Another AppSec Brasil

During my time at the Brazilian Chamber of Deputies, my participation in OWASP continued to grow. The conference we organized in Brasília in 2009 was considered a success, even though it did not generate any profit for the organization. Soon, conversations began about a second edition. The main question was where it would take place.

In the meantime, I took part in a scientific conference at Unicamp. It was a good chance to go back to Campinas and reconnect with people, places, and stories that had been part of my past. It was also a chance to meet new people in the field, like my friend Anderson and Diego Aranha, who was finishing his PhD under the supervision of a former colleague of mine. It happened at the conference dinner, where we were all at the same table, along with Roberto Gallo, if I’m not mistaken, and we ended up getting into a discussion about the security of the Brazilian electronic voting machines. With that group, it could hardly have been any other topic. The conversation was so good that we stayed late: the conference bus left and we stayed at the restaurant. Since I had a rental car, I ended up giving Anderson and Diego a ride to where they were staying.

That conference was also important because I reconnected with my friend Alexandre, who was already working at CPQD. He ended up being a key contact in helping us secure a venue for the second edition of AppSec Brasil. He liked the idea and was willing to look into the possibility of using CPQD’s convention center. There was some resistance within the OWASP community, since Campinas wasn’t seen as a major hub and CPQD was outside the city’s central area. Still, we decided to hold the event there, mainly because of the cost: the space would be made available free of charge.

With the venue defined, we moved on to organizing the content and the visual identity of the conference. We had many volunteers, but not all of them were consistently available. Luckily, one of them had a knack for design and managed to create a complete visual identity, with a logo and posters. In parallel, we started looking for possible keynote speakers. I sent several emails to well-known names in security and got positive responses from Jeremiah Grossman and Bruce Schneier. Schneier was one of the most recognized figures in the field, and the fact that he accepted gave us a lot of confidence that we would draw a good crowd.

As soon as we had these confirmations, we began promoting the conference on the main security mailing lists. It would be Schneier’s first time in Brazil. At the same time, we opened the call for talks and training sessions and set up the committees responsible for selection. Everything seemed to be going well until, at one point, someone noticed that our event had disappeared from Schneier’s public agenda and that, on the same date, he was listed as attending another event. Despite all our conversations and even after we had accepted his conditions, he dropped our event for another commitment without even letting us know. We had to adapt, but we managed to bring Robert “Rsnake” Hansen, who gave a very interesting talk.

To help organize the conference, CPQD hired someone specialized in events. That significantly reduced the workload on the team and brought in the experience we were lacking. In addition to handling logistics, that person also worked on promotion. She had good press contacts and managed to get coverage in news outlets and on local TV stations. Even so, attendance was below expectations. Despite the excellent content, the event ended up breaking even financially.

During the conference, Dinis Cruz, who always strongly encouraged Brazilian participation in OWASP, suggested we stop having a single chapter for the whole country. The idea was to turn the existing chapter into a São Paulo chapter and create new chapters in other cities. After the conference, new chapters were created in Rio de Janeiro, Porto Alegre, Florianópolis, and Brasília, where I took on the role of chapter leader. With help from contacts at UnB, we held meetings a few times a year in a basement room in the Minhocão, the university’s main building.

At the event in Campinas, we were approached by Jerônimo and Gustavo, from Porto Alegre, who volunteered to organize the next edition. That’s how OWASP AppSec Brasil 2011 was born. By then, I was a bit tired of leading the overall organization every year and decided to participate only as chair of the program committee, responsible for evaluating proposals and assembling the talk schedule. Despite some difficulties with financial management, AppSec Brasil 2011 was also a success and drew an even bigger audience than previous editions. For that event, we decided to rebrand it as AppSec Latam and turn it into an event for all of Latin America.

OWASP wasn’t officially registered in Brazil, so we had some difficulty managing the event’s finances. In the first edition, there was no sponsorship and registration was free, which eliminated the need to handle financial resources. For the second edition, I got support from a foundation run by my friend Senna, who took on that responsibility for us. When I asked if they’d be interested in supporting the third edition, the answer was no: the workload had been bigger than expected and the return hadn’t been very good, which was understandable. The Porto Alegre folks then found a contact who was willing to take on that role. Everything went well until the end of the event, when the company’s owner disappeared, making it hard to pay the suppliers. In the end, everyone got paid, but he vanished with the profit.

With the experience I had accumulated organizing these events, I was invited to join OWASP’s Conferences Committee, which was responsible for overseeing and supporting the organization’s events around the world. As part of that work, I was assigned to support the conference held in China in 2011. One of the organizers was a Chinese woman who lived in New York and whom I had met at one of OWASP’s Summits. We worked together to make sure the event followed the organization’s standards.

That involvement ended up leading to a trip to Beijing. I spent a week at the conference and another week on my own exploring the city. It was a very interesting experience and, during that trip, I received some news that would end up causing a major shift in my career and in my family’s life. But that’s for another chapter.