WEBVTT - The Def Con Story

0:00:04.160 --> 0:00:07.520
<v Speaker 1>Get in texts with technology with tex Stuff from stuff

0:00:07.520 --> 0:00:14.120
<v Speaker 1>works dot com. Hey there, and welcome to tex Stuff.

0:00:14.160 --> 0:00:17.480
<v Speaker 1>I'm your host, senior writer, Jonathan Strickland. I worked for

0:00:17.560 --> 0:00:21.120
<v Speaker 1>how stuff works dot com been recording text stuff since

0:00:21.280 --> 0:00:25.080
<v Speaker 1>two thousand eight, and I cannot believe that I've gone

0:00:25.200 --> 0:00:29.480
<v Speaker 1>that long without covering this next topic. I'm talking about

0:00:30.080 --> 0:00:33.680
<v Speaker 1>def Con. It's a really interesting subject. I've touched on

0:00:33.720 --> 0:00:35.600
<v Speaker 1>it once or twice in the past, and I've talked

0:00:35.600 --> 0:00:38.760
<v Speaker 1>to people who have presented at def Con or attended

0:00:38.840 --> 0:00:42.400
<v Speaker 1>def Con. I personally have never been to one, but

0:00:42.479 --> 0:00:44.479
<v Speaker 1>I felt like now was the time. It would be

0:00:44.520 --> 0:00:46.400
<v Speaker 1>really cool to take a look at a conference filled

0:00:46.440 --> 0:00:50.600
<v Speaker 1>with people who know all about bypassing security and getting

0:00:50.640 --> 0:00:55.400
<v Speaker 1>to all of your precious secrets. These are hackers and

0:00:55.480 --> 0:01:00.120
<v Speaker 1>security experts who can identify vulnerabilities and weak implementations and

0:01:00.160 --> 0:01:03.200
<v Speaker 1>then exploit them. It's a conference where if you're not careful,

0:01:03.560 --> 0:01:07.200
<v Speaker 1>you'll be publicly mocked for your poor security protocols. And

0:01:07.240 --> 0:01:11.000
<v Speaker 1>it's called def Con. Jeff Moss, who is a hacker

0:01:11.040 --> 0:01:14.600
<v Speaker 1>who used the handle the dark Tangent, founded the conference

0:01:14.600 --> 0:01:19.720
<v Speaker 1>back in Moss operates some bulletin board systems or bbs

0:01:19.840 --> 0:01:22.759
<v Speaker 1>is back in the early nineties on Phyto networks, and

0:01:22.800 --> 0:01:25.520
<v Speaker 1>you may have my brother has forgotten what these bbs

0:01:25.640 --> 0:01:28.360
<v Speaker 1>is would like. Things changing so scoring nowadays and people

0:01:28.440 --> 0:01:30.760
<v Speaker 1>quick to forget, So I thought maybe we should go

0:01:30.840 --> 0:01:33.040
<v Speaker 1>back and talk about what the heck is a bulletin

0:01:33.080 --> 0:01:36.840
<v Speaker 1>board system? What is phto net well, A bulletin board

0:01:36.880 --> 0:01:40.160
<v Speaker 1>system is a pretty simple concept. You have a host

0:01:40.240 --> 0:01:44.200
<v Speaker 1>computer running some special software, and that software sets aside

0:01:44.240 --> 0:01:48.320
<v Speaker 1>certain assets for the bulletin board system or BBS, such

0:01:48.320 --> 0:01:53.600
<v Speaker 1>as hard drive storage space and maybe uh filing system

0:01:53.640 --> 0:01:56.720
<v Speaker 1>of some sort of navigation system, a user interface, if

0:01:56.720 --> 0:02:00.760
<v Speaker 1>you will, and this would typically include this message board system.

0:02:00.760 --> 0:02:05.200
<v Speaker 1>It allows participants to communicate with each other, typically asynchronously,

0:02:05.920 --> 0:02:07.920
<v Speaker 1>which means that you could leave a message and then

0:02:07.960 --> 0:02:09.919
<v Speaker 1>the next time someone checks in they could read their

0:02:09.919 --> 0:02:12.880
<v Speaker 1>messages respond to them. The next time you check in

0:02:12.960 --> 0:02:16.520
<v Speaker 1>you could see the responses, very similar to email um

0:02:16.800 --> 0:02:20.320
<v Speaker 1>and many bbs is would only allow one person to

0:02:20.400 --> 0:02:23.200
<v Speaker 1>connect to the bbs at a time because you actually

0:02:23.240 --> 0:02:26.680
<v Speaker 1>were using dial up modems in those days. So you

0:02:27.000 --> 0:02:29.240
<v Speaker 1>hook up a dial up modem to your computer, it

0:02:29.280 --> 0:02:33.160
<v Speaker 1>would call out a number using the telephone system. The

0:02:33.280 --> 0:02:37.000
<v Speaker 1>plain old telephone system or pots, if you will, and

0:02:37.360 --> 0:02:41.360
<v Speaker 1>that would dial up the host computer's modem, which would

0:02:41.360 --> 0:02:45.200
<v Speaker 1>then allow you to connect. And some would have the

0:02:45.200 --> 0:02:48.400
<v Speaker 1>capacity for multiple connections, maybe up to three or so,

0:02:48.760 --> 0:02:51.000
<v Speaker 1>but a lot were just single connections and you would

0:02:51.480 --> 0:02:53.560
<v Speaker 1>be you would have to wait if someone was already

0:02:53.560 --> 0:02:54.959
<v Speaker 1>on there, you get a busy signal and you'd have

0:02:55.000 --> 0:02:59.400
<v Speaker 1>to try again later. Uh. Many BBSs would include simple

0:02:59.520 --> 0:03:03.079
<v Speaker 1>games or drives where you could upload or download files

0:03:03.120 --> 0:03:06.960
<v Speaker 1>at incredibly slow speeds. Imagine the Internet if it were

0:03:06.960 --> 0:03:09.079
<v Speaker 1>limited to just the stuff that was on this one

0:03:09.080 --> 0:03:13.920
<v Speaker 1>guy's computer across town. And you kind of get the idea. Now,

0:03:13.960 --> 0:03:15.880
<v Speaker 1>because we're talking about the era of dialot modems, we're

0:03:15.880 --> 0:03:18.799
<v Speaker 1>also talking about time when long distance calls were expensive

0:03:19.440 --> 0:03:21.720
<v Speaker 1>and there was no free long distance in those days

0:03:22.040 --> 0:03:25.040
<v Speaker 1>unless you were getting around the system. But we'll get

0:03:25.040 --> 0:03:29.280
<v Speaker 1>into that. So you're spending money in order to connect

0:03:29.280 --> 0:03:32.280
<v Speaker 1>to anything that's not within your area code. Typically most

0:03:32.280 --> 0:03:34.400
<v Speaker 1>people would just stick to bbs is that we're in

0:03:34.680 --> 0:03:37.440
<v Speaker 1>the area codes that were in the local dialing options

0:03:37.480 --> 0:03:40.080
<v Speaker 1>that they had, and initially that was the only way

0:03:40.080 --> 0:03:43.560
<v Speaker 1>you could check messages on other bbs is you could

0:03:44.000 --> 0:03:46.880
<v Speaker 1>you'd have to call into that BBS. So if you

0:03:46.920 --> 0:03:49.720
<v Speaker 1>have a friend who's three cities over and they're technically

0:03:49.720 --> 0:03:52.760
<v Speaker 1>in long distance range and you want to check any

0:03:52.760 --> 0:03:56.200
<v Speaker 1>messages they were leaving for you on the their local BBS,

0:03:56.560 --> 0:03:58.240
<v Speaker 1>you had to call a long distance or they had

0:03:58.240 --> 0:04:01.240
<v Speaker 1>to do the same for your low gold BBS. There

0:04:01.320 --> 0:04:04.880
<v Speaker 1>wasn't really any inner connectivity in the early days, So

0:04:04.960 --> 0:04:07.480
<v Speaker 1>if your BBS of choice was called I don't know,

0:04:07.560 --> 0:04:11.000
<v Speaker 1>let's say it's moss Eisley Cantina, So yours is moss

0:04:11.040 --> 0:04:15.040
<v Speaker 1>Eiseley Cantina, my BBS of choice is called the Raven,

0:04:15.680 --> 0:04:18.000
<v Speaker 1>we wouldn't be able to leave messages for each other

0:04:18.120 --> 0:04:21.680
<v Speaker 1>unless we were willing to visit the other person's favorite BBS,

0:04:21.760 --> 0:04:24.680
<v Speaker 1>and thus we'd be unable to share our love of

0:04:24.680 --> 0:04:28.200
<v Speaker 1>Harrison Ford, who obviously inspired the names of both of

0:04:28.240 --> 0:04:31.960
<v Speaker 1>those bbs is and bonus points if you know what

0:04:32.160 --> 0:04:37.040
<v Speaker 1>the Raven is. But either way, one of us or

0:04:37.120 --> 0:04:39.279
<v Speaker 1>both of us would have to spend money on a

0:04:39.320 --> 0:04:42.400
<v Speaker 1>long distance call if we wanted to drop a communication

0:04:42.480 --> 0:04:45.760
<v Speaker 1>to the other. But then along came Fido net, and

0:04:45.839 --> 0:04:48.120
<v Speaker 1>this was a network designed in the nineteen eighties to

0:04:48.200 --> 0:04:52.280
<v Speaker 1>allow different BBS is to have exchanges between them. So

0:04:52.440 --> 0:04:56.480
<v Speaker 1>if both the Moss Eiseley Cantina and the Raven connected

0:04:56.880 --> 0:05:00.479
<v Speaker 1>through Fido Net, you could communicate between the two. You

0:05:00.520 --> 0:05:03.880
<v Speaker 1>could leave a message for your friend over at In

0:05:03.920 --> 0:05:06.320
<v Speaker 1>my case, you would leave a message on the Raven

0:05:06.360 --> 0:05:09.359
<v Speaker 1>for me, and the message you left at Moss Eisley

0:05:09.440 --> 0:05:12.120
<v Speaker 1>Cantina would be relayed to the Raven. I could read

0:05:12.160 --> 0:05:14.280
<v Speaker 1>your message. I could then send a message to you

0:05:14.320 --> 0:05:16.640
<v Speaker 1>and it would be relayed to Moss Eisley Cantina and

0:05:16.680 --> 0:05:19.400
<v Speaker 1>you could read it there. So again, very much like email,

0:05:20.240 --> 0:05:23.640
<v Speaker 1>BBS culture allowed people who otherwise would have had problems

0:05:23.680 --> 0:05:27.800
<v Speaker 1>meeting up with folks who shared their similar interests like

0:05:28.480 --> 0:05:32.719
<v Speaker 1>I don't know, let's say hacking, for example, and I

0:05:32.720 --> 0:05:36.000
<v Speaker 1>should probably talk about what hacking actually is now. The

0:05:36.080 --> 0:05:40.320
<v Speaker 1>popular definition of hacking is very narrow and misleading. It

0:05:40.360 --> 0:05:44.000
<v Speaker 1>tends to focus on super negative stuff like breaking into

0:05:44.000 --> 0:05:47.440
<v Speaker 1>secure systems in order to steal stuff or commit sabotage

0:05:48.600 --> 0:05:53.400
<v Speaker 1>or install malware. You know, you're designing viruses and worms

0:05:53.400 --> 0:05:57.440
<v Speaker 1>in order to be some sort of online menace to society.

0:05:57.480 --> 0:06:00.200
<v Speaker 1>But the basic definition of a hacker is just someone

0:06:00.200 --> 0:06:02.919
<v Speaker 1>who wants to know how something works. They want to

0:06:03.040 --> 0:06:08.400
<v Speaker 1>understand a system or a product or software or hardware.

0:06:08.440 --> 0:06:09.960
<v Speaker 1>They just want to know how it works, and then

0:06:09.960 --> 0:06:12.359
<v Speaker 1>how to make changes to it, how to tweak it

0:06:12.440 --> 0:06:14.719
<v Speaker 1>so it does things it wasn't and just you know,

0:06:14.800 --> 0:06:18.000
<v Speaker 1>expected to do it wasn't designed to do. You increase

0:06:18.120 --> 0:06:21.560
<v Speaker 1>its utility by making it do other things, or maybe

0:06:21.560 --> 0:06:24.680
<v Speaker 1>you do things better or often worse, but in an

0:06:24.800 --> 0:06:29.400
<v Speaker 1>entertaining way. So they hack a system up and see

0:06:29.400 --> 0:06:31.680
<v Speaker 1>what makes it tick, and then they put it back together.

0:06:31.920 --> 0:06:34.760
<v Speaker 1>And sometimes they'll hack together code to accomplish something, and

0:06:34.760 --> 0:06:36.719
<v Speaker 1>there's no requirement for that code to be in any

0:06:36.720 --> 0:06:40.359
<v Speaker 1>way malicious or illegal. Hackers might make a program that

0:06:40.440 --> 0:06:43.760
<v Speaker 1>lacks elegance or efficiency, but it gets the job done,

0:06:44.160 --> 0:06:46.000
<v Speaker 1>and the same is true for hackers who work with

0:06:46.040 --> 0:06:49.880
<v Speaker 1>physical gadgets as opposed to just code. They might make

0:06:49.960 --> 0:06:52.960
<v Speaker 1>circuits that do nifty things, though it may be a

0:06:53.480 --> 0:06:59.000
<v Speaker 1>primitive or particularly inelegant approach, refinement can come later. Hacking

0:06:59.080 --> 0:07:02.240
<v Speaker 1>is just can I take this stuff and make it

0:07:02.279 --> 0:07:05.200
<v Speaker 1>do what I wanted to do? So again, it could

0:07:05.200 --> 0:07:08.279
<v Speaker 1>be hardware, it could be software, and there's also some

0:07:08.960 --> 0:07:13.560
<v Speaker 1>social hacking as well. The ability to manipulate people into

0:07:13.640 --> 0:07:19.480
<v Speaker 1>doing things, not necessarily maliciously, though frequently it is uh.

0:07:19.640 --> 0:07:22.280
<v Speaker 1>Sometimes it's just meant as a way of seeing how

0:07:22.320 --> 0:07:25.680
<v Speaker 1>people tick. That's really what hackers are interested in. So

0:07:25.800 --> 0:07:28.480
<v Speaker 1>working for a company like how Stuff Works, we appeal

0:07:28.640 --> 0:07:31.960
<v Speaker 1>to that same sort of sensibility, that sense of curiosity

0:07:32.000 --> 0:07:37.240
<v Speaker 1>that wants to be uh satisfied by learning how the

0:07:37.280 --> 0:07:41.160
<v Speaker 1>world works. Now back to Jeff Moss. He operated a

0:07:41.200 --> 0:07:44.400
<v Speaker 1>few different bulletin board systems on Fido net, and his

0:07:44.440 --> 0:07:47.400
<v Speaker 1>bulletin board systems were part of a larger network of

0:07:47.480 --> 0:07:51.000
<v Speaker 1>people interested in hacking or freaking, which is sort of

0:07:51.040 --> 0:07:53.800
<v Speaker 1>like the telephone system version of hacking. Now. I did

0:07:53.800 --> 0:07:56.800
<v Speaker 1>a full episode about freaking years ago, and you can

0:07:56.880 --> 0:07:58.640
<v Speaker 1>learn all about it, and also about some of the

0:07:58.680 --> 0:08:04.240
<v Speaker 1>famous people who were freaks, like uh Wosniak so Wasniac

0:08:04.360 --> 0:08:06.800
<v Speaker 1>being one of the co founders of Apple back in

0:08:06.880 --> 0:08:09.800
<v Speaker 1>the seventies, was one of the phone freakers. You can

0:08:09.840 --> 0:08:13.400
<v Speaker 1>also learn about Captain Crunch, who used a toy whistle

0:08:13.680 --> 0:08:18.080
<v Speaker 1>found in cereal boxes to help hack the phone systems.

0:08:18.600 --> 0:08:21.400
<v Speaker 1>These were people who were learning how those phone systems

0:08:21.440 --> 0:08:24.360
<v Speaker 1>worked and then how to manipulate them. Whether it was

0:08:24.440 --> 0:08:26.960
<v Speaker 1>to make long distance phone calls for free, or just

0:08:27.080 --> 0:08:30.200
<v Speaker 1>to really figure out how all those network switches worked

0:08:30.360 --> 0:08:32.920
<v Speaker 1>because it was interesting and not a lot of material

0:08:33.080 --> 0:08:38.959
<v Speaker 1>was available publicly for people to look into. Uh Well,

0:08:39.360 --> 0:08:42.320
<v Speaker 1>there were also people who were interested in just sharing information.

0:08:42.480 --> 0:08:45.360
<v Speaker 1>They had access to information that they thought other people

0:08:45.400 --> 0:08:47.880
<v Speaker 1>needed access to, and so they would use bolton board

0:08:47.880 --> 0:08:52.520
<v Speaker 1>systems to disseminate that information to other folks. His BBS is,

0:08:52.800 --> 0:08:55.559
<v Speaker 1>that is, Jeff Mosses BBS is connected to other systems

0:08:55.600 --> 0:08:59.760
<v Speaker 1>located around the world through this network. Now, Mosses bb

0:09:00.080 --> 0:09:02.360
<v Speaker 1>as were popular and he started to function as sort

0:09:02.400 --> 0:09:06.439
<v Speaker 1>of the centralized hub for many of these other BBS platforms,

0:09:06.800 --> 0:09:11.719
<v Speaker 1>including platforms like hacknet, freak Net, and platinum Net. There

0:09:11.720 --> 0:09:16.320
<v Speaker 1>were eleven in total that used his BBS as sort

0:09:16.320 --> 0:09:21.160
<v Speaker 1>of a connecting point, and platinum Net out of Canada

0:09:21.400 --> 0:09:25.680
<v Speaker 1>had a request for moss or more specifically, the administrator

0:09:25.960 --> 0:09:28.880
<v Speaker 1>of the BBS platinum Net, which was located in Canada,

0:09:29.440 --> 0:09:32.560
<v Speaker 1>was asking moss for a favor. The operator of that

0:09:32.640 --> 0:09:36.160
<v Speaker 1>BBS was going to go offline because quote his dad

0:09:36.200 --> 0:09:38.960
<v Speaker 1>got a better job in the quote. So this was

0:09:39.040 --> 0:09:42.440
<v Speaker 1>someone who is fairly young. One can presume living with

0:09:42.520 --> 0:09:46.160
<v Speaker 1>his dad and that he was soon going to lose

0:09:46.480 --> 0:09:49.720
<v Speaker 1>access to the computer they were using, the phone line

0:09:49.720 --> 0:09:53.760
<v Speaker 1>they were using because they were going to relocate. And

0:09:53.800 --> 0:09:55.640
<v Speaker 1>this is where we remember there were a lot of

0:09:55.720 --> 0:09:58.760
<v Speaker 1>young folks really interested in the way computers and complicated

0:09:58.800 --> 0:10:01.640
<v Speaker 1>systems worked, and the operator of Platinum Net was hoping

0:10:01.679 --> 0:10:05.480
<v Speaker 1>that Jeff Moss would be able to organize a big bash,

0:10:05.640 --> 0:10:09.000
<v Speaker 1>a big going away party for Platinum Net. Because Jeff

0:10:09.040 --> 0:10:12.199
<v Speaker 1>Moss again was operating this sort of centralized hub and

0:10:12.480 --> 0:10:15.560
<v Speaker 1>Moss was in the United States, whereas this guy was

0:10:15.600 --> 0:10:22.479
<v Speaker 1>in Canada. So most of the members of these networks

0:10:22.520 --> 0:10:25.040
<v Speaker 1>that we're using these bbs is happened to be in

0:10:25.120 --> 0:10:27.959
<v Speaker 1>the US. That's why Platinum Net really wanted Jeff Moss

0:10:28.000 --> 0:10:30.840
<v Speaker 1>to organize this, because he wanted as many of his

0:10:30.920 --> 0:10:32.679
<v Speaker 1>friends to be able to go as possible, and it

0:10:32.720 --> 0:10:35.560
<v Speaker 1>would be difficult to organize a party in the United

0:10:35.559 --> 0:10:40.000
<v Speaker 1>States while you are actually in Canada. Now, Moss had

0:10:40.000 --> 0:10:42.400
<v Speaker 1>talked to Platinum nets administrator. And by the way, the

0:10:42.440 --> 0:10:44.720
<v Speaker 1>reason why I'm not using any names here is because

0:10:45.040 --> 0:10:47.800
<v Speaker 1>Moss himself says he forgot the name of the kid

0:10:48.520 --> 0:10:51.880
<v Speaker 1>from so many years ago. He's forgot what the kid's

0:10:51.920 --> 0:10:54.320
<v Speaker 1>name was. So Moss decided that the best place to

0:10:54.400 --> 0:10:57.880
<v Speaker 1>locate the party would be Las Vegas, Nevada, for a

0:10:57.880 --> 0:11:00.600
<v Speaker 1>couple of different reasons. For one, he had never been

0:11:00.640 --> 0:11:03.360
<v Speaker 1>to Vegas, so he was kind of curious. He's like,

0:11:03.360 --> 0:11:05.400
<v Speaker 1>why don't we have the party in Vegas? And he

0:11:05.440 --> 0:11:08.400
<v Speaker 1>felt that the party if it fell apart, if it

0:11:08.440 --> 0:11:11.360
<v Speaker 1>was a bust and no one showed up, worst case scenario,

0:11:11.679 --> 0:11:14.559
<v Speaker 1>he'd be sitting by a pool drinking a Pinia Colada

0:11:14.640 --> 0:11:17.520
<v Speaker 1>in Las Vegas, Nevada. So he saw it as a

0:11:17.520 --> 0:11:22.000
<v Speaker 1>win win, and that's when things took a turn. So

0:11:22.280 --> 0:11:28.040
<v Speaker 1>platinum Net disappeared, the administrator that is of the BBS disappeared,

0:11:28.080 --> 0:11:32.480
<v Speaker 1>the BBS itself went offline. Apparently his father took the

0:11:32.640 --> 0:11:36.760
<v Speaker 1>job earlier than was expected, and Platinum Net went dark.

0:11:37.360 --> 0:11:40.400
<v Speaker 1>So Moss had already begun preparations for this great, big

0:11:40.440 --> 0:11:43.240
<v Speaker 1>party in Las Vegas, and people were already expecting a

0:11:43.240 --> 0:11:46.800
<v Speaker 1>big shin dig. So Moss was left, as he said,

0:11:47.559 --> 0:11:53.040
<v Speaker 1>holding the bag. He decided that instead of canceling it

0:11:53.320 --> 0:11:56.360
<v Speaker 1>or making excuses, he would actually turn it up a notch.

0:11:56.559 --> 0:12:01.079
<v Speaker 1>He decided to invite everyone across the eleven networks that

0:12:01.120 --> 0:12:04.960
<v Speaker 1>were connected to his BBS, and then he got on

0:12:05.040 --> 0:12:08.080
<v Speaker 1>I r C also known as Internet Relay Chat and

0:12:08.160 --> 0:12:12.720
<v Speaker 1>posted to Pound hack and Pound freak or if you prefer,

0:12:12.840 --> 0:12:16.280
<v Speaker 1>hashtag hack and hashtag freak in these days, and those

0:12:16.280 --> 0:12:19.480
<v Speaker 1>are chat rooms. IRC uses the hashtag or pound symbol

0:12:19.520 --> 0:12:22.360
<v Speaker 1>to designate different chat rooms. Back in the day, there

0:12:22.400 --> 0:12:25.520
<v Speaker 1>was only one hack chat room and only one freak

0:12:25.640 --> 0:12:28.720
<v Speaker 1>chat room, and he posted about the party there. Essentially,

0:12:29.240 --> 0:12:33.520
<v Speaker 1>he was opening it up to everybody. He also says

0:12:33.600 --> 0:12:36.000
<v Speaker 1>that he sent faxes out to tons of different people

0:12:36.040 --> 0:12:41.959
<v Speaker 1>and organizations, including law enforcement agencies, agencies like the FBI

0:12:42.040 --> 0:12:44.640
<v Speaker 1>and the Secret Service, and he said, we're gonna have

0:12:44.679 --> 0:12:47.480
<v Speaker 1>a big hacking conference in Las Vegas. Now. Later on,

0:12:47.520 --> 0:12:49.720
<v Speaker 1>he said he knew information about the gathering was gonna

0:12:49.720 --> 0:12:52.199
<v Speaker 1>get out anyway. It was going to become public, so

0:12:52.400 --> 0:12:54.360
<v Speaker 1>he might as well get in front of it and

0:12:54.440 --> 0:12:57.000
<v Speaker 1>let people know ahead of time, rather than make it

0:12:57.040 --> 0:12:59.440
<v Speaker 1>seem like he's trying to be secretive and that perhaps

0:12:59.520 --> 0:13:01.320
<v Speaker 1>these people are up to no good. He wanted to

0:13:01.360 --> 0:13:02.839
<v Speaker 1>get in front of that and say no, no, no,

0:13:03.559 --> 0:13:06.839
<v Speaker 1>we're getting together to have a party. Yes, we're all folks.

0:13:06.800 --> 0:13:11.480
<v Speaker 1>Who are interested in information security, but we're not clandestinely

0:13:11.559 --> 0:13:15.520
<v Speaker 1>trying to take down the government or something. And now

0:13:15.520 --> 0:13:18.640
<v Speaker 1>he had to call the party something, and he was

0:13:18.720 --> 0:13:22.360
<v Speaker 1>thinking about different names and ultimately decided upon def Con

0:13:23.200 --> 0:13:26.840
<v Speaker 1>D E, F C O N. Now, in military speak,

0:13:27.280 --> 0:13:31.439
<v Speaker 1>def con as an acronym stands for defense readiness condition,

0:13:31.520 --> 0:13:34.640
<v Speaker 1>and it's generally followed by a number. And here's how

0:13:34.640 --> 0:13:37.480
<v Speaker 1>the scale breaks down. If you've ever heard about def

0:13:37.480 --> 0:13:40.000
<v Speaker 1>con followed by number, this is what it means. Def

0:13:40.080 --> 0:13:45.000
<v Speaker 1>Con five is normal peacetime readiness, meaning you are not

0:13:45.240 --> 0:13:48.080
<v Speaker 1>on high alert in any way, shape or form. Def

0:13:48.160 --> 0:13:53.160
<v Speaker 1>Con four is normal increased intelligence and strengthened security measures,

0:13:53.720 --> 0:13:57.360
<v Speaker 1>so not quite as laid back as normal peacetime readiness.

0:13:57.640 --> 0:14:01.079
<v Speaker 1>Def Con three is an increase in four readiness above

0:14:01.280 --> 0:14:07.120
<v Speaker 1>normal readiness, so you've got perhaps some various military units

0:14:07.160 --> 0:14:12.920
<v Speaker 1>and equipment on standby. Def Con two is further increase

0:14:12.960 --> 0:14:17.120
<v Speaker 1>in force readiness, but less than maximum readiness, so somewhere

0:14:17.160 --> 0:14:20.360
<v Speaker 1>in between being a little more ready than usual and

0:14:20.440 --> 0:14:25.080
<v Speaker 1>being totally ready. Def Con one is maximum force readiness.

0:14:25.120 --> 0:14:29.640
<v Speaker 1>You are ready to go to war at a moment's notice. Now,

0:14:29.680 --> 0:14:32.200
<v Speaker 1>Moss like the term def con partly because it was

0:14:32.240 --> 0:14:36.840
<v Speaker 1>in a film called War Games starring Matthew Broderick. Highly

0:14:36.840 --> 0:14:38.440
<v Speaker 1>recommend that movie, by the way, It's one of my

0:14:38.480 --> 0:14:41.480
<v Speaker 1>favorites from the eighties. In that movie, Broderick plays a

0:14:41.560 --> 0:14:46.440
<v Speaker 1>young hacker who uncovers some interesting games that, unbeknownst to him,

0:14:46.480 --> 0:14:50.280
<v Speaker 1>are controlled by a supercomputer called Whopper w O p

0:14:50.520 --> 0:14:54.440
<v Speaker 1>R that stands for War Operation Planned Response, and that

0:14:54.480 --> 0:14:59.240
<v Speaker 1>particular supercomputer belonged to the North American Aerospace Defense Command

0:14:59.560 --> 0:15:02.720
<v Speaker 1>also known as NORAD, and it turns out that the

0:15:02.800 --> 0:15:05.400
<v Speaker 1>supercomputer runs on a program that was designed by an

0:15:05.400 --> 0:15:11.600
<v Speaker 1>eccentric programmer named Stephen Falcon. Now, Broderick's character, whose name

0:15:11.680 --> 0:15:15.120
<v Speaker 1>is David Lightman, has no idea that he's accessed a

0:15:15.160 --> 0:15:19.280
<v Speaker 1>defense computer. He was actually doing what he called war dialing.

0:15:19.360 --> 0:15:22.120
<v Speaker 1>In in old days, people called demon dialing, which is

0:15:22.160 --> 0:15:25.960
<v Speaker 1>where you would set up your computer's phone modem to

0:15:26.120 --> 0:15:29.520
<v Speaker 1>just automatically dial a list of phone numbers, and your

0:15:29.560 --> 0:15:32.280
<v Speaker 1>goal is to see if any of those phone numbers

0:15:32.680 --> 0:15:35.760
<v Speaker 1>match up with another computer hooked up to a modem

0:15:36.000 --> 0:15:39.240
<v Speaker 1>so that you can get access to that computer. In

0:15:39.320 --> 0:15:42.560
<v Speaker 1>the movie, what Lightman is trying to do is he's

0:15:42.600 --> 0:15:45.240
<v Speaker 1>heard about a computer game company, and he wants to

0:15:45.280 --> 0:15:48.280
<v Speaker 1>play the games that that computer game company is making

0:15:48.320 --> 0:15:50.480
<v Speaker 1>before they come out. He wants to play them and

0:15:50.520 --> 0:15:54.400
<v Speaker 1>test them and find out they're worthwhile. So he said

0:15:54.480 --> 0:15:57.040
<v Speaker 1>this list of numbers. Why he doesn't know is that

0:15:57.120 --> 0:16:00.280
<v Speaker 1>his computer is actually called into a defense computer, not

0:16:00.520 --> 0:16:04.840
<v Speaker 1>a gaming companies computer. He just thinks he's playing games.

0:16:04.840 --> 0:16:08.120
<v Speaker 1>So he launches a game called Thermonuclear War, it's really

0:16:08.160 --> 0:16:11.560
<v Speaker 1>a thermonuclear war simulator, and tries to decide where he'll

0:16:11.600 --> 0:16:14.160
<v Speaker 1>attack first, and he decides cheekily that he's going to

0:16:14.240 --> 0:16:17.640
<v Speaker 1>attack Las Vegas, Nevada. So Moss, who was living in

0:16:17.680 --> 0:16:20.680
<v Speaker 1>Seattle at the time, uh the same place that David

0:16:20.760 --> 0:16:24.080
<v Speaker 1>Lightman was supposed to be from, decides he's gonna hold

0:16:24.080 --> 0:16:26.440
<v Speaker 1>a party in Las Vegas, and inspired by war games,

0:16:26.440 --> 0:16:29.120
<v Speaker 1>he calls it def Con. He also mentioned that the

0:16:29.240 --> 0:16:33.000
<v Speaker 1>letters D E F correspond to the phone key number three.

0:16:33.520 --> 0:16:37.640
<v Speaker 1>So in the old text days, each number on a

0:16:37.720 --> 0:16:41.240
<v Speaker 1>phone was related to three letters, and the number three

0:16:41.640 --> 0:16:44.880
<v Speaker 1>was related to the letters D E n F. So

0:16:44.920 --> 0:16:47.120
<v Speaker 1>that was where the phone freakers out in the audience.

0:16:47.720 --> 0:16:50.760
<v Speaker 1>And at that first def Con Moss accepted cash only

0:16:50.840 --> 0:16:53.520
<v Speaker 1>that is true today. By the way, it is a

0:16:53.600 --> 0:16:57.320
<v Speaker 1>cash only experience, and about a hundred people showed up.

0:16:57.840 --> 0:17:01.120
<v Speaker 1>They had a few speakers talk about various programming projects

0:17:01.120 --> 0:17:05.000
<v Speaker 1>and concepts and information security. Moss says that everyone seemed

0:17:05.040 --> 0:17:09.200
<v Speaker 1>to enjoy themselves, and afterwards he was completely exhausted and

0:17:09.240 --> 0:17:12.000
<v Speaker 1>decided to go hibernate for a while. But then he

0:17:12.040 --> 0:17:15.480
<v Speaker 1>started getting messages from people about how to improve the

0:17:15.520 --> 0:17:19.120
<v Speaker 1>event for the next year, and a lot of requests about, hey,

0:17:19.200 --> 0:17:21.399
<v Speaker 1>are you going to do this next year? And according

0:17:21.400 --> 0:17:23.080
<v Speaker 1>to Moss, that was the first time he had ever

0:17:23.119 --> 0:17:26.280
<v Speaker 1>considered making it an annual event. It was originally just

0:17:26.359 --> 0:17:28.760
<v Speaker 1>gonna be this one time going away party. Remember it

0:17:28.760 --> 0:17:31.640
<v Speaker 1>was originally going to be for Platinum Net, but Platinum

0:17:31.640 --> 0:17:33.920
<v Speaker 1>Net had already gone away, and so he decided, well,

0:17:33.960 --> 0:17:37.040
<v Speaker 1>I guess, I guess we can make it an annual party.

0:17:38.480 --> 0:17:40.600
<v Speaker 1>Well they decided to hold it again the next year,

0:17:41.320 --> 0:17:44.480
<v Speaker 1>and according to Moss, it was about twice the size

0:17:44.720 --> 0:17:47.000
<v Speaker 1>of the year before, and then the third year they

0:17:47.080 --> 0:17:51.280
<v Speaker 1>held it it increased in size again. And shenanigans would

0:17:51.320 --> 0:17:53.760
<v Speaker 1>happen at these parties. For example, you might get into

0:17:53.800 --> 0:17:57.000
<v Speaker 1>a building's elevator and discover that someone had rewired all

0:17:57.040 --> 0:17:59.320
<v Speaker 1>the buttons, so they go to different floors than what

0:17:59.440 --> 0:18:02.280
<v Speaker 1>you pushed. You might push floor three and end up

0:18:02.280 --> 0:18:05.520
<v Speaker 1>on floor twelve, or you might see folks lugging around

0:18:05.560 --> 0:18:09.400
<v Speaker 1>an enormous satellite up link dish for reasons that they

0:18:09.560 --> 0:18:12.920
<v Speaker 1>wouldn't be willing to explain. But Moss says the tone

0:18:12.960 --> 0:18:16.359
<v Speaker 1>of the conference really began to change around this time too.

0:18:16.680 --> 0:18:19.960
<v Speaker 1>The Internet was starting to take off and information security

0:18:20.040 --> 0:18:24.199
<v Speaker 1>was transitioning from something that people were interested in as

0:18:24.240 --> 0:18:28.120
<v Speaker 1>a personal passion into a legitimate career, and Moss says

0:18:28.160 --> 0:18:30.280
<v Speaker 1>that the years between def Con four, which would have

0:18:30.320 --> 0:18:33.920
<v Speaker 1>been and when the bubble burst in two thousand one,

0:18:34.000 --> 0:18:36.120
<v Speaker 1>the tone of the show had turned into one centered

0:18:36.160 --> 0:18:40.000
<v Speaker 1>around money and commerce and less about the geeky technical

0:18:40.080 --> 0:18:42.399
<v Speaker 1>details of how to get around problems or to ensure

0:18:42.440 --> 0:18:45.520
<v Speaker 1>your own Internet security. We've got a lot more to

0:18:45.560 --> 0:18:49.239
<v Speaker 1>talk about with def Con, including how it works and

0:18:49.280 --> 0:18:52.440
<v Speaker 1>what goes on there, but first let's take a quick

0:18:52.480 --> 0:19:02.159
<v Speaker 1>break to thank our sponsor. So pretty soon Defcon was

0:19:02.200 --> 0:19:04.800
<v Speaker 1>just way too big for any one person to carry off,

0:19:04.840 --> 0:19:09.159
<v Speaker 1>and so Moss depended upon a growing staff of volunteers.

0:19:09.600 --> 0:19:14.400
<v Speaker 1>They're affectionately referred to as goons, their departments within the goons,

0:19:14.560 --> 0:19:17.240
<v Speaker 1>such as people who maintain the network connections for def

0:19:17.280 --> 0:19:21.480
<v Speaker 1>Con or folks who act as points of information or security.

0:19:21.600 --> 0:19:24.640
<v Speaker 1>The goons typically wear an identifiable element, like a red

0:19:24.680 --> 0:19:26.800
<v Speaker 1>shirt to let people know they are part of the

0:19:26.880 --> 0:19:31.520
<v Speaker 1>volunteer staff. Moss says that the year before the bubble bursts,

0:19:31.520 --> 0:19:33.800
<v Speaker 1>so in around two thousand, the show had swelled up

0:19:33.840 --> 0:19:38.040
<v Speaker 1>to seven thousand attendees, and according to Moss, only about

0:19:38.160 --> 0:19:41.879
<v Speaker 1>half of those folks really seemed to belong there, like

0:19:41.920 --> 0:19:44.160
<v Speaker 1>they seemed to be the actual geeky people who were

0:19:44.200 --> 0:19:47.439
<v Speaker 1>interested in learning how this stuff worked and playing with

0:19:47.520 --> 0:19:50.400
<v Speaker 1>it and exploring it and breaking it and fixing it,

0:19:50.680 --> 0:19:53.680
<v Speaker 1>and the other half didn't really seem to be those folks.

0:19:53.720 --> 0:19:59.400
<v Speaker 1>They seem to be more people interested in commodity, commodifying security,

0:19:59.440 --> 0:20:03.800
<v Speaker 1>making money, and and making deals. After the bubble bursts,

0:20:03.800 --> 0:20:06.959
<v Speaker 1>the attendants dropped closer to five thousands, So some of

0:20:06.960 --> 0:20:10.240
<v Speaker 1>those people that you might refer to as posers or

0:20:10.280 --> 0:20:13.199
<v Speaker 1>just people who didn't belong at def Con sorry to

0:20:13.680 --> 0:20:17.280
<v Speaker 1>not go anymore, because everyone was pretty much freaking out

0:20:17.280 --> 0:20:20.359
<v Speaker 1>about whether or not tech would even be profitable anymore.

0:20:20.440 --> 0:20:24.520
<v Speaker 1>Especially in the dot com space. By def Con twenty

0:20:24.560 --> 0:20:26.760
<v Speaker 1>in two thousand twelve, the numbers had increased up to

0:20:26.840 --> 0:20:30.960
<v Speaker 1>fifteen thousand, and by then it was a lot of

0:20:30.960 --> 0:20:33.680
<v Speaker 1>the legit folks who were really interested in info SEC

0:20:33.760 --> 0:20:37.040
<v Speaker 1>and not just hangers on. The venue for the conference

0:20:37.040 --> 0:20:39.080
<v Speaker 1>has changed a few times too. For several years, the

0:20:39.119 --> 0:20:42.679
<v Speaker 1>con took place at Alexis Park, which I've actually stayed

0:20:42.720 --> 0:20:45.680
<v Speaker 1>at on a trip to c e S. Alexis Park

0:20:45.760 --> 0:20:48.639
<v Speaker 1>in Las Vegas is a former apartment complex and it

0:20:48.680 --> 0:20:51.480
<v Speaker 1>doesn't have a casino. That was the reason I stayed there.

0:20:51.840 --> 0:20:54.359
<v Speaker 1>I was thinking, if there's no casino, I don't have

0:20:54.440 --> 0:20:57.119
<v Speaker 1>to walk through this enormous casino to get to an

0:20:57.200 --> 0:20:59.359
<v Speaker 1>elevator to get up to my room. I can skip

0:20:59.400 --> 0:21:03.679
<v Speaker 1>all that. Because casinos are notoriously labyrinthian and difficult to

0:21:03.720 --> 0:21:06.360
<v Speaker 1>get through. They don't want you to make they don't

0:21:06.359 --> 0:21:08.359
<v Speaker 1>want it to be easy for you to get out right.

0:21:09.160 --> 0:21:11.200
<v Speaker 1>Uh So I thought, oh, Alexis Park, it doesn't have

0:21:11.200 --> 0:21:13.199
<v Speaker 1>a casino, I'll do that. I did not realize that

0:21:13.200 --> 0:21:17.080
<v Speaker 1>it was a bunch of apartment buildings separate from each other,

0:21:17.119 --> 0:21:19.560
<v Speaker 1>and I was booked in a room that was like

0:21:19.600 --> 0:21:22.680
<v Speaker 1>five apartment buildings back from the entrance, so it meant

0:21:22.720 --> 0:21:25.760
<v Speaker 1>walking I don't know, maybe half a mile to get

0:21:25.760 --> 0:21:28.480
<v Speaker 1>to my room. Uh, so I didn't save any time

0:21:28.520 --> 0:21:31.320
<v Speaker 1>in the long run. Well, Alexis Park was where they

0:21:31.359 --> 0:21:35.720
<v Speaker 1>had several def cons in the early years, and it

0:21:35.840 --> 0:21:39.800
<v Speaker 1>was a very popular place. Uh. It has several pools

0:21:39.840 --> 0:21:43.199
<v Speaker 1>and lots of open spaces, and apparently a ton of

0:21:43.240 --> 0:21:46.560
<v Speaker 1>shenanigans happened in and around those spots during the Alexis

0:21:46.600 --> 0:21:49.920
<v Speaker 1>Park years. The pool parties, in particular, were the stuff

0:21:50.000 --> 0:21:54.840
<v Speaker 1>of legend and sometimes of law enforcement. The hotel even

0:21:54.880 --> 0:21:57.920
<v Speaker 1>printed up sheets that explained how much it would cost

0:21:57.960 --> 0:22:01.000
<v Speaker 1>to replace stuff in your room. So if you wanted

0:22:01.040 --> 0:22:03.800
<v Speaker 1>to trash your room, you could, but you'd have to

0:22:03.840 --> 0:22:05.840
<v Speaker 1>pay for it. But you would know right up front

0:22:05.840 --> 0:22:08.440
<v Speaker 1>how much you had to pay. And actually the hackers

0:22:08.480 --> 0:22:11.280
<v Speaker 1>like this. They liked the idea that, oh, well, if

0:22:11.320 --> 0:22:13.639
<v Speaker 1>we destroy this television, it's gonna be two hundred bucks.

0:22:13.680 --> 0:22:15.720
<v Speaker 1>But I got two hundred bucks, so let's go ahead

0:22:15.720 --> 0:22:18.680
<v Speaker 1>and do it. And it was funny because Alexis Park

0:22:18.720 --> 0:22:20.560
<v Speaker 1>management was totally cool with this. Is said, well, if

0:22:20.560 --> 0:22:22.840
<v Speaker 1>you pay your build and that's fine because we'll just

0:22:22.920 --> 0:22:26.120
<v Speaker 1>replace it. So it was an interesting experience and an

0:22:26.119 --> 0:22:29.840
<v Speaker 1>interesting relationship between Alexis Park and the hackers, and everyone

0:22:30.080 --> 0:22:35.320
<v Speaker 1>seemed to really dig that. But it got to the

0:22:35.320 --> 0:22:38.520
<v Speaker 1>point where Alexis Park just could not handle Defcon. It

0:22:38.560 --> 0:22:42.560
<v Speaker 1>wasn't big enough. The convention had grown so large that

0:22:42.640 --> 0:22:46.600
<v Speaker 1>they needed to have space that had better meeting facilities.

0:22:46.640 --> 0:22:49.119
<v Speaker 1>The rooms weren't large enough to hold the crowds that

0:22:49.160 --> 0:22:53.240
<v Speaker 1>were coming in, and so they eventually moved out of

0:22:53.240 --> 0:22:55.600
<v Speaker 1>Alexis Park. Now, there are a lot of people who

0:22:55.640 --> 0:22:58.639
<v Speaker 1>have nostalgia for the Alexis Park days, even though everyone

0:22:58.720 --> 0:23:01.679
<v Speaker 1>knows that logistically it and and't work anymore. And so

0:23:01.760 --> 0:23:06.040
<v Speaker 1>that is why often to this day, someone at some

0:23:06.080 --> 0:23:09.760
<v Speaker 1>point during def Con, we'll go to Alexis Park and

0:23:09.800 --> 0:23:13.520
<v Speaker 1>they will go into the lobby of the area and

0:23:13.560 --> 0:23:18.160
<v Speaker 1>they will steal the Alexis Park welcome Matt and smuggle

0:23:18.240 --> 0:23:21.520
<v Speaker 1>it out and bring it over to the actual def

0:23:21.640 --> 0:23:25.640
<v Speaker 1>Con meeting area and people will pose with the Alexis

0:23:25.720 --> 0:23:29.040
<v Speaker 1>Park welcome Matt that has been stolen from their lobby

0:23:29.240 --> 0:23:31.960
<v Speaker 1>and they'll return it, typically at the end of the conference.

0:23:32.680 --> 0:23:36.600
<v Speaker 1>But yeah, while they are no longer located in Alexis Park,

0:23:36.720 --> 0:23:40.119
<v Speaker 1>the hackers will still, you know, bring it along as

0:23:40.280 --> 0:23:44.080
<v Speaker 1>as a reminder of the good old days. Parties are

0:23:44.080 --> 0:23:47.320
<v Speaker 1>a huge thing at def Con, and there are tons

0:23:47.359 --> 0:23:52.840
<v Speaker 1>of parties, dances, DJ sets, lots of plausible deniability. Def

0:23:52.920 --> 0:23:56.400
<v Speaker 1>Con frequently attracts musicians who work in digital media and

0:23:56.960 --> 0:23:59.680
<v Speaker 1>use technology like chip tunes and other forms of musical

0:23:59.720 --> 0:24:03.800
<v Speaker 1>exprestion that rely heavily on technology. I've actually seen some

0:24:03.880 --> 0:24:06.080
<v Speaker 1>of the sets, of course I've never attended to def Con,

0:24:06.200 --> 0:24:10.639
<v Speaker 1>but watching some videos of the various DJ performances, it's incredible.

0:24:11.440 --> 0:24:14.280
<v Speaker 1>You've got high tech light shows, You've got really cutting

0:24:14.359 --> 0:24:18.800
<v Speaker 1>edge technology which is being used to make music. You've

0:24:18.800 --> 0:24:22.560
<v Speaker 1>got people hacking each other the whole time, like technologically speaking,

0:24:22.600 --> 0:24:26.080
<v Speaker 1>not physically hacking one another. Although bio hacking is one

0:24:26.119 --> 0:24:29.000
<v Speaker 1>of the areas of interest at def Con, the scheduled

0:24:29.040 --> 0:24:32.000
<v Speaker 1>talks at def Con often revolve around important or even

0:24:32.040 --> 0:24:35.840
<v Speaker 1>critical computer and network security issues, and sometimes the presentations

0:24:35.960 --> 0:24:39.240
<v Speaker 1>are humorous. There's a great one that you can find online.

0:24:39.240 --> 0:24:41.439
<v Speaker 1>You can actually watch it on YouTube, in which a

0:24:41.440 --> 0:24:43.800
<v Speaker 1>programmer described how he was able to track down his

0:24:43.920 --> 0:24:47.120
<v Speaker 1>stolen computer and lead police to the thief who took

0:24:47.160 --> 0:24:51.119
<v Speaker 1>it by monitoring when it came online. And this was

0:24:51.160 --> 0:24:54.040
<v Speaker 1>a process that took a lot of creative thinking because

0:24:54.040 --> 0:24:57.760
<v Speaker 1>he had already taken several steps to protect his computer,

0:24:57.840 --> 0:25:00.919
<v Speaker 1>and once it was physically stolen, meant that some of

0:25:00.920 --> 0:25:03.960
<v Speaker 1>those options were no longer available, Like he couldn't find

0:25:04.000 --> 0:25:07.160
<v Speaker 1>it in certain ways because he had already removed that

0:25:07.280 --> 0:25:10.439
<v Speaker 1>as a capability. But eventually he was able to discover

0:25:10.480 --> 0:25:14.119
<v Speaker 1>his computer and even retrieve much of, although not all,

0:25:14.160 --> 0:25:16.439
<v Speaker 1>of the data that was on his computer when it

0:25:16.480 --> 0:25:21.120
<v Speaker 1>was stolen. Other talks are a little more sobering. For example,

0:25:21.280 --> 0:25:25.520
<v Speaker 1>take the talk titled go beyond tabletop Scenarios by building

0:25:25.520 --> 0:25:29.359
<v Speaker 1>an Incident Response Simulation Platform. So this is a talk

0:25:29.359 --> 0:25:31.959
<v Speaker 1>where a security expert with the Texas Department of Safety

0:25:32.080 --> 0:25:37.000
<v Speaker 1>named Eric Capuano explained how organizations need to prepare themselves

0:25:37.040 --> 0:25:41.040
<v Speaker 1>to respond to serious security threats by building out simulations

0:25:41.040 --> 0:25:43.879
<v Speaker 1>that allow I T. Professionals the chance to train and

0:25:43.960 --> 0:25:46.399
<v Speaker 1>hone their skills. So he's saying, it doesn't do you

0:25:46.440 --> 0:25:49.200
<v Speaker 1>any good to learn how to deal with an emergency

0:25:49.240 --> 0:25:52.840
<v Speaker 1>when the emergency is happening. You want to train yourself

0:25:52.880 --> 0:25:56.280
<v Speaker 1>in all of those strategies early on so that when

0:25:56.480 --> 0:26:00.280
<v Speaker 1>something like that does happen, you can respond appropriately. There's

0:26:00.320 --> 0:26:04.040
<v Speaker 1>another talk that was titled Fooling the Hound Deceiving Domain

0:26:04.200 --> 0:26:08.240
<v Speaker 1>Admin Hunter hunters uh. This focused on ways to trick

0:26:08.280 --> 0:26:12.479
<v Speaker 1>attackers into following a false pathway while they are seeking

0:26:12.520 --> 0:26:16.600
<v Speaker 1>out admin login credentials to a network system. So hacker

0:26:16.680 --> 0:26:19.959
<v Speaker 1>gets access to perhaps a machine on a network and

0:26:20.000 --> 0:26:22.320
<v Speaker 1>wants to see if they can find the admin level

0:26:22.359 --> 0:26:25.440
<v Speaker 1>access to the whole network. Well, this was a talk

0:26:25.520 --> 0:26:28.360
<v Speaker 1>saying that might happen. So here's some ways to lay

0:26:28.400 --> 0:26:32.360
<v Speaker 1>down a trap where the hacker thinks they're getting access

0:26:32.400 --> 0:26:35.600
<v Speaker 1>to the admin credentials, but in fact what they're really

0:26:35.600 --> 0:26:40.360
<v Speaker 1>doing is revealing their presence to the network administrator, who

0:26:40.359 --> 0:26:44.720
<v Speaker 1>can then perhaps pursue that or handover information to law enforcement.

0:26:45.560 --> 0:26:50.639
<v Speaker 1>So very interesting talks about not just circumventing security, but

0:26:50.680 --> 0:26:53.680
<v Speaker 1>how to improve security. In fact, almost all the discussions

0:26:53.760 --> 0:26:59.120
<v Speaker 1>ultimately revolve around the fact that vulnerabilities aren't necessarily there

0:26:59.119 --> 0:27:01.560
<v Speaker 1>for you to explore, eight they are there for you

0:27:01.640 --> 0:27:05.800
<v Speaker 1>to examine, to learn from, and then to patch. So

0:27:06.840 --> 0:27:10.480
<v Speaker 1>a lot of interesting approaches. Although the people who attend

0:27:10.760 --> 0:27:13.880
<v Speaker 1>def con can sometimes seem like they're on the other

0:27:13.960 --> 0:27:16.560
<v Speaker 1>side of the law, and often they are people who

0:27:16.560 --> 0:27:20.119
<v Speaker 1>want to protect their identities and their security, and so

0:27:20.160 --> 0:27:22.840
<v Speaker 1>they'll go to great pains to do that. And to

0:27:23.000 --> 0:27:25.639
<v Speaker 1>some people that might seem like it's an admission of guilt,

0:27:25.680 --> 0:27:30.119
<v Speaker 1>but in fact that's not necessarily the case. Other recent

0:27:30.160 --> 0:27:33.600
<v Speaker 1>talks have looked at security vulnerabilities and shortcomings and autonomous

0:27:33.640 --> 0:27:38.080
<v Speaker 1>and connected cars. Chris Valisek and Charlie Miller showed that

0:27:38.119 --> 0:27:40.920
<v Speaker 1>they could compromise a jeep and connect to its systems

0:27:41.040 --> 0:27:44.080
<v Speaker 1>from miles away using a laptop computer connected to the internet.

0:27:44.600 --> 0:27:48.200
<v Speaker 1>They could even cut the brakes or the transmission from

0:27:48.240 --> 0:27:53.439
<v Speaker 1>their laptop pretty easily. Another presenter did a talk about

0:27:53.440 --> 0:27:56.520
<v Speaker 1>how air traffic control systems work and pointed out some

0:27:56.560 --> 0:28:00.199
<v Speaker 1>serious concerns and security vulnerabilities, and he did this be us.

0:28:00.359 --> 0:28:03.880
<v Speaker 1>There was no easy way to communicate to anyone appropriate

0:28:03.960 --> 0:28:06.120
<v Speaker 1>about the concerns. It's not like he could just pick

0:28:06.200 --> 0:28:09.000
<v Speaker 1>up the phone and talk to air traffic control and say, hey,

0:28:09.080 --> 0:28:11.600
<v Speaker 1>I noticed that this is how you are using your systems.

0:28:11.800 --> 0:28:14.800
<v Speaker 1>Did you know that it could be manipulated in a

0:28:14.840 --> 0:28:19.840
<v Speaker 1>way that could cause catastrophic results if you aren't able

0:28:19.880 --> 0:28:22.560
<v Speaker 1>to address this issue. So he had to talk about it,

0:28:22.880 --> 0:28:25.399
<v Speaker 1>which got a lot of attention and got people talking

0:28:25.440 --> 0:28:27.440
<v Speaker 1>to him, and he said, well, that was my whole purpose.

0:28:27.480 --> 0:28:32.160
<v Speaker 1>It wasn't too give people the keys to the air

0:28:32.200 --> 0:28:35.159
<v Speaker 1>traffic control system. It was to alert the world to

0:28:35.200 --> 0:28:38.120
<v Speaker 1>the presence of these vulnerabilities so that those vulnerabilities could

0:28:38.120 --> 0:28:43.400
<v Speaker 1>be patched. There's um they're They're not meant to be

0:28:44.800 --> 0:28:47.680
<v Speaker 1>something to inspire terror in people. They're not meant to

0:28:47.720 --> 0:28:51.200
<v Speaker 1>make people scared to use technology, but just raise awareness

0:28:51.280 --> 0:28:54.080
<v Speaker 1>of those gaps in security so that experts can close

0:28:54.120 --> 0:28:57.640
<v Speaker 1>those gaps and we create better systems further down the

0:28:57.720 --> 0:29:00.800
<v Speaker 1>road as a pun, because we were just talking about

0:29:00.840 --> 0:29:05.200
<v Speaker 1>cars and planes and travel, so down the road anyway.

0:29:05.240 --> 0:29:08.560
<v Speaker 1>There's also tracks of programming for kids. People have been

0:29:08.560 --> 0:29:10.920
<v Speaker 1>bringing their kids to def Con over the past several years,

0:29:10.920 --> 0:29:14.320
<v Speaker 1>and now the kids themselves have actual programming tracks they

0:29:14.320 --> 0:29:17.480
<v Speaker 1>can follow. Uh. A lot of the same speakers who

0:29:17.480 --> 0:29:19.840
<v Speaker 1>will talk to the adults will come and do presentations

0:29:19.880 --> 0:29:23.040
<v Speaker 1>for the kids. And according to all the videos I saw,

0:29:23.080 --> 0:29:25.920
<v Speaker 1>the speakers love it because kids pay attention and they

0:29:25.960 --> 0:29:29.400
<v Speaker 1>want to know how things work. They have interesting questions,

0:29:29.440 --> 0:29:33.000
<v Speaker 1>sometimes ones that people don't anticipate that lead to amazing

0:29:33.000 --> 0:29:35.400
<v Speaker 1>discoveries down the line, and the kids get to learn

0:29:35.480 --> 0:29:39.560
<v Speaker 1>how to do cool skills like soldering, or some scary

0:29:39.600 --> 0:29:44.560
<v Speaker 1>skills like luck picking or programming, and lots of other stuff.

0:29:45.440 --> 0:29:48.280
<v Speaker 1>Def Con celebrates hacking in its many forms, so you'll

0:29:48.480 --> 0:29:52.880
<v Speaker 1>find lots of talks about coding, security, security vulnerabilities, how

0:29:52.920 --> 0:29:54.959
<v Speaker 1>to make sure you don't end up a victim of

0:29:55.000 --> 0:29:59.640
<v Speaker 1>security vulnerabilities, including which software packages you probably want to avoid,

0:30:00.200 --> 0:30:03.640
<v Speaker 1>ways you can improve your Internet browsing behaviors to minimize

0:30:03.640 --> 0:30:06.120
<v Speaker 1>the risk of someone sniffing out what you are doing

0:30:06.280 --> 0:30:08.720
<v Speaker 1>or trying to take advantage of you in some way.

0:30:08.880 --> 0:30:12.000
<v Speaker 1>There are also tons of contests and games that take

0:30:12.040 --> 0:30:14.680
<v Speaker 1>place over the weekend. Some of them are getting really, really,

0:30:14.680 --> 0:30:18.680
<v Speaker 1>really clever. For example, at Defcon twenty, the convention held

0:30:18.720 --> 0:30:22.800
<v Speaker 1>an intrusion challenge, so teams of three could compete, and

0:30:22.800 --> 0:30:25.840
<v Speaker 1>the challenge simulated a physical break in of a locked

0:30:25.880 --> 0:30:29.160
<v Speaker 1>office space and required teams to document evidence and try

0:30:29.200 --> 0:30:32.240
<v Speaker 1>to return everything to its original place so that their

0:30:32.280 --> 0:30:35.200
<v Speaker 1>presence wouldn't be detected. You also had to unlock a

0:30:35.240 --> 0:30:38.440
<v Speaker 1>smartphone and get information off hit And then there was

0:30:38.600 --> 0:30:42.320
<v Speaker 1>the computer. The computer had some forms of protection on

0:30:42.320 --> 0:30:45.000
<v Speaker 1>it like password protection, but more than that, it had

0:30:45.040 --> 0:30:48.040
<v Speaker 1>information stored on it that would disappear if the computer

0:30:48.120 --> 0:30:52.000
<v Speaker 1>were to lose power. So there was a bonus element

0:30:52.200 --> 0:30:55.760
<v Speaker 1>of stealing the computer without having the power cut to

0:30:55.760 --> 0:30:59.880
<v Speaker 1>the machine, which would require using government level spy a

0:31:00.000 --> 0:31:04.200
<v Speaker 1>agency stuff where you could cut a power chord, splice

0:31:04.200 --> 0:31:06.800
<v Speaker 1>it to another power source in such a way that

0:31:06.880 --> 0:31:10.320
<v Speaker 1>the power supply is never interrupted, and then you could

0:31:10.360 --> 0:31:12.800
<v Speaker 1>put the computer on a cart and cart it out.

0:31:13.400 --> 0:31:15.960
<v Speaker 1>But it requires you to actually physically cut the power

0:31:16.080 --> 0:31:18.120
<v Speaker 1>chord that goes to the computer and do it in

0:31:18.160 --> 0:31:21.400
<v Speaker 1>such a way that you never break the connection entirely,

0:31:21.760 --> 0:31:25.000
<v Speaker 1>so that you can actually move the computer with its

0:31:25.000 --> 0:31:27.640
<v Speaker 1>still powered on, and that way you could retrieve the

0:31:27.680 --> 0:31:30.720
<v Speaker 1>information that's on that computer, but otherwise we'd be lost

0:31:30.760 --> 0:31:34.080
<v Speaker 1>if the power went out. It's really cool and it's

0:31:34.120 --> 0:31:36.760
<v Speaker 1>fun to watch those sort of things. Uh, and again

0:31:36.800 --> 0:31:39.400
<v Speaker 1>it gets you thinking into the different types of security

0:31:39.440 --> 0:31:41.800
<v Speaker 1>you need to put in place if you want your

0:31:41.840 --> 0:31:44.920
<v Speaker 1>information to be secure, not just the computer systems, but

0:31:45.000 --> 0:31:48.040
<v Speaker 1>the physical locks that you use things like that. It's

0:31:48.080 --> 0:31:50.440
<v Speaker 1>important to know how it all works so that you

0:31:50.440 --> 0:31:53.400
<v Speaker 1>can make sure you create the most secure system to

0:31:53.480 --> 0:31:58.440
<v Speaker 1>protect your data and other equipment. So all told, this

0:31:58.480 --> 0:32:01.240
<v Speaker 1>competition required you to pick a lock, get access to

0:32:01.240 --> 0:32:04.600
<v Speaker 1>an office, photograph some documents, access a phone, and steal

0:32:04.680 --> 0:32:07.040
<v Speaker 1>a power down computer without turning its power off, which

0:32:07.080 --> 0:32:10.800
<v Speaker 1>was pretty intense. Another popular game at Defcon, In fact,

0:32:10.840 --> 0:32:14.080
<v Speaker 1>one of the most defining experiences at def Con is

0:32:14.280 --> 0:32:17.240
<v Speaker 1>ct F, which stands for Capture the Flag. Now, in

0:32:17.280 --> 0:32:20.040
<v Speaker 1>a traditional capture the Flag game, teams compete to try

0:32:20.080 --> 0:32:22.560
<v Speaker 1>and steal a competing team's flag and return it to

0:32:22.600 --> 0:32:26.600
<v Speaker 1>their own home base, while simultaneously protecting their own flags

0:32:26.640 --> 0:32:29.880
<v Speaker 1>from being stolen by the other team. But DevCon changes

0:32:29.920 --> 0:32:33.280
<v Speaker 1>things up a bit. You have multiple teams playing, and

0:32:34.120 --> 0:32:36.880
<v Speaker 1>your team has a computer on a network, and all

0:32:36.920 --> 0:32:39.920
<v Speaker 1>the other competing teams have their computers on a network.

0:32:40.560 --> 0:32:43.920
<v Speaker 1>On each computer is some piece of data that represents

0:32:43.960 --> 0:32:47.680
<v Speaker 1>a flag, So this is the information on your computer

0:32:47.800 --> 0:32:50.400
<v Speaker 1>that other people are trying to steal. Your opposing teams

0:32:50.880 --> 0:32:54.000
<v Speaker 1>have those same sort of flags on their computers on

0:32:54.080 --> 0:32:59.680
<v Speaker 1>that network, So everyone's trying to secure other teams flags

0:32:59.680 --> 0:33:03.400
<v Speaker 1>while protecting their own flag from being taken by other teams,

0:33:03.760 --> 0:33:05.880
<v Speaker 1>and the administrators have had to come up with rules

0:33:05.880 --> 0:33:09.120
<v Speaker 1>to help prevent teams from circumventing criteria for play, such

0:33:09.120 --> 0:33:12.880
<v Speaker 1>as taking a computer completely offline the network. I mean

0:33:12.920 --> 0:33:15.840
<v Speaker 1>that kind of is unfair because you have to be

0:33:15.920 --> 0:33:19.320
<v Speaker 1>on the network in order to participate. So people have

0:33:19.360 --> 0:33:23.160
<v Speaker 1>come up with creative ways to meet these criteria, and

0:33:23.240 --> 0:33:25.680
<v Speaker 1>every year the administrators have to kind of tweak the

0:33:25.760 --> 0:33:28.480
<v Speaker 1>rules a little bit so that people don't just find

0:33:28.520 --> 0:33:31.680
<v Speaker 1>creative workarounds and they are actually actively trying to play

0:33:31.720 --> 0:33:34.920
<v Speaker 1>the game as it was intended to be played. However,

0:33:35.200 --> 0:33:38.560
<v Speaker 1>that being said, finding workarounds is really what hacking is

0:33:38.560 --> 0:33:42.120
<v Speaker 1>all about. So it can it can. It might work

0:33:42.200 --> 0:33:44.520
<v Speaker 1>once and you get rewarded, and then later on it

0:33:44.520 --> 0:33:48.640
<v Speaker 1>gets written out of the options that you have. Uh,

0:33:48.760 --> 0:33:51.920
<v Speaker 1>the next time they do a CTF. At the twenty

0:33:52.040 --> 0:33:55.080
<v Speaker 1>six team def Con and AI played in the CTF

0:33:55.080 --> 0:33:59.960
<v Speaker 1>for the first time ever, so and un chaperoned art

0:34:00.000 --> 0:34:05.360
<v Speaker 1>actual intelligent program participated in the CTF and for a

0:34:05.400 --> 0:34:07.920
<v Speaker 1>while it would pull ahead of some of the human teams,

0:34:08.360 --> 0:34:10.400
<v Speaker 1>but by the end of the game it actually placed

0:34:10.640 --> 0:34:13.279
<v Speaker 1>last in the competition, So we don't have to worry

0:34:13.320 --> 0:34:17.399
<v Speaker 1>about the computer hackers actual like computer hackers just yet.

0:34:18.160 --> 0:34:21.600
<v Speaker 1>Then there's the crash and Compile drinking game competition in

0:34:21.600 --> 0:34:24.640
<v Speaker 1>which competitors are given a task. Typically it's to create

0:34:24.680 --> 0:34:27.359
<v Speaker 1>a program that will take certain types of input and

0:34:27.400 --> 0:34:30.520
<v Speaker 1>produce certain types of output, which is only normal. That's

0:34:30.520 --> 0:34:34.239
<v Speaker 1>a normal programming you know, assignment. You might have a

0:34:34.239 --> 0:34:36.840
<v Speaker 1>programming course and it says you need to build a

0:34:36.880 --> 0:34:39.239
<v Speaker 1>program that's gonna take this input. You run it through

0:34:39.280 --> 0:34:41.799
<v Speaker 1>the program, you get that output. Build a program that

0:34:41.840 --> 0:34:45.280
<v Speaker 1>does that. But in Crashing compile, it's a drinking game,

0:34:45.640 --> 0:34:48.000
<v Speaker 1>so there are all these rules that come into play.

0:34:48.040 --> 0:34:50.919
<v Speaker 1>If you try to compile your code and that doesn't work,

0:34:50.960 --> 0:34:54.200
<v Speaker 1>you have to take a drink. If the code works

0:34:54.239 --> 0:34:56.200
<v Speaker 1>but it's unstable and it crashes, you've got to take

0:34:56.200 --> 0:34:59.160
<v Speaker 1>a drink. If it's stable but it's not producing the

0:34:59.239 --> 0:35:01.760
<v Speaker 1>right output, you how to take a drink. And obviously

0:35:01.800 --> 0:35:04.120
<v Speaker 1>the less careful you are, the more mistakes you make.

0:35:04.200 --> 0:35:06.000
<v Speaker 1>The more you have to drink, and the more likely

0:35:06.040 --> 0:35:09.680
<v Speaker 1>you'll make even more mistakes due to that influence of drink.

0:35:11.040 --> 0:35:13.560
<v Speaker 1>Perhaps my favorite of all the challenges is a different

0:35:13.640 --> 0:35:17.320
<v Speaker 1>kind of drinking game. It's the Beverage Cooling Contraption Contest

0:35:17.520 --> 0:35:20.520
<v Speaker 1>or b C c C. This is a competition that

0:35:20.560 --> 0:35:23.120
<v Speaker 1>took its inspiration from an episode of MythBusters in which

0:35:23.160 --> 0:35:25.400
<v Speaker 1>the team on MythBusters were trying to come up with

0:35:25.440 --> 0:35:28.160
<v Speaker 1>ways to quickly cool cans of beer to what was

0:35:28.200 --> 0:35:30.680
<v Speaker 1>determined to be the ideal temperature for drinking, which on

0:35:30.680 --> 0:35:33.160
<v Speaker 1>the show was thirty eight degrees fahrenheit or three point

0:35:33.160 --> 0:35:36.640
<v Speaker 1>three three degrees celsius. Teams of up to three people

0:35:36.760 --> 0:35:40.440
<v Speaker 1>can compete in this competition to create an air temperature

0:35:40.480 --> 0:35:44.440
<v Speaker 1>beverage in the quickest and most creative way possible. They

0:35:44.440 --> 0:35:47.840
<v Speaker 1>are not allowed to use any commercial appliances in their efforts,

0:35:47.880 --> 0:35:50.480
<v Speaker 1>and the contraptions have to be designed and built by

0:35:50.520 --> 0:35:52.799
<v Speaker 1>the team, so they can't just buy something and use that.

0:35:53.480 --> 0:35:56.320
<v Speaker 1>The team with the fastest time to cool their beverage

0:35:56.360 --> 0:36:01.040
<v Speaker 1>to the proper temperature wins. Points are deducted for fouls.

0:36:01.560 --> 0:36:06.120
<v Speaker 1>So if your methodology creates a beer or other drink,

0:36:06.160 --> 0:36:08.400
<v Speaker 1>whatever drink they're using at that time, that has a

0:36:08.400 --> 0:36:10.960
<v Speaker 1>metallic taste to it, like, if it alters the taste

0:36:11.040 --> 0:36:14.319
<v Speaker 1>of the drink, you get points taken off. If it

0:36:14.360 --> 0:36:16.719
<v Speaker 1>makes the drink go flat, you get points taken off.

0:36:16.760 --> 0:36:19.640
<v Speaker 1>If you spill drink, you get points taken off. That

0:36:19.760 --> 0:36:23.600
<v Speaker 1>sort of thing. Other contests are equally cheeky. There's a

0:36:23.640 --> 0:36:28.719
<v Speaker 1>counterfeit badge contest. In recent years, the badges have been electronic.

0:36:28.840 --> 0:36:31.680
<v Speaker 1>They've been circuit boards that actually do something, and they

0:36:31.719 --> 0:36:34.680
<v Speaker 1>have USB ports and you can connect them to computers

0:36:34.680 --> 0:36:36.919
<v Speaker 1>and you can actually hack the badges if you want,

0:36:36.960 --> 0:36:41.080
<v Speaker 1>and do interesting things with them. So one thing that

0:36:41.080 --> 0:36:43.360
<v Speaker 1>people try to do is they'll try and spoof a badge.

0:36:43.360 --> 0:36:45.719
<v Speaker 1>They'll try and create a copy of the badge and

0:36:45.719 --> 0:36:48.600
<v Speaker 1>create a counterfeit one. Jeff Moss has actually said that

0:36:48.640 --> 0:36:51.600
<v Speaker 1>if you're good enough to hack a badge and fool security,

0:36:51.880 --> 0:36:54.319
<v Speaker 1>you probably belong at deaf Con and you should be

0:36:54.360 --> 0:36:57.719
<v Speaker 1>able to attend without forking over the participation fee. Of course,

0:36:57.760 --> 0:37:00.720
<v Speaker 1>you're probably spending more time and effort building your version

0:37:00.719 --> 0:37:03.480
<v Speaker 1>of the badge then they did designing the badge in

0:37:03.520 --> 0:37:05.680
<v Speaker 1>the first place, and in a way that kind of

0:37:05.719 --> 0:37:09.479
<v Speaker 1>shows your own level of dedication. Other contests include things

0:37:09.480 --> 0:37:13.920
<v Speaker 1>like forensics puzzles as in computer forensics and network forensics puzzles,

0:37:13.960 --> 0:37:18.040
<v Speaker 1>and scavenger hunts, which can get absolutely insane, and nearly

0:37:18.080 --> 0:37:22.120
<v Speaker 1>all the contests test attendees knowledge and skill encoding or

0:37:22.200 --> 0:37:25.960
<v Speaker 1>hacking in some way While winning a contest will get

0:37:26.000 --> 0:37:29.040
<v Speaker 1>you a claim, landing on the Wall of Sheep will

0:37:29.080 --> 0:37:32.400
<v Speaker 1>mean you're an example of someone practicing poor security behaviors.

0:37:32.719 --> 0:37:35.719
<v Speaker 1>The Wall of Sheep is a display that lists logins

0:37:35.960 --> 0:37:39.359
<v Speaker 1>and the first part of passwords that have been harvested

0:37:39.400 --> 0:37:43.120
<v Speaker 1>off of the Defcon network, and it illustrates how many

0:37:43.160 --> 0:37:47.399
<v Speaker 1>authentication technologies on the web use clear text authentication rather

0:37:47.440 --> 0:37:51.240
<v Speaker 1>than a more secure method. Clear text authentication is terrible.

0:37:51.760 --> 0:37:54.680
<v Speaker 1>You don't want passwords stored in clear text, you want

0:37:54.680 --> 0:37:59.640
<v Speaker 1>that encrypted. So if you're using services that have unencrypted

0:37:59.719 --> 0:38:03.040
<v Speaker 1>clear text passwords stored in them, then your password is

0:38:03.040 --> 0:38:05.680
<v Speaker 1>gonna get posted up on the Wall of Sheep. Typically,

0:38:05.680 --> 0:38:08.200
<v Speaker 1>they only post the very beginning of the password. The

0:38:08.239 --> 0:38:11.279
<v Speaker 1>rest of it will be asterisks out. But if your

0:38:11.320 --> 0:38:14.040
<v Speaker 1>word is a plain English word, people might be able

0:38:14.040 --> 0:38:16.240
<v Speaker 1>to guess it just from the letters that are showing.

0:38:16.800 --> 0:38:19.839
<v Speaker 1>So this is a way of demonstrating, hey, you're using

0:38:19.880 --> 0:38:23.440
<v Speaker 1>some bad stuff and you should probably change that. Speaking

0:38:23.440 --> 0:38:26.759
<v Speaker 1>of secure methods, the only way you can attend def

0:38:26.800 --> 0:38:29.600
<v Speaker 1>Con is to show up at the door with your

0:38:29.640 --> 0:38:32.160
<v Speaker 1>cash in hand in order to purchase the badge, or

0:38:32.239 --> 0:38:36.080
<v Speaker 1>you have to create a spoofed badge that can fool security. Now,

0:38:36.320 --> 0:38:38.920
<v Speaker 1>Defcon does not accept any form of payment other than

0:38:39.040 --> 0:38:42.000
<v Speaker 1>cash at the door, and this helps keep those transactions

0:38:42.000 --> 0:38:45.120
<v Speaker 1>away from prying eyes, such as any agencies that might

0:38:45.120 --> 0:38:48.000
<v Speaker 1>have an interest in identifying people who are particularly least

0:38:48.040 --> 0:38:52.640
<v Speaker 1>skilled at let's say, intrusion attacks against secure systems, and

0:38:52.719 --> 0:38:56.839
<v Speaker 1>everyone apart from official convention staff and guest speakers, will

0:38:56.880 --> 0:39:00.200
<v Speaker 1>pay full price to get in, including the media. So

0:39:00.280 --> 0:39:02.400
<v Speaker 1>Jeff Moss has actually said that one of the purposes

0:39:02.440 --> 0:39:05.239
<v Speaker 1>of this is that if def Con has ever hit

0:39:05.280 --> 0:39:09.480
<v Speaker 1>with a lawsuit to hand over the list of attendees,

0:39:09.560 --> 0:39:13.560
<v Speaker 1>they can't because there's no record apart from just cash

0:39:13.600 --> 0:39:16.839
<v Speaker 1>transactions which don't have any paper trail to them other

0:39:16.880 --> 0:39:19.400
<v Speaker 1>than there's a badge and there was cash given for it.

0:39:19.719 --> 0:39:23.000
<v Speaker 1>There's no name associated with that, no credit card, no location.

0:39:23.719 --> 0:39:26.640
<v Speaker 1>So that's one of the reasons Jeff Moss insists on

0:39:26.719 --> 0:39:30.239
<v Speaker 1>doing cash only. And while the cost might be a

0:39:30.239 --> 0:39:32.399
<v Speaker 1>couple hundred dollars to get in, you're really getting into

0:39:32.440 --> 0:39:36.279
<v Speaker 1>a bunch of different conferences, all related to information security

0:39:36.719 --> 0:39:40.040
<v Speaker 1>and hacking and programming. There are tons of different projects

0:39:40.080 --> 0:39:42.560
<v Speaker 1>and tracks that you can follow, and lots of different

0:39:42.560 --> 0:39:45.200
<v Speaker 1>activities you can participate in. For example, if you ever

0:39:45.239 --> 0:39:47.279
<v Speaker 1>wanted to learn how to pick locks, you can head

0:39:47.320 --> 0:39:49.560
<v Speaker 1>over to lock pick Village at def Con and get

0:39:49.560 --> 0:39:52.360
<v Speaker 1>a lesson. Within five to ten minutes, you might be

0:39:52.400 --> 0:39:55.160
<v Speaker 1>picking locks. You can practice your skills on various types

0:39:55.200 --> 0:39:57.560
<v Speaker 1>of locks. You can learn how they work and how

0:39:57.600 --> 0:40:00.000
<v Speaker 1>they're vulnerable. And again this isn't so that you can

0:40:00.080 --> 0:40:04.160
<v Speaker 1>become a cat burglar extraordinaire, but rather understand how secure

0:40:04.200 --> 0:40:07.360
<v Speaker 1>these locks actually are. So if a lock is fiendishly

0:40:07.440 --> 0:40:09.839
<v Speaker 1>difficult to pick, that's a darn fine lock and one

0:40:09.920 --> 0:40:12.200
<v Speaker 1>you might want to use for yourself. You might want

0:40:12.200 --> 0:40:14.520
<v Speaker 1>to use that to secure your belongings. But if you

0:40:14.600 --> 0:40:16.200
<v Speaker 1>find a lock that you're able to get in in

0:40:16.280 --> 0:40:19.440
<v Speaker 1>less than five minutes with bare minimum training, that's probably

0:40:19.440 --> 0:40:22.000
<v Speaker 1>not the best lock to use. So in a way,

0:40:22.040 --> 0:40:25.200
<v Speaker 1>it's kind of a consumer service learning which locks are

0:40:25.239 --> 0:40:29.279
<v Speaker 1>really the most reliable, because you can bet the bad

0:40:29.320 --> 0:40:33.879
<v Speaker 1>guys already know this, that's what they look for, So

0:40:34.080 --> 0:40:36.640
<v Speaker 1>learning it and then putting that information to use is

0:40:36.680 --> 0:40:39.040
<v Speaker 1>actually a good thing because it means that you're keeping

0:40:39.040 --> 0:40:44.520
<v Speaker 1>stuff safe. The conference and its attendees haven't been connected

0:40:44.520 --> 0:40:47.400
<v Speaker 1>to some stuff that goes beyond pranks and mischief, maybe

0:40:47.440 --> 0:40:53.080
<v Speaker 1>some stuff that crosses over into illegal territory. Mostly the attendees,

0:40:53.200 --> 0:40:56.160
<v Speaker 1>not really the conference. The conference does try very hard

0:40:56.200 --> 0:40:59.759
<v Speaker 1>to distance itself from anything that is outright illegal. Most

0:40:59.760 --> 0:41:02.719
<v Speaker 1>of the stuff that they encourage is more on the

0:41:02.760 --> 0:41:06.279
<v Speaker 1>mischief side of things. But some people have decided that

0:41:06.320 --> 0:41:08.279
<v Speaker 1>while they're attending def Con they want to try and

0:41:08.360 --> 0:41:11.800
<v Speaker 1>show off and shut down maybe a computer system belonging

0:41:11.840 --> 0:41:15.640
<v Speaker 1>to a particularly powerful company or organization. And some of

0:41:15.640 --> 0:41:18.120
<v Speaker 1>that is for bragging rights. Uh. Some of that is

0:41:18.160 --> 0:41:20.319
<v Speaker 1>because a lot of the attendees have kind of an

0:41:20.360 --> 0:41:24.359
<v Speaker 1>anarchist ethos that they subscribe to, but not everybody does.

0:41:24.560 --> 0:41:27.880
<v Speaker 1>It's not like it's just a convention filled with people

0:41:27.920 --> 0:41:32.160
<v Speaker 1>trying to watch the world burn. There are some interesting stuff,

0:41:32.239 --> 0:41:35.680
<v Speaker 1>like I love that there's a competition to take a

0:41:35.840 --> 0:41:39.800
<v Speaker 1>box that has a lot of tamper proof materials inside

0:41:39.800 --> 0:41:42.160
<v Speaker 1>of it, and your job is to access all of

0:41:42.200 --> 0:41:45.720
<v Speaker 1>those materials in that tamper proof system and then return

0:41:45.840 --> 0:41:48.400
<v Speaker 1>them so that it looks like you haven't tampered with

0:41:48.440 --> 0:41:51.800
<v Speaker 1>it at all. It requires a lot of creative thinking

0:41:52.160 --> 0:41:55.960
<v Speaker 1>and using different skills if you want to actually be

0:41:56.080 --> 0:42:02.120
<v Speaker 1>able to get into that stuff without being found out. Now,

0:42:02.160 --> 0:42:05.799
<v Speaker 1>there's a ton of other things that go on over

0:42:05.840 --> 0:42:09.000
<v Speaker 1>at def Con and interesting stories that come out of it,

0:42:09.280 --> 0:42:11.359
<v Speaker 1>but I think the best way to learn about it

0:42:11.400 --> 0:42:13.960
<v Speaker 1>is to talk to someone who has been there. So

0:42:14.000 --> 0:42:16.520
<v Speaker 1>when we come back, I'm gonna have a little conversation

0:42:16.680 --> 0:42:20.280
<v Speaker 1>with my friend Shannon Morris. We'll talk about her experiences

0:42:20.320 --> 0:42:22.640
<v Speaker 1>of attending def Con. But we'll talk about that in

0:42:22.680 --> 0:42:25.080
<v Speaker 1>just a second after we take this quick break to

0:42:25.239 --> 0:42:35.799
<v Speaker 1>thank our sponsor guys. I am so pleased we are

0:42:35.960 --> 0:42:39.359
<v Speaker 1>joined by Shannon Morris, a good friend of mine. She's

0:42:39.400 --> 0:42:41.319
<v Speaker 1>been on the show a few times and she has

0:42:41.440 --> 0:42:45.560
<v Speaker 1>generously agreed to dedicate some of her precious time to

0:42:45.680 --> 0:42:48.360
<v Speaker 1>talking with us about def Con. Shannon, Welcome back to

0:42:48.400 --> 0:42:52.200
<v Speaker 1>Tech Stuff. Hi, how are you doing, Jonathan? I'm great.

0:42:52.920 --> 0:42:55.920
<v Speaker 1>I'm so happy that you are here. So to catch

0:42:56.000 --> 0:43:00.520
<v Speaker 1>you up, Shannon. What has happened previously? On text I

0:43:00.600 --> 0:43:03.960
<v Speaker 1>recorded an episode about the history of def Con. But

0:43:04.480 --> 0:43:07.920
<v Speaker 1>I told all my listeners I have not ever actually

0:43:07.960 --> 0:43:10.520
<v Speaker 1>been to a deaf Con. However, you have been to

0:43:10.840 --> 0:43:14.399
<v Speaker 1>a couple. How many deaf cons have you attended? Almost ten?

0:43:14.719 --> 0:43:17.000
<v Speaker 1>The first year I went, I believe was in two

0:43:17.000 --> 0:43:21.680
<v Speaker 1>thousand eight and I never stopped going, So come next year,

0:43:21.719 --> 0:43:25.840
<v Speaker 1>it'll be a decade awesome. So, as someone who has

0:43:25.840 --> 0:43:28.719
<v Speaker 1>actually attended def con, can you can you tell me

0:43:28.800 --> 0:43:32.440
<v Speaker 1>in your own words, how would you describe the convention

0:43:32.480 --> 0:43:35.319
<v Speaker 1>to someone who has only heard the name but has

0:43:35.360 --> 0:43:38.719
<v Speaker 1>no real idea of what it's all about. So I

0:43:38.760 --> 0:43:43.719
<v Speaker 1>would say def Con is it's the largest hacker con

0:43:44.080 --> 0:43:47.600
<v Speaker 1>in the United States. But it's not only hackers that go.

0:43:48.360 --> 0:43:53.280
<v Speaker 1>Sometimes it's government people, sometimes it's hackers uh, and sometimes

0:43:53.360 --> 0:43:57.319
<v Speaker 1>it's the kids that the hackers have had that will

0:43:57.360 --> 0:44:00.320
<v Speaker 1>also go to the convention. So a lot of people

0:44:00.360 --> 0:44:03.319
<v Speaker 1>go to this convention in Las Vegas every single year,

0:44:03.800 --> 0:44:07.640
<v Speaker 1>uh in the summertime, and we lovingly refer to it

0:44:07.719 --> 0:44:12.080
<v Speaker 1>as hashtag hacker summer camp because it is always it

0:44:12.080 --> 0:44:15.040
<v Speaker 1>always feels like it's a big family get together. There's

0:44:15.080 --> 0:44:18.680
<v Speaker 1>lots of hugs, there's a lot of get togethers after

0:44:18.760 --> 0:44:22.080
<v Speaker 1>the convention hours, like at restaurants and stuff like that

0:44:22.160 --> 0:44:24.720
<v Speaker 1>just to hang out. UH. And it's also a big party.

0:44:24.920 --> 0:44:27.240
<v Speaker 1>There's a lot of partying. There's a lot of booze

0:44:27.280 --> 0:44:30.360
<v Speaker 1>for the people that can legally drink UH and there's

0:44:30.400 --> 0:44:33.360
<v Speaker 1>a lot of really good time. So it's it's become

0:44:33.840 --> 0:44:35.800
<v Speaker 1>a really big part of my life in the fact

0:44:35.840 --> 0:44:39.080
<v Speaker 1>that a lot of my very close friends, some of

0:44:39.120 --> 0:44:41.719
<v Speaker 1>which that went to my wedding, even I met at

0:44:41.760 --> 0:44:44.160
<v Speaker 1>def Con. So it's it's a big part of my life.

0:44:44.800 --> 0:44:48.160
<v Speaker 1>So what would it be like like walk people through?

0:44:48.680 --> 0:44:51.799
<v Speaker 1>I know that there's not really a typical def Con experience,

0:44:51.840 --> 0:44:55.200
<v Speaker 1>as most conventions tend to change quite a bit from

0:44:55.320 --> 0:44:58.439
<v Speaker 1>year to year. They do this because they don't want

0:44:58.480 --> 0:45:01.839
<v Speaker 1>to remain static and just be known for the same thing.

0:45:02.280 --> 0:45:05.360
<v Speaker 1>But if you were attending def Con, what are the

0:45:05.400 --> 0:45:07.880
<v Speaker 1>sort of things you would be going to? Like do

0:45:07.920 --> 0:45:10.360
<v Speaker 1>you get do you go to any of the presentations

0:45:10.400 --> 0:45:14.000
<v Speaker 1>for example? So for me, Um, I'm not your normal

0:45:14.080 --> 0:45:17.680
<v Speaker 1>convention goer. I always go as either either press or

0:45:17.840 --> 0:45:21.120
<v Speaker 1>as a vendor. Uh so I usually get my badge

0:45:21.160 --> 0:45:23.359
<v Speaker 1>ahead of time. I pay for my badge ahead of time.

0:45:23.680 --> 0:45:26.360
<v Speaker 1>But for an attendee, what you have to do is

0:45:26.520 --> 0:45:28.680
<v Speaker 1>show up on the first day, stand in a really

0:45:28.719 --> 0:45:31.439
<v Speaker 1>really long line, and pay in cash because they don't

0:45:31.440 --> 0:45:35.239
<v Speaker 1>accept any credit cards and that's for the hacker anonymity.

0:45:35.880 --> 0:45:38.520
<v Speaker 1>But once you get there, you just stand in line

0:45:38.560 --> 0:45:41.080
<v Speaker 1>you pay. I think this year was like two hundred

0:45:41.120 --> 0:45:43.040
<v Speaker 1>dollars in cash or something like that, and then you

0:45:43.080 --> 0:45:45.839
<v Speaker 1>get your badge and you're good to go. Um. There

0:45:45.880 --> 0:45:50.040
<v Speaker 1>are talks, there are the vendor the vendor hall, of course,

0:45:50.120 --> 0:45:52.800
<v Speaker 1>and then there's also a whole bunch of different rooms

0:45:52.840 --> 0:45:55.919
<v Speaker 1>that you can hang out and called villages. Um. Each

0:45:55.960 --> 0:45:59.560
<v Speaker 1>of these villages kind of focuses on a hacker specialty,

0:46:00.040 --> 0:46:04.480
<v Speaker 1>whether that is WiFi hacking or car hacking. There's a

0:46:04.520 --> 0:46:07.440
<v Speaker 1>lock picking village. There's even a village that is just

0:46:07.560 --> 0:46:10.279
<v Speaker 1>for kids. So you can pretty much find whatever you

0:46:10.320 --> 0:46:12.480
<v Speaker 1>are interested in, as long as it has to do

0:46:12.560 --> 0:46:16.080
<v Speaker 1>with breaking things and then making them work again, which

0:46:16.120 --> 0:46:19.439
<v Speaker 1>is kind of the epitome of being a hacker, right,

0:46:19.480 --> 0:46:21.680
<v Speaker 1>And I'm glad you brought that up, because, as I

0:46:21.760 --> 0:46:25.880
<v Speaker 1>mentioned in the podcast section where I was chatting about

0:46:26.000 --> 0:46:32.480
<v Speaker 1>this whole concept, the term hacker has been misused dramatically

0:46:32.680 --> 0:46:36.680
<v Speaker 1>over the past twenty thirty years, and it's been the

0:46:36.760 --> 0:46:41.080
<v Speaker 1>definition has been too narrow for the common definition, because

0:46:41.120 --> 0:46:44.919
<v Speaker 1>of course, hacker originally meant people who, as you say,

0:46:44.960 --> 0:46:47.080
<v Speaker 1>like to take things apart, see how they work, put

0:46:47.080 --> 0:46:49.799
<v Speaker 1>them back together, maybe tweak them so they do something

0:46:49.840 --> 0:46:52.759
<v Speaker 1>they weren't intended to do in the first place, or

0:46:52.840 --> 0:46:55.640
<v Speaker 1>maybe do it differently, or perhaps even do it better

0:46:55.680 --> 0:46:59.400
<v Speaker 1>than it had been doing before. But it didn't necessarily

0:46:59.520 --> 0:47:02.600
<v Speaker 1>have this connotation that it tends to have in popular media,

0:47:02.680 --> 0:47:07.279
<v Speaker 1>which is a person who specializes in uh, penetrating a

0:47:07.400 --> 0:47:11.440
<v Speaker 1>secure system and then exploiting it in some way. Yeah. Absolutely,

0:47:11.480 --> 0:47:13.239
<v Speaker 1>I think a lot of and I know we've talked

0:47:13.239 --> 0:47:16.080
<v Speaker 1>about this before, but I think a lot of the

0:47:16.160 --> 0:47:19.920
<v Speaker 1>hacker name in the biased against it comes from Hollywood,

0:47:19.960 --> 0:47:23.279
<v Speaker 1>like the Hollywood core movies and TV shows that we

0:47:23.320 --> 0:47:26.000
<v Speaker 1>have seen in the eighties and nineties that have made

0:47:26.080 --> 0:47:28.480
<v Speaker 1>us think like, oh, hackers are really bad people, like

0:47:28.520 --> 0:47:30.320
<v Speaker 1>there is no way you could be a good hacker.

0:47:30.600 --> 0:47:33.640
<v Speaker 1>But that's actually not true of all of the hackers

0:47:33.680 --> 0:47:36.759
<v Speaker 1>I know. I don't know anybody that does something illegal.

0:47:37.080 --> 0:47:39.759
<v Speaker 1>All of them work as a penetration tester, as a

0:47:39.800 --> 0:47:42.920
<v Speaker 1>professional who goes in with a contract to a company

0:47:42.960 --> 0:47:46.480
<v Speaker 1>and then breaks into their network under that contract to

0:47:46.560 --> 0:47:49.040
<v Speaker 1>make sure that it is safe. Because if you don't

0:47:49.080 --> 0:47:52.239
<v Speaker 1>take the time to find the vulnerabilities, you won't know

0:47:52.280 --> 0:47:55.480
<v Speaker 1>how to secure yourself in the future. So hackers for

0:47:55.520 --> 0:47:58.120
<v Speaker 1>me are the good guys. And I think um a

0:47:58.160 --> 0:48:01.560
<v Speaker 1>lot of our community and lot of the people out

0:48:01.560 --> 0:48:04.520
<v Speaker 1>in the world who don't really understand hackers. What they

0:48:04.560 --> 0:48:07.480
<v Speaker 1>need to relate to is the fact that hackers are

0:48:07.520 --> 0:48:10.120
<v Speaker 1>good people who come in and make sure your stuff

0:48:10.160 --> 0:48:12.920
<v Speaker 1>is safe. Because there are bad guys out there, but

0:48:12.960 --> 0:48:15.400
<v Speaker 1>I don't refer to them as hackers. I refer to

0:48:15.440 --> 0:48:19.960
<v Speaker 1>them as criminals, right right. And I'm glad you mentioned

0:48:20.000 --> 0:48:22.120
<v Speaker 1>that too, because we've seen in the past a lot

0:48:22.200 --> 0:48:28.080
<v Speaker 1>of different def Con presentations, for example, have focused on vulnerabilities,

0:48:28.400 --> 0:48:31.360
<v Speaker 1>and it becomes clear that the presenter has said, you know,

0:48:31.400 --> 0:48:34.640
<v Speaker 1>in multiple instances of this that I tried to reach

0:48:34.640 --> 0:48:37.440
<v Speaker 1>out there was either no one to reach out to

0:48:38.080 --> 0:48:41.160
<v Speaker 1>or no one would listen to me about this vulnerability.

0:48:41.239 --> 0:48:43.520
<v Speaker 1>And so in order to force the issue, I am

0:48:43.520 --> 0:48:47.279
<v Speaker 1>going to bring this forward to everybody because because trust me,

0:48:47.520 --> 0:48:49.600
<v Speaker 1>if I don't talk about it, it just means the

0:48:49.640 --> 0:48:52.200
<v Speaker 1>people who are aware of it are going to exploit it.

0:48:52.239 --> 0:48:54.800
<v Speaker 1>If I talk about it, then it forces the hand

0:48:55.520 --> 0:48:59.520
<v Speaker 1>of whatever entity to patch that vulnerability or address it

0:48:59.600 --> 0:49:04.480
<v Speaker 1>in some way, because secrecy only helps the criminals, it

0:49:04.520 --> 0:49:08.120
<v Speaker 1>doesn't help like the The The assumption is that if

0:49:08.200 --> 0:49:11.040
<v Speaker 1>I talk about this thing, I've opened up the floodgates

0:49:11.040 --> 0:49:14.560
<v Speaker 1>and everyone can exploit it. Trust me, the criminals know already,

0:49:14.719 --> 0:49:17.400
<v Speaker 1>they're just not talking about it. Yeah, exactly a lot

0:49:17.440 --> 0:49:19.920
<v Speaker 1>of times you'll see these hawks that are exactly just that.

0:49:20.440 --> 0:49:24.040
<v Speaker 1>Um At Defcon, somebody will bring up a presentation and

0:49:24.200 --> 0:49:26.600
<v Speaker 1>turn in a call for paper paper to the def

0:49:26.680 --> 0:49:29.759
<v Speaker 1>Con committee, and they'll either accept it or deny it.

0:49:29.800 --> 0:49:32.279
<v Speaker 1>And when they show up at the convention and give

0:49:32.320 --> 0:49:36.760
<v Speaker 1>their talk, that's generally a very important disclaimer to say is, hey,

0:49:36.880 --> 0:49:39.719
<v Speaker 1>I reached out to this company two or three times,

0:49:39.840 --> 0:49:42.279
<v Speaker 1>I gave them six months to fix it. It has

0:49:42.320 --> 0:49:45.120
<v Speaker 1>not been fixed. Or maybe on the other hand, they

0:49:45.120 --> 0:49:47.239
<v Speaker 1>could say I reached out to the company, this has

0:49:47.280 --> 0:49:49.840
<v Speaker 1>already been fixed, but this is what I found and

0:49:49.920 --> 0:49:52.520
<v Speaker 1>this is why you need to update. For example, if

0:49:52.640 --> 0:49:56.239
<v Speaker 1>there is a smartphone vulnerability, they might say this has

0:49:56.280 --> 0:50:00.879
<v Speaker 1>already been released by the operating systems smartphone manufacture. Uh,

0:50:01.080 --> 0:50:03.520
<v Speaker 1>so this is very important for you to make sure

0:50:03.560 --> 0:50:06.440
<v Speaker 1>that you are updating on your own personal devices or

0:50:06.520 --> 0:50:09.520
<v Speaker 1>something around that. But basically they'll go in, they'll give

0:50:09.520 --> 0:50:13.719
<v Speaker 1>this disclaimer and then hopefully the company won't go after them.

0:50:14.320 --> 0:50:17.719
<v Speaker 1>After that fact, because since they can prove that they've

0:50:17.760 --> 0:50:20.880
<v Speaker 1>already reached out to this company, they have that that

0:50:20.960 --> 0:50:25.239
<v Speaker 1>they can fall back on. So there's unfortunately, there's a

0:50:25.239 --> 0:50:28.799
<v Speaker 1>lot of uh legal issues when it comes to what

0:50:28.880 --> 0:50:31.399
<v Speaker 1>information you can release, and a lot of it comes

0:50:31.440 --> 0:50:34.120
<v Speaker 1>down to you, how is the company actually dealing with

0:50:34.160 --> 0:50:36.839
<v Speaker 1>these things behind the scenes, Like what do what kind

0:50:36.880 --> 0:50:43.040
<v Speaker 1>of policies do they have in place for their own devices? Wow? Yeah,

0:50:43.120 --> 0:50:47.279
<v Speaker 1>I mean it's to me, it's fascinating to take that

0:50:47.360 --> 0:50:52.520
<v Speaker 1>into consideration, the idea that uh, this this this group

0:50:52.640 --> 0:50:55.600
<v Speaker 1>that has this reputation. Mostly I think because a lot

0:50:55.600 --> 0:50:57.400
<v Speaker 1>of the people over at Defcon also have kind of

0:50:57.400 --> 0:51:00.640
<v Speaker 1>a mischievous streak. So there's a lot of Yeah, there's

0:51:00.640 --> 0:51:02.319
<v Speaker 1>a lot of mischief making. I'm gonna ask you about

0:51:02.360 --> 0:51:05.120
<v Speaker 1>that in a minute. Uh, but there's a lot of

0:51:05.200 --> 0:51:07.600
<v Speaker 1>mischief making that goes on at the convention. It's largely

0:51:07.640 --> 0:51:10.160
<v Speaker 1>because you know, once you know how something works, it's

0:51:10.160 --> 0:51:11.919
<v Speaker 1>a lot of fun to show that off to other

0:51:12.000 --> 0:51:15.680
<v Speaker 1>people and sometimes show how it could potentially be misused.

0:51:15.760 --> 0:51:19.800
<v Speaker 1>Not in a way of like maliciously trying to promote

0:51:19.840 --> 0:51:22.680
<v Speaker 1>that misuse, but rather say, like, look at this crazy

0:51:22.760 --> 0:51:26.680
<v Speaker 1>thing I found and uh, this should not exist or

0:51:26.800 --> 0:51:29.880
<v Speaker 1>or the fact that this exists delights me, but however

0:51:29.920 --> 0:51:33.000
<v Speaker 1>we should probably address it. But it is interesting to

0:51:33.120 --> 0:51:36.720
<v Speaker 1>also know that, you know, there's this very cognizant approach

0:51:37.680 --> 0:51:40.640
<v Speaker 1>to what can and cannot be said. So that's so,

0:51:40.680 --> 0:51:42.560
<v Speaker 1>that's so that it's all done in it and as

0:51:42.760 --> 0:51:46.200
<v Speaker 1>as responsible away as possible. I mean, there is definitely

0:51:46.280 --> 0:51:48.520
<v Speaker 1>a tongue in cheek kind of approach. I mean the

0:51:48.560 --> 0:51:50.840
<v Speaker 1>thing that the convention is called def Con, and it

0:51:50.960 --> 0:51:54.520
<v Speaker 1>largely is because of the movie War Games, which is

0:51:54.560 --> 0:51:57.760
<v Speaker 1>one of those Hollywood films that has created this image

0:51:57.760 --> 0:52:00.399
<v Speaker 1>of the hacker that although I would you the War

0:52:00.480 --> 0:52:03.759
<v Speaker 1>Games hacker was more mischievous than anything else. Uh that uh,

0:52:04.040 --> 0:52:08.839
<v Speaker 1>that has continued to be perpetuated in media. Uh So

0:52:09.000 --> 0:52:12.080
<v Speaker 1>let me ask you this, like, as a vendor, I

0:52:12.160 --> 0:52:16.520
<v Speaker 1>understand that it's a pretty small number of vendors in

0:52:16.560 --> 0:52:18.719
<v Speaker 1>the grand scheme of things that tend to be invited

0:52:18.719 --> 0:52:21.399
<v Speaker 1>to def Con. Isn't it one of those things where

0:52:21.400 --> 0:52:24.680
<v Speaker 1>every single vendor must be approved before they can actually

0:52:25.120 --> 0:52:28.080
<v Speaker 1>uh show up and set up a table. That's correct, Yeah,

0:52:28.200 --> 0:52:30.799
<v Speaker 1>you have to be approved as a vendor. You ask

0:52:31.080 --> 0:52:33.200
<v Speaker 1>you also have to pay a fee for that table,

0:52:33.840 --> 0:52:36.880
<v Speaker 1>which is why you know, we we generally choose to

0:52:36.880 --> 0:52:39.280
<v Speaker 1>go to def Con and not the smaller cons because

0:52:39.440 --> 0:52:42.919
<v Speaker 1>since uh, yes, we do have to pay a rather

0:52:43.000 --> 0:52:46.520
<v Speaker 1>expensive fee, but we also have a very large audience

0:52:46.560 --> 0:52:49.919
<v Speaker 1>that is coming to purchased equipment from us, it ends

0:52:49.960 --> 0:52:52.319
<v Speaker 1>up offsetting the cost, so it ends up working out

0:52:52.360 --> 0:52:56.280
<v Speaker 1>pretty well. Um, but as a vendor, each and everyone

0:52:56.320 --> 0:52:59.080
<v Speaker 1>has to apply. You don't get invited every year anything

0:52:59.120 --> 0:53:01.239
<v Speaker 1>like that. So even the Hack five has been going

0:53:01.280 --> 0:53:03.160
<v Speaker 1>for ten years, Hack five is the company that I

0:53:03.200 --> 0:53:07.560
<v Speaker 1>work with, We've never been invited. We've always had to apply.

0:53:08.120 --> 0:53:11.040
<v Speaker 1>And with that application, you know, you go through all

0:53:11.040 --> 0:53:13.720
<v Speaker 1>the business e jargon, but you also have to say like, hey,

0:53:13.760 --> 0:53:15.960
<v Speaker 1>this is why I think we should go to the convention,

0:53:15.960 --> 0:53:18.120
<v Speaker 1>and this is what we think that we can bring

0:53:18.160 --> 0:53:21.000
<v Speaker 1>to it. In Hack five's case, we are filling this

0:53:21.120 --> 0:53:25.840
<v Speaker 1>void of giving giving the hacker community something that is

0:53:25.920 --> 0:53:30.000
<v Speaker 1>very introductory. A lot of the community basis on very

0:53:30.120 --> 0:53:36.200
<v Speaker 1>expertise related information that may already assume that you already

0:53:36.239 --> 0:53:39.840
<v Speaker 1>know the foundational information that you need to use equipment.

0:53:40.160 --> 0:53:41.880
<v Speaker 1>So we came in and we were like, hey, we

0:53:41.920 --> 0:53:45.560
<v Speaker 1>need to introduce something that gives beginners a way to

0:53:46.080 --> 0:53:48.759
<v Speaker 1>understand how to use not only to the devices that

0:53:48.800 --> 0:53:52.120
<v Speaker 1>we use, but also understand the fundamentals of why these

0:53:52.160 --> 0:53:54.880
<v Speaker 1>devices were built. Uh so, and that's one of the

0:53:54.880 --> 0:53:58.319
<v Speaker 1>reasons why we also do podcasts. But the vendors come in,

0:53:58.400 --> 0:54:00.879
<v Speaker 1>we all build our own boot so nobody builds them

0:54:00.920 --> 0:54:03.240
<v Speaker 1>for us. Of course, if you want to hang anything,

0:54:03.360 --> 0:54:07.040
<v Speaker 1>there's the the unions in Las Vegas that will do

0:54:07.080 --> 0:54:10.040
<v Speaker 1>that for you. But we set up our own boots

0:54:10.040 --> 0:54:14.000
<v Speaker 1>and we sell our equipment throughout the weekend. One big

0:54:14.040 --> 0:54:17.480
<v Speaker 1>thing that vendors have noticed in recent years is even

0:54:17.560 --> 0:54:21.400
<v Speaker 1>though the convention itself only accepts cash at the door,

0:54:21.760 --> 0:54:25.279
<v Speaker 1>a lot more people that are coming as guests or

0:54:25.320 --> 0:54:29.000
<v Speaker 1>attendees are paying with credit card, which is the strangest

0:54:29.040 --> 0:54:32.920
<v Speaker 1>thing given that it's a hacker con and the general

0:54:32.960 --> 0:54:35.400
<v Speaker 1>consensus is you do not want to use your credit

0:54:35.400 --> 0:54:38.480
<v Speaker 1>card whenever you are at the convention, but people still do.

0:54:38.560 --> 0:54:41.680
<v Speaker 1>And I think it's because since we as vendors are

0:54:41.800 --> 0:54:44.000
<v Speaker 1>part of the community, they trust us not to take

0:54:44.040 --> 0:54:46.640
<v Speaker 1>advantage of that. And we are using third parties, you know,

0:54:46.680 --> 0:54:50.400
<v Speaker 1>we're using Square, we're using Shopify or whatever. The company

0:54:50.520 --> 0:54:52.680
<v Speaker 1>might be that you choose to use at the convention,

0:54:53.040 --> 0:54:56.560
<v Speaker 1>so they know that their information is um encrypted and

0:54:56.600 --> 0:54:59.200
<v Speaker 1>it's safe with that third party, and we don't actually

0:54:59.239 --> 0:55:02.440
<v Speaker 1>even see anything except for the physical card, right, So

0:55:02.480 --> 0:55:05.560
<v Speaker 1>you can't if you were for some reason, let's say,

0:55:05.680 --> 0:55:09.560
<v Speaker 1>a shadowy government agency or command commanding you to hand

0:55:09.640 --> 0:55:13.360
<v Speaker 1>over those customer transactions. All you would have is just

0:55:13.440 --> 0:55:16.279
<v Speaker 1>the fact that well, we've got I can't give you

0:55:16.320 --> 0:55:19.319
<v Speaker 1>any more data than this. This is not I know that.

0:55:19.320 --> 0:55:21.680
<v Speaker 1>That's like the purpose behind cash only at the door

0:55:21.760 --> 0:55:24.239
<v Speaker 1>for the conventions that we aren't. We can't hand hand

0:55:24.320 --> 0:55:27.600
<v Speaker 1>over the people who are here because it's all a

0:55:27.680 --> 0:55:31.160
<v Speaker 1>cash based transaction. So you've either paid cash or you've

0:55:31.200 --> 0:55:36.800
<v Speaker 1>somehow managed to perfectly spoof the badge for that year, which,

0:55:36.800 --> 0:55:39.120
<v Speaker 1>as the founder of Deacon has said, like if you

0:55:39.160 --> 0:55:41.600
<v Speaker 1>can do it, then you probably deserve to be here.

0:55:42.360 --> 0:55:44.960
<v Speaker 1>Oh yeah, there's a whole bunch of contests that happened

0:55:44.960 --> 0:55:47.240
<v Speaker 1>at def Conto, and that's one of them where people

0:55:47.360 --> 0:55:49.680
<v Speaker 1>make their own badges to see who can make the

0:55:49.719 --> 0:55:52.759
<v Speaker 1>best one, and generally they'll either win something that's not

0:55:52.880 --> 0:55:59.120
<v Speaker 1>necessarily like a totally recorded contest, but you know, they

0:55:59.160 --> 0:56:01.200
<v Speaker 1>might go up to one of the goons that work

0:56:01.239 --> 0:56:03.480
<v Speaker 1>at Defcon and be like, hey, check out my badge,

0:56:03.480 --> 0:56:05.720
<v Speaker 1>and they might you know, end up giving them a prize.

0:56:06.040 --> 0:56:07.960
<v Speaker 1>There's a lot of really cool contests. There's a lot

0:56:07.960 --> 0:56:11.360
<v Speaker 1>of cool villages. There's the vendors, the talks um, There's

0:56:11.440 --> 0:56:14.080
<v Speaker 1>a lot of really interesting things that happen at Defcon.

0:56:14.440 --> 0:56:18.040
<v Speaker 1>There's also conventions that happen during dev Con in Vegas,

0:56:18.120 --> 0:56:19.640
<v Speaker 1>which is part of the reason why we call it

0:56:19.680 --> 0:56:24.000
<v Speaker 1>Hackers Summer Camp, because the whole community is getting a

0:56:24.080 --> 0:56:27.799
<v Speaker 1>lot more aware of being inclusive to minorities, to women too,

0:56:27.840 --> 0:56:31.000
<v Speaker 1>people that aren't necessarily you know, the norm that you

0:56:31.000 --> 0:56:34.160
<v Speaker 1>would see at Defcon. So for example, we're starting to

0:56:34.200 --> 0:56:37.920
<v Speaker 1>see um last I think in the last several years,

0:56:37.960 --> 0:56:40.719
<v Speaker 1>there's been Queer Con, which is for the l g

0:56:40.840 --> 0:56:44.160
<v Speaker 1>B t Q community. It's a big suite, it's a convention.

0:56:44.200 --> 0:56:46.359
<v Speaker 1>They also have their own pool party that people can

0:56:46.400 --> 0:56:49.920
<v Speaker 1>go to and everybody's invited. Of course. Uh, there's a

0:56:49.960 --> 0:56:54.000
<v Speaker 1>bunch of women's sweet setup that are very that generally

0:56:54.040 --> 0:56:57.480
<v Speaker 1>talked about inclusiveness for women. And there's you know, the

0:56:57.560 --> 0:57:01.600
<v Speaker 1>kids convention to the kids villages, so kids are invited.

0:57:01.640 --> 0:57:04.480
<v Speaker 1>It's not necessarily just like the twenty one upcrowd that

0:57:04.520 --> 0:57:07.600
<v Speaker 1>we've seen in the past. So it's becoming a much

0:57:07.680 --> 0:57:10.400
<v Speaker 1>larger convention. It's becoming a lot more friendly to people

0:57:10.400 --> 0:57:13.640
<v Speaker 1>that didn't necessarily uh know that they could go or

0:57:13.760 --> 0:57:16.040
<v Speaker 1>feel safe at the convention. And I think that's a

0:57:16.080 --> 0:57:19.080
<v Speaker 1>really positive effort that def con and the other conventions

0:57:19.080 --> 0:57:21.760
<v Speaker 1>that happen in Vegas are trying to do. Yeah, I

0:57:21.840 --> 0:57:24.400
<v Speaker 1>like that a lot. I like I like the fact that,

0:57:24.760 --> 0:57:28.760
<v Speaker 1>you know, because the general perception, more frequently than not,

0:57:28.920 --> 0:57:31.920
<v Speaker 1>I think of of what the stereotypical hacker is is

0:57:31.960 --> 0:57:35.600
<v Speaker 1>they tend to be twenty something to maybe early thirty something.

0:57:35.960 --> 0:57:38.640
<v Speaker 1>More frequently than not, they're portrayed as white, and they're

0:57:38.680 --> 0:57:44.240
<v Speaker 1>almost always male. And so to see that this convention

0:57:44.440 --> 0:57:49.919
<v Speaker 1>is actively or even just encouraging the participation of other

0:57:50.000 --> 0:57:53.440
<v Speaker 1>groups that don't fall into those categories and is acknowledging, Hey,

0:57:53.520 --> 0:57:56.880
<v Speaker 1>you know, there are people who are not falling into

0:57:56.920 --> 0:57:59.760
<v Speaker 1>the stereotypical view of what a hacker is supposed to be,

0:58:00.040 --> 0:58:04.000
<v Speaker 1>who have valid opinions, They have contributions to make to

0:58:04.040 --> 0:58:07.760
<v Speaker 1>the community, They have great ideas that we should listen to.

0:58:08.200 --> 0:58:10.720
<v Speaker 1>Is really encouraging, because you know, we we want to.

0:58:11.080 --> 0:58:13.200
<v Speaker 1>I've always been one of those people who championed the

0:58:13.280 --> 0:58:17.120
<v Speaker 1>idea of more inclusiveness with any sort of stem kind

0:58:17.120 --> 0:58:20.840
<v Speaker 1>of approach, and that includes hacking, and I'm pleased to

0:58:20.880 --> 0:58:23.480
<v Speaker 1>see that there are people who have taken up that

0:58:23.520 --> 0:58:26.600
<v Speaker 1>banner and they have really pushed it, especially over the

0:58:26.680 --> 0:58:28.760
<v Speaker 1>last few years. I was looking into some of the

0:58:28.760 --> 0:58:33.080
<v Speaker 1>stuff about the children's village, like you pointed out, and

0:58:33.120 --> 0:58:36.640
<v Speaker 1>I think it's fantastic that they book some of the

0:58:36.680 --> 0:58:40.400
<v Speaker 1>same speakers who give the big presentations to the entire con.

0:58:40.520 --> 0:58:42.640
<v Speaker 1>They'll come in and they'll do a session with the kids,

0:58:42.640 --> 0:58:45.200
<v Speaker 1>and I think that's amazing. You know that you're getting

0:58:45.200 --> 0:58:48.480
<v Speaker 1>these people, some of whom have national reputations in the

0:58:48.520 --> 0:58:51.920
<v Speaker 1>form of information security, coming in and talking to kids

0:58:52.000 --> 0:58:54.280
<v Speaker 1>on their level, like not talking down to them, because

0:58:54.360 --> 0:58:56.640
<v Speaker 1>kids are way smarter than we give them credit for,

0:58:57.240 --> 0:58:59.240
<v Speaker 1>and they pick up on this stuff way faster than

0:58:59.280 --> 0:59:02.840
<v Speaker 1>old fogies. Me um, it's great to see that. So

0:59:02.880 --> 0:59:06.680
<v Speaker 1>I find that really interesting. I am somewhat sad Shannon

0:59:07.320 --> 0:59:10.280
<v Speaker 1>that that your first your first def con was two

0:59:10.280 --> 0:59:13.360
<v Speaker 1>thousand eight, because it means I cannot ask you about

0:59:13.400 --> 0:59:20.080
<v Speaker 1>the legendary by gone days of the Alexis Park. I've

0:59:20.120 --> 0:59:24.760
<v Speaker 1>heard stories the last Alexis Park def Con took place

0:59:24.800 --> 0:59:27.280
<v Speaker 1>in two thousand five, so those days were over by

0:59:27.280 --> 0:59:30.040
<v Speaker 1>the time you came in. However, you have been there since.

0:59:30.080 --> 0:59:32.760
<v Speaker 1>They've changed locations a few times. It started off at

0:59:32.760 --> 0:59:35.400
<v Speaker 1>the Riviera Hotel, and then it was at the Rio,

0:59:35.640 --> 0:59:38.640
<v Speaker 1>and then at Paris and Valleys, and now I think

0:59:38.680 --> 0:59:42.120
<v Speaker 1>the most recent one was at Caesar's Palace, and it

0:59:42.160 --> 0:59:44.560
<v Speaker 1>will be at Caesar's Palace again next year as well.

0:59:45.440 --> 0:59:48.360
<v Speaker 1>So with those changes in location, have you noticed any

0:59:48.400 --> 0:59:51.880
<v Speaker 1>other like subsequent changes in the con itself or is

0:59:51.920 --> 0:59:53.800
<v Speaker 1>it just one of those things where it's just gotten

0:59:53.840 --> 0:59:58.360
<v Speaker 1>bigger with each change in venue. Um, it's mostly just

0:59:58.480 --> 1:00:01.200
<v Speaker 1>been getting bigger and bigger with the changes of venue,

1:00:01.280 --> 1:00:05.520
<v Speaker 1>and I think that's the main reason. Although given some

1:00:05.640 --> 1:00:08.480
<v Speaker 1>of the strange things that happened at the hotels, they

1:00:08.520 --> 1:00:12.840
<v Speaker 1>could change those hotels because of something else, Tangent Assigne.

1:00:12.880 --> 1:00:15.640
<v Speaker 1>More on that later, but yeah, it's It's one of

1:00:15.640 --> 1:00:17.920
<v Speaker 1>the really strange things about Defcon is the fact that

1:00:17.960 --> 1:00:22.880
<v Speaker 1>they do change hotels every two to three to four years. Uh,

1:00:22.880 --> 1:00:25.600
<v Speaker 1>And I don't know why that is necessarily because I'm

1:00:25.600 --> 1:00:27.840
<v Speaker 1>not on the board, but I can make my own

1:00:28.000 --> 1:00:31.440
<v Speaker 1>personal assumptions based on what I've seen. You know, first

1:00:31.480 --> 1:00:33.640
<v Speaker 1>of all, there's always i mean one, when you're ever,

1:00:33.720 --> 1:00:36.400
<v Speaker 1>you're doing events, planning for a big event, there's always

1:00:36.600 --> 1:00:38.960
<v Speaker 1>long term contract type stuff that you have to look at.

1:00:39.040 --> 1:00:41.240
<v Speaker 1>So there's that. So some of it could very well

1:00:41.280 --> 1:00:43.280
<v Speaker 1>be that it's just oh, we were only able to

1:00:43.320 --> 1:00:45.400
<v Speaker 1>secure that location for two years and we knew it

1:00:45.440 --> 1:00:48.480
<v Speaker 1>was going to be a transition. Sometimes it might be oh,

1:00:48.560 --> 1:00:51.520
<v Speaker 1>this hotel wasn't so pleased when it found out all

1:00:51.560 --> 1:00:56.320
<v Speaker 1>the elevator buttons were rewired to the wrong floor. Yeah,

1:00:56.520 --> 1:01:01.880
<v Speaker 1>So on that fact um, there have been many different

1:01:01.960 --> 1:01:05.200
<v Speaker 1>things that happen at dev Con, and it doesn't matter

1:01:05.240 --> 1:01:08.160
<v Speaker 1>which hotel is at there are always these funny little

1:01:08.160 --> 1:01:11.720
<v Speaker 1>pranks that get pulled all around the hotel. It could

1:01:11.760 --> 1:01:17.200
<v Speaker 1>be anything from the hotel elevators getting switched up like that.

1:01:17.480 --> 1:01:19.960
<v Speaker 1>It could be them getting stopped in the middle of

1:01:20.040 --> 1:01:24.040
<v Speaker 1>two floors. Uh. It could be a great example as

1:01:24.040 --> 1:01:26.680
<v Speaker 1>Caesar's Palace this year is they have a food court,

1:01:27.120 --> 1:01:29.760
<v Speaker 1>and the food court all of the different restaurants give

1:01:29.800 --> 1:01:34.840
<v Speaker 1>out those little wireless handset things. Uh, those little square

1:01:34.880 --> 1:01:38.320
<v Speaker 1>boxes that vibrate whenever your food is ready. They all

1:01:38.400 --> 1:01:41.400
<v Speaker 1>run on the same frequency. And of course, since you

1:01:41.480 --> 1:01:44.520
<v Speaker 1>have a bunch of hackers at Caesar's Palace, if they

1:01:44.520 --> 1:01:47.160
<v Speaker 1>find out everything runs on the same frequency and they

1:01:47.200 --> 1:01:51.120
<v Speaker 1>can recreate that pattern to make all of the devices

1:01:51.200 --> 1:01:53.560
<v Speaker 1>vibrate and go off at the same time, they will

1:01:53.600 --> 1:01:56.200
<v Speaker 1>do it, and then everybody's sitting in that food court

1:01:56.200 --> 1:01:58.640
<v Speaker 1>will stand up all at the same time expecting their

1:01:58.640 --> 1:02:03.200
<v Speaker 1>food to be ready. Wow. Um, I've seen another example

1:02:03.240 --> 1:02:07.080
<v Speaker 1>here in Caesar's Palace this year was Uh, there are

1:02:07.120 --> 1:02:09.680
<v Speaker 1>a whole bunch of statues that are supposed to be

1:02:09.720 --> 1:02:13.640
<v Speaker 1>like Roman, you know, the Roman gods, Roman, all the

1:02:13.680 --> 1:02:18.880
<v Speaker 1>different beings from histories past. And they're like animatronic, aren't they. Um.

1:02:18.920 --> 1:02:22.200
<v Speaker 1>There are some animatronic ones in one of the shopping centers,

1:02:23.040 --> 1:02:24.800
<v Speaker 1>and then a lot of the other ones are just

1:02:24.840 --> 1:02:26.840
<v Speaker 1>like made out of really nice stone and they're in

1:02:26.880 --> 1:02:29.520
<v Speaker 1>the middle of walking areas. They're very easy to get

1:02:29.600 --> 1:02:32.720
<v Speaker 1>up to. And Google eyes are a really big thing

1:02:32.920 --> 1:02:35.040
<v Speaker 1>at def Con, so you will find all of these

1:02:35.040 --> 1:02:39.320
<v Speaker 1>statues by the end of the convention weekend. With Google's

1:02:39.600 --> 1:02:43.440
<v Speaker 1>Google eyes on them, and it is the funniest thing. Luckily,

1:02:43.600 --> 1:02:46.919
<v Speaker 1>I think Caesar's Palace was really dealing with it kind

1:02:46.920 --> 1:02:49.680
<v Speaker 1>of humorously because they left a lot of those things

1:02:49.720 --> 1:02:52.240
<v Speaker 1>on even after the janitorial staff went through in the

1:02:52.240 --> 1:02:54.480
<v Speaker 1>middle of the night, So I think that they were

1:02:54.480 --> 1:02:57.919
<v Speaker 1>taking it with like a good positive appeal, like, hey,

1:02:57.960 --> 1:03:00.320
<v Speaker 1>this is a part of the hacker community, this is

1:03:00.400 --> 1:03:02.880
<v Speaker 1>def con, Like, this is what we were expecting. So

1:03:02.920 --> 1:03:04.440
<v Speaker 1>we're just going to leave those up for the weekend

1:03:04.440 --> 1:03:06.720
<v Speaker 1>and let y'all have your fun as long as you

1:03:06.760 --> 1:03:10.720
<v Speaker 1>do follow follow the rule of MPD no permanent damage. Yes,

1:03:10.760 --> 1:03:15.280
<v Speaker 1>no permanent damage. So luckily Google eyes don't cause permanent damage. Um.

1:03:15.320 --> 1:03:17.480
<v Speaker 1>I don't like it when the elevators get messed with

1:03:17.560 --> 1:03:19.800
<v Speaker 1>because I'm an old lady and I like to go

1:03:19.840 --> 1:03:22.040
<v Speaker 1>to sleep at night and not get stuck in an elevator,

1:03:22.040 --> 1:03:26.400
<v Speaker 1>which has happened before. But it also comes with the territory,

1:03:26.520 --> 1:03:28.600
<v Speaker 1>so I understand that if I'm going to def con,

1:03:28.800 --> 1:03:33.440
<v Speaker 1>those things will happen. Well, if you were if you

1:03:33.560 --> 1:03:38.200
<v Speaker 1>were talking to someone who was possibly thinking about going

1:03:38.240 --> 1:03:41.960
<v Speaker 1>to def con, what is what is your pitch and

1:03:42.120 --> 1:03:45.160
<v Speaker 1>convincing that person to say, like you know what, Yeah,

1:03:45.200 --> 1:03:47.560
<v Speaker 1>this is something that you should try. If you're interested

1:03:47.600 --> 1:03:49.320
<v Speaker 1>in it, you should give it a go. What would

1:03:49.320 --> 1:03:52.479
<v Speaker 1>you tell that person? So, I would say that def

1:03:52.520 --> 1:03:55.640
<v Speaker 1>Con is unlike any of the other hacker cons that

1:03:55.680 --> 1:03:58.880
<v Speaker 1>I've been to. All of the local conventions are much smaller,

1:03:58.880 --> 1:04:02.720
<v Speaker 1>which also have a huge deal of appeal. But if

1:04:02.760 --> 1:04:07.919
<v Speaker 1>you really want to see the uh the prankster def Con,

1:04:08.120 --> 1:04:11.160
<v Speaker 1>if you want to see the family get together, the

1:04:11.240 --> 1:04:14.640
<v Speaker 1>Hacker summer camp, if you want to get that huge

1:04:14.920 --> 1:04:17.520
<v Speaker 1>deal of inspiration throughout the weekend from all of the

1:04:17.560 --> 1:04:20.600
<v Speaker 1>different villages uh, and if you want to feel included.

1:04:20.960 --> 1:04:23.280
<v Speaker 1>Defcon has a code of Contact, which means that they

1:04:23.280 --> 1:04:26.400
<v Speaker 1>are very very inclusive, and if anything happens there, you

1:04:26.400 --> 1:04:29.040
<v Speaker 1>can report it and know that you'll be okay. UM.

1:04:29.280 --> 1:04:31.240
<v Speaker 1>Def Con is the one place that I go every year,

1:04:31.320 --> 1:04:34.520
<v Speaker 1>and I just love going, even though at the end

1:04:34.560 --> 1:04:37.320
<v Speaker 1>of the week my voice is shot, even though I

1:04:37.360 --> 1:04:39.880
<v Speaker 1>am tired, and sometimes I come home with the con

1:04:39.920 --> 1:04:42.600
<v Speaker 1>flu which will generally happen if you go to Vegas

1:04:42.640 --> 1:04:46.040
<v Speaker 1>and you don't drink enough water because it's a desert. Um.

1:04:46.080 --> 1:04:48.000
<v Speaker 1>It's it's the one place that I can go and

1:04:48.040 --> 1:04:51.480
<v Speaker 1>feel like I'm not only included, even as a woman

1:04:51.920 --> 1:04:55.240
<v Speaker 1>in a very even though I'm considered a minority in

1:04:55.280 --> 1:04:57.360
<v Speaker 1>the hacker genre, even as a woman, I can go

1:04:57.360 --> 1:05:01.200
<v Speaker 1>there and I feel included and I feel real embraced

1:05:01.280 --> 1:05:05.520
<v Speaker 1>in that community. But it's it's friendly, it's fun, and

1:05:06.200 --> 1:05:09.360
<v Speaker 1>it's big. It's huge. So if you're looking for a party,

1:05:09.400 --> 1:05:11.440
<v Speaker 1>it's also a very good time. If you're looking for

1:05:11.480 --> 1:05:13.360
<v Speaker 1>a job, it's a great place to go as well.

1:05:13.840 --> 1:05:18.080
<v Speaker 1>Oh yeah, fantastic uh networking opportunity in more ways than one.

1:05:18.880 --> 1:05:23.280
<v Speaker 1>Now I also have to ask, but this will kind

1:05:23.280 --> 1:05:26.600
<v Speaker 1>of be our sign off because I talked about in

1:05:26.680 --> 1:05:30.200
<v Speaker 1>the actual podcast, But I want to hear what your

1:05:30.280 --> 1:05:32.960
<v Speaker 1>thoughts are and perhaps just the sort of the general

1:05:33.640 --> 1:05:39.240
<v Speaker 1>uh conception of the Wall of Sheep. Um. Yes, so

1:05:39.320 --> 1:05:42.360
<v Speaker 1>the Wall of Sheep is hilarious. I think it is

1:05:42.400 --> 1:05:45.200
<v Speaker 1>a great way to spread awareness of the fact that

1:05:45.320 --> 1:05:50.200
<v Speaker 1>wireless is not necessarily safe. It is very vulnerable, especially

1:05:50.240 --> 1:05:52.600
<v Speaker 1>to people that go to the convention and forget to

1:05:52.640 --> 1:05:57.360
<v Speaker 1>turn wireless off on their devices. Um. I've never been

1:05:57.440 --> 1:05:59.240
<v Speaker 1>on the Wall of Sheep, so I can't tell you

1:05:59.280 --> 1:06:01.280
<v Speaker 1>from experience it is how it feels to be on

1:06:01.320 --> 1:06:04.400
<v Speaker 1>the wall of sheep, but I would probably be embarrassed

1:06:04.400 --> 1:06:06.360
<v Speaker 1>if I showed up on there, but I would take

1:06:06.400 --> 1:06:09.120
<v Speaker 1>it as a learning experience. If if I was to

1:06:09.160 --> 1:06:11.040
<v Speaker 1>show up on there, I would be like, Okay, how

1:06:11.080 --> 1:06:13.600
<v Speaker 1>did this happen? And I would want to learn so

1:06:13.640 --> 1:06:15.920
<v Speaker 1>that that would never happen to me again in the future,

1:06:16.200 --> 1:06:18.360
<v Speaker 1>and I could take that into the real world and

1:06:18.880 --> 1:06:23.240
<v Speaker 1>know that I am safe with my own devices. Right again. More,

1:06:23.680 --> 1:06:26.360
<v Speaker 1>while you might have suffer a little bit of embarrassment

1:06:26.400 --> 1:06:29.200
<v Speaker 1>in the short term as you appear on a wall,

1:06:29.680 --> 1:06:32.760
<v Speaker 1>the lesson you learn is more valuable because again, the

1:06:32.800 --> 1:06:35.960
<v Speaker 1>criminals aren't going to alert you that you are sharing

1:06:35.960 --> 1:06:39.080
<v Speaker 1>any information. They're going to be using that. So it's

1:06:39.120 --> 1:06:41.360
<v Speaker 1>better for you to be aware of it and be

1:06:41.480 --> 1:06:44.760
<v Speaker 1>able to prevent that from happening than to be unaware

1:06:44.760 --> 1:06:47.880
<v Speaker 1>of it and then just be taken advantage of perpetually.

1:06:48.560 --> 1:06:51.160
<v Speaker 1>So absolutely I see it. I see it as a

1:06:51.200 --> 1:06:53.280
<v Speaker 1>valuable service, even though I know that I would be

1:06:53.320 --> 1:06:55.640
<v Speaker 1>paranoid the entire time that was going to show up.

1:06:55.760 --> 1:06:57.880
<v Speaker 1>Do you take do you take a burner phone with you?

1:06:58.640 --> 1:07:01.880
<v Speaker 1>I used to um I I stopped doing the burner

1:07:01.920 --> 1:07:05.000
<v Speaker 1>phone just out of pure laziness the past few years,

1:07:05.440 --> 1:07:08.160
<v Speaker 1>which is very bad. You should take a burner phone

1:07:08.240 --> 1:07:12.200
<v Speaker 1>with you. I am not the norm, but there are

1:07:12.200 --> 1:07:14.160
<v Speaker 1>a few things that I would recommend to people that

1:07:14.200 --> 1:07:16.960
<v Speaker 1>are going just for their own security and privacy because

1:07:17.040 --> 1:07:21.520
<v Speaker 1>it is a very target rich environment. I would say,

1:07:21.560 --> 1:07:24.560
<v Speaker 1>if you can take a burner phone, UH, if you

1:07:24.600 --> 1:07:27.120
<v Speaker 1>can erase all the data off that burner phone, any

1:07:27.160 --> 1:07:30.280
<v Speaker 1>personal data, and don't log into like your bank, for example,

1:07:30.400 --> 1:07:33.480
<v Speaker 1>while you are at the convention on that phone. UM.

1:07:33.560 --> 1:07:37.560
<v Speaker 1>I would also recommend keeping NFC, Bluetooth, and wireless turned

1:07:37.600 --> 1:07:40.160
<v Speaker 1>off the entire time, because there are hacks for all

1:07:40.200 --> 1:07:44.240
<v Speaker 1>of those uh. And if you want to on sites

1:07:44.280 --> 1:07:47.800
<v Speaker 1>like Amazon, there's these really cool things called Faraday bags,

1:07:48.000 --> 1:07:51.200
<v Speaker 1>and I bought one myself and it works great. I've

1:07:51.240 --> 1:07:54.800
<v Speaker 1>tested it, and Faraday bags will If you put your

1:07:54.800 --> 1:07:57.680
<v Speaker 1>smartphone inside of a Faraday bag, the Faraday bag will

1:07:57.760 --> 1:08:01.960
<v Speaker 1>stop any kind of UH wireless frequencies from coming into

1:08:02.000 --> 1:08:05.000
<v Speaker 1>the bag and coming onto your device, so it'll protect

1:08:05.080 --> 1:08:07.880
<v Speaker 1>your device from anything out there that might be trying

1:08:07.920 --> 1:08:11.000
<v Speaker 1>to attack the devices in the wild. I would also

1:08:11.040 --> 1:08:15.120
<v Speaker 1>recommend water because it is Vegas, really good tennis shoes

1:08:15.160 --> 1:08:18.000
<v Speaker 1>because any hotel you go to that def Con is

1:08:18.040 --> 1:08:21.280
<v Speaker 1>in Ore, You'll you will be walking very very far

1:08:21.960 --> 1:08:24.519
<v Speaker 1>uh and get lots of sleep and make sure to

1:08:24.560 --> 1:08:28.400
<v Speaker 1>take a shower, just like any other convention. Yep. Personal

1:08:28.479 --> 1:08:31.200
<v Speaker 1>hygiene does not stop just because the convention has started. No,

1:08:31.320 --> 1:08:34.600
<v Speaker 1>it does not. Hand sanitizer not a bad idea, or

1:08:34.600 --> 1:08:37.120
<v Speaker 1>at least washing your hands frequently, not a bad idea

1:08:37.160 --> 1:08:40.400
<v Speaker 1>at any of these sort of conventions. I've been the

1:08:40.479 --> 1:08:43.360
<v Speaker 1>champion of that at c e S so many years running,

1:08:43.479 --> 1:08:45.799
<v Speaker 1>especially at a place like CES, because you're just handling

1:08:45.880 --> 1:08:49.040
<v Speaker 1>your handling stuff that so many other people have handled, Yes, exactly,

1:08:49.040 --> 1:08:53.080
<v Speaker 1>but valuable tips and take advantage of the learning experience

1:08:53.080 --> 1:08:54.800
<v Speaker 1>to make sure that you get out there and you

1:08:54.880 --> 1:08:57.280
<v Speaker 1>ask questions. Because the people that go to def Con

1:08:57.400 --> 1:09:00.840
<v Speaker 1>and have vendor booze have villages that they running there

1:09:00.880 --> 1:09:04.160
<v Speaker 1>there to answer your questions. I believe that no question

1:09:04.240 --> 1:09:07.000
<v Speaker 1>is a stupid question. If you are a beginner, you

1:09:07.080 --> 1:09:08.800
<v Speaker 1>come up to me and you ask a question. If

1:09:08.840 --> 1:09:11.400
<v Speaker 1>I don't think that my product that I'm selling at

1:09:11.400 --> 1:09:13.880
<v Speaker 1>my vendor booth is correct for you, I've I've done

1:09:13.880 --> 1:09:15.960
<v Speaker 1>this in the past. I will lead you out of

1:09:16.000 --> 1:09:18.280
<v Speaker 1>my booth and take you to the bookstore where you

1:09:18.320 --> 1:09:20.040
<v Speaker 1>can pick up a book that teaches you all the

1:09:20.080 --> 1:09:22.599
<v Speaker 1>fundamentals and the theory behind the products that we sell.

1:09:22.840 --> 1:09:25.879
<v Speaker 1>So I I highly recommend that if you're a beginner,

1:09:26.200 --> 1:09:29.080
<v Speaker 1>to go to these conventions, especially def COM, because the

1:09:29.240 --> 1:09:31.640
<v Speaker 1>learning experience that you'll you will get there and the

1:09:31.680 --> 1:09:34.960
<v Speaker 1>networking that you'll get is like no other You can't

1:09:35.000 --> 1:09:38.439
<v Speaker 1>get that same kind of experience online. Yeah. And and

1:09:38.439 --> 1:09:40.600
<v Speaker 1>in my now I've not been to death count, but

1:09:40.600 --> 1:09:43.920
<v Speaker 1>in my experience talking with people who do this sort

1:09:43.960 --> 1:09:47.559
<v Speaker 1>of stuff, they get they get a thrill out of

1:09:47.560 --> 1:09:50.360
<v Speaker 1>being able to talk about and explain it to other people.

1:09:50.520 --> 1:09:54.080
<v Speaker 1>They they enjoy sharing that knowledge. It's not like they're

1:09:54.120 --> 1:09:57.000
<v Speaker 1>hoarding knowledge and they don't want other people to have it.

1:09:57.560 --> 1:10:00.840
<v Speaker 1>So in fact, I often see it as the act opposite,

1:10:00.880 --> 1:10:03.200
<v Speaker 1>Like people learn something cool and they immediately want to

1:10:03.200 --> 1:10:05.160
<v Speaker 1>share it with other folks so that they also know

1:10:05.240 --> 1:10:08.280
<v Speaker 1>how to do it. So yeah, So that to me

1:10:08.400 --> 1:10:13.759
<v Speaker 1>is something that is really a valuable thing to take away,

1:10:13.880 --> 1:10:18.320
<v Speaker 1>is that these are folks who really want to share

1:10:18.400 --> 1:10:21.920
<v Speaker 1>that experience and to explain and to teach and to

1:10:22.280 --> 1:10:27.720
<v Speaker 1>have that knowledge expand beyond just their own circle, So definitely.

1:10:27.880 --> 1:10:30.160
<v Speaker 1>You know, Defcon is not like a participant not not

1:10:30.240 --> 1:10:34.519
<v Speaker 1>like a spectator sport. You know, it's fully participatory. And

1:10:34.560 --> 1:10:37.000
<v Speaker 1>the more I heard this more and more every time

1:10:37.040 --> 1:10:40.320
<v Speaker 1>I was watching any video about it or anything, everyone

1:10:40.360 --> 1:10:42.880
<v Speaker 1>was saying the more you participate, the more you get

1:10:42.920 --> 1:10:45.920
<v Speaker 1>out of it, and that it's it's an environment that

1:10:46.080 --> 1:10:52.120
<v Speaker 1>encourages participation. And you know, I'm sure that you've you've

1:10:52.120 --> 1:10:55.960
<v Speaker 1>had a chance to practice all sorts of skills that

1:10:56.040 --> 1:11:00.320
<v Speaker 1>you didn't necessarily go into, you know, with any uh

1:11:00.400 --> 1:11:03.439
<v Speaker 1>real affinity for at the beginning. Like I mean, it

1:11:03.439 --> 1:11:06.000
<v Speaker 1>wouldn't surprise me at all to learn that you have

1:11:06.360 --> 1:11:10.240
<v Speaker 1>started to really get good at picking locks. Yeah, that's

1:11:10.240 --> 1:11:12.760
<v Speaker 1>actually a thing that I was going to mention. I

1:11:12.840 --> 1:11:16.120
<v Speaker 1>started picking locks at def Con, and I didn't know

1:11:16.200 --> 1:11:19.320
<v Speaker 1>that I was that it was a skill that I

1:11:19.400 --> 1:11:23.320
<v Speaker 1>had naturally until I started doing it, And I wouldn't

1:11:23.360 --> 1:11:25.840
<v Speaker 1>have done it if I hadn't gone to Defcon. But

1:11:25.920 --> 1:11:28.800
<v Speaker 1>now I have that skill that I could use for

1:11:29.040 --> 1:11:32.080
<v Speaker 1>more security awareness, like even on my own house, I

1:11:32.080 --> 1:11:35.360
<v Speaker 1>can make sure that my house isn't you know, luck pickable,

1:11:35.880 --> 1:11:38.479
<v Speaker 1>for example. But you you do learn skills there, you

1:11:38.520 --> 1:11:41.240
<v Speaker 1>get to. You get to meet a lot of really

1:11:41.280 --> 1:11:45.920
<v Speaker 1>amazing people and it's a great experience all around. Um,

1:11:45.960 --> 1:11:47.960
<v Speaker 1>even if you go on your own there's some really

1:11:48.000 --> 1:11:51.759
<v Speaker 1>awesome people that you can meet there. Shannon Morrise, thank

1:11:51.800 --> 1:11:54.880
<v Speaker 1>you so much for joining our show. Please tell people

1:11:54.880 --> 1:11:57.320
<v Speaker 1>where they can find all the stuff what you do.

1:11:57.960 --> 1:12:00.759
<v Speaker 1>Uh So, you can follow me on Twitter, I'm snubs

1:12:00.960 --> 1:12:03.320
<v Speaker 1>S and U b S. That is where I post

1:12:03.400 --> 1:12:06.120
<v Speaker 1>most frequently, and I can also answer any questions that

1:12:06.200 --> 1:12:09.280
<v Speaker 1>you have about def Con as well over there. If

1:12:09.280 --> 1:12:11.800
<v Speaker 1>you are interested in the podcast that I do, you

1:12:11.840 --> 1:12:13.840
<v Speaker 1>can check out all of those over at h K

1:12:14.040 --> 1:12:18.120
<v Speaker 1>five dot org o r G and hack five is

1:12:18.160 --> 1:12:20.560
<v Speaker 1>also the place where I do all of my own teachings.

1:12:20.800 --> 1:12:23.560
<v Speaker 1>So if you have questions about the hacker community, or

1:12:23.600 --> 1:12:26.759
<v Speaker 1>if you're interested in pent testing as a profession, definitely

1:12:26.840 --> 1:12:29.559
<v Speaker 1>check out our podcast there because we go through not

1:12:29.640 --> 1:12:32.519
<v Speaker 1>only the fundamentals, but also the theory and sometimes some

1:12:32.600 --> 1:12:36.599
<v Speaker 1>expert advice as well. Awesome, it was a pleasure having

1:12:36.640 --> 1:12:38.559
<v Speaker 1>you back on the show. I'll make sure to have

1:12:38.640 --> 1:12:42.240
<v Speaker 1>you on again before too long. Thank you guys. That

1:12:42.520 --> 1:12:45.360
<v Speaker 1>is the history of def Con. This was a really

1:12:45.400 --> 1:12:48.560
<v Speaker 1>interesting subject for me to look into. I was completely

1:12:48.640 --> 1:12:52.200
<v Speaker 1>in the dark ha ha about this convention. I had

1:12:52.240 --> 1:12:54.720
<v Speaker 1>only had some idea of what was going on, and

1:12:54.760 --> 1:12:56.360
<v Speaker 1>the more I looked into it, the more I realized

1:12:56.400 --> 1:12:59.680
<v Speaker 1>that a lot of those notions were based on misinformation.

1:13:00.240 --> 1:13:03.320
<v Speaker 1>And again, big thanks to Shannon Morris for jumping on

1:13:03.400 --> 1:13:06.640
<v Speaker 1>here and giving me the first person perspective of what

1:13:06.840 --> 1:13:09.280
<v Speaker 1>it's like to go to one of these conventions. It

1:13:09.360 --> 1:13:11.920
<v Speaker 1>sounds like it would be really fascinating. I know I

1:13:11.960 --> 1:13:14.559
<v Speaker 1>would be completely out of my element where I to attend,

1:13:14.560 --> 1:13:17.280
<v Speaker 1>and yet I feel like I gotta make an effort

1:13:17.320 --> 1:13:20.200
<v Speaker 1>to go at least one year and experience this just

1:13:20.320 --> 1:13:25.160
<v Speaker 1>as an attendee and to learn and to to see

1:13:25.200 --> 1:13:29.200
<v Speaker 1>that community and to experience this for myself. If you

1:13:29.240 --> 1:13:32.759
<v Speaker 1>guys have suggestions for future topics of tech stuff, please

1:13:33.000 --> 1:13:34.800
<v Speaker 1>let me know. You can send me an email that

1:13:34.840 --> 1:13:38.600
<v Speaker 1>addresses tech stuff at how stuff works dot com, or

1:13:38.680 --> 1:13:41.320
<v Speaker 1>you can always drop me a line on Facebook or Twitter.

1:13:41.400 --> 1:13:44.600
<v Speaker 1>The handle for both of those is text stuff hs W.

1:13:45.160 --> 1:13:49.120
<v Speaker 1>Remember you can watch me record episodes live on twitch

1:13:49.240 --> 1:13:52.960
<v Speaker 1>dot tv slash text Stuff. I record on Wednesdays and Friday's.

1:13:53.360 --> 1:13:55.400
<v Speaker 1>Just pop over to that U r L and you'll

1:13:55.400 --> 1:13:57.559
<v Speaker 1>be able to see the schedule there, and I'll talk

1:13:57.600 --> 1:14:06.559
<v Speaker 1>to you again really soon for more on this and

1:14:06.640 --> 1:14:09.200
<v Speaker 1>thousands of other topics. Is it how stuff Works? Dot

1:14:09.200 --> 1:14:19.320
<v Speaker 1>com