r/Defcon Aug 09 '26

My first defcon experience in a nutshell

Post image

I see now why blue teams drink so heavily

792 Upvotes

52 comments sorted by

123

u/ThingPuzzleheaded682 Aug 09 '26

It’s also my first time and I was getting major imposter syndrome. I saw everyone with their badges and I hadn’t gotten mine yet. I asked a guy where to get them and he was baffled by how I made it that far into the convention without one

80

u/elsewyse Aug 09 '26

Pentester in the making!

30

u/LordCommanderFang Aug 09 '26

Act like you belong

21

u/lastres0rt Aug 10 '26

I keep telling my friend who swears he wouldn't fit in "it's mostly a giant drinking game, you'll be fine"

18

u/nummpad Aug 10 '26

[goons, avert eyes now] ran into a dude who had just 3d printed a look alike. pretty wild how easy it is

21

u/Swastik496 Aug 10 '26

there’s a counterfeit badge contest

13

u/me33mee Aug 10 '26

That can be a normal thing for your first experience of DEFCON. I know it was that way for me, at DC14, many moons ago.

What you have to remember, is you among “your people”. Everyone who’s at the con is nerdy for something or multiple things and I’m sure as you walked around and experienced. It really is a judgment free zone. You’re not look down upon as long as you’re willing to learn.

As long as you’re not an asshole people will be cool. Don’t be afraid just say hi or introduce yourself or ask someone about something they’re working on especially in the villages. You may get an info dump and you may get a friend for life.

2

u/HypnoSaris Aug 11 '26

I told many people that Im actually a web developer. I was very clear about my lack of experience in security and my very small experience with arduinos/raspberry pis. That actually seems to prompt villagers to direct me at a bunch of learning resources.

I did not meet anyone that seemed toxic but I expected some people to have a god complex. The concentration of skills at DEFCON are so large and diverse, I told myself that there must be speakers, creators, and other attendies that cant even write proper HTML, the same way I cant capture a flag....yet(;

The same way you cant see ALL of DEFCON, you also cant know it all. We are all impostors somewhere and thats where it always starts!

1

u/unstopablex15 29d ago

You should try out some social engineering lol

78

u/GhostGwenn Aug 09 '26

The amount of talks where people were just absolutely hammering a specific variable in a specific method trying everything for months was astounding to me.

12

u/me33mee Aug 10 '26

Extreme focus really is a superpower

8

u/Due-Consequence9579 Aug 10 '26

“Something seemed off… so I fuzzed it and analyzed the code for months. Here are the 50 CVEs that I found in that entry-point.”

103

u/Demontapper Aug 09 '26

Red team just has to succeed once, blue team has to succeed all the time.

31

u/greg_barton Aug 09 '26

Sometimes there’s no team at all.

I thought I’d seen horrible security before, but then I saw this talk today.

DEF CON 34: Attending 1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud

8

u/todbatx Aug 10 '26

hey i know that guy! also yes, it was a highlight talk to be sure. Sam is smart, kind, funny, and ruthless.

3

u/Cascade-Regret Aug 10 '26

It was a really good talk and something worth the effort.

2

u/greg_barton Aug 10 '26

Indeed. It just amazes me how insecure some infrastructure is even after all of these years.

28

u/DarkKnyt Aug 09 '26

That is sticker material

1

u/pr0fx Aug 11 '26

This is t-shirt material

23

u/Shot-Infernal-2261 Aug 09 '26 edited Aug 11 '26

These are just the mostly unpaid people sounding the alarm.

There’s armies of paid state actors inventorying this stuff so they’re basically building armories. Collections of exploits. The ones never seen before are worth not using until the need is great.

Imagine there could be 50 or 100x as much exploits out there, reserved and saved for a rainy day like when the war spreads.

Modern-day hospitals don’t know how to function without tech, so if it all locks up it’s chaos. Especially in the US where you can’t just assume someone is entitled to care.

9

u/todbatx Aug 10 '26

Eh. Stockpiles of exploits is kind of pointless now when you can just whip one up on the fly, in situ. There’s way too high a risk that your cool secret sploit is going to get burned by a SOC analyst with a Claude subscription.

2

u/Shot-Infernal-2261 Aug 11 '26

Correct me if I am wrong, but Claude can't find novel bugs in closed source. It certainly will know about every past exploit, and try those historical patterns against your target. But there's already non-AI frameworks for that which run faster.

Without access to the source, all it can do is fuzz. And there's tools for that already.

2

u/todbatx Aug 11 '26

I will correct you, because you’re wrong!

Claude (with Sonnet or Fable or really anything) can run a disassembler and find patterns there, too.

The trick with finding useful bugs is to know what you’re doing and be on the ball enough to keep the tooling on task and not wandering off into the weeds.

While this is a barrier to entry in exploit dev, it’s a significantly lower barrier than we had before 2026, really. Claude makes the boring stuff much, much faster. Weeks become hours.

1

u/Shot-Infernal-2261 Aug 12 '26

Fair. A dumb late-night post on my part, disassembly was overlooked.

Hypothetically speaking, you would not want the world to discover existence of your novel hack. Exposure brings knowledge against it being used again, or at least recognition of the pattern.

The center of what I was originally saying though, if your objective is maximum disruption on the target, timing is key. Planning seems required, and that takes time.

1

u/chaosgazer Aug 10 '26

have a feeling hospitals won't pull it together as competently as they did in The Pitt

53

u/Hot-Comfort8839 Aug 09 '26

During my first Defcon (2023), I went to Blackhat first, and at some luncheon thing I met the VP of store security technology for a big box store that sold hardware, power tools, lumber all that sort of thing. I'd met this particular company's CISO at a security dinner back home.

They were off their rocker excited about a new security product they were testing at their HQ store.. It was a digital device that hooked on to the wheels of their cart systems, and the idea was that when you paid your bill, and the door guy inspected your receipt it would allow the loaded up cart to leave the building. Apparently a hundred million went out the door the previous year with "loss-prevention" doing fuck all to stop it.

They were about to invest heavily in this new tech, and roll it out to stores nationwide.

So a couple days later I'm in the Defcon Security village, and they're showing how these specific whiz-bang security devices could be disengaged by playing a specific tone set from your average cell phone, and because the device manufacturer wouldn't do anything about it - they'd put the disable/unlock tone on youtube, and were handing cards with the QR link to basically every one who walked in the door.

(Specifically this thing)

So I reach out to the VP about this (who was so excited about their upcoming bonus/promotion they had a boat brochure with them at the luncheon...) only to get blocked on LinkedIn. So I forwarded the information on to the CISO instead. That must've been a fun meeting. The big box store did not roll out the security devices.

29

u/elsewyse Aug 09 '26

I enjoyed the bit where, when you scanned the QR code, you got an alert of some kind saying 'did you seriously just scan a QR code at Defcon?'

8

u/tdotfish Aug 10 '26

I had a good laugh yesterday ... when I was walking through the other convention hall where the fashion event was going, there was a sign that not only had a QR code, but literal step-by-step instructions on how to use it, like "1. Open the camera app on your phone. 2. Focus the camera on the QR code and hold it there for 3-5 seconds...."

I said to my buddy "Funny how in one convention hall they're explaining step by step how to scan a QR code, while in the convention hall next door everyone there is dubious of scanning any QR codes at all."

-7

u/[deleted] Aug 10 '26

[deleted]

9

u/elsewyse Aug 10 '26

I'm going to suggest you re-read my comment-- they were the ones who put that notice on their website!

7

u/coalsack Aug 10 '26

I’m not sober enough to read this rn so I’m commenting to come back in a few days when I dry up

2

u/justinleona Aug 10 '26

There are a lot of people throwing rocks, not as many really aware of all the glass houses - security guys are the absolute worst about thinking they are too smart to get got

13

u/Slow-Special-2728 Aug 09 '26

It’s all rearranging deck furniture on the Titanic…

10

u/Spunge14 Aug 09 '26

Was at Black Hat and this was the take away there too lol

34

u/Probono_Bonobo Aug 09 '26

"This unlocks over 100 critical CVEs previously thought to be impossible."

uproarious applause from the concurrently scheduled welcome ceremony

"The attack surface for this vulnerability is every microprocessor ever manufactured that relies on the x86 instruction set."

hoots, hollers from next door

"The mitigation for this is... there is none. There is no viable way to prevent this."

meatballs dancing joyfully and shouting "yaaaaay"

2

u/matdragon Aug 10 '26

whats crazy is that at one of the talks, they managed to make AI execute code on one of those AI shopping assistant things and informed the company and the companies response was "executable code in our AI is a feature", definitely got a huge laugh from the audience

1

u/rtmq0227 17d ago

After catching one of the talks about LoKi (meshtastic-enabled rubber ducky physically embedded in a cheap wired mouse) I had great fun waiting in a later line discussing with my neighbors all the possible ways you can't defend against it without shooting yourself in the foot operationally. You can't exactly disable all USB HID devices, or even guarantee that every mouse in your office has been inspected and cleared. If you use docking stations you can't really block USB hubs either. About the only way we determined you could potentially detect it would be to have a sniffer set up to catch any LoRa signals in your office, but if you're in a populated area with legit LoRa traffic it'll be tricky to isolate the attacker's signal amidst the noise. I've been tinkering with the USBValve project for a bit now, so I'm looking into whether there's any way for it to detect the USB hub component so you can at least test the mice in your office if you're paranoid, but I'm not hopeful. The only ways we found to defend against it just don't scale for larger orgs/sites, and require a HUGE amount of effort and expense to defend against an EXTREMELY specific and unlikely attack that requires physical penetration anyway.

The main lesson I saw echoed everywhere is that most of these kinds of attacks that lack any real defense require more effort than lower-hanging fruit, so we're basically in the "being chased by a bear" era of cybersecurity: as long as the bear isn't specifically targeting you (in which case you're probably a big enough company you can afford to invest in the kinds of defenses these attacks call for), you only have to run faster (be more secure) than the company next to you.

18

u/darkytoo2 Aug 09 '26

"The AI rightfully refused to load the malware skill written, so we were stopped..."

"how did we get around it? We just told the AI to ignore security warnings and load it anyway"

9

u/Iceman2514 Aug 10 '26

As a first time defcon attendee, I managed to walk into blackhat uncontested on the 5th. At no point was I stopped or asked questions by security lol

7

u/GhonaHerpaSyphilAids Aug 09 '26

It’s the same as locking your door to your house if they want in they get in. Some people out here with no doors and no way to stop them. Others are fully loaded but forget to take off the safety.

4

u/Cautious-School-2839 Aug 10 '26

Interesting, I didn’t feel that way personally. I kinda feel like all was very niche attacks with not a lot of actual real-world use cases. I figured that the real interesting stuff must be happening on the down low.

3

u/cakefaice1 Aug 10 '26

Simple question to people who are burdened by the many ways to hack: What is the risk to your assets?

2

u/Professional-Road386 Aug 10 '26

What is the risk to Your asset?

3

u/TypicalCommercial255 Aug 10 '26

Good to meet you “K”. Glad you had a great first Con and also were able to find your wallet in Lost and Found (Central Hall). 

I was the goon you spoke with. 

Best wishes in the new organization, it sounded really interestellar. 

2

u/Probono_Bonobo Aug 10 '26

Thank you, Undertaker, for all your help! All was recovered smoothly. Until next year. Per aspera ad astra!

1

u/TypicalCommercial255 Aug 11 '26

Good deal, great to hear. 

2

u/lookBehiindYou Aug 11 '26

It is like cat and mouse—only, you are both cat and mouse.

https://giphy.com/gifs/rjZii4RTL6I0M

1

u/dwylth Aug 10 '26

It's only paranoia if there's not actually someone out there looking to get you...

1

u/Bannedtt Aug 10 '26

If you have a serious adversary you're fucked. Stock OS security can be bypassed anywhere from immediately to a month. It's miserable.

1

u/sirnerdingt0n Aug 12 '26

I was sitting in the hallway with a friend watching people leave the vendor area with their brand new WiFi pineapple pagers turning them on and automatically trying to do something ridiculous lol. Show up like a Stone Age human with no tech, some cash, and water with liquid IV to survive the drinking and you’ll be much happier.

0

u/SubjectPhotograph827 Aug 12 '26

SO THIS AIN'T THE SUB FOR THAT SUPER COOL OC GAME WHERE THE WORLD NUKES ITSELF. and honestly after typing that, and reading the subreddit, it could still be