@willenck Yes, I've heard back from the chair. It also is not obvious to me that cispa.saarland — the hosting site — is the same as cispa.de.
Look—I know Python well enough that I can probably spot (most) dangerous things. But that isn't the point. A security conference should not be training people to run random stuff that an apparently authoritative email address sent them. I just finished writing something that includes the following two adages:
Never trust a URL in an inbound email or text message: It’s extremely hard, and sometimes impossible, to tell if it’s legitimate or not.
Trust nothing you receive: If you’re concerned about information you’ve received, use information you already have to contact the organization.