Meetup #19: Hands-on Workshop on Serverless and Serverless Security on AWS
Details
----This is a FREE event-----
This meetup is for anyone who wants to Deep dive into Serverless Computing on AWS. Participants from all experience levels are welcome.
Please DO NOT RSVP in this meetup page - please RSVP HERE: https://konfhub.com/serverless
Session 1: Serverless app: Authenticate with your selfie! by Srushith Repakula (https://www.linkedin.com/in/srushith/), Head of Engineering, KonfHub
The BookYourCab team wants to add a new feature by requiring riders to upload a selfie after signing up. This accomplishes a few things:
- Prevents the same user from signing up for multiple accounts and prevent from using new-user sign up promotions
- Allows users to easily identify the rider during pickup to provide a good customer experience. This also enhances security so bad guys can't spoof to be riders
In this workshop, we will build a serverless face authentication/verification system using the following AWS services - Lambda, Rekognition, Step functions, S3, API Gateway and Dynamo DB.
Prerequisites:
- Basic knowledge of AWS services like Lambda, IAM, S3 etc
- AWS account with the CLI configured
- Basic understanding of Python
Session 2: Pentesting and Securing Serverless Applications by Swaroop Yermalkar (https://www.linkedin.com/in/swaroop-yermalkar/), Lead Security Engineer, Traveloka
Description: Most of the companies are adopting serverless technology to eliminate maintaining managed server and paying only for required resources. However one should not consider that there won't be threats considering any managed server. This workshop will talk about possible threats and will also teach different ways to implement security.
About Speaker:
Swaroop Yermalkar works as a lead security engineer with a diverse skill set focused on Mobile App Pentest, Web, API and AWS Pentesting. In addition, he has authored the book “Learning iOS Pentesting” and lead an open-source project - OWASP iGoat which is developed for iOS security. He is one of the top researchers worldwide, working with Cobalt.io, Synack.inc. He has given talks and workshops at many security conferences including AppSec Israel 2018, AppSec USA 2018, AppSec USA 2017, BruCON, SEC-T, EuropeanSec, Hacks in Taiwan (HITCON), GroundZero, c0c0n, 0x90, GNUnify, etc. More details at https://swaroopsy.com/




