BSidesPDX-2025

Corey Le

Corey has been in the Information Security space for over 20 years and building software applications even longer. He spent years on the east coast as a principle security consultant with the Interpidus Group before joining the in-house security teams at places like Etsy and Simple. He spent 6 years at a unicorn tech company becoming their Director of Product Security. Currently living on the Oregon Coast, he enjoys tinkering with PCB designs in KiCad, signing off-key punk songs with his son, and trying to convince people that video games can be art.

Corey has previously presented at BlackHat, CanSecWest, Yandex, and BSidesRoc.


Session

10-24
13:00
20min
Securing GraphQL from Design to Production
Corey Le

Learn to secure GraphQL interfaces by looking at design decisions and actual attacks. This talk dives into a half dozen GraphQL services that were deployed at a tech unicorn. You'll learn practical defensive strategies, discover where common security controls fall short, and see the fall out from attack scenarios that were missed.

Talk 1
Talk 1