Opening Remarks
Huxley Barbee, Shweta Jain
BSides NYC 2023 (0x04) · Day 1 · Opening
Overview
This article details the opening remarks for BSides NYC 2023, a significant event marking the conference's return after a five-year hiatus. Delivered by Huxley Barbee, the primary organizer, and Professor Shweta Jain from John Jay College, the session served to welcome attendees, articulate the core values of the conference, and highlight the crucial partnership with John Jay College as the host institution. The talk emphasized BSides NYC's commitment to accessibility, high-quality technical talks, and fostering a strong community within the cybersecurity landscape.

Key moments
- 0:00 Welcome to BSides NYC 2023: Accessibility, Technicality, Community
- 2:00 Navigating BSides NYC: Red, Blue, Workshops, Village, CTFs
- 4:00 Thanking volunteers; community input crucial for conference future
- 6:00 Gratitude to sponsors, especially John Jay College for venue
- 7:00 Professor Shweta Jain introduces John Jay's unique program
- 8:40 John Jay's advanced forensics lab and student job opportunities
- 10:00 Seeking industry partners for curriculum and advisory board
Opening Remarks
Speakers: Huxley Barbee; Shweta Jain, Professor, Math and Computer Science Department, John Jay College
Conference: BSides NYC
YouTube: https://www.youtube.com/watch?v=nW-ukZIm0bA
Overview
This article details the opening remarks for BSides NYC 2023, a significant event marking the conference's return after a five-year hiatus. Delivered by Huxley Barbee, the primary organizer, and Professor Shweta Jain from John Jay College, the session served to welcome attendees, articulate the core values of the conference, and highlight the crucial partnership with John Jay College as the host institution. The talk emphasized BSides NYC's commitment to accessibility, high-quality technical talks, and fostering a strong community within the cybersecurity landscape.
The opening remarks provided an essential orientation to the conference's structure, including its diverse track rooms, workshop areas, and a dedicated "Village" for career development and niche interest groups. A key component of the event, two distinct Capture the Flag (CTF) competitions, were also announced. Furthermore, Professor Jain elaborated on John Jay College's unique Digital Forensics and Cyber Security (D4CS) master's program, underscoring its blend of legal and technical education, its state-of-the-art forensics lab, and its active pursuit of industry partnerships and student placement opportunities.
This session is crucial as it sets the philosophical and logistical stage for the entire conference. By outlining the event's commitment to inclusivity through affordable and free tickets, ensuring a high standard of content via a rigorous submission process, and promoting community engagement, the speakers effectively communicated the ethos of BSides NYC. The partnership with John Jay College further solidifies this foundation, bridging the gap between academic rigor and practical industry application, making the conference not just a gathering but a platform for growth and collaboration within the cybersecurity domain.
Background
▶ Watch: Welcome to BSides NYC 2023: Accessibility, Technicality, Community (0:00)
BSides conferences worldwide are renowned for their grassroots, community-driven approach to cybersecurity knowledge sharing. Originating as an alternative to larger, often more expensive, mainstream security conferences, BSides events prioritize accessibility, deep technical talks, and fostering a strong sense of community among participants. BSides NYC 2023 represents a significant milestone, marking its revival after a five-year break, a testament to the enduring need for such a platform in the vibrant New York City cybersecurity scene. The context of these opening remarks is therefore deeply rooted in the mission to re-establish a welcoming, intellectually stimulating, and practically relevant forum for security professionals, enthusiasts, and students.
Huxley Barbee, as the conference organizer, framed the event around three pillars:
- Accessibility: With tickets priced at an exceptionally low $15, and a substantial number of free tickets allocated (238 for students with .edu addresses, refunded upon attendance, and 26 for individuals facing financial hardship), the conference aimed to remove economic barriers. This strategy ensured that approximately one-quarter of the attendees received free access, directly addressing a common problem in the industry where high conference costs can exclude emerging talent and those with limited resources.
- Technical Talks: The emphasis on high-quality technical content was underscored by an impressive 127 submissions from across the globe. This volume resulted in a highly selective acceptance rate of only 17 percent, ensuring that the speakers and trainers presented content of the "highest quality anywhere in the cyber security community." This rigorous selection process directly tackled the challenge of maintaining technical relevance and depth, distinguishing BSides NYC as a premier venue for cutting-edge discussions.
- Community: From the extensive network of volunteers (40 individuals supporting an attendance of around a thousand) to the diverse planning committee, speakers, and sponsors, the conference was presented as a collective effort. The call for attendee feedback via a QR code further cemented the community-centric approach, positioning the conference as a collaborative endeavor shaped by its participants. This focus aims to counteract the potential for large conferences to feel impersonal, instead fostering a sense of shared ownership and active participation.
The partnership with John Jay College, highlighted by Professor Shweta Jain, provided the critical infrastructure and academic backing for the event. John Jay College's donation of the venue spaces at a "hundred percent discount" was pivotal in enabling the conference's accessible pricing model. This collaboration exemplifies a growing trend in the cybersecurity community where academic institutions play an increasingly vital role in hosting and supporting industry-led initiatives, bridging the gap between theoretical knowledge and practical application, and providing a pipeline for future talent.
Key Findings
▶ Watch: Thanking volunteers; community input crucial for conference future (4:00)
As the provided transcript pertains specifically to the opening remarks of BSides NYC 2023, rather than a technical presentation, this section will detail the key announcements, organizational insights, and programmatic highlights shared by the speakers. There are no technical research findings or discoveries to report in the traditional sense of a security talk.
The primary findings from the opening remarks can be summarized as follows:
- BSides NYC's Core Tenets: The conference is fundamentally built upon three pillars: accessibility, exemplified by its $15 ticket price, 238 student refunds, and 26 free tickets for those under financial hardship; high-quality technical talks, evidenced by a 17% acceptance rate from 127 global submissions; and a strong sense of community, driven by 40 dedicated volunteers and active participant feedback.
- Conference Structure and Content Diversity: Attendees were guided through the physical layout, which included a Red Room for red team topics, a Blue Room for blue team discussions, a room for "other colors of the infosec color wheel," and a dedicated workshop room. The Village area on the sixth floor was highlighted for its niche interest groups, career development talks, and two distinct Capture the Flag (CTF) competitions.
- Capture the Flag Competitions: Two CTFs were announced: one focused on application security, hosted by Secure Code Warrior, and another on more traditional network security, hosted by CTFd. These competitions provide practical, hands-on learning experiences for attendees.
- John Jay College's Pivotal Role: John Jay College was recognized as the most significant sponsor, providing the venue at a "hundred percent discount." Professor Shweta Jain introduced the college's Digital Forensics and Cyber Security (D4CS) master's program, emphasizing its unique curriculum blending legal and technical courses, attracting both STEM and non-STEM students.
- State-of-the-Art Digital Forensics Lab: The D4CS program boasts a cutting-edge digital forensics lab on the sixth floor, equipped with 13 "gamer computers" with huge heavy towers, designed for intensive forensic analysis. This facility represents a significant resource for students and a testament to the program's practical orientation.
- Industry Engagement and Student Placement: John Jay College actively seeks industry partnerships to develop case studies and curriculum, as well as an industry Advisory board. A key objective for the college's representatives at the conference was to make 200 connections with potential employers and place 200 students in jobs and internships, highlighting the program's commitment to career readiness.
In essence, the "key findings" of this session are the foundational principles and operational details that define BSides NYC 2023, coupled with the strategic importance of its academic partnership in fostering talent and advancing the cybersecurity field.
Technical Deep Dive
▶ Watch: Gratitude to sponsors, especially John Jay College for venue (6:00)
While the transcript for the "Opening Remarks" of BSides NYC 2023 does not delve into a specific technical exploit, vulnerability, or research paper, it provides a high-level overview of the technical landscape and educational infrastructure discussed during the conference's introduction. The primary technical mentions revolve around the types of cybersecurity disciplines covered and the tools and environments supporting them.
The conference structure itself delineated distinct technical domains through its room assignments:
- The Red Room was explicitly designated for "red teams," implying a focus on offensive security methodologies, penetration testing, ethical hacking, and adversary simulation. While no specific tools or techniques were mentioned, this categorization signals an emphasis on active exploitation and evasion tactics.
- The Blue Room, conversely, was dedicated to "blue team talks," indicating content centered around defensive security, incident response, threat hunting, security operations, and digital forensics. This implies discussions around SIEM solutions, endpoint detection and response (EDR), network traffic analysis, and defensive strategies.
- A third room was allocated for "other colors of the infosec color wheel," suggesting a broader scope encompassing purple teaming (collaboration between red and blue), security architecture, governance, risk, and compliance (GRC), or perhaps niche areas like industrial control system (ICS) security or automotive cybersecurity.
Beyond the talk tracks, the conference actively engaged participants through two Capture the Flag (CTF) competitions, which are inherently technical:
- One CTF, hosted by Secure Code Warrior, was specified as an application security CTF. This typically involves challenges related to identifying and exploiting vulnerabilities in web applications (e.g., SQL injection, Cross-Site Scripting, insecure direct object references), API security, or secure coding practices. Participants would likely interact with web proxies, static/dynamic application security testing (SAST/DAST) tools, and various web exploitation frameworks.
- The second CTF, hosted by CTFd, was described as a more traditional network security based CTF. Such competitions often involve tasks like network reconnaissance, packet analysis (using tools like Wireshark), binary exploitation, reverse engineering, cryptography, privilege escalation on compromised systems, and exploiting common network services. The platform CTFd itself is a popular open-source framework for hosting CTF events, providing infrastructure for challenges, scoring, and team management.
Professor Shweta Jain's discussion of John Jay College's Digital Forensics and Cyber Security (D4CS) master's program further illuminated technical infrastructure:
- The program's curriculum includes "all the core cyber security stuff" and specifically teaches digital forensics. This implies a curriculum covering topics such as forensic disk imaging, memory forensics, network forensics, malware analysis, and legal aspects of digital evidence collection and preservation.
- A highlight was the mention of a "state-of-the-art lab" for digital forensics on the sixth floor. This lab is equipped with 13 "gamer computers with huge heavy towers." This specification is significant; "gamer computers" typically feature high-performance processors, ample RAM, and powerful graphics processing units (GPUs). These components are critical for digital forensics work, enabling faster processing of large datasets, accelerating brute-force attacks on encrypted evidence, and improving performance for virtual machine environments used in malware analysis or incident response simulations. The "heavy towers" likely indicate robust cooling systems and expansion capabilities necessary for specialized forensic hardware or multiple storage arrays. The description of it as a "secure space" also points to controlled access and integrity of forensic workstations.
While no specific exploits or code snippets were presented, the technical context provided by the speakers paints a picture of a conference deeply engaged with both offensive and defensive cybersecurity practices, supported by practical competitions and advanced academic resources. The emphasis on application security, network security, and digital forensics underscores the breadth of technical disciplines considered vital by the BSides NYC organizers and their academic partners.
Demo / Proof of Concept
▶ Watch: John Jay's advanced forensics lab and student job opportunities (8:40)
The "Opening Remarks" for BSides NYC 2023, as detailed in the provided transcript, did not include any live demonstrations or proofs of concept related to cybersecurity vulnerabilities, tools, or research. The session was entirely dedicated to welcoming attendees, outlining the conference's structure and mission, and highlighting the academic partnership with John Jay College. Therefore, this section does not apply to the content of this specific talk.
Defensive Implications
▶ Watch: Seeking industry partners for curriculum and advisory board (10:00)
Given that the "Opening Remarks" did not present any new vulnerabilities, attack vectors, or technical exploits, there are no direct defensive implications in the traditional sense of actionable security measures against a specific threat. However, the talk implicitly highlights broader defensive strategies and the foundational elements necessary for a strong security posture within the cybersecurity community and workforce.
The emphasis on technical talks and Capture the Flag (CTF) competitions, particularly the application security CTF by Secure Code Warrior and the network security based CTF by CTFd, directly supports the development of defensive capabilities. By providing platforms for hands-on learning and skill development in both offensive and defensive techniques, the conference indirectly equips defenders with a deeper understanding of attacker methodologies and how to counteract them. For instance, participation in an application security CTF can train developers and security analysts to identify and remediate common web vulnerabilities before they can be exploited in production environments. Similarly, a network security CTF enhances skills in network monitoring, incident response, and system hardening.
Furthermore, Professor Shweta Jain's discussion of John Jay College's Digital Forensics and Cyber Security (D4CS) master's program has significant long-term defensive implications. The program's focus on digital forensics, combined with its state-of-the-art lab, is crucial for building a skilled workforce capable of:
- Incident Response: Effectively investigating security breaches, identifying the root cause, scope, and impact of an attack.
- Threat Intelligence: Analyzing artifacts from past incidents to understand adversary tactics, techniques, and procedures (TTPs) to proactively defend against future attacks.
- Evidence Collection and Preservation: Ensuring that digital evidence is properly handled for legal proceedings, a critical aspect in post-incident recovery and accountability.
The call for industry partnerships and the creation of an industry Advisory board by John Jay College also contributes to a stronger defensive posture across the industry. By aligning academic curricula with current industry needs and emerging threats, educational institutions can produce graduates who are better prepared to face real-world cybersecurity challenges. This continuous feedback loop between academia and industry ensures that the next generation of defenders is equipped with the most relevant knowledge and skills.
In summary, while no immediate defensive actions were prescribed, the opening remarks underscored the importance of continuous learning, skill development through practical exercises like CTFs, and robust academic programs in digital forensics and cybersecurity as fundamental pillars for enhancing collective defensive capabilities against evolving cyber threats.
Key Takeaways
- BSides NYC 2023's Core Mission: The conference emphasizes accessibility through affordable tickets ($15, with 238 student refunds and 26 free tickets), high-quality technical talks (17% acceptance rate from 127 global submissions), and fostering a strong community through volunteer efforts and participant feedback.
- Diverse Technical Content and Engagement: The conference offers specialized tracks (Red Team, Blue Team, etc.), workshops, and a "Village" area, alongside two Capture the Flag (CTF) competitions: one for application security hosted by Secure Code Warrior and another for network security hosted by CTFd.
- John Jay College Partnership: John Jay College serves as a pivotal host and sponsor, providing the venue and supporting the conference's mission. Professor Shweta Jain highlighted the college's unique Digital Forensics and Cyber Security (D4CS) master's program, which blends legal and technical education.
- Advanced Digital Forensics Education: The D4CS program features a state-of-the-art digital forensics lab equipped with 13 high-performance "gamer computers", underscoring its commitment to practical, hands-on training in a secure environment.
- Industry Collaboration for Workforce Development: John Jay College actively seeks industry partnerships to develop curriculum and case studies, establish an industry Advisory board, and aims to connect 200 students with jobs and internships, demonstrating a strong focus on bridging academic learning with career opportunities.
About the Speaker(s)
Huxley Barbee served as a key organizer and host for BSides NYC 2023, delivering the initial welcome remarks. His address focused on articulating the core values and mission of the conference: promoting accessibility in cybersecurity events, ensuring the delivery of high-quality technical talks, and fostering a vibrant community spirit. Barbee highlighted the rigorous selection process for speakers, the diverse range of content tracks, and the crucial role of volunteers and sponsors in making the event possible. He is presented as a central figure in the revival and execution of BSides NYC.
Shweta Jain is a distinguished Professor in the Math and Computer Science Department at John Jay College. She also leads the Master's program in Digital Forensics and Cyber Security (D4CS). Professor Jain's contribution to the opening remarks focused on showcasing John Jay College's significant role as the conference host and detailing the unique aspects of the D4CS program. She emphasized its comprehensive curriculum, which integrates both legal and technical aspects of cybersecurity, and its appeal to students from diverse academic backgrounds (both STEM and non-STEM). Professor Jain also highlighted the program's advanced, state-of-the-art digital forensics lab and articulated the college's active pursuit of industry partnerships, an Advisory board, and opportunities for student placement in jobs and internships, underscoring the program's commitment to practical relevance and career readiness.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
This is conference housekeeping dressed up with an academic recruitment pitch — not a talk in any meaningful sense. There's nothing here that couldn't have been a printed program insert and a two-minute stage announcement.
Heather Calloway (CISO) — PASS
This is conference housekeeping, not a security talk. There is no finding, no argument, no decision, and no risk to evaluate — just logistics and an academic program pitch dressed up in conference framing.