BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.bsidescbr.com.au//bsides-canberra-2026//talk//UHLRL
 X
BEGIN:VTIMEZONE
TZID:Australia/Sydney
BEGIN:STANDARD
DTSTART:20250926T000000
TZNAME:AEST
TZOFFSETFROM:+1000
TZOFFSETTO:+1000
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20251005T030000
RDATE:20261004T030000
TZNAME:AEDT
TZOFFSETFROM:+1000
TZOFFSETTO:+1100
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20260405T030000
RDATE:20270404T030000
TZNAME:AEST
TZOFFSETFROM:+1100
TZOFFSETTO:+1000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:API Key Attribution Sucks\, Lets Change That - Luke Marshall
DTSTART;TZID=Australia/Sydney:20260926T133000
DTEND;TZID=Australia/Sydney:20260926T135500
DTSTAMP:20260727T190250Z
UID:pretalx-bsides-canberra-2026-UHLRLX@cfp.bsidescbr.com.au
DESCRIPTION:When a secret is leaked most people look at who leaked the sec
 ret\; the GitHub committers email\, package author\, but this sucks. Milli
 ons of commits are created by noreply emails\, clankers and personal email
 s with no attribution back to your org at all.\n\nWe analysed hundreds of 
 thousands of live\, verified credentials with a new method of attribution\
 , API calls to dynamically fetch ownership information. What we found will
  change the way you think about secret detection and remediation. \n\nUsin
 g this methodology we were able to achieve attribution at scale\, uncoveri
 ng contextless keys that had access to medical devices\, defense equipment
  and some of the most popular software packages ever (GnuTLS\, OpenConnect
 )\, KYC databases and much more.\n\nThis session discusses:\nWhy attributi
 on in its current form is broken\nThe challenges of attribution at scale\n
 What our methodology looks like\nCase studies of our findings
LOCATION:Off-Main Track
URL:https://cfp.bsidescbr.com.au/bsides-canberra-2026/talk/UHLRLX/
END:VEVENT
END:VCALENDAR
