Beyond Software Defenses: Hardware-assisted CFI on Arm-based systems

Most attacks against software rely on subverting a program's control flow to execute malicious code. Control-flow integrity (CFI) refers to a set of security techniques that aim to limit a program's flow to its original execution path. In this talk we will explore the state-of-the-art in CFI mitigations on Arm-based systems, namely Pointer Authentication (PAuth) and Branch Target Identification (BTI). These are hardware-assisted mechanisms deployed in the latest System-On-Chip architectures, raising the bar against software exploitation.

Zoraxy - A reverse proxy server for networking noobs

In this sharing sessions, I will talk about the development and usage of Zoraxy, one of my open source projects that I am using as an NPM (nginx proxy manager) replacement. Zoraxy provide an easy to use & fast to deploy reverse proxy server for networking noobs with tons of handful utilities to help manage your homelab. I will share a bit on how the features in Zoraxy can help you build a geologically distributed web services, proxying request across nodes using ZeroTier UI in Zoraxy as well as some basic ideas of subdomain & TLS SNI.

hkbus.app - Free and Ad-free bus app costing HKD 1000 per year to support ~40k daily users

hkbus.app is a web application utilizes the public transport ETA data from data.gov.hk. The proposal will covers the software stack for achieving extremely low cost to support several thousands and even more users. Then, I will present the outcome and status of marketing, mainly via SEO and social media. In the third part, I will jump into the discussion on contribution by other users and the community status in Telegram, currently with ~1300 users and 7 admins.

Charles Cheng

Charles Cheng is a cybersecurity enthusiast, currently a member of Black Bauhinia and HKUST Firebird CTF team. He is passionate about the cybersecurity field, interested in studying different cybersecurity issues, and loves spending time playing Capture-the-Flag (CTF) competitions.

Azure Adventure – A RPG game to test student’s Azure practical skills

Azure Adventure is an open source HTML5 RPG game that builds on top of the latest version of Azure Automatic Grading Engine. Students need to talk to non-player character (NPC) in the game, then NPC will give some Azure tasks to students. If students can complete those tasks within time limit, then students can get some coins in the game.

Arnt Gulbrandsen

Arnt Gulbrandsen is Senior UA Technology Engineer at ICANN, which is to say, he manages no one, talks about universal acceptance to anyone who’ll listen and contributes code to make it happen. At the moment Arnt has pull requests outstanding for Firefox, the Python and Ruby standard libraries, and more. In the past, Arnt has written about ten RFCs about the DNS and email and worked as a contractor and in various startups, the most well-known probably being qt.io. You have probably used some of his code today.

Authgear

Authgear is an open-source auth-as-a-service solution for consumer-facing web and mobile applications created by Oursky. Authgear is developer-friendly with opinionated defaults that help developers improve the security of their apps by easily enabling 2FA, session management, and passwordless login out of the box. The ideal solution for businesses to unify the authentication experience across multiple platforms with simple integration.