependency_Check Dependency Check]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project ZAP Proxy]&lt;br /&gt;
*[https://www.owasp.org/index.php/Cheat_Sheets Cheat Sheets]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Top Ten Project|Top 10]]&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_OWTF OWTF]&lt;br /&gt;
*[[:Category:OWASP_Application_Security_Verification_Standard_Project |ASVS]]&lt;br /&gt;
*[[:Category:Software_Assurance_Maturity_Model|SAMM]]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Guide Project|Development Guide]]&lt;br /&gt;
*[https://www.owasp.org/index.php/OWASP_AppSensor_Project AppSensor]&lt;br /&gt;
|style=&amp;quot;width:180px;font-size:95%&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Testing Project|Testing Guide]]&lt;br /&gt;
*[https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project ModSecurity Ruleset]&lt;br /&gt;
|style=&amp;quot;width:110px;font-size:95%&amp;quot;|&lt;br /&gt;
*'''[[:Category:OWASP_Project|More...]]'''&lt;br /&gt;
&lt;br /&gt;
|} &amp;lt;!-- End Banner --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;&lt;br /&gt;
{|style=&amp;quot;width:100%;background:none;&amp;quot;&lt;br /&gt;
|style=&amp;quot;font-size:95%;text-align:left;color:#000&amp;quot;|[[About The Open Web Application Security Project|About]] '''·'''  [[Searching|Searching]] '''·''' [[Tutorial|Editing]] '''·''' [[How to add a new article|New Article]]  '''·'''  [[OWASP Categories]]&lt;br /&gt;
|style=&amp;quot;font-size:95%;padding:10px 0;margin:0px;text-align:right;color:#000&amp;quot;|  [[Special:Statistics|Statistics]]  '''·'''  [https://www.owasp.org/index.php?title=Special:Recentchanges&amp;amp;limit=100&amp;amp;hidebots=0 Recent Changes]&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Main Content --&amp;gt;&lt;br /&gt;
{|style=&amp;quot;width:100%;border-spacing:8px;margin:0px -8px&amp;quot;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Start of left-column --&amp;gt;&lt;br /&gt;
|class=&amp;quot;MainPageBG&amp;quot; style=&amp;quot;width:50%;border:1px solid #cedff2;background-color:#f5faff;vertical-align:top&amp;quot;|{{Main Left Panel}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Start of right-column --&amp;gt;&lt;br /&gt;
|class=&amp;quot;MainPageBG&amp;quot; style=&amp;quot;width:50%;border:1px solid #cedff2;background-color:#f5faff;vertical-align:top&amp;quot;|{{Main Right Panel}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- End of Main Content --&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ __NOEDITSECTION__&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=197903</id>
		<title>File:AppSecUSA-1.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:AppSecUSA-1.png&amp;diff=197903"/>
				<updated>2015-07-24T21:52:53Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:MichaelCoates&amp;diff=197848</id>
		<title>User:MichaelCoates</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:MichaelCoates&amp;diff=197848"/>
				<updated>2015-07-23T19:32:00Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;List of all edits to the OWASP wiki: [[:Special:Contributions/MichaelCoates|click here]].&lt;br /&gt;
&lt;br /&gt;
'''Michael Coates''' - [https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Global_Board_Members Global Board Member]&lt;br /&gt;
&lt;br /&gt;
[[Image:MichaelCoates-OWASP.jpg|100px]]&lt;br /&gt;
&lt;br /&gt;
Contact at : Michael.Coates [at] owasp.org&lt;br /&gt;
&lt;br /&gt;
Blog: http://michael-coates.blogspot.com&lt;br /&gt;
&lt;br /&gt;
Twitter:[https://twitter.com/_mwc @_mwc]&lt;br /&gt;
&lt;br /&gt;
=About=&lt;br /&gt;
&lt;br /&gt;
==OWASP Involvement==&lt;br /&gt;
[https://www.owasp.org/index.php/About_The_Open_Web_Application_Security_Project#Global_Board_Members OWASP Board] - Elected September, 2011&lt;br /&gt;
&lt;br /&gt;
[[:Category:OWASP_AppSensor_Project|AppSensor]]  - Project Lead, project started Summer of Code 2008&lt;br /&gt;
&lt;br /&gt;
[[Global_Membership_Committee]] - Member since committee inception November, 2008&lt;br /&gt;
&lt;br /&gt;
[[Top_10_2010| OWASP Top 10 2010]] - Recognized Contributor&lt;br /&gt;
&lt;br /&gt;
[[Transport_Layer_Protection_Cheat_Sheet| OWASP Transport Layer Protection Cheat Sheet]] - Author&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/Special:Contributions/MichaelCoates| Wiki Contributions]&lt;br /&gt;
&lt;br /&gt;
Speaker at following OWASP conferences/events:&lt;br /&gt;
&lt;br /&gt;
* OWASP Minneapolis Chapter, 2011&lt;br /&gt;
* OWASP San Antonio Chapter, 2011&lt;br /&gt;
* OWASP World Summit - Portugal, 2011&lt;br /&gt;
* OWASP AppSec USA California, 2010&lt;br /&gt;
* OWASP Northern Virginia Chapter, 2010&lt;br /&gt;
* OWASP Chicago Chapter, 2009&lt;br /&gt;
* OWASP AppSec EU Poland, 2009&lt;br /&gt;
* OWASP World Summit - Portugal, 2008&lt;br /&gt;
&lt;br /&gt;
Full conference speaking history [http://michael-coates.blogspot.com/p/speaking-events.html here]&lt;br /&gt;
&lt;br /&gt;
==Bio==&lt;br /&gt;
&lt;br /&gt;
Michael Coates is the Chairman of the OWASP board. In addition, he is the creator of OWASP AppSensor, a project dedicated to creating attack aware applications that leverage real time detection and response capabilities.&lt;br /&gt;
&lt;br /&gt;
Michael is also the Director of Product Security at Shape Security, a Silicon Valley startup developing an entirely new type of web security product to protect web sites against modern attacks.&lt;br /&gt;
&lt;br /&gt;
Previously, Michael was the Director of Security Assurance at Mozilla where he founded and grew the Security Assurance and Web Security programs to 25 people.&lt;br /&gt;
&lt;br /&gt;
Throughout Michael's career he has advised major corporations and governments on secure architecture and software security. He’s also performed hundreds of technical security assessments for financial, enterprise, and cellular &lt;br /&gt;
customers worldwide. Michael also maintains a security blog at michael-coates.blogspot.com&lt;br /&gt;
&lt;br /&gt;
Michael holds a Master of Science degree in Computer, Information and Network Security from DePaul University and a Bachelor of Science degree in Computer Science from the University of Illinois at Urbana-Champaign.&lt;br /&gt;
&lt;br /&gt;
==History==&lt;br /&gt;
&lt;br /&gt;
A bit more in my own words...&lt;br /&gt;
&lt;br /&gt;
My day job is at Shape Security - an exciting startup in the heart of silicon valley. Here we're evaluating how applications are compromised and building new approaches to fundamentally change the model of defending applications. This is an exciting role where I focus on the secure design of our product and also evaluating the threat space to educate and understand risks facing large applications.&lt;br /&gt;
&lt;br /&gt;
I previously worked at Mozilla, a company of 900+ people with a massive footprint with over 450 million users. Here I was responsible for the Mozilla security program. This included security of Firefox, all web applications, servers and infrastructure. As part of this role we led threat modeling, secure design, training, testing and continual security maintenance.  Security can be tough, and perhaps one of the most interesting challenges is designing security solutions that scale and are usable to such a massive number of people.&lt;br /&gt;
&lt;br /&gt;
Security is what I do. Like many of us in the security industry, this is more than just a means of employment, it's a hobby and a passion.  Throughout my professional career I've had the opportunity to assess and secure a wide variety of systems.  Straight out of college my career started in the risk division of a CPA firm. With a focus on financial institutions, our security team performed traditional no knowledge black box penetration assessments, internal network assessments, and even social engineering.  Some of my best security stories involve the stories and persona I invented in order to talk my way into the bank's vault or server room (all part of the approved engagement of course). &lt;br /&gt;
&lt;br /&gt;
My next opportunity led me  to a major telecommunication and mobile company. I had the opportunity to work in the security operations center for a period of time where I gain an eye opening experience being on the &amp;quot;other side of the fence&amp;quot;. Tasked with defending and investing attacks on a network of 150K seats, there was never a dull moment.  I also had the opportunity to transition into the consulting division where I performed secure architecture design review on mobile and telecommunications networks.  Another great security story involved an assessment where, with just a tethered cell phone and an international data connection, I was able to gain full control of the data service for the targeted mobile provider in Asia.&lt;br /&gt;
&lt;br /&gt;
I was fortunate enough to land a spot in a top-notch application security consulting firm.  With this company I was able to focus every day on threat modeling, code review and web application penetration assessments for the most critical applications in the world. From working on major financial systems to voting devices, I had a chance to really see it all. &lt;br /&gt;
&lt;br /&gt;
Don't get me wrong, the deep dive into the technical items is great. I've done it for years. But the key item has been translating these technical issues into the overall risk to the business and users. Managing risk is the driving factor for everything that we end up doing in security.&lt;br /&gt;
&lt;br /&gt;
=OWASP Board Candidate 2011=&lt;br /&gt;
&lt;br /&gt;
'''My Vision For OWASP'''&lt;br /&gt;
&lt;br /&gt;
Technology is changing at a rapid pace and security plays a vital role in the technology ecosystem.  Security should not be seen as a blockade to innovation; instead, security can be leveraged to allow our technology to do more than we ever realized.  OWASP is well poised to provide the advanced security knowledge, tools and training to empower companies to integrate security as a product differentiator and impetus for technology advancement.&lt;br /&gt;
&lt;br /&gt;
My vision for OWASP includes a board that creates opportunities and acts as a catalyst for OWASP projects and the advancement of the OWASP mission.  OWASP is powerful because of the massive expertise that we contain from all of our contributors around the world.  I believe that the OWASP board should provide the necessary resources, technologies, funding and support for OWASP contributors to be successful in growing security technology, addressing security challenges and sharing these skills with the world.  &lt;br /&gt;
&lt;br /&gt;
In addition, I feel the OWASP board should work to help OWASP identify key challenges that should be focused upon in a planned period of time.  The combination of addressing an identified security challenge and continued support for individual project growth will allow OWASP to both leverages our collective expertise and also support organic individual project growth. I believe this two-pronged approach will allow OWASP to continue to grow and create world-class security resources.&lt;br /&gt;
&lt;br /&gt;
The following areas are key positions that I hold and represent the direction I wish to pursue on the OWASP board:&lt;br /&gt;
&lt;br /&gt;
* '''Breaking out of the Echo Chamber''': OWASP should focus on working with people that have never heard of OWASP before. I plan to build the necessary presentations, tools and funding to get OWASP members at college campuses and developer conferences to teach OWASP materials.&lt;br /&gt;
&lt;br /&gt;
* '''Funding''': OWASP is a non-profit and is powered by our mission and our volunteers. However, we can do more if we have the necessary resources to dream big.  I plan to pursue grants and funding that enable OWASP to do more to spread our knowledge and advance our mission.&lt;br /&gt;
&lt;br /&gt;
* '''Integration with Enterprises''': As a security professional employed at a major technology company I wish to further expand OWASP's involvement with corporate entities to address the core risks and challenges they are facing.  This involves sitting down with these industries through our global committees and identifying their needs and how we can help meet them.&lt;br /&gt;
&lt;br /&gt;
* '''Community and Open''': I strongly believe in the O in OWASP. Like the web, security should be open and available to all. The power of OWASP lies in the individuals that donate their time and skills.  I plan to grow  our community and identify ways we can further strengthen the worldwide community.&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=July_22,_2015&amp;diff=197764</id>
		<title>July 22, 2015</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=July_22,_2015&amp;diff=197764"/>
				<updated>2015-07-22T21:52:38Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[link:addme Meeting Recording]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
14:00 - 15:00pm PDT&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[link:addme Meeting Minutes]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Tobias Gondrom ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Fabio Cerullo ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report - Matt Konda  ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Michael Coates, Andrew van der Stock &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/a/owasp.org/document/d/1zWzeusXisqEXWC_ryld9kcC7mdZFGsuy9H1ohcEGwDE/edit?usp=sharing  Monthly Summary Report from  P.Ritchie]&lt;br /&gt;
** Financial Update - [https://drive.google.com/file/d/0BxjNZI6rYJRKbndBeVgyaDRvdUE/view?usp=sharing June 2015 Monthly &amp;amp; YTD Financials, Balance Sheet US/EU and AR/AP]&lt;br /&gt;
** Director Update - Kate Hartmann - [https://docs.google.com/a/owasp.org/document/d/1okYVt-cdOPAF0ji1gteWWdPG7IyxuTt_tbPKm6tKUtw/edit?usp=sharing Operations Update]&lt;br /&gt;
** Community Manager Update - [https://docs.google.com/a/owasp.org/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit?usp=sharing Community Manager Report]&lt;br /&gt;
** Project Coordinator Update - [https://docs.google.com/a/owasp.org/document/d/1mBlyyCl-h3HGEbmafbz5nV6SLMtRvnY0u8CmvxQcn6E/edit?usp=sharing Project Coordinator Monthly Update]&lt;br /&gt;
** Membership Update - [[June 2015 Membership Report]]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
*  Item 1:  Discuss and confirm Date &amp;amp; Time for September Board meeting during AppSec San Francisco, so meeting room &amp;amp; A/V can be scheduled&lt;br /&gt;
** Recommend Friday evening, Sept.25  18:00 - 20:00 like in Amsterdam.  Wiki currently says Saturday, July 26.&lt;br /&gt;
&lt;br /&gt;
* Item 2:  Review Bylaws Section 3.02 per Fabio email.  Discuss if appropriate to change.  Vote as needed.&lt;br /&gt;
**  Fabio recommendation:   The election terms needs to be reviewed in my opinion.. at present it reads &amp;quot;An individual is limited to 4 consecutive 2 year terms” &amp;gt;&amp;gt; I think we need to change the statement to the following “An individual (member?) is limited to be elected no more than three terms in any 7 years period”. By doing so we reinforce the message that you need to be an OWASP member to run for the Board and also are limiting the scope in amount of years which is quite currently long in my opinion.&lt;br /&gt;
**  (Paul still looking for current editable version of Bylaws in Word or Google Docs.  Checked with Bil, Andrew, Jim.  May need to use current pdf)&lt;br /&gt;
&lt;br /&gt;
* Item 3:  Carry-over from June 24 meeting.&lt;br /&gt;
**  Review of [https://docs.google.com/document/d/1RnVbx6DXX3tGcFWlrSxyn8NDKPQEYbTcACJR0oCuyaI/edit#heading=h.rye1xpr37ksy Bylaws DRAFTv7] as proposed by Andrew.&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* P.Ritchie - Update &amp;amp; Action plan for AppSec-EU Conference 2016.  [https://docs.google.com/a/owasp.org/document/d/1jcHr1vMaFudtiCOue7J-ACxzYiFunLHB03yBWkszCGM/edit?usp=sharing Ops &amp;amp; Planning team recommendation]&lt;br /&gt;
** Vote needed?  Past Year's AppSec Conf. selections did not require Board vote.  This is update based on broader Planning team and greater Staff engagement in decision process, due to no Chapter Volunteers or proposal by mid-year deadline.&lt;br /&gt;
* P.Ritchie - Board Discussion and Action on Dinis Cruz recommendation as follows:  Request for OWASP Board to approve $100K for a Project Summit in 2016, and then ask for a team of OWASP leaders to apply to lead that effort.  Per June 26, 2015 email.  Discussion topic - What actions, if any, to take on this&lt;br /&gt;
*&lt;br /&gt;
*  P.Ritchie - Handling issues of Commercialization creeping into presentations, trainings, chapter meetings, etc.   Paul recommends Staff take this on at the ED &amp;amp; Community Mgr level to do first level communication and reminder of OWASP Policy.  Continued abuse or disagreement would be taken to Compliance officer, but first level communication should be in professional, collaborative manner from Staff.&lt;br /&gt;
&amp;gt;&amp;gt;  Goal is to confirm with Board that this operating guideline is acceptable with the 2-3 cases brought to our attention this month.&lt;br /&gt;
*&lt;br /&gt;
* For Action - [https://docs.google.com/document/d/1flUHQfne84BXixhnEAozXy8OrfX8Fx2Ch73kkLwQGes/edit Approve minutes from June 24 Board meeting]&lt;br /&gt;
* [Michael]&lt;br /&gt;
** Proposal - Motion to move primary responsibility of planning and execution of the AppSecUSA 2016 conference to the OWASP Foundation. Selection of core conference themes and speaker/proposal would be driven by the owasp community.&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=June_24,_2015&amp;diff=197763</id>
		<title>June 24, 2015</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=June_24,_2015&amp;diff=197763"/>
				<updated>2015-07-22T21:52:30Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */ added to wrong month&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[https://www.dropbox.com/s/s70mzmo1j3hvw96/2015-06-24%2014.05%20OWASP%20Board%20Meeting.wmv?dl=0  Recording of June 24, 2015 OWASP Board Meeting]&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
14:00-15:00 PDT&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[https://docs.google.com/a/owasp.org/document/d/1flUHQfne84BXixhnEAozXy8OrfX8Fx2Ch73kkLwQGes/edit?usp=sharing Minutes of June 24, 2015 OWASP Board Meeting]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
* [https://docs.google.com/document/d/1RnVbx6DXX3tGcFWlrSxyn8NDKPQEYbTcACJR0oCuyaI/edit#heading=h.rye1xpr37ksy|OWASP By Laws v7]&lt;br /&gt;
&lt;br /&gt;
* [https://docs.google.com/a/owasp.org/document/d/1d6c5LqjN-qSQjWfMQdqaYaQz2dBVTNssBSLCSKAgusY/edit?usp=sharing On-Demand Training Proposal]&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Tobias Gondrom ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Fabio Cerullo ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report - Matt Konda  ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updates from Members at Large - Michael Coates, Andrew van der Stock &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
* Andrew van der Stock - Education strategic goal update.&lt;br /&gt;
* Michael - Motion to move primary responsibility of planning and execution of the AppSecUSA 2016 conference to the OWASP Foundation. Selection of core conference themes and speaker/proposal would be driven by the OWASP community.&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/document/d/1q2vHPudcavDMnZmViKDhRz-TMUsT1Zpvsuwh0kX9aJM/edit?usp=sharing  Summary Report P.Ritchie]&lt;br /&gt;
** Financial Update - [https://docs.google.com/spreadsheets/d/1ugKTW94CQJ3HImlJ6q8Fkbs2c7gj1ytSYRbNaYgjjZE/edit?usp=sharing  YTD P&amp;amp;L to Budget, Jan-May 2015 with Balance sheet]&lt;br /&gt;
** Director Update - Kate Hartmann - [link:addme Kate Hartmann Update]&lt;br /&gt;
** Community Manager Update - [https://docs.google.com/a/owasp.org/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit?usp=sharing Noreen Community Manager Report]&lt;br /&gt;
** Project Manager Update - [link:addme  Project Manager Report]&lt;br /&gt;
** Membership Update - [https://www.owasp.org/index.php/May_2015_Membership_Report Membership Report]&lt;br /&gt;
** Events Manager Update - [https://docs.google.com/a/owasp.org/document/d/1j9YQ5IZ2qGtkLcTPh2boKH4JJQPFJtWtmPrxHj0CTAc/edit?usp=sharing June 2015 Conference Manager Report]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* Bylaws (pre-reading material: [https://docs.google.com/document/d/1RnVbx6DXX3tGcFWlrSxyn8NDKPQEYbTcACJR0oCuyaI/edit#heading=h.rye1xpr37ksy|OWASP By Laws v7])&lt;br /&gt;
&lt;br /&gt;
Discuss revised by laws, approve, reword or reject changes to bring our by laws into good standing before the election. &lt;br /&gt;
&lt;br /&gt;
* Fund ring fencing &lt;br /&gt;
&lt;br /&gt;
Discuss how we ensure that all of our strategic goals are properly funded, and ensure that the Foundation doesn't need to borrow when we have funds on hand. Chapters have 71% of OWASP's funds ring fenced. Let's discuss how we deliver all of OWASP's strategic goals, and improve our admin cost overhead ratio.&lt;br /&gt;
&lt;br /&gt;
* On Demand Training (pre-reading material link above)&lt;br /&gt;
&lt;br /&gt;
At OWASP we are frequently receiving requests from companies looking for training related to application security. This is an area of expertise that plenty of individuals in our Community could fulfil. This growing demand for training is aligned with OWASP Strategic Goals and will become a much needed revenue stream for the Foundation that is not conference driven. Discuss revised proposal for OWASP to deliver/organise trainings.&lt;br /&gt;
&lt;br /&gt;
* Review &amp;amp; Approve Minutes from May 22 Board meeting.&lt;br /&gt;
&lt;br /&gt;
* Note in Meeting Minutes that Proposed OWASP.org email policy and terms of usage was approved via email vote as of June 23.&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* [Tobias] - reopen communication with RSA to explore potential opportunities for OWASP outreach. &lt;br /&gt;
** [discussion topic]&lt;br /&gt;
* [Matt] - hire a technical editor for a few months. &lt;br /&gt;
** [discussion topic]&lt;br /&gt;
* [Jim] - Making public statements on crypto&lt;br /&gt;
** &amp;quot;Even though 501c3 organizations *can* do some lobbying (as long as expenditures are not substantial), the IAB is careful not to talk about legislation or urge anyone to contact representatives about legislation.&amp;quot; - Jeff Willams&lt;br /&gt;
* [Josh] - Funding request for Project Summit at AppSecUSA 2015&lt;br /&gt;
** http://lists.owasp.org/pipermail/owasp-leaders/2015-June/014359.html&lt;br /&gt;
** $10,000 requested&lt;br /&gt;
* [Jim] - Different Board voting models &lt;br /&gt;
** We have both email and in-person voting models which are very different. For email, all members can vote. For in person, only present members may vote. Should me merge this into one model only?&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=June_24,_2015&amp;diff=197755</id>
		<title>June 24, 2015</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=June_24,_2015&amp;diff=197755"/>
				<updated>2015-07-22T21:10:28Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[https://www.dropbox.com/s/s70mzmo1j3hvw96/2015-06-24%2014.05%20OWASP%20Board%20Meeting.wmv?dl=0  Recording of June 24, 2015 OWASP Board Meeting]&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
14:00-15:00 PDT&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[https://docs.google.com/a/owasp.org/document/d/1flUHQfne84BXixhnEAozXy8OrfX8Fx2Ch73kkLwQGes/edit?usp=sharing Minutes of June 24, 2015 OWASP Board Meeting]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
* [https://docs.google.com/document/d/1RnVbx6DXX3tGcFWlrSxyn8NDKPQEYbTcACJR0oCuyaI/edit#heading=h.rye1xpr37ksy|OWASP By Laws v7]&lt;br /&gt;
&lt;br /&gt;
* [https://docs.google.com/a/owasp.org/document/d/1d6c5LqjN-qSQjWfMQdqaYaQz2dBVTNssBSLCSKAgusY/edit?usp=sharing On-Demand Training Proposal]&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Tobias Gondrom ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Fabio Cerullo ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report - Matt Konda  ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updates from Members at Large - Michael Coates, Andrew van der Stock &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
* Andrew van der Stock - Education strategic goal update.&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/document/d/1q2vHPudcavDMnZmViKDhRz-TMUsT1Zpvsuwh0kX9aJM/edit?usp=sharing  Summary Report P.Ritchie]&lt;br /&gt;
** Financial Update - [https://docs.google.com/spreadsheets/d/1ugKTW94CQJ3HImlJ6q8Fkbs2c7gj1ytSYRbNaYgjjZE/edit?usp=sharing  YTD P&amp;amp;L to Budget, Jan-May 2015 with Balance sheet]&lt;br /&gt;
** Director Update - Kate Hartmann - [link:addme Kate Hartmann Update]&lt;br /&gt;
** Community Manager Update - [https://docs.google.com/a/owasp.org/document/d/1-4fIJfiLa8l02Hf1XBMqRYEiY2z6g4qwln-_ZLQ6GIs/edit?usp=sharing Noreen Community Manager Report]&lt;br /&gt;
** Project Manager Update - [link:addme  Project Manager Report]&lt;br /&gt;
** Membership Update - [https://www.owasp.org/index.php/May_2015_Membership_Report Membership Report]&lt;br /&gt;
** Events Manager Update - [https://docs.google.com/a/owasp.org/document/d/1j9YQ5IZ2qGtkLcTPh2boKH4JJQPFJtWtmPrxHj0CTAc/edit?usp=sharing June 2015 Conference Manager Report]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* Bylaws (pre-reading material: [https://docs.google.com/document/d/1RnVbx6DXX3tGcFWlrSxyn8NDKPQEYbTcACJR0oCuyaI/edit#heading=h.rye1xpr37ksy|OWASP By Laws v7])&lt;br /&gt;
&lt;br /&gt;
Discuss revised by laws, approve, reword or reject changes to bring our by laws into good standing before the election. &lt;br /&gt;
&lt;br /&gt;
* Fund ring fencing &lt;br /&gt;
&lt;br /&gt;
Discuss how we ensure that all of our strategic goals are properly funded, and ensure that the Foundation doesn't need to borrow when we have funds on hand. Chapters have 71% of OWASP's funds ring fenced. Let's discuss how we deliver all of OWASP's strategic goals, and improve our admin cost overhead ratio.&lt;br /&gt;
&lt;br /&gt;
* On Demand Training (pre-reading material link above)&lt;br /&gt;
&lt;br /&gt;
At OWASP we are frequently receiving requests from companies looking for training related to application security. This is an area of expertise that plenty of individuals in our Community could fulfil. This growing demand for training is aligned with OWASP Strategic Goals and will become a much needed revenue stream for the Foundation that is not conference driven. Discuss revised proposal for OWASP to deliver/organise trainings.&lt;br /&gt;
&lt;br /&gt;
* Review &amp;amp; Approve Minutes from May 22 Board meeting.&lt;br /&gt;
&lt;br /&gt;
* Note in Meeting Minutes that Proposed OWASP.org email policy and terms of usage was approved via email vote as of June 23.&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* [Tobias] - reopen communication with RSA to explore potential opportunities for OWASP outreach. &lt;br /&gt;
** [discussion topic]&lt;br /&gt;
* [Matt] - hire a technical editor for a few months. &lt;br /&gt;
** [discussion topic]&lt;br /&gt;
* [Jim] - Making public statements on crypto&lt;br /&gt;
** &amp;quot;Even though 501c3 organizations *can* do some lobbying (as long as expenditures are not substantial), the IAB is careful not to talk about legislation or urge anyone to contact representatives about legislation.&amp;quot; - Jeff Willams&lt;br /&gt;
* [Josh] - Funding request for Project Summit at AppSecUSA 2015&lt;br /&gt;
** http://lists.owasp.org/pipermail/owasp-leaders/2015-June/014359.html&lt;br /&gt;
** $10,000 requested&lt;br /&gt;
* [Jim] - Different Board voting models &lt;br /&gt;
** We have both email and in-person voting models which are very different. For email, all members can vote. For in person, only present members may vote. Should me merge this into one model only?&lt;br /&gt;
* [Michael]&lt;br /&gt;
** Proposal - Motion to move primary responsibility of planning and execution of the AppSecUSA 2016 conference to the OWASP Foundation. Selection of core conference themes and speaker/proposal would be driven by the owasp community.&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=March_25,_2015&amp;diff=192128</id>
		<title>March 25, 2015</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=March_25,_2015&amp;diff=192128"/>
				<updated>2015-03-25T00:36:51Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[link:addme Meeting Recording]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
12:00pm - 1:00pm PACIFIC&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[link:addme Meeting Minutes]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
&lt;br /&gt;
For Review &amp;amp; Approval [https://docs.google.com/document/d/13TnxGl4N1fM0IcVi104d-2CqKfBrDJVeCV2HdxFgtsI/edit?usp=sharing Minutes of Feb. 11, 2015 OWASP Board meeting]&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/document/d/1PcUNDdL6K6EySI_Otrc0_bVWPIXFU94m3sdQvuO-4_g/edit?usp=sharing Proposal for Insperity Payroll &amp;amp; HR Services]&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/document/d/1R9VQd5t32JjSQbJjU7p4vqFrIEV73SFsEpRffZxOLYw/edit?usp=sharing Proposal to adjust policy and allow Corporate Member Allocaton to Chapter or Project on annual basis]&lt;br /&gt;
&lt;br /&gt;
Proposal for Virtual Mgmt Services&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Tobias Gondrom ===&lt;br /&gt;
* Employer status moving from Virtual/Insperity to OWASP/Insperity&lt;br /&gt;
* Contract with Virtual for Finance&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Fabio Cerullo ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report - Matt Konda  ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Michael Coates, Andrew van der Stock &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director Report - [https://drive.google.com/a/owasp.org/file/d/0BxjNZI6rYJRKRk1zWGlURkNLelU/view?usp=sharing Rollup Report P.Ritchie]&lt;br /&gt;
** Financial Update - [link:addme Monthly &amp;amp; YTD Financials]&lt;br /&gt;
** Director Update - Kate Hartmann - [link:addme Kate Hartmann Update]&lt;br /&gt;
** Project Manager Update - [link:addme  Project Manager Report]&lt;br /&gt;
** Membership Update - [https://www.owasp.org/index.php/February_2015_Membership_Report Kelly's Feb. 2015 Membership Report]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* add items&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* Josh Sokol - BlackHat fundraiser (Tuesday, August 4th)&lt;br /&gt;
* Michael Coates - AppSecUSA &amp;amp; AppSecEurope Planning Models - Discussion&lt;br /&gt;
* [name of person adding topic] - topic&lt;br /&gt;
** [vote needed | discussion topic]&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
* Review of China Chapter Practices re: Foundation policy&lt;br /&gt;
** Work in progress.  Kate &amp;amp; Helen G talking on issues and next steps.  Paul to work with Kate &amp;amp; Helen as 'collaborative' process improvement.&lt;br /&gt;
*Open - Paul to ID &amp;amp; schedule Board Training on Anti-harassment&lt;br /&gt;
** In progress.  Insperity has online courses, need to signup at cost range $400-2,000 per volume of courses.  Other vendors available.  Target start early April with Completion by end of May.  [http://www.complianceonline.com/offensive-behavior-and-harassment-that-violates-title-vii-of-the-civil-rights-act-of-1964-webinar-training-703890-prdw?channel=M9_NW_AP13_Kelly_MR24_BR Sample Course from 3rd Party]&lt;br /&gt;
* Open - Updates to Bylaws &amp;amp; Election process.&lt;br /&gt;
** In process.  Andrew working with Kelly &amp;amp; Paul &amp;amp; Community on input and updates&lt;br /&gt;
*Open - Tobias - Update on the numbers for the Asia tour.&lt;br /&gt;
*Open - Josh - Board sponsors for each Strategic goal?  Opportunity for non-board sponsors too?&lt;br /&gt;
* Open - Determine status of &amp;quot;Interim Executive Director&amp;quot;, Update as needed.&lt;br /&gt;
* Open - ID Board candidates for OWASP VZW, Europe legal entity. Review roles &amp;amp; tasks. In Process - Paul &amp;amp; Tobias working this issue&lt;br /&gt;
* Closed - Whistleblower Policy updated and posted to wiki.  Ops Staff informed of updates.&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=187957</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=187957"/>
				<updated>2015-01-13T06:55:44Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Where */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:2015AppSecUSA-SF.png|400px|thumb|alt=Register Now!|link=https://2015.appsecusa.org]]&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Next Event=&lt;br /&gt;
Wednesday, January 21, 2015 - Redwood City @ Synack &lt;br /&gt;
&lt;br /&gt;
OWASP Chapter Meeting in Redwood City hosted by [https://www.synack.com/ Synack]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/219158654/ RSVP on Meetup]&amp;lt;br&amp;gt;&lt;br /&gt;
====When====&lt;br /&gt;
&lt;br /&gt;
* Wednesday, Jan 21&lt;br /&gt;
* 5:45 pm - 8:00 pm&lt;br /&gt;
&lt;br /&gt;
====Where====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Synack&lt;br /&gt;
[https://goo.gl/maps/Dmkzr 1600 Seaport Boulevard, Redwood City, CA] &lt;br /&gt;
Building - #170 North&lt;br /&gt;
&lt;br /&gt;
====Agenda====&lt;br /&gt;
&lt;br /&gt;
5:45-6:30 pm - Networking with Drinks &amp;amp; Food &amp;lt;br&amp;gt;&lt;br /&gt;
6:30-7:10 : Michael Barrett - FIDO Alliance v1.0 UAF &amp;amp; U2F &amp;lt;br&amp;gt;&lt;br /&gt;
7:15-7:55 : Scott Behrens - The Joy Of Intelligent Proactive Security &amp;lt;br&amp;gt;&lt;br /&gt;
8:00-8:20 : More food, drink, and security &amp;quot;hallway con&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Speakers====&lt;br /&gt;
&lt;br /&gt;
* Michael Barrett, Stealth Startup &amp;amp; FIDO Alliance&lt;br /&gt;
* Scott Behrens, Netflix&lt;br /&gt;
&lt;br /&gt;
===== Michael Barrett, Stealth Startup &amp;amp; FIDO Alliance ===== &lt;br /&gt;
'''FIDO Alliance v1.0 UAF &amp;amp; U2F'''&lt;br /&gt;
&lt;br /&gt;
The FIDO (Fast IDentity Online) Alliance is a 501(c)6 non-profit organization nominally formed in July 2012 to address the lack of interoperability among strong authentication devices as well as the problems users face with creating and remembering multiple usernames and passwords.&lt;br /&gt;
&lt;br /&gt;
On December 9, 2014 FIDO published final 1.0 drafts of its two specifications – Universal Authentication Framework (UAF) and Universal 2nd Factor (U2F). &lt;br /&gt;
&lt;br /&gt;
'''Michael Barrett''' is the CEO of an early stage startup in the enterprise security space. (“We’re in stealth mode - if I told you, I’d have to shoot you...”)&lt;br /&gt;
&lt;br /&gt;
Previously, Barrett was President of the FIDO Alliance, an open standards consortium that is  reimagining authentication on mobile devices and the Internet. He serves on the board of directors of StopBadWare, a 501(c)(3) Berkman Center spin out organization dedicated to mitigating the impact of malware on businesses and individuals.&lt;br /&gt;
&lt;br /&gt;
From 2006 to 2013, Barrett was the Chief Information Security Officer for PayPal. In this role, he was responsible for ensuring the security of PayPal’s 130+ million accounts worldwide. He  oversaw the information systems and services that protect the integrity and confidentiality of PayPal customer and employee information, and led a team of roughly 100 people.&lt;br /&gt;
&lt;br /&gt;
=====  Scott Behrens, Netflix===== &lt;br /&gt;
'''The Joy Of Intelligent Proactive Security '''&lt;br /&gt;
&lt;br /&gt;
Netflix is amongst the largest users of the public cloud, consuming roughly 30% of all the US's downstream bandwidth at peak. Multiple concurrent code bases, continuous deployments, regional content, and an ever-changing threat landscape make vulnerability and asset management difficult. In order to battle this dynamic environment, we have taken an approach of automating, simplifying, and collecting actionable data with proactive security.&lt;br /&gt;
&lt;br /&gt;
This presentation will assert that the agility of modern infrastructure requires a different approach to security. We look at common areas of a mature security program: identifying and addressing potential issues, monitoring for attacks and anomalies, understanding your environment, collecting and sharing information, all while constantly reevaluating your approach. We will also walk through a few real world cases where intelligent proactive security has simplified Netflix's response time for identifying, responding to, and remediating security issues.&lt;br /&gt;
&lt;br /&gt;
We will also provide demonstrations of a number of Netflix applications that are currently or soon-to-be open sourced that can help you simplify your security program regardless of whether you operate in the cloud or data center.&lt;br /&gt;
&lt;br /&gt;
Attendees will leave this talk with real world strategies, techniques, and Netflix open source tools they can use in their own organizations.&lt;br /&gt;
&lt;br /&gt;
'''Scott Behrens''' is a security evangelists at Netflix focusing on application security engineering as part of the Product and Application Security team. Scott loves security research and has previously spoken at DEF CON, Derbycon, Shakacon, Chicago B­sides, and a handful of other security conferences. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide.'''''&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
RSS of all public bay area events (it only contains the next event so don't worry if it's empty when you subscribe)&lt;br /&gt;
&lt;br /&gt;
http://www.eventbrite.com/rss/user_list_events/22961305858&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
&lt;br /&gt;
==== December 2014 - San Francisco @ Mozilla ====&lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
* Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
&lt;br /&gt;
====  August 2014 - San Francisco @ Lookout ==== &lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
* Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
&lt;br /&gt;
====  May 2014 - Redwood City @ Evernote ==== &lt;br /&gt;
OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Arshad Noor - CTO, StrongAuth&lt;br /&gt;
* Rich Tener - Director of Security, Evernote&lt;br /&gt;
&lt;br /&gt;
==== March 2014 - San Francisco @ Stripe ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - San Jose @ Jillians ====&lt;br /&gt;
OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - Special Free Training Event ====&lt;br /&gt;
OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
&lt;br /&gt;
Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
&lt;br /&gt;
==== Jan 2014 - San Jose @ F5====&lt;br /&gt;
OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
&lt;br /&gt;
==== Dec 2013 - San Francisco @ Twilio ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
&lt;br /&gt;
==== Nov 2013 - San Francisco @ LendingClub ====&lt;br /&gt;
OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
&lt;br /&gt;
==== Sept 2013 - Mt View @ Shape Security====&lt;br /&gt;
OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
&lt;br /&gt;
==== July 2013 - Berkeley @ University of Berkely====&lt;br /&gt;
OWASP Presentation Meeting&lt;br /&gt;
&lt;br /&gt;
* An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
* &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
*[mailto:teresa.ann.stevens2009@gmail.com Teresa Stevens] &lt;br /&gt;
*[mailto:cory@crazypenguin.com Cory Scott]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=187956</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=187956"/>
				<updated>2015-01-13T06:54:16Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Next Event */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:2015AppSecUSA-SF.png|400px|thumb|alt=Register Now!|link=https://2015.appsecusa.org]]&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Next Event=&lt;br /&gt;
Wednesday, January 21, 2015 - Redwood City @ Synack &lt;br /&gt;
&lt;br /&gt;
OWASP Chapter Meeting in Redwood City hosted by [https://www.synack.com/ Synack]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/219158654/ RSVP on Meetup]&amp;lt;br&amp;gt;&lt;br /&gt;
====When====&lt;br /&gt;
&lt;br /&gt;
* Wednesday, Jan 21&lt;br /&gt;
* 5:45 pm - 8:00 pm&lt;br /&gt;
&lt;br /&gt;
====Where====&lt;br /&gt;
&lt;br /&gt;
[https://goo.gl/maps/iQIKh Mozilla, 2 Harrison St, San Francisco, CA 94105]&lt;br /&gt;
&lt;br /&gt;
====Agenda====&lt;br /&gt;
&lt;br /&gt;
5:45-6:30 pm - Networking with Drinks &amp;amp; Food &amp;lt;br&amp;gt;&lt;br /&gt;
6:30-7:10 : Michael Barrett - FIDO Alliance v1.0 UAF &amp;amp; U2F &amp;lt;br&amp;gt;&lt;br /&gt;
7:15-7:55 : Scott Behrens - The Joy Of Intelligent Proactive Security &amp;lt;br&amp;gt;&lt;br /&gt;
8:00-8:20 : More food, drink, and security &amp;quot;hallway con&amp;quot; &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Speakers====&lt;br /&gt;
&lt;br /&gt;
* Michael Barrett, Stealth Startup &amp;amp; FIDO Alliance&lt;br /&gt;
* Scott Behrens, Netflix&lt;br /&gt;
&lt;br /&gt;
===== Michael Barrett, Stealth Startup &amp;amp; FIDO Alliance ===== &lt;br /&gt;
'''FIDO Alliance v1.0 UAF &amp;amp; U2F'''&lt;br /&gt;
&lt;br /&gt;
The FIDO (Fast IDentity Online) Alliance is a 501(c)6 non-profit organization nominally formed in July 2012 to address the lack of interoperability among strong authentication devices as well as the problems users face with creating and remembering multiple usernames and passwords.&lt;br /&gt;
&lt;br /&gt;
On December 9, 2014 FIDO published final 1.0 drafts of its two specifications – Universal Authentication Framework (UAF) and Universal 2nd Factor (U2F). &lt;br /&gt;
&lt;br /&gt;
'''Michael Barrett''' is the CEO of an early stage startup in the enterprise security space. (“We’re in stealth mode - if I told you, I’d have to shoot you...”)&lt;br /&gt;
&lt;br /&gt;
Previously, Barrett was President of the FIDO Alliance, an open standards consortium that is  reimagining authentication on mobile devices and the Internet. He serves on the board of directors of StopBadWare, a 501(c)(3) Berkman Center spin out organization dedicated to mitigating the impact of malware on businesses and individuals.&lt;br /&gt;
&lt;br /&gt;
From 2006 to 2013, Barrett was the Chief Information Security Officer for PayPal. In this role, he was responsible for ensuring the security of PayPal’s 130+ million accounts worldwide. He  oversaw the information systems and services that protect the integrity and confidentiality of PayPal customer and employee information, and led a team of roughly 100 people.&lt;br /&gt;
&lt;br /&gt;
=====  Scott Behrens, Netflix===== &lt;br /&gt;
'''The Joy Of Intelligent Proactive Security '''&lt;br /&gt;
&lt;br /&gt;
Netflix is amongst the largest users of the public cloud, consuming roughly 30% of all the US's downstream bandwidth at peak. Multiple concurrent code bases, continuous deployments, regional content, and an ever-changing threat landscape make vulnerability and asset management difficult. In order to battle this dynamic environment, we have taken an approach of automating, simplifying, and collecting actionable data with proactive security.&lt;br /&gt;
&lt;br /&gt;
This presentation will assert that the agility of modern infrastructure requires a different approach to security. We look at common areas of a mature security program: identifying and addressing potential issues, monitoring for attacks and anomalies, understanding your environment, collecting and sharing information, all while constantly reevaluating your approach. We will also walk through a few real world cases where intelligent proactive security has simplified Netflix's response time for identifying, responding to, and remediating security issues.&lt;br /&gt;
&lt;br /&gt;
We will also provide demonstrations of a number of Netflix applications that are currently or soon-to-be open sourced that can help you simplify your security program regardless of whether you operate in the cloud or data center.&lt;br /&gt;
&lt;br /&gt;
Attendees will leave this talk with real world strategies, techniques, and Netflix open source tools they can use in their own organizations.&lt;br /&gt;
&lt;br /&gt;
'''Scott Behrens''' is a security evangelists at Netflix focusing on application security engineering as part of the Product and Application Security team. Scott loves security research and has previously spoken at DEF CON, Derbycon, Shakacon, Chicago B­sides, and a handful of other security conferences. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide.'''''&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
RSS of all public bay area events (it only contains the next event so don't worry if it's empty when you subscribe)&lt;br /&gt;
&lt;br /&gt;
http://www.eventbrite.com/rss/user_list_events/22961305858&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
&lt;br /&gt;
==== December 2014 - San Francisco @ Mozilla ====&lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
* Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
&lt;br /&gt;
====  August 2014 - San Francisco @ Lookout ==== &lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
* Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
&lt;br /&gt;
====  May 2014 - Redwood City @ Evernote ==== &lt;br /&gt;
OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Arshad Noor - CTO, StrongAuth&lt;br /&gt;
* Rich Tener - Director of Security, Evernote&lt;br /&gt;
&lt;br /&gt;
==== March 2014 - San Francisco @ Stripe ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - San Jose @ Jillians ====&lt;br /&gt;
OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - Special Free Training Event ====&lt;br /&gt;
OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
&lt;br /&gt;
Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
&lt;br /&gt;
==== Jan 2014 - San Jose @ F5====&lt;br /&gt;
OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
&lt;br /&gt;
==== Dec 2013 - San Francisco @ Twilio ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
&lt;br /&gt;
==== Nov 2013 - San Francisco @ LendingClub ====&lt;br /&gt;
OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
&lt;br /&gt;
==== Sept 2013 - Mt View @ Shape Security====&lt;br /&gt;
OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
&lt;br /&gt;
==== July 2013 - Berkeley @ University of Berkely====&lt;br /&gt;
OWASP Presentation Meeting&lt;br /&gt;
&lt;br /&gt;
* An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
* &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
*[mailto:teresa.ann.stevens2009@gmail.com Teresa Stevens] &lt;br /&gt;
*[mailto:cory@crazypenguin.com Cory Scott]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=187955</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=187955"/>
				<updated>2015-01-13T06:49:35Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Past Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:2015AppSecUSA-SF.png|400px|thumb|alt=Register Now!|link=https://2015.appsecusa.org]]&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Next Event=&lt;br /&gt;
Wednesday, December 10, 2014 - San Francisco @ Mozilla &lt;br /&gt;
&lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://www.mozilla.org/en-US/ Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/218988323/ RSVP on Meetup]&amp;lt;br&amp;gt;&lt;br /&gt;
====When====&lt;br /&gt;
&lt;br /&gt;
* Wednesday, Dec 10&lt;br /&gt;
* 5:30 pm - 8:00 pm&lt;br /&gt;
&lt;br /&gt;
====Where====&lt;br /&gt;
&lt;br /&gt;
[https://goo.gl/maps/iQIKh Mozilla, 2 Harrison St, San Francisco, CA 94105]&lt;br /&gt;
&lt;br /&gt;
====Agenda====&lt;br /&gt;
&lt;br /&gt;
5:30-6:15 pm - Networking with Drinks &amp;amp; Food&amp;lt;br&amp;gt;&lt;br /&gt;
6:15-6:45 : Speaker: Jasvir Nagra, Google &amp;lt;br&amp;gt;&lt;br /&gt;
7:00-7:30 : Speaker: Sergey Shekyan &amp;amp; Bei Zhang, Shape Security &amp;lt;br&amp;gt;&lt;br /&gt;
7:30-8:00 : More food, drink, and security &amp;quot;hallway con&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Speakers====&lt;br /&gt;
&lt;br /&gt;
* Jasvir Nagra, Google&lt;br /&gt;
* Sergey Shekyan &amp;amp; Bei Zhang, Shape Security&lt;br /&gt;
&lt;br /&gt;
===== Jasvir Nagra, Google ===== &lt;br /&gt;
'''Firing Bots at Bugs'''&lt;br /&gt;
&lt;br /&gt;
It remains all too easy to find simple security vulnerabilities in many web applications.  Why is it so hard to automatically find vulnerabilities when finding them manually remains so relatively easy? In this talk, we’ll share some of gotchas that we’ve run into scanning for web security bugs at Google, armed with a 'firing squad' of examples. We'll then walk through some of the solutions we've come up with, and finish up with a few unsolved problems which remain that really make web vulnerability scanning a hard (but fun!) problem to work on.&lt;br /&gt;
&lt;br /&gt;
Jasvir Nagra is a security engineer at Google dedicated to making the web vulnerability-free.  He has led the design and implementation of Caja, a pure JavaScript sandbox. Previously, he co-authored Surreptitious Software, a book on obfuscation, software watermarking and tamper-proofing; and built autonomous soccer-playing robots.  These days he builds web application scanners that work at scale&lt;br /&gt;
&lt;br /&gt;
=====  Sergey Shekyan &amp;amp; Bei Zhang, Shape Security===== &lt;br /&gt;
'''Headless Browsers Hide and Seek'''&lt;br /&gt;
&lt;br /&gt;
Headless browsers have become indispensable tools for security teams, researchers, and attackers focusing on web applications. Tools like PhantomJS enable anyone to automatically interact with highly dynamic websites and to perform many types of automated attacks. This presentation will dive into headless browser detection and spoofing techniques.&lt;br /&gt;
&lt;br /&gt;
Sergey Shekyan is a Principal Engineer at Shape Security, where he is focused on the development of the new generation web security product. Prior to Shape Security, he spent 4 years at Qualys developing their on demand web application vulnerability scanning service. &lt;br /&gt;
&lt;br /&gt;
Bei Zhang is a Senior Software Engineer at Shape Security, focused on analysis and countermeasures of automatic web attacks. Previously, he worked at the Chrome team at Google with a focus on the Chrome Apps API. His interests include web security, source code analysis, and algorithms.&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide.'''''&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
RSS of all public bay area events (it only contains the next event so don't worry if it's empty when you subscribe)&lt;br /&gt;
&lt;br /&gt;
http://www.eventbrite.com/rss/user_list_events/22961305858&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
&lt;br /&gt;
==== December 2014 - San Francisco @ Mozilla ====&lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://mozilla.org Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Jasvir Nagra, Google - Firing Bots at Bugs&lt;br /&gt;
* Sergey Shekyan &amp;amp; Bei Zhang, Shape Security - Headless Browsers Hide and Seek&lt;br /&gt;
&lt;br /&gt;
====  August 2014 - San Francisco @ Lookout ==== &lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
* Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
&lt;br /&gt;
====  May 2014 - Redwood City @ Evernote ==== &lt;br /&gt;
OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Arshad Noor - CTO, StrongAuth&lt;br /&gt;
* Rich Tener - Director of Security, Evernote&lt;br /&gt;
&lt;br /&gt;
==== March 2014 - San Francisco @ Stripe ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - San Jose @ Jillians ====&lt;br /&gt;
OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - Special Free Training Event ====&lt;br /&gt;
OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
&lt;br /&gt;
Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
&lt;br /&gt;
==== Jan 2014 - San Jose @ F5====&lt;br /&gt;
OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
&lt;br /&gt;
==== Dec 2013 - San Francisco @ Twilio ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
&lt;br /&gt;
==== Nov 2013 - San Francisco @ LendingClub ====&lt;br /&gt;
OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
&lt;br /&gt;
==== Sept 2013 - Mt View @ Shape Security====&lt;br /&gt;
OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
&lt;br /&gt;
==== July 2013 - Berkeley @ University of Berkely====&lt;br /&gt;
OWASP Presentation Meeting&lt;br /&gt;
&lt;br /&gt;
* An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
* &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
*[mailto:teresa.ann.stevens2009@gmail.com Teresa Stevens] &lt;br /&gt;
*[mailto:cory@crazypenguin.com Cory Scott]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186743</id>
		<title>December 10, 2014</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186743"/>
				<updated>2014-12-10T01:51:15Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[link:addme Meeting Recording]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
12:00pm - 1:00pm EST&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[link:addme Meeting Minutes]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
*Reminder - Meeting Minutes from September, October &amp;amp; November have not been formally approved and noted in meeting minutes as recommended by Auditors.  Please review past minutes and be prepared to approve during December 10 BoD meeting, and/or suggest edits with 'Approval as amended'. P.Ritchie&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Michael Coates ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Tom Brennan ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report- Tobias Gondrom ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Fabio Cerullo, Eoin Keary, &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/a/owasp.org/document/d/1vMBMHSvIKGeXHZXoIeX_rsDSHBOrwMY1p55V2b_BM4U/edit?usp=sharing Summary Report for 10 Dec. 2014]&lt;br /&gt;
** Financial Update - [https://drive.google.com/a/owasp.org/file/d/0BxjNZI6rYJRKZk1ycVNlbGhuYzA/view?usp=sharing Draftv2 2015 Operating Budget &amp;amp; YTD P&amp;amp;L though Nov.2014]&lt;br /&gt;
** Ops Director Update - Kate Hartmann - [link:addme [https://docs.google.com/a/owasp.org/document/d/1tA31mJVhk78We-MQh0xk-KCgpqDJp18_ZIIzTL9lyao/edit?usp=sharing Kate Hartmann Update]&lt;br /&gt;
** Community Manager Update - [link:addme  Report]&lt;br /&gt;
** Membership Update - [link:addme Membership Report]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
* OWASP Whistleblower Policy (https://docs.google.com/a/owasp.org/document/d/1OwoHQtNGWxpr2qgSGbTqCRJJYLayh5d8zvzxoh2Cnqk/edit)&lt;br /&gt;
* For Action - Approve Sept, Oct, Nov meeting minutes and note in Dec. minutes.  May be 'Approved as amended' if edits still needed. P.Ritchie&lt;br /&gt;
* Compliance Officer - Outstanding actions &amp;amp; updates&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* [name of person adding topic] - topic&lt;br /&gt;
** [vote needed | discussion topic]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
* Executive Director&lt;br /&gt;
** Motion to move Paul from role of “Interim Executive Director” to “Executive Director” and change the reporting structure such that OWASP operations staff report directly to the Executive Director. Contingent upon successful terms and negotiation of contract for 12 month period.&lt;br /&gt;
** Background - [https://docs.google.com/a/owasp.org/document/d/1A37o_qP-63WaTXebtBKxIM1aAfduUa0hWL1y5VUI130/edit Google Doc]&lt;br /&gt;
* Executive Director contract with Virtual&lt;br /&gt;
** Contract Extension for 1 month (Dec - Jan)&lt;br /&gt;
* 2015 OWASP Roles&lt;br /&gt;
** Determination of when / how to vote&lt;br /&gt;
** Tom has put forth a motion for roles. (Note: Discussion on 2015 voting process &amp;amp; handling of motion)&lt;br /&gt;
* OWASP EU Entity&lt;br /&gt;
** Topic 1: Removal of Seba from OWASP Europe Board&lt;br /&gt;
** Topic 2: Discussion of What is the cost / benefit analysis (information gathered by Paul) &lt;br /&gt;
* 2015 Budget - preliminary overview by Paul&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186742</id>
		<title>December 10, 2014</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186742"/>
				<updated>2014-12-10T01:48:02Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Old Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[link:addme Meeting Recording]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
12:00pm - 1:00pm EST&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[link:addme Meeting Minutes]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
*Reminder - Meeting Minutes from September, October &amp;amp; November have not been formally approved and noted in meeting minutes as recommended by Auditors.  Please review past minutes and be prepared to approve during December 10 BoD meeting, and/or suggest edits with 'Approval as amended'. P.Ritchie&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Michael Coates ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Tom Brennan ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report- Tobias Gondrom ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Fabio Cerullo, Eoin Keary, &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/a/owasp.org/document/d/1vMBMHSvIKGeXHZXoIeX_rsDSHBOrwMY1p55V2b_BM4U/edit?usp=sharing Summary Report for 10 Dec. 2014]&lt;br /&gt;
** Financial Update - [https://drive.google.com/a/owasp.org/file/d/0BxjNZI6rYJRKZk1ycVNlbGhuYzA/view?usp=sharing Draftv2 2015 Operating Budget &amp;amp; YTD P&amp;amp;L though Nov.2014]&lt;br /&gt;
** Ops Director Update - Kate Hartmann - [link:addme [https://docs.google.com/a/owasp.org/document/d/1tA31mJVhk78We-MQh0xk-KCgpqDJp18_ZIIzTL9lyao/edit?usp=sharing Kate Hartmann Update]&lt;br /&gt;
** Community Manager Update - [link:addme  Report]&lt;br /&gt;
** Membership Update - [link:addme Membership Report]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
* OWASP Whistleblower Policy (https://docs.google.com/a/owasp.org/document/d/1OwoHQtNGWxpr2qgSGbTqCRJJYLayh5d8zvzxoh2Cnqk/edit)&lt;br /&gt;
* For Action - Approve Sept, Oct, Nov meeting minutes and note in Dec. minutes.  May be 'Approved as amended' if edits still needed. P.Ritchie&lt;br /&gt;
* Compliance Officer - Outstanding actions &amp;amp; updates&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* [name of person adding topic] - topic&lt;br /&gt;
** [vote needed | discussion topic]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
* Executive Director&lt;br /&gt;
** Motion to move Paul from role of “Interim Executive Director” to “Executive Director” and change the reporting structure such that OWASP operations staff report directly to the Executive Director. Contingent upon successful terms and negotiation of contract&lt;br /&gt;
** Background - [https://docs.google.com/a/owasp.org/document/d/1A37o_qP-63WaTXebtBKxIM1aAfduUa0hWL1y5VUI130/edit Google Doc]&lt;br /&gt;
* 2015 OWASP Roles&lt;br /&gt;
** Determination of when / how to vote&lt;br /&gt;
** Tom has put forth a motion for roles. (Note: Discussion on 2015 voting process &amp;amp; handling of motion)&lt;br /&gt;
* OWASP EU Entity&lt;br /&gt;
** Topic 1: Removal of Seba from OWASP Europe Board&lt;br /&gt;
** Topic 2: Discussion of What is the cost / benefit analysis (information gathered by Paul) &lt;br /&gt;
* 2015 Budget - preliminary overview by Paul&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186741</id>
		<title>December 10, 2014</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186741"/>
				<updated>2014-12-10T01:43:57Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Old Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[link:addme Meeting Recording]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
12:00pm - 1:00pm EST&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[link:addme Meeting Minutes]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
*Reminder - Meeting Minutes from September, October &amp;amp; November have not been formally approved and noted in meeting minutes as recommended by Auditors.  Please review past minutes and be prepared to approve during December 10 BoD meeting, and/or suggest edits with 'Approval as amended'. P.Ritchie&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Michael Coates ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Tom Brennan ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report- Tobias Gondrom ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Fabio Cerullo, Eoin Keary, &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/a/owasp.org/document/d/1vMBMHSvIKGeXHZXoIeX_rsDSHBOrwMY1p55V2b_BM4U/edit?usp=sharing Summary Report for 10 Dec. 2014]&lt;br /&gt;
** Financial Update - [https://drive.google.com/a/owasp.org/file/d/0BxjNZI6rYJRKZk1ycVNlbGhuYzA/view?usp=sharing Draftv2 2015 Operating Budget &amp;amp; YTD P&amp;amp;L though Nov.2014]&lt;br /&gt;
** Ops Director Update - Kate Hartmann - [link:addme [https://docs.google.com/a/owasp.org/document/d/1tA31mJVhk78We-MQh0xk-KCgpqDJp18_ZIIzTL9lyao/edit?usp=sharing Kate Hartmann Update]&lt;br /&gt;
** Community Manager Update - [link:addme  Report]&lt;br /&gt;
** Membership Update - [link:addme Membership Report]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
* OWASP Whistleblower Policy (https://docs.google.com/a/owasp.org/document/d/1OwoHQtNGWxpr2qgSGbTqCRJJYLayh5d8zvzxoh2Cnqk/edit)&lt;br /&gt;
* For Action - Approve Sept, Oct, Nov meeting minutes and note in Dec. minutes.  May be 'Approved as amended' if edits still needed. P.Ritchie&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* [name of person adding topic] - topic&lt;br /&gt;
** [vote needed | discussion topic]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
* Executive Director&lt;br /&gt;
** Motion to move Paul from role of “Interim Executive Director” to “Executive Director” and change the reporting structure such that OWASP operations staff report directly to the Executive Director. Contingent upon successful terms and negotiation of contract&lt;br /&gt;
** Background - [https://docs.google.com/a/owasp.org/document/d/1A37o_qP-63WaTXebtBKxIM1aAfduUa0hWL1y5VUI130/edit Google Doc]&lt;br /&gt;
* 2015 OWASP Roles&lt;br /&gt;
** Determination of when / how to vote&lt;br /&gt;
** Tom has put forth a motion for roles. (Note: Discussion on 2015 voting process &amp;amp; handling of motion)&lt;br /&gt;
* OWASP EU Entity&lt;br /&gt;
** Topic 1: Removal of Seba from OWASP Europe Board&lt;br /&gt;
** Topic 2: Discussion of What is the cost / benefit analysis (information gathered by Paul) &lt;br /&gt;
* 2015 Budget - preliminary overview by Paul&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186740</id>
		<title>December 10, 2014</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186740"/>
				<updated>2014-12-10T01:43:41Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[link:addme Meeting Recording]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
12:00pm - 1:00pm EST&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[link:addme Meeting Minutes]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
*Reminder - Meeting Minutes from September, October &amp;amp; November have not been formally approved and noted in meeting minutes as recommended by Auditors.  Please review past minutes and be prepared to approve during December 10 BoD meeting, and/or suggest edits with 'Approval as amended'. P.Ritchie&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Michael Coates ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Tom Brennan ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report- Tobias Gondrom ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Fabio Cerullo, Eoin Keary, &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/a/owasp.org/document/d/1vMBMHSvIKGeXHZXoIeX_rsDSHBOrwMY1p55V2b_BM4U/edit?usp=sharing Summary Report for 10 Dec. 2014]&lt;br /&gt;
** Financial Update - [https://drive.google.com/a/owasp.org/file/d/0BxjNZI6rYJRKZk1ycVNlbGhuYzA/view?usp=sharing Draftv2 2015 Operating Budget &amp;amp; YTD P&amp;amp;L though Nov.2014]&lt;br /&gt;
** Ops Director Update - Kate Hartmann - [link:addme [https://docs.google.com/a/owasp.org/document/d/1tA31mJVhk78We-MQh0xk-KCgpqDJp18_ZIIzTL9lyao/edit?usp=sharing Kate Hartmann Update]&lt;br /&gt;
** Community Manager Update - [link:addme  Report]&lt;br /&gt;
** Membership Update - [link:addme Membership Report]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* OWASP Whistleblower Policy (https://docs.google.com/a/owasp.org/document/d/1OwoHQtNGWxpr2qgSGbTqCRJJYLayh5d8zvzxoh2Cnqk/edit)&lt;br /&gt;
* For Action - Approve Sept, Oct, Nov meeting minutes and note in Dec. minutes.  May be 'Approved as amended' if edits still needed. P.Ritchie&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
* [name of person adding topic] - topic&lt;br /&gt;
** [vote needed | discussion topic]&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
* Executive Director&lt;br /&gt;
** Motion to move Paul from role of “Interim Executive Director” to “Executive Director” and change the reporting structure such that OWASP operations staff report directly to the Executive Director. Contingent upon successful terms and negotiation of contract&lt;br /&gt;
** Background - [https://docs.google.com/a/owasp.org/document/d/1A37o_qP-63WaTXebtBKxIM1aAfduUa0hWL1y5VUI130/edit Google Doc]&lt;br /&gt;
* 2015 OWASP Roles&lt;br /&gt;
** Determination of when / how to vote&lt;br /&gt;
** Tom has put forth a motion for roles. (Note: Discussion on 2015 voting process &amp;amp; handling of motion)&lt;br /&gt;
* OWASP EU Entity&lt;br /&gt;
** Topic 1: Removal of Seba from OWASP Europe Board&lt;br /&gt;
** Topic 2: Discussion of What is the cost / benefit analysis (information gathered by Paul) &lt;br /&gt;
* 2015 Budget - preliminary overview by Paul&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186739</id>
		<title>December 10, 2014</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=December_10,_2014&amp;diff=186739"/>
				<updated>2014-12-10T01:38:43Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* New Business */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Dial In Info==&lt;br /&gt;
===Notice of Recording===&lt;br /&gt;
* Notice to all attendees - board meetings are recorded and publicly available as of March, 2013&lt;br /&gt;
* Joining the call acknowledges your awareness of recording and consent to be recorded and public dissemination of the recording.&lt;br /&gt;
*[link:addme Meeting Recording]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Time===&lt;br /&gt;
12:00pm - 1:00pm EST&lt;br /&gt;
&lt;br /&gt;
===Location===   &lt;br /&gt;
&lt;br /&gt;
'''Teleconference Information:'''&lt;br /&gt;
&lt;br /&gt;
https://www3.gotomeeting.com/join/861328838&lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
=== Attendance Tracker===&lt;br /&gt;
'''[https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0ApZ9zE0hx0LNdG5uRzNYZE8ycDFabnBWNkU4SFpwREE Board Meeting Attendance Tracker]'''&lt;br /&gt;
&lt;br /&gt;
=== Meeting Minutes===&lt;br /&gt;
[link:addme Meeting Minutes]&lt;br /&gt;
&lt;br /&gt;
= Reading Material  =&lt;br /&gt;
'''''It is a requirement as a board member to fully read all material prior to the start of the meeting'''''&lt;br /&gt;
*Reminder - Meeting Minutes from September, October &amp;amp; November have not been formally approved and noted in meeting minutes as recommended by Auditors.  Please review past minutes and be prepared to approve during December 10 BoD meeting, and/or suggest edits with 'Approval as amended'. P.Ritchie&lt;br /&gt;
&lt;br /&gt;
= Meeting Agenda =&lt;br /&gt;
== Call to Order /OWASP Mission ==&lt;br /&gt;
*Administrative (List of attendees and Agenda bashing (only if last-minute changes to the agenda are needed) (5 min)&lt;br /&gt;
&lt;br /&gt;
== Reports ==&lt;br /&gt;
=== Chairmain's Report - Michael Coates ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Vice Chairmain's Report - Tom Brennan ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Treasurer Report - Josh Sokol ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Secretary Report- Tobias Gondrom ===&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
=== Updated from Members at Large - Fabio Cerullo, Eoin Keary, &amp;amp; Jim Manico ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Reports==&lt;br /&gt;
* Executive Director/Operations Update - [https://docs.google.com/a/owasp.org/document/d/1vMBMHSvIKGeXHZXoIeX_rsDSHBOrwMY1p55V2b_BM4U/edit?usp=sharing Summary Report for 10 Dec. 2014]&lt;br /&gt;
** Financial Update - [https://drive.google.com/a/owasp.org/file/d/0BxjNZI6rYJRKZk1ycVNlbGhuYzA/view?usp=sharing Draftv2 2015 Operating Budget &amp;amp; YTD P&amp;amp;L though Nov.2014]&lt;br /&gt;
** Ops Director Update - Kate Hartmann - [link:addme [https://docs.google.com/a/owasp.org/document/d/1tA31mJVhk78We-MQh0xk-KCgpqDJp18_ZIIzTL9lyao/edit?usp=sharing Kate Hartmann Update]&lt;br /&gt;
** Community Manager Update - [link:addme  Report]&lt;br /&gt;
** Membership Update - [link:addme Membership Report]&lt;br /&gt;
** IT Update - [link:addme Matt Tesauro Report]&lt;br /&gt;
&lt;br /&gt;
=== Community Initiative Reports  ===&lt;br /&gt;
*&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* OWASP Whistleblower Policy (https://docs.google.com/a/owasp.org/document/d/1OwoHQtNGWxpr2qgSGbTqCRJJYLayh5d8zvzxoh2Cnqk/edit)&lt;br /&gt;
* For Action - Approve Sept, Oct, Nov meeting minutes and note in Dec. minutes.  May be 'Approved as amended' if edits still needed. P.Ritchie&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
* [name of person adding topic] - topic&lt;br /&gt;
** [vote needed | discussion topic]&lt;br /&gt;
* Michael - Executive Director&lt;br /&gt;
** Motion to move Paul from role of “Interim Executive Director” to “Executive Director” and change the reporting structure such that OWASP operations staff report directly to the Executive Director. Contingent upon successful terms and negotiation of contract&lt;br /&gt;
** Background - [https://docs.google.com/a/owasp.org/document/d/1A37o_qP-63WaTXebtBKxIM1aAfduUa0hWL1y5VUI130/edit Google Doc]&lt;br /&gt;
&lt;br /&gt;
== Action Items==&lt;br /&gt;
*&lt;br /&gt;
&lt;br /&gt;
==Announcements==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Adjournment==&lt;br /&gt;
*Next meeting date/time: &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Motion to close meeting==&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=186407</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=186407"/>
				<updated>2014-12-03T19:23:39Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Sergey Shekyan &amp;amp; Bei Zhang, Shape Security */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:2015AppSecUSA-SF.png|400px|thumb|alt=Register Now!|link=https://2015.appsecusa.org]]&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Next Event=&lt;br /&gt;
Wednesday, December 10, 2014 - San Francisco @ Mozilla &lt;br /&gt;
&lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://www.mozilla.org/en-US/ Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/218988323/ RSVP on Meetup]&amp;lt;br&amp;gt;&lt;br /&gt;
====When====&lt;br /&gt;
&lt;br /&gt;
* Wednesday, Dec 10&lt;br /&gt;
* 5:30 pm - 8:00 pm&lt;br /&gt;
&lt;br /&gt;
====Where====&lt;br /&gt;
&lt;br /&gt;
[https://goo.gl/maps/iQIKh Mozilla, 2 Harrison St, San Francisco, CA 94105]&lt;br /&gt;
&lt;br /&gt;
====Agenda====&lt;br /&gt;
&lt;br /&gt;
5:30-6:15 pm - Networking with Drinks &amp;amp; Food&amp;lt;br&amp;gt;&lt;br /&gt;
6:15-6:45 : Speaker: Jasvir Nagra, Google &amp;lt;br&amp;gt;&lt;br /&gt;
7:00-7:30 : Speaker: Sergey Shekyan &amp;amp; Bei Zhang, Shape Security &amp;lt;br&amp;gt;&lt;br /&gt;
7:30-8:00 : More food, drink, and security &amp;quot;hallway con&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Speakers====&lt;br /&gt;
&lt;br /&gt;
* Jasvir Nagra, Google&lt;br /&gt;
* Sergey Shekyan &amp;amp; Bei Zhang, Shape Security&lt;br /&gt;
&lt;br /&gt;
===== Jasvir Nagra, Google ===== &lt;br /&gt;
'''Firing Bots at Bugs'''&lt;br /&gt;
&lt;br /&gt;
It remains all too easy to find simple security vulnerabilities in many web applications.  Why is it so hard to automatically find vulnerabilities when finding them manually remains so relatively easy? In this talk, we’ll share some of gotchas that we’ve run into scanning for web security bugs at Google, armed with a 'firing squad' of examples. We'll then walk through some of the solutions we've come up with, and finish up with a few unsolved problems which remain that really make web vulnerability scanning a hard (but fun!) problem to work on.&lt;br /&gt;
&lt;br /&gt;
Jasvir Nagra is a security engineer at Google dedicated to making the web vulnerability-free.  He has led the design and implementation of Caja, a pure JavaScript sandbox. Previously, he co-authored Surreptitious Software, a book on obfuscation, software watermarking and tamper-proofing; and built autonomous soccer-playing robots.  These days he builds web application scanners that work at scale&lt;br /&gt;
&lt;br /&gt;
=====  Sergey Shekyan &amp;amp; Bei Zhang, Shape Security===== &lt;br /&gt;
'''Headless Browsers Hide and Seek'''&lt;br /&gt;
&lt;br /&gt;
Headless browsers have become indispensable tools for security teams, researchers, and attackers focusing on web applications. Tools like PhantomJS enable anyone to automatically interact with highly dynamic websites and to perform many types of automated attacks. This presentation will dive into headless browser detection and spoofing techniques.&lt;br /&gt;
&lt;br /&gt;
Sergey Shekyan is a Principal Engineer at Shape Security, where he is focused on the development of the new generation web security product. Prior to Shape Security, he spent 4 years at Qualys developing their on demand web application vulnerability scanning service. &lt;br /&gt;
&lt;br /&gt;
Bei Zhang is a Senior Software Engineer at Shape Security, focused on analysis and countermeasures of automatic web attacks. Previously, he worked at the Chrome team at Google with a focus on the Chrome Apps API. His interests include web security, source code analysis, and algorithms.&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide.'''''&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
RSS of all public bay area events (it only contains the next event so don't worry if it's empty when you subscribe)&lt;br /&gt;
&lt;br /&gt;
http://www.eventbrite.com/rss/user_list_events/22961305858&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
&lt;br /&gt;
====  August 2014 - San Francisco @ Lookout ==== &lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
* Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
&lt;br /&gt;
====  May 2014 - Redwood City @ Evernote ==== &lt;br /&gt;
OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Arshad Noor - CTO, StrongAuth&lt;br /&gt;
* Rich Tener - Director of Security, Evernote&lt;br /&gt;
&lt;br /&gt;
==== March 2014 - San Francisco @ Stripe ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - San Jose @ Jillians ====&lt;br /&gt;
OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - Special Free Training Event ====&lt;br /&gt;
OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
&lt;br /&gt;
Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
&lt;br /&gt;
==== Jan 2014 - San Jose @ F5====&lt;br /&gt;
OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
&lt;br /&gt;
==== Dec 2013 - San Francisco @ Twilio ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
&lt;br /&gt;
==== Nov 2013 - San Francisco @ LendingClub ====&lt;br /&gt;
OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
&lt;br /&gt;
==== Sept 2013 - Mt View @ Shape Security====&lt;br /&gt;
OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
&lt;br /&gt;
==== July 2013 - Berkeley @ University of Berkely====&lt;br /&gt;
OWASP Presentation Meeting&lt;br /&gt;
&lt;br /&gt;
* An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
* &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
*[mailto:teresa.ann.stevens2009@gmail.com Teresa Stevens] &lt;br /&gt;
*[mailto:cory@crazypenguin.com Cory Scott]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=186406</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=186406"/>
				<updated>2014-12-03T19:23:20Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: /* Jasvir Nagra, Google */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:2015AppSecUSA-SF.png|400px|thumb|alt=Register Now!|link=https://2015.appsecusa.org]]&lt;br /&gt;
{{Chapter Template|chaptername=Bay Area|extra=|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-bayarea|emailarchives=http://lists.owasp.org/pipermail/owasp-bayarea}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP-Bay-Area-Aug-2014.png]]&lt;br /&gt;
&lt;br /&gt;
150+ attendees at the OWASP Bay Area meeting in August, 2014&lt;br /&gt;
&lt;br /&gt;
Picture is @BenHagen talking about cloud security and applications&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Next Event=&lt;br /&gt;
Wednesday, December 10, 2014 - San Francisco @ Mozilla &lt;br /&gt;
&lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://www.mozilla.org/en-US/ Mozilla]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://www.meetup.com/Bay-Area-OWASP/events/218988323/ RSVP on Meetup]&amp;lt;br&amp;gt;&lt;br /&gt;
====When====&lt;br /&gt;
&lt;br /&gt;
* Wednesday, Dec 10&lt;br /&gt;
* 5:30 pm - 8:00 pm&lt;br /&gt;
&lt;br /&gt;
====Where====&lt;br /&gt;
&lt;br /&gt;
[https://goo.gl/maps/iQIKh Mozilla, 2 Harrison St, San Francisco, CA 94105]&lt;br /&gt;
&lt;br /&gt;
====Agenda====&lt;br /&gt;
&lt;br /&gt;
5:30-6:15 pm - Networking with Drinks &amp;amp; Food&amp;lt;br&amp;gt;&lt;br /&gt;
6:15-6:45 : Speaker: Jasvir Nagra, Google &amp;lt;br&amp;gt;&lt;br /&gt;
7:00-7:30 : Speaker: Sergey Shekyan &amp;amp; Bei Zhang, Shape Security &amp;lt;br&amp;gt;&lt;br /&gt;
7:30-8:00 : More food, drink, and security &amp;quot;hallway con&amp;quot;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
====Speakers====&lt;br /&gt;
&lt;br /&gt;
* Jasvir Nagra, Google&lt;br /&gt;
* Sergey Shekyan &amp;amp; Bei Zhang, Shape Security&lt;br /&gt;
&lt;br /&gt;
===== Jasvir Nagra, Google ===== &lt;br /&gt;
'''Firing Bots at Bugs'''&lt;br /&gt;
&lt;br /&gt;
It remains all too easy to find simple security vulnerabilities in many web applications.  Why is it so hard to automatically find vulnerabilities when finding them manually remains so relatively easy? In this talk, we’ll share some of gotchas that we’ve run into scanning for web security bugs at Google, armed with a 'firing squad' of examples. We'll then walk through some of the solutions we've come up with, and finish up with a few unsolved problems which remain that really make web vulnerability scanning a hard (but fun!) problem to work on.&lt;br /&gt;
&lt;br /&gt;
Jasvir Nagra is a security engineer at Google dedicated to making the web vulnerability-free.  He has led the design and implementation of Caja, a pure JavaScript sandbox. Previously, he co-authored Surreptitious Software, a book on obfuscation, software watermarking and tamper-proofing; and built autonomous soccer-playing robots.  These days he builds web application scanners that work at scale&lt;br /&gt;
&lt;br /&gt;
=====  Sergey Shekyan &amp;amp; Bei Zhang, Shape Security===== &lt;br /&gt;
Headless browsers have become indispensable tools for security teams, researchers, and attackers focusing on web applications. Tools like PhantomJS enable anyone to automatically interact with highly dynamic websites and to perform many types of automated attacks. This presentation will dive into headless browser detection and spoofing techniques.&lt;br /&gt;
&lt;br /&gt;
Sergey Shekyan is a Principal Engineer at Shape Security, where he is focused on the development of the new generation web security product. Prior to Shape Security, he spent 4 years at Qualys developing their on demand web application vulnerability scanning service. &lt;br /&gt;
&lt;br /&gt;
Bei Zhang is a Senior Software Engineer at Shape Security, focused on analysis and countermeasures of automatic web attacks. Previously, he worked at the Chrome team at Google with a focus on the Chrome Apps API. His interests include web security, source code analysis, and algorithms.&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
'''OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide.'''''&lt;br /&gt;
&lt;br /&gt;
= About OWASP Bay Area Chapter=&lt;br /&gt;
== Geographic Area of Bay Area Chapter ==&lt;br /&gt;
&lt;br /&gt;
The 'Bay Area' is actually the San Francisco Bay Area in California, which is near other large towns that are across the bay from San Francisco such as Berkeley and Oakland, and south of San Francisco are San Mateo, Palo Alto, and the whole San Jose area.  Currently, the Bay Area OWASP Chapter covers this whole geographic region. &lt;br /&gt;
&lt;br /&gt;
== Become a Presenter ==&lt;br /&gt;
Submit your talk now for an upcoming OWASP Bay Area Chapter Meeting&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/a/owasp.org/forms/d/1ImmfY5KtSILjIym1uToOzSmT2Xv58bVzfxUPDAAn9-c/viewform Link to submit]&lt;br /&gt;
&lt;br /&gt;
=== Notes about OWASP presentations ===&lt;br /&gt;
OWASP presentations are geared for a technical audience. We are particularly interested in new approaches to tackling application security problems, defensive techniques for new technology in the application security space and lessons learned from developers and security professionals tackling application security. Please consider a wide breadth of topic areas and we can discuss if they should be tailored in a particular direction for the OWASP audience.&lt;br /&gt;
&lt;br /&gt;
OWASP chapter presentations must not be sales pitches and must adhere to a vendor neutral approach to the topic.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meetings ==&lt;br /&gt;
&lt;br /&gt;
RSS of all public bay area events (it only contains the next event so don't worry if it's empty when you subscribe)&lt;br /&gt;
&lt;br /&gt;
http://www.eventbrite.com/rss/user_list_events/22961305858&lt;br /&gt;
&lt;br /&gt;
=== About Presentation Events ===&lt;br /&gt;
Presentation events will feature 1 or more speakers discussing application security. These events will include a networking session, with drinks and food, before and after the event.&lt;br /&gt;
&lt;br /&gt;
=== About OWASP Social Hours===&lt;br /&gt;
The purpose of the OWASP social gathering is:&lt;br /&gt;
&lt;br /&gt;
* Informal security chat - the benefits of &amp;quot;hallway con&amp;quot; and security talk with others in the industry&lt;br /&gt;
* Networking - meet other people in the field and industry&lt;br /&gt;
* After work drinks - a nice break after a long work day&lt;br /&gt;
&lt;br /&gt;
Note: These events won't have any formal presentations. They're meant to be social gatherings to meet others in the industry and chat about security. Check our quarterly OWASP Bay Area schedule for the security presentation events.&lt;br /&gt;
https://www.owasp.org/index.php/Bay_Area&lt;br /&gt;
 &lt;br /&gt;
Is your organization interested in hosting an OWASP social hour in the bay area (San Francisco, South Bay, East Bay)? Contact michael.coates@owasp.org&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Past Events==&lt;br /&gt;
&lt;br /&gt;
====  August 2014 - San Francisco @ Lookout ==== &lt;br /&gt;
OWASP Chapter Meeting in San Francisco hosted by [https://Lookout.com/ Lookout]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Paul McMillan from Nebula [https://twitter.com/PaulM @PaulM] - Attacking the Internet of Things using Time&lt;br /&gt;
* Ben Hagen from Netflix [https://twitter.com/enHagen @BenHagen] - Cloud Security at Scale and What it Means for Your Application &lt;br /&gt;
&lt;br /&gt;
====  May 2014 - Redwood City @ Evernote ==== &lt;br /&gt;
OWASP Chapter Meeting in Redwood City hosted by [https://Evernote.com/ Evernote]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* Arshad Noor - CTO, StrongAuth&lt;br /&gt;
* Rich Tener - Director of Security, Evernote&lt;br /&gt;
&lt;br /&gt;
==== March 2014 - San Francisco @ Stripe ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Wednesday, Mar 12, 2014 &lt;br /&gt;
Hosted by [https://stripe.com/ Stripe]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - San Jose @ Jillians ====&lt;br /&gt;
OWASP Developer Training &amp;amp; Social Hour - Monday 2/24/2013&lt;br /&gt;
Hosted by OWASP at Jillian's Billiards Club&lt;br /&gt;
&lt;br /&gt;
==== Feb 2014 - Special Free Training Event ====&lt;br /&gt;
OWASP is hosting a special security boot camp for all RSA attendees and local developers. The training is recommended for developers who want to learn more about securing their code as well as security professionals who want to become acquainted with the latest web vulnerabilities.  &lt;br /&gt;
&lt;br /&gt;
Presented by Jim Manico and Eoin Keary, this intensive boot camp focuses on the most common web application security problems, including aspects of both the OWASP Top Ten and the MITRE Top 25. The course will introduce and demonstrate application assessment techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code and understand fixes.  &lt;br /&gt;
&lt;br /&gt;
==== Jan 2014 - San Jose @ F5====&lt;br /&gt;
OWASP Social Hour in San Jose - Wednesday 1/22/2013&lt;br /&gt;
Hosted by [http://www.f5.com/ F5]&lt;br /&gt;
&lt;br /&gt;
==== Dec 2013 - San Francisco @ Twilio ====&lt;br /&gt;
OWASP Social Hour in San Francisco - Thursday 12/19/2013&lt;br /&gt;
Hosted by [http://www.twilio.com/ Twilio]&lt;br /&gt;
&lt;br /&gt;
==== Nov 2013 - San Francisco @ LendingClub ====&lt;br /&gt;
OWASP Social Hour in Mountain View - Wednesday 11/6/13&lt;br /&gt;
Hosted by [https://www.lendingclub.com/ LendingClub]&lt;br /&gt;
&lt;br /&gt;
==== Sept 2013 - Mt View @ Shape Security====&lt;br /&gt;
OWASP Social Hour in Mountain View -  Wednesday 9/25/13&lt;br /&gt;
Hosted by [http://www.shapesecurity.com/ Shape Security]&lt;br /&gt;
&lt;br /&gt;
==== July 2013 - Berkeley @ University of Berkely====&lt;br /&gt;
OWASP Presentation Meeting&lt;br /&gt;
&lt;br /&gt;
* An Empirical Study of Vulnerability Rewards Programs, Devdatta Akhawe&lt;br /&gt;
* &amp;quot;Putting Your Robots to Work&amp;quot;, Twitter Security Team&lt;br /&gt;
&lt;br /&gt;
==== Older Events ====&lt;br /&gt;
[[Bay Area Past Events]]&lt;br /&gt;
&lt;br /&gt;
== Bay Area Chapter Leaders ==&lt;br /&gt;
&lt;br /&gt;
*[[User:MichaelCoates | Michael Coates]] &lt;br /&gt;
*[mailto:teresa.ann.stevens2009@gmail.com Teresa Stevens] &lt;br /&gt;
*[mailto:cory@crazypenguin.com Cory Scott]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Stay In Touch =&lt;br /&gt;
* All events will be listed on this webpage&lt;br /&gt;
* Keep in touch via twitter [https://twitter.com/OWASPBayArea @OWASPBayArea] or on [https://www.linkedin.com/groups/OWASP-BayArea-6568682 Linkedin]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:California]]&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=International_Toll_Free_Calling_Information&amp;diff=186405</id>
		<title>International Toll Free Calling Information</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=International_Toll_Free_Calling_Information&amp;diff=186405"/>
				<updated>2014-12-03T17:50:41Z</updated>
		
		<summary type="html">&lt;p&gt;MichaelCoates: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Access Code: 184-789-686'''&lt;br /&gt;
&lt;br /&gt;
2.  Use your microphone and speakers (VoIP) - a headset is recommended. Or, call in using your telephone.&lt;br /&gt;
&lt;br /&gt;
Argentina (toll-free): 0 800 444 3375&lt;br /&gt;
&lt;br /&gt;
Austria: +43 (0) 7 2088 1047&lt;br /&gt;
&lt;br /&gt;
Austria (toll-free): 0 800 202148&lt;br /&gt;
&lt;br /&gt;
Australia: +61 2 8355 1020&lt;br /&gt;
&lt;br /&gt;
Australia (toll-free): 1 800 193 385&lt;br /&gt;
&lt;br /&gt;
Belgium: +32 (0) 28 08 4368&lt;br /&gt;
&lt;br /&gt;
Belgium (toll-free): 0 800 26116&lt;br /&gt;
&lt;br /&gt;
Brazil (toll-free): 0 800 047 4906&lt;br /&gt;
&lt;br /&gt;
Belarus (toll-free): 8 820 0011 0214&lt;br /&gt;
&lt;br /&gt;
Canada: +1 (647) 497-9353&lt;br /&gt;
&lt;br /&gt;
Canada (toll-free): 1 888 455 1389&lt;br /&gt;
&lt;br /&gt;
Switzerland: +41 (0) 435 0167 13&lt;br /&gt;
&lt;br /&gt;
Switzerland (toll-free): 0 800 740 393&lt;br /&gt;
&lt;br /&gt;
China (toll-free): 4008 811084&lt;br /&gt;
&lt;br /&gt;
Czech Republic (toll-free): 800 500448&lt;br /&gt;
&lt;br /&gt;
Germany: +49 (0) 811 8899 6903&lt;br /&gt;
&lt;br /&gt;
Germany (toll-free): 0 800 184 4222&lt;br /&gt;
&lt;br /&gt;
Denmark: +45 (0) 69 91 89 28&lt;br /&gt;
&lt;br /&gt;
Denmark (toll-free): 8090 1924&lt;br /&gt;
&lt;br /&gt;
Spain: +34 911 82 9906&lt;br /&gt;
&lt;br /&gt;
Spain (toll-free): 800 900 582&lt;br /&gt;
&lt;br /&gt;
Finland: +358 (0) 942 59 7850&lt;br /&gt;
&lt;br /&gt;
Finland (toll-free): 0 800 94507&lt;br /&gt;
&lt;br /&gt;
France: +33 (0) 170 950 594&lt;br /&gt;
&lt;br /&gt;
France (toll-free): 0 805 541 047&lt;br /&gt;
&lt;br /&gt;
United Kingdom: +44 (0) 20 7151 1853&lt;br /&gt;
&lt;br /&gt;
United Kingdom (toll-free): 0 808 168 0229&lt;br /&gt;
&lt;br /&gt;
Hong Kong SAR China (toll-free): 30713169&lt;br /&gt;
&lt;br /&gt;
Indonesia (toll-free): 007 803 011 0395&lt;br /&gt;
&lt;br /&gt;
Ireland: +353 (0) 19 030 010&lt;br /&gt;
&lt;br /&gt;
Ireland (toll-free): 1 800 946 538&lt;br /&gt;
&lt;br /&gt;
Israel (toll-free): 1 809 212 875&lt;br /&gt;
&lt;br /&gt;
India (toll-free): 000 800 100 7855&lt;br /&gt;
&lt;br /&gt;
Iceland (toll-free): 800 9869&lt;br /&gt;
&lt;br /&gt;
Italy: +39 0 247 92 13 01&lt;br /&gt;
&lt;br /&gt;
Italy (toll-free): 800 906959&lt;br /&gt;
&lt;br /&gt;
Japan (toll-free): 0 120 663 800&lt;br /&gt;
&lt;br /&gt;
Luxembourg (toll-free): 800 22104&lt;br /&gt;
&lt;br /&gt;
Mexico (toll-free): 01 800 925 0372&lt;br /&gt;
&lt;br /&gt;
Malaysia (toll-free): 1 800 81 6851&lt;br /&gt;
&lt;br /&gt;
Netherlands: +31 (0) 208 080 219&lt;br /&gt;
&lt;br /&gt;
Netherlands (toll-free): 0 800 265 8469&lt;br /&gt;
&lt;br /&gt;
Norway: +47 75 80 32 07&lt;br /&gt;
&lt;br /&gt;
New Zealand: +64 (0) 9 280 6302&lt;br /&gt;
&lt;br /&gt;
New Zealand (toll-free): 0 800 47 0011&lt;br /&gt;
&lt;br /&gt;
Panama (toll-free): 00 800 226 8832&lt;br /&gt;
&lt;br /&gt;
Peru (toll-free): 0 800 54682&lt;br /&gt;
&lt;br /&gt;
Philippines (toll-free): 1 800 1651 0716&lt;br /&gt;
&lt;br /&gt;
Poland (toll-free): 00 800 1213979&lt;br /&gt;
&lt;br /&gt;
Portugal (toll-free): 800 784 461&lt;br /&gt;
&lt;br /&gt;
Russia (toll-free): 810 800 29674011&lt;br /&gt;
&lt;br /&gt;
Sweden: +46 (0) 852 500 186&lt;br /&gt;
&lt;br /&gt;
Sweden (toll-free): 020 980 772&lt;br /&gt;
&lt;br /&gt;
Singapore (toll-free): 800 101 2992&lt;br /&gt;
&lt;br /&gt;
Thailand (toll-free): 001 800 658 131&lt;br /&gt;
&lt;br /&gt;
Taiwan (toll-free): 0 800 666 854&lt;br /&gt;
&lt;br /&gt;
Ukraine (toll-free): 0 800 50 0641&lt;br /&gt;
&lt;br /&gt;
United States: +1 (224) 649-0001&lt;br /&gt;
&lt;br /&gt;
United States (toll-free): 1 877 309 2073&lt;br /&gt;
&lt;br /&gt;
Uruguay (toll-free): 000 413 598 4110&lt;br /&gt;
&lt;br /&gt;
Vietnam (toll-free): 120 32 153&lt;br /&gt;
&lt;br /&gt;
South Africa (toll-free): 0 800 555 447&lt;br /&gt;
&lt;br /&gt;
'''Access Code: 184-789-686'''&lt;br /&gt;
Audio PIN: Shown after joining the meeting&lt;br /&gt;
&lt;br /&gt;
Meeting ID: 184-789-686&lt;/div&gt;</summary>
		<author><name>MichaelCoates</name></author>	</entry>

	</feed>