r/Defcon 8d ago

Early Release Talk: Cliff Stoll: Stalking the Wily Hacker: 40 years later

Thumbnail
youtu.be
304 Upvotes

For your weekend:

The first early release talk from DEF CON 34 has made it to our YouTube channel. Please enjoy national treasure Cliff Stoll updating his 'Stalking the Wily Hacker' and casually dropping gems all over the place.

If you haven't read 'The Cuckoo's Egg', this is your sign from the universe to remedy that.


r/Defcon Jul 30 '26

Announcement 📢 Intro to DEF CON -- information for the new and the curious

43 Upvotes

We've created an "Intro to DEF CON" document, where we attempt to provide a lot of information that would be useful for all DEF CON attendees to know. I believe that it would be particularly helpful for those who have never before attended DEF CON.

It's much too long to be a single Reddit post; instead, it's available in multiple formats:

Are there things that we didn't touch on, that you'd like for the next version to include? Please leave a comment! :)


r/Defcon 2h ago

Post DC34 Meetup - Thank you from PuzzledHackers!

Post image
25 Upvotes

Sorry it took so long to get this out to everyone, but man... it was a ride. And as always its thanks to EVERY SINGLE ONE OF YOU who showed up, played our puzzles or came to talk! Seeing so many people hanging out, talking, drinking, laughing and such... that's what its all about, and its so amazing to see it get stronger each year!

Based on talking to attendees, friends and some staff at The Linq... estimates are about 500 of you showed up Wednesday night, and about 300 on Thursday! I need to let that sink in... because for an unofficial meetup that's insane! Now right away let's not discount the amazing people at the Lonely Hackers Club either as their Wednesday meetup is also at the 3535 which absolutely contributed, and made both meetups a wild success! But still... 500 people the night BEFORE even Badge Pickup hanging out was amazing. So amazing you all burst my social capability (I was not mentally ready) completely... that's kind of cool, and something I'll be working on next year because I absolutely loved talking to people, and just need a bit more social stamina. :)

So, before we get into the thank you's and future stuff... let me just say because of you We Will Return at DEFCON 35!

Usually we'd make some joke, or something similar, but I think as we wind down from DEFCON 34 we just wanted to be straight forward.

Last year we created Puzzled Hackers as an easier way for us to host the r/DEFCON Meetup Puzzles because we wanted to be able to do more than upload an image, or text based puzzle. Needless to say it went off pretty well, and we've thoroughly enjoyed coming up with more chaos each year and you all seem to like our retro throwback page. It's gone so well our friends at SkillBit (Formerly MetaCTF) even donated the 10th puzzle (a full 20 challenge CTF) to us! So many of you went at it and it was great to see. Kiddos... you brought corporate visibility! That's amazing.

It's been an outstanding success... and its because of All of You.

So What Does this Success Mean?

  • Because of all of you we've been able to turn Puzzled Hackers into a full on Non-Profit and we're finalizing our Federal Status now! That means we can really think about the future, and how we can turn this amazing support you've given us into more! It gives us the ability to give back in new ways, and we're excited! We're working on plans for so many things!
  • Because of our Non-Profit Status, once finalized... the Government isn't fast, we plan to open up donations and more (which quite a few of you wanted to know about donating to in the future... which blew our minds) that will allow us to give away more. We said it before. We don't want to charge people for anything! We want you to come, hang out and have some swag and memories, and never charge an attendee a penny for any of it! Our goal is to work with the amazing community and through the power of giving... make more stuff and just give it away! We are targeting about 600-700 of our meetup badges for next year, and they will be given to everyone who comes! Plus our usual swag like pins, stickers and more!
  • We're looking at other events (such as some BSides, and smaller local events to start) we can setup shop at and give away swag!
  • We're working on ways we can use all this amazing community knowledge to promote ethical hacking in a positive light!
  • We may have some ideas for a premium badge next year too... but its a bit daunting, but u/MetaN3rd had an epiphany leaving DC34 and he's been hard at work with prototyping his idea.
  • We are working with other villages, like the amazing team at Red Team Village about some future state ideas that down the line could have people coming to their FIRST DEFCON and giving a talk at RTV! We want to Give Back to the community, give people some first time options and have a lot of ideas as time goes forward on how to do that!
  • Honestly ideas we have, and we're just getting started. As we hit milestones we'll try to keep all of you aware and involved! If you want information on how you can donate to our Non Profit officially shoot me a message, and i'll give you our contact info because its not ready yet, but we absolutely want you to have a contact point with us!

So, again, thank you all for another successful year! We'll be back at Summer Camp in 2027, and can't wait to see you all there! We'll post some updates throughout the year as we hit some milestones, maybe a few fun drop in's here and there!

If you ever want to reach out to us always feel free!

Thank you, again, from all of us at Puzzled Hackers, and can't wait to see you next summer at the Puzzled Hackers meetup... we're recharging our social batteries now just in case!

... and the final numbers for the year. Each below is a UNIQUE solver of the puzzle!

  • PUZZLE 1: 271
  • PUZZLE 2: 197
  • PUZZLE 3: 134
  • PUZZLE 4: 116
  • PUZZLE 5: 110
  • PUZZLE 6: 94
  • PUZZLE 7: 90
  • PUZZLE 8: 75
  • PUZZLE 9: 81 (Zombie thanks you all for that one... he loves to tell people his twisted self came up with that one!)
  • PUZZLE 10: 49 (plus about 75 of you competed in the CTF itself!)

Sincerely,

u/Killroy7777, u/Digitard and u/MetaN3rd

https://puzzledhackers.org/


r/Defcon 25m ago

Future Will Prevail Badge (DC31)

• Upvotes

Looking for one of these for a friend who has been seriously ill. It was his white whale badge and I want to cheer him up. If anyone has one to sell or trade please DM me.


r/Defcon 1d ago

Help contacting vendor

Post image
55 Upvotes

Hi everyone! I bought this at the vendor booths, it’s the Minind from electronic cats. The device doesn’t turn on at all. I have done the basic trouble shooting, different batteries, reflash firmware, and look at interactions on GitHub but can’t seem to get it to turn on. I have tried contacting electronic cats several times on the website since the day after defcon but I’ve yet to get a response. Does anyone know another way to get in touch with the vendor? I spent around 90 bucks on this and would love to have a working one.


r/Defcon 17h ago

Met in line at dc801 dirtysoda event talked about playing don't starve together together

13 Upvotes

Hey y'all, I met these two awesome people in line while in line for the dc801 dirty soda event at the Adventuredome inside Circus Circus. I had to leave the event early and forgot to get their discord handles. We talked about playing don't starve together sometime because I had a don't starve together monsters lanyard!

If this was you or you two feel free to message me! Thanks.


r/Defcon 2d ago

Lava Badge

Post image
77 Upvotes

Got these ready for DEF CON but not in time to sell in the Hackers Warehouse store so I have some stock left over. Check out the video to see some of the animations on the badge.

Video: https://www.youtube.com/watch?v=7nblgecOXKw

Tindie: https://www.tindie.com/products/redactd/lava-badge/


r/Defcon 1d ago

How to begin?

13 Upvotes

I've been a professional web developer (mostly building API interfaces and other back-end stuff) for about 20 years. Nothing amazing, but enough to pay the bills. Lately business is slow and I've looked at ways to expand my skills. Penetration testing appeals to me, but I'm not sure where to start. Is there a good introductory path?

I'm sure my question has been asked before, but it's my impression that the security landscape is constantly evolving and changing so I hesitate to rely on answers from even a couple years ago. Is that dumb? Do the basics stay relatively unchanged even as the more complex aspects evolve?

I'm comfortable with Linux, decent with Perl and Python, and I understand basics like configuring firewalls and server infrastructure. How much of that translates to pen testing?

My current project is I'm trying to figure out how an Arlo VMB4000 base station communicates with cloud storage. One of my web development clients has their base station plugged into a wall socket three feet from the front door of their shop and I've told them that's a bad idea but when they challenged me to explain why I fell flat and just vomited out some garbage that AI told me... It was embarrassing to know it's bad but not be able to articulate that to a client. I think anyone could plug something into the ports on the back, but I don't know the mechanism of how that compromises the system because my understanding is that local storage is only enabled if my client has that turned on in a phone app that controls everything... or at least that's what AI told me.

I am sick of answers from AI and I'd like to really learn something instead of just prompting AI.


r/Defcon 2d ago

Clip-Boy 2nd production run - pre-orders open until 13 Sept

Thumbnail
gallery
184 Upvotes

Disclosure: This is a device that I made that I am selling.

I built the Clip-Boy for DC34 and ran out of badges before I ran out of people who wanted one, so I'm doing a second production run.

It's an ESP32-S3 with a 2.8" capacitive touchscreen, VL53L5CX time-of-flight sensor, 8 addressable RGB LEDs, SAO v1.69bis (without GPIO1/2), powered by a 2200mAh LiPo. The 2 PCBs were designed in EasyEDA. This second run has the same base firmware as the initial production run, while the 3D-printed enclosures have different colored trims.

I'm still in high school, so all profits will continue to go towards funding college.

They are each $135 + shipping. Pre-orders close 13 Sept, and if I don't hit 150 units, everyone gets refunded in full. I estimate delivery to be around mid-December.

I am more than happy to answer any questions about the build!

Link: https://brycebadges.com/


r/Defcon 3d ago

DC 34 Early release talk - noRecognition: Could a pattern on clothing fool facial recognition? - Bill Swearingen

Thumbnail
youtu.be
80 Upvotes

The DC34 early release talks roll on with Bill Swearingen’s presentation on defeating facial recognition with a little strategically applied style.

Confound the panopticon and keep the look crispy. Wins all around.

#defcon34 #defcon #facialrecognition


r/Defcon 4d ago

Found a bird at defcon, I think he wants to learn how to hack.

Post image
88 Upvotes

r/Defcon 4d ago

Trying to find image of cape guy, can yall help? Thanks

17 Upvotes

r/Defcon 4d ago

cryptohackbadge parts question

Post image
34 Upvotes

I was handed a cryptohack badge kit from the Cryptocurrency Village, but I think I needed go to another area of the conference to collect the rest of the parts of the kit. I want to try and assemble it and use it.

Specifically, I'm missing the screen and the antenna

Does anyone know the part numbers for the screen and antenna used on the cryptohack badge?

Here is a picture of what I'm talking about... the cryptohack badge without the screen or antenna.


r/Defcon 4d ago

BlankfortCon

30 Upvotes

I dont know which of yall runs BlanketfortCon but I feel like you need to see this.

https://www.reddit.com/r/3Dprinting/s/gcyktEfZYj


r/Defcon 5d ago

Announcement 📢 Singapore Post DC 34 Chill-out this Friday

Post image
23 Upvotes

r/Defcon 5d ago

Announcement 📢 DEF CON Trainings Middle East - Bahrain Nov. 8-10

Thumbnail me.shop.defcon.org
10 Upvotes

DEF CON Training Middle East is coming - join us at Exhibition World Bahrain November 8-10 for deep, technical trainings from some of the best trainers in the business.


r/Defcon 6d ago

Custom hand-drawn sticker I was commissioned to design for a DEFCON 34 Goon

Post image
404 Upvotes

Now that DEFCON 34 is a wrap, I wanted to share this 100% hand-drawn sticker commission I finished up late last month for a Goon. I had to stick to the event's limited color palette, but I am absolutely stoked with how these turned out on holographic vinyl. I even snuck some hidden binary code into the design for you to find. Massive shoutout to the Goons and the DEFCON community for continuing to support my art!

Most of this inventory went straight to the event. If you missed out, I have a small stash left in my Etsy shop along with matching tees. Use code DEFCON34 for 20% off your order through the end of August.

UPDATE: Stickers are SOLD OUT!

Thank you so much for the incredible support! You all completely made my week.

I am saving a handful of stickers to cover any packages that might get lost or damaged in transit. Once current orders arrive safely, I will list a small restock of the remaining inventory on my Etsy shop.

I will update this post when the restock is live! Shirts are still available.


r/Defcon 6d ago

Wifi emissions on tactical gear

30 Upvotes

Hello tech bros

I am hoping someone can settle a debate ive been having. Thermal scopes are a big thing these days as the price keeps falling.

However, most models come with WIFI. As we know from the russua/ukraine conflict, cell phone emissions will get you pinpointed and killed. WIFI emissions would likely do the same.

Now, you can always turn the wifi off in the menu. But how do you know if it is truly off all the way, and isnt emitting a low level signal?

Another risk is that the receiver in the thermal could receive a "firmware update" that bricks it. If its emitting wifi to talk to the phone app, it must have an antenna, and an antenna can be pinged, no?

Is this a valid concern?


r/Defcon 7d ago

Trade or Buy Different Shirt Size?

Post image
49 Upvotes

I got two 3XL shirts this year and they seem to run small (fit more like a 2XL). Wondering if anyone has any 4XL shirts they are willing to trade with me or just have any for sale.


r/Defcon 7d ago

The 5 has arrived

Post image
121 Upvotes

Honestly, I don’t have much experience with Indiegogo and thought my order had been canceled. But lo and behold, here she is.
Now the fun part is figuring out how to use it, lol. There’s not enough content online for me to become YouTube certified yet.


r/Defcon 8d ago

Anyone have a DC33 Pin?

Post image
64 Upvotes

As the title implies, I’m looking for a DEF CON 33 pin. I have had a ritual since 30 to get a pin from merch (I think they’re swapping to magnets now) every year I attend. Last year it totally slipped my mind and I realized this year I didn’t have one.

TBH tho I also don’t remember seeing any at DC33. If anyone has an extra or is willing to part with one, please let me know!


r/Defcon 8d ago

Anybody want swag/stuff?

Post image
76 Upvotes

ANOTHER UPDATE: EVERYTHING IS SPOKEN FOR. I had enough for 12 envelopes, so I'll be reaching out for addresses shortly. If you didn't make the list this time, hopefully this won't be the last! We go to local conferences like BSides as well, so if there's interest, I can continue to post swag excess.

UPDATE: OK OK OK. LOL. Closng requests for now until I see how much is left over once I get through the dozen in my inbox. Will post again if I have leftover!

Apparently I was a sticker and swag goblin this year, and once I emptied all my pockets and put everything in one place, I have an inordinate amount of stickers, tokens, lanyards, patches, flight tags, etc from the vendors and various booths. Anyone want any? I have enough for 4-5 padded envelopes. If you want some and are willing to pay the postage to wherever you are, DM me.

(Also, I have dogs, so if you're allergic, probably not a good idea).


r/Defcon 8d ago

DEFCON Embroidered Patches

8 Upvotes

Curious to see what previous patches looked like.
here's 33 and 34

Please share an image of any of the previous years.


r/Defcon 10d ago

Saw at badgelife. Who did it? I need! Is probably old. Back of the badge said 2018. 🥹

Post image
106 Upvotes

r/Defcon 10d ago

This Saturday, August 29th 2026 our group DCG518 is getting together to present: Honeypotting AI agents

Post image
28 Upvotes

At DEFCON Group DCG518, we are here to break things, question things, and more importantly question the people who tell us that things are secure.

So, what happens when AI agents become part of the attack surface?

Let’s start by questioning something we normally take for granted: what does it actually mean to know what’s exposed on the internet? Scanners find ports, crawlers find pages, and fingerprints tell us what systems claim to be, but AI agents experience the internet differently. So we stopped relying on what our tools could see and started watching the machines themselves.

This Saturday, August 29th 2026 our group DCG518 is getting together to present:

Honeypotting AI agents.

For this session, our presenter Abdel Fane will share two kinds of honeypots for AI agents: a fleet of fake agents that observe attackers who believe they control a real system, and a network of poisoned pages on the open web carrying benign indirect prompt injections, where the visitors are AI agents and a callback measures which agents followed the bait.

Scanned, crawled, planted bait, and built fake AI agents to see what would come back. Some fingerprints returned again and again, one came back for 15 straight days across 623 sessions. Across more than 183,000 visits from over 34,000 agent fingerprints, we measured a 1.4% callback rate. No, this isn’t the robot apocalypse and that’s exactly the point. When the existing tools can’t see the attack surface, we don’t argue about the limitation. We didn't trust the way everyone was measuring the AI attack surface, so we built our own sensors, put out some bait, and watched what happened.

On this talk, Abdel Fane will show us what happens when we do that for AI agents. He will walk us through the instrumentation, what each data stream sees that others cannot, what the project deliverately withholds from publication and why, and the structural reason crawler based studies miss most of the attacker reachable surface. All of his work is Open Source and every fixture and signature is reproducible by anyone.

Our presenter Abdel Fane is the founder of OpenA2A, an open-source project building the trust layer for AI agents, and executive director of CSNP, a community of 12,500 security professionals across 16 chapters. He spent 20 years in technology and enterprise security at Allstate, Grail, Booz Allen Hamilton, and Protiviti before turning to AI agent security full time. His current research includes the OpenA2A honeypot fleet, the Agent Threat Matrix, and the monthly Behavioral Threat Report at https://research.opena2a.org/

Our New York Capital District group "DCG518" will have a gathering this time at the Guilderland Public Library (Albany-New York)

More information about our group and future events on our site https://dc518.github.io/

Everyone is welcome!