{"id":740,"date":"2016-08-07T21:32:43","date_gmt":"2016-08-08T01:32:43","guid":{"rendered":"http:\/\/lorrie.cranor.org\/blog\/?p=740"},"modified":"2017-08-19T22:31:20","modified_gmt":"2017-08-20T02:31:20","slug":"bsides-black-hat-and-defcon","status":"publish","type":"post","link":"https:\/\/lorrie.cranor.org\/blog\/2016\/08\/07\/bsides-black-hat-and-defcon\/","title":{"rendered":"BSides, Black Hat, and DEFCON"},"content":{"rendered":"<p>I spent 4 days in Las Vegas this past\u00a0week attending the back-to-back <a href=\"https:\/\/www.bsideslv.org\" target=\"_blank\">BSides LV<\/a>, <a href=\"https:\/\/www.blackhat.com\/us-16\/\" target=\"_blank\">Black Hat<\/a>, and <a href=\"https:\/\/www.defcon.org\/html\/defcon-24\/dc-24-index.html\" target=\"_blank\">DEFCON 24<\/a> hacker conferences. \u00a0This was my first trip to Vegas and my first time at these events (although I have attended local hacker events, such as <a href=\"http:\/\/www.archc0n.org\" target=\"_blank\">ArchC0n<\/a> in St. Louis last September). Here are some thoughts on my experience and some photos from my trip.<\/p>\n<p>You know you are in Vegas when you get off the plane, because who wants to wait until you leave the airport to start gambling?<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9002.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\" size-thumbnail wp-image-741 alignnone\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9002-150x150.jpg\" alt=\"Slot machines at Las Vegas airport\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>Usually I try to stay at a conference hotel,\u00a0but I had been prohibited from using any of my\u00a0\u00a0government devices in\u00a0the conference hotels (too much of a security risk), so I opted for the Westin, where I could also get a government rate. BSides was a short walk down the street at the Tuscany. It was nearly 100 degrees in the mid-day sun, but without all the humidity we&#8217;ve been having on the East Coast. (And the hotels were\u00a0heavily air conditioned so I was glad to have a cardigan\u00a0for inside the hotels!)<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9004.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\" size-thumbnail wp-image-742 alignnone\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9004-150x150.jpg\" alt=\"Westin hotel in Las Vegas\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9005.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\" size-thumbnail wp-image-743 alignnone\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9005-150x150.jpg\" alt=\"Tuscany Suites\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>I gave the\u00a0Gave opening keynote at BSides LV Tuesday\u00a0morning in a noisy room with about 1000 people&#8230;. a few hundred people were sitting at tables, standing, or sitting on the floor paying attention to my talk. The rest were collecting swag from vendors, talking to each other, learning how to pick locks in the back of the room, or getting a drink at the bar (at 10 am!). Nonetheless, I had good audience participation when I quizzed them on password strength, and an artist captured the key points of my talk pretty well. And my <a href=\"http:\/\/arstechnica.com\/security\/2016\/08\/frequent-password-changes-are-the-enemy-of-security-ftc-technologist-says\/\" target=\"_blank\">talk got some nice press coverage<\/a>. I wore my password dress (as requested) and many people asked me\u00a0to <a href=\"https:\/\/twitter.com\/AmericanMilU\/status\/761573823355518977\/photo\/1\" target=\"_blank\">pose for selfies<\/a> with them throughout the day. After my keynote I spoke on a career panel\u00a0and attended some of the <a href=\"https:\/\/passwordscon.org\/vegas\/\" target=\"_blank\">Passwords<\/a> talks (kudos to <a href=\"https:\/\/godpraksis.no\/about\/\" target=\"_blank\">Per Thorsheim<\/a> for organizing a great event). I also enjoyed <a href=\"http:\/\/andreamm.com\" target=\"_blank\">Andrea Matwyshyn<\/a>&#8216;s talk on hacker kids.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9014.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\" size-thumbnail wp-image-744 alignnone\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9014-150x150.jpg\" alt=\"Besides LV chill out room\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9028.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-745\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9028-150x150.jpg\" alt=\"visual summary of BSides LV keynotes\" width=\"150\" height=\"150\" srcset=\"https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9028-150x150.jpg 150w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9028-300x300.jpg 300w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9028-1024x1024.jpg 1024w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9028.jpg 1500w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a><\/p>\n<p>BSides is the scrappy conference of the week. It doesn&#8217;t have many bells and whistles, but it is also the least overwhelming. Volunteer staff (known as &#8220;goons&#8221;) are mostly polite, but I did have a run-in with one who refused to let me back into a session for the end of the Q&amp;A because I had stepped out into the hall. \u00a0The hotel is not so classy and the whole thing smells like cigarettes, but the event is free to attend and not nearly as crowded as the other two events. And bonus points for the visual notes, speaker lunch, and providing a nice women&#8217;s cut v-neck speaker t-shirt.<\/p>\n<p>I spent most of Wednesday and Thursday at Black Hat at Mandalay Bay, a 15-minute\u00a0taxi-ride down the Strip from BSides. This is the classiest, most corporate, and most expensive of the three events. It was also the most traditional conference, the only one that did not require walking through a casino, and the conference badges actually had peoples&#8217; names on them. Some people even wore button down shirts and suit jackets, although black t-shirts, jeans, and hoodies were still totally ok. Everything about Black Hat is big and polished. The breakfast\/lunch room (this is the only event that includes meals) was an enormous matrix of banquet tables and professional staff who greeted everyone with a smile and directed people to the open buffet lines politely and efficiently. The plenary room was full of flashing lights and a glass cracking theme for the opening session (I assume the idea is glass cracking as in breaking things, not cracking the glass ceiling, since there wasn&#8217;t a whole lot of evidence of glass ceiling cracking here). I got to see Jeff Moss and Dan Kaminsky. Among other things, Dan urged hackers\u00a0to &#8220;break things faster,&#8221; encouraged\u00a0companies to publish their code so that it would be indexed by Google and easier for their own employees to find, and suggested outsourcing more security functions to the cloud.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9076.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-747\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9076-150x150.jpg\" alt=\"Black Hat breakfast and lunch room\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9100.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-751\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9100-150x150.jpg\" alt=\"Black Hat opening keynote\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9077.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-748\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9077-150x150.jpg\" alt=\"Black Hat opening keynote\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9084.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-749\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9084-150x150.jpg\" alt=\"Black Hat opening keynote - Jeff Moss\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9093.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-750\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9093-150x150.jpg\" alt=\"Black Hat opening keynote - Dan Kaminsky\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>The Black Hat business hall was also enormous, and many vendors were handing out swag. I collected enough t-shirts to clothe my kids for quite a while, plus bags, pens, and light-up balls. I would not come home empty handed. I was excited to visit\u00a0the <a href=\"http:\/\/wombatsecurity.com\" target=\"_blank\">Wombat<\/a> booth.\u00a0Down the hall from Blackhat, in the same hotel, was the <a href=\"http:\/\/www.superzoo.org\" target=\"_blank\">Superzoo<\/a> show for pet retailers. The carts stacked with dog beds and cat food were an amusing contrast to Black Hat.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9102.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-752\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9102-150x150.jpg\" alt=\"Black Hat business hall\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9106.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-753\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9106-150x150.jpg\" alt=\"Black Hat business hall - Wombat booth\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9171.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-762\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9171-150x150.jpg\" alt=\"SuperZoo at Mondalay Bay\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>I attended several really interesting talks at Black Hat, mostly on the human factors track (including a talk by my former PhD student, <a href=\"http:\/\/patrickgagekelley.com\" target=\"_blank\">Patrick Kelley<\/a>). There was a fun talk about dropping USB sticks in the parking lot. I was mostly interested in the data about how often they got picked up, although I think many in the audience enjoyed learning about how to make a fake USB stick that would automatically deploy malware when someone sticks it in their computer. One of my favorite talks was on using forensic linguistics to identify signs that a phone call is from a scammer. And of course no hacker conference is\u00a0complete if you don&#8217;t see someone\u00a0who has brought their own ATM machine.<\/p>\n<p>As with the other hacker conferences,\u00a0the crowd was not particularly diverse, although I did not find the climate uncomfortable at Black Hat and I was glad to see\u00a0that all the staff in the business hall booths seemed to be dressed appropriately for the event. The Black Hat organizers had posted their <a href=\"https:\/\/www.blackhat.com\/code-of-conduct.html\" target=\"_blank\">code of conduct<\/a> all over the place, and there were a couple of sessions focussed on getting more women into the security field (thanks <a href=\"http:\/\/www.ewf-usa.com\" target=\"_blank\">EWF <\/a>and <a href=\"https:\/\/www.facebook.com\/groups\/EqualRespect\/\" target=\"_blank\">Equal Respect<\/a>!). When asked what they could do to attract more women to apply to be speakers I suggested personal invitations (which is the main reason I was at BSides, thanks Per!) and childcare and\/or kids track (my kids were not available this week, but had they been I could have brought them to BSides and DEFCON but Black Hat would have been prohibitively expensive).<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9180.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-763\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9180-150x150.jpg\" alt=\"Patrick presenting at Black Hat\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9156.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-758\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9156-150x150.jpg\" alt=\"ATM machine for Black Hat demo\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9072.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-746\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9072-150x150.jpg\" alt=\"Black Hat code of conduct\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>I didn&#8217;t have much time to sight-see, but did check out some of the other hotels and casinos. I visited Ancient Egypt, where I discovered you can eat sushi. Then on to New York, which was an adorable scaled-down replica of the real thing, but so much more peaceful without honking horns and huge crowds. The Excalibur castle looked like something out of Disneyland.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9119.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-754\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9119-150x150.jpg\" alt=\"Inside the Pyramid in Las Vegas\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9134.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-755\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9134-150x150.jpg\" alt=\"New York New York\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9145.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-756\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9145-150x150.jpg\" alt=\"New York New York\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9149.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-757\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9149-150x150.jpg\" alt=\"Excalibar at night\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>I had to taxi over to DEFCON and back on Thursday mid-day to pick up my speaker badge and was back there in the evening and then all day on Friday. DEFCON is the largest of the three events and uses space in both the Bally&#8217;s and Paris hotels. The Paris has a casino at the base of the Eiffel tower and cute Parisian streets lined with over-priced cafes where they require you to show ID when you buy a $3 yogurt with a credit card.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9322.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-788\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9322-150x150.jpg\" alt=\"Las Vegas strip\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9160.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-759\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9160-150x150.jpg\" alt=\"Paris hotel\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9166.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-760\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9166-150x150.jpg\" alt=\"Paris hotel\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>DEFCON has something like 15,000 attendees, but you can&#8217;t register in advance and you have to pay cash at the door. Badge distribution and crowd control in general is quite a challenge, and there is a lot of waiting in line at DEFCON. Nonetheless, the DEFCON goons were friendly and managed the crowd well. And they looked stylish\u00a0with their red t-shirts and police-style goon badges. I walked by the <a href=\"https:\/\/r00tz.org\" target=\"_blank\">DEFCON kids track<\/a> which looked like it would be fun to check out if I had brought my kids.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9168.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-787\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9312-150x150.jpg\" alt=\"Bally's to Paris connection at DEFCON\" width=\"150\" height=\"150\" \/><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-761\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9168-150x150.jpg\" alt=\"DEFCON at Paris Hotel\" width=\"150\" height=\"150\" \/><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-769\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9243-150x150.jpg\" alt=\"DEFCON at Paris Hotel\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>I checked out the DARPA Cyber Grand Challenge and saw the <a href=\"https:\/\/blog.forallsecure.com\/2016\/08\/06\/mayhem-wins-darpa-cgc\/\" target=\"_blank\">Mayhem team<\/a> with CMU colleagues being interviewed after their victory. I met up with some of my fellow &#8220;feds&#8221; to prepare for our Meet the Feds panel.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9195.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-764\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9195-150x150.jpg\" alt=\"Cyber Grand Challenge\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9198.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-765\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9198-150x150.jpg\" alt=\"Cyber Grand Challenge\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9203.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-766\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9203-150x150.jpg\" alt=\"Cyber Grand Challenge\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9209.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-767\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9209-150x150.jpg\" alt=\"Allan and Jonathan at Cyber Grand Challenge at DEFCON\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9213.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-768\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9213-150x150.jpg\" alt=\"Allan, Jonathan, and Lorrie at Cyber Grand Challenge at DEFCON\" width=\"150\" height=\"150\" srcset=\"https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9213-150x150.jpg 150w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9213-300x300.jpg 300w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9213-1024x1024.jpg 1024w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9213.jpg 1500w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a><\/p>\n<p>We reported to the speakers room\u00a045 minutes before our talk and our goon escorted us to the room we were speaking in, a long walk through the casino and into Bally&#8217;s. We had about 800 people for the Meet the Feds panel\u00a0and it was standing room only. We had some good questions, including from a high school student who wanted to know about careers in government.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9245.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-770\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9245-150x150.jpg\" alt=\"DEFCON speaker ready room, with Eric Mill and goon\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9250.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-771\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9250-150x150.jpg\" alt=\"DEFCON, Meet the Feds\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9259.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-772\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9259-150x150.jpg\" alt=\"Allan, Eric, Lorrie, and Jonathan - DEFCON, Meet the Feds\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9261.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-773\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9261-150x150.jpg\" alt=\"Allan, Eric, Lorrie, and Jonathan - DEFCON, Meet the Feds\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>My second panel was back in the Paris hotel in another large room. Commissioner McSweeney and I talked about the <a href=\"https:\/\/www.ftc.gov\/news-events\/blogs\/techftc\/2016\/08\/ftc-goes-def-con\" target=\"_blank\">FTC and our research wish list<\/a>. I discovered that the super cool podium looks great, but is not so good for short people as I could hardly be seen behind it.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9264.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-774\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9264-150x150.jpg\" alt=\"DEFCON FTC session\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9269.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-775\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9269-150x150.jpg\" alt=\"DEFCON FTC session - Terrell and Lorrie\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9271.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-776\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9271-150x150.jpg\" alt=\"DEFCON FTC session - Terrell and Lorrie\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9275.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-777\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9275-150x150.jpg\" alt=\"DEFCON FTC session - Terrell and Lorrie\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>FTC folks all wore the FTC DEFCON t-shirts I designed, complete with secret code (successfully cracked by my son in about 90 minutes).<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9286.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-778\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9286-150x150.jpg\" alt=\"Joe, Lorrie, Aaron, Terrell at DEFCON\" width=\"150\" height=\"150\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9339.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-791\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9339-150x150.jpg\" alt=\"FTC DEFCON t-shirt front\" width=\"150\" height=\"150\" srcset=\"https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9339-150x150.jpg 150w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9339-300x300.jpg 300w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9339-1024x1024.jpg 1024w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9339.jpg 1500w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9340.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-792\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9340-150x150.jpg\" alt=\"FTC DEFCON t-shirt back\" width=\"150\" height=\"150\" srcset=\"https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9340-150x150.jpg 150w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9340-300x300.jpg 300w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9340-1024x1024.jpg 1024w, https:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9340.jpg 1500w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a><\/p>\n<p>The DEFCON vendor room did not have much for free, but lots of fun things to buy like lock\u00a0picks and hacking tools. Contest rooms and &#8220;villages&#8221; featured tables full of hackers working on competitions and projects, lots of people soldering (not sure what exactly), cars for car hacking, and phones for social engineering. There were beauticians\u00a0offering\u00a0mohawks in any color. Hacker jeopardy was a low point, as interspersed between geeky technical questions were questions full of sexual innuendo, which produced the predictably inappropriate and vulgar responses from contestants. Not classy!\u00a0While this sort of behavior seemed to be the exception and not the rule at DEFCON this year, it should not be tolerated.<\/p>\n<p>Overall, I did not see\u00a0too many women at DEFCON. One attendee who saw my speaker badge asked if I was <a href=\"http:\/\/www.internethalloffame.org\/inductees\/radia-perlman\" target=\"_blank\">Radia Perlman<\/a>. Perhaps she was the only female computer scientist he could think of who might be a speaker? There are worse people to be mistaken for, but she is about 20 years older than me and we look nothing alike.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9293.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-779\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9293-150x150.jpg\" alt=\"DEFCON Venders\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9295.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-780\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9295-150x150.jpg\" alt=\"DEFCON contest room\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9296.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-781\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9296-150x150.jpg\" alt=\"DEFCON contest room\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9300.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-782\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9300-150x150.jpg\" alt=\"DEFCON contest room\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9305.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-783\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9305-150x150.jpg\" alt=\"DEFCON car hacking\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9306.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-784\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9306-150x150.jpg\" alt=\"Hacker jeopardy\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9309.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-785\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9309-150x150.jpg\" alt=\"DEFCON soldering\" width=\"150\" height=\"150\" \/><\/a> <a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9310.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-786\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9310-150x150.jpg\" alt=\"DEFCON\" width=\"150\" height=\"150\" \/><\/a><\/p>\n<p>On the flight home the couple sitting next to me asked if I knew anything about all those people walking around the Strip with skull badges. Yes, indeed, I told them as I pulled my DEFCON badge out of my backpack and showed them how I could press the buttons in the right order and make it light up.<\/p>\n<p><a href=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9336.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-thumbnail wp-image-789\" src=\"http:\/\/lorrie.cranor.org\/blog\/wp-content\/uploads\/2016\/08\/DSCF9336-150x150.jpg\" alt=\"badges\" width=\"150\" height=\"150\" \/><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>I spent 4 days in Las Vegas this past\u00a0week attending the back-to-back BSides LV, Black Hat, and DEFCON 24 hacker conferences. \u00a0This was my first trip to Vegas and my first time at these events (although I have attended local &hellip; <a href=\"https:\/\/lorrie.cranor.org\/blog\/2016\/08\/07\/bsides-black-hat-and-defcon\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":791,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[],"class_list":["post-740","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-travel"],"_links":{"self":[{"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/posts\/740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/comments?post=740"}],"version-history":[{"count":12,"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/posts\/740\/revisions"}],"predecessor-version":[{"id":803,"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/posts\/740\/revisions\/803"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/media\/791"}],"wp:attachment":[{"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/media?parent=740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/categories?post=740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/lorrie.cranor.org\/blog\/wp-json\/wp\/v2\/tags?post=740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}