OWASP AppSec Brasil 2009

I’ve always liked taking part in technical communities, events, and conferences. It’s always good to have some time to stop and think about technical topics without the pressure that comes with the job. I already mentioned I’d found the CISSPBR list, in which I ended up participating pretty actively. Despite the flame wars that occasionally happened, there was a good exchange of knowledge and a certain sense of community there.
In 2006, I discovered a new community through contacts from CISSPBR. A guy from São Paulo had created the Brazilian chapter of OWASP, a community focused on topics related to application security. That was a subject I was very interested in, so I started participating in the OWASP Brazil mailing list. At the time, there was a single chapter for the whole country, which made sense, since the community was still quite small. A lot of people were also on CISSPBR, and some names were already familiar.
That “guy from São Paulo” was Wagner, who also participated in CISSPBR and in other mailing lists where I used to exchange ideas, like one called “Código Seguro.” We had already exchanged some emails when he created the Brazilian chapter of OWASP. After that, we met in person and ended up becoming friends in real life too.
In 2008, Wagner and his partner, Eduardo, invited me to teach a course on secure Java development in partnership with the company they had created, called Conviso, which still exists today. I gathered some material I already had, did some research to update the content, and put together a syllabus proposal for the course. I prepared the teaching material, and we worked together on promoting it. We managed to put together one class in São Paulo and another in Brasília.
While we were working on preparing and promoting the course, OWASP announced it would hold its first Summit, a gathering of project and chapter leaders from the organization, which would take place in Portugal at the end of 2008. Eduardo was responsible for organizing the Summit’s courses and training sessions. He announced this in Brazil and, some time later, got in touch with me to ask if I’d be interested in bringing the training to the Summit. To do that, I’d have to prepare all the material in English.
I accepted the challenge and prepared the material. The course was accepted, and OWASP would cover the costs of my trip to Portugal. Since it was the first event of this kind organized by the community, the format ended up changing quite a bit after the initial announcement. One of the changes was that they removed the training sessions so the event could focus more on discussing OWASP projects and the organization itself. Even with my course canceled, since the tickets had already been bought, I went anyway to take part in the event.
It was a very interesting event and marked my first in-person interaction with the international OWASP community. Many of the project leaders were there, including people whose projects produced tools I used or whose work I had read about, and I talked to several of them and even started some friendships. The main organizer of the event was Dinis Cruz, who was already one of the most respected OWASP leaders at that time. Dinis really encouraged us to run more OWASP activities and events in Brazil.
In an interesting coincidence, Eduardo and I came back to Brazil on the same flight. That gave us plenty of time to talk about the idea of organizing an OWASP conference in Brazil. Inspired by the many references to CPLP in the immigration queues at Lisbon airport, the initial idea was to have a Portuguese-language conference aimed at the countries of the Community of Portuguese-Language Countries. The first name that came up was OWASP AppSec CPLP. Later, the name evolved to OWASP AppSec Brasil and, after a few editions, to OWASP AppSec Latam.
When we returned to Brazil, discussions began on the OWASP Brazil chapter mailing list, with many suggestions and ideas about where and how to organize the conference. 2008 was also the year I switched from the Central Bank to the Chamber of Deputies. In a conversation with the director of the Chamber’s computing center, the idea came up of holding a joint event between OWASP and CENIN. That would solve the event’s sponsorship problem, but would also bring some changes to how OWASP, as an organization, would handle it. Conferences were already one of OWASP’s main funding sources and, in this case, the event would be organized in partnership and without the possibility of generating a profit. In return, it would be a free event held at the Chamber of Deputies headquarters in Brasília. That’s how AppSec Brasil 2009 came to be.
With that institutional support, I had enough time to dedicate to organizing the event, and I also got support from a team member to help with that work. I ended up becoming the local coordinator of the event, both on the Chamber’s side and on OWASP’s side. In my view, the event was a success. We had keynotes by pretty well-known names in the field, many extremely interesting presentations on application security, and an excellent opportunity to interact with the OWASP community, not just from Brazil, but also from other countries.
After the event, someone who had said they would help organize it, but who in practice did very little, started a discussion with Wagner claiming the event had several issues. In the middle of the discussion, accusations also began to surface that there had been misuse of public funds, an accusation that affected me directly. That discussion started on a mailing list I wasn’t on, but Wagner let me know what was happening and that the situation was being escalated to the OWASP Foundation.
I considered the accusations totally baseless and asked the OWASP ethics committee to intervene. In the end, the committee concluded the accusations weren’t well founded, but also understood that the person hadn’t committed any ethical violation by expressing their opinion.
With that resolved, we could start thinking about the next edition of the conference. But that’s a story for another chapter.