Wednesday 

Room 3 

11:40 - 12:40 

(UTC+01

Talk (60 min)

Practical cryptography with Tink

There are many textbooks and courses to learn the theoretical foundations of cryptography, and particular constructions, but fewer dive into the details of how to translate that into working production code.

Application Security
Programming

In this session we will describe the challenges presented by traditional cryptography libraries, and the security vulnerabilities that can result from misuse. We will then examine modern hard-to-misuse libraries, focusing on Google’s Tink library. Particular attention is paid to key storage and management.

Neil Madden

Neil Madden is the founder and CEO of Illuminated Security and the author of API Security in Action. Neil was previously the Security Architect for ForgeRock, and is an active contributor to the OAuth and JOSE Working Groups at the IETF. In 2021, Neil discovered a critical vulnerability in Java's elliptic curve digital signature algorithm (ECDSA), which was dubbed the "cryptography bug of the year" and named as one of the top 10 web hacking techniques of 2022. Neil has a PhD in Computer Science and lives in the Cotswolds, England with his wife and daughter