<?xml version='1.0' encoding='utf-8' ?>
<!-- Made with love by pretalx v2026.1.2. -->
<schedule>
    <generator name="pretalx" version="2026.1.2" />
    <version>0.3</version>
    <conference>
        <title>NLUUG Spring Conference 2026</title>
        <acronym>nluug-voorjaarsconferentie-2026</acronym>
        <start>2026-05-07</start>
        <end>2026-05-07</end>
        <days>1</days>
        <timeslot_duration>00:05</timeslot_duration>
        <base_url>https://cfp.nluug.nl</base_url>
        <logo>https://cfp.nluug.nl/media/nluug-voorjaarsconferentie-2026/img/nluug-logo_vRiGCq5_Dwwvpm2.png</logo>
        <time_zone_name>Europe/Amsterdam</time_zone_name>
        
        
    </conference>
    <day index='1' date='2026-05-07' start='2026-05-07T04:00:00+02:00' end='2026-05-08T03:59:00+02:00'>
        <room name='Room 1' guid='baee871f-7067-5723-8dd5-e423f1759410'>
            <event guid='620a8c99-f153-5fa4-aae7-3387f5f8c281' id='178' code='QXWNBE'>
                <room>Room 1</room>
                <title>Getting started with CI/CD using Forgejo Actions and why this is important AF</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T09:00:00+02:00</date>
                <start>09:00</start>
                <duration>00:45</duration>
                <abstract>Continuous Integration and Continuous Delivery (CI/CD) have become essential practices for modern software development&#8212;but many teams still rely on centralized, proprietary platforms like GitHub or GitLab for all their build automation. In this talk, we introduce Forgejo Actions, a powerful, self-hostable CI/CD solution that is largely compatible with GitHub Actions. This makes it incredibly easy for beginners and experienced developers alike to get started with automated testing and delivery pipelines&#8212;without surrendering control of their code or infrastructure.

We will walk through the core concepts of Forgejo CI/CD: the Forgejo server, the Docker-powered runners, workflow files, and practical examples to get newcomers up and running. In the second half, we zoom out and explain why this matters &quot;AF&quot;: digital autonomy, reducing vendor lock-in, and avoiding dependency on increasingly centralized platforms. Migrating from GitHub Actions to Forgejo Actions is often surprisingly painless, giving developers the freedom to host their own pipelines while still syncing code to major platforms when needed.

Finally, we&apos;ll explore how Forgejo connects to the broader ecosystem&#8212;most notably Codeberg, the fast-growing European non-profit hosting platform with 200,000+ repositories and over 1,200 paying members (membership &#8364;24/year; &#8364;12 discounted). Together, Forgejo and Codeberg demonstrate that modern CI/CD doesn&#8217;t need to depend on Big Tech.

Attendees will walk away with a clear understanding of how to start implementing Forgejo-based CI/CD workflows today&#8212;and why doing so is strategically vital for long-term developer independence.

Links:
-  Forgejo: https://forgejo.org
- Codeberg: https://codeberg.org
- Codeberg e.V.: https://codeberg.org/Codeberg/org
- Forgejo Actions docs: https://forgejo.org/docs/latest/admin/actions/
- Submitter&#8217;s involvement (LibrePlan CI/CD work): 
-- https://github.com/LibrePlan/libreplan
-- https://www.libreplan.dev/</abstract>
                <slug>nluug-voorjaarsconferentie-2026-178-getting-started-with-ci-cd-using-forgejo-actions-and-why-this-is-important-af</slug>
                <track></track>
                
                <persons>
                    <person id='189'>Jeroen Baten</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://cfp.nluug.nl/media/nluug-voorjaarsconferentie-2026/submissions/QXWNBE/resources/NLU_voSzxt9.pdf">Slidedeck in PDF format</attachment>
                </attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/QXWNBE/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/QXWNBE/feedback/</feedback_url>
            </event>
            <event guid='08b0bdd2-9dca-52f9-9399-8f2231998d9f' id='173' code='YXXE8K'>
                <room>Room 1</room>
                <title>OpenKAT, a living digital twin that you can query over time.</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T09:50:00+02:00</date>
                <start>09:50</start>
                <duration>00:45</duration>
                <abstract>OpenKAT is seen by many as &apos;just another scanner&apos;, and while that is &apos;also&apos; true, its architecture and goals allow us to do things not many other tools allow users to do. In this talk, we&apos;ll explain how our scanning cycle works (and why that isn&apos;t the magic sauce), but more importantly how that feeds into the bitemporal normalized database on which all reporting, querying and deduction is build.
We&apos;ll show why OpenKAT gives you the ability to collect and maintain a digital twin of your infra, and how and why being able to proof the quality of that data fits into the upcoming legislative and  compliance frameworks.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-173-openkat-a-living-digital-twin-that-you-can-query-over-time</slug>
                <track></track>
                
                <persons>
                    <person id='185'>failbaitr</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/YXXE8K/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/YXXE8K/feedback/</feedback_url>
            </event>
            <event guid='ba06c0ee-fb09-5f9b-8fe2-30d72bc1e0f6' id='195' code='MDTH3S'>
                <room>Room 1</room>
                <title>What could *possibly* go wrong? Applying the Hacker Mindset to Kubernetes and GenAI.</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T12:00:00+02:00</date>
                <start>12:00</start>
                <duration>00:45</duration>
                <abstract>What do vulnerabilities in Kubernetes and GenAI have in common? And why is Jinja2 the problem? Together, we dive into the technical details of the Ingress Nightmare vulnerability and GenAI prompt injection. We discover the patterns that lead to those problems and discuss the lessons we learn to better secure our own systems.

Whether you write code, automate infrastructure, design architectures, implement GenAI in your products or manage people who do this for you, this presentation will give you much to think about. You will start looking at your own systems and organisation with the Hacker Mindset. You will find yourself saying &quot;What could possibly go wrong?&quot; a lot!

All subjects are presented with full technical details to really understand and appreciate what is going on, with clear high-level explanations for people who do not live on the command line every day.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-195-what-could-possibly-go-wrong-applying-the-hacker-mindset-to-kubernetes-and-genai</slug>
                <track></track>
                
                <persons>
                    <person id='205'>Frank van Vliet</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/MDTH3S/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/MDTH3S/feedback/</feedback_url>
            </event>
            <event guid='bc373409-7eb5-5763-9b50-7f62c740764e' id='188' code='RRQUMG'>
                <room>Room 1</room>
                <title>Linux &amp; TPM2 - praktische toepassingen</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T12:50:00+02:00</date>
                <start>12:50</start>
                <duration>00:45</duration>
                <abstract>Op veel moderne servers, desktop pc&apos;s, laptops maar ook virtuele (cloud) servers is tegenwoordig een tpm2 device aanwezig.  Tpm is een internationale standaard voor een crypto processor, ontworpen om hardware te beveiligen door middel van ge&#239;ntegreerde cryptografische sleutels en om cryptografische sleutels op een veilige plek op te slaan.
Hoewel de aandacht voor dit *&quot;Trusted Platform Module&quot;* is vergroot door de introductie van Windows 11, bestaat tpm al sinds 2003 (!) en wordt als standaard onderhouden door de Trusted Computing Group. Tpm is (dus) ook beschikbaar voor Linux en biedt interessante opties voor een veiliger gebruik van cryptografische sleutels of vertrouwelijke gegevens zoals bijvoorbeeld wachtwoorden.
In een wereld van toenemende *cyber dreigingen* zal worden toegelicht hoe tpm kan helpen om risico&apos;s te verminderen. Besproken zal worden:

- wat is tpm...
- ...en wat is het vooral *niet*
- tpm devices
- tpm en random number generator
- tpm en opslag cryptografische gegevens zoals bijvoorbeeld OpenSSL sleutels
- linux en tpm: beschikbare software en tools

In een *live demo* worden een aantal praktische toepassingen getoond waarin gebruik wordt gemaakt van tpm2:
- Opslag (OpenSSL) sleutels
- Veiliger opslag SSH priv&#233; sleutels
- Veiliger opslag Wireguard VPN sleutels m.b.v. *systemd credentials* en tpm
- Veiliger opslag applicatie configuraties (wachtwoorden!) m.b.v. *systemd credentials* en tpm
- Verbeteren entropy voor betere cryptografische sleutels</abstract>
                <slug>nluug-voorjaarsconferentie-2026-188-linux-tpm2-praktische-toepassingen</slug>
                <track></track>
                
                <persons>
                    <person id='200'>Winfried de Heiden</person>
                </persons>
                <language>nl</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/RRQUMG/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/RRQUMG/feedback/</feedback_url>
            </event>
            <event guid='f59d9e31-5a5b-5acb-a19b-73648ed5595b' id='177' code='RJAHMT'>
                <room>Room 1</room>
                <title>Suricata: 10 years later</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>00:45</duration>
                <abstract>In 2015 Victor Julien presented Suricata at NLUUG. A lot has happened since then, both in the project and in the world.

Suricata is a widely used open source (GPLv2) network security engine, mostly used as an IDS and IPS.

This talk go over the improvements in Suricata in the last 10 years and how network security remains critically important. It will cover new deployment and integration methods for Suricata like the firewall mode and the Suricata as a library effort. 

The talk will also go into the challenges of running a Open Source project in an independent organization (OISF) and hopes to have some feedback on the future of open source projects like Suricata in a world that is getting more complex.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-177-suricata-10-years-later</slug>
                <track></track>
                
                <persons>
                    <person id='188'>Victor Julien</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/RJAHMT/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/RJAHMT/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Room 2' guid='47ae1da6-6edb-5ce1-9648-bb7fe3f5c303'>
            <event guid='8a890d61-b9ba-5c80-a8c4-4eec6fb34524' id='181' code='QMRQVR'>
                <room>Room 2</room>
                <title>Outside In Guide to Engaging with Public Policy</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T07:30:00+02:00</date>
                <start>07:30</start>
                <duration>01:00</duration>
                <abstract>Our modern way of life depends on open source more than ever before. Public policy is tasked with establishing protections that support just these types of ecosystems. Yet these two key groups lack a common venue and understanding to ensure they are both successful. As governments worldwide draft rules affecting the world around us, the responsibility falls to all of us to bridge that gap or accept that the negative consequences of decisions made without benefit of high-trust dialogs. 

This session provides practical frameworks for effective policy engagement, tailored to technical community members. You&#8217;ll better understand policymaker motivations and hear examples of using standards versus dynamic mechanisms like reference implementations and transparency may serve better. Drawing on examples from collaboration with NCSC-NL and working on precursor standards to ETSI 303 645, Beau will discuss collaboration in context of European cyber policy like the latest Network and Information Security Directive (NIS2) and the Cyber Resilience Act (CRA). Open source proved that radical collaboration can build the internet; now we need to prove we can translate that model to shape the policies that govern it.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-181-outside-in-guide-to-engaging-with-public-policy</slug>
                <track></track>
                
                <persons>
                    <person id='192'>Beau Woods</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/QMRQVR/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/QMRQVR/feedback/</feedback_url>
            </event>
            <event guid='a499b256-604f-59a8-8a5b-6378fcb1076d' id='196' code='MEMRTY'>
                <room>Room 2</room>
                <title>postmarketOS, freeing yourself from big tech with a proper Linux distribution doing it &quot;the right way&quot;</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T09:00:00+02:00</date>
                <start>09:00</start>
                <duration>00:45</duration>
                <abstract>Phones are all around us. They&apos;re not just there to call your friends and family with anymore, but dominate our lives and they are the main way most people on this planet access the world wide web. However, currently that &quot;gateway to the internet&quot; is controlled by 2 American big tech companies: Google and Apple. Especially nowadays it shouldn&apos;t need explaining how that&apos;s a bad thing.
Enter *postmarketOS*, a Linux distribution &quot;doing it the right way&quot;. We&apos;re not controlled by a company, we do not force proprietary and internet connected services or even an online account at all upon the user and we actively try to work against the giant amount of e-waste that the current phone landscape is producing. We do this by using &quot;regular&quot; Linux with tools and UI&apos;s you already know and love from the desktop and porting phones away from their outdated kernels and proprietary drivers to the *mainline* Linux kernel and FOSS drivers like Mesa.

This talk will introduce the OS and show how far we&apos;ve gotten in the almost 10 years it exists now, and the goals we&apos;re currently working towards.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-196-postmarketos-freeing-yourself-from-big-tech-with-a-proper-linux-distribution-doing-it-the-right-way</slug>
                <track></track>
                
                <persons>
                    <person id='206'>Bart Ribbers</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/MEMRTY/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/MEMRTY/feedback/</feedback_url>
            </event>
            <event guid='d14eb45e-8fea-5c66-814a-5c217f9d1767' id='172' code='VUEEXQ'>
                <room>Room 2</room>
                <title>Digital Sovereignty in Action: Migrating Virtual Servers Without a Vendor Lock-In</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T09:50:00+02:00</date>
                <start>09:50</start>
                <duration>00:45</duration>
                <abstract>Digital sovereignty is commonly discussed in political or economic terms. This presentation treats it as a technical and architectural challenge that emerges from concrete implementation choices.

Through a case study, migrating virtual machines between a single cloud provider, we show how portability constraints (boot firmware, licenses and export restrictions),  arise even within a single  seemingly homogeneous environment, and how these constraints can lead to a vendor lock-in.

Building on this foundational work, we extended the OS migration platform to include multiple cloud providers. The focus is on enabling seamless migration and orchestration between providers while respecting your local compliance, performance, and sovereignty requirements.

By installing our existing open source migration platform on your server, you can migrate your server away from US hyperscalers by a single submit-click today.     

On our roadmap for this project we create a selection tool, to select the best cloud provider. We highlight the key metrics and trade-offs that must guide platform selection. We are using the methods from the academic world (MultiCriteria-Desicion Making, MCDM) to indentity importance of: interoperability, energy efficiency, legal jurisdiction, costs, and operational complexity. Our analysis identifies patterns that allow organizations to make informed, scalable choices rather than relying on vendor defaults.

The presentation concludes with a forward-looking view: a practical framework for designing a multi-provider, open-source-ready VM strategy. This approach helps European organizations retain flexibility, reduce hidden lock-ins, and align cloud choices with strategic and ethical objectives.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-172-digital-sovereignty-in-action-migrating-virtual-servers-without-a-vendor-lock-in</slug>
                <track></track>
                
                <persons>
                    <person id='183'>Mike Krom (DigitalNomadSky)</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/VUEEXQ/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/VUEEXQ/feedback/</feedback_url>
            </event>
            <event guid='034a056f-a13b-5274-a6b8-52fc4573974f' id='183' code='SEEHMQ'>
                <room>Room 2</room>
                <title>Platform- en leveranciers onafhankelijke Cloud met Haven</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T12:00:00+02:00</date>
                <start>12:00</start>
                <duration>00:45</duration>
                <abstract>Een bevlogen verhaal over de praktijk van ecosysteem gestuurd samenwerken aan Haven waarbij we de kracht van digitalisering inzetten voor het maatschappelijk belang. Haven is een open oplossing voor platform- en leveranciersonafhankelijke Cloud diensten. Haven is een speerpunt in de nationale digitale strategie en een bouwsteen in het overheid brede programma Generieke Digitale Infrastructuur. Haven biedt uniforme inrichting van Cloud technologie en biedt organisaties een toepasbaar exit plan.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-183-platform-en-leveranciers-onafhankelijke-cloud-met-haven</slug>
                <track></track>
                
                <persons>
                    <person id='195'>Jacco Brouwer</person>
                </persons>
                <language>nl</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/SEEHMQ/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/SEEHMQ/feedback/</feedback_url>
            </event>
            <event guid='516caf83-820d-5a8c-bac9-08df68250207' id='186' code='KSBJZM'>
                <room>Room 2</room>
                <title>Building a data lakehouse in the European cloud</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T12:50:00+02:00</date>
                <start>12:50</start>
                <duration>00:45</duration>
                <abstract>It&apos;s 2026 and all of a sudden your regular solution to build a data pipeline in Azure or AWS seems to have gone out of favour pretty fast. We want to store our data outside of the reach of the next autocrat.
But what are the alternatives? In this session we&apos;ll discuss how you can build a data lakehouse in the European cloud. And we want more: we want PySpark, notebooks and data visualization. Is that all possible?

For this data lakehouse solution we start with Kubernetes and object storage. You&apos;ll be surprised how many European cloud providers offer these products. Now we&apos;ll use Nessie as catalog and Trino as query engine. With Iceberg, our open table format, we can already create our first table.

Next we&apos;ll run Jupyter Hub for shared notebooks. And now we can cooperate on writing PySpark code. 
Great, but can we still use (local) PowerBI for data visualisation?

Yes, but that actually turns out a bit harder and for some reason expensive. We&apos;ll look at the alternatives for that.

This presentation is also suitable for visitors who are not data engineers or who have little knowledge of Kubernetes.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-186-building-a-data-lakehouse-in-the-european-cloud</slug>
                <track></track>
                
                <persons>
                    <person id='198'>Marcel-Jan Krijgsman</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/KSBJZM/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/KSBJZM/feedback/</feedback_url>
            </event>
            <event guid='60bc1e61-0e07-5ca8-bd02-853d3a179f1f' id='174' code='3RTNED'>
                <room>Room 2</room>
                <title>Praktijkervaringen met de verkiezingssoftware Abacus</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>00:45</duration>
                <abstract>De Kiesraad werkt aan Abacus, de open source software voor verkiezingsuitslagen en zetelverdeling. Abacus is bij 14 gemeenten tijdens de gemeenteraadsverkiezingen in 2026 gebruikt om resultaten te digitaliseren en op te tellen. Wat zijn de praktijkervaringen, hoe kijken de gebruikers ernaar? De software wordt open source ontwikkeld, de repo is publiek op https://github.com/kiesraad/abacus en iedereen kan PR&apos;s indienen - zowel de gebruikers als mensen van buiten. Deze openheid is een randvoorwaarde, maar je moet ook het land in en de feedback vanuit gebruikers en de community ophalen. Hoe pakt de Kiesraad dit aan en wat leren we hiervan? Het ontwikkelteam blikt terug op het ontwikkelproces en de eerste toepassing van Abacus en laat zien hoe je mee kunt helpen.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-174-praktijkervaringen-met-de-verkiezingssoftware-abacus</slug>
                <track></track>
                
                <persons>
                    <person id='184'>Niels Hatzmann</person>
                </persons>
                <language>nl</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/3RTNED/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/3RTNED/feedback/</feedback_url>
            </event>
            <event guid='75b6a2bd-cc20-5c9c-8288-f50c80472f6d' id='193' code='NGNFFP'>
                <room>Room 2</room>
                <title>What is it like to work for a Hyperscalar?</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T14:50:00+02:00</date>
                <start>14:50</start>
                <duration>00:45</duration>
                <abstract>Having worked for Google Switzerland in Z&#252;rich for 15 years, former NLUUG chair JC van Winkel returns to the Netherlands. What is it that makes Google Switzerland such an attractive employer for (former) NLUUG board members (Jos Visser and Bram Moolenaar started at Google 4 years before JC)?  What is it like to work for such a large tech company? Wat is different compared to other, smaller companies? And what has changed in the past 15 years?</abstract>
                <slug>nluug-voorjaarsconferentie-2026-193-what-is-it-like-to-work-for-a-hyperscalar</slug>
                <track></track>
                
                <persons>
                    <person id='210'>JC van Winkel</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments>
                    <attachment href="https://cfp.nluug.nl/media/nluug-voorjaarsconferentie-2026/submissions/NGNFFP/resources/Wor_TGXSYga.pdf">Slides and notes.</attachment>
                </attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/NGNFFP/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/NGNFFP/feedback/</feedback_url>
            </event>
            
        </room>
        <room name='Room 3' guid='3590bbc2-f883-5b92-8036-151f08b2aca9'>
            <event guid='5abe1745-536e-56fc-8ea4-d8f8c11a3c98' id='194' code='VJLAEK'>
                <room>Room 3</room>
                <title>Crystal Ball Vulnerability Prediction: A Wizard&#8217;s Guide to Foreseeing the Unseen</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T09:00:00+02:00</date>
                <start>09:00</start>
                <duration>00:45</duration>
                <abstract>As a **neuro-divergent practitioner of the arcane**, I wield a rare and potent magic: *pattern recognition*. Once, I channelled this power solely into the art of programming. But lo! My craft has since expanded into the **shadowy realm of security**, where, with a fair degree of precision, I can peer into the future itself.

You doubt me? Ah, but I have a tool to focus my visions: a **crystal ball**.

When I unroll the parchment of a security fix&#8212;be it for software, firmware, or some other enchanted artifact&#8212;I feed its secrets into my orb. There, the mists part to reveal deeper truths:
- Where more vulnerabilities lurk (*both kin and stranger*),
- Which other creations of the same artisan may falter,
- And, most crucially, whether this vendor&#8217;s name shall soon darken the scrolls again.

*&quot;But how does this sorcery work?&quot;* you ask, eyes alight with curiosity.
Ah, patience, seeker! In this session, those gathered (whether in hall or through *scrying glass*) may earn a glimpse behind the curtain.

**A warning, though:**
Like all magic, this craft is a double-edged blade. Evil wizards already stalk the digital shadows, and we must outpace them. Our duty?
- To **unmask the vulnerable**,
- To **expose the flaws**,
- And, unlike those who merely slap on bandages (or *&quot;patches,&quot;* as the mundanes call them), **forge solutions that endure**.

*&quot;What kind of solutions?&quot;* you wonder.
Oh, eager apprentice! All shall be revealed.
But know this: **we must be swifter, sharper, and bolder than the darkness**.
The fate of the realm depends on it.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-194-crystal-ball-vulnerability-prediction-a-wizard-s-guide-to-foreseeing-the-unseen</slug>
                <track></track>
                
                <persons>
                    <person id='204'>Arjen Lentz</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/VJLAEK/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/VJLAEK/feedback/</feedback_url>
            </event>
            <event guid='01d6379f-c71f-5f5f-b479-59b41a3b9701' id='169' code='C999YA'>
                <room>Room 3</room>
                <title>The Cascade DNSSEC Signing Solution</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T09:50:00+02:00</date>
                <start>09:50</start>
                <duration>00:45</duration>
                <abstract>Cascade is the new DNSSEC signing solution by NLnet Labs slated to replace OpenDNSSEC. It manages keys on disk or on HSMs, has sensible defaults, provides review hooks which allow us to use our preferred verification solutions, very decent logging, and it is designed to be easy to interact with and to communicate sensibly what it is doing.

In this talk I present Cascade, discuss some of its features, and I will of course demo signing a zone with it. 

If you&apos;ve been putting off DNSSEC-signing your zones, now&apos;s the chance to embark on that project!</abstract>
                <slug>nluug-voorjaarsconferentie-2026-169-the-cascade-dnssec-signing-solution</slug>
                <track></track>
                
                <persons>
                    <person id='179'>Jan-Piet Mens</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/C999YA/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/C999YA/feedback/</feedback_url>
            </event>
            <event guid='df331b51-46d3-587c-b985-7d28357c92f6' id='182' code='FNHNKC'>
                <room>Room 3</room>
                <title>JPEG XL: a deep dive</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T12:00:00+02:00</date>
                <start>12:00</start>
                <duration>00:45</duration>
                <abstract>Standardized in 2022, thirty years after the original 1992 JPEG format, the JPEG XL format brings many improvements and new features that are missing in the &apos;old JPEG&apos;: better compression, a lossless mode, support for alpha transparency (and many other kinds of &apos;extra channels&apos;), HDR, layered images, and animation, for example. Browser support for JPEG XL has recently gained momentum: both Chromium and Firefox are adding JPEG XL support, while Safari already supports it since 2023.

In this talk we&apos;ll dive deep into the actual codec design. How can JPEG XL reversibly recompress existing JPEG files while reducing their size by 20%? How does it achieve better lossless compression than PNG? How does it take advantage of modern processors (SIMD, multi-threading)? What was the design philosophy and which trade-offs were made in the design of this codec?
Those are some of the questions that will be answered.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-182-jpeg-xl-a-deep-dive</slug>
                <track></track>
                
                <persons>
                    <person id='194'>Jon Sneyers</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/FNHNKC/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/FNHNKC/feedback/</feedback_url>
            </event>
            <event guid='f2984c74-e858-574b-a078-76ad20dbe5a8' id='180' code='C3GG97'>
                <room>Room 3</room>
                <title>AsteroidOS - Linux on your smartwatch</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T12:50:00+02:00</date>
                <start>12:50</start>
                <duration>00:45</duration>
                <abstract>Smartwatches are cool, can be convinient, and at times useful too. But, most options either run propietary software, often requiring accounts on top of that, or are simple systems running on microcontrollers. This is where AsteroidOS differs. It&apos;s a full Linux computer running on your wrist, able to run fully local with connections being optional, yet having many of the features you&apos;d expect of a modern smartwatch. And as a Linux computer, it has the potential to be even more. There is good reason &quot;Free your wrist&quot; is the slogan of AsteroidOS. 

In this presentation I&apos;ll like to tell you a bit about this smartwatch distro, both on the user- as the technical side, and show some cool stuff you can do with it. And of course, I&apos;ll have a few different watches to show, altrough the total amount of supported watches is much bigger.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-180-asteroidos-linux-on-your-smartwatch</slug>
                <track></track>
                
                <persons>
                    <person id='191'>Jessica Tran</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/C3GG97/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/C3GG97/feedback/</feedback_url>
            </event>
            <event guid='207fb9af-8cbf-539e-961e-b0737818d561' id='190' code='LLWRZM'>
                <room>Room 3</room>
                <title>The CVE Illusion: Behind the Metadata Curtain</title>
                <subtitle></subtitle>
                <type>Talk</type>
                <date>2026-05-07T14:00:00+02:00</date>
                <start>14:00</start>
                <duration>00:45</duration>
                <abstract>Vulnerabilities are the &quot;bread and butter&quot; of security, yet the ecosystem providing this data is more opaque and more fragile than we realize. We track CVE numbers like stock prices, but do we understand the machinery behind them?
As the volume of reported vulnerabilities explodes and new registries emerge, we face a critical question: What happens if the feed stops?
This session looks beyond the surface and examines the layers of the global vulnerability ecosystem. We will move beyond the four-digit ID to explore the &quot;metadata soup&quot; that powers our scanners and risk assessments.
Key takeaways include:
&#8226;	The CVE Anatomy: A deep dive into the inner workings, history, and uncertain future of the CVE Program.
&#8226;	Metadata Clarified: A breakdown of what vulnerability metadata actually tells us, who generates it, and more importantly when it lies or misleads us.
&#8226;	The Registry Wars: Navigating the rise of new vulnerability databases and what this fragmentation means for open-source security.
&#8226;	Actionable Intelligence: How to separate high-signal data from the noise and build a more resilient security posture.
Whether you&apos;re a maintainer, a researcher, or a defender, it&#8217;s time we stop taking CVEs for granted and treated as gospel and start understanding the data that drives our industry.</abstract>
                <slug>nluug-voorjaarsconferentie-2026-190-the-cve-illusion-behind-the-metadata-curtain</slug>
                <track></track>
                
                <persons>
                    <person id='201'>Katie Noble</person><person id='202'>Jeroen van der Ham-de Vos</person>
                </persons>
                <language>en</language>
                
                <recording>
                    <license></license>
                    <optout>false</optout>
                </recording>
                <links></links>
                <attachments></attachments>

                <url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/LLWRZM/</url>
                <feedback_url>https://cfp.nluug.nl/nluug-voorjaarsconferentie-2026/talk/LLWRZM/feedback/</feedback_url>
            </event>
            
        </room>
        
    </day>
    
</schedule>
