BSides Las Vegas

March 21-22, 2026

Las Vegas, NV

Join Semgrep at BSides Las vegas, where we’re a proud All In Sponsor. Swing by our table to say hello, pick up swag, and see how Semgrep’s AI-driven AppSec platform helps teams find and fix issues earlier, reduce noise across SAST/SCA/Secrets, and ship faster.

📍 The Tuscany
🗓 August 3-5

Here’s where you can catch the Semgrep team on stage:
Crypto is Fine. The Code Is Not: Real-World Cryptographic Failures
Diptendu Kar (Security Researcher)

Cryptography has a reputation for being intimidating, mathematical, and difficult to reason about. In reality, many cryptographic failures in production systems have very little to do with cryptography itself. They happen because of small implementation mistakes such as skipping a validation check, trusting unvalidated input, or selecting the wrong algorithm.

In this talk, we take a practical and data-driven look at the OWASP Cryptographic Failures category using GitHub Security Advisories collected as of January 2026. We begin with a brief overview of how these vulnerabilities are distributed across CWEs, then focus on two of the most common failure patterns. Using real vulnerable open source libraries, we examine signature verification bypasses and algorithm confusion bugs.

Rather than only showing exploits, this talk actively involves the audience. For each case study, we pause at key moments and work through the vulnerability together, asking questions like what inputs could be sent or what assumptions might be broken. Live demos and CTF-style challenges are used throughout, making the session interactive and approachable even without a cryptography background.

For more information, visit the BSides Las Vegas website.

Dr. Katie Paxton-Fear
Semgrep
Staff Security Advocate