Skip to content
Carolina Code Conference
Served by F* (OCaml Unix) in 21ms

2024 speaker

Lydia Stepanek

Lydia Stepanek

Owner and Lead Software Engineer, Pen Loop, LLC

LLC

New York, NY

Lydia Stepanek brings over a decade of experience as a software and DevOps engineer, specializing in data-related technologies at places like MongoDB and Codecademy. Last year marked a significant shift in her career as she embarked on the journey of entrepreneurship, successfully launching two products, Is This Phishy and Too Phishy, both garnering 5-star ratings on Product Hunt.

She's dedicated to anti-phishing education, empowering users against fraud on her cybersecurity blog, which has made the front page of Hacker News multiple times.

Outside of work, Lydia finds balance in books and Brooklyn.

Visit website

2024 · lightning

Bridging the Gap: Developing Accessible Anti-Phishing Solutions

In the realm of cybersecurity, the battle against phishing attacks remains a perpetual challenge. While email providers offer spam filters and enterprises invest in sophisticated anti-phishing solutions, there's a noticeable gap in accessibility for the average internet user. This session delves into the journey of building an anti-phishing tool tailored for regular people, exploring the challenges encountered and the valuable lessons learned along the way.

At the outset of 2023, the absence of a free, user-friendly anti-phishing tool for everyday individuals sparked a realization: Why not build one? Thus began the journey of crafting an anti-phishing plugin designed to empower users worldwide. However, the path to success was far from straightforward. Initial attempts resulted in setbacks, with the first iteration falling short of expectations.

Through perseverance and a commitment to improvement, the anti-phishing plugin evolved, eventually garnering acclaim with 15 5-star reviews on Google and widespread adoption across diverse global communities. Yet, the journey was marked by numerous trials and tribulations, each offering valuable insights into the complexities of email analysis and phishing detection.

Throughout the session, I'll share firsthand accounts of the mistakes made and the invaluable lessons gleaned from each setback. From the intricacies of email headers to the subtleties of sender authentication protocols, we'll dissect the technical nuances that underpin effective phishing detection.

From the talk