Tech

Inside Defcon, the Conference That Made Cybersecurity Noob-Friendly

Published

on

The first thing I learned at Defcon was that I apparently didn’t know what a badge was.

I already had one hanging around my neck: the press credential that got me through the door at the annual hacker convention in Las Vegas in early August. Yet everywhere I looked, people stood in long lines to buy more. When I asked what they were waiting for and heard “badges,” I glanced down at mine, confused.

I would soon learn that Defcon badges can be electronic puzzles, soldering projects, collectibles and signs of belonging to a culture I was experiencing for the first time. Those badges were my first indication of how much I had to learn.

Everyone else seemed to understand the schedule, the language and the unwritten rules. But me? I felt like I was back in high school and had somehow missed orientation.

Advertisement

Over the next few days, talking with professionals, hobbyists and other beginners made cybersecurity feel much more accessible. For the first time, I could see a path from playing around with hacking tools to actually understanding how they work.

I was a script kiddie before I knew what that meant

I wasn’t completely new to hacking. In college at UCLA, I spent more time than I probably should have in the library experimenting with Firesheep, a Firefox extension that demonstrated how exposed session cookies could be intercepted over shared Wi-Fi. Watching it work showed me how easily technology could be manipulated.

I didn’t build Firesheep or understand the code behind it. I knew how to install it and click around. In hacker terminology, that made me a script kiddie: someone who uses tools created by other people without fully understanding how they work.

Still, I loved testing technology’s limits and making it do things it wasn’t designed to do. I liked the feeling of opening a door everyone else assumed was locked. That curiosity stuck, even if my technical knowledge never caught up. 

Advertisement

Defcon was my chance to see whether it finally could.

Exploring Defcon

Defcon featured talks and scheduled events, but much of the convention was divided into villages dedicated to particular corners of hacking. There were villages for lock picking, artificial intelligence, aerospace, cars and even boats. Inside them, people were hacking devices, building things, competing in challenges or sitting around tables working on projects I couldn’t begin to identify.

Elsewhere, teams competed in capture the flag contests, or CTFs, where players solve cybersecurity puzzles to uncover hidden pieces of text known as flags. Some competitions were designed for experts. Others were specifically meant to help beginners learn. I wanted to try one, but never did. There was always another room to explore, another talk to catch or another unfamiliar object I needed someone to explain to me.

Mostly, I wandered.

Advertisement

That was how I ended up learning about Defcon badges. The official badge gets you into the convention, but villages, groups and independent creators also make their own. Many are small electronic devices with lights, screens, games or hidden puzzles. Some communicate with other badges. Others come as bare circuit boards that you have to assemble yourself. Collecting and hacking them is an entire subculture within Defcon.

Because I arrived late, many of the badges I heard people talking about had already sold out. But I managed to buy one from the Maritime Hacking Village, where hackers explore the technology used on boats and other maritime systems, as well as the Car Hacking Village.

I also sat down at a soldering station and made a small badge of my own.

I had always wanted to learn how to solder, but was intimidated by the idea of trying it alone. At Defcon, a young guy and a much older man — two people who seemed like complete opposites in almost every way — took turns guiding me through it.

Advertisement
I learned to solder by assembling a small electronic badge, shown before and after, that lit up on my first try.Nelson Aguilar/CNET

They showed me how to heat each connection and apply just enough solder to hold the components in place. Once I got the hang of it, I was surprised by how naturally it came to me. When the badge lit up, I realized soldering had never been beyond me; I just needed someone to show me where to start.

A lot of it went over my head, obviously

The talks were a reminder of how much I don’t know. Speakers spoke through code and acronyms as if everyone in the room spoke the same language, which frustrated me at times. Sometimes I could follow the larger idea, but lost the technical details. Other times, I had almost no idea what was happening.

One project I could understand came from Billy Swearingen. He developed software that generates and tests visual patterns designed to confuse the AI systems used by surveillance cameras. His goal isn’t to make someone invisible, but rather to make it more difficult for a camera’s software to recognize a person or face.

Bill Swearingen demonstrates how a specially designed pattern can lower an AI camera’s confidence that it sees a person.Nelson Aguilar/CNET

A talk about cellular surveillance went the same way for me. I didn’t understand every detail about cellular networks, but I understood the problem. Police can use devices that pretend to be cellphone towers, and the people being monitored may never know. Rayhunter offered an inexpensive way to start looking for signs of that surveillance.

I quickly gave up on trying to understand every technical detail. I followed whatever interested me, bought a few devices to let me experiment in different areas of cybersecurity and filled my phone with terms to look up later. It was like a college curriculum I had given myself.

I found my village

Eventually, I wandered into Noob Village. For the first time all weekend, I knew immediately that I was in the right place.

Advertisement

Noob Village was built for people trying to enter cybersecurity without needing to understand everything. It offered beginner-focused talks, workshops, career advice and a place to ask basic questions without feeling stupid.

That was where I met Andrew Crotty, founder and president of the Ginger Hacker Initiative, a nonprofit that helps beginners, students, veterans and career changers find their way into cybersecurity through accessible education, mentorship and hands-on learning.

Crotty and I talked about my own attempt to move beyond using tools other people built and develop a more technical understanding of hacking. I told him that I grew up in a place where cybersecurity never felt accessible. Nobody around me talked about hacking as a skill you could learn or a career you could pursue. Even after I became interested in it, I didn’t know where to begin or who to ask for help.

After wandering through rooms organized around specialties I barely understood, I had finally found my village. Literally.

Advertisement

That didn’t mean I suddenly knew what I was doing. It meant I had found one place that catered to not knowing. I left with a better idea of where to begin, then walked back into the chaos to see what else Defcon had waiting for me.

Some of the best moments happened in line

One of the few things I had planned was getting a copy of The Cuckoo’s Egg signed by its author, Cliff Stoll. Jaron Bradley, director of Jamf Threat Labs, had recommended the book when I interviewed him at Black Hat as a good way for me to start learning about cybersecurity. I had never heard of Stoll, but at Defcon, his name carried a kind of celebrity.

Stoll was an astronomer working at Lawrence Berkeley National Laboratory in the 1980s when a 75-cent accounting discrepancy led him to discover a hacker inside the lab’s computer network. He spent the next year tracking the intruder, eventually uncovering an international espionage operation connected to the Soviet KGB. This story became The Cuckoo’s Egg, one of the foundational books of modern cybersecurity.

Cliff Stoll, author of the cybersecurity classic The Cuckoo’s Egg, was every bit as eccentric and energetic as I had been told.Nelson Aguilar/CNET

While I waited for Stoll, I started talking to the man in front of me. He had joined the military without a cybersecurity background, learned the technical skills and eventually turned them into a career in his 20s. We talked about where we came from, politics and the different paths that had brought us into the same line.

It wasn’t an interview. Neither of us was trying to impress the other or extract anything useful.

Advertisement

It was exactly the kind of unexpected conversation I had hoped to have when I came to Defcon alone: a chance to meet someone whose path into cybersecurity looked nothing like mine and to hear how he found his way in.

Then I met Stoll, who was every bit as strange, energetic and entertaining as his reputation suggested. He signed my book and shook my hand, wishing me luck on my journey in this strange new world.

The whole experience was another reminder of how wonderfully unpredictable Defcon could be.

Next year, I’m joining in

By the end of the weekend, I had learned to solder, solved a cryptography puzzle involving a Vigenère cipher and spent more money than expected on hacking tools. More importantly, the technical side of cybersecurity no longer felt as intimidating as it had when I arrived.

Advertisement

There was still plenty I didn’t try. I never attempted a CTF, even though several were designed for beginners. I had my laptop with me, but I mostly used it to take notes while watching other people hack. This year, I wanted to wander and understand what Defcon was. Next year, I want to participate.

I’ll have a better idea of which villages I want to visit, and I plan to commit to at least one beginner CTF — not because I think I’ll suddenly know what I’m doing, but because I’m no longer as afraid of not knowing.

One of my favorite things about Defcon was seeing how many parents had brought their children. They were being introduced to technology as something they could question and rebuild in their own vision. That gave me a little more courage.

I didn’t leave Defcon as a hacker, not that I was supposed to. I did leave with enough confidence to start figuring things out for myself.

Advertisement

At one point, I admitted to another attendee that I felt like I didn’t belong there. He told me something I kept thinking about for the rest of the weekend: “You don’t have to know what you’re doing most of the time,” he said. “You just have to want to find out.”

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version