Research: The Conference Circuit — DEF CON, Black Hat, and the Self-Aware Security Industry
Contents 39 sections
The Conference Circuit — DEF CON, Black Hat, and the Self-Aware Security Industry
THESIS
The information security industry knows it is broken. It knows compliance is not security. It knows pen tests are theater. It knows bug bounties underpay researchers while governments pay millions for the same work. It knows all of this — and it gathers thirty thousand strong in Las Vegas every August to laugh about it. The gallows humor at security conferences is not incidental to the dysfunction. It is the dysfunction’s confession.
1. DEF CON — History and Evolution
Founding
DEF CON was founded in 1993 by Jeff Moss (handle: “The Dark Tangent”), then eighteen years old. The original event was intended as a one-off farewell party for a friend who was a member of “Platinum Net,” a FidoNet-protocol-based hacking network out of Canada. Moss invited his hacker friends to Las Vegas instead. Roughly 100 people showed up at the Sands Hotel, where they shared a rented meeting room for talks, continuous sessions, and — reportedly — sleeping.
Source: Jeff Moss (hacker) — Wikipedia; Malicious Life Podcast: Jeff Moss on the History of DEF CON
Growth
The response was overwhelmingly positive. Attendance nearly doubled the second year. By 1999, DEF CON was attracting major media attention. By 2019 (DEF CON 27), attendance had reached 30,000. It has remained at or above that level since.
The trajectory tells a story: from 100 people in a hotel room to 30,000 people across multiple venues at the Las Vegas Convention Center. The underground went mainstream, and the mainstream showed up in costume.
Source: DEF CON — Wikipedia
Cash Only, No Names
DEF CON registration is cash only. No checks, no credit cards, no money orders. Badges carry no identifying information, no barcodes. Attendees are not scanned by vendors. The official explanation: “Paying in cash helps protect your privacy, and search warrants can’t vacuum up PII we don’t collect.” The unofficial explanation is the same, but angrier.
This is a hacker conference that structurally refuses to create the kind of data trail that the rest of the industry spends its time protecting (badly). The irony is architectural.
Source: DEF CON 30 FAQ; DEF CON 32 FAQ — DEF CON Forums
Badge Culture
The first electronic badge appeared at DEF CON 14 (2006), designed by Joe “Kingpin” Grand — a PCB smiley skull that launched an entire subculture. Grand designed badges from 2006 through 2010. Subsequent years saw badges made of vinyl records, custom PCBs with crypto riddles, wireless communication capabilities, built-in screens, and miniature keyboards.
The unofficial badge scene (“Badgelife”) is now arguably larger than the official one. Independent makers spend a full year designing and manufacturing custom circuit board badges. Some attendees report that collecting unofficial badges has become their primary reason to attend. In 2018, the “shitty add-on” (SAO) standard emerged — miniature PCBs that connect to other badges, extending functionality or serving purely as collectibles.
For a conference about security, the badge culture is revealing: the most celebrated artifacts are handmade, open-source, designed by individuals, and traded in a gift economy. The vendors in the expo hall sell enterprise solutions. The hackers make art.
Source: A History of Badgelife — Vice; Grand Idea Studio: A Five-Year History of DEFCON’s Electronic Badges; DEF CON Hacker Badges — Infosec Conferences
“Spot the Fed”
One of DEF CON’s oldest traditions: attendees attempt to identify undercover federal agents in the crowd. Correctly identify one, win a t-shirt. The contest rules facetiously offered t-shirts to feds in exchange for agency coffee mugs.
FBI files released via FOIA show the Bureau was not amused. Their earliest file on DEF CON dates to the conference’s third year — the FBI decided an annual hacker conference was “probably something they should be looking into.” The Spot the Fed rules were included in the FBI’s file.
The contest’s meaning has inverted over time. In the early years, feds were rare and covert. By the 2010s and 2020s, federal presence was overt — agencies presenting on stage, hosting workshops, running hackathons. At DEF CON 31 (2023), White House officials attended publicly. “Spot the Fed” became trivially easy: they were on the program.
The evolution from adversarial game to open collaboration is the security conference circuit in miniature. The hackers didn’t change. The government decided they were useful.
Source: When the FBI Found Out About Def Con’s ‘Spot the Fed’ Contest — Vice; FBI files on DEF CON — MuckRock; Spot the Fed? I was the Fed — DEF CON 32 Policy Blog
2. Famous Presentations — The Hall of Shame
These are not presentations about obscure technical vulnerabilities. They are public demonstrations that critical infrastructure — ATMs, cars, voting machines, hotel rooms — is defended by systems that a motivated researcher can break in hours or minutes. The presentations are entertaining. The implications are not.
Barnaby Jack — ATM “Jackpotting” (Black Hat 2010)
Barnaby Jack (1977–2013), a New Zealand security researcher, demonstrated live on stage at Black Hat 2010 how to exploit two ATMs and make them dispense cash on command. He called it “jackpotting.” He showed both physical-access and fully remote attack vectors, injecting malware into the ATMs’ operating systems and causing them to spit out currency.
Jack subsequently turned his attention to medical devices. In 2012, his testimony led the FDA to change regulations regarding wireless medical device security — specifically, he demonstrated that pacemakers and insulin pumps could be remotely compromised.
Jack was found dead in his San Francisco apartment on July 25, 2013, one week before he was scheduled to present at Black Hat on pacemaker vulnerabilities. Cause of death: accidental overdose. He was 35.
Source: Barnaby Jack — Wikipedia; Elite Hacker Barnaby Jack Dies At 36 — NPR
Charlie Miller & Chris Valasek — Jeep Cherokee Remote Hack (2015)
In collaboration with Wired journalist Andy Greenberg, Miller and Valasek demonstrated they could remotely hack a 2015 Jeep Cherokee via its Uconnect cellular connection. From a basement miles away, they controlled the air conditioning, radio, windshield wipers, and — critically — disabled the transmission and brakes while Greenberg drove on a highway.
The vulnerability affected 1.4 million vehicles. Fiat Chrysler issued a recall — the first physical product recall in history triggered by a cybersecurity vulnerability. The fix was a software patch distributed on USB drives that owners were expected to install themselves.
The presentation was at Black Hat 2015. The recall was announced before the talk. The talk happened anyway, because the point was never just the Jeep — it was that an entire class of internet-connected vehicles had been shipped with no meaningful security architecture.
Source: Black Hat USA 2015: The full story — Kaspersky; Chrysler recalls 1.4M vehicles — Computerworld; Jeep hackers: Only a dramatic stunt could force a Chrysler recall — CS Monitor
Cody Brocious — Onity Hotel Lock Hack (Black Hat 2012)
Brocious demonstrated at Black Hat 2012 that Onity keycard locks — installed in an estimated four million hotel rooms worldwide — could be opened with a device built from $50 in parts. The attack exploited an unprotected DC port on the bottom of the lock, reading key data from unencrypted memory and triggering the door to open.
Onity initially called the hack “unreliable and complex to implement.” It was subsequently used in real-world hotel burglaries. The Hyatt House Galleria in Houston confirmed that rooms were broken into using the technique.
Four million hotel rooms. A $50 device. “Unreliable and complex.”
Source: Hotel Lock Hacker Leads Manufacturer to Release Fixes — NBC News; Hotel key security flaw demonstrated at Black Hat — CBS News; Hotel blames burglaries on hacked Onity card locks — The Register
DEF CON Voting Village (2017–present)
Launched at DEF CON 25 (2017), the Voting Village gave attendees access to real voting machines used in U.S. elections. The results were immediate and devastating:
- 2017: Every piece of equipment in the Village was breached. Carsten Schurmann hacked an AVS WinVote machine remotely over Wi-Fi within minutes, using a vulnerability from 2003 and stock Metasploit payloads.
- 2018: An 11-year-old hacked a mockup of Florida’s election results website in under 10 minutes, changing reported vote totals. Over 30 brands of equipment were targeted.
- 2019: Hackers were “100 percent successful” in compromising every machine tested, either finding new attack vectors or replicating published methods.
The Voting Village’s findings were compiled into formal reports co-authored with the University of Chicago’s Cyber Policy Initiative and shared with election officials. The response from voting machine manufacturers was largely to argue that the Village’s conditions were “unrealistic” — ignoring that the machines were the same ones used in actual polling places.
Source: DEF CON 25 Voting Village Report (PDF); DefCon Hackers Broke Into U.S. Voting Machines in 90 Minutes — Fortune; How 5 Years of DEF CON’s Voting Village Has Shaped Election Security — Dark Reading
3. Black Hat vs. DEF CON — The Industry’s Split Personality
Black Hat and DEF CON occupy the same week in Las Vegas (“Hacker Summer Camp”). They share a founder (Jeff Moss created Black Hat in 1997). They do not share a culture.
The Numbers
| Black Hat USA | DEF CON | |
|---|---|---|
| Registration | ~$2,600 (Briefings Pass, 2024) | $440–$480, cash only |
| Payment | Credit card, corporate PO | Cash. Period. |
| Badge | Barcode, name, company | No name, no barcode |
| Dress code | Business casual to suits | T-shirts, costumes, mohawks |
| Expo hall | Vendor booths, product demos | Villages, CTF, lockpicking |
| Audience | CISOs, managers, vendors | Researchers, hackers, feds in disguise |
What the Split Means
The price differential is the thesis statement. Black Hat costs $2,600 because employers pay. DEF CON costs $440 because attendees pay. Black Hat is where the industry sells solutions. DEF CON is where the industry admits the solutions don’t work.
Black Hat has become, in the words of multiple attendees, “a sales and networking-led event” — still with high-quality technical talks, but increasingly dominated by vendor presence. DEF CON remains “community-focused” and “people-focused.” The two conferences together form a complete picture: the industry’s public face (professional, funded, optimistic) and its private knowledge (adversarial, underfunded, bleak).
As one Hacker News commenter put it: “It’s also painfully corporate. It used to be Defcon attendees would make fun of Black Hat. Now Black Hat has eaten everything.”
Source: Breaking it Down: Black Hat vs. DEFCON — Pete Slade; Photos show the cultural difference — VentureBeat; Reflections on DefCon and Black Hat — Lawfare; HN comment thread
4. BSides — The Grassroots Response
Origin Story
In 2009, Black Hat USA received an overwhelming number of talk submissions and rejected many of them. Several rejected speakers lamented this on Twitter. Mike Dahn, Jack Daniel, and Chris Nickerson proposed an alternative: hold the rejected talks at a separate, simultaneous event. They named it “BSides” after the B-side of a vinyl record — the track that didn’t make the album but might be the better song.
Growth
From that single event, BSides grew into a worldwide movement: over 650 events in more than 50 countries by the mid-2020s. Each BSides is independently organized by local communities. There is no central authority, no corporate parent, no ticket price floor. Many BSides events are free or under $50.
What BSides Represents
BSides is the security community’s answer to its own corporatization. When Black Hat became too expensive and too vendor-driven, the community didn’t just complain — it forked. The BSides model is open-source conferencing: a framework released for anyone to instantiate locally. The movement’s existence is itself an argument: the best security knowledge is produced by communities, not corporations, and the barrier to entry should be a willingness to show up, not a $2,600 registration fee.
Source: Security BSides — Wikipedia; BSides History; Security B-Sides: Rise of the ‘Anti-conference’ — CSO Online; Creating BSides — Malicious Life Podcast
5. Researchers Arrested at or Around DEF CON
The conference that federal agencies now openly attend and sponsor has also been the site of federal arrests of the researchers who make it worth attending.
Dmitry Sklyarov (DEF CON 9, 2001)
Sklyarov, a Russian programmer employed by ElcomSoft, presented “eBook Security — Theory and Practice” at DEF CON 9, demonstrating that Adobe’s eBook encryption was cryptographically incompetent. On July 16, 2001, as he was about to fly home to Moscow, the FBI arrested him for violating the Digital Millennium Copyright Act (DMCA). His crime: writing software that removed DRM from eBooks.
He was jailed. The charges were eventually dropped in exchange for his testimony at ElcomSoft’s trial. On December 17, 2002, a federal jury found ElcomSoft not guilty on all four DMCA counts.
Bruce Schneier wrote at the time: “Arrest of Computer Researcher Is Arrest of First Amendment Rights.” The EFF mounted a major defense campaign. The case became a landmark in the debate over whether security research constitutes speech.
Source: United States v. Elcom Ltd. — Wikipedia; Fallout From Def Con: Ebook Hacker Arrested by FBI — Slashdot; Arrest of Computer Researcher — Schneier on Security; US v. ElcomSoft & Sklyarov FAQ — EFF
Marcus Hutchins (DEF CON 25, 2017)
Marcus Hutchins — “MalwareTech” — was the 22-year-old British researcher who stopped the WannaCry ransomware pandemic in May 2017 by registering a domain that served as the malware’s kill switch. He became an instant celebrity in the security community. Three months later, he attended DEF CON 25 in Las Vegas.
On August 3, 2017, as Hutchins was preparing to fly home to England, the FBI arrested him at McCarran International Airport. The charges were not related to WannaCry. He had been secretly indicted on six federal counts for creating and distributing Kronos, a banking trojan, in 2014–2015 — work he had done as a teenager.
Hutchins eventually pleaded guilty to two counts. In July 2019, he was sentenced to time served and one year of supervised release. The judge cited his “subsequent course of conduct” — including the WannaCry kill switch — as grounds for leniency.
The optics were staggering: the researcher who saved the internet from a ransomware pandemic was arrested at the conference where the security community celebrates its own. The message, intended or not, was clear: past sins are not forgiven, no matter how many hospitals you save.
Source: Marcus Hutchins — Wikipedia; WannaCry kill-switch hero Marcus Hutchins collared by FBI — The Register; WannaCry ‘hero’ Marcus Hutchins pleads guilty — CNN; Marcus Hutchins sentenced — CyberScoop
Kevin Poulsen (“Dark Dante,” 1991)
Not a DEF CON arrest per se — Poulsen was arrested in 1991, two years before DEF CON existed — but his story is foundational context for the conference’s culture. Poulsen was a hacker who, among other exploits, seized control of all phone lines into LA radio station KIIS-FM to guarantee he would be the 102nd caller and win a Porsche 944 S2.
He evaded capture for 17 months. In 1993, he was convicted on 19 counts including conspiracy, computer fraud, and wiretapping. He served 51 months — at the time, the longest sentence ever given to a hacker. After release, he became a journalist covering security and hacking, eventually working at Wired.
The Poulsen trajectory — hacker to fugitive to prisoner to journalist — is a template the industry knows well. The line between researcher and criminal is drawn by prosecutors, not by technical capability.
Source: Kevin Poulsen — Wikipedia; Kevin Poulsen, the story of “Dark Dante” — PID Perspectives
6. The Gallows Humor — An Industry That Knows
“Compliance Is Not Security”
This phrase has become the security industry’s central meme — repeated in talks, printed on shirts, embedded in a thousand conference slides. It captures a truth everyone in the room already knows: an organization can be fully compliant with every framework (SOC 2, PCI DSS, HIPAA, ISO 27001) and still be catastrophically insecure. Compliance is the minimum. The minimum is not enough. The minimum is what gets funded.
The humor comes from the gap between knowledge and action. Every CISO in the room can recite the mantra. Most of them work at organizations where compliance is the security program, because compliance is what the auditors check and what the board understands.
Source: Compliance Theater — Security Magazine
Bruce Schneier and “Security Theater”
Bruce Schneier coined the term “security theater” in his 2003 book Beyond Fear to describe measures that create the feeling of security without improving actual safety. His original target was the TSA — billions spent on airport screening that security experts regarded as largely performative.
The term migrated from physical security to cybersecurity and became the industry’s preferred diagnosis of its own condition. Schneier has noted: “The difference between the feeling of security and the reality of security will continue to be a pervasive problem in our industry.” He ran a “Doghouse” column from 2005 to 2019 calling out snake oil security products. He stopped because “it wasn’t fun anymore.”
Source: Beyond Security Theater — Schneier on Security; Bruce Schneier Quotes — Goodreads
The Meme Economy
The cybersecurity meme ecosystem is not incidental. It is diagnostic. Common themes:
- The unfunded mandate: “We need world-class security.” “What’s the budget?” “We just said — world-class.”
- The SOC analyst’s despair: Security Operations Center workers processing thousands of alerts, most of them false positives, for salaries that make fast food management look competitive.
- The post-breach meeting: Executives who ignored every recommendation now demanding to know how this happened.
- The “before and after” career arc: Entry-level optimism vs. decade-in weariness — the journey from “I’m going to make systems secure” to “I’m going to update this spreadsheet so the auditor leaves.”
The humor is coping. The coping is evidence. An industry that produces this volume of self-deprecating content is an industry that has internalized its own futility and chosen laughter over resignation — or rather, chosen laughter as resignation.
Source: 25 Cybersecurity Memes For 2025 — Rhymetec; Top 29 Cybersecurity Memes — Security Compass
7. Penetration Testing Reality — The Scope Problem
What Pen Testers Actually Do
A penetration test, as sold, simulates a real-world attack against an organization’s systems. In practice, it simulates an attack conducted by someone who has been told which systems they may touch, how long they have, what methods are forbidden, and what time they must stop.
The Constraints
| Constraint | Pen Tester | Real Adversary |
|---|---|---|
| Scope | Defined by contract. Specific systems, specific networks. | Everything. |
| Time | Days to weeks. | Months to years. |
| Methods | No DoS, no social engineering (usually), no destruction. | Whatever works. |
| Access | Often restricted to specific network segments. | Moves laterally without permission. |
| Consequences | Must avoid crashing production systems. | Does not care. |
| Reporting | Writes a PDF. | Exfiltrates data. |
The Structural Problem
The fundamental dishonesty of penetration testing is not that testers are incompetent — many are excellent. It is that the test is designed to be passed. Scope is negotiated to exclude the systems most likely to fail. Time windows are too short for the kind of persistent, creative exploitation that real adversaries employ. Rules of engagement prohibit the techniques that actually work.
The result: a clean report that executives present to the board as evidence of security. A “checkbox exercise” that satisfies compliance requirements without revealing the actual attack surface.
As one critic wrote: “Penetration testing is security theater for executives who don’t understand risk.” The pen test “passed” — and then the breach came through the CI/CD pipeline that was excluded from scope.
Source: Penetration Testing Is Security Theater — Maxwell Cross, Medium; Limitations of Penetration Testing — Cypress Data Defense; The Limitations of Penetration Testing — Vertex Cyber Security
8. Bug Bounty Economics — The Market Speaks
The Legitimate Market
Bug bounty platforms like HackerOne and Bugcrowd connect security researchers with organizations willing to pay for vulnerability reports. The economics are instructive:
- HackerOne paid out $81 million in bounties in the 12 months ending mid-2025 (up 13% year-over-year). Cumulative all-time payouts exceeded $300 million.
- Median payout for a critical vulnerability on HackerOne: $3,000. High severity: $1,000. Medium: $500. Low: $150.
- Top 100 all-time earners on HackerOne have collectively earned $31.8 million.
- Average annual program payout: approximately $42,000 across all active programs.
Source: HackerOne paid $81 million — Bleeping Computer; Hackers Surpass $300 Million — HackerOne
The Gray Market
Now compare those numbers to what zero-day brokers pay:
Zerodium (founded by Chaouki Bekrar, formerly of VUPEN) was the first company to publish a full zero-day price list. Selected prices:
| Target | Zerodium Price |
|---|---|
| iOS full chain (zero-click) | Up to $2,000,000 |
| Android full chain (zero-click) | Up to $2,500,000 |
| WhatsApp/iMessage RCE+LPE | Up to $1,500,000 |
| Chrome RCE+SBX | Up to $500,000 |
| Windows RCE | Up to $300,000 |
By 2025, competing brokers had pushed prices even higher. Crowdfense offered $5–7 million for iPhone zero-days, up to $5 million for Android, and $3–5 million for WhatsApp/iMessage exploits.
Source: Zerodium — Wikipedia; Price of zero-day exploits rises — TechCrunch; Zerodium offers $2.5 million for Android zero-days — CyberScoop
The Math
A researcher who finds a critical iOS vulnerability faces a choice:
- Report to Apple via bug bounty: receive somewhere between $25,000 and $250,000 (Apple’s published range for the most severe issues), plus the satisfaction of doing the right thing, minus the frustration of Apple’s notoriously slow triage process.
- Sell to Zerodium: receive up to $2,000,000, no questions asked about what happens next. Zerodium’s clients are “mostly governmental bodies.”
- Sell to Crowdfense or another broker: receive up to $7,000,000.
The legitimate market pays $3,000 median for a critical bug. The gray market pays $2,000,000 for the same class of work. The gap is not a rounding error. It is a policy choice: the organizations responsible for securing billions of devices have decided that vulnerability discovery is worth four or five orders of magnitude less than the governments buying those vulnerabilities to exploit them.
Multiple researchers have spoken publicly about this calculus. After frustrating experiences with Apple’s bug bounty program, some researchers told TechTarget they were considering selling to brokers instead.
Source: Burned by Apple, researchers mull selling zero days to brokers — TechTarget; Zero-day exploits are rarer and more expensive than ever — CyberScoop
9. Synthesis — The Conference as Confession
The Pattern
Every August, the security industry gathers in Las Vegas for what it calls “Hacker Summer Camp.” BSides runs first (free or cheap, community talks, grassroots). Black Hat follows (expensive, corporate, vendor-driven). DEF CON closes the week (mid-price, cash only, adversarial).
The three conferences together form a complete social anatomy of an industry:
- BSides is what the industry wants to be: open, community-driven, accessible.
- Black Hat is what the industry is: corporate, credentialed, expensive.
- DEF CON is what the industry knows: that the systems it builds and sells are fundamentally breakable, that compliance is theater, that the people who find the bugs are underpaid relative to the people who exploit them, and that the only honest response is to show up in Las Vegas with cash and a sense of humor.
The Evidence
The gallows humor is not incidental. It is the industry’s immune response — the same mechanism this book traces through trolling, heresy, and hacking. When an institution cannot reform itself, the people inside it develop a shared language of irony. The security industry’s meme culture, its sardonic conference talks, its tradition of publicly demolishing the products it sells — these are not signs of a healthy industry blowing off steam. They are the symptoms of an industry that has diagnosed its own disease and decided the treatment is too expensive.
The conferences are the evidence. Thirty thousand people who know the emperor has no clothes, gathering annually to compare notes on the quality of the tailoring.
Source URLs
- DEF CON — Wikipedia
- Jeff Moss (hacker) — Wikipedia
- Black Hat Briefings — Wikipedia
- Security BSides — Wikipedia
- Barnaby Jack — Wikipedia
- Marcus Hutchins — Wikipedia
- United States v. Elcom Ltd. — Wikipedia
- Kevin Poulsen — Wikipedia
- Zerodium — Wikipedia
- Bruce Schneier — Wikipedia
- HackerOne Paid $81 Million in Bug Bounties — Bleeping Computer
- Price of Zero-Day Exploits Rises — TechCrunch
- DEF CON 25 Voting Village Report (PDF)
- BSides History
Prefer RSS? Subscribe here.