This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Summit 2011"
Sarah Baso (talk | contribs) |
Sarah Baso (talk | contribs) (Undo revision 96007 by Sarah Baso (Talk)) |
||
Line 3: | Line 3: | ||
==== Welcome ==== | ==== Welcome ==== | ||
− | {| | + | {| cellspacing="0" cellpadding="20" border="0" class="FCK__ShowTableBorders" |
|- | |- | ||
| [[Image:OWASPGlobalSummitLogo-3THISONEHASTHEMOSTVOTESSOFAR.jpg|border|center|462x347px]] | | [[Image:OWASPGlobalSummitLogo-3THISONEHASTHEMOSTVOTESSOFAR.jpg|border|center|462x347px]] | ||
Line 9: | Line 9: | ||
=== Dear OWASP Leaders and appsec community, === | === Dear OWASP Leaders and appsec community, === | ||
− | <br>The Summit will be held February 8th-11th at [http://www.camporeal.pt/en/home.aspx CampoReal Resort] in central Oeste Portugal, 38 km north of Lisbon and 18 km inland from the Atlantic Ocean. This will be the place where appsec experts meet, discuss, work, socialize, and set the roadmap for OWASP in coming years. <br><br> | + | <br>The Summit will be held February 8th-11th at [http://www.camporeal.pt/en/home.aspx CampoReal Resort] in central Oeste Portugal, 38 km north of Lisbon and 18 km inland from the Atlantic Ocean. This will be the place where appsec experts meet, discuss, work, socialize, and set the roadmap for OWASP in coming years. <br><br> |
=== The Summit Activates *You* === | === The Summit Activates *You* === | ||
Line 27: | Line 27: | ||
=== Organizing Committee === | === Organizing Committee === | ||
− | [[User:Lorna Alamri|Lorna Alamri]], [[User:Bradcausey|Brad Causey]], [[User:Justin42|Justin Clarke]], [[User:Paulo Coimbra|Paulo Coimbra]], [[User:Dinis.cruz|Dinis Cruz]], [[User:Knoblochmartin|Martin Knobloch]], [[User:Wichers|Dave Wichers]], [[User:John.wilander|John Wilander]], [[User:Jason Li|Jason Li]] | + | [[User:Lorna Alamri|Lorna Alamri]], [[User:Bradcausey|Brad Causey]], [[User:Justin42|Justin Clarke]], [[User:Paulo Coimbra|Paulo Coimbra]], [[User:Dinis.cruz|Dinis Cruz]], [[User:Knoblochmartin|Martin Knobloch]], [[User:Wichers|Dave Wichers]], [[User:John.wilander|John Wilander]], and [[User:Jason Li|Jason Li]]. |
| valign="top" | | | valign="top" | | ||
=== Who's Invited? === | === Who's Invited? === | ||
− | As an OWASP leader you are automatically invited to the summit, but we also welcome leading experts from industry and academia. Together we can create a more secure web. Check the "How Do I Join?" tab above for more info. | + | As an OWASP leader you are automatically invited to the summit, but we also welcome leading experts from industry and academia. Together we can create a more secure web. Check the "How Do I Join?" tab above for more info. |
|} | |} | ||
− | <!---[[Image:Summit Group 4.jpg|border|OWASP Summit 2008 in Portugal]] ---> | + | <!---[[Image:Summit Group 4.jpg|border|OWASP Summit 2008 in Portugal]] ---> |
− | + | <br> | |
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | <br> | ||
==== OWASP Around the World ==== | ==== OWASP Around the World ==== | ||
Line 107: | Line 59: | ||
**Securing | **Securing | ||
**Re-Structuring | **Re-Structuring | ||
− | **Re-Design | + | **Re-Design |
*OWASP Branding | *OWASP Branding | ||
+ | *Can/should OWASP push for fundamental change to flawed specs? | ||
+ | **OWASP Influence change - or - Is it enough to make/use bandages on poor specs? | ||
+ | ***HTML spec - separate data and code | ||
+ | ***HTTP - CSRF should be at a much lower level than the app layer | ||
+ | ***OpenID - transparent login is a security issue | ||
+ | ***SSL - long list of CAs, who delegate CAs <recurse> - trust? security? | ||
*[Your topic here] | *[Your topic here] | ||
Line 125: | Line 83: | ||
It goes without saying - the summit is all about meeting people. So there will be a constant mixture of workshops, dinners, beers and wine. We like to think of the summit as a very social event in itself. | It goes without saying - the summit is all about meeting people. So there will be a constant mixture of workshops, dinners, beers and wine. We like to think of the summit as a very social event in itself. | ||
− | <br> | + | <br> |
==== Summit Pricing and Reservations ==== | ==== Summit Pricing and Reservations ==== | ||
Line 139: | Line 97: | ||
[[Image:Hotel entrance 697x395.jpg]] | [[Image:Hotel entrance 697x395.jpg]] | ||
− | Below is the link to the Venue of the 2011 OWASP Global Summit -- CampoReal Resort. CampoReal is located in central Oeste Portugal 38 km north of Lisbon and 18 km inland from the Atlantic Ocean.<br> | + | Below is the link to the Venue of the 2011 OWASP Global Summit -- CampoReal Resort. CampoReal is located in central Oeste Portugal 38 km north of Lisbon and 18 km inland from the Atlantic Ocean.<br> |
[http://www.camporeal.pt/en/hotel-residences.aspx http://www.camporeal.pt/en/hotel-residences.aspx] | [http://www.camporeal.pt/en/hotel-residences.aspx http://www.camporeal.pt/en/hotel-residences.aspx] | ||
Line 147: | Line 105: | ||
The hotel has an Airport Shuttle, Gym and Fitness Center, Gootball camp, Horse Back Riding, Day Spa, Internet WiFi, and Golfcourse as well as many other amenities. | The hotel has an Airport Shuttle, Gym and Fitness Center, Gootball camp, Horse Back Riding, Day Spa, Internet WiFi, and Golfcourse as well as many other amenities. | ||
− | Meals and coffee breaks will be provided by OWASP.<br> | + | Meals and coffee breaks will be provided by OWASP.<br> |
− | [[Image:Villas.jpg]]<br> | + | [[Image:Villas.jpg]]<br> |
− | '''Villa Accommodations:'''<br> | + | '''Villa Accommodations:'''<br> |
Residence-Pool 3 or 4 bedrooms<br>- Villa | Residence-Pool 3 or 4 bedrooms<br>- Villa | ||
Line 157: | Line 115: | ||
Each Residence includes:<br>- Private bathroom(s)<br>- Kitchenette<br>- Balcony or garden<br>- Swimming-pool shared by apartment/townhouse block<br>- Residence-Pool for 3 bedroom and 4 bedroom villas include a private swimming-pool | Each Residence includes:<br>- Private bathroom(s)<br>- Kitchenette<br>- Balcony or garden<br>- Swimming-pool shared by apartment/townhouse block<br>- Residence-Pool for 3 bedroom and 4 bedroom villas include a private swimming-pool | ||
− | <br> | + | <br> |
'''A Day in Lisbon, Portugal:''' | '''A Day in Lisbon, Portugal:''' | ||
− | [[Image:Cascais2.jpg]]<br><br>Click this link to see all the City of Lisbon has to offer, which is only a short train ride from the resort.<br>[http://www.golisbon.com/portugal/cities/cascais.html http://www.golisbon.com/portugal/cities/cascais.html]<br>or<br>[http://www.travel-in-portugal.com/Cascais/ http://www.travel-in-portugal.com/Cascais/]<br>'''Lisbon''' - Spreading out along the right bank of the Tagus, its downtown, the Baixa, is located in the 18th-century area around Rossio. East of the arcade Praça do Comércio, are the medieval quarters of Alfama and Mouraria, crowned by the magnificent St. George's Castle. To the west lie Bairro Alto and Madragoa, with their typical streets, and on the western extreme is Belém, with its Belém Tower, (the sentinel over the Tagus river that protects the entrance into Lisbon), the Jerónimos Monastery (masterpieces of Manueline architecture and classified in UNESCO's International Heritage list) and the Cultural Center of Belém.[http://www.portugalvirtual.pt/0/83.html <br>Museums:] Ancient Art, Chiado (Contemporary Art), Tile, Archaeology, Ethnology, Coach, Costume, Theater, Maritime, Military, City, Gulbenkian, Modern Art Center, and the Ricardo Espirito Santo Silva Foundation. Palaces open to the public: Ajuda and Fronteira. Churches: Cathedral (with Treasury); São Vicente de Fora; Conceição Velha (Manueline), São Roque and Sacred Art; Madre Deus; Santa Engrácia Pantheon (Baroque), and the Estrela Basilica.<br>[http://www.portugalvirtual.pt/0/60.html Shopping:] Downtown; Avenida de Roma, Praça de Londres, Avenida Guerra Junqueiro, and Amoreiras. <br>[http://www.portugalvirtual.pt/0/80.html Nightlife:] Bairro Alto and Avenida 24 de Julho.<br>[http://www.portugalvirtual.pt/tours/index.html Guided Tours]<br><br> | + | [[Image:Cascais2.jpg]]<br><br>Click this link to see all the City of Lisbon has to offer, which is only a short train ride from the resort.<br>[http://www.golisbon.com/portugal/cities/cascais.html http://www.golisbon.com/portugal/cities/cascais.html]<br>or<br>[http://www.travel-in-portugal.com/Cascais/ http://www.travel-in-portugal.com/Cascais/]<br>'''Lisbon''' - Spreading out along the right bank of the Tagus, its downtown, the Baixa, is located in the 18th-century area around Rossio. East of the arcade Praça do Comércio, are the medieval quarters of Alfama and Mouraria, crowned by the magnificent St. George's Castle. To the west lie Bairro Alto and Madragoa, with their typical streets, and on the western extreme is Belém, with its Belém Tower, (the sentinel over the Tagus river that protects the entrance into Lisbon), the Jerónimos Monastery (masterpieces of Manueline architecture and classified in UNESCO's International Heritage list) and the Cultural Center of Belém.[http://www.portugalvirtual.pt/0/83.html <br>Museums:] Ancient Art, Chiado (Contemporary Art), Tile, Archaeology, Ethnology, Coach, Costume, Theater, Maritime, Military, City, Gulbenkian, Modern Art Center, and the Ricardo Espirito Santo Silva Foundation. Palaces open to the public: Ajuda and Fronteira. Churches: Cathedral (with Treasury); São Vicente de Fora; Conceição Velha (Manueline), São Roque and Sacred Art; Madre Deus; Santa Engrácia Pantheon (Baroque), and the Estrela Basilica.<br>[http://www.portugalvirtual.pt/0/60.html Shopping:] Downtown; Avenida de Roma, Praça de Londres, Avenida Guerra Junqueiro, and Amoreiras. <br>[http://www.portugalvirtual.pt/0/80.html Nightlife:] Bairro Alto and Avenida 24 de Julho.<br>[http://www.portugalvirtual.pt/tours/index.html Guided Tours]<br><br> |
− | <br> | + | <br> |
==== Sponsoring ==== | ==== Sponsoring ==== | ||
− | We will welcome a few sponsors of this very special event, typically | + | We will welcome a few sponsors of this very special event, typically organizations that participate in the summit. |
− | + | A number of opportunities to sponsor attendees are available: | |
+ | * For organizations that are sponsoring their employees attending the summit, logo promotion and links on the Summit Attendee page | ||
+ | * Organizations can sponsor an individual non-employee attendee for USD$2,000, with associated logo promotion and links on the Summit Attendee page | ||
+ | * Organizations can sponsor an entire villa (5 attendees) for USD$10,000, with associated logo promotion and links on the Summit Attendee page, promotional mentions, and on-site promotion and photo opportunities (such as banner advertising on the sponsored villa) | ||
− | + | Other sponsorship options are under discussion, and will be posted here soon. | |
+ | |||
+ | If you are interested in supporting the global summit, please contact Lorna.Alamri at owasp.org. | ||
+ | |||
+ | <br> | ||
+ | |||
+ | ==== Attending the Summit ==== | ||
+ | |||
+ | The summit is open to the OWASP community, and the members of the general Application Security community invited to participate and add to the summit working sessions. | ||
+ | |||
+ | Some leaders that are active within OWASP may qualify to have all or partial transportation and lodging paid for by OWASP.<br>To be considered for qualification, you must meet one or more of the following criteria: | ||
#Member of the OWASP Board | #Member of the OWASP Board | ||
Line 177: | Line 148: | ||
#Operational personnel that are necessary for the operation of the Summit | #Operational personnel that are necessary for the operation of the Summit | ||
− | ''' | + | '''The current OWASP sponsorship budget is $50,000 for the Summit.''' |
− | If you feel you might qualify, please contact Brad Causey or Jason Li. If you do not meet these criteria, and still feel that you should be sponsored, please contact {{Template:Contact | name = Brad Causey | email = bradcausey@owasp.org}} or {{Template:Contact | name = Jason Li | email = jason.li@owasp.org}} | + | If you feel you might qualify, please contact Brad Causey or Jason Li. If you do not meet these criteria, and still feel that you should be sponsored, please contact {{Template:Contact | name = Brad Causey | email = bradcausey@owasp.org}} or {{Template:Contact | name = Jason Li | email = jason.li@owasp.org}} or apply for [http://www.owasp.org/index.php/Summit_2011#tab=Applying_for_Chapter_or_Project_Sponsorship Chapter or Project Sponsorship]. |
+ | <br> | ||
+ | '''Please visit our [http://www.owasp.org/index.php/Summit_2011_Attendee Summit Attendee Page] to see who will be joining us in Portugal or to add your name to the list!''' <br><br>[[Image:12 3 2010 6 18 39 PM tmp52.jpg|600x166px]] | ||
− | <br> | + | <br> |
==== Applying for Chapter or Project Sponsorship ==== | ==== Applying for Chapter or Project Sponsorship ==== | ||
− | [https://docs.google.com/document/d/1TBj0BxBnzx8P7SegtEc8dSUNlQdLEZ5xXTbwfbdh6Bg/edit?hl=en&authkey=CNvixYEL Application for OWASP Chapter or Project Funding] <br> | + | [https://docs.google.com/document/d/1TBj0BxBnzx8P7SegtEc8dSUNlQdLEZ5xXTbwfbdh6Bg/edit?hl=en&authkey=CNvixYEL Application for OWASP Chapter or Project Funding] <br> |
+ | |||
+ | '''*DATES HAVE BEEN EXTENDED!!!''' | ||
− | + | '''Please submit forms - we will continue to process until mid-January.''' | |
− | + | <br>[[Image:WorkflowProcesstoApplyforChapterorProjectFunding.png|800x600px]] <br> | |
− | + | <br> | |
− | <br> | ||
==== Letters and Summit Materials ==== | ==== Letters and Summit Materials ==== | ||
Line 198: | Line 172: | ||
[[Media:OWASP_summit2011_DC_update.pdf|Summit 2011 Presentation for AppSec DC]] <br>[https://docs.google.com/document/d/1TBj0BxBnzx8P7SegtEc8dSUNlQdLEZ5xXTbwfbdh6Bg/edit?hl=en&authkey=CNvixYEL Application for OWASP Chapter or Project Funding] <br>[https://docs.google.com/document/d/1Q3it1KCIm3HKFhWUtQYdaYd-bTbw_5oLN_dwk9Sc-j0/edit?hl=en&authkey=COymwN4E Confirmed 2011 OWASP Global Summit Attendees]<br><br>[https://docs.google.com/document/d/1sDeYKk6HuJiQ-CvihS4r1QVs21W3LhtLYfPyyLBwtQc/edit?hl=en&authkey=CPXmjJkK Template Letter - 2011 Global Summit Basic Invitation] <br>[https://docs.google.com/document/d/1Hi2Rc6wsaDMVEEssKuWqpBZe0IxtR51dLEbNIYsQaR0/edit?hl=en&authkey=CJbSpfEI Template Letter - 2011 Global Summit University Outreach Invitation]<br>[https://docs.google.com/document/d/13H-iGoHeUrAC0Pdm9mkA40no1M71YwgMdNA1829rLs0/edit?hl=en&authkey=CMaG0pIK Template Letter - 2011 Global Summit Government Invitation]<br>[https://docs.google.com/document/d/1u0ydRKuDOlzoxM4pI9Gyka_Goh_RDz5rLlMcLohUtdU/edit?hl=en&authkey=CMOizEs Template Letter - 2011 Global Summit Request for Employer Funding and Sponsorship]<br>[https://docs.google.com/document/d/10mE4EcsfwNOl3X43fKaTMERU79X2z5jUxLvAKkrlgqQ/edit?hl=en&authkey=CN2x0qoN Template Letter - 2011 Global Summit Request for Employer Funding, Version 2]<br>[https://docs.google.com/document/d/1eozoXB7_17Y_G7wDpJ5PjiPT7Z8Byc0yBS956L6otqo/edit?hl=en&authkey=COmE6JkL Template Letter - 2011 Global Summit Request for Employer SUPPORT - no funding] | [[Media:OWASP_summit2011_DC_update.pdf|Summit 2011 Presentation for AppSec DC]] <br>[https://docs.google.com/document/d/1TBj0BxBnzx8P7SegtEc8dSUNlQdLEZ5xXTbwfbdh6Bg/edit?hl=en&authkey=CNvixYEL Application for OWASP Chapter or Project Funding] <br>[https://docs.google.com/document/d/1Q3it1KCIm3HKFhWUtQYdaYd-bTbw_5oLN_dwk9Sc-j0/edit?hl=en&authkey=COymwN4E Confirmed 2011 OWASP Global Summit Attendees]<br><br>[https://docs.google.com/document/d/1sDeYKk6HuJiQ-CvihS4r1QVs21W3LhtLYfPyyLBwtQc/edit?hl=en&authkey=CPXmjJkK Template Letter - 2011 Global Summit Basic Invitation] <br>[https://docs.google.com/document/d/1Hi2Rc6wsaDMVEEssKuWqpBZe0IxtR51dLEbNIYsQaR0/edit?hl=en&authkey=CJbSpfEI Template Letter - 2011 Global Summit University Outreach Invitation]<br>[https://docs.google.com/document/d/13H-iGoHeUrAC0Pdm9mkA40no1M71YwgMdNA1829rLs0/edit?hl=en&authkey=CMaG0pIK Template Letter - 2011 Global Summit Government Invitation]<br>[https://docs.google.com/document/d/1u0ydRKuDOlzoxM4pI9Gyka_Goh_RDz5rLlMcLohUtdU/edit?hl=en&authkey=CMOizEs Template Letter - 2011 Global Summit Request for Employer Funding and Sponsorship]<br>[https://docs.google.com/document/d/10mE4EcsfwNOl3X43fKaTMERU79X2z5jUxLvAKkrlgqQ/edit?hl=en&authkey=CN2x0qoN Template Letter - 2011 Global Summit Request for Employer Funding, Version 2]<br>[https://docs.google.com/document/d/1eozoXB7_17Y_G7wDpJ5PjiPT7Z8Byc0yBS956L6otqo/edit?hl=en&authkey=COmE6JkL Template Letter - 2011 Global Summit Request for Employer SUPPORT - no funding] | ||
− | <br> | + | <br> |
==== Working Sessions ==== | ==== Working Sessions ==== | ||
Line 204: | Line 178: | ||
{{:Summit_2011_Working_Sessions}} | {{:Summit_2011_Working_Sessions}} | ||
− | <br> | + | <br> |
==== Schedule and Tracks ==== | ==== Schedule and Tracks ==== | ||
Line 210: | Line 184: | ||
{{:Summit_2011_Schedule}} | {{:Summit_2011_Schedule}} | ||
− | <headertabs /> | + | <headertabs /> |
[[Category:Summit_2011]] | [[Category:Summit_2011]] |
Revision as of 21:01, 12 December 2010
Welcome
Dear OWASP Leaders and appsec community,
The Summit Activates *You*Whereas the OWASP AppSec conferences are great places to listen to interesting talks, go for training, and meet with OWASP people, the Global Summit is the place where we all sit down together and take the time to discuss and work out plans, projects and solutions for the appsec future. Examples of topics:
| |
Organizing CommitteeLorna Alamri, Brad Causey, Justin Clarke, Paulo Coimbra, Dinis Cruz, Martin Knobloch, Dave Wichers, John Wilander, and Jason Li. |
Who's Invited?As an OWASP leader you are automatically invited to the summit, but we also welcome leading experts from industry and academia. Together we can create a more secure web. Check the "How Do I Join?" tab above for more info. |
OWASP Around the World
OWASP is a fast growing global community. How should we support and manage this growth? During this session we'll look into issues of:
- Internationalization
- The global job board
- New OWASP chapters in parts of the world where we have not spread much yet
More Topics
You know how OWASP works - it's all up to you. Please edit this tab and enter topics we should cover during the Global Summit 2011! If you want you can add your name after each suggestion and we can work out the details with you.
- Discussion on Douglas Crockford's bold statement that we should stop HTML5 development, fix XSS, and then start over. Is he right? How is OWASP active in the HTML5 development? Check this webcast, jump to 20:50 to hear the XSS part. /John Wilander
- Better engagement/partnerships with the development community - Mark Bristow
- Ways to recognize participation in OWASP in a tangable way - Mark Bristow
- Foundation/Board/Committee Governance & Standardization - Mark Bristow
- OWASP Website
- Securing
- Re-Structuring
- Re-Design
- OWASP Branding
- Can/should OWASP push for fundamental change to flawed specs?
- OWASP Influence change - or - Is it enough to make/use bandages on poor specs?
- HTML spec - separate data and code
- HTTP - CSRF should be at a much lower level than the app layer
- OpenID - transparent login is a security issue
- SSL - long list of CAs, who delegate CAs <recurse> - trust? security?
- OWASP Influence change - or - Is it enough to make/use bandages on poor specs?
- [Your topic here]
How Do I Join? / Mailing list
As an OWASP leader you are automatically invited to the summit. Cost to attend the summit is $800 USD (shared accommodations) plus travel expenses. Please see "Applying for Chapter and Project Funding" and "Letters and Summit Materials" tabs for more information on finding funding help for expenses.
The first thing to do is to join the Summit 2011 mailing list.
On the mailing list you'll get first hand information on how to register, exact dates, updates to the agenda, funding for your trip etc.
If you are a leading appsec expert from industry or academia but not yet an OWASP leader you can just contact John.Wilander at owasp.org and we'll try to get you in.
Social Events
It goes without saying - the summit is all about meeting people. So there will be a constant mixture of workshops, dinners, beers and wine. We like to think of the summit as a very social event in itself.