Every summer around 30,000 hackers travel to Las Vegas to spend a week in the desert where it’s reliably over 100 degrees.
There are rules about surveillance, you are not allowed to freely photograph or film the crowd of attendees, and if you do take a picture of a stranger without asking, staff will make you delete it. The attendees are referred to and labeled as “Humans” while the staff wear badges labeling them as “Goons.” And it’s not what you’d think of as a typical conference badge. In 2024, it was a cat-shaped circuit board with a fully playable Game Boy emulator.
Real medical devices like pacemakers, insulin pumps, glucose monitors, etc are set up specifically to be hacked into. There are cars, boats, and voting machines set up for the same purpose: to see if they can be hacked. There are soundproof booths where people can sit down and call real companies live in front of an audience, and try to sweet talk employees into handing over sensitive information.
It is almost guaranteed that at some point you’ll run into someone walking around in full pineapple costume ( a nod to the wifi pineapple). And speaking of WiFi, a good chunk of the WiFi networks you’ll see at the venue aren’t real. They are set up by attendees specifically to catch people who connect to them without thinking. If you fall for the trap, there’s a chance your information will show up (partially redacted) on a giant public screen called the Wall of Sheep.
The event I’m describing is sometimes referred to as “hacker summer camp”.
This term refers to the week where three back-to-back cybersecurity conferences are held in Las Vegas. The first two conferences are Black Hat and BSidesLV, then right after is DEF CON. Black Hat is usually considered the more “corporate” and “no nonsense” of the three. It’s more expensive and pretty consistent with what you’d imagine a tech conference is like. DEF CON which runs right after it is considered to be much “less corporate” and typically has a lot more instances of “nonsense” baked into DEF CON culture. For example, one year someone hacked the registers at one of the casinos, and all guests had to be checked out using a calculator.
Each conference is valuable in its own way, but this article is going to mostly focus on DEF CON because it is what I have the most personal experience with.
DEF CON is organized into dozens of “villages” each built around a specific niche, like hardware hacking, aerospace, radio, artificial intelligence and much much more. There is something there for everyone.
The Badge
Every DEFCON badge is designed from scratch that year and figuring out what it does is part of the fun. They tend to alternate between electronic badges and non-electronic badges. Last years badge (DEF CON 33) was a very clever layered 3-D art piece. You could hold it up with different lenses and combine them to reveal hidden images around the conference center. This year's badge is electronic and it is built around a new open source fully inspectable chip (and it's rumored to double as a security token and password manager).
The Medical Device Hacking
This happens in the Biohacking Village. Medical device manufacturers, bring in real hardware and invite attendees to try and break into them on purpose. Last year. I played around with a surgical laser and an electronic prescription dispenser. The motivation for companies to bring these devices is to get free pen testing.
Pen Testing: (short for penetration testing) is when a security researcher with permission, deliberately tries to break into a system (device, network, app, etc). It is meant to simulate a real attack under controlled conditions.
They’re hoping dangerous vulnerabilities will be found here and able to be patched before someone with worse intentions finds it.
The Car and Boat hacking.
The Car Hacking Village does the same thing for vehicles. Attendees are encouraged to hack them and learn how cars can be exploited. There is also a Maritime Village where you can do the same thing to boats.
The Soundproof Booths.
This is in the Social Engineering Village. They run a vishing competition where contestants research a real target company in advance, then sit in a glass soundproof booth in front of a live audience. They place actual phone calls to that companies employees trying to extract sensitive information. It is hilarious to watch but also genuinely unsettling to see how easy it is to trick people.
Vishing: (short for voice phishing) is a social engineering attack where someone uses a phone call (instead of email or text) to trick a person into handing over sensitive information. It works the same way as phishing emails but in this case the medium used is voice instead of text.
The Goons.
DEF CON staff and volunteers are unironically called goons. The Goons run registration, security, the info booth and everything else that's part of the conference.
After 30,000 hackers arrive in Vegas, you can predict that the digital devices around town start to behave oddly.
One year every video poker machine at one of the hotels was hacked to display pornographic images. Another time, someone launched a balloon over a casino to sniff Wi-Fi signals from the air. A fake ATM kiosk was once discovered, just out of view of security cameras, skimming card data. None of this ‘nonsense’ is officially sanctioned by DEF CON. They explicitly warn attendees not to do anything illegal, but with this many curious and skilled people packed into a building for four days, a little bit of extra hacking is inevitable. But it’s mostly all in good fun.
To be safe, you can keep bluetooth and airdrop turned off of your devices. And definitely don’t join any WiFi networks unless it’s the one linked in the official DEFCON guide.
But seriously, don’t worry too much about getting hacked. Likely, the worst thing that will happen if you accidentally leave on airdrop or bluetooth is some pop-up notifications (like what happened to me a few years ago).
Research the villages before you go.
Look at the list ahead of time and figure out which ones actually interest you, because you will not have time for all of them.
Don’t try to see everything. There isn’t enough time, and trying anyway is any easy way to ensure you will burnout. I recommend making a priority list based on your village research and work through it in order.
Find people, not just talks. If you meet someone doing interesting work, follow them on social media or Substack instead of trying to catch every talk they’re giving live. You can go back and read or watch their stuff later, at your own pace, without missing everything else happening around you in the moment. Also a lot of the talks are posted online after the conference. So don’t stress about missing something.
Use the break spaces when you’re overwhelmed. Many villages have a low-pressure area built in somewhere to sit down, drink water (Vegas is super hot and dry!), and get out of the crowd for a bit.
You don’t need a technical background. This is one of the most common misconceptions about DEF CON. Almost every village has something beginner-friendly, and there’s an entire community (Noob Village) built specifically for people who are new to hacking or cyber security altogether. If you’re not technical at all, the Lock & Key Village is a great entry point: it requires zero coding knowledge, and Goons will walk you through picking your first lock start to finish. There is also a really fun sticker exchange and contests where people bring their favorite stickers and trade them. Collecting cool stickers requires no technical knowledge.
I’ve gotten a lot of questions from people nervous about ending up on the Wall of Sheep or being overwhelmed by the knowledge of other attendees. But I promise DEF CON can be a lot of fun and you will find so many kind and passionate people there who want to connect with hackers (or aspiring hackers) of all levels!
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.