For some, the path to infosec starts in a lecture hall-- for Rachel it started in a glass booth hacking live in front of 400 people. Join Rachel as she walks through her nonlinear path to infosec from her background in neuroscience to the rat lab, through teaching to UX research, through live hacking to starting her own company in the field. You’ll hear tales from the glass booth, lessons she learned along the way, and insights from other non-traditional journeys to information security. How to Build an Application Security Program Jerry GamblinN/Ahttps://static.sched.com/hosted_files/bsidessf2019/c2/HowToBuildAnApplicationProgram.pdfDo you need to start or revamp your application security program?I have spent the majority of my 20-year career helping government agencies, public companies and now a startup build out application security programs. In this discussion, I will talk about what has worked for me, what has not worked and things you should absolutely *never* do. Lyft Cartography: Automating Security Visibility and Democratization Sacha FaustN/AN/ALyft Security Intelligence team mission is to "Empower the company to make informed and automated security decisions." To achieve our mission, we invested in our cartography capabilities that aim at keeping track of our assets but most importantly, the relationship and interaction between them.The talk provides insight on an intelligence service solution implemented by Lyft Security Intelligence team to tackle knowledge consolidation and improve decision making. Attendees of this session will be introduced to the platform we implemented along with a broad set of scenarios that allow us to burndown security debt, detect assumptions drift, and enable teams to explore their service and environment. Furthermore, Lyft will release the platform to the open source community as part of the conference and provide details on how it can be extended to adapt to each need. Self Care for Security Professionals Caroline WongN/AN/AA career in security is part of a larger phenomenon called life. The work we do can be so all-encompassing that it can be easy to forget to take care of one's body and one's spirit.In my career I've traveled the world to speak at security conferences, published a popular textbook, and written the security policies that enabled a company to go public. On the outside it usually looks pretty sunny, but on the inside it's been a mixed bag.Life happens, and so does anxiety, depression, burn-out, alcoholism, marriage, divorce, medication, therapy, pregnancy, birth, death, etc.In this session, I'll talk about the strategies I've tried and the various successes (and failures) I've had with managing my mental health. I hope that by sharing my story I can offer empathy and advice to others who may be struggling beneath the surface. Conquer the Enterprise from Inside with Penetration Testing Dropboxes Simon Roses FemerlingN/AN/APenetration Testing Dropboxes are dismissed by many clients and infosec pros because they require internal access to corporate network. The reality is that dropboxes are a very valuable tool because they can lower costs and gain efficiency testing. Penetration Testing Dropboxes fit perfectly with the Assume Breach approach; as pentesters can launch internal attacks to simulate an attacker with access to the network to uncover gaps in the corporate security posture from the start of the engagement, both red teams and blue teams win. This talk focuses on the different types of dropboxes, hardware additions, how to set up, and what attacks can be executed. Demos included. Cats? In My Certificate Transparency Logs? It's More Likely Than You Think Scott Behren & Ian HakenN/Ahttps://static.sched.com/hosted_files/bsidessf2019/88/Catlog_BSidesSF_2019.pdfCertificate Transparency (CT) logs are a new and incredibly useful tool for bringing auditability and accountability to the public web certificate ecosystem. CT logs aim to provide a verifiable, append-only history of all publicly trusted certificates on the web. With browsers like Chrome now enforcing that certificates belong to CT logs, CT logging has become a vital part of the web's ecosystem.But as with any new technology, it's our hacker duty to ask the question "How can this be misused?" We'll be providing a deep-dive into what CT logs are, how they work, and how we can take advantage of them for novel and nefarious purposes. We'll also explore if any bad actors have exploited our use cases in the wild. Most importantly, we'll be showing you why CT logs are the best new place to find pictures of cats on the internet.