DEF CON and Black Hat and BSides, Oh My
The Three Horsemen of Hacker Summer Camp.
Let’s get ready to rumble!!
The DEF CON / Black Hat / BSides conferences are happening this week. It’s a time when the entire industry shuts down, everybody either travels to the mythical city of Las Vegas to attend or wishes they could, and for one glorious, chaotic week, Las Vegas becomes the center of the cybersecurity universe.
I’m making the annual pilgrimage myself this year. Among other things, I’ll be signing copies of Cybersecurity First Principles at the conference bookstore. If you’ll be in Las Vegas for the conference, I’d love to meet you.
In honor of the occasion, I thought a little historical perspective on these three great conferences was in order.
DEF CON
DEF CON began by accident in 1993. An 18-year-old Jeff Moss (AKA The Dark Tangent) ran his own BBS, which had become a hub for 11 different hacking and phreaking networks, including Platinum Net (a network with roots in Canada).
For you youngsters out there, BBSs were the internet before we had the internet. We connected to them via modems through our home telephone lines and we could share files and chat with our buddies. We all thought we had gone to Nirvana.
A friend on the Platinum Net was leaving town and asked Moss to throw him a farewell party in Las Vegas. The friend decided to depart early leaving Moss holding a party with no guest of honor, so he invited everybody on Platinum Net to come. He even extended the invite to the Secret Service and the FBI by faxing their respective headquarters buildings.
Again, for you youngsters, if you don’t know what a fax is, look it up on Wikipedia and work back from there.
About 100 people showed up at the Sands Hotel to gamble, drink, and listen to a dozen speakers talk about hacking computers. People had so much fun that Moss decided to repeat the conference annually.
Trivia: DEF CON, the name, comes from one of the greatest hacker movies of all time, the 1983 film WarGames, in which Las Vegas is depicted as a nuclear target. In the movie and in real life, “DEFCON” is the U.S. military’s readiness scale (DEFCON 5 = calm, DEFCON 1 = about to launch missiles).
Black Hat
Four years later (1997), Moss created the Black Hat conference because DEF CON attendees couldn’t convince their day-job bosses to expense the trip. Back then, the business elite considered the conference to be a boondoggle run by, and attended by, a bunch of ne’er-do-well hacker troublemakers. Moss established Black Hat as a legitimate security conference because of that criticism. He scheduled Black Hat immediately before DEF CON each year so attendees could expense the “professional” event and stay for the “party.”
Trivia: “Black Hat,” the name, goes back to 1950s Western movies and TV. Villains traditionally wore black hats and heroes wore white ones. Hacker culture had already borrowed that convention before Moss chose the name. Sometime in the early 1990s, the hacker community started using “Black Hat (Bad Guy),” “White Hat (Good Guy),” and “Gray Hat (A little bit of both)” to refer to community members.
BSides
Over a decade later (2009), some members of the hacker community’s royalty (Mike Dahn, Jack Daniel, and Chris Nickerson) created BSides Las Vegas. They were frustrated with Black Hat’s formal process for accepting presentations and denying many simply because there wasn't room. What started as scattered disappointment on Twitter, Facebook, and email among the rejected submitters turned into a plan to host those rejected talks in a rented vacation house, for a small crowd, deliberately without the scale or corporate structure Black Hat had back then.
The first BSides ran July 29–30, 2009, with roughly 200 people, and by most accounts was as much a party as a conference. Over the years, BSides scaled into a global franchise (600+ events by 2020) and became the third horseman of “Hacker Summer Camp.”
Trivia: “BSides,” the name, comes from the vinyl-record industry where, back in the old days (‘50s through the ‘70s), it was common practice to put the non-hit side of a single on the B-Side of a 45 rpm record, a direct, self-aware metaphor for "the talks that didn't make the main stage" at Black Hat.
Legendary Stories
Over the years, several stories have emerged that build on the conference triad’s mystique.
1999: The Release of Back Orifice 2000 (DEF CON): A hacker group called the Cult of the Dead Cow (cDc) released Back Orifice 2000 (BO2k) targeting the Windows NT/2000/XP operating systems. Back then, when security researchers told Microsoft “your software has holes,” Microsoft ignored them. To get their attention, the cDc released the code at the conference: actual working software that lets a stranger take over your Windows computer remotely. It mattered because it forced Microsoft to take the vulnerability research community seriously. Note: The exploits of the cDc are fully documented in Joe Menn’s 2020 Canon Hall of Fame book Cult of the Dead Cow.
2001: The Infamous Whistleblower James Bamford (Black Hat): Bamford's NSA-history talk previews the whistleblower-vs-traitor debate, 12 years before Snowden. Bamford is to the NSA what Bob Woodward is to the White House. He was an investigative chronicler the NSA threatened with prosecution over his 1982 book (the 2008 Canon Niche- Nominated book, The Shadow Factory) though no charges were ever actually filed.
2001: FBI Arrests Dmitry Sklyarov after Talk (DEF CON): Sklyarov made a $99 tool letting people strip the copy-protection off Adobe e-books they’d already legally bought. He gave a talk explaining exactly how weak that protection was. The day after his talk, the FBI arrested him, not for hacking anything or stealing anything, but simply for having made a tool that could remove copy protection. It became one of the first real tests of whether security research itself, the act of demonstrating how a protection scheme fails, could be prosecuted as a crime, independent of what anyone did with that knowledge.
2005: Ciscogate (Black Hat): Michael Lynn found a serious bug in Cisco’s router software. Cisco pressured his employer, ISS, who told Lynn not to present. Lynn gave the talk anyway, explained exactly how to take over a Cisco router, and then quit his ISS job. Cisco and ISS then sued both Lynn and Black Hat but settled the lawsuit by letting a neutral third party wipe Lynn’s research and slapping a gag order on Lynn. The incident became a landmark case in the fight over whether researchers can tell the truth about security holes when the company that made them doesn’t want to hear it.
2007: NBC Caught Secretly Filming (DEF CON): Producer Michelle Madigan tried to secretly film DEF CON attendees hoping to catch people admitting to illegal stuff. Somebody tipped DEF CON leadership that she was coming, and DEF CON Security (the Goons) caught her secretly filming people playing a hacking game. Jeff Moss got on stage, told the whole room a reporter with a hidden camera was there, and turned it into an impromptu game: “Spot the Undercover Press.” Before the crowd could even respond, she bolted. Roughly 150 people, including actual reporters, chased her out of the room and through the hotel parking lot to her car.
2010: The Barnaby Jack ATM Demo (Black Hat): Jack demonstrated that a gas-station/bar-style ATM could be made to spray out cash on command, no card or PIN needed. He bought two machines himself and demonstrated the holes on stage when the machines flashed “JACKPOT” and started spraying money.
2012: NSA Director Denies Domestic Surveillance (DEF CON): During his keynote, U.S. Army General Keith Alexander denied that the NSA conducts any domestic surveillance.
2013: Moss Disinvites the Government (DEF CON): Moss asked federal agencies to skip the conference in response to the the Snowden release of classified information. That data set completely refuted General Alexander’s denials from the year before.
2015: Jeep Remote Hack (Black Hat): Charlie Miller and Chris Valasek remotely hack a Jeep at 70 mph with a Wired reporter driving.
2016: DARPA AI CTF Challenge (DEF CON): The Defense Advanced Research Projects Agency (DARPA) ran a competition asking: can a computer find and fix its own security holes entirely on its own, faster than a human? Seven AI systems fought it out to automatically find bugs in unfamiliar code, patch them, exploit the other systems in the competition, all without any human touching the keyboard. ForAllSecure’s Mayhem system, spun out of Carnegie Mellon, won and took home $2 million. DEF CON then let Mayhem into the human Capture the Flag finals, the real, top-tier human hacking tournament. It finished dead last, 15th of 15.
Time passes, people and conferences mature, and the headline-grabbing iconic hack that we could routinely expect from the triad stopped happening. Even Black Hat’s own 25th-anniversary retrospective (Dark Reading, 2023) stops naming “iconic hacks” at the 2015 Jeep hack, then pivots straight into a “Growing Up” section.
My two favorite stories.
The first might be apocryphal because I didn’t see it happen nor could I find a source that validated it, but sometime in the late 2000s, conference attendees were are all sharing it with each other with a “Can you believe this?” expression on our faces.
Apparently, at the beginning of the DEF CON conference, four guys wearing workman’s overalls carried a slot machine into a casino, found an open spot on an interior wall, plugged it in and walked out. During the week, casino customers would plop money into the machine, but when they did, they received an error message saying the game was out of order. Most customers just moved on to the next machine. If customers complained, Casino management returned their quarters. But no casino employee bothered to check the broken machine. At the end of the week, the four guys returned wearing their overalls, and carried the “broken” machine out the front door. Clean getaway. I love that story, and even though it might not be true, it captures the spirit of the hacker mindset. The caper’s purpose wasn’t exactly to steal money from unsuspecting tourists. It was, primarily, to test the system, to see what could be done in the old-fashioned sense of the hacker mythos.
The second story I can vouch for. I was in the room. DEF CON has this tradition called “Spot the Fed.” In the early days, there were a lot of suspicion and trust issues between law enforcement and the hacker community. Naturally, various international law enforcement agencies would send agents to the conference, incognito style, to see what they could learn. It became a game for hacker attendees to out these federal agents in public. If you were in a speaker session, you stood up, interrupted the speaker, and pointed to the suspected fed. Everything would stop. The goons (volunteer security) would haul both people on stage to validate the accusation. If it was true, the hacker would get a T-shirt that said “I spotted the fed.” The Fed would get the “I am the fed” T-shirt, a coveted prize by real federal agents.
Sometime in the late 2000s, maybe early 2010s, I was listening to a presentation in one of the big rooms. A young woman stood up, pointed to a guy, and said, “Fed!” The act was a rarity in itself because you traditionally don’t see a lot of women at DEF CON (although the numbers have improved over the years). The Goons came in, hauled the two people to the stage and asked the woman why she knew the guy was a fed. The woman said, “Well, I slept with the guy last night.” The crowd exploded with applause. After it died down, one Goon asked the woman, “Yes, but how do you know he is a fed?” The woman said, “I stole his badge!” and proceeded to wave an open wallet over her head with a gleaming golden badge clearly visible. Mayhem! Standing ovation. It was fantastic. The fed himself was just standing there with a sheepish grin on his face silently admitting that yes, he did sleep with this woman, and yes, I am a fed. T-shirt earned.
Take Away
Black Hat, DEF CON, and BSides, the Three Horsemen of Hacker Summer Camp, are almost a religious destination, like Mecca, for the white hats, black hats, and gray hats in the community. If you’re in one or more of those groups, or aspire to be in those groups, you have to attend at least once in your career just to have the bragging rights that says yes, you have been there and done that.
Sources
Staff, 2026. Black Hat USA 2026 [Conference Website]. URL: https://blackhat.com/us-26/
Staff, 2026. DEF CON® Hacking Conference [Conference Website]. URL: https://www.defcon.org/
Staff, 2026. BSides Las Vegas [Conference Website]. URL: https://bsideslv.org/
References
Andrada Fiscutean, 2023. Looking Back at 25 Years of Black Hat [Essay]. Dark Reading, URL: https://www.darkreading.com/cyber-risk/looking-back-at-25-years-of-black-hat
James Bamford, 2008. The Shadow Factory: The Ultra-Secret NSA from 9/11 to the Eavesdropping on America [2016 Canon Niche Nominated]. Canon Review URL: https://cybercanon.org/the-shadow-factory-the-ultra-secret-nsa-from-9-11-to-the-eavesdropping-on-america/
John Badham (Director), Matthew Broderick, Dabney Coleman, Ally Sheedy, Barry Corbin, and James Tolkan (Actors), 1983. WarGames [Movie]. Letterboxd, URL: https://letterboxd.com/film/wargames/
Joseph Menn, 2019. Cult of the Dead Cow: How the Original Hacking Supergroup Might Just Save the World [2020 Canon Hall of Fame book]. Canon Book Review URL: https://cybercanon.org/cult-of-the-dead-cow/
Nicole Perlroth, 2021. This Is How They Tell Me the World Ends: The Cyberweapons Arms Race [2023 Canon Hall of Fame book]. Canon review: https://cybercanon.org/this-is-how-they-tell-me-the-world-ends/
Staff, ND. DEF CON [Explainer]. Wikipedia, URL: https://en.wikipedia.org/wiki/DEF_CON
Staff, ND. DEF CON Hacker Conference - Book List [Listing]. DEF CON, URL: https://defcon.org/html/links/book-list.html
Tony Frazier, 2008. Out of the Vault - D’Arc Tangent [Blog]. TheyStoleFrazier’sBrain, URL: https://fraziersbrain.blogspot.com/2008/12/out-of-vault-darc-tangent.html
Winn Schwartau, 1994. DefCon II: Las Vegas - Cyber-Christ meets Lady Luck [Essay]. Wayback Machine, URL: http://www.winnschwartau.com/resources/CyberChrist%2BMeets%2BLady%2BLuck%2BDC2.pdf
Jeff Moss, 2007. The Story of DEFCON [History]. Help Net Security - YouTube, URL:
Jason Scott ( Director), 2013. DEFCON - The Full Documentary [Documentary]. The Documentary Network - YouTube, URL:
Note about Using AI for this Essay
I used ChatGPT and Claude to
check for grammar and spelling errors.
flag passive voice.
suggest changes to awkward sentence construction.
create images.
fact-check.
stress-test my thesis




It must have been '97 then when I went to Black Hat and DefCon. I still have the metal badge somewhere. I signed up for Black Hat, as there was no way that BoG mgmt would send me to a hacker fest. DefCon was at some dumpy hotel a couple of blocks off the Strip. I hung out close to the exits as I fully expected a police raid at any time. The Feds who showed up there stuck out like a sore thumb. Their idea of dressing down was wearing hawaiian shirts, golf pants, and loafers. I had lots of dirtbag clothes to wear so I fit in. I dont recall Black Hat being all that memorable. I guess it got better.
I am coming next year!