#SoCraTes2023

Sebastian Bergmannsebastian@brettspiel.space
2024-08-23

Spannende Session auf der #socrates2024: diese drei netten Menschen haben seit der #socrates2023 an einem #Kartenspiel mit IT-Security als Thema gearbeitet. Jetzt spielen wir es gerade in einer großen Gruppe und geben Feedback.

2024-03-12

Dear #OpenSpace practitioners,

some time ago I did a little survey about how well known the Open Space format is in the #CyberSecurity community
infosec.exchange/@realn2s/1118
(It turned out it's not well known at all)

As we are organising the @OSCo an Open Space security conference we feel that this requires some introduction of the Open Space format.
Because of this I'm looking for material to describe and explain the Open Space format.
E.g. pictures of an empty and an filled schedule, the market place, ... which we could use.

Any suggestions welcome.

#SoCraTes2023 @SoCraTes_Conf

Lea Rosemalea@lea.lgbt
2024-02-01

@Ihazchaos ich hab meine von der #socrates2023 ☺️ und da stand auch irgendwo ne url zu dem sticker-shop: schwarzesocke.org

2023-09-09

@Patricia AFAIR @krys and @rradczewski showed their pipeline at #SoCraTes2023 and it was GitHub Actions an Kubernetes. But I don't have the link, though.

Marc Kalmes has movedmkalmes@chaos.social
2023-09-05

If you would like to know how awesome #SoCraTes2023 was, read @lisihocke personal recap.
> Heading home, my heart was full, my brain energized, my body tired, and me super happy. I was certain that if I have any chance to be back next year I will take it.
👏👏👏 Yes, SoCraTes is THAT good!

lisihocke.com/2023/09/socrates

maschmiinw
2023-09-04

In case you are interested in my experiences and learnings with the conference in Soltau head over to medium.com/@immernurwollen/soc

Short version: it was tremendous fun and I hope I can attend the conference next year again.

2023-09-04

There’s a slim chance that my colleague and I might get invited to a conference in another country(!) with our very interactive accessibility workshop „How to build websites, that don’t make people puke“, that we did at #SoCraTes2023. :O

I mean, this is by far the best, most interactive and fun workshop I ever did, still, until now I didn’t even consider presenting it outside of SoCraTes or one of our company‘s studios.

Wow, suddenly there are awesome new possibilities. :rainbow_heart_eyes:

2023-09-03

@coderbyheart Perhaps use a live #Mastowall at the event next time to push Mastodon usage? 🤔 #SoCraTes2023

2023-09-02

I'm happy to see that #SoCraTes2023 created quite some new sign-ups on Mastodon, because the conference didn't really happen on Twitter and there were many attendees who created their Mastodon accounts because of the conference. Only 13 attendees tweeted during the conference. In my book, the SoCraTes Germany community has left Twitter and I hope this can serve as a good example for other #SoCraTes events around the world: Mastodon is ready to maintain the post-event connections.

2023-09-01

After meeting so many lovely folks at #SoCraTes2023 who are active on the fediverse, finally time to take the plunge! So, what's a good thing to say on a first post?

Hello world!

Lisi Hockelisihocke
2023-09-01

why I'm glad I didn't miss | A Tester's Journey: SoCraTes 2023 - A Place Where I Belong lisihocke.com/2023/09/socrates

2023-08-30

I'm super happy that I was able to attend #SoCraTes2023 in Soltau, Germany ❤️

2023-08-30

@tuxflo
Hab mir den Montag dann freigenommen.
Donnerstag bin ich dann schon wieder los zur #SoCraTes2023
(socrates-conference.de/home)

Die war auch richtig gut. Dafür hänge ich jetzt ganz schön in den Seilen.

Christoph Menzeltraveling_developer
2023-08-30

SoCraTes 2023 - It was a blast 🤩
Last weekend a few colleagues and I attended the @SoCraTes_Conf - A self-organized Open Space.
Many thanks to all organizers and attendees who made this event so special. 🥳
I can always recommend it. 👍

2023-08-29

Btw. best side-effect of #SoCraTes2023: Finally finding someone to talk to about Battlebots. :blob_rainbowheart:

How my gay, nerdy heart rejoiced.

Lisi Hockelisihocke
2023-08-28

What an awesome time we had at . It was my second one and it felt like coming home! Wonderful folks, lots of learning and fun together in a safe space that keeps including more and more people intentionally. Yep, I'll do that again next year. My deepest thanks to everyone. ❤

Lisi Hockelisihocke
2023-08-28

Finally, the workshop day of . Originally, I intended to join the as it was an awesome experience last year. Then @realn2s offered to co-facilitate a workshop together on "Painless Security" - couldn't resist! It ended up being quite insightful. Schemed 2 new projects to work on with folks. Was asked to host further sessions! So that's what we did until late in the night, having fun discovering secret information as an . Just absolutely awesome.

Flipchart notes from workshop "Painless Security" given by Claudius Link and Lisi Hocke at SoCraTes 2023, part one.

"Painless Security", framed as a title.

Sticky notes with six agenda items: welcome and agreements, our connection to security, what's painful, how to reduce the pain, deep dive of your choice, what's next. All items are checked besides the deep dive being marked as on hold.

Agreement: We keep confidentiality.

Collection of points from the initial conversation how people connect with security, nine items:

Missing out - shouldn't we know that?

Assume breach

Information knowledge sharing

The department of "no"

For due diligence

Legal and GDPR

Legacy "code"

Security versus communication

Trust boundariesFlipchart notes from workshop "Painless Security" given by Claudius Link and Lisi Hocke at SoCraTes 2023, part two, section one.

Two headings: "What's painful?" and "How to reduce the pain?"

Heading "What's painful?", 29 items listed in no specific order:

Fear

Security theater

More effort

Poor user and developer experience

Cross-team collaboration and dependencies

People issue

Security always comes last 

Future problem

UX

QA

Detection

Not more people are invested

Procedural problems

Changing permissions

Scary to ask questions

Seeing issues yet no real pain perceived ... until suddenly pain is super high

Incidents

Complex system

Multiple levels or layers

Prevention, detection, reaction

Security experts missing, distant, condescending

Paranoia

Vast area of expertise and lack of knowledge

Secrecy

Communication gaps, no shared language

Outdated dependencies

Alert fatigue

Overwhelming: never finished

Can only know system is insecure, not the other way around

Heading "How to reduce the pain", 34 items listed in no specific order:

Get security advice early on!

"Shift left" security

Put security considerations more to the start (like TDD)

Anti-personas

Ask any questions channel

Have a good developer experience and involve the whole team

Getting ahead of the wave

Dependencies: automate

Fun

Hack the Box team

Pentesting by ourselves or externals

Red versus blue events

Education: e.g. WebGoat or Hack the Box

Continued in next image.Flipchart notes from workshop "Painless Security" given by Claudius Link and Lisi Hocke at SoCraTes 2023, part two, section two.

Everybody should know some tools

Secure code warrior

Hack your own system

Table top exercises

Host CTF sessions

Make security more experiencable

Security "katas"?

For example: JuiceShop

Examples: collection of real stories

Bug bounty

Coordinated disclosure

Security.txt

Knowledge sharing

Security meetups

Security without jargon

Security champions program

Threat modeling

Drive-by versus targeted

Risk assessment, e.g. excluding scenarios, accepting risks actively

Do not obfuscate for security

Split systems into secure-ish and secure where possibleFlipchart notes from workshop "Painless Security" given by Claudius Link and Lisi Hocke at SoCraTes 2023, part three.

"What next?", framed as a cloud.

10 sticky notes listing takeaways to try.

I would like to introduce semi-regular security sessions into my team. Hack the Box / CTF / JuiceShop / WebGoat but also threat modeling. Maybe for a start 30-60 minutes a week after the daily? Sneakily or explicitly?

Security (experience) exchange

AskAppSec: Security without jargon, examples collection, host CTF

Collect examples

Make it fun

Offer my security experience to colleagues

Create security exercises from EMS system

Security RPG? P&P? Board game?

Write an adventure

Security team as tool smith
Lisi Hockelisihocke
2023-08-28

Second open space day of . Joined a dry run of an upcoming talk by @IsItArtOrTrash on why we should "Stop being a superhero!" and try working as (you'll be in for a treat!). Had people help me get started building a small showcase app. Enjoyed an exploration of scanners. Had fun playing a security game. A late night ensemble session on a code and playing a classic C64 adventure game completed an amazing day! 😃

Lea Rosemalea@lea.lgbt
2023-08-28

Now I know I'm sweet. At least the mosquitos at #socrates2023 think so 🥴

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst