The underlying desire with any technology is to push beyond its limits. In the 80s, we had the PC turbo button. In the 00s, everyone got all saas-y with software as a service. In the 2010s, we have the cloud (or as some of us know it, just someone else's computer). Jokes aside, leveraging the cloud allows teams to deliver content more rapidly compared to a local/on-prem solution. This sounds great until you remember nothing in life is free—cloud security is no exception. While this talk is technical, we will begin by discussing the benefits motivating a small startup's decision to transition from on-prem to the cloud along with the inherent risk. A wide range of factors were considered: hiring, platform selection, technology stack, user management. We will talk about Amazon Web Services (AWS), the moving parts of our cloud, and what was required to get a minimum viable product off the ground. We will share our own ProTips for going cloud first; by the end, hopefully you’ll walk away with a few cheat codes of your own, whether it’s getting a peek at going cloud first or a verification of your own cloud security best practices. Ask the EFF Andrew Crocker, Alexis Hancock, Sydney Li, India McKinney, Alex Moss, Kurt Opsahl, Cooper QuintinN/AN/AGet the latest information about how the law is racing to catch up with technological change from staffers at the Electronic Frontier Foundation, the nation's premiere digital civil liberties group fighting for freedom and privacy in the computer age. This session will include updates on current EFF issues such as surveillance online, encryption (and backdoors), and fighting efforts to use intellectual property claims to shut down free speech and halt innovation. The panel will also include a discussion on some exciting new technology projects, updates on cases and legislation affecting security research, and much more. Half the session will be given over to question-and-answer, so it's your chance to ask EFF questions about the law and technology issues that are important to you. Navigating Passwordless Authentication with FIDO2 & WebAuthn Jerrod ChongN/Ahttps://static.sched.com/hosted_files/bsidessf2019/10/BsidesSF%2019%20FIDO2_WebAuthn.pdfFor decades, passwords have been the common backbone (headache) of authentication and are well known to lack in security while being frustrating and difficult to use. As we continue to see daily data breaches, the reality of moving away from weak static credentials and killing the password is upon us. Join this session to learn how FIDO2 and WebAuthn open authentication standards, in conjunction with YubiKeys, are solving the elimination of passwords at scale. Hear how organizations like Microsoft have implemented these standards for a true passwordless experience and find out how your organization can follow suit. You'll gain a greater understanding of how to achieve a modern and flexible security architecture through the use of FIDO open standards and hardware authenticators. Keynote: Securing Online Identities with Simple, Secure, Open StandardsStina EhrensvardN/AN/AAs Volvo realized when developing the three-point seatbelt, security needs to be simple and work in a simple gesture, or users won’t adopt it. Volvo also knew that in order to scale to every car and user, their invention needed to be an open standard. Eventually, all countries made the seatbelt a legal requirement, and it has since then saved millions of lives.The future of strong online identities is following the same path and must be simple to use across all computers and mobile devices. Several years ago, the Swedish/American authentication innovator Yubico co-developed the open authentication standard U2F (Universal 2nd Factor), which was further developed by the open standards organization FIDO Alliance. Since deployed by Google staff and end users, U2F devices have significantly reduced fraud, support calls, and time to login compared to mobile software authentication. We are today moving beyond U2F with the evolution of FIDO2 - a new open standard which delivers upon removing the need for a username and long complicated passwords. Microsoft has already incorporated this standard to allow for passwordless login into Microsoft Accounts and we expect to see much more passwordless support for hardware security keys as we continue into 2019. Stina will explain the advantages presented by FIDO U2F and FIDO2 in comparison to one-time passwords (apps, SMS, tokens) and smart cards, how and why these technologies will continue to coexist in the coming future, and where they fit in the larger identity ecosystem.