Daily Note - Saturday, April 25th, 2026
5 minute read •
BSidesCharm
Today was Day One of BSidesCharm, a small, grass roots security conference here in Baltimore City, aka, Charm City. This my first time back in the Baltimore Security Scene since late 2011 and it has grown. Some of the folks who used to attend CharmSec meetups are involved in the conference, so it was so good to see them and be welcomed back to the fold. The conference is definitely punching over its weight. I think it’s probably good enough to travel to attend, and some people did just that!
Here’s some notes I took today and thought might be worth sharing.
Keynote Talk: Rob Lee
Rob is the founder and CEO of Dragos Security. His talk was about the world of Operational Technology (OT) security and it’s evolution against the backdrop of IT Security. Years ago, when I lived in Baltimore and went to CharmSec at Slainte in Fells Point every month, most of the attendees were from the local power company. I had heard about their struggles with OT Security, but Rob’s talk really helped me understand it a lot better. Operational Technology is anything that controls a physical device, ie, power station controls, water systems, manufacturing, etc.
Back in the late 2000’s, security started to become a profitable discipline and sector in Technology. Money needed to be allocated, and when companies had both OT and IT, nearly all the money went to securing IT because attacks there were higher frequency. Obviously, the affect of an attack on OT would be higher impact, but because of the bespoke and fragmented nature of the OT sector, the risk was very low an attacker could do much. Fast-forward to today and capitalism has intervened to centralize and homogenize the OT space. An attacker who learns to compromise OT infrastructure in Des Moines, can likely re-use that same attack in Dubai, or Singapore. This has changed the game for attackers. Dragos has seen nation states, criminal organization, and now amateur hacking groups successfully attacking OT systems.
Rob briefly talked about the AI impact, and it was refreshing to see someone at his level cut through the hype. His take was that AI is going to remove the perimeter. Essentially, for decades the speed at which vulnerabilities were discovered kept pace with our abilities to patch. That’s going to change, and so anything connected to the internet, at least for a while, will likely be compromised. This means the years of preventing attacks is over. It is now imperative to have a really good detection position. Orgs that have good logging, monitoring, and analysis will be fine. Orgs that still primarily rely on prevention mechanisms are sunk. Those detection and analysis platforms take years to develop, and we have weeks or months before things get weird.
The talk was truly one of my favorite security, maybe tech talks of all time. If a video is posted, I will be sure to post it because I cannot do it justice. One choice quote was,
AI is an enabler. If you have good data and good analysts, AI is going to give you good results. If you have shitty data or shitty analysts, AI’s just going to help them get shitty results faster.
Cloud Misconfigurations: Oh look – Poke, Poke,, Breach!
This talk by Kat Fitzgerald was so good, but as an InfoSec profressional for 20 years, also so depressing. Her message was we need to do the foundations correct. Cloud has been around for over a decade now. We had only just managed to correctly prioritize basics in on-prem, and then we shifted to the cloud. It’s depressing to see that someone who is well-versed in Cloud Security is saying the same thing I’ve been saying since I started giving conference talks in 2007, “do the foundational, boring stuff first because it has the biggest impact.” This particular talk was primarily about Cloud misconfigurations which fell into four tiers: 1) IAM and RBAC, 2) SaaS and API Integrations, 3) Leaky Storage, and 4) Abandoned Infrastructure.
I learned about a few things in her talk that I want to explore more:
- Grayhat Warefare - Shodan, but for S3 Buckets
- Open Policy Agent - Policy as Code, PaC, turns “best practices” into enforcement
- Rego is the policy language and tool
- Prowler - A cloud policy audit tool, think cross-cloud CIS Benchmarks
- Trufflehog - Audit artifacts on a ton of different platforms for secrets, including the ability to validate and verify
And so much more!!
The panel in the Cloud Village was really great! Shawn Thomas’ talk on TDR was infomration dense, but incredibly accessible. There were about 900 people there today, but it still had the feeling of a small, community event. Seriously impressed with the first day of my first BsidesCharm and looking forward to tomorrow!
No Artificial Colors, Flavors, or Intelligence were used in the creation of this content.