Dsc 1141 2

ā€¦ is over and I had lots of fun, met interesting new people and long-time-no-see ā€œoldā€ friends and had interesting discussions. I went to 2 presentations, the first by JĆ¼rg Stucker about namics' internal multi-blog platform, quite interesting, as we currently build something similar for one of our customers (which was present, as well :) )

The second presentation was by blog.benbit.ch about XSS or as he put it ā€œWie man sich mit einem Blog unbeliebt macht.ā€ (in English: ā€œhow to make oneself unpopular with a blogā€). While he's completely right that XSS is a dangerously underrated security issue and should be taken much more seriously (we blogged about it more than 2 years ago), his tone, arrogance (ā€œat least one third in here will hate me nowā€) and technical half-knowledge was none the less a little bit annoying. One of his solution ā€œdon't use auto-loginā€ for example just raises the entry-barrier for exploiting XSS issues, but usually doesn't help anything to prevent them at all. But at least he didn't claim he's a technical expert, so I can't really blame him for that. Nevertheless an entertaining presentation and certainly opened up the eyes of a lot of people in that room, so mission accomplished :)

Now last but not least, a big thanks to the organizers, a well done ā€œunconferenceā€, I'll be happy to come again next time.

More pictures by me at flickr and by the others and tons of blogposts.