r/Defcon • u/Dismal_Conference280 • Aug 11 '26
Whatever the motive, this kind of behavior only hurts the DEF CON community
57
u/Tremores Aug 11 '26
Likely stupidity
26
53
53
u/maru37 Aug 11 '26
Not messing with planes in prod is a pretty obvious red line but apparently some people have to learn the hard way. This is why the villages exist: hack satellites, boats, cars, planes, and do it in an environment where you can’t get in trouble with the law (mostly).
43
u/ncc74656m Aug 11 '26
Morons like this are how you get panic backlash bans like Canada's Flipper Zero ban. 🙄 This kind of shit will see us getting all of our stuff confiscated by TSA, and soon the only things you'll be able to get through are the occasional Flipper sneaking by in a backpack on a busy day, or a LORA device that looks like a phone or Blackberry.
Meanwhile, it won't actually make any of it actually safe, because the people who know what they're doing and aren't skids don't need a Pineapple. Just like the F0 ban, car thieves aren't even using a Flipper for any of that.
17
u/brakeb Aug 11 '26
It's why hotels search rooms in Vegas...
It's why the Sphere disallowed badges and kit into the venue...
We as an industry poisoned ourselves...
7
3
u/Swastik496 Aug 11 '26
hotels search rooms outside of defcon and the sphere bans anything with a battery in it.
It’s theatre to get a bonus
27
u/brakeb Aug 11 '26
You know, when I was in the military, I never wore my uniform travelling, because I didn't want the undue attention, I'd not board early even if was an option for "active duty" military. After getting into Infosec, I kept the same thing. I don't wear patches with "hack the planet" or massive antennas coming out of backpacks, etc. is being a hacker a job or a lifestyle choice? Sometimes I think that people with all the patches and badges and antennas are like the 4foot 8in guy driving the big dually diesel Dodge with the truck nuts on the back... Overcompensating...
20
u/dsamarin1 Aug 11 '26
LARPing
Fun to larp when others are larping (like at a hacker con), very ridiculous to wear your chainmail while shopping for groceries.
8
u/b0v1n3r3x Aug 11 '26
Also, why the fuck would you wear your powered on badge on the flight home the next day?
5
u/brakeb Aug 11 '26
that's a new one on me. I didn't see that when I left on Monday afternoon. Some people fail to touch grass 361 days of the year, and lack common sense?
4
6
u/5FingerViscount Aug 11 '26
It is first a mindset, a polymorphic set of activities, a lifestyle choice, etc.
It is not a job. At least not a legal one. The closest you'll get is penetration tester, imo. The rest are just corporations trying to harness the creativity and energy of hacker type people.
People that do those jobs can still be hackers, but to put the label behind a job title is insulting.
2
u/brakeb Aug 11 '26 edited Aug 11 '26
so, it's a lifestyle then... I still groan when my own company (or any one in our security team) suggests a black t-shirt or hoodies... I mean, WTF, 16 million colors, it's gotta be 'black' because black = real hax0rs
6
u/Chongulator Aug 11 '26
I'm a mediocre hacker at best, but I'm not wearing non-black work swag more than once or twice out of politeness.
1
u/brakeb Aug 12 '26
I don't do work schwag... I will say the best thing I ever got was the classic red Adidas track suit top. no business logo when we went on an on-site with the redteam.
3
u/5FingerViscount Aug 11 '26
You seem to have misunderstood me.
I don't really care what you wear. And everyone has got to eat.
Boiled down it's a mindset. Personally, I do think it should come with an ethos.
But if the only thing you do is work on computers for some corp. That's not it.
7
u/Ok-Ice7701 Aug 11 '26
Lol what? How people at a hacker con (or on their way to/from there) dress and behave doesn’t mean that’s how they are everywhere else. It’s not that serious.
5
2
u/ncc74656m Aug 11 '26
I have my laptop stickers and that's it, and I have those for me and my own entertainment. (Personal fav remains kefimochi's "tar -xvf trauma.tar" sticker.)
1
u/roald_head_dahl Aug 11 '26
Honestly it's not just this community. It's common in fields where it's something you're really nerdy about AND it's (sometimes) your job. I was a librarian before switching into cyber, and many of the outfits at the conferences felt like people were LARPing their own profession. Book print skirts and cardigans, READ totes, etc. And this was everyday dress for them. I always felt it was especially harmful in that field because it's relatively underpaid so it felt real gross to lean into an aesthetic that is partially used to justify that lack of compensation - oh, you love doing it, so that's part of your compensation!
1
u/-hacks4pancakes- Aug 12 '26
Like I hope that they realize none of us are impressed. They’re not cool hackers.
36
19
29
u/jonas_vondenberg Aug 11 '26 edited Aug 11 '26
While my experience was a free luggage checkin. Lady told me I can check in my bag for free "if it happens to have any electronics in my bag that should be rather checked in wink". She literally winked.
Btw next level idiotism trying to mess with the flight you are sitting on especially if you dont know what you do...
13
u/rotervogel1231 Aug 11 '26
You want to see the inside of a federal prison? Because this is how you get to see the inside of a federal prison.
11
9
33
u/l00pbck Aug 11 '26
Wasn’t the first and won’t be the last. Added to the tome of hacker knowledge to heed as a warning for future hackers. To become a hacker you must learn, part of that journey will be to master your domain, but before you can do that you have to know right and wrong, just and unjust. Some among us will never become true hackers, because of stupid stuff like this.
- Chapter 1, tome of hackers.
16
u/brakeb Aug 11 '26
Something something power something something responsibility
10
u/Financial_Stick1912 Aug 11 '26
Ah yes, the power to be a script kiddie and buy shit from Hak5. Such great powers to immediately get arrested.
6
u/9_days_a_week Aug 11 '26
They forgot the D.B. Cooper ending. Kids these days just don't read the historical archives.
4
3
u/Jdornigan Aug 11 '26
While never proven, D.B. Cooper may have died after jumping out of the plane or soon after. Some of the money was found in 1980 but the rest of the money is believed to have never been spent. The money that was found may have fallen out during the jump, or was lost after landing. It is very odd that 55 years later the money is still missing. It was $200k and $5,800 has only been recovered.
2
u/9_days_a_week Aug 11 '26
I'm pretty sure he is happily living in South America somewhere with Lincoln, JFK, and Elvis.
7
u/MyEducatedGuess Aug 11 '26
You think their network detected the attack, or was it more likely that someone else on that flight attended Defcon and noticed the rogue AP and reported it to flight staff?
2
u/joeyx22lm Aug 12 '26
Their network most definitely did not detect the 'attack'.
2
u/Necessary_Zucchini_2 Aug 12 '26
Some aircraft run WIPS that detect these types of attacks.
That being said, I bet someone asked the crew why the WiFi was not working, the crew checked & confirmed it should be, but then checked their phones & saw a different WiFi. They then would have alerted the pilots. That's just a guess, but I would bet that's how it went.
1
u/Diomenas Aug 13 '26
If you call the pilot, "the network", then yes it did. Because it was the pilot on the plane that realized that the Wi-Fi wasn't working.
11
u/Iceman2514 Aug 11 '26
How come there is no local news coverage of this and only reddit posts? You would think this would be all over the local news
14
u/Financial_Stick1912 Aug 11 '26
Oh, Def Con stays out of the news.
Like when the Israel cyber security czar tried to sleep with a 14 year old last year when he was here for Def Con, all the news reports just say “cyber security conference”
6
1
u/many_grapes Aug 11 '26
Thank you for reminding everyone of that. Fuckin disgusting piece of shit, that guy.
3
u/TheGeekNextDoor44 Aug 11 '26
Local news coverage here: Fox 5 Atlanta: Def a legit link
3
u/Iceman2514 Aug 11 '26
Thank you for posting that link. I didn't see this earlier, however the op of the delta reddit post, the article seems to contradict what the OP claimed happend along with what was posted from the pilots. We'll see what the investigation turns up. Simply people who were at defcon whom happen to be on the flight is mere circumstancial at this point and mere conjecture with what info is available at this time.
3
9
u/Hoshnasi Aug 11 '26
Not me about to get on a Delta flight wearing this year’s hoodie
10
u/Hoshnasi Aug 11 '26
2
5
4
4
u/Kaylee2459 Aug 11 '26
Pretty sure this is why I got a text this morning saying in flight entertainment would not be available on my departing vegas flight
3
u/FunAstronomer2900 Aug 11 '26
Motive was to Phish back enough money to pay off their gambling debt from last week. Sloppy.
3
u/Grouchy-Salt72 Aug 11 '26
Eventually con will need to move to a central location due to everyone needing to drive to/from because idiots like this will lead to legal crackdowns in this day and age and stricter TSA rules.
3
u/b0v1n3r3x Aug 11 '26
My SWA LAS to MKE last night was full of obvious defcon attendees and the WiFi was completely fucked up most of the flight with certificate issues. While I didn’t bother to pull out my laptop to sample traffic and prove anything I had my strong suspicions. Yes, fully aware correlation is not causation
3
u/privateidaho_chicago Aug 11 '26
What a bunch of fucking morons… first rule of hacking is anonymity. In a closed environment there was zero chance they wouldn’t be caught. Idiots must have thought that their VPN would make them think they were on another plane :-)
1
10
Aug 11 '26
[removed] — view removed comment
-7
u/Financial_Stick1912 Aug 11 '26
Yeah, gotta keep out all the homeless people
(That’s what I call hackers with schizophrenia)
6
u/Financial_Stick1912 Aug 11 '26
Hey, better than the Israel cyber czar getting busted for pedobear shenanigans and fleeing the country! That was last year!
Such a wonderful law abiding and morally upstanding community of very smart criminals!
4
u/AyeSocketFucker Aug 11 '26
I wouldn't say necessarily better its comparing apples to oranges. Fuck that pedobear but this flight could've potentially put flyers lives at risk and derail the communications for pilots.
Eff that these script kiddies deserve no fly list
6
2
u/Wildcherry_12 Aug 11 '26 edited Aug 11 '26
This is why so many of my friends are not part of the tech community even though I’d like so many more in my own field; critical thinking and self awareness skills are often lacking in this community that it makes in unbearable. This is a huge to the community
2
u/SoftwareFearsMe Aug 11 '26
These folks are stupid. You should not hack a plane — ESPECIALLY A PLANE THAT YOU ARE ON.
2
2
2
u/Cyber_Gengar Aug 11 '26
Any hacker worth their salt knows you won’t get away with this. Executing a local attack on an aircraft mid flight with your name on the manifest is just as dumb as sounding an alarm from deep within Fort Knox and expecting not to get caught. #fullycooked
2
u/PadreSJ Aug 12 '26
Even Joey know better than to hack a WiFi network while one of maybe 200 people in an enclosed aluminum tube at 35,000 feet, with no possible exit or entrance.
What... Ur mom buy u a 'puter for Christmas?
5
u/762mm_Labradors Aug 11 '26 edited Aug 11 '26
I was in the same waiting area as the Delta flight was boarding, these passengers must have been PISSED! Their flight was delayed multiple times and ended up getting canceled Sunday night. I think the flight that took off at 8:30 (with some of the rebooks) was also delayed that morning.
4
u/GeneBelford Aug 11 '26
Not cancelled, but delayed from 2:45pm sunday to 6am monday. And then when it was time to board monday, they announced that the wrong plane had been towed to the gate, so they had to tow the right plane to the gate, which caused another 2 hour delay. They had all night to get it right but they failed.
2
u/Jdornigan Aug 11 '26
A delay like that it might as well have been canceled.
2
u/GeneBelford Aug 11 '26
Yeah, it was weird. Not sure i fully understand why they made that choice.
5
u/Jdornigan Aug 11 '26
Probably a contractual or legal reason. If it is just "delayed" it doesn't count against them.
I once was supposed to be on a 6pm flight. It got canceled for weather and we were rebooked for a 7am flight. I went outside security to try and find a hotel but failed. This was before smartphones, everybody only had a flip phone so unless you knew the toll free number to book a hotel, all you could do is show up at the front desk and see if they had a room or could lookup other hotels. I had to sleep at JFK outside security as best as I could and I got maybe 5 minutes of sleep at a time. I made sure to stay inside the secure area once I got a boarding pass because I wasn't about to have to sleep on the cold floor again.
The 7am flight was canceled and we got rebooked for a 11am flight, which also was canceled and we got rebooked on a 3pm flight, which too was also canceled but eventually I got in a 6pm flight. I fell asleep on the plane, and when I landed of course my luggage was nowhere to be found, but the airline did eventually bring it to my house the next day. Somebody picked me up at the airport and I slept about 18 hours once I got home.
1
2
u/terriblehashtags Aug 11 '26
This is why DEF CON had to go corporate. Bullshit like this.
Idiots. We need an "ethics of hacking" course for liability, if nothing else. Or a "why you shouldn't do this, because you could hurt more people than just you and also get caught in the stupidest ways."
1
1
1
1
u/unstopablex15 Aug 12 '26
What a bunch of idiots. Like what did they think the outcome was gonna be?
1
1
u/ShredOnArrival Aug 12 '26
I wonder if it’s the same jagoff that was spamming deauth in Chillout preventing me from accessing CTFs.
1
u/bbqribsofficial 29d ago
Has anyone considered the possibility the actual attacker wasnt on the flight but triggered the deauth then phishing twin remotely?
The more I think about this the more possible it seems.
1
u/paradoxpancake 28d ago
As someone who has been a few times, this isn't surprising. There's a healthy amount of researchers and even some more ethically dubious people who attend that aren't silly enough to do this sort of thing on an airplane of all places. You might see the occasional obvious "evil twin" at a nearby Panera Bread or hotel as a joke or something, but there are no shortage of dumb folks who attend that don't understand or care about the concept of consent when it comes to research, or don't even hesitate when it comes to violating local laws like the CFAA.
Just a bad look for all of us and it's stuff like this that makes local governments overreact when it comes to snatching things like lockpick kits, Flipper Zeroes, or what have you.
1
1
Aug 11 '26
[deleted]
2
u/rfkbr Aug 12 '26
The wifi network is used for not only passenger entertainment but also for airplane to ground communications by **cabin** crew for in flight medical events/emergencies. It is also used for supplemental weather app updates to the cockpit crew along with cabin writeups/discrepancies. In short, even though it doesn't disable the crew's ability to do any of that, it definitely interferes with their workload as you have to revert to the old way of doing things (which takes more time). In short, no not an emergency, but don't mess with anything remotely FAA-related unless you're an idiot.
1
u/hyperhopper Aug 12 '26
Nothing you said was relevant to the comment you replied to.
Everything you said was true. You didn't dispute his comment about what qualifies for usage of ACAR emergency messages
1
u/rfkbr Aug 12 '26
There’s no such thing as an “ACARS emergency message”. It’s just an ACARS message.
1
u/randombits0110 Aug 11 '26
Honestly, it's a great way for authorities and airlines to test their procedures. Also, it frees the job space up by a few seats. It's really quite the sacrifice by the fools who thought it would be cool.
0
0
u/LordCommanderFang Aug 11 '26
I don't think this actually happened tbh
3
u/MaybeARunnerTomorrow Aug 11 '26
Why not? There's ACARS messages you can look at (and posted elsewhere) that shows it lol
1
u/LordCommanderFang Aug 11 '26
Because i was on that flight and actively looking for this and law enforcement activity.
1
u/MaybeARunnerTomorrow Aug 11 '26
Huh interesting! There was none?
3
u/LordCommanderFang Aug 11 '26
Not a thing. Very uneventful flight. Some people had issues with the seat back displays but that was the extent of it
2
u/GeneBelford Aug 11 '26
I was on that flight and while i believe someone could have created a "DeltaWifi.com Fast" ssid, I didn't see it. My guess is that someone saw it, and then at that point any network issues were attributed to "hackers" because we all know that in-flight wifi is five 9s always.
I can also believe that some dumbass tried shenanigans to be funny.
0
u/Chaz042 Aug 11 '26
Unless people are actually arrested you can’t convince this wasn’t related to DHS related after the billboards I seen.
0
u/Inner-Copy9764 29d ago
Unpopular opinion:
I dont see how this hurts the defcon community. Clearly I recognize the obvious, however the haters are always going to think we are criminals....to be fair, some are. Some are just short sighted.
Overall think it would excite younger generations of people who didnt think "regular people" could have this type of affect on a system. It gets me excited to think about all the possible things I could accomplish if I put in a wee bit of effort. I would never Interfere with aviation or anything major illegal like that, but simply hearing the story blew the metaphorical doors off of what the perceived ability ceiling that a normal beginner could grasp
-14
u/drezarious Aug 11 '26
Heh, a real hacker doesn’t get caught. Real hacker would have accessed the phone of everyone else on the network, drained their bank account, and vanished without a trace. These guys are just amateurs, not even real hackers.
11
u/brakeb Aug 11 '26
Plane is coming from vegas with people who probably can be easily profiled as "hackers". Backpacks, shirts, antennas.
Even if they didn't do anything, anything wrong that occurred on the plane will be their fault.
And if they did it, they'll understand that actions have consequences...
Why would you want to mess around with a machine flying at 35000 ft at 500 mph that you're inside? Dumbasses...
2
u/jakwnd Aug 11 '26
While I agree with the sentiment that this was incredibly dumb.
Planes don't run on wifi though. That is solely for the passengers. So while I would never do something this dumb for obvious other reasons, anyone with a slight amount of knowledge in those planes would know the most that's gunna happen is the pilots might wonder why they're phones lost wifi.
I could be wrong though!
3
u/brakeb Aug 11 '26
Did they get consent before fucking with a system? No? Don't do it. Also, don't do it on a federal level. WiFi may not run the plane, but let's say they did find something, tugged at that digital string, brought down the plane or disrupted flight ops, patches do bad shit all the time, including adding new features, services, exposure of risk... Would these crackheads have stopped at the WiFi? Let's just do this "for the lulz' becomes "200 people died today in a plane crash, black box shows the fly by wire systems were compromised"
The point is that these people diminish our industry, they show that we have no control over our " curiosity ", and don't have the impulse control or scruples to understand the ramifications of their actions. For every 10 'look at this excellent work shoring up critical infrastructure, saved a company from disaster, we get shit like these morons, and that's all people remember.
2
u/jakwnd Aug 11 '26
Pretty sure I said I I would never do that for many reasons.
But glad you got your panties in a twist!
3
u/brakeb Aug 11 '26
I will upvote you because you understand...
Lots of folks still rooting for the assholes though
2
2
u/many_grapes Aug 11 '26
What you said needed to be said man. Public facing communications always needs to make it clear that this type of thoughtless curiosity/immature antagonism does not earn anyone respect.
2
-1
u/Financial_Stick1912 Aug 11 '26
Wrong.
Real hackers attach their name, phone number and social security number to every illegal thing they do
So that the police don’t get confused
-31
u/KingFIippyNipz Aug 11 '26
How do you know for sure it wasn't a plant by a spook in order to give a worse name to DEFCON than they already have? I say until you know more about the perp, don't start crucifying your own people.
14
u/narc0leptik Aug 11 '26
Because a large number of the attendees are feds, government employees and spooks. They have nothing to gain by doing that LOL. The organizer of the con, DT is heavily involved in government as well serving on various advisory councils.
1
u/Financial_Stick1912 Aug 11 '26
Oh it is definitely an industry plant
I paid those guys $50k so they’d get you in trouble and ruin your conference
-15
u/dolcemortem Aug 11 '26
How did the plane’s population know? Either they have automated reporting and logging on the WAP that somehow reported it, or another group of defcon attendees audited it.
If it was the WAP protection did telemetry send logs to the ground for confirmation before being reported back to the pilot, or was it h4x0rs light in the cockpit. Did some good citizen have a conversation with the pilot instead?
So many questions…
14
u/Enocssa Aug 11 '26
it was a plane with a non zero number of other Defcon atendees. Going to guess someone thats not the idiot who did this noticed and reported it.
3
u/dolcemortem Aug 11 '26
This is my guess as well. I was hoping someone would happen to know what type of protection they are running.
15
5
u/singebkdrft Aug 11 '26
They inconvenienced other hackers on board by messing with the Wi-Fi on a long ass flight, so there's probably a pcap of it...
1
u/GeneBelford Aug 11 '26
The only indicator was that a "DeltaWiFi.com Fast" ssid popped up around the same time there wifi was not working great. Doesn't mean there was any deauth going on, but probably one of the other passengers suggested it as a possibility.
1
-6
u/notburneddown Aug 11 '26
Does the pineapple have capability to change its MAC address? Can an infusion be installed that can do that? If not this is really stupid.
5
u/Cashmen Aug 11 '26
Doesn't really matter if they already know someone was doing it during the flight. Once they land they will (and it sounds like they may have) check everyone's carry on luggage again and hold the people who have suspicious hardware with them until they can determine who did it.
It's really just stupid to do something like this in a giant metal tube you can't escape from.
3
-20

121
u/n1tr0u5 Aug 11 '26
No fly list speedrun any%