Welcome to Cossack Labs website! We use cookies to ensure that you have the best experience on our website! Cookie Policy

AGREE

🇺🇦 We bring our capabilities to all institutions that help protect Ukraine across critical infrastructure, defence, and government.\ \ Read moreWe stand with Ukraine

Conferences & events

Members of the Cossack Labs team often participate in international security and development conferences as speakers, organise and co-organise local events, conduct public workshops and private trainings, and support communities (CocoaHeads, Women Who Code, OWASP).

You can read more in our blog, LinkedIn, Facebook, Twitter, and DEV. Below you can find a collection of video recaps and speaker slides from such events.

Security architecture Security engineering Mobile Risk management Security for senior managers High level cryptography Acra DevSecOps Encryption IOS dev SSDLC Cryptography Zero knowledge architectures Cyberwarfare Product engineering Security controls Security documentation Security patterns Application security Critical Infrastructure Mission-Critical Applications Mission-Critical Systems Technical writers UAVs Web Distributed apps GDPR Key management Open source Product Security Usability vs security Workshop AI in mission-critical systems AI security engineering Blockchain Cloud microservices security CNI CNI systems security Code Europe 2025 Cost of security decisions Critical infrastructure protection Cross-domain security solutions Cryptography to reduce costs Cyber defence Cyber defence and artificial intelligence Cyber resilience CyberNova 2026 Cybersec domains Cybersecurity for AI-powered systems Cybersecurity in defence Data-centric security Defence-in-depth systems Defence technology solutions Defense in depth DELTA project cyber security E2ee Edge AI security End-to-end encryption ENDR 2025 Enterprise security GitHub wiki vs Doc Server Integrated forces operations Interoperability in defence IoT security LLM security Logging, monitoring, tracing Machine learning Mission-critical systems protection Multi-domain operations Naming Next-generation cybersecurity practices OODA loop Password authentication Prague Cyber Security Conference Privacy regulations Private AI infrastructure React native Robotic systems cybersecurity Robotic systems security Ruby Search over encrypted records Secure search Security challenges of AI adoption Security for autonomous systems Security for high-risk systems Security management Security solutions SQL firewall SQL injections State security Success and fail stories System development Themisshow all tags hide tags

Mar 2026 #

Waagnatie, Antwerpen

Ihor Malchenyuk

@ CyberNova

Securing the business of tomorrow

Money spent on platforms that age faster than the threat landscape evolves does not build resilience. What does is the ability to update and redeploy components in hours rather than months — this is what keeps an organisation capable in the face of today’s threats.

CyberNova 2026 Critical infrastructure protection

Mar 2026 #

Prague, Czech Republic

Ihor Malchenyuk

@ Prague Cyber Security Conference

Beyond firewalls: Is cyber resilience the only real defence?

At the Prague Cyber Security Conference, Cossack Labs contributed to the discussion on why true defence means resilience, not just firewalls, sharing hands-on experience in building systems that keep operating under attack.

Prague Cyber Security Conference Cyber resilience

Dec 2025 #

Warsaw, Poland

Anastasiia Voitova

@ WAWTech

Cybersecurity Architectures in 2030: ZT, DCS, CDSS

By 2030, cybersecurity for distributed systems will be less about restricting networks and software, and more about protecting data and keeping systems alive. Our software will need to make its own trust decisions, recover quickly, and exchange data securely even in messy, unpredictable environments. Anastasiia talked about what’s actually working: Zero Trust, Data Centric Security, and Cross-Domain Security Solutions that make complex systems resilient by design.

Data-centric security Cross-domain security solutions Edge AI security Cloud microservices security Next-generation cybersecurity practices

Dec 2025 #

Tampere, Finland

Anastasiia Voitova

@ The European Network of Defence-related Regions Conference Tampere 2025

Utilising civilian technologies in cyber defence, security engineering, drone warfare.

For Finnish representatives of the defence sector, cybersecurity is a pressing issue—they are preparing for all possible scenarios. This makes Ukrainian experience a priority. Anastasiia shared how Cossack Labs builds cybersecurity solutions that ensure the resilience of integrated military technologies in high-risk environments.

ENDR 2025 Cybersecurity in defence Integrated forces operations Multi-domain operations Interoperability in defence

Anastasiia Voitova: resilience depends on speed, adaptability and the ability to coordinate

Tampere 2025 gathered around 300 attendees, which was twice the organisers’ expectations

Nov 2025 #

Kyiv, Ukraine

Elmir Iskanderov

@ DevFest Kyiv 2025

On-prem AI infrastructure for secure PR reviews

Cossack Labs team works with complex, high-risk systems that have unique security requirements—systems whose weaknesses and vulnerabilities we thoroughly understand. They require maximum caution when using third-party AI platforms. Elmir spoke about our approach to deploying our own private AI infrastructure, designed with cybersecurity requirements in mind.

LLM security Private AI infrastructure AI security engineering

slidesOn-prem AI infrastructure for secure PR reviews

Oct 2025 #

Riga, Latvia

Anastasiia Voitova

@ CyberChess 2025

Building security into Ukrainian CNI and mission-critical systems

The era of isolated, “perfectly secure” systems is over—everything is now interconnected, interdependent, and vulnerable. At CyberChess 2025, Anastasiia Voitova, Head of Security Engineering at Cossack Labs, shared, under TLP:AMBER and only with participants, Cossack Labs’ experience of securing selected Ukrainian critical national infrastructure and mission-critical systems, and the security measures implemented to mitigate russian cyber threats.

CNI Mission-Critical Systems Critical Infrastructure Cyberwarfare Mission-Critical Applications UAVs Security Architecture

Sep 2025 #

Kyiv, Ukraine

Anastasiia Voitova

@ Software Architecture fwdays`25 conference

Cybersecurity for high-risk systems

For large-scale governmental and defence systems operating under real operational pressure, cybersecurity is not a feature added at the end, but an engineering discipline embedded into architecture, processes, and day-to-day operations. Design decisions at every layer, from data flows and integrations to deployment and incident response — directly affect system resilience, operational continuity, and real-world outcomes.

Cyber defence Security for high-risk systems Defence technology solutions DELTA project cyber security CNI systems security

Representatives of Cossack Labs, Center of Innovations and Defence Technologies Development of Ministry of Defence of Ukraine, Directorate of Digital Transformation in the Defence Sector of Ministry of Defence of Ukraine, and Ministry of Digital Transformation of Ukraine discuss the challenges of cybersecurity protection and resilience in governmental and defence systems.

Jul 2025 #

Kyiv, Ukraine

Anastasiia Voitova

@ SKELAR Meetup

How AI is changing security

Some Ukrainian defense systems already have integrated AI capabilities. Attackers with unlimited resources are also using AI to find vulnerabilities in these systems. Our job as security engineers is to keep changing security controls and implement adaptive, defense-in-depth systems that are very hard to compromise.

Cybersecurity for AI-powered systems Security engineering AI in mission-critical systems Cyber defence and artificial intelligence Security challenges of AI adoption

For skilled engineers, AI is just a tool. Sadly, more and more often, we’re seeing people who simply aren’t prepared to use it responsibly.

Cybersecurity certainly won’t stop the arrival of the technological singularity. It definitely won’t reduce its impact either. But maybe cybersecurity—as a set of measures and tools—can make people’s lives a bit more comfortable before it happens.

Jun 2025 #

KrakĂłw, Poland

Anastasiia Voitova

@ Code Europe 2025

Building security for autonomous and robotic systems

Anastasiia explored the differences between building security for civilian and high-stakes mission-critical systems. She highlighted how overlapping security controls help ensure that critical functions remain operational even when others fail under pressure.

Code Europe 2025 Security for autonomous systems Robotic systems cybersecurity Mission-critical systems protection Defence-in-depth systems

May 2025 #

Kyiv, Ukraine

Anastasiia Voitova

@ DOU Day 2025

Security and adaptability in modern defence systems

At the Defense Tech Stage of DOU Day 2025, Anastasiia Voitova, Head of Security Engineering at Cossack Labs, spoke about how modern defence systems are built to remain resilient in high-risk operational conditions. A strong cybersecurity foundation enables faster OODA loops and a more efficient decision-making process.

One example is Ukraine’s largest situational awareness system—accessible via laptops and smartphones over the internet—which faces attacks from opportunistic threats leveraging well-known vulnerabilities to highly sophisticated nation-state operations.

Mission-Critical Systems UAVs OODA loop Security Architecture

Feb 2025 #

Helsinki, Finland

Anastasiia Voitova

@ NATO TIDE Sprint 2025

Speeding up decision-making in cybersecurity for mission-critical systems

Cossack Labs shared practical approaches on speeding up decision-making in cybersecurity for mission-critical systems at NATO TIDE Sprint 2025 event, held by NATO Allied Command Transformation. The talk covered defense-in-depth, security by design, dynamic cryptographic trust, and insights on building security for situational awareness and defense systems.

SSDLC UAVs Mission-Critical Systems

Oct 2024 #

Kyiv, Ukraine

Anton Shepeta

@ CocoaTalks

How to hide from too curious users

Anton shared the best practices for building anti-reverse engineering controls, explain why these defences are essential for protecting sensitive data in mobile applications, and how they can fail.

Product Security Application security Security engineering Mobile Security controls

slidesHow to hide from too curious users

Jun 2024 #

Kyiv, Ukraine

Anastasiia Voitova

@ DevOpsDays Kyiv

Building Security Protections for Robotic Devices

Anastasiia Voitova described the multi-layered security of a modern robotic and autonomous system designed to protect devices and their data. Building defence-in-depth measures include operating system hardening, automated secure device provisioning pipelines, unambiguous device identification, data security for telemetry and commands, secure over-the-air updates, active reverse engineering protections, reducing human involvement, and more.

DevSecOps Robotic systems security

videoBuilding Security Protections for Robotic Devices

May 2024 #

Kyiv, Ukraine

Anastasiia Voitova

@ DOU Day

Secure architecture for mission-critical systems

Anastasiia Voitova, Head of Security Engineering at Cossack Labs, talked at the DOU Day offline conference about building secure architecture for mission-critical applications. Anastasiia focused on reinforcing the resilience of critical systems to make them secure and reliable.

Mission-Critical Applications Security architecture Application security

Mar 2024 #

online

Elmir Iskanderov

@ Online QADay 2024

Bulletproof your software: The magic of security autotests

Product security is a process, and some of the steps could be automated to save resources and prevent security regressions. Our Security Engineer, Elmir Iskanderov, talked about his experience and ways to speed up product updates through automation at the Online QADay conference.

SSDLC DevSecOps Product Security

videoBulletproof your software: The magic of security autotests slidesBulletproof your software: The magic of security autotests

Mar 2024 #

Berlin, Germany

Anastasiia Voitova

@ NATO TIDE Sprint 2024

Building data-centric security controls for mission-critical applications

Head of Security Engineering Anastasiia Voitova shared unique expertise on building resilient security controls for mission-critical applications and defending nation-wide infrastructures from cybersecurity threats at NATO TIDE Sprint 2024 event, held by NATO Allied Command Transformation.

Critical Infrastructure Cyberwarfare Mission-Critical Applications

Feb 2024 #

Kyiv, Ukraine

Ihor Malchenyuk

@ Conference by USAID Cybersecurity Activity

Critical Infrastructure Cybersecurity Diagnostics: Strengthening Digital Protection

Cossack Labs participates in the discussion of current issues of assessing the state of cybersecurity of critical infrastructure and took part in the “Critical Infrastructure Cybersecurity Diagnostics: Strengthening Digital Protection” conference. The conference was held by USAID Cybersecurity Activity, the State Service for Special Communications and Information Protection of Ukraine and the Ministry of Digital Transformation of Ukraine.

The talks focused on critical infrastructure cyber defence enhancement as part of the USAID-supported Program for diagnosing cybersecurity status of critical infrastructure operators. The Program is based on the updated NIST Cybersecurity Framework 2.0 from National Standards and Technology Institute.

Critical Infrastructure Cyberwarfare

solutions for critical infrastructureCritical Infrastructure Cybersecurity Diagnostics: Strengthening Digital Protection

Ihor Malchenyuk at “Critical Infrastructure Cybersecurity Diagnostics: Strengthening Digital Protection” conference

Jun 2023 #

Katowice, Poland

Ihor Malchenyuk

@ CYBERSEC FORUM/EXPO 2023

Investments in Cybersecurity in the CEE region

Ihor Malchenyuk, Head of Customer Solutions at Cossack Labs, spoke at the CYBERSEC FORUM/EXPO 2023 panel “Investments in Cybersecurity in the CEE Region.”

Ihor discussed cybersecurity challenges in the CEE region, such as the growing number of malware and ransomware attacks, the increased focus on users/people and endpoints, the rising cost of data breaches, the expansion of privacy regulations, and cyberwarfare against mission-critical applications and critical infrastructure assets.

The main conclusion—a lot of pressure from a very dynamic threat landscape, lessons learned from current cyber warfare, and legislation to encourage businesses to practise healthy cyber hygiene create a market opportunity for cooperation between governments and businesses to address the challenges.

Privacy regulations Cyberwarfare Risk management

the realistic security approachInvestments in Cybersecurity in the CEE region

Panel discussion “Investments in Cybersecurity in the CEE region.”

Feb 2022 #

Kyiv, Ukraine

Julia Mezher

@ React fwdays’22

Crypto wallets security for developers

Why cryptocurrency wallets security is not about blockchain but about application security and user education? What crypto wallets and banking apps have in common? Are they as secure as banking apps? In her new talk, Julia goes into details, risks and threats of crypto wallets, design concerns and implementation issues, and gives practical advice for developers who want to make their apps more secure.

Security engineering Mobile Security controls Risk management Application security

slidesCrypto wallets security for developers blog postCrypto wallets security for developers

Nov 2021 #

Artur Hil

@ OWASP Zhytomyr 2021 Meetup

The secret life of Android apps

In his talk for the OWASP Zhytomyr community, Artur uncovers solutions to practical security issues every security engineer faces. The mobile application landscape is constantly changing – developers use new frameworks, Google demands new requirements and security features. Artur demonstrates the latest setup of a lab environment for security testing of Android apps. He uses it to illustrate how different apps implement specific OWASP MASVS requirements — like certificate pinning or root protection. Artur shows where to look to spot the missing security controls.

Security engineering Mobile Security controls Risk management

slidesThe secret life of Android apps video (ru)The secret life of Android apps

Nov 2021 #

Anastasiia Voitova

@ OWASP Global AppSec US 2021 Conference

Data is a new security boundary

As a keynote speaker of this flagship event by OWASP, Anastasiia explains how developers and companies use cutting-edge cryptography and data security approaches when no perimeters and trusted zones exist anymore. In this talk, she starts with data security 101 and gets you through peculiarities of application level encryption (ALE), end-to-end encryption (E2EE), searchable encryption, zero knowledge architectures and zero trust. She demonstrates real-world cases of integrating application level encryption and supporting traditional security controls to protect customers’ data. By the end of the talk, you can have a whole picture how “strong cryptography” becomes “real-world security boundary around sensitive data” and what it takes in different contexts.

Security architecture Cryptography Security engineering Security for senior managers

slidesData is a new security boundary videoData is a new security boundary

Sep 2021 #

Julia Mezher

@ OWASP Ukraine 2020, OWASP 20th Anniversary

React Native security: addressing typical mistakes

Can React Native apps be secure? Is it a leaky abstraction? Julia went in details of React Native architecture, platform usage, and its dependencies. This security talk is designed specially for developers, decision-makers, and tech leads interested in addressing and preventing typical mistakes related to this cross-platform solution from Facebook.

React native Security engineering Security architecture Mobile

OWASP slidesReact Native security: addressing typical mistakes slidesReact Native security: addressing typical mistakes videoReact Native security: addressing typical mistakes blog postReact Native security: addressing typical mistakes

Sketch of Julia's NSSpain talk by felibe444

Sep 2021 #

Anastasiia Voitova

@ NoNameCon

Cryptographic protection of ML models

The security challenge is to protect ML models from leakage and massive accumulation, which leads to reverse engineering of unique IP. In this talk, Anastasiia explains building DRM-like protection with application level encryption using HPKE-like approach on ephemeral keys. She discusses risks, threats, dataflow, cryptographic layer, key management and integration with traditional application security controls for defense-in-depth approach.

Security engineering Machine learning Cryptography

slidesCryptographic protection of ML models videoCryptographic protection of ML models

Slide from Anastasiia's talk about ML models protection by means of cryptography

Sep 2021 #

Julia Mezher

@ NoNameCon and Craft

The art of secure architecture

Secure architecture is about decision making. Learn from Julia how it differs from secure coding and what you can do for your developer team to achieve better results while following SSDLC.

Security engineering Security architecture SSDLC

slidesThe art of secure architecture videoThe art of secure architecture

Slide from Julia's talk about security architecture and tradeoffs

Jun 2021 #

Julia Mezher

@ WomenWhoCode Connect

Encryption export regulations. Why should mobile developers care?

Julia talks about US encryption export regulations - what they mean, which applications they affect, and what developers should do.

Security engineering Risk management Mobile

slidesEncryption export regulations. Why should mobile developers care? videoEncryption export regulations. Why should mobile developers care?

May 2021 #

Julia Mezher

@ iOSUkraine

iOS vulnerabilities and how to fix them

In this talk, Julia invites app devs and architects to explore common iOS vulnerabilities, outlines popular requirements from OWASP MASVS, enlists examples and paths to make applications more secure.

Security engineering Security architecture Mobile

slidesiOS vulnerabilities and how to fix them

Slide from Julia's talk about improper usage of biometric authentication API

Jan 2021 #

Anastasiia Voitova

@ Mobile Notts

End-to-end encrypted doesn't mean secure

End-to-end encryption doesn’t guarantee privacy and/or security of your data. Your favourite application can use e2ee and sell data to someone at the same time. Anastasiia explained the relationship between security, privacy and encryption, and how different encryption approaches protect users data from various events or threats.

End-to-end encryption Security engineering Risk management Mobile

slidesEnd-to-end encrypted doesn't mean secure videoEnd-to-end encrypted doesn't mean secure

Nov 2020 #

Julia Mezher

@ NSSpain 2020 Online

Secure Authentication. Are you sure you do it right?

Julia unraveled security issues developers should keep in mind to implement SSDLC, gave clues to the secure authentication standards, and shared experience on how to avoid typical auth mistakes in iOS apps.

slidesSecure Authentication. Are you sure you do it right?

Jun 2020 #

Anastasiia Voitova

@ OWASP Chapters All Day

Use cryptography, don’t learn it

Anastasiia gave a small hardcore cryptographic session and covered usable cryptography and the scenarios which can help app developers to right up their ship in case of cryptography or data security tools misuse. Get in details why boring crypto is actually better than “fun” crypto.

Cryptography Security engineering Security architecture Risk management

slidesUse cryptography, don’t learn it videoUse cryptography, don’t learn it

Eugene @ QCon London 2020

Mar 2020 #

Eugene Pilyankevich

@ QCon London 2020

Designing secure architectures the modern way, regardless of stack

Eugene talked about implementing sophisticated defences in constrained environments: ranging from protecting massive power grid SCADA networks to improving end-to-end encryption in small mobile applications. Technological stack doesn’t matter if you focus on the risk assets and design defences around asset lifecycle.

Security architecture Security management Risk management

slidesDesigning secure architectures the modern way, regardless of stack video with transcriptDesigning secure architectures the modern way, regardless of stack

Nov 2019 #

Eugene Pilyankevich

@ UA.SC

Protecting data in ICS, SCADA and industrial IoT: goals, problems, solutions

Eugene shared our experience and lessons learnt of building secure data aggregation systems with hardware-based encryption, time-series processing and end-to-end security. Learn about our solutions that are integrated into ICS/SCADA networks of industrial operators, extract sensitive data, encrypt it “on the fly” and process separately.

Security for senior managers Security architecture IoT security

solutions for critical infrastructureProtecting data in ICS, SCADA and industrial IoT: goals, problems, solutions

Eugene @ UA.SC

Nov 2019 #

Anastasiia Voitova

Jean-Philippe Aumasson

@ their own training

Security engineering: from encryption to software architecture patterns

Public training on security and cryptography engineering conducted jointly by Anastasiia and Jean-Philippe. We focused on solving practical security engineering challenges rather than academic cryptography. We talked about SSDLC and risk management, cryptography and typical cryptographic mistakes, using and misusing APIs, building defence-in-depth for distributed applications.

Cryptography Security engineering SSDLC Security architecture

training modulesSecurity engineering: from encryption to software architecture patterns

Nov 2019 #

Anastasiia Voitova

@ BlackAlps

Maintaining cryptographic library for 12 languages

Maintaining cross-platform cryptographic library is a journey full of unexpected bugs, language-specific hacks, difficult decisions and the endless struggle to make developer-facing APIs easy-to-use and hard-to-misuse. Anastasiia described the four years journey of designing and supporting Themis: from shaping cryptosystems, writing language wrappers to CICD pipelines, autotests and interactive documentation.

Security engineering Open source High level cryptography Themis DevSecOps

slidesMaintaining cryptographic library for 12 languages videoMaintaining cryptographic library for 12 languages

Anastasiia @ BlackAlps

Oct 2019 #

Eugene Pilyankevich

@ Devops Stage

Designing secure architectures, the modern way

In this talk, Eugene tried to cross the bridge between modern DevOps/SRE practices, systems architecture design and traditional security/risk management. It is driven by lessons learnt from building systems the modern way in high-risk environments with high reliability and security demands, drawing from the experience of protecting governmental secrets, critical infrastructure and preventing banking fraud at scale..

Security for senior managers Security architecture Risk management DevSecOps

blog postDesigning secure architectures, the modern way

Eugene and Anastasiia taking part in panel discussion @ Devops Stage

Oct 2019 #

Artem Storozhuk

@ OWASP Kyiv and Fwdays Highload

Building SQL firewall: insights from developers

How SQL firewalls can help to protect databases from SQL injections: the main difference from web application firewalls (WAFs), common usage scenarios, pros, and cons. We implemented SQL firewall as part of data encryption proxy Acra, and we will share insights about security and development decisions. Expect a story about parsing SQL protocols, matching rules, hidden dangers of logging, best of configuration and usage patterns.

Acra SQL firewall SQL injections Encryption Security architecture Product engineering

video [ru] from OWASPBuilding SQL firewall: insights from developers video [ru] from HighloadBuilding SQL firewall: insights from developers slidesBuilding SQL firewall: insights from developers blog postBuilding SQL firewall: insights from developers

Artem @ Fwdays Highload

Sep 2019 #

Eugene Pilyankevich

@ OSDN

10 ways open source will hurt security and reliability

We all know how open source is useful. In this talk, Eugene describes the obvious and not very obvious risks that open source brings with it and what are the practical consequences. Learn what you need to pay attention to when selecting components for your new spacecraft to protect it from exploding during takeoff.

Security for senior managers Security architecture Risk management Open source

video (ru)10 ways open source will hurt security and reliability

Sep 2019 #

Anastasiia Voitova

@ FrenchKit and RSConf

10 lines of encryption, 1500 lines of key management

Watch a story behind implementing end-to-end encryption for Bear application. Anastasiia explained the security engineering flow: protocol design, selecting cryptographic library, cryptocoding techniques, building defence-in-depth and preparing for incidents. Learn how to build an encryption engine for the app with 6M users.

Mobile IOS dev Security engineering High level cryptography

slides10 lines of encryption, 1500 lines of key management blog post10 lines of encryption, 1500 lines of key management case study10 lines of encryption, 1500 lines of key management video (ru)10 lines of encryption, 1500 lines of key management video (eng)10 lines of encryption, 1500 lines of key management

Slide from Anastasiia's talk with lines of defense around end-to-end encrypted notes

Sep 2019 #

Karen Sawrey

@ API Days Paris and Write the Docs Prague

Disagree with "I Agree". Enforcing Better GDPR Compliance Through API Documentation

The talk addresses the aspects and elements of API documentation that need to be reconsidered and restyled in the light of GDPR. The way things are, an absolute GDPR compliance is impossible, but maximal compliance is doable. Technical writers can enforce it through the language graphic elements that are used for guiding the users around the API portals.

GDPR Security documentation Technical writers

video from API DaysDisagree with "I Agree". Enforcing Better GDPR Compliance Through API Documentation video from Write the DocsDisagree with "I Agree". Enforcing Better GDPR Compliance Through API Documentation links and materialsDisagree with "I Agree". Enforcing Better GDPR Compliance Through API Documentation

Jun 2019 #

Anastasiia Voitova

@ CocoaHeads Ukraine

Security, privacy and cryptography at WWDC19

Apple made many announcements on WWDC 2019 about cryptography, cybersecurity and privacy. Anastasiia highlighted important changes for developers – including new CryptoKit framework, data privacy regulations, new app permissions.

Mobile IOS dev Security engineering

slidesSecurity, privacy and cryptography at WWDC19 blog postSecurity, privacy and cryptography at WWDC19 blog postSecurity, privacy and cryptography at WWDC19

May 2019 #

Artem Storozhuk

@ NoNameCon

Search over encrypted records: from academic dreams to production-ready tool

The search over encrypted data is the modern cryptographic engineering problem. We will talk about existing approaches (both well-known and modern), and concentrate on practical solution based on blind index technique to search data in databases. What’s inside: cryptographic and functional schemes, implementation details, practical security evaluation (risk modelling and potential attacks). We will show how theoretical models turn into real, usable, maintainable, security tools. Search over encrypted records is part of Acra encryption proxy.

Acra Secure search Search over encrypted records Encryption Product engineering

slidesSearch over encrypted records: from academic dreams to production-ready tool video [ru]Search over encrypted records: from academic dreams to production-ready tool blog postSearch over encrypted records: from academic dreams to production-ready tool

Artem Storozhuk @ NoNameCon

Apr 2019 #

Anastasiia Voitova

@ muCon London

"Defense in depth": trench warfare principles for building secure distributed applications

“Defense in depth” is a security engineering pattern, that suggests building an independent set of security controls aimed at mitigating more risks even if the attacker crosses the outer perimeter. During the talk, Anastasiia modeled threats and risks for the modern distributed application, and improved it by building multiple lines of defence. She gave an overview of high-level patterns and exact tools how to build defense in depth for your distributed web applications.

Defense in depth Acra Web Security engineering Security architecture Security patterns

slides"Defense in depth": trench warfare principles for building secure distributed applications video from muCon"Defense in depth": trench warfare principles for building secure distributed applications blog post"Defense in depth": trench warfare principles for building secure distributed applications

Mar 2019 #

Alexei Lozovsky

@ PeerLab Kyiv

Code injections using ptrace

Have you ever used dynamic libraries before? We’re sure you did. Alexei explains how OS loads dynamic libraries and how to load another library instead (using LD_PRELOAD hooks). As it’s easy to detect and mitigate LD_PRELOAD, Alexei digs deeper and talks about code injection on runtime. Learn how to use ptrace to search functions in a memory-mapped process and to manipulate the process’s state and thread execution.

System development

video (ru)Code injections using ptrace

Mar 2019 #

Anastasiia Voitova

@ iOSCon London

Secure software development: from rookie to hardcore in 90 minutes [workshop]

A workshop for iOS developers that illustrates typical mistakes they do trying to implement security into their apps. Anastasiia showed an actionable to-do list of things developers might want to improve in their apps, and gave a set of key management techniques for mobile apps.

Mobile IOS dev Encryption Key management Workshop

workshop repoSecure software development: from rookie to hardcore in 90 minutes [workshop] slidesSecure software development: from rookie to hardcore in 90 minutes [workshop]

Anastasiia Voitova

Mar 2019 #

Dmytro Shapovalov

@ SecurityBSides Kyiv and Pacemaker Conference

Delivering security products without shooting yourself in the foot

Dmytro Shapovalov, our senior infrastructure engineer, talks about improving the infrastructure for developing, testing, and delivering security tools. Our experience of smoothing the difference between security idealism and engineering friendliness.

SSDLC Product engineering DevSecOps Acra

video from BSides [ru]Delivering security products without shooting yourself in the foot video from Pacemaker [ru]Delivering security products without shooting yourself in the foot slidesDelivering security products without shooting yourself in the foot

Dmytro Shapovalov @ SecurityBSides Kyiv

Feb 2019 #

Dmytro Shapovalov

@ RubyMeditation 26

Teach your application eloquence. Logs, metrics, traces.

Most modern applications live in a close cooperation with each other. Dmytro spoke about the ways to effectively use the modern techniques for monitoring the health of applications. Being an infrastructure engineer, Dmytro explain typical mistakes developers do when implement monitoring, and suggested a couple of approaches and tools that can help.

DevSecOps Web Acra Logging, monitoring, tracing

video [ru]Teach your application eloquence. Logs, metrics, traces. slidesTeach your application eloquence. Logs, metrics, traces. blog postTeach your application eloquence. Logs, metrics, traces.

Dmytro Shapovalov @ RubyMeditation

Dec 2018 #

Dmytro Shapovalov

@ RubyMeditation 25

Data encryption for Ruby web applications

Making secure applications is not easy, especially when encryption tools are difficult and incomprehensible. Dmytro talked about typical data security problems in web apps and about proper implementation of encryption. Dmytro reviewed the cryptographic approaches and the exact tools that ensure that no sensitive data leaks from the application or the database.

Ruby Web Acra Encryption

video [ru]Data encryption for Ruby web applications slidesData encryption for Ruby web applications

Dec 2018 #

Eugene Pilyankevich

@ SecurityBSides Kharkiv

Cryptography & data security: protecting the data while reducing cost in distributed systems

Using cryptography for data protection is not exclusively reserved for “secure chats” and financial products. Modern cryptographic tools help to comply with the regulations and laws, help to improve control over the infrastructure, to prevent data leakages, and to reduce the risk of incidents. Eugene talked about the way modern cryptographic tools allow technology companies to reduce the security budget and to remain protected at the same time.

Security for senior managers Cryptography to reduce costs Distributed apps Enterprise security

slidesCryptography & data security: protecting the data while reducing cost in distributed systems

Anastasiia Voitova @ JavaZone

Dec 2018 #

Anastasiia Voitova

@ Women in Appsec Kyiv Winter Meetup 2018

Defensive team – who are the security engineers and how they help teams to develop secure applications

Who are the people in the “blue team” and how do they prevent business risks for company assets? What is secure development, secure architecture, secure coding? A lecture for Women in Appsec Kyiv community and infosec students.

Cybersec domains Security engineering

slidesDefensive team – who are the security engineers and how they help teams to develop secure applications

Cossack Labs people @ NoNameCon

Sep 2018 #

Eugene Pilyankevich

@ OSDN Kyiv and UA.SC

Marrying usability and security in large-scale infrastructures

Usability is often thought of as the opposite of security. However, most of the security controls inside operating systems and most of the security tools that run there are designed for being operated by humans. This talk is a summary of Eugene’s experience in building and seeing engineers integrate the security tooling – how security controls and tools are mis-designed and fail once used, how poorly integrated controls decrease the overall security of a system, and how lessons learned in reliability/infrastructure engineering apply to security tooling to fix that.

Security for senior managers Usability vs security High level cryptography Success and fail stories

video from OSDN Kyiv [ru]Marrying usability and security in large-scale infrastructures

Sep 2018 #

Anastasiia Voitova

@ JavaZone and DevExperience 2019

Protecting sensitive data in modern multi-component systems

A talk for solution architects and technical leads, in which we took a deep look into data lifecycle, risk, trust, and how they affect security architecture, encryption, and key management techniques. We illustrated typical SDL patterns: narrowing trust, monitoring intrusions, zero knowledge architectures, distributing trust. The goal of the talk was to provide a general thinking framework and enough ideas about tools for senior engineers for them to be able to plan their solutions securely, in relation to the sensitive data inside.

Distributed apps Security patterns High level cryptography Zero knowledge architectures SSDLC

video from JavaZoneProtecting sensitive data in modern multi-component systems slidesProtecting sensitive data in modern multi-component systems

Karen Sawrey @ API The Docs Amsterdam

Jun 2018 #

Anastasiia Voitova

@ SwiftAveiro 2018

Zero Knowledge Architecture Approach for Mobile Developers [workshop]

A workshop for iOS developers that illustrates how to implement end-to-end encryption of Firebase notes application. Zero knowledge algorithms and protocols ensure that no keys, passwords, files, or any other sensitive material ever gets transferred in an unencrypted or reversible form. Workshop code contains two encryption schemes and set of general recommendations of improving security of any iOS application.

Mobile IOS dev Encryption E2ee Zero knowledge architectures Workshop

workshop repoZero Knowledge Architecture Approach for Mobile Developers [workshop]

Jun 2018 #

Anastasiia Voitova

@ QConNYC

Making security usable: product engineer perspective

This is a story of going over the typical security challenges: how to build products that reliably deliver security guarantees, how to avoid the typical pitfalls, and how to create tools that could be usable and predictable for real users. It’s a tale of balancing religious adherence to security practices while keeping the customers’ needs in mind all the time, inside the development team; a story of listening to the customers and observing the actual user behaviour outside in the wild, and trying to make the best decisions when it comes to empowering the customers with easy tools for encrypting data in their apps, securely and without pain. Presented for senior software engineers at QConNYC.

Usability vs security Product engineering Naming

videoMaking security usable: product engineer perspective slidesMaking security usable: product engineer perspective

May 2018 #

Eugene Pilyankevich

@ NoNameCon

Getting secure against challenges or getting security challenges done

What it takes to make security decisions in a business environment, from the perspectives of both vendor and client, urging security engineers not only to think outside the technical box but also outside the box of engineering thinking when faced with real humans on the other side of the wire. Presented for security engineers at NoNameCon.

Security for senior managers Cost of security decisions Security solutions

video [ru]Getting secure against challenges or getting security challenges done slidesGetting secure against challenges or getting security challenges done

Eugene Pilyankevich

May 2018 #

Karen Sawrey

@ API The Docs Amsterdam

Documenting the secret

A talk for Women Techmakers Lviv on creating and maintaining documentation for cryptographic software. Besides the issues of information security, such things as basic self-care and sanity were also brought up. This talk was also given in December 2017 at the one-day API The Docs Amsterdam conference.

Security documentation Technical writers

May 2018 #

Anastasiia Voitova

@ UIKonf and CocoaHeads Kyiv

X things you need to know before implementing cryptography

A “tips and tricks” talk for mobile developers. Even when developers create apps with security in mind, (at least try to) protect user secrets, and don’t reveal unencrypted data, attackers can still find ways to bypass these security measures by exploiting architectural weaknesses and non-obvious, yet very simple vulnerabilities. The talk is about all the tiny bits and pieces that are necessary for making your app secure against simple attacks way before focusing on the hard things (like cryptography).

Mobile IOS dev Encryption Security controls

video from UIKonf [eng]X things you need to know before implementing cryptography video from CocoaHeads [ru]X things you need to know before implementing cryptography video from mDevTalk [eng]X things you need to know before implementing cryptography slidesX things you need to know before implementing cryptography

Apr 2018 #

Anastasiia Voitova

@ QCon London, Codemotion Milan and Security BSides Ukraine

Encryption without magic, risk management without pain

An in-depth technical inquiry about cryptography in a wider context: how it helps to narrow more significant risks to controllable attack surfaces, enables efficient and elegant risk management, and how tools and algorithms sit in a broader context of managing infrastructure-wide risks associated with handling the sensitive data.

High level cryptography Risk management Security patterns Security architecture Acra

video from QConEncryption without magic, risk management without pain video from Security BSides [ru]Encryption without magic, risk management without pain slidesEncryption without magic, risk management without pain

Karen Sawrey

Apr 2018 #

Karen Sawrey

@ API The Docs Paris

The Bad, The Ugly, The Good

Karen Sawrey, our technical writer, gave a talk on refactoring the existing GitHub documentation of our products and moving it to our own proprietary documentation server.

Security documentation Technical writers GitHub wiki vs Doc Server

videoThe Bad, The Ugly, The Good

Apr 2018 #

Karen Sawrey

Eugene Pilyankevich

GDPR – Get security done

We co-organised a security meetup for Ukrainian companies to discuss the various technical aspects of GDPR. Our speakers gave two talks, outlining various aspects of GDPR demands and possible compliance tactics.

GDPR Security documentation

Facebook eventGDPR – Get security done Karen slidesGDPR – Get security done

Eugene Pilyankevich @ OSDN Kyiv explaining Data encryption

Oct 2017 #

Anastasiia Voitova

@ MobiConf and DevFest Baltics

Zero-knowledge architectures for mobile applications

The talk focused on real-world problems that ZKA counters, typical cryptographic designs and progress in different spheres of ZKA. The talk also explained the practical approaches useful for mobile developers (implementing data sharing and user collaboration on data in a cloud in a way that makes a mobile app provably secure).

Mobile IOS dev Zero knowledge architectures Security architecture High level cryptography

video from DevFestBalticsZero-knowledge architectures for mobile applications video from MobiConfZero-knowledge architectures for mobile applications slidesZero-knowledge architectures for mobile applications blog postZero-knowledge architectures for mobile applications

Oct 2017 #

Eugene Pilyankevich

Why decentralized social services fail

It often feels like distributed and federated services provide better resiliency, risk management, and privacy than typical star-topology systems. However, Facebook et al. provide and maintain huge, single-point-of-entry, solely owned, walled gardens with hostile privacy policies, and yet they successfully serve millions of users, attracting some of the best engineering talents along the way.

State security Blockchain Security architecture

blog postWhy decentralized social services fail

Anastasiia Voitova @ NoNameCon

Apr 2017 #

Anastasiia Voitova

@ AppBuilders

Key management approaches for mobile applications

Trust is built around various trust tokens: keys, passwords, secrets, biometric properties, things you have and things you know. Key management is complicated when done the right way.

Mobile IOS dev Key management Encryption

video from AppBuilders 17Key management approaches for mobile applications slidesKey management approaches for mobile applications blog postKey management approaches for mobile applications

Apr 2017 #

Eugene Pilyankevich

DevOps and security: from the trenches to command centers

DevOps movement emerged as an attempt to build the bridge between people who write code, people who maintain the infrastructure for running it, and people who make the business decisions. These changes have put the emphasis on the new set of techniques and values. These techniques and values can either be beneficial or problematic for the security posture.

DevSecOps SSDLC Security patterns Security architecture

blog postDevOps and security: from the trenches to command centers

Nov 2016 #

Eugene Pilyankevich

End-to-end data turnover: building Zero-knowledge software

Our CTO’s talk on the evolution of end-to-end software, survival within the “everything will be broken” model with the help of employing proper cryptography and trust management, plus a disclosure of some ideas and concepts behind Hermes.

Zero knowledge architectures Security architecture High level cryptography Security for senior managers

blog postEnd-to-end data turnover: building Zero-knowledge software

Eugene Pilyankevich

Aug 2016 #

Eugene Pilyankevich

@ SecurityBSides Kyiv

Everything will be broken

Our CTO’s talk about the classic and emerging threat models, a proper understanding of security risks, perception of technical infrastructures ranging from idealistic to realistic, and adopting stronger techniques in the face of the vanishing perimeter and the (sadly) lowering standards of security tools and overall quality of the produced software.

Security architecture High level cryptography Security for senior managers Risk management

blog postEverything will be broken

May 2016 #

Ignat Korchagin

@ DefCon Crypto Village

Evolution of password-based authentication systems

These are the slides that accompanied the talk of our core scientific contributor. The talk is focused on on evolving from regular authentication to Zero-Knowledge Proofs (including with Secure Comparator) at DefCon Crypto Village.

Password authentication Cryptography Zero knowledge architectures

Secure ComparatorEvolution of password-based authentication systems slidesEvolution of password-based authentication systems

Contact us

Your name and company name*Business email*

I consent for this website to store my submitted information and accept Privacy and Cookie Policies. This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Get whitepaper

Apply for the position

Our team will review your resume and provide feedback

within 5 business days

Full nameEmail Resume Comment (optional)

How did you hear about this job opportunity? (optional)

Choose variant

  • Colleagues/Friends
  • Conference/Meetups
  • DOU
  • Facebook
  • Job Boards
  • Linkedin
  • Recruiter
  • University
  • Other

By submitting this form, you consent to Cossack Labs processing your personal data for recruitment purposes, including storage, analysis, and sharing with relevant parties involved in the hiring process.

Thank you!

We’ve received your request and will respond soon.

Close

Your resume has been sent!

Our team will review your resume and provide feedback

within 5 business days

Close

reCAPTCHA

Recaptcha requires verification.

protected by reCAPTCHA