Code Monkey home page Code Monkey logo

my-talks's Introduction

This repo is where I keep a list of my tech talks about application security, women in tech and related topics.

My name is Julia. I'm from Ukraine πŸ‡ΊπŸ‡¦ Nice to meet you! πŸ‘‹

I'm a Lead Security Engineer at Cossack Labs, building convenient and affordable data security and encryption solutions. My main personal specialization is mobile application security and Secure SDLC, as I have a solid background in mobile application development. Together with my team I like to build secure stuff, not to break it πŸ˜„ I hold an SSCP certification.

Take a look at case studies for projects I worked on:

⭐ Product security for one of the biggest African banks

⭐ Xumm wallet security assurance and improvements

⭐ Building ironclad data security for M&A solution leader

⭐ Cryptographic IP protection for AI/ML product

⭐ Crypto wallet security assessment for Temple Wallet

I'm passionate about local tech communities. πŸ‘©πŸΌβ€πŸ’» I'm a Director at Women Who Code Kyiv, a Leader of the OWASP Zhytomyr Chapter, and a contributor to OWASP MAS.


Flutter mobile application security

TBD in 2024

Related article: Flutter application security considerations


Crypto Wallets Security. For developers

The main ideas I've covered in my talk are:

  • Crypto wallets security is not only about the blockchain, it is also about regular application security;
  • Bypassing application-level security controls can be much easier than breaking cryptography;
  • Application developers are not experts in cryptography, they usuallyy need assistance;
  • Web3 enthusiast may not have deep knowlendge of security controls of the platform they are working on, e.g. web or mobile.

Slides: Crypto Wallets Security. For developers

Related article: Crypto wallets security as seen by security engineers

Presented at:

React Native Security. Addresing Typical Mistakes

In my talk, I shed light on:

  • The new risks React Native platform brings, comparing to native applications;
  • The security challenges it adds for developers and the potential vulnerabilities they should be aware of;
  • Time management issues when dealing with dependencies.

Slides: React Native Security. Addresing Typical Mistakes

Related article: React Native Security: Thing to Keep in Mind

Video: Youtube (in Ukrainian)

Presented at:


The Art of Secure Architecture

Alternative title: "Why can't developers make it secure?"

In this talk I raise the following questions:

  • The difference between secure coding and secure architecture;
  • The importance of communication, ownership and shared responsibility;
  • SSDLC and secure architecture lifecycle.

Slides: The Art of Secure Architecture

Slides: Why can't developers make it secure?

Video: Why can't developers make it secure? (in English)

Presented at:


Secure Authentication. Are you sure you do it right?

Alternative titles: "Making authentication more secure", "When authentication goes wrong"

It is a talk created for the audience of mobile application developers where I show

  • Guides and standards commonly used to assess security level of the mobile apps;
  • Common mobile app authentication vulnerabilities and how to find and fix them;
  • Local authentication best practices with examples.

Slides: Secure Authentication. Are you sure you do it right?

Video: Vimeo (in English) Youtube (in Russian)

Presented at:

  • NSSpain - 19 November 2020
  • WTM Lviv / CocoaHeads Lviv local meetup - 29 September 2019
  • CocoaHeads Kyiv CocoaFriday local meetup - 10 May 2019

Discussions Formats

DOU Interview "Who is Security Specialist?"

It was a short interview under their "X questions" format where I was answering general questions about working in cybersecurity. For example, who is security engineer, what are pros and cons of profession in cybersecurity, are security certifications worth it, etc.

Video (in Ukrainian) - 28 April 2023

Cybersecurity career roundtable

This meetup was a mix of talks and roundtables of security experts who works with foreign customers and those who works on government-led projects. It showed how different cybersecurity careers can be.

Profession and career in cybersecurity meetup - 5 April 2023

The audience of IT Nation 2.0 are people who fled from war from Eastern part of Ukraine and who are willing to build a tech career. It was a series of online cources and additional events with mentors and experts of different professions. I've joined as a mentor for a group of internally displaced women to encourage them to pursue their dream job. Later on, I've also joined a roundtable about career in cybersecurity.

IT Nation 2.0 - October 2022

Simple Security and Complience Interview

We've dicussed what secure software development lifecycle is and how to implement it.

Video (in English) of the event - 21 September 2022

SecuriTea

A series of cozy online meetups of the local WWCodeKyiv chapter - started in 2021. We share our recent thoughts about security with the members of the community. Recent topics:

  • WWDC news: Security & Privacy;
  • Books, blogs, people to learn more about security.

Security Roundtable

A roundtable session with Anastasi Voitova and Julia Vashchenko where we discuss real-life securuty cases together with the audince of iOS developers.

Video (in English) from the conference SwiftHeroes - 2 October 2020


Other Mobile Security Talks

Encryption Export Regulations. Why should mobile developers care?

A lightning talk presented at Women Who Code Connect - 10 June 2021.

Slides. Video (in English).

iOS App Vulnerabilities and how to fix them

Presented at iOS Ukraine - 17 May 2021.

Slides

Touch ID and Face ID. Is it secure?

Presented at OWASP Zhytomyr local meetup - 29 June 2019.

Slides. Video (in Russian)

OWASP MSTG in Real Life

Presented at OWASP Kyiv local meetup - 6 April 2019.

Slides. Video (in Russian)


Diversity and Inclusion

Diversity Programs: The Key to Building and Supporting Inclusive Tech Teams

Presented at WTM Ukraine: Recharge for 2024 - 10 December 2023.

Slides

History of Women Who Code Kyiv through wartime

Presented at MacPaw meetup: Women in Engineering - 25 October 2023

Vector Interview

Vector media interviewed Women Who Code Kyiv members, including me, about building tech community for women and stereotypes that we're facing. We talked about the history of our chapter, our mentoring program and how we continue to funtion even during russian full-scale invasion of Ukraine.

Article (in Ukrainian) - 11 May 2023

Dima Maleev Podcast "What's wrong with IT?"

It was a Podcast where participants were raising donations for Armed Forces of Ukraine. While we were aiming at 4 million hryvnias, we've actually raised 12 millions! It is about $300 000. I was just amazing. I was just one of the guests. I've talked about Women Who Code Kyiv community and stereotypes about women in tech.

Video (in Ukrainian) - 20 August 2022

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.