Skip to content

Details

Much like parties have a set place for their rentrée, Cloudflare is our mojo as we once again emerge from our Summer Slumber with a new event at their headquarters ☀️

A year after the previous one, we’re returning to dig up some more treasure 🪏

This meetup will take place on September 10th, 2026, at 18:30, and is sponsored by Cloudflare and AP2SI.

The venue is located in Cloudflare's office at ALLO - Alcântara Lisbon Offices. Try to arrive at the venue by 18:00. The event will start shortly after.

🧭 Upon reaching ALLO, head to the reception desk and then take the elevator to the 6th floor. You are here (there)📍

Please register ahead of time through this link 🚨

Our tentative schedule:
18:40 - Quick intro by the OWASP Lisboa chapter leadership team
18:45 - "Straight to Spam: The Art of Email Reputation" by André Cruz and Matthieu Tourne
19:20 - "Why OAuth Doesn't Fit Agents" by Dick Hardt
20:00 - Dinner & Drinks by Cloudflare

--------------------------
Talks:
--------------------------
Title: Straight to Spam: The Art of Email Reputation

Speaker: André Cruz and Matthieu Tourne

Abstract:
Sending an email is easy; reaching the inbox is not. This talk explores how providers assess Email reputation, the signals that influence delivery, and the ways suspicious behavior is scored and penalized. We’ll examine how fraud bots, data analytics, and machine-learning classifiers are reshaping email abuse and defense, giving attendees a practical understanding of why legitimate messages end up in spam and what matters most for maintaining a trustworthy sending reputation.

👉🏻 https://www.linkedin.com/in/andrefcruz
👉🏻 https://www.linkedin.com/in/mtourne

--------------------------

Title: Why OAuth Doesn't Fit Agents
Speaker: Dick Hardt

Abstract:
OAuth assumes a known client and a static scope, granted once with a browser present. Agents break all three: they choose their own resources and operations at run time, and the same call can be routine or catastrophic depending on context OAuth never sees. This talk introduces AAuth, an IETF draft that replaces static scope with mission-based, per-call authorization evaluated against signed justification and prior acts rather than a fixed set of permissions granted in advance.

Bio:
Dick Hardt is Founder and CEO of Hellō, a cooperative identity platform. He led the design of OAuth 2.0 and JSON Web Token, standards used by billions of people every day. He is now the author of AAuth, which does for agents what OAuth did for apps: gives agents access to resources without giving them credentials. Dick co-chairs the OpenID Foundation's IPSIE working group and co-authors OAuth 2.1, and previously founded ActiveState and Sxip Identity and led identity initiatives at Microsoft and Amazon. He lives in Lisbon with his wife and their dog.

👉🏻 https://www.linkedin.com/in/dickhardt/

Related topics

Events in Lisbon, PT
Application Security
OWASP
Software Security
Information Security
Web Application

You may also like