Loading…
October 30, 2024
Learn More and Register to Attend

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for SOSS Community Day Japan 2024 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.

Please note: This schedule is automatically displayed in Japan Standard time (JST/UTC+9). To see the schedule in your preferred timezone, please select from the drop-down located at the bottom of the menu to the right.

The schedule is subject to change.
strong>Breakout Sessions [clear filter]
Wednesday, October 30
 

11:55 JST

Let’s Join CNCF TAG Security APAC! - Yoshiyuki Tabata, Hitachi, Ltd.
Wednesday October 30, 2024 11:55 - 12:00 JST
The CNCF Security Technical Advisory Group (TAG Security) is a group of cloud-native security experts and anyone interested in cloud-native security, and we can come together to work on various issues in different security areas. We do this in various ways, including through white papers we produce as resources for the community, presentations on new security projects including CNCF projects, and security assessments we provide to CNCF projects and many other initiatives. Previously, TAG Security meetings were only held in the US and EMEA time zones for a long time. This made it difficult for security friends in the APAC time zone to contribute to TAG Security, but we have now managed to hold meetings in the APAC time zone starting in August of this year! In this presentation, Yoshiyuki Tabata, facilitator for TAG Security APAC, will provide an overview of TAG Security and its latest trends. Let's make TAG Security APAC even more exciting together!
Speakers
avatar for Yoshiyuki Tabata

Yoshiyuki Tabata

Senior OSS Consultant, Hitachi
Yoshiyuki Tabata is a Senior OSS Consultant at Hitachi, Ltd, responsible for IAM and API-related solutions. As an authentication and authorization expert, he has provided numerous consultations, for example, designing and building API/SSO systems in various fields such as finance... Read More →
Wednesday October 30, 2024 11:55 - 12:00 JST
Main Hall

13:45 JST

Navigating the Quantum Readiness Journey: Open-Source Cryptography, PKI and Signing Tools - Tony Chen, Keyfactor
Wednesday October 30, 2024 13:45 - 14:05 JST
With the arrival of the new Post Quantum Cryptography (PQC) NIST standards, we look at the current state. Cryptography and crypto agility are cornerstones of cybersecurity and are essential for everyone. With this presentation, we want to empower every engineer and security expert with hands-on insights into quantum-resistant cryptography to help them navigate the quantum readiness journey. We will explore PQC aspects for use cases in IoT, container, and software supply chain security, as well as initiatives based on standards such as those involving FIPS and IEFT. Additionally, we will discuss the advancements in PQC within the Open-Source products available from bouncycastle.org, ejbca.org, and signserver.org. Security is a collective effort; community collaboration is vital for high-quality, interoperable cryptographic solutions.
Speakers
avatar for Tony Chen

Tony Chen

Solution Engineer, Keyfactor
Meet Tony Chen, the cybersecurity wizard with over 8 years of PKI magic up his sleeve! As an Asia-Pacific and Japan Solution Engineer at Keyfactor, he’s the go-to guy for all things secure. With a Master’s in Cybersecurity from the National University of Singapore and a CISSP... Read More →
Wednesday October 30, 2024 13:45 - 14:05 JST
Main Hall

14:10 JST

How Application Security Will Change with the Rise of AI - Riotaro Okada, Asterisk Research, Inc
Wednesday October 30, 2024 14:10 - 14:25 JST
DevOps, CI/CD, and rapid improvement cycles have improved code maintenance and quality. Yet, application security remains vulnerable and underdeveloped. Drawing on my experience with the OWASP community in Japan and some OWASP Projects like the OWASP LLM Top 10 Risks project, I will share some concepts of beneficial and risky practices throughout DevOps.
Speakers
avatar for Riotaro Okada

Riotaro Okada

executive, Asterisk Research, Inc
A Japanese security researcherAn OWASP Japan chapter lead (since 2011)An OWASP contributor with projects (since 200x)Executive director / xSIRT advisor at Asterisk ResearchMBA, CISA, CSAhttps://www.linkedin.com/in/riotaro
Wednesday October 30, 2024 14:10 - 14:25 JST
Main Hall

14:30 JST

Learnings from Teaching Students Who Are Willing to Be Cyber Security Expert. - Masato Matsuoka, Black Duck Software G.K.
Wednesday October 30, 2024 14:30 - 14:40 JST
I have been chosen a lecturer of IoT cyber security for Security Camp, and I taught them IoT system risk analysis from outside of the systems, and software levels which system internal risks identifying with SBOM. Many of them are very good cyber security learner, but there are some findings from the series of lecture. They are knowing about risks of software in general, but they have not much experiences yet then it's always discussing about basic things after all. e.g. Their knowledge and experiences are very limited then identify the risks of the OSS components by evaluating Software BOMs is quite challenging. I don't give you any guidance, ideas or so, but I will share my experiences with students.
Speakers
avatar for ANI Matsuoka

ANI Matsuoka

Sr. Technical Marketing Manager, Black Duck Software G.K.
Graduated from the Department of Electrical Engineering, Nagaoka Technical High School, Niigata Prefecture. Former software developer and cyclist including embedded. After mainly experiencing control systems and embedded software development, he was involved in embedded development... Read More →
Wednesday October 30, 2024 14:30 - 14:40 JST
Main Hall

14:45 JST

Developers Meet Security: Lessons Learnt - Marta Rybczynska, Ygreky
Wednesday October 30, 2024 14:45 - 15:00 JST
Security training for developers has become more and more popular. However, do they bring the desired effect? In this talk, Marta will summarize the experience of communicating and training developers on security topics. She will share lessons learned and suggestions on topics like addressing previous bad experiences in communication between developers and security people, the existence of silos, developers being overwhelmed by methodologies and tools, lack of time and resources for security and quality work, and more. This session will be a call for a discussion on how to better explain security to people who are not security experts and do not want to be.
Speakers
avatar for Marta Rybczynska

Marta Rybczynska

Founder, Ygreky
Marta Rybczynska has a network security background, with 20 years of experience in Open Source. She has worked with embedded operating systems like Linux and various real-time OSes, and with system libraries and frameworks up to user interfaces. She has been involved in various Open... Read More →
Wednesday October 30, 2024 14:45 - 15:00 JST
Main Hall
 
  • Filter By Venue
  • Filter By Type
  • Content Experience Level
  • Timezone

Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.