DH
David Hook
Qui custodiam castelli per decennia tenuit
— who has kept the watch of the castle for decades
— On the schedule —
Dr. Tokenlove or: How Bouncy Castle Learned to Stop Worrying and Love the LLM
It has been hard to miss how much LLM-based tools have changed in the last twelve months and the subsequent effects on cyber security and software development. This talk will look at how the Bouncy Castle team have tried to cope with the transition of AI coding tools from "perhaps promising" to "enormously useful" for software development and in providing new approaches to analyzing and hardening a cryptography library. We will cover the ups and downs with real examples from development: the discoveries of what these tools can do, equally of what they cannot, and, most importantly, how to tell the difference. For better or worse, designing and implementing cyber security software will never be the same again.
— Compositor's note —
David Hook is an active developer and co-founder of the Bouncy Castle cryptography project, now in its 26th year, and has been working with the Java Cryptography APIs since their original publication in the late 1990s. In addition to his development work with Bouncy Castle, David has also given presentations and tutorials on the Java Cryptography framework and on the use of the Bouncy Castle APIs, as well as writing several articles, the books "Beginning Cryptography with Java", "Java Cryptography: Tools and Techniques" and the mini-ebook "BC FIPS in 100 Examples". He currently works at Keyfactor supporting the use and development of the Bouncy Castle APIs and led the charges that saw the APIs certified for both FIPS 140-2 and FIPS 140-3, as well as helping develop and oversee Bouncy Castle's PQC algorithm suite.