Erez Yalon and Liora Herman – The Application Security Village @ DefCon
With Erez Yalon and Liora Herman
What would an application security conference look like inside DEF CON? Erez Yalon and Liora Herman explain how a volunteer idea became the Application Security Village, a dedicated space for talks, workshops, demonstrations, and community at one of security’s largest gatherings.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 9 chapters
- 00:00Creating an Application Security VillageAudio
- 02:16How Erez and Liora joined forcesAudio
- 05:51Building a volunteer-driven eventAudio
- 08:42Villages as conferences within DEF CONAudio
- 10:48Getting support from DEF CONAudio
- 13:27Designing content for the AppSec communityAudio
- 16:03Workshops and hands-on topicsAudio
- 18:42Where to find updates and participateAudio
- 21:49A village for newcomers and expertsAudio
About this episode
What would an application security conference look like inside DEF CON? Erez Yalon and Liora Herman explain how a volunteer idea became the Application Security Village, a dedicated space for talks, workshops, demonstrations, and community at one of security’s largest gatherings. They describe the gap they saw between traditional DEF CON villages and the needs of AppSec practitioners, then discuss winning support, recruiting volunteers, and designing content for both newcomers and experienced professionals. The conversation covers workshops, project showcases, and the practical challenges of building an inclusive event from scratch. Erez and Liora close by inviting listeners to participate, contribute, and use the village as a place to learn directly from the people creating application security tools and practices.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Erez Yalon and Liora Herman:
→ Erez Yalon on LinkedIn
→ Liora Herman on LinkedIn
→ Application Security Village
Resources
→ Application Security Village
→ DEF CON
→ OWASP Foundation
Actionable
From this conversation
- 2:44
Tell the application-security story
I happened to land in application security and discovered one of my superpowers is helping to tell the application security story.
- 3:27
Include every role in AppSec
We truly believe it's something that we need everybody involved in whatever role that they are inside of a given company.
- 3:52
Build AppSec teams around diverse skills
In these computer things I described, I did software and security, but I did not know that I'm doing security.
Transcript · 23 min conversation
0:00Chris RomeoErez Yalon and Liora Herman are both passionate security professionals, and they both come to security from different angles. They've joined forces along with a number of other folks in creating the AppSec Village. So, the AppSec Village is an event that's gonna be happening at DEF CON this summer in Las Vegas in just a few weeks. And So, we want to encourage all of our listeners to get out to the AppSec Village if you're in Las Vegas for Black Hat DEF CON. Get out to the AppSec Village, check it out. There's going to be a bunch of speakers. We talk all about that in this episode.
0:38And make sure you stop by the village and say hi to Robert, who's going to be there as well. Hope you enjoy.
0:43Chris RomeoI want to take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is conversational, quick, hands-on, and fun. We don't do lectures. Instead, we let the experts talk about what's important. The modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo, the application security podcast.
1:39Here we go. Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, co-host of the podcast as well as CEO of Security Journey, and we are here today to talk about something that's brand new this year at DEF CON, something that's called the AppSec Village.
2:16Chris RomeoBut before— Woo-hoo!
2:16Yeah, a lot of, a lot of happy sounds there, which is great. But before we get there, I want you to have a chance to hear about the background of our 2 guests today.
2:27Chris RomeoAnd so, Uh, Liora and Erez are both here representing the AppSec Village.
2:32And so Liora, I wanna start with you and ask, could you tell us your security origin story? If there was a comic book about how you got into security, what would episode 1 of that comic book look like?
2:44Episode 1 would probably be me in an airplane. flying from little Georgia all the way to Israel to start a whole new life in the world of high-tech marketing. And I just happened to land in application security and discovered maybe one of my superpowers is helping to tell the application security story. So I've sort of brought my marketing superpowers to the world of application security. Along the way, I met Ares. And he sort of convinced me to go on this crazy journey of building a village with him.
3:27That is, that's awesome. And we love to hear that, you know, somebody who's coming from the world of marketing is so passionate about application security because we truly believe it's something that we need everybody involved in whatever role that they are inside of a given company. So definitely great to hear that. So, Erez, I understand you are a listener of the podcast, and so you know this question that's coming up for you, but what's your security origin story?
3:52Yeah, actually I'm a big fan, but I made the mistake of not preparing. So I will— my story is not very traditional. If you need me in a comic strip, I would probably be the crazy scientist. I was into what I called computers and nothing else since childhood. Now I'm in my 40s, just to give proportions. In these computer things I described, I did software and security, but I did not know that I'm doing security. This knowledge of what I'm doing was only introduced to me later. Again, my path was really not traditional. I actually chose to start by doing a degree in biology and continuing all the way to study veterinary medicine. But computers and security and software was always there in the background, sometimes as a hobby, sometimes as a job. And eventually I could not resist and I came back to becoming a developer. After several years as a developer, I chose to take the path again towards security, then I already knew that AppSec is my, probably my destiny. I think I realized that I'm a better breaker than builder, like many, many other of us. And since then I was working in Checkmarx, an AppSec security software company, and which at the moment I'm running 3 different teams. Amazing people, bounty hunters, AppSec researchers, pentesters, developers. We're having the fun of our lives.
5:51Yeah, isn't it? It's fun to do something like this when I always tell people like, you know, I think I would do this stuff even if they didn't pay me because we're just having a lot of fun what we're doing. It sounds like you're in the same boat. Now, tell folks, where are you in the world right now?
6:08Okay, so right now actually I'm in Tanzania, East Africa, with my kids. Just what we call doing a proportions adventure, just to see how most of the world actually looks like out of our convenient bubble. I think it's very sobering and important for everyone to see. What's happening in the other part of the world.
6:36Yeah, I totally agree with you. And I have done the same with my family, gone to other places in the world just to see that, hey, you know, people don't always live like where we're from. And kind of makes me think of an interesting, I guess, anecdote in the world of AppSec in that if you're a security person, you should get out of your kind of bubble and get into the developer's mindset a little bit, go spend some time sitting next to them and watching what they do. But that's a whole other episode right there. So, all right, so we're here to talk about, first of all, we're here to talk about DEF CON and this whole idea of villages. And so, Ares, what's your background with DEF CON? Have you been going there for a long time? Is this something that's brand new to you or what's your kind of perspective on DEF CON?
7:24So DEF CON, no, it's not new. It's something that I've been visiting for several years. Um, I think that DEF CON and the, the OWASP, uh, conventions, conferences are those I, I usually try to go to, um, with very different mindsets. Um, DEF CON is very hacker-oriented while the OWASP conferences are sometimes more builder and defender oriented. I think that they kind of complete each other in a weird way. Well, I don't really know the actual reason or when did villages started. Maybe we should look at the history books. But I think that when DEF CON became very, very large and there was a need to give a better way better infrastructures of, um, like-minded geeks to meet their own. So I think that each village gives this opportunity, you know, like-minded geeks, as I said, to meet each other in a specific theme of a village.
8:42Yeah, and so a lot of people don't even realize that DEF CON has become such a large conference And the villages actually represent almost mini conferences with their own speaking tracks, with their own hands-on experimentation sessions. And, uh, there's almost— DEF CON is almost a conference of hundreds of other conferences. I know like the Wall of Sheep has, or the Packet Hacking Village and stuff like that, has become their own kind of experience over the last number of years. And so, um, I think it's exciting to hear that AppSec is, is finally taking a place in— at DEF CON. And so, Liora, I guess the question for you is, how did this AppSec Village thing even become a thing?
9:30Well, AppSec Village has been a dream of Eris's for many years, especially because he's spoken at different villages. I believe last year he spoke at the IoT Village, and he's been attending for years, and it's a different perspective on application security. And he felt that there was this piece missing, something for the community, something on application security, because you have, um, the people involved in application security are breakers or defenders, they're, you know, builders, white hat, black hat. It's such a mishmash of people that it really sort of spoke to the, the def— the heart of DEF CON of bringing people together to learn something. that Eris came to me and says— said he wanted to do a village. And I said, okay, um, how? Um, so we started to look into it, um, more than half a year ago, and slowly, slowly we gained momentum.
10:33How hard was it to actually get a village approved through DEF CON, and, uh, what were some of the things that you had to do to even get this village to become a reality for this year?
10:48I'm not sure the, the difficult part was the, the buy-in from DEF CON. I think DEF CON is a very open-minded and inclusive place, that they want to sort of provide a platform, um, for exploration and diversity. I think that the part that has been most challenging for us is, for none of us is this a paid position. Yeah, we're all doing this voluntarily. you know, out of the goodness of our hearts. We're going hardcore needing sponsors to help pay for things. Um, but, you know, we all work in high-tech or in security. We're working those long weeks, and then the couple hours of free time we have on the weekends or in the evenings, we're spending trying to build this amazing village. Um, and so it's, it's really out of the, the energy and passion that people have for AppSec, for— that the leadership team has for AppSec that is sort of bringing this village to life, but it's definitely a community-based initiative.
11:51Yeah, I always try to thank volunteers at various conferences because I know what goes into it, and a lot of people don't really have that perspective behind the scenes, but I've done these type of events before, and I know how much effort, Liora and Erez, you're putting into this whole thing, and it's It's— and, uh, you know, so we certainly thank you. I guess I can speak on behalf of the industry, but, you know, so we certainly here at the podcast, we certainly thank you for just putting that effort in to be a part of that because we know a lot of times it's a huge sacrifice and then people only look at and say, hey, what went wrong at this event or something? They don't hardly ever say, hey, this, this was really awesome. So, um, we certainly, uh, definitely thank you for going through this, this step. dates for this? Is this AppSec Village, is this thing open the whole time DEF CON's open, or what should our listeners that are going to be out around Vegas, what should, what should they be putting on their schedule here about when the AppSec Village is running?
12:48First of all, I think it's a good time to give a shout out, um, to the other 3 members of our leadership. It's Bola Ejiawolen, Nick Osemor, and Joe Christian, 3 amazing guys pushing forward this initiative. We could probably not do that without them. The village is going to take place between the 9th and 11th of August, the 3 days of DEF CON, from morning to afternoon, like many other villages in DEF CON.
13:27Okay.
13:29The plan is not just to have an extra track of talks, but also have some more interesting AppSec activities to draw the hardcore AppSec people to the village. We're going to have some interesting workshops. We have keynotes. Uh, Liora, we can already say the names, right, of the Keynote speakers?
13:55Yes, yes. Can you insert a drum roll here?
13:59Yeah, I saw them on Twitter already, so I was gonna say, I think you can say it.
14:03Definitely.
14:05Okay, so yeah, so it's going to be Jim and Tania, Jim Enico and Tania. I think all of the listeners— yeah, I think all the listeners of the podcast know them. These are the faces when I close my eyes and think UpTech, these are the faces that I see.
14:27They have combined for a total of 6 episodes of— not together, but in different capacities. They have been featured 6 times in 6 different episodes. So yeah, our audience knows them well, and that should be a driver for our audience to get out, and if they're at DEF CON, and be a part of these events just to see Tanya and Jim speak in, in person. And I've seen both of them speak in different venues, and they're both a lot of fun and definitely worth getting there to be a part of that live.
14:57Not only speaking, but they're bringing something new to the Village. They're— they have 2 brand new talks that they've not presented in this sort of same capacity that you've maybe seen at OWASP or other conferences. This is something that they're doing specifically tailored for an AppSec Village at DEF CON?
15:18So other than them, we have some more really good speakers that we cannot, cannot announce yet. I think it will be in the next couple of days. We're going to have some workshops, very good workshops that in other places people would probably pay good money to get, but they're going to get it in the AppSec Village. Also, we're working on a challenge in the kind of CTF. It's very AppSec-focused. And in general, have a place for networking, for talking, for roundtables of ask me any AppSec question you have, and many other things.
16:03That's great. So from the kind of from the workshop perspective, what are some of the topics that are going to be available there on the workshop level?
16:11So at this point, we're not really ready to reveal all. We still have some— we don't want to have any spoilers out there quite yet. But we are planning to have workshops throughout the village, not just on one day, but sort of every day to break it up so that there's more interaction between members of the community and not just a frontal presentation.
16:34Is there going to be a, like, a kind of Is there a vendor area in the AppSec Village as well for the sponsors?
16:41Depending on the sponsor level, there will be some sort of sponsor presence, but we wanted to keep it minimal because this is more about the village itself and getting people involved in the village and exposed to the village. There is, you know, great opportunities for brand recognition and brand awareness. and I'm using marketing words, so I apologize, um, but to get your brand in front of members of the community. But we wanted to keep with the spirit of DEF CON and not have like an expo of exhibitors. That's, that's not what the AppSec Village or DEF CON villages are about. It's more about the, the community and the talks and the exchange of ideas.
17:26So if I'm somebody who's relatively new to AppSec, and I'm just, I'm gonna be at DEF CON. What advice would you give to me as far as what am I gonna get out of the AppSec Village?
17:38So first of all, I think you're going to realize that there are many professional people out there like you in terms of enthusiasm, in terms of understanding that AppSec is a very, very important part of security. And well, Jim hates when I say it, but sometimes AppSec is not considered very, you know, very sexy or very interesting because you cannot see the packets flying through the air and no LEDs are blinking. Nothing is disconnected at the root or something, but— AppSec is amazing. AppSec is everything, and it's everywhere that you find software, you find AppSec, and software is everywhere, and everyone knows that. So I think this is the important message here, to see the actual value and importance of AppSec.
18:42Where would, where would someone go for updates about the Application Security Village? Would it be— is Twitter the best place for that, or is there a website somewhere where I can—
18:52We've got a website, AppSecVillage.com, that we are keeping up to date. We've also got a pretty active Twitter handle. If you search for AppSec, I think it's AppSec_Village. Pretty active on Twitter, building up our LinkedIn presence. I'm the wrong generation for Instagram, so we're not doing Instagram. But I think that the website and Twitter are the main places. And, you know, we are a community initiative, so, you know, there's a lot of questions and ideas and suggestions that are coming out from the community that we're definitely incorporating into the plan.
19:34So is there a need for volunteers at this point, or are you fully staffed up for the event?
19:40We would love to have more volunteers. There's actually a volunteer section of our website, again, appsecvillage.com. If you'd like to volunteer, just fill out the form there and BJ, who is handling our volunteer initiative, will get in touch with you regarding our needs. There's also a need for sponsorship as this is a community-led initiative. Being able to pay for the recording of talks and the, the swag that everyone loves and the AV systems that we need. It all needs to come from somewhere and unfortunately, we are not independently wealthy and I emphasize yet there. But if you know someone who's interested in becoming a superfan, they can do that for $150 and we give them tons of shoutouts and love on Twitter or there's sponsor packages that's also on our website.
20:38Yeah, and I was just perusing the website here while we were talking which kind of helped me to see the volunteer. I love the idea of the superfan thing too. I think that's really cool. as a way to support. And I happened to see the kind of description of Jim and Tanya's talk, which definitely sounds very interesting. Tanya is going to talk about Purple is the New Black: Modern Approaches to Application Security on day 2, which is August 10th. And then Jim's going to talk about the Abridged History of AppSec on day 1, August 9th. So that sounds definitely very exciting. 2 great talks. Sounds like you got a lot of really cool things happening here. And I love the fact that you're promoting application security in this world. We know that, you know, the OWASP folks have some tie-ins to DEF CON and have been trying to build momentum in the last number of years and having tables and things, but this has really taken it to the next level. Super exciting to introduce all these breakers that are hanging around DEF CON to this whole world of AppSec. And so, I guess to leave our listeners with kind of one last thought, Liora, what would your kind of last— thought or your, your key takeaway be here?
21:49Even if you're an AppSec noob or, you know, you eat, breathe, um, and live AppSec on a daily basis, uh, come by the Village. There's something for everyone and we'd love to see you.
22:02Hey, Rez, what about, uh, what about your kind of last word?
22:05Well, I would probably say that no matter what color you are— white, black, red, purple or blue, please come say hi.
22:15Purple, purple.
22:18Chris RomeoThanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Born and TJ, and our outro music is Southern Delight by Stefan Cartenberg. You'll find the show on Twitter @appsecpodcast or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @roberthurlbut. Remember, security is a journey, not a destination.
3,421 words · transcript by assemblyai
More on Conferences and Community
View all episodes →- November 29, 2016 · 27 minChris Romeo -- Security Community at Any Scale
- March 9, 2023 · 38 minJames Mckee -- Developer Security
- June 1, 2019 · 29 minBjörn Kimminich — The new JuiceShop, GSOC, and Open Security Summit