BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.nsec.io//2024//MLU3QP
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-2024-YVBKMG@cfp.nsec.io
DTSTART;TZID=EST:20240516T164500
DTEND;TZID=EST:20240516T171500
DESCRIPTION:In a mobile-first world\, user registration using only a phone 
 number has become pretty common\, this phone number has become the primary
  method of authentication due to its convenience and speed. These systems 
 may or may not verify other details about the user\, such as their email a
 ddress and typically rely on Single Sign-On (SSO) identity Providers. \n\n
 This talk explores the potential issues that can arise when multiple syste
 ms are used for authentication\, and how these can lead to vulnerabilities
 . We will touch upon how authentication and authorization bugs can origina
 te from user registration and how this can lead to full account takeover\,
  password stealing\, and denial of service. The speaker will draw from the
 ir own experiences in identifying and addressing these vulnerabilities\, p
 roviding valuable insights into this common issue.\n\nFinally\, the talk c
 oncludes by discussing potential solutions and stronger controls that can 
 be implemented to prevent these issues from occurring.\n\nAttendee Takeawa
 ys \n* Security engineers will gain valuable experience in identifying and
  addressing authentication bugs\, helping them to improve their skills in 
 this area.\n* Developers will be encouraged to think more broadly about po
 tential edge cases and vulnerabilities in their applications\, leading to 
 stronger and more secure authentication and authorization controls.
DTSTAMP:20260916T064757Z
LOCATION:Ville-Marie
SUMMARY:UnRegister Me - Advanced Techniques for hunting and securing user r
 egistration vulnerabilities. - Priyank
URL:https://cfp.nsec.io/2024/talk/YVBKMG/
END:VEVENT
END:VCALENDAR
