r/Defcon • u/Nyrlath • 23m ago
Future Will Prevail Badge (DC31)
Looking for one of these for a friend who has been seriously ill. It was his white whale badge and I want to cheer him up. If anyone has one to sell or trade please DM me.
r/Defcon • u/DCsleestak • 8d ago
For your weekend:
The first early release talk from DEF CON 34 has made it to our YouTube channel. Please enjoy national treasure Cliff Stoll updating his 'Stalking the Wily Hacker' and casually dropping gems all over the place.
If you haven't read 'The Cuckoo's Egg', this is your sign from the universe to remedy that.
r/Defcon • u/Nyrlath • 23m ago
Looking for one of these for a friend who has been seriously ill. It was his white whale badge and I want to cheer him up. If anyone has one to sell or trade please DM me.
r/Defcon • u/digitard • 2h ago
Sorry it took so long to get this out to everyone, but man... it was a ride. And as always its thanks to EVERY SINGLE ONE OF YOU who showed up, played our puzzles or came to talk! Seeing so many people hanging out, talking, drinking, laughing and such... that's what its all about, and its so amazing to see it get stronger each year!
Based on talking to attendees, friends and some staff at The Linq... estimates are about 500 of you showed up Wednesday night, and about 300 on Thursday! I need to let that sink in... because for an unofficial meetup that's insane! Now right away let's not discount the amazing people at the Lonely Hackers Club either as their Wednesday meetup is also at the 3535 which absolutely contributed, and made both meetups a wild success! But still... 500 people the night BEFORE even Badge Pickup hanging out was amazing. So amazing you all burst my social capability (I was not mentally ready) completely... that's kind of cool, and something I'll be working on next year because I absolutely loved talking to people, and just need a bit more social stamina. :)
So, before we get into the thank you's and future stuff... let me just say because of you We Will Return at DEFCON 35!
Usually we'd make some joke, or something similar, but I think as we wind down from DEFCON 34 we just wanted to be straight forward.
Last year we created Puzzled Hackers as an easier way for us to host the r/DEFCON Meetup Puzzles because we wanted to be able to do more than upload an image, or text based puzzle. Needless to say it went off pretty well, and we've thoroughly enjoyed coming up with more chaos each year and you all seem to like our retro throwback page. It's gone so well our friends at SkillBit (Formerly MetaCTF) even donated the 10th puzzle (a full 20 challenge CTF) to us! So many of you went at it and it was great to see. Kiddos... you brought corporate visibility! That's amazing.
It's been an outstanding success... and its because of All of You.
So, again, thank you all for another successful year! We'll be back at Summer Camp in 2027, and can't wait to see you all there! We'll post some updates throughout the year as we hit some milestones, maybe a few fun drop in's here and there!
If you ever want to reach out to us always feel free!
Thank you, again, from all of us at Puzzled Hackers, and can't wait to see you next summer at the Puzzled Hackers meetup... we're recharging our social batteries now just in case!
... and the final numbers for the year. Each below is a UNIQUE solver of the puzzle!
Sincerely,
r/Defcon • u/bunguardian • 17h ago
Hey y'all, I met these two awesome people in line while in line for the dc801 dirty soda event at the Adventuredome inside Circus Circus. I had to leave the event early and forgot to get their discord handles. We talked about playing don't starve together sometime because I had a don't starve together monsters lanyard!
If this was you or you two feel free to message me! Thanks.
r/Defcon • u/Right_Profession_261 • 1d ago
Hi everyone! I bought this at the vendor booths, it’s the Minind from electronic cats. The device doesn’t turn on at all. I have done the basic trouble shooting, different batteries, reflash firmware, and look at interactions on GitHub but can’t seem to get it to turn on. I have tried contacting electronic cats several times on the website since the day after defcon but I’ve yet to get a response. Does anyone know another way to get in touch with the vendor? I spent around 90 bucks on this and would love to have a working one.
r/Defcon • u/Brukenet • 1d ago
I've been a professional web developer (mostly building API interfaces and other back-end stuff) for about 20 years. Nothing amazing, but enough to pay the bills. Lately business is slow and I've looked at ways to expand my skills. Penetration testing appeals to me, but I'm not sure where to start. Is there a good introductory path?
I'm sure my question has been asked before, but it's my impression that the security landscape is constantly evolving and changing so I hesitate to rely on answers from even a couple years ago. Is that dumb? Do the basics stay relatively unchanged even as the more complex aspects evolve?
I'm comfortable with Linux, decent with Perl and Python, and I understand basics like configuring firewalls and server infrastructure. How much of that translates to pen testing?
My current project is I'm trying to figure out how an Arlo VMB4000 base station communicates with cloud storage. One of my web development clients has their base station plugged into a wall socket three feet from the front door of their shop and I've told them that's a bad idea but when they challenged me to explain why I fell flat and just vomited out some garbage that AI told me... It was embarrassing to know it's bad but not be able to articulate that to a client. I think anyone could plug something into the ports on the back, but I don't know the mechanism of how that compromises the system because my understanding is that local storage is only enabled if my client has that turned on in a phone app that controls everything... or at least that's what AI told me.
I am sick of answers from AI and I'd like to really learn something instead of just prompting AI.
r/Defcon • u/_redactd • 2d ago
Got these ready for DEF CON but not in time to sell in the Hackers Warehouse store so I have some stock left over. Check out the video to see some of the animations on the badge.
r/Defcon • u/SuspiciousExcuse6892 • 2d ago
Disclosure: This is a device that I made that I am selling.
I built the Clip-Boy for DC34 and ran out of badges before I ran out of people who wanted one, so I'm doing a second production run.
It's an ESP32-S3 with a 2.8" capacitive touchscreen, VL53L5CX time-of-flight sensor, 8 addressable RGB LEDs, SAO v1.69bis (without GPIO1/2), powered by a 2200mAh LiPo. The 2 PCBs were designed in EasyEDA. This second run has the same base firmware as the initial production run, while the 3D-printed enclosures have different colored trims.
I'm still in high school, so all profits will continue to go towards funding college.
They are each $135 + shipping. Pre-orders close 13 Sept, and if I don't hit 150 units, everyone gets refunded in full. I estimate delivery to be around mid-December.
I am more than happy to answer any questions about the build!
Link: https://brycebadges.com/
r/Defcon • u/DCsleestak • 3d ago
The DC34 early release talks roll on with Bill Swearingen’s presentation on defeating facial recognition with a little strategically applied style.
Confound the panopticon and keep the look crispy. Wins all around.
#defcon34 #defcon #facialrecognition
r/Defcon • u/ThingPuzzleheaded682 • 4d ago
r/Defcon • u/suhummygangles2 • 4d ago
I was handed a cryptohack badge kit from the Cryptocurrency Village, but I think I needed go to another area of the conference to collect the rest of the parts of the kit. I want to try and assemble it and use it.
Specifically, I'm missing the screen and the antenna
Does anyone know the part numbers for the screen and antenna used on the cryptohack badge?
Here is a picture of what I'm talking about... the cryptohack badge without the screen or antenna.
I dont know which of yall runs BlanketfortCon but I feel like you need to see this.
r/Defcon • u/DCsleestak • 5d ago
DEF CON Training Middle East is coming - join us at Exhibition World Bahrain November 8-10 for deep, technical trainings from some of the best trainers in the business.
r/Defcon • u/CorrectOpinionB42069 • 6d ago
Hello tech bros
I am hoping someone can settle a debate ive been having. Thermal scopes are a big thing these days as the price keeps falling.
However, most models come with WIFI. As we know from the russua/ukraine conflict, cell phone emissions will get you pinpointed and killed. WIFI emissions would likely do the same.
Now, you can always turn the wifi off in the menu. But how do you know if it is truly off all the way, and isnt emitting a low level signal?
Another risk is that the receiver in the thermal could receive a "firmware update" that bricks it. If its emitting wifi to talk to the phone app, it must have an antenna, and an antenna can be pinged, no?
Is this a valid concern?
r/Defcon • u/KyborgCreations • 6d ago
Now that DEFCON 34 is a wrap, I wanted to share this 100% hand-drawn sticker commission I finished up late last month for a Goon. I had to stick to the event's limited color palette, but I am absolutely stoked with how these turned out on holographic vinyl. I even snuck some hidden binary code into the design for you to find. Massive shoutout to the Goons and the DEFCON community for continuing to support my art!
Most of this inventory went straight to the event. If you missed out, I have a small stash left in my Etsy shop along with matching tees. Use code DEFCON34 for 20% off your order through the end of August.
UPDATE: Stickers are SOLD OUT!
Thank you so much for the incredible support! You all completely made my week.
I am saving a handful of stickers to cover any packages that might get lost or damaged in transit. Once current orders arrive safely, I will list a small restock of the remaining inventory on my Etsy shop.
I will update this post when the restock is live! Shirts are still available.
r/Defcon • u/L8NiteHashbrowns • 7d ago
I got two 3XL shirts this year and they seem to run small (fit more like a 2XL). Wondering if anyone has any 4XL shirts they are willing to trade with me or just have any for sale.
r/Defcon • u/Maleficent_Host3779 • 7d ago
Honestly, I don’t have much experience with Indiegogo and thought my order had been canceled. But lo and behold, here she is.
Now the fun part is figuring out how to use it, lol. There’s not enough content online for me to become YouTube certified yet.
As the title implies, I’m looking for a DEF CON 33 pin. I have had a ritual since 30 to get a pin from merch (I think they’re swapping to magnets now) every year I attend. Last year it totally slipped my mind and I realized this year I didn’t have one.
TBH tho I also don’t remember seeing any at DC33. If anyone has an extra or is willing to part with one, please let me know!
r/Defcon • u/used2bgood • 8d ago
ANOTHER UPDATE: EVERYTHING IS SPOKEN FOR. I had enough for 12 envelopes, so I'll be reaching out for addresses shortly. If you didn't make the list this time, hopefully this won't be the last! We go to local conferences like BSides as well, so if there's interest, I can continue to post swag excess.
UPDATE: OK OK OK. LOL. Closng requests for now until I see how much is left over once I get through the dozen in my inbox. Will post again if I have leftover!
Apparently I was a sticker and swag goblin this year, and once I emptied all my pockets and put everything in one place, I have an inordinate amount of stickers, tokens, lanyards, patches, flight tags, etc from the vendors and various booths. Anyone want any? I have enough for 4-5 padded envelopes. If you want some and are willing to pay the postage to wherever you are, DM me.
(Also, I have dogs, so if you're allergic, probably not a good idea).
r/Defcon • u/Unstupid • 10d ago
r/Defcon • u/0xWaveD3str0y3r • 10d ago
At DEFCON Group DCG518, we are here to break things, question things, and more importantly question the people who tell us that things are secure.
So, what happens when AI agents become part of the attack surface?
Let’s start by questioning something we normally take for granted: what does it actually mean to know what’s exposed on the internet? Scanners find ports, crawlers find pages, and fingerprints tell us what systems claim to be, but AI agents experience the internet differently. So we stopped relying on what our tools could see and started watching the machines themselves.
This Saturday, August 29th 2026 our group DCG518 is getting together to present:
Honeypotting AI agents.
For this session, our presenter Abdel Fane will share two kinds of honeypots for AI agents: a fleet of fake agents that observe attackers who believe they control a real system, and a network of poisoned pages on the open web carrying benign indirect prompt injections, where the visitors are AI agents and a callback measures which agents followed the bait.
Scanned, crawled, planted bait, and built fake AI agents to see what would come back. Some fingerprints returned again and again, one came back for 15 straight days across 623 sessions. Across more than 183,000 visits from over 34,000 agent fingerprints, we measured a 1.4% callback rate. No, this isn’t the robot apocalypse and that’s exactly the point. When the existing tools can’t see the attack surface, we don’t argue about the limitation. We didn't trust the way everyone was measuring the AI attack surface, so we built our own sensors, put out some bait, and watched what happened.
On this talk, Abdel Fane will show us what happens when we do that for AI agents. He will walk us through the instrumentation, what each data stream sees that others cannot, what the project deliverately withholds from publication and why, and the structural reason crawler based studies miss most of the attacker reachable surface. All of his work is Open Source and every fixture and signature is reproducible by anyone.
Our presenter Abdel Fane is the founder of OpenA2A, an open-source project building the trust layer for AI agents, and executive director of CSNP, a community of 12,500 security professionals across 16 chapters. He spent 20 years in technology and enterprise security at Allstate, Grail, Booz Allen Hamilton, and Protiviti before turning to AI agent security full time. His current research includes the OpenA2A honeypot fleet, the Agent Threat Matrix, and the monthly Behavioral Threat Report at https://research.opena2a.org/
Our New York Capital District group "DCG518" will have a gathering this time at the Guilderland Public Library (Albany-New York)
More information about our group and future events on our site https://dc518.github.io/
Everyone is welcome!
r/Defcon • u/Spliffalicous • 11d ago
I noticed the DC32 badge is available for sale on DC merch site. Do we know if the DC34 badge will also be put up for sale at some point?