Closing Ceremonies

Huxley Barbee

BSides NYC 2025 (0x05) · Day 1 · Closing

Overview

The "Closing Ceremonies" of BSides NYC, led primarily by conference organizer Huxley Barbee, marked the culmination of a successful and community-driven cybersecurity event. Far from a traditional technical presentation, this session served as a vital institutional component, reflecting on the conference's achievements, acknowledging the immense contributions of volunteers and sponsors, and celebrating the vibrant community that defines the BSides ethos. It provided a comprehensive overview of the event's operational successes, programmatic enhancements, and unwavering commitment to accessibility, setting a positive tone for future iterations.

Watch on YouTube

Visual summary for Closing Ceremonies by Huxley Barbee
Visual summary for Closing Ceremonies by Huxley Barbee

Key moments

  1. 0:00 Huxley Barbee opens closing ceremonies, thanks organizers
  2. 0:40 Code Red Partners discusses careers village, first prize
  3. 2:20 Dashlane offers free premium for students, announces prize
  4. 7:00 Layer X discusses browser security, extension risks
  5. 10:40 AI Village announces Capture The Flag winners
  6. 11:45 CTFD.io announces top three CTF competition winners
  7. 13:00 Final thanks to volunteers, call for next year

Closing Ceremonies

Speakers: Huxley Barbee, Conference Organizer

Conference: BSides NYC

YouTube: https://www.youtube.com/watch?v=U839L4RCbz0

Overview

The "Closing Ceremonies" of BSides NYC, led primarily by conference organizer Huxley Barbee, marked the culmination of a successful and community-driven cybersecurity event. Far from a traditional technical presentation, this session served as a vital institutional component, reflecting on the conference's achievements, acknowledging the immense contributions of volunteers and sponsors, and celebrating the vibrant community that defines the BSides ethos. It provided a comprehensive overview of the event's operational successes, programmatic enhancements, and unwavering commitment to accessibility, setting a positive tone for future iterations.

Huxley Barbee, alongside various sponsor representatives and CTF organizers, guided attendees through a series of prize giveaways and heartfelt acknowledgements. The core message underscored the collaborative spirit and dedicated effort required to host a large-scale, free cybersecurity conference. While not delving into specific technical vulnerabilities or research, the ceremony implicitly highlighted the diverse facets of the cybersecurity industry through the brief introductions of sponsoring organizations and the nature of the Capture The Flag (CTF) competitions.

The significance of this closing ceremony extends beyond mere formalities; it is a testament to the growth and impact of BSides NYC. By sharing key metrics on programming quality, attendance, and community engagement, Barbee painted a clear picture of a conference that is not only expanding but also continually improving its offerings. This collective celebration reinforced the fundamental values of knowledge sharing, skill development, and community building that are central to the global BSides movement.

Background

▶ Watch: Huxley Barbee opens closing ceremonies, thanks organizers (0:00)

The BSides conference series originated from a desire to create more accessible, community-driven, and diverse information security events, contrasting with the often high-cost and corporate-centric nature of larger industry conferences. These grassroots events prioritize local talent, foster open discussion, and provide platforms for emerging researchers and practitioners. BSides NYC stands as a prime example of this philosophy, particularly through its commitment to offering $0 tickets, a practice explicitly highlighted and celebrated during these closing ceremonies.

The "Closing Ceremonies" itself is an indispensable element of such a conference. It serves multiple critical functions: formally recognizing the tireless efforts of organizers and volunteers, expressing gratitude to financial sponsors who make the event possible, and celebrating the successes of participants in various challenges like Capture The Flag competitions. More broadly, it acts as a retrospective "state of the union" for the conference, providing transparent insights into its growth, challenges, and future trajectory.

This particular closing ceremony for BSides NYC demonstrated the conference's maturity and its adherence to the core BSides principles. The emphasis on increased attendance, improved programming quality, and expanded hands-on learning opportunities through CTFs underscores a continuous commitment to serving the cybersecurity community. By sharing these operational details, the organizers not only celebrated their achievements but also invited ongoing community engagement and support for the conference's mission.

Key Findings

▶ Watch: Dashlane offers free premium for students, announces prize (2:20)

The "Closing Ceremonies" presented a series of compelling metrics and achievements that collectively illustrate the significant success and growth of BSides NYC. These "findings" are not technical discoveries but rather indicators of the conference's organizational prowess and increasing impact within the cybersecurity community.

Firstly, programming quality saw a notable improvement. The technical talk acceptance rate for BSides NYC increased to an impressive 12%, a 2% improvement over the previous year. This indicates a more competitive and curated selection process, ensuring that attendees were exposed to high-caliber content. Similarly, the entrepreneur track also experienced enhanced quality, achieving a 25% acceptance rate, signifying a strong pool of innovative ideas and ventures.

Secondly, the conference significantly expanded its hands-on learning opportunities. The number of Capture The Flag (CTF) events doubled from two in the previous year to four in the current iteration. This expansion, encompassing villages like Red Team Village, AI Village, CTFD.io, and Pros versus Joe's, provided participants with diverse practical challenges ranging from lockpicking to offensive/defensive cybersecurity scenarios. This commitment to experiential learning is a cornerstone of effective cybersecurity education.

Thirdly, BSides NYC reaffirmed its foundational commitment to accessibility by continuing its policy of offering $0 tickets. In an industry where conference fees can range from $75 to over $500, this policy makes high-quality cybersecurity education and networking available to a broad audience, including students and those with limited resources. This outlier status in the conference landscape underscores the community-first mission of BSides NYC.

Finally, the conference demonstrated substantial community engagement and operational efficiency. Attendance increased by a remarkable 14% over the previous year, highlighting the growing appeal and relevance of BSides NYC. Furthermore, the organizers implemented sustainable practices by ensuring that all leftover food and t-shirts were immediately donated, preventing waste and benefiting the wider community. These achievements were attributed to the "whole lot of hard work over the past 364 days" by Huxley Barbee and his dedicated team of volunteers and partners.

Technical Deep Dive

▶ Watch: Layer X discusses browser security, extension risks (7:00)

The "Closing Ceremonies" itself was an organizational wrap-up rather than a presentation of technical research or a deep dive into specific vulnerabilities. Therefore, it did not feature detailed technical content, code examples, protocol analyses, or architectural discussions in the traditional sense of a security conference talk.

However, the event did offer several brief glimpses into pertinent technical domains through the introductions of sponsoring organizations and the nature of the various Capture The Flag (CTF) competitions. These mentions collectively illustrate the breadth of technical areas within modern cybersecurity that were present and supported at BSides NYC:

  • Dashlane, represented by CISO Joanna Chen, highlighted its core offering as a password manager. This technology is fundamental to Identity and Access Management (IAM), providing secure generation, storage, and auto-filling of complex credentials. Dashlane also offers features for monitoring credentials against malware dumps and data breaches, alerting users if their information appears in leaked datasets. This underscores the technical challenges associated with secure credential hygiene, encryption, and the proactive use of threat intelligence to protect user accounts across various online services. The underlying technologies involve robust cryptographic practices, secure storage architectures, and continuous monitoring of public and dark web breach data.
  • Gecko, introduced by JJ, is developing an LLM static analysis tool aimed at finding business logic vulnerabilities. This represents an advanced application of Artificial Intelligence (AI) and Machine Learning (ML) in Application Security (AppSec). Traditional static analysis tools often focus on common coding errors or known vulnerability patterns. However, business logic vulnerabilities, such as improper authorization flows, incorrect transaction processing, or flawed state transitions, are often more subtle and require a deeper understanding of the application's intended functionality. An LLM-powered tool would leverage large language models to analyze codebases, comprehend the business rules, and identify deviations or exploitable logic flaws that might be missed by purely rule-based or pattern-matching approaches. This pushes the frontier of automated code review, making it more effective against complex, context-dependent flaws.
  • Layer X, an enterprise browser security company, represented by its speaker, focuses on providing web and SaaS security controls, Data Loss Prevention (DLP), and phishing prevention. Their innovative approach involves integrating these capabilities "natively in the browser," as opposed to traditional perimeter-based web proxies. This addresses the evolving attack surface where the browser has become the primary interface for most business activities, especially with the proliferation of SaaS applications. Layer X specifically mentioned combating malicious extensions, which they likened to "the flash drives of 2004" in terms of their potential for risk. Technically, this involves deep browser introspection, real-time analysis of web content and user actions, sandboxing, and potentially leveraging browser APIs to enforce security policies, detect anomalies, and prevent data exfiltration or credential harvesting directly at the endpoint where user interaction occurs. Their mention of extensionpd.com implies a tool or resource for assessing browser extension risks.
  • The various Capture The Flag (CTF) events, including those supported by CTFD.io and Pros versus Joe's, provided hands-on technical challenges. CTFD.io awarded prizes like lockpicking sets, Raspberry Pi 5s, and a Raspberry Pi 500 plus keyboard, indicating challenges that span physical security, embedded systems, and general-purpose computing. The AI Village, hosted by Align, featured a CTF with a "tight finish," suggesting complex challenges related to AI security, such as adversarial machine learning, model poisoning, or secure AI deployment. Pros versus Joe's, described by Dichconomy, is an offensive/defensive CTF "modeled after CCDC" (Collegiate Cyber Defense Competition). This type of CTF involves blue teams defending live network ranges against sophisticated red team adversaries. Participants engage in practical tasks like system hardening, vulnerability patching, log analysis, incident response, threat detection, and maintaining service availability under active attack. These scenarios require deep technical skills across operating systems, networking, security tools, and analytical thinking, providing invaluable experiential learning in a simulated real-world environment.

While these technical areas were introduced rather than exhaustively explained in the closing ceremonies, their inclusion underscores the broad and dynamic technical landscape of cybersecurity that BSides NYC aims to cover and foster within its community.

Demo / Proof of Concept

▶ Watch: CTFD.io announces top three CTF competition winners (11:45)

As a "Closing Ceremonies" event, this particular talk did not feature any live demonstrations or proof-of-concept presentations of security vulnerabilities, tools, or research. The format was dedicated to organizational updates, acknowledgements, prize giveaways, and celebratory remarks.

However, it is important to note that the various Capture The Flag (CTF) competitions hosted throughout the BSides NYC conference, such as those organized by CTFD.io, AI Village, and Pros versus Joe's, inherently served as practical, hands-on "demos" for participants. These CTFs provided interactive environments where attendees could apply and test their security knowledge and skills in realistic scenarios, thereby acting as experiential proof-of-concepts for a wide range of offensive and defensive cybersecurity techniques.

Defensive Implications

▶ Watch: Final thanks to volunteers, call for next year (13:00)

The "Closing Ceremonies" itself, being an organizational wrap-up, did not directly present specific defensive implications in the manner of a technical security talk. However, the brief introductions from sponsors and the nature of the CTFs implicitly highlighted several critical areas where defenders should focus their efforts.

  • Strengthening Credential Management: Dashlane's presence as a password manager underscores the persistent and paramount importance of robust credential security. Defenders must advocate for and implement strong password policies, enforce Multi-Factor Authentication (MFA) across all critical systems, and consider enterprise password management solutions. Proactive monitoring for credential leaks in breach dumps, as offered by Dashlane, is also a crucial defensive layer, enabling rapid response to compromised accounts before adversaries can exploit them.
  • Evolving Application Security Practices: Gecko's development of an LLM static analysis tool for business logic vulnerabilities points to a maturing landscape in Application Security (AppSec). Defenders need to move beyond merely scanning for common vulnerabilities (e.g., OWASP Top 10) and invest in tools and methodologies that can identify complex, context-dependent flaws in an application's core logic. This implies a need for deeper integration of security into the Software Development Life Cycle (SDLC), with a focus on design reviews and advanced static/dynamic analysis that can understand business context.
  • Securing the Browser as a Primary Endpoint: Layer X's focus on enterprise browser security highlights the browser's critical role as both a primary attack vector and a conduit for Data Loss Prevention (DLP). Defenders must recognize that traditional network perimeter security is insufficient in a cloud-first, SaaS-heavy environment. Comprehensive browser security solutions are essential to protect against phishing attacks, malicious browser extensions, and unauthorized data exfiltration. Policies should be implemented to control extension usage, enforce secure browser configurations, and monitor browser activity for anomalies.
  • Prioritizing Hands-on Skill Development and Training: The strong emphasis on Capture The Flag (CTF) competitions, particularly the offensive/defensive CTF format of Pros versus Joe's, directly informs defensive strategy. Effective defenders require not just theoretical knowledge but practical, hands-on experience in incident response, system hardening, threat hunting, and maintaining operational resilience under pressure. Organizations should invest in continuous training programs, internal CTFs, and participation in external competitions to ensure their security teams possess the practical skills needed to combat sophisticated adversaries.
  • Leveraging Community and Collaboration: The entire ethos of BSides NYC, celebrated in these ceremonies, reinforces the power of community in cybersecurity defense. Sharing threat intelligence, collaborating on solutions, and fostering a strong network of security professionals are invaluable defensive assets. Events like BSides facilitate this collective defense, enabling defenders to stay informed, learn from peers, and contribute to the broader security posture of the industry.

Key Takeaways

  • Accessibility and Community Focus: BSides NYC successfully maintained its commitment to providing a free, accessible cybersecurity conference, a core tenet that significantly broadens participation and fosters an inclusive community.
  • Enhanced Program Quality and Diversity: The conference demonstrated significant improvements in its programming, evidenced by a higher acceptance rate for technical talks (12%) and a doubling of hands-on CTF offerings (from two to four).
  • Vital Role of Sponsors: Key sponsors like Dashlane, Gecko, Layer X, and Google Cloud not only provided essential financial support but also showcased innovative solutions addressing critical security challenges in areas such as identity management, application security, and browser defense.
  • Importance of Experiential Learning: The robust presence of diverse CTFs, including offensive/defensive scenarios like Pros versus Joe's, underscores the value of practical, hands-on experience for skill development in cybersecurity.
  • Growth and Operational Excellence: BSides NYC experienced a 14% increase in attendance and implemented sustainable practices, such as donating all leftover food and t-shirts, reflecting strong organizational leadership and community engagement.
  • Power of Volunteerism: The conference's success was overwhelmingly attributed to the dedicated, year-round efforts of Huxley Barbee and his extensive team of volunteers and partners, highlighting the indispensable role of community contribution.

About the Speaker(s)

Huxley Barbee served as the lead organizer for BSides NYC, a role that encompasses extensive planning, coordination, and community engagement over an entire year. During the "Closing Ceremonies," Barbee expressed gratitude to his team, family, and volunteers, emphasizing the collective effort required to bring such a large-scale, free conference to fruition. His leadership was instrumental in the conference's growth, including improvements in programming quality, increased attendance, and the expansion of hands-on learning opportunities like CTFs, all while upholding the BSides commitment to accessibility through $0 tickets.

The "Closing Ceremonies" also featured brief appearances from various individuals representing key sponsors and CTF organizers, each contributing to the overall success and diversity of the conference:

  • Joanna Chen, the Chief Information Security Officer (CISO) of Dashlane, represented the password management solution provider, highlighting their role in secure credential management and breach monitoring.
  • JJ from Gecko briefly introduced their work on an LLM static analysis tool for business logic vulnerabilities, showcasing innovation in application security.
  • Lucas Mason, CEO and Co-founder of Convu, spoke about their agent-based vulnerability management platform.
  • Christian and Kevin from CTFD.io were present to award prizes for their Capture The Flag competition, a long-standing supporter of BSides NYC.
  • Dichconomy, the organizer of Pros versus Joe's, detailed their offensive/defensive CTF, which focuses on providing realistic, learning-oriented challenges for blue teams.
  • Gina Moren Gambe from Google Cloud's CISO security engineering team represented Google Cloud, acknowledging their support and contributing to the prize pool.

Collectively, these individuals and their organizations represent the diverse expertise and collaborative spirit that underpin community-driven cybersecurity conferences like BSides NYC, reinforcing the event's mission to educate, connect, and empower security professionals.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

This is a closing ceremony, not a talk — grading it as research would be lazy. Judged on what it actually is — a community event wrap-up — it does its job: honest metrics, genuine gratitude, no obvious corporate theater. Nothing here will change how anyone defends a network tomorrow, but that's not what it was trying to do.

Heather Calloway (CISO) — PASS

This is a closing ceremony, not a session — gratitude remarks, prize giveaways, and attendance metrics have no governance, defender, or operational content to evaluate. There is nothing here for a CISO or security leader that a post-event recap email wouldn't cover.

→ Top-rated talks at BSides NYC 2025 (0x05)

All talks from BSides NYC 2025 (0x05)