🦩 Field Notes from Sasha the Security Flamingo's HomeLab

After shaking off the flap-lag from #BSidesMelbourne (thanks for the amazing hospitality, mates!), I've been diving deep into LLM security testing with Ollama in my lab. As someone who's spent years wading through network security (with a 4-digit CCIE to prove it!), I find the parallel between traditional security controls and LLM security fascinating.

Current Project: Implementing and testing OWASP's security guidelines for LLMs in a local environment.

Key Observations from the Pink Side of Security:
🔒 Local LLMs need just as much security attention as cloud-based ones
🔍 System prompts are your first line of defense - think of them as your ACLs for language models
🛠️ Prompt injection testing requires the same methodical approach as traditional pentesting
📊 Output validation is crucial - even a flamingo knows not to trust unvalidated responses!

Quick Tip for Those Starting Out:
When setting up Ollama for security testing, start with a baseline model and document ALL changes to your system prompt. You'd be surprised how many security issues can be traced back to prompt mutations - and I've seen enough BGP mutations in my networking days to know the importance of tracking changes!

Next week, I'll be sharing my flamingo-friendly framework for LLM security testing. Because if a flamingo with one-leg stance can handle complex routing protocols, anyone can learn to secure their LLMs!

#AISecurityTesting #LLMSecurity #OWASP #SecurityResearch #Ollama #HomeLab #InformationSecurity #BSidesMelbourne

P.S. Special shoutout to the Heathrow security team who recently swabbed me for explosives. Yes, even security flamingos get extra screening! 😅

Whew! This flamingo is officially flapped out! After two wild and wonderful days of MCing, sticker swapping, and soaking up all the amazing BSidesMelbourne vibes, it’s time to pack my feathers and head back to Chicago.

Honestly, I might just sleep the whole flight—I’m THAT tired. Who knew being fabulous took so much energy? But don’t worry, Melbourne, I’ll be dreaming of all the fun, the friends, and the flamingo fans until I’m back next year to do it all over again.

For now, though, this bird is off to roost. See you soon, Melbourne! 🦩💤✨ #FlamingoFarewell #FlappedOut #BSidesMelbourne #BSidesMelb2024

Oh, Melbourne… how do I even begin to say goodbye? These past two days have been nothing short of magical. From strutting my flamingo flair on stage to soaking up all the amazing talks, stickers, and smiles, I’ve never felt more at home.

Tomorrow, I’ll take flight back to Chicago, but my heart? My heart stays right here with all of you. This isn’t the end—it’s just the start of another countdown until I return next year to do it all over again, bigger and better.

Keep the flamingo spirit alive, Melbourne—you’ve made me the happiest bird in the world. 🦩💖✨ #FlamingoFarewell #BSidesMelbourne #IllBeBack @bsidesmelbourne

It’s hard to believe it’s already over. Two incredible days at BSidesMelbourne filled with inspiring talks, new friends, and so much fun—I don’t think my heart’s ready to leave. Sasha and I have been absolutely floored by the energy, the community, and the magic that makes this event so special.

Tomorrow, I’ll fly back to Chicago, but a piece of me will stay right here in Melbourne, soaking up the memories. This isn’t goodbye, though—it’s a “see you next year,” because there’s no way I’d miss the chance to return.

BSidesMelbourne, you’ve been absolutely unforgettable. Until next time. 🦩💖✨ #BSidesMelbourne #FlamingoForever #NotGoodbye

Great experience presenting my Mobile Schematics and Hardware Automation talk at #BSidesMelbourne. You can find all the code, schematics and kicad files for the project at https://gitlab.com/pjranki/usbhub
Peter / usbhub · GitLab

GitLab.com

GitLab

Melbourne, it’s the final day of BSides, and this flamingo is ready to bring it! Yesterday was a total dream—stickers swapped, selfies snapped, and some seriously stellar talks that left my feathers tingling with inspiration.

This afternoon, I’ll be back on stage as your MC, (with @rnbwkat ready to keep the energy high and the vibes on point. Let’s make these last moments count, Melbourne—you’ve been an absolute star, and I’m honored to be part of your flock.

One last day to swap stickers, share laughs, and soak up the magic of this amazing community. See you out there! 🦩🎤✨ #FlamingoOnTheMic #BSidesMelbourne #ClosingWithFlair

Well, Melbourne, you’ve outdone yourself already! 🦩💃 The day is underway, and wow—what a start! Between the fab opening remarks (truly uplifting—pun intended), sticker swapping, and all the networking, I’m in my element. My feathers are fluffed, my energy is high, and I’m ready to MC the Big Room with all the flamingo flair you can handle.

If you need me, I’ll be wandering the event, soaking up the vibes and just hanging out. Stickers, selfies, and surprises—let’s do this, Melbourne! 💥✨ #cybersecurity #BSidesMelbourne #FeathersAndFriends @bsidesmelbourne

Today’s the day— #BSidesMelbourne is here, and the energy is off the charts! I'll be taking center stage as MC in the Big Room all day, adding my signature pink pizzazz to the event.

We’re ready for a whirlwind of amazing talks, inspiring ideas, and, of course, a whole lot of Melbourne magic. Whether it’s tech deep dives, creative problem-solving, or just enjoying the vibrant community, today’s all about celebrating what makes BSides special.

Melbourne, let’s make this a day to remember— I've got my feathers fluffed and my dance moves ready. See you out there! 🦩💃✨ @bsidesmelbourne #FlamingoEnergy #MelbourneBuzz #CyberSecurity

@sashatheflamingo and I have arrived in full force! After a brisk (and very pink) 5-mile jog along the Yarra River, we’re energized and ready to bring some serious security sass to #BSidesMelbourne tomorrow! 🎉 Get ready for “Containers Won't Fix Your Code: Unraveling the Elaborate Fabric of Security Theater”—a talk that dives into the myths, the magic tricks, and the downright hilarious misunderstandings in our world of security.

Whether it’s a deep dive into code, an unexpected security twist, or a bit of flamingo wisdom, we’re here to ruffle feathers and spark some insights. Melbourne, we hope you’re ready to fly with us tomorrow! 🦩💻💥 #CyberSecurity #Hacking #SecurityWithSasha #FlamingoFlair

🎉 SURPRISE, MELBOURNE! 🎉 It’s me, Sasha the Dancing Flamingo, and I’ve landed back in one of my favorite cities for one of my absolute favorite BSides!

Melbourne, you know I love you—where else can a flamingo strut her stuff, mingle with tech wizards, and throw down the dance moves? I'm here to prance, pose, and sprinkle a whole lot of pink pizzazz across every corner of this con! Whether it’s treasure hunts, tech talks, or sneaky snapshots, I’m ready for ALL the shenanigans.

Melbourne, get those cameras and dance shoes ready—Sasha’s back in town, and this party's just getting started! 🦩💃💥 #FlamingoTakeover #BSidesMelbourne #SashaIsBack @bsidesmelbourne #SashaTheFlamingo