BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.hackfest.ca//hf2022//speaker//VUJ9KZ
BEGIN:VTIMEZONE
TZID:EST
BEGIN:STANDARD
DTSTART:20001029T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10;UNTIL=20061029T070000Z
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:STANDARD
DTSTART:20071104T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=11
TZNAME:EST
TZOFFSETFROM:-0400
TZOFFSETTO:-0500
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000402T030000
RRULE:FREQ=YEARLY;BYDAY=1SU;BYMONTH=4;UNTIL=20060402T080000Z
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
BEGIN:DAYLIGHT
DTSTART:20070311T030000
RRULE:FREQ=YEARLY;BYDAY=2SU;BYMONTH=3
TZNAME:EDT
TZOFFSETFROM:-0500
TZOFFSETTO:-0400
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-hf2022-GCKBJA@cfp.hackfest.ca
DTSTART;TZID=EST:20221029T090000
DTEND;TZID=EST:20221029T092000
DESCRIPTION:In 2022\, most of us have bought goods and services online or u
 sing mobile apps\, for convenience\, for safety (e.g.\, pandemic) or as a 
 matter of personal preference. As mobile payments and integrations with th
 ird-party payment processors become more and more prevalent\, common AppSe
 c mistakes from the past reappear under new forms. Merchants who overlook 
 security best practices and fail to secure their systems can be victims of
  fraud.\n\nIn this talk\, we will cover some examples of payment APIs and 
 mobile in-app purchases (e.g.\, with Apple Pay or Google Play Store) that 
 fail to perform sufficient validation in ways that may have devastating fi
 nancial and reputational impact to merchants. We aim to bring awareness to
  these often-overlooked issues and provide recommendations to avoid these 
 vulnerabilities with real-world examples.
DTSTAMP:20260909T161937Z
LOCATION:Track 2
SUMMARY:Defrauding merchants like it’s Y2K - Craig Barretto\, Yuk Fai Chan
URL:https://cfp.hackfest.ca/hf2022/talk/GCKBJA/
END:VEVENT
BEGIN:VEVENT
UID:pretalx-hf2022-ZAWBMP@cfp.hackfest.ca
DTSTART;TZID=EST:20221030T133000
DTEND;TZID=EST:20221030T142000
DESCRIPTION:As a security researcher\, it is a herculean task not to wonder
  and poke at many of the apps we interact with on a daily basis. Platforms
  in industries such as banking\, education\, social media\, security\, doc
 ument management\, IoT\, and healthcare are riddled with security vulnerab
 ilities that go undetected for months or even years. While hackers have th
 e luxury of exploiting these vulnerabilities under the guise of anonymity\
 , white hats and cybersecurity researchers are often faced with resistance
  or are flat-out ignored when trying to responsible disclose vulnerabiliti
 es. \nIn this talk\, I will discuss the pains of responsible disclosure an
 d bug bounty programs and how companies should rethink how they handle dis
 closed vulnerabilities from researchers. The aim is to bring awareness to 
 often overlooked and misunderstood issues and provide solutions that encou
 rage healthy responsible disclosure interactions.
DTSTAMP:20260909T161937Z
LOCATION:Track 1
SUMMARY:The good\, bad\, and ugly of responsible disclosure - Craig Barrett
 o
URL:https://cfp.hackfest.ca/hf2022/talk/ZAWBMP/
END:VEVENT
END:VCALENDAR
