--- title: "Jon McCoy — Hacker outreach" url: https://appsecpodcast.com/jon-mccoy-hacker-outreach/ date: 2019-05-06 duration_seconds: 1489 guests: ["Jon Mccoy"] topics: ["Security Culture", "Conferences and Community"] audio: https://www.buzzsprout.com/1730684/episodes/8122647-jon-mccoy-hacker-outreach.mp3 transcript: true --- # Jon McCoy — Hacker outreach *May 6, 2019 · 25 min* with [Jon Mccoy](https://appsecpodcast.com/guests/jon-mccoy/) on [Security Culture](https://appsecpodcast.com/topics/security-culture/), [Conferences and Community](https://appsecpodcast.com/topics/conferences-and-community/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122647-jon-mccoy-hacker-outreach.mp3) ## Show notes How can hackers and corporate security teams work together when each sees the other through a different set of assumptions? Jon McCoy explains hacker outreach as a way to connect people, share knowledge, and make security communities easier to enter. He describes DEF CON for newcomers, discusses its culture, and recalls a cautionary story about Robert’s connected wearable at the event. The conversation follows Jon’s journey into OWASP and his support for diversity initiatives, including Women in AppSec and conference scholarships. Chris asks how organizations can help and what a more welcoming community might look like. Jon’s message centers on practical generosity: introduce people, remove barriers, and help the next person find a place to contribute. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Jon Mccoy: → [Jon McCoy on GitHub](https://github.com/theJonMccoy) Mentioned in this episode: → [DEF CON](https://defcon.org/) → [OWASP Women in AppSec — project repository](https://github.com/OWASP/WIA) → [OWASP Foundation](https://owasp.org/) Chapters: 00:00 Hacker outreach with Jon McCoy 02:42 What hacker outreach means 05:12 Where outreach happens 06:11 Introducing DEF CON 07:42 What newcomers should expect 09:06 Robert’s connected-wearable cautionary tale 11:19 Jon’s journey from DEF CON to OWASP 13:05 Bringing hacker outreach into OWASP 15:18 Diversity initiatives and access to community 16:32 Women in AppSec 17:58 Conference diversity scholarships 18:31 How organizations can help 19:42 A more welcoming security community 23:05 Jon’s call to action ## Transcript *4,020 words · assemblyai* **0:00 Chris Romeo:** John McCoy is a security engineer, a developer, and a hacker, and a passionate OWASP advocate. Maybe even a hacker first. John has a passion to connect people and bring down barriers between hackers and corporate folks. John explains the idea of hacker outreach and breaks down what we can expect if we venture to the DEF CON event in Las Vegas. John also remembered a cautionary tale of Robert's Fitbit out at a DEF CON event. John is someone we can all learn from about giving back to our community. I wanna take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is first conversational. We don't do lectures. Instead, we let the experts talk about what's important in security. The modules are quick, 10 to 20 minutes in length. They're deep. We've got some of the best security minds in the industry working to provide this content. And last but not least, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. The Application Security Podcast. Here we go. Hey, folks. Welcome to this episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey, and I'm joined by my co-host, Robert Hurlbut. Robert, how's it going? **2:00 Robert Hurlbut:** Good. Yeah. Hi, this is Robert Hurlbut, Threat Modeling Architect, Application Security Architect, and definitely enthusiasm— I have all kinds of enthusiasm about application security. **2:11 Chris Romeo:** You forgot architect to the stars as well for your time you spend in Hollywood helping stars secure their web applications. **2:17 Robert Hurlbut:** There you go. **2:19 Chris Romeo:** Maybe not, but— and we're joined today by John McCoy, who— this is his second visit to the Application Security Podcast, and I know he's an avid listener as well as an idea person who brings us lots of ideas for additional shows. So, John, welcome back to the show. **2:35 Jon Mccoy:** Oh, thanks. It's nice to be back. And yeah, excited to talk to you guys. **2:42 Chris Romeo:** Yeah, we are definitely excited as well. And so the primary topic that we want to talk about today is this thing called hacker outreach. And so I'm realizing I really don't know what that means. I think I know what hacker means. I know what outreach means. I kind of think I know what it means if we put those 2 words together, but Why don't you start by defining that for us? As far as when you say hacker outreach, what does this mean? **3:05 Jon Mccoy:** Yeah, um, there's a community of white hats and a community of black hats. We have our own conferences, and it's, it's a little bit of the same community, but very separated, uh, uh, tools and training and norms between the two. And so there's kind of a divide where CEOs of a white hat company don't really try to attract hackers, and hackers don't really try to attract white hats to their teams. And so trying to show that we're all part of the same ecosystem and have the same concerns and bring the two together. **3:44 Chris Romeo:** So you're saying that then there's two different— there's almost two sides of the equation here, right? There's the kind of hardcore hacker side, And then there is the kind of CEO corporate folks maybe that are on the other side that have security people working for them. **4:01 Jon Mccoy:** Um, well, I guess you have an AppSec engineer like I am. I help defend applications and work with engineers to secure their infrastructure code design, the whole SDLC. And then you have a hacker on the other side, maybe a red team that comes in and blows it apart and finds vulnerabilities. But at the end of the day, we both use a scanner. We maybe both use ZAP, or we both rely on the same, same skill sets of knowing SQL injection and blind SQL injection. We rely on the same base patterns to do our work, just in different, different ways. Same, same coin, different side. **4:42 Chris Romeo:** So when you say hacker outreach, then that's— that is the AppSec engineer the application security person reaching out to the people that are kind of in that hacker category, the red teamers, penetration testers, security researchers, trying to bridge the divide then between these 2 groups. **4:59 Jon Mccoy:** Yeah. And both ways, opening that path for OWASP people to get in touch and integrate into the hacker community. Yeah. **5:08 Chris Romeo:** Okay. So we— **5:09 Jon Mccoy:** I think they have a lot to learn from each other. **5:12 Chris Romeo:** Yeah, I think we all— that's definitely something we always gotta keep in perspective, right? That we all have a lot to learn from each other. And that's one of the things I live my life by is that, you know, there's— I always say I can learn something from anybody. I don't care who they are or what their background is. They have something to teach me because it just makes me that much more aware of what I don't know, which is a lot of stuff. So, um, where do you, where do you do this type of— when you do hacker outreach, where is this? Are you going door to door in neighborhoods and just asking people, hey, are there any hackers in here that I can influence? **5:44 Jon Mccoy:** Or— **5:44 Chris Romeo:** You know, where are you doing this stuff? **5:45 Jon Mccoy:** Yeah, the hackers don't really respond too well when I show up on their doorstep. So we're doing a table at DEF CON, OWASP table in the vendor area. And so we do on-the-ground work with introducing OWASP, the community, our programs, such as like our projects, to the the wider hacker community. **6:11 Chris Romeo:** Yeah, let's, let's even move further back and say, what is a DEF CON? So like, I know what it is, Robert knows what it is, but not everybody that's listening. A lot of folks are coming from an AppSec or dev background. They may not know what a DEF CON is. So let's, let's start there. **6:24 Jon Mccoy:** Yeah, yeah, that's definitely part of hacker outreach. What is— so DEF CON is, I guess, to kind of sum it up quickly, it's kind of, to me, it's the Olympics of hacking. Like, if, if you're the best person at breaking TLS, SSL, you give a presentation at DEF CON and Black Hat too. But DEF CON is where, like, the, the, the top hackers in car hacking, in XYZ, go to, to present. DEF CON isn't exactly like AppSecUSA as a conference. It's, it's much more like a hacker festival. I think last year it was 27,000, 29,000 people. So it's, it's miles. It's, it's across multiple casinos, and it has an entire area dedicated just to car hacking or IoT. It's massive, and it's community organizing where if you're into doing injecting microcomputers into your body. There's an entire group that's into biohacking. And so, it's a community. It's definitely worth going to. Yeah. **7:42 Chris Romeo:** So, what do I— let's kind of flip the script around here and say, okay, I'm an application security person and I've never been to DEF CON before. What should I expect from this experience? Because I know in the media, everybody writes an article in July that says, hey, You know, what not to bring to hacker summer camp so you don't get compromised and everything else. And there's a lot of fear, uncertainty, and doubt about if I go here, I'm gonna have all my stuff compromised and hacked and all that type of stuff. So is that— is there truth to that? And what should I expect as somebody who's new to this community? **8:14 Jon Mccoy:** Oh, it's definitely true. I've been in speeches where they'll come in and say, hey, we're dropping an 0-day on Wi-Fi next door, so turn off your Wi-Fi, um, or you're liable to get attacked. Um, if you look at the cell towers, you have a few, I think, 100 cell towers that pop up around DEF CON. Hackers and nation-states spin up fake cell towers. Um, you have, uh, just about— I, I definitely recommend bringing a burner, uh, cell phone if, if you need to be secure and you don't want to come back with something. It's definitely worth it to get a burner cell phone and SIM card. SIM cards also store programs on them and can be infected. And Robert has a good story about, uh, securing your, your infrastructure at DEF CON. **9:06 Chris Romeo:** Robert, you got a story about infrastructure, huh? **9:09 Robert Hurlbut:** I do, I do. Actually, uh, this happened back in 2017. Uh, so I had heard all the— and I had been there before. This is my, I think, my second DEF CON. And I had heard all the stories about what you need to do in terms of bringing a burner phone, not turning on your phone, certainly not turning on Wi-Fi, Bluetooth, all those kinds of things. And so I was— I thought I was pretty safe. I kept my phone off, all that stuff. One thing I didn't think about was any of those devices that you use for fitness. And in particular, I had a Fitbit. And which, you know, always-on Bluetooth. And so John and I were actually in a lobby at the DEF CON. We were just talking and all of a sudden my Fitbit started beeping, giving all kinds of weird numbers and lights and all kinds of fun things there. And I go, what in the world's going on? And so I'm like, oh great, somebody's trying to compromise it, probably trying to pair with it and try to take it over if they could. Maybe they get close enough they can read numbers. I'm not sure what they were doing. All I know is that I took that back home, I put it on the shelf. I've never synced it again, ever again with anything. It still sits on the shelf. I bought a new one. But since then, I've actually talked about it, you know, tried to investigate how can I figure out what happened and all those kinds of things. But yeah, fun story, fun, interesting experience there, learning the hard way about DEF CON. **10:45 Chris Romeo:** Yeah, and it just says that, you know, even we as security professionals don't always make the right choice or the right decision. We have faults. We click on phishing emails once in a while. We do things that we kind of should— then you probably look back at that and you're like, ah, I should have known better, but— **11:02 Robert Hurlbut:** I should have known better. I thought about it. I thought about it, but no, it's not going to happen. And there it was. **11:08 Jon Mccoy:** Yeah, and that's a good side of DEF CON is you come there and get to see what is the bleeding edge. Like, what's paranoia and what can a 14-year-old do to you? Like, it's very visceral. **11:19 Chris Romeo:** Yeah. And so, John, you kind of came to the world of OWASP and AppSec through DEF CON, was kind of your first place that you landed, unlike a lot of our listeners who are going to be AppSec people who may not have even been to DEF CON, or if they have, it's in the context of AppSec. So, how did you actually originally get to DEF CON, and then how'd you get to OWASP as a transition through there? **11:45 Jon Mccoy:** Um, I, I originally was a developer and I stumbled into forensics and kind of turning my development tools and skills into building weapons, digital weapons to attack programs, make malware, crack software. And like, I was focused on C# and no one was then and very little now. Um, And I went, I did the speaking circuit. I did really well at DEF CON, dropped a bunch of demos on stage, free tools, bleeding-edge attacks, integrated C# and hybrid malware containing Metasploit payloads and bridging the gap between C++ and Java and C# malware and assembly code malware and kind of packaging up some nice tools and then going around the hacker circuit speaking on it, demonstrating it, giving it out for free. And did that for a couple of years and just happened to stumble into OWASP. Every now and then I would try different conferences and forensics conferences, business technology conferences, and some white hat conferences, and OWASP just happened to, to be there and turned out to be incredibly friendly, and I just fell in love with the community and have been in OWASP for 10+ years. I don't even know anymore. **13:05 Chris Romeo:** So then what, when you think about kind of hacker outreach into the OWASP world, what does that look like as you look at OWASP? **13:14 Jon Mccoy:** I guess as I look at OWASP, I see some of the same technology being developed. Like we have ATT&CK trees and hackers have kill chains. We have ZAP that we produce on OWASP side that's used very heavily on the pentester Black Hat side. And I also, just as a quick pitch, I'm seeing some things in the hacker side like LangSec that is gaining traction and basically shows you how to understand the structure of a security control to understand its potential weaknesses from its construct. And LangSec is taking off because you can basically predict where vulnerabilities will happen. **14:01 Robert Hurlbut:** Hmm. **14:01 Jon Mccoy:** And on the white hat side, that's still in our future. And so, like, we're facing the same challenges and we're creating tools to solve these challenges. And ironically, it works on the other side incredibly well. **14:13 Chris Romeo:** So yeah, LangSec. I'm just curious what— give us a couple sentences if you can about that for those people who might not have heard of LangSec. **14:21 Jon Mccoy:** It's linguistic security, kind of driving all the way back to like Noam Chomsky. There's conferences on LangSec. An example of a LangSec evaluation of security is on XML. XML gives you the ability to do recursion and stateful passing between your, your recursions, which gives you Turing completeness. And from Turing completeness, you can launch all these clever hacks and attacks and payloads, while JSON doesn't allow you to do recursion. And so you can't do the, the stateful creation of a Turing-complete system, and so JSON isn't vulnerable to these fundamental attacks. By taking out that Turing-completeness, you remove an entire class of attack. It's more about not vulnerabilities, but weaknesses or conceptual weaknesses that you can drive into your security controls. **15:18 Chris Romeo:** Diversity initiatives, I know, is something that you've been very passionate about over the last number of years and so I wanted to explore that and understand, first of all, when we say diversity initiatives, what are we talking about? But then I'm curious as to why you're passionate about this particular topic. **15:36 Jon Mccoy:** Yeah, uh, right now we're spinning up a DEF CON table for OWASP to do hacker outreach, and this is a diversity-focused table to encourage the hacker community to see and check out OWASP and kind of plant a flag out there to say that we're friendly and open to the hacker community and provide an on-ramp to support people coming to OWASP for the first time. And as well as if you come to DEF CON, there's an OWASP group there that you can connect with and can help you. And so if you come to DEF CON for the first time, there's an OWASP table with OWASP people that can help you, uh, not get phished, or, or give you a context for how to navigate DEF CON, or partner you up with another senior or newbie buddy, uh, at DEF CON. And so it's, it's bidirectional. **16:32 Chris Romeo:** I know you've done some stuff with kind of women in AppSec and helping to promote that. How does Women in AppSec for OWASP as a, as an organization, how does that fit within this idea of diversity initiatives? **16:46 Jon Mccoy:** Yeah, there's Project OWASP WIA, Women in AppSec, and run by Vandy and Zoe and some really awesome women in OWASP, and it's focused on building training and support and infrastructure and a project to encourage women in OWASP AppSec. And as the diversity table is at DEF CON and pro that, we're working on how, how can the table at DEF CON help do outreach to companies to find diversity sponsors, or how can we do on-the-ground support at DEF CON or AppSecUSA to, to provide support for new people. For example, at AppSecUSA, We did diversity scholarships, 35+, and then there was enough momentum to do hands-on training classes and supported lunch talks for your first time in OWASP and diversity in OWASP and kind of being able to build a foothold community for new people coming en masse to OWASP. **17:58 Chris Romeo:** So the diversity scholarships there for AppSecUSA, did that— was that kind of in association with Women in AppSec? **18:05 Jon Mccoy:** That was for Women in AppSec. I supported it and, uh, helped drive it forward as much as I could. But at the end of the day, I'm, I'm a supporter for them to help empower them to achieve whatever they want. **18:17 Chris Romeo:** And there were a couple of companies that were big, that were big in supporting that as well, right? **18:21 Jon Mccoy:** I think it was Uber and Salesforce were the major supporters of it. And this year we have a lot more that we're excited to try and bring on board. **18:31 Robert Hurlbut:** Yeah. **18:31 Chris Romeo:** I think we should call them out. I mean, I think that's a good thing to be supporting the community in such a way and helping. You know, we all know we need more people in cybersecurity in general, application security very much so. And this is great that these types of efforts are underway. And so, I guess you talked about, you know, more people coming on board this year to be a part of this. How do our listeners get involved in— let's say somebody's out there and they're thinking, oh, I'd like my company to sponsor a diversity scholarship for AppSecUSA or one of the other conferences, how do they get connected? Who should they be talking to to make that— the fact that they want to do that known? **19:09 Jon Mccoy:** Yeah, there's OWASP WIA. It's an official project on Twitter, OWASP WIA, W-I-A, and reach out and And there is movement to get diversity at, uh, AppSec Cali, uh, did it. A lot of the conferences are starting to spin it up. So even regional conferences can take advantage of diversity scholarships or on-the-ground diversity support infrastructure from, uh, WIA. **19:42 Chris Romeo:** Okay. And then what, I mean, what do you see as the future of this? I mean, there's, what's, what are the kind of the next steps that we should be thinking about as far as helping to— and I'll bring this back around for hacker outreach and diversity initiatives together. What are some of the things that you're thinking about, like, in the next 5 years? In 5 years from now, I'd like to see this, or, you know, kind of like, what, what are the things that you think— what should we be striving towards? What's our goal? And then ultimately, how do we, how do we get closer to that goal? **20:14 Jon Mccoy:** I certainly hope to see a nice cross-pollination between DEF CON and OWASP and the hacker community. It's not just DEF CON. And kind of energizing the new blood that's coming into OWASP instead of waiting for people that got their CISSP to join OWASP. It's also doing outreach to people that just got their first capture the flag win at a prestigious conference and they're joining OWASP. Some of the nice-to-haves, we're doing really cool swag at DEF CON and you can get an OWASP shirt. We're working on doing on-the-ground projects at DEF CON for OWASP, so there'll hopefully be a party or some sort of event where you can come and meet other people from OWASP that attend DEF CON and build a little bit of a community initiative on the ground there. And the same with having more diversity inside of dev and inside of AppSec USA and OWASP. So there's been— I've seen a few of my friends come to OWASP and not quite click with the community and do some things that would be hacker normal, like hacking the hotel Wi-Fi. They experienced what happens in OWASP if you attack the hotel, and it didn't go well. And so, um, kind of hoping to also grow a little bit of a community foothold inside of OWASP to integrate hackers. And like if they have requests for ZAP to start building that channel that hackers know they can come and request open source development because that's not really something on the hacker side. There isn't really a support network for building open source projects. **21:57 Robert Hurlbut:** Yeah. **21:57 Jon Mccoy:** And that's something that we have that is fairly unique. **22:01 Chris Romeo:** Yeah, so I guess if we were to flash forward 5 years, then sounds like if I kind of summarize what I took away there, you would see, or in your best case, there would be a lot more integration between the hacker community and OWASP such that there's a lot of crossover, cross-pollination between those communities. They're not 2 separate things, but there's people involved on both sides that are kind of, you know, whether it's at DEF CON, whether it's at AppSecUSA or other AppSec events, There's just more integration and more conversation and working together and stuff that's happening. **22:36 Jon Mccoy:** Oh yeah. And, and kind of on a personal note, like I was in DEF CON and I thought it was writing 0-days and it was creating next-generation AV bypasses that made money. And then after coming into OWASP, I found that there's, there's a lot of money to be made on the white hat side. And so kind of just propping that door open for other highly skilled engineers to, to cross over. **23:04 Robert Hurlbut:** Yeah. **23:05 Chris Romeo:** So coming into kind of the end of our conversation here, John, what would you provide as like a kind of last-minute thoughts or a kind of a summary call to action coming out of this conversation? **23:16 Jon Mccoy:** OWASP WIA is looking for scholarship sponsors, both to AppSecUSA to regional conferences, SnowFROG, AppSec Cali, LASKON. And if we can start kind of creating the cultural norm in OWASP that there's both a landing pad for people to come in for the first time, maybe it's someone's kid that they didn't think would fit into OWASP, there's a group that will kind of help and foster them and maybe even help them get over some of the first hurdles for integrating into the community. picking up hands-on pen testing or getting the tools. **23:54 Chris Romeo:** Very cool. And so, uh, I mean, just, you know, we're all passionate about this idea of women in AppSec and diversity and how we can get more folks involved. And so, John, thank you for the things you're doing as far as hacker outreach and being somebody who's just passionate about getting more people involved across the board. We certainly need that in our community. We need more perspectives. So we thank you for work there, and thanks for coming back on the podcast. And hey, until the third time you visit the podcast, which will be sometime in the future. **24:23 Robert Hurlbut:** Thanks. **24:25 Jon Mccoy:** Keep up the awesome podcast. Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/jon-mccoy-hacker-outreach/