2024
- Gave a 40min presentation on principals in designing a good security strategy as a conference sponsor.
- The session title was: CNAPP・ASM・ASPM…またバズワードが移りゆく、2024 年もなお不変の脆弱性評価・管理の勘所
- See this page for further information
- Appeared in a panel discussion about careers in product security fields.
- See this page for further information
- Gave a lightning talk on cloud security 101.
- The session title was: AWS/GCPのセキュリティ、いつから・誰が・どう始める?
- See this page for further information
2023
- Gave a 30min presentation on early/seed startups.
- Gave a short talk on how to build a strong culture on product security.
- Appeared in the panel discussion on security engineer careers.
- See this post for feeling the vibe!
- Gave a short talk on the intersection of Site Reliability Engineering (SRE) and Security Engineering.
- See this page for further information
- Appeared on the interview-styled page.
- Visit this page for further information.
- Contributed an article to our tech blog.
- Visit this page to read.
- Gave a short talk on CSPM 101.
- See this page for further information
- Served as a producer to design the whole class.
- Gave a 2-hour training named "Webプロダクトセキュリティへのいざない" by myself as well.
- See this page for further information
- Won 18th in ACSC 2023, by which I was selected as finalists of ICC 2023.
- Gave a talk titled "開発者体験をむしろ向上させるセキュリティ施策のイロハ ― Policy as Code の理論と実践".
- See this page for further information
- The transcription is available here.
- Appeared at a panel discussion about software supply chain security.
- See this page for further information
- Gave a talk titled "Eliminating ReDoS with Ruby 3.2".
- See this page for further information
2022
- Appeared at a panel discussion about software supply chain security.
- See this page for further information
- Contributed a really small part of the translation project.
- Check out this page to order the book!
- Conducted a 6-hour training named "ソフトウェサプライチェーンセキュリティのこれから".
- Served as a producer to design the whole class.
- See this page for further information
- Related: Web セキュリティクラスのプロデュース後日談
- Appeared at a panel discussion about next-generation security operations.
- See this page for further information
- Appeared at a panel discussion on career stratergy of security engineers.
- See the event page for further information.
2021
- Talked about Shisho and what it was like becoming the CTO of a Japanese cyber security company.
- Click here to read the interview!
- Appeared at a Q&A session about developer experience.
- See this page for further information
- Gave a talk about developer-first security.
- See this page for further information
- Conducted a 4-hour training named "ちいさな Web ブラウザを作ってみよう".
- Here's an online book for this event: "ちいさな Web ブラウザを作ってみよう".
- See this page for further information
- Contributed some parts to a book describing all about CTF written by some specialists.
- Check out this Amazon page to order the book!
- Organized some parts of the project.
- Provided a Web challenge named osoba.
- Discussed the future of Web security with great security engineers.
- See here to check the detail of the event!
- Gave a short seminar on Web-related modern security aspects.
- See the event page for further information.
- Contributed an article explaining how to deal with anxiety about cyber security for NISC's website.
- You can read the article from here (Wayback Machine).
- Appeared in an interview article in Japanese: 前編, 後編.
- Published a book on security features of web browsers.
- See this page for further information of this book.
2020
- Conducted a 4-hour training named "Web Security from the Macro Perspective: Understanding Modern Hacking Techniques with Web Infrastructure and Side-channels" (日: 「マクロな視点から捉える Web セキュリティ: Web インフラストラクチャを利用した攻撃とサイドチャネル攻撃の実践と評価」).
- Reference: event page
- Appeared in a panel discussion named "Why organize a CTF -This is the way-" (日: 「我々はなぜCTFを運営するのか?」).
- Reference: event page
- Gave a presentation about CTFs and how to learn security stuffs related to them.
- Reference: event page
- Gave a presentation to introduce activities of Security Camp Committee.
- Reference: event page
- Did a online & long-term course on Web security.
- Reference: event page.
- Talked about issues related to ReDoS and show a new attack vector.
- Reference: event page
- Organized the whole project.
- Provided two challenges: unzip and somen.
2019
- Did an eight-hour workshop on web security in collaboration with Information-technology Promotion Agency.
- Provided a challenge named "Snippet".
- Did an eight-hour workshop on web security at National Institute of Information and Communications Technology (NICT) Innovation Center.
- Reference: event page
- Conducted a 4-hour training named "体系的に学ぶモダン Web セキュリティ" (Learn Modern Web Security Systematically).
- Reference: event page
- Contributed an article to JNSA (Japan Network Security Association) e-zine.
- Reference: article
- Participated as a volunteer staff.
- Gave a presentation to introduce activities of Security Camp Committee.
- Reference: event page
- Provided three challenges: Ramen, Secure Meyasubako, and Himitsu.
- Gave a presentation on hot topics on XS-Leaks and advanced CSS Injection.
- Reference: event page
- Provided two challenges: RECON and BADNONCE.
2018
- Conducted a 4-hour introduction-level class on Web security.
- Reference: event page
- Gave a small presentations on hot topics on Web security at the time.
- Reference: event page
- Talked on the complexity of Web and its security from the viewpoint of attackers.
- Reference: event page
- Provided three challenges: Gimme your comment, SECCON Goods, Gimme your comment Revenge.