DEF CON explained

Logo Alt:DEF CON Logo
Status:Active
Frequency:Annual
Genre:Security Conference, Hacker Conference
Venue:Varies
Location:Las Vegas, Nevada
Prev:August 8-11, 2024
Next:TBD
Founder Name:Jeff Moss
Attendance:Over 30,000
First:[1]

DEF CON (also written as DEFCON, Defcon or DC) is a hacker convention held annually in Las Vegas, Nevada. The first DEF CON took place in June 1993 and today many attendees at DEF CON include computer security professionals, journalists, lawyers, federal government employees, security researchers, students, and hackers with a general interest in software, computer architecture, hardware modification, conference badges, and anything else that can be "hacked". The event consists of several tracks of speakers about computer- and hacking-related subjects, as well as cyber-security challenges and competitions (known as hacking wargames). Contests held during the event are extremely varied and can range from creating the longest Wi-Fi connection to finding the most effective way to cool a beer in the Nevada heat.[2]

Other contests, past and present, include lockpicking, robotics-related contests, art, slogan, coffee wars, scavenger hunt, and Capture the Flag. Capture the Flag (CTF) is perhaps the best known of these contests and is a hacking competition where teams of hackers attempt to attack and defend computers and networks using software and network structures. CTF has been emulated at other hacking conferences as well as in academic and military contexts (as red team exercises).

Federal law enforcement agents from the FBI, DoD, United States Postal Inspection Service, DHS (via CISA) and other agencies regularly attend DEF CON.[3] Some have considered DEF CON to be the "world's largest" hacker con given its attendee size and the number of other conferences modeling themselves after it.

History

DEF CON was founded in 1993, by then 18-year-old Jeff Moss as a farewell party for his friend, a fellow hacker and member of "Platinum Net", a FidoNet protocol based hacking network from Canada.[4] The party was planned for Las Vegas a few days before his friend was to leave the United States, because his father had accepted employment out of the country. However, his friend's father left early, taking his friend along, so Jeff was left alone with the entire party planned. Jeff decided to invite all his hacker friends to go to Las Vegas with him and have the party with them instead. Hacker friends from far and wide got together and laid the foundation for DEF CON, with roughly 100 people in attendance.

The term DEF CON comes from the movie WarGames, referencing the U.S. Armed Forces defense readiness condition (DEFCON). In the movie, Las Vegas was selected as a nuclear target, and since the event was being hosted in Las Vegas, it occurred to Jeff Moss to name the convention DEF CON. However, to a lesser extent, CON also stands for convention and DEF is taken from the letters on the number 3 on a telephone keypad, a reference to phreakers.[5] The official name of the conference includes a space in-between DEF and CON.

Though intended to be a one-time event, Moss received overwhelmingly positive feedback from attendees, and decided to host the event for a second year at their urging. The event's attendance nearly doubled the second year, and has enjoyed continued success.[6] In 2019, an estimated 30,000 people attended DEF CON 27.[7]

For DEF CON's 20th Anniversary, a film was commissioned entitled DEFCON: The Documentary. The film follows the four days of the conference, events and people (attendees and staff), and covers history and philosophy behind DEF CON's success and unique experiences.

In January 2018, the DEF CON China Beta event was announced. The conference was held May 11–13, 2018 in Beijing, and marked DEF CON's first conference outside the United States. The second annual DEF CON China was canceled due to concerns related to COVID-19.[8]

In 2020, due to safety concerns over COVID-19 the DEF CON 28 in-person Las Vegas event was cancelled[9] and replaced with DEF CON Safe Mode,[10] a virtual event planned for the same August 6–9 dates as DC 28.

In 2021, DEF CON 29 was held on August 5–8 in-person in Las Vegas and virtually (via Twitch and Discord). In-person attendees were required to wear masks in conference areas and to show proof of COVID-19 vaccination. Attendees with verified vaccine records (verified by a 3rd party) were given a wristband which was required for entry into the conference areas.[11]

Components

Handles

Attendees at DEF CON and other Hacker conferences often utilize an alias or "handle" at conferences. This is in keeping with the hacker community's desire for anonymity. Some known handles include DEF CON founder Jeff Moss' handle of "Dark Tangent". A notable event at DEF CON is DEF CON 101 which starts off the con and may offer the opportunity for an individual to come up on stage and be assigned a handle by a number of members of the community.

Badges

A notable part of DEF CON is the conference badge, which identifies attendees and ensures attendees can access conference events and activities. The DEF CON badge has historically been notable because of its changing nature, sometimes being an electronic badge (PCB), with LEDs, or sometimes being a non-electronic badge such as a vinyl record. Conference badges often contain challenges or callbacks to hacker or other technology history, such as the usage of the Konami Code in the DEF CON 24 badge, or the DEF CON 25 badge reverting to the look of the DEF CON 1 badge. DEF CON Badges do not (generally) identify attendees by name; however, the badges are used to differentiate attendees from others. One way of doing this has been to have different badges, a general conference attendee (HUMAN) badge, a Staff member (GOON), Vendor, Speaker, Press, and other badges. In addition, individuals and organizations have begun creating their own badges in what has become known as badgelife. These badges may be purchased in many cases, or earned at the conference by completing challenges or events. Some badges may give the holder access to after hours events at the conference. In 2018, the evolution of this came with what was termed "shitty addon's" or SAOs. These were miniature (usually) PCBs that connected to the official and other badges that may extend functionality or were just collected.[12] [13]

Villages

Villages are dedicated spaces arranged around a specific topic. Villages may be considered mini conferences within the con, with many holding their own independent talks as well as hands-on activities such as CTFs, or labs. Some villages include Aerospace Village, Car Hacking Village, IoT Village, Recon, Biohacking, lockpicking, ham radio, and the well known Social Engineering and vote hacking villages. In 2018 the vote hacking village gained media attention due to concerns about US election systems security vulnerabilities.[14] [15]

Internal Conferences

DEF CON has its own cultural underground which results in individuals wanting to create their own meetups or "cons" within DEF CON. These may be actual formal meetups or may be informal. Well known cons are:

Workshops

Workshops are dedicated classes on various topics related to information security and related topics. Historical workshops have been held on topics such as Digital Forensics investigation, hacking IoT devices, playing with RFID, fuzzing and attacking smart devices.

Fundraising

Since DEF CON 11, fundraisers have been conducted for the Electronic Frontier Foundation (EFF). The first fundraiser was a dunk tank and was an "official" event. The EFF now has an event named "The Summit" hosted by the Vegas 2.0 crew that is an open event and fundraiser. DEF CON 18 (2010) hosted a new fundraiser called MohawkCon.

Contests

Within DEF CON there are many contests and events which range from, Capture the Flag, Hacker Jeopardy,[16] Scavenger Hunt,[17] Capture the Packet, Crash and Compile,[18] and Hackfortress[19] to name a few.

Black Badge

The Black Badge is the highest award DEF CON gives to contest winners of certain events. Capture the flag (CTF) winners sometimes earn these, as well as Hacker Jeopardy winners. The contests that are awarded Black Badges vary from year to year, and a Black Badge allows free entrance to DEF CON for life, potentially a value of thousands of dollars.[20]

In April 2017, a DEF CON Black Badge was featured in an exhibit[21] in the Smithsonian Institution's National Museum of American History entitled "Innovations in Defense: Artificial Intelligence and the Challenge of Cybersecurity". The badge belongs to ForAllSecure's Mayhem Cyber Reasoning System,[22] the winner of the DARPA 2016 Cyber Grand Challenge at DEF CON 24 and the first non-human entity ever to earn a Black Badge.

Capture the flag

The first instance of the DEF CON CTF was held in 1996, at the 4th DEF CON, and has been held since then every year.[23] It's one of the few CTF in the attack/defense format. The prize of the winning team is a couple of black badges.[24]

Capture the Flag Timeline [25] !Year!DEF CON!Competing Teams!Organizers!Architecture!Platform!Winning Team
19964GoonsAJ Reznor
19975GoonsAJ Reznor
19986GoonsSNI
19997GoonsGhetto Hackers
20008GoonsGhetto Hackers
20019GoonsMultipleGhetto Hackers & digirev
200210Ghetto HackersRedhat 6.2Digital Revelation
2003118Ghetto HackersOpenBSDAnomaly
2004128Ghetto Hackersi386Windowssk3wl0fr00t
2005138Kenshotoi386FreeBSD 5.4shellphish
2006148Kenshotoi386Solaris 101@stplace
2007158Kenshotoi386FreeBSD1@stplace
2008168Kenshotoi386FreeBSDSk3wl of Root
2009179DDTEKi386FreeBSDVedaGodz[26]
20101812DDTEKi386FreeBSD & DebianACME Pharm[27]
20111912DDTEKi386FreeBSDEuropean Nopsleders[28]
20122020DDTEKi386FreeBSDSamurai
20132120Legitimate Business Syndicatearmv7LinuxPlaid Parliament of Pwning
20142220Legitimate Business Syndicatearmv7 & i386LinuxPlaid Parliament of Pwning
20152315Legitimate Business SyndicateMIPS, x86 & armv7LinuxDEFKOR
20162415Legitimate Business Syndicatei386DECREEPlaid Parliament of Pwning
20172515Legitimate Business SyndicatecLEMENCycLEMENCyPlaid Parliament of Pwning
20182624Order Of the OverflowMIPS, x86 & armv7LinuxDEFKOR00T[29]
20192716Order Of the Overflowx86, arm64, esotericLinux, iOS, XboxPlaid Parliament of Pwning[30]
20202816Order Of the Overflowx86, esotericLinuxA*0*E[31]
20212916Order Of the Overflowx86, microengineLinuxKatzebin[32]
20223016Nautilus InstitutemixedLiveCTFMaple Mallard Magistrates
20233112Nautilus InstitutemixedLiveCTFMaple Mallard Magistrates

Capture the Flag History

In 1996, the first DEF CON CTF was organized, with a couple of servers for participants to hack, and judges to decide if a machine has been hacked, and award points accordingly.[33]

In 2002, the company Immunix took part in the game under the moniker "immunex",[34] to benchmark the security of their Linux-based operating system, with modifications including StackGuard, FormatGuard, OpenWall's non-executable stack, SubDomain (the ancestor of AppArmor), ...[35] Confident in their defense capabilities, they even opened access to their servers to other teams, and even spent some time taunting them. The team got the second place, and all their services deployed on their Immunix stack were never compromised.[36] It was also the first year the contest had an organiser-provided services infrastructure connected to a real-time scoreboard.[37]

In 2003, the game had become so popular that a qualification round was introduced, with the previous winner automatically qualified.[38]

In 2008, the Sk3wl of Root team took advantage of a bug in the game (privilege dropping and forking were inverted), allowing them to have such a massive lead that they spent most of the CTF playing Guitar Hero.

In 2009, it was announced[39] that "Diutinus Defense Technology Corp" (DDTEK) would be the new organisers, but nobody knew who they were. It was revealed at the end of the game that the team playing as sk3wl0fr00t was in fact organising the CTF! "Hacking the top hacker contest seemed like a fun way to introduce ourselves to CTF organization. The yells of "bullshit" from CTF teams during the Defcon 17 awards ceremony were very gratifying." said vulc@n, a member of DDTEK, on the topic.

In 2011, the team "lollerskaters dropping from roflcopters" used a 0day in FreeBSD (namely CVE-2011-4062[40]) to escape jails, causing havoc in the game's infrastructure.[41]

In 2016, the 15th edition of the CTF was done in partnership with the DARPA, as part of its Cyber Grand Challenge program, where teams wrote autonomous systems to play the game without any human interaction.[42]

In 2017, the Legitimate Business Syndicate came up with their very own CPU architecture called cLEMENCy: a middle-endian with 9 bits bytes CPU. With its specifications released only 24h before the beginning of the CTF, it was designed with the explicit goals of both surprising the teams, and leveling the playing field by breaking all their tools.[43]

Groups

DEF CON Groups are worldwide, local chapters of hackers, thinkers, makers and others. DEF CON Groups were started as a splinter off of the 2600 meetup groups because of concerns over politicization. Local DEF CON groups are formed and are posted online.[44] DEF CON Groups are usually identified by the area code of the area where they are located in the US, and by other numbers when outside of the US e.g., DC801, DC201. DEF CON Groups may seek permission to make a logo that includes the official DEF CON logo with approval.

Notable incidents

High-profile issues which have garnered significant media attention.

YearDescription
1999On July 10, 1999, the Cult of the Dead Cow hacker collective released Back Orifice 2000 (later discovered to be infected with the CIH virus) at DEF CON 7, in what was, at the time, the largest presentation in DEF CON history.
2001On July 16, 2001, Russian programmer Dmitry Sklyarov was arrested the day after DEF CON for writing software to decrypt Adobe's e-book format.
2005On July 31, 2005, Cisco used legal threats to suppress Mike Lynn from presenting at DEF CON about flaws he had found in the Cisco IOS used on routers.[45]
2007In August 2007, Michelle Madigan, a reporter for Dateline NBC, attempted to secretly record hackers admitting to crimes at the convention. After being outed by DEF CON founder Jeff Moss during an assembly, she was heckled and chased out of the convention by attendees for her use of covert audio and video recording equipment. DEF CON staff tried to get Madigan to obtain a press pass before the outing happened.[46] A DEF CON source at NBC had tipped off organizers to Madigan's plans.[47]
2008

See main article: article and Massachusetts Bay Transportation Authority v. Anderson. MIT students Zack Anderson, R.J. Ryan and Alessandro Chiesa were to present a session entitled "The Anatomy of a Subway Hack: Breaking Crypto RFIDS and Magstripes of Ticketing Systems." The presentation description included the phrase "Want free subway rides for life?" and promised to focus on the Boston T subway.[48] However, the Massachusetts Bay Transit Authority (MBTA) sued the students and MIT in United States District Court in Massachusetts on August 8, 2008, claiming that the students violated the Computer Fraud and Abuse Act (CFAA) by delivering information to conference attendees that could be used to defraud the MBTA of transit fares.[49] [50] The court issued a temporary restraining order prohibiting the students from disclosing the material for a period of ten days, despite the fact the material had already been disseminated to DEF CON attendees at the start of the show.
In 2008's contest "Race to Zero," contestants submitted a version of given malware which was required to be undetectable by all of the antivirus engines in each round. The contest concept attracted much negative attention.[51] [52]

2009WIRED[53] reported that an ATM kiosk was positioned in the conference center of the Riviera Hotel Casino capturing data from an unknown number of hackers attending the DEF CON hacker conference.
2011Security company HBGary Federal used legal threats to prevent former CEO Aaron Barr from attending a panel discussion at the conference.[54]
2012The director of the National Security Agency, Keith B. Alexander, gave the keynote speech.[55] During the question and answers session, the first question for Alexander, fielded by Jeff Moss,[56] was "Does the NSA really keep a file on everyone, and if so, how can I see mine?" Alexander replied "Our job is foreign intelligence" and that "Those who would want to weave the story that we have millions or hundreds of millions of dossiers on people, is absolutely false…From my perspective, this is absolute nonsense." On March 12, 2013, during a United States Senate Select Committee on Intelligence hearing, Senator Ron Wyden quoted the 2012 DEF CON keynote speech and asked Director of National Intelligence James Clapper if the U.S. conducted domestic surveillance; Clapper made statements saying that there was no intentional domestic surveillance. In June 2013, NSA surveillance programs which collected data on US citizens, such as PRISM, had been exposed. Andy Greenberg of Forbes said that NSA officials, including Alexander, in the years 2012 and 2013 "publicly denied–often with carefully hedged words–participating in the kind of snooping on Americans that has since become nearly undeniable."
2013On July 11, 2013, Jeff Moss posted a statement,[57] located on the DEF CON blog, titled "Feds, We Need Some Time Apart". It stated that "I think it would be best for everyone involved if the feds call a 'time-out' and not attend DEF CON this year."[58] This was the first time in the organization's history that it had asked federal authorities not to attend. Actor Will Smith visited the convention to study the DEF CON culture for an upcoming movie role.
2016On August 4, 2016, DEF CON and DARPA co-hosted the 2016 Cyber Grand Challenge, a first-of-its-kind all-machine hacking tournament. Competing teams had to create a bot capable of handling all aspects of offense and defense with complete autonomy. Seven finalists competed for a US$2M grand prize.

The winner of the Cyber Grand Challenge was "Mayhem", an AI created by ForAllSecure of Pittsburgh, Pennsylvania.[59] Mayhem then went on to participate in the previously humans-only DEF CON Capture the Flag Contest,[60] where it finished in last place, despite pulling ahead of human teams often in a contest for which it was not specifically designed.

2017At the "Voting Machine Village" event, dozens of voting machines brought to the conference were breached.[61]

In September 2017, the Voting Machine Village produced "DEF CON 25 Voting Machine Hacking Village: Report on Cyber Vulnerabilities in US Election Equipment, Databases and Infrastructure" summarizing its findings. The findings were publicly released at an event sponsored by the Atlantic Council[62] and the paper went on to win an O'Reilly Defender Research Award.[63]

Marcus Hutchins, better known online by his handle MalwareTech, the 23-year-old British security researcher who was credited with stopping the WannaCry outbreak was arrested by the FBI at the airport preparing to leave the country after attending DEF CON over his alleged involvement with the Kronos banking trojan.[64]

2018In March 2018, the DEF CON Voting Machine Hacking Village was awarded a Cybersecurity Excellence Award.[65] The award cites both the spurring of a national dialog around securing the US election system and the release of the nation's first cybersecurity election plan.
2020On May 8, 2020, the DEF CON in-person conference itself was cancelled[66] and virtualized due to COVID-19. DEF CON Safe Mode[67] was held August 6–9 online with a full roster of talks, villages, contests and events.

Entertainment references

Venues, dates, and attendance

Each conference venue and date has been extracted from the DEF CON archives for easy reference.[69]

Conference NameVenueDurationYearAttendance
DEF CON 33TBDAugust 7–102025N/A
DEF CON 32Las Vegas Convention Center, and The Sahara[70] August 8–112024N/A
DEF CON 31Caesars Forum, Flamingo, Harrah's Hotel, and Linq HotelAugust 10–132023~25,000
DEF CON 30Caesars Forum, Flamingo, Harrah's Hotel, and Linq HotelAugust 11–142022~25,000
DEF CON 29Paris Hotel and Bally's HotelAugust 5–82021~8,700
DEF CON Safe ModeVirtual eventAugust 6–92020N/A
DEF CON 28Planned Caesars Forum, Harrah's, The Linq, and FlamingoAugust 6–920200[71]
DEF CON 27Paris Hotel, Bally's Hotel, Planet Hollywood, and FlamingoAugust 8–112019~30,000
DEF CON China 1.0751 D-ParkMay 31 – June 22019Unknown
DEF CON 26Caesars Palace and FlamingoAugust 9–12201828,000[72]
DEF CON China [Beta]Kuntai Hotel (Beijing)May 11–132018Unknown
DEF CON 25Caesars PalaceJuly 27–30201725,000[73]
DEF CON 24Paris Hotel and Bally's HotelAugust 4–7201622,000[74]
DEF CON 23Paris Hotel and Bally's HotelAugust 6–9201516,000+[75]
DEF CON 22Rio Hotel & CasinoAugust 7–10201416,000[76]
DEF CON 21Rio Hotel & CasinoAugust 1–4201312,000
DEF CON 20Rio Hotel & CasinoJuly 26–292012Unknown
DEF CON 19Rio Hotel & CasinoAugust 4–72011Unknown
DEF CON 18Riviera Hotel & CasinoJuly 30 – August 12010Unknown
DEF CON 17Riviera Hotel & CasinoJuly 30 – August 22009Unknown
DEF CON 16Riviera Hotel & CasinoAugust 8–1020088,000[77]
DEF CON 15Riviera Hotel & CasinoAugust 3–52007Unknown
DEF CON 14Riviera Hotel & CasinoAugust 4–62006Unknown
DEF CON 13Alexis Park ResortJuly 29–312005Unknown
DEF CON 12Alexis Park ResortJuly 30 – August 12004Unknown
DEF CON 11Alexis Park ResortAugust 1–32003Unknown
DEF CON 10Alexis Park ResortAugust 2–42002Unknown
DEF CON 9Alexis Park ResortJuly 13–152001Unknown
DEF CON 8Alexis Park ResortJuly 28–302000Unknown
DEF CON 7Alexis Park ResortJuly 9–111999Unknown
DEF CON 6Plaza Hotel & CasinoJuly 31 – August 21998Unknown
DEF CON 5Aladdin Hotel & CasinoJuly 11–131997Unknown
DEF CON 4Monte Carlo Resort and CasinoJuly 26–281996Unknown
DEF CON 3Tropicana Resort & CasinoAugust 4–61995Unknown
DEF CON 2Sahara Hotel and CasinoJuly 22–241994~200
DEF CON 1Sands Hotel and CasinoJune 9–111993~100

See also

Further reading

External links

DEF CON

Multimedia

Notes and References

  1. Web site: Def Con 1 Archive. 2017-04-23.
  2. Web site: DefCon Beverage Cooling Contraption Contest. deviating.net.
  3. Web site: DEFCON 15 FAQ's . 9 Feb 2011 . Lots of people come to DEFCON and are doing their job; security professionals, federal agents, and the press..
  4. Web site: DEF CON® Hacking Conference – About. Tangent. The Dark. www.defcon.org. 2016-03-12.
  5. Web site: DEFCON about.
  6. . July 30, 2007 . The Story of DEFCON . 9 Feb 2011.
  7. Web site: Def Con 27 Transparency Report - DEF CON Forums. forum.defcon.org. 2019-08-17.
  8. Web site: Coronavirus claims new victim: 'DEF CON cancelled' joke cancelled after DEF CON China actually cancelled. The Register.
  9. Defcon is Cancelled. Wired. Newman. Lily Hay.
  10. Web site: DEF CON 28 Safe Mode FAQ.
  11. Web site: DEF CON 29 FAQ.
  12. Web site: Oberhaus . Daniel . September 18, 2018 . A History of Badgelife, Def Con's Unlikely Obsession with Artistic Circuit Boards . January 14, 2019 . Vice Motherboard.
  13. Web site: McAllister . Neil . August 12, 2015 . Is this the most puzzling DEF CON attendee badge yet on record? . January 14, 2019 . The Register UK.
  14. Web site: Molina . Brett . August 14, 2018 . 11-year-old hacks replica of Florida state website, changes election results . January 14, 2019 . USA Today.
  15. Web site: Home . Aerospace Village.
  16. Web site: Hacker Jeopardy for DEF CON 28 . 2024-01-29 . www.dfiu.tv.
  17. Web site: DEF CON Scavenger Hunt . 2024-01-29 . DEF CON Scavenger Hunt.
  18. Web site: DEF CON Crash and Compile Contest . 2024-01-29 . crashandcompile.org.
  19. Web site: Hackfortress . 2024-01-29 . hackfortress.net.
  20. Web site: Tangent . The Dark . DEF CON® Hacking Conference – Black Badge Hall of Fame . 2016-03-12 . www.defcon.org.
  21. Web site: 20 April 2017 . Innovations in Defense: Artificial Intelligence and the Challenge of Cybersecurity . americanhistory.si.edu.
  22. Web site: Mayhem Wins DARPA CGC . dead . https://web.archive.org/web/20190215222729/https://forallsecure.com/blog/2016/08/06/mayhem-wins-darpa-cgc/ . 2019-02-15 . 2017-04-24.
  23. Web site: Moss . Jeff . DEF CON Hacking Conference - Capture the Flag Archive .
  24. Web site: vulc@n of DDTek . 2023 . A history of Capture the Flag at DEF CON .
  25. Web site: A Brief History of CTF . 2023-12-20 . psifertex.github.io.
  26. Web site: Diutinus Defense Techonologies Corp. / DC17 . 2023-12-27 . ddtek.biz.
  27. Web site: Diutinus Defense Techonologies Corp. / DC18 . 2023-12-27 . ddtek.biz.
  28. Web site: Diutinus Defense Techonologies Corp. / Home . 2023-12-27 . ddtek.biz.
  29. Web site: DEF CON CTF 2018 . 2023-12-21 . OOO — DEF CON CTF . en-US.
  30. Web site: OOO — DEF CON CTF . 2023-12-21 . OOO — DEF CON CTF . en-US.
  31. Web site: OOO — DEF CON CTF . 2023-12-21 . OOO — DEF CON CTF . en-US.
  32. Web site: OOO — DEF CON CTF . 2023-12-21 . OOO — DEF CON CTF . en-US.
  33. Web site: Riley . Eller . 2004 . Capture the Flag Games .
  34. Web site: 2001-07-09 . Defcon 9 - Capture The Flag Contest Network .
  35. Web site: 4/23/ Immunix & Defcon: Defending Vulnerable Code From Intense Attack Crispin Cowan, Ph.D Seth Arnold, Steve Beattie, Chris Wright WireX and John. - ppt download . 2023-12-21 . slideplayer.com.
  36. Crispin . Cowan . May 2003 . Defcon Capture the Flag: defending vulnerable code from intense attack . DARPA Information Survivability Conference and Exposition . 2 . 2003.
  37. Web site: Ghettohackers . Defcon 10 - Capture the Flag (CTF) contest .
  38. Web site: The Ghetto Hackers . June 29, 2003 . Announcing Capture the Flag - Root Fu - Vegas 2003 @ DefCon 11 .
  39. Web site: 2011-05-14 . Diutinus Defense Techonologies Corp. / Home . 2023-12-21 . https://web.archive.org/web/20110514105932/http://ddtek.biz/about.html . 2011-05-14 .
  40. Web site: The FreeBSD Project . 2011-09-28 . Buffer overflow in handling of UNIX socket addresses .
  41. Web site: routardz . Defcon 19 CTF - CTF Inside . 2023-12-20.
  42. Web site: Cyber Grand Challenge (CGC) (Archived) . 2023-12-20 . www.darpa.mil.
  43. Web site: Unknown . cLEMENCy - Showing Mercy . 2023-12-20 . en.
  44. Web site: Official forums social group section for DEF CON groups . 2023-02-25 . DEF CON Forums . en.
  45. Web site: Exploit writers team up to target Cisco routers . . 31 July 2005 . 2004-07-31 . Lamos . Rob . 2012-07-28 . https://web.archive.org/web/20120728132402/http://www.securityfocus.com/news/11263 . dead.
  46. Web site: Cassel . David . Transcript: Michelle Madigan's run from Defcon . Tech.Blorge.com . 4 August 2007 . 2007-08-15 . dead . https://web.archive.org/web/20070908114514/http://tech.blorge.com/Structure%3A%20/2007/08/04/transcript-michelle-madigans-run-from-defcon/ . 2007-09-08 .
  47. Web site: Dateline Mole Allegedly at DefCon with Hidden Camera – Updated: Mole Caught on Tape . . 3 August 2007 . 2007-08-15 . Zetter . Kim . According to DefCon staff, Madigan had told someone she wanted to out an undercover federal agent at DefCon. That person in turn warned DefCon about Madigan's plans. Federal law enforcement agents from FBI, DoD, United States Postal Inspection Service and other agencies regularly attend DefCon to gather intelligence on the latest techniques of hackers..
  48. Web site: Lundin. Leigh . Dangerous Ideas . MBTA v DefCon 16 . Criminal Brief . 2010-10-07 . 2008-08-17 .
  49. Web site: Jeschke. Rebecca . MIT Students Gagged by Federal Court Judge . Press Room . . 2008-08-09 .
  50. Massachusetts Bay Transit Authority v. Zack Anderson, RJ Ryan, Alessandro Chiesa, and the Massachusetts Institute of Technology. United States District Court District of Massachusetts. http://cryptome.org/mbta-v-zack/01-complaint.pdf .
  51. Web site: Race to Zero . 2008-06-09 . https://web.archive.org/web/20111118024142/http://www.racetozero.net/concept.html/ . 2011-11-18 . dead . Contest concept.
  52. Web site: Antivirus Vendors Slam Defcon Virus Contest . Robert . McMillan . IDG News Service . April 2008 . 2024-03-19 . https://web.archive.org/web/20240319232009/https://www.computerworld.com/article/2535498/antivirus-vendors-slam-defcon-virus-contest.html . 2024-03-19.
  53. Malicious ATM Catches Hackers. Kim. Zetter. Wired . www.wired.com.
  54. Web site: Legal Threat Pushes Former HBGary Federal CEO Out Of DEFCON . August 10, 2011. Dennis . Fisher. Paul . Roberts. Business Security . dead . https://web.archive.org/web/20110810110924/http://threatpost.com/en_us/blogs/legal-threat-pushes-former-hbgary-federal-ceo-out-defcon-072711 . 2011-08-10 .
  55. Greenberg, Andy. "Watch Top U.S. Intelligence Officials Repeatedly Deny NSA Spying On Americans Over The Last Year (Videos)." Forbes. June 6, 2013. Retrieved on June 11, 2013. "Eight months later, Senator Ron Wyden quoted[...]"
  56. Wagenseil, Paul. "Hackers Don't Believe NSA Chief's Denial of Domestic Spying." (Archive) NBC News. August 1, 2012. Retrieved on June 13, 2013.
  57. Whitney, Lance. "Defcon to feds: 'We need some time apart'". CNET. July 11, 2013. Retrieved on July 12, 2013.
  58. [Violet Blue|Blue, Violet]
  59. Web site: ForAllSecure | Mayhem Security | Application Security. ForAllSecure.
  60. Web site: DEF CON Capture the Flag Final Scores. blog.legitbs.net.
  61. Web site: Hackers breach dozens of voting machines brought to conference . Joe Uchill . July 29, 2017 . The Hill . . 2 August 2017.
  62. Web site: DEF CON Hacking Warns Voting Machines Vulnerability, Oct 10 2017 C-SPAN.org. C-SPAN.org. en-US. 2017-12-08.
  63. Web site: O'Reilly Security Conference in NYC 2017 Defender Awards. conferences.oreilly.com. 2017-12-08.
  64. Web site: Briton who stopped WannaCry attack arrested over separate malware claims. Alex. Hern. Sam. Levin. August 4, 2017. The Guardian. 0261-3077. August 11, 2017. en-GB.
  65. 971036175514394624. VotingVillageDC. WOW! Congrats to the @defcon Team, recently honored for its innovative #VotingVillage concept & the continued debat… . 6 March 2018.
  66. Web site: DEF CON 28 in-person conference is CANCELLED - DEF CON Forums. forum.defcon.org. 2020-05-08.
  67. Web site: DEF CON Safe Mode archive site.
  68. Web site: Cyber Christ Meets Lady Luck . https://web.archive.org/web/20110718063846/http://www.winnschwartau.com/resources/CyberChrist+Meets+Lady+Luck+DC2.pdf . dead . 18 July 2011 . Winn Schwartau . 9 Feb 2011 .
  69. Web site: DEF CON® Hacking Conference – Show Archives. www.defcon.org. 2016-04-09.
  70. Web site: DEF CON 32 Was Canceled. We Un-Canceled it.. 2024-02-04.
  71. Newman . Lily Hay . Defcon Is Canceled . en-US . Wired . 2023-02-25 . 1059-1028.
  72. Web site: "DEF CON Transparency". August 2018. 2018-10-28.
  73. Web site: "Voting Machine Hacking Village". September 2017. 2018-05-17. 4.
  74. Web site: "Norton at DefCon". September 2019. 2019-09-15.
  75. Web site: "Gray Tier Technologies at DEFCON23". August 2015. 2019-09-15.
  76. Web site: "Black Hat and Defcon see record attendance — even without the government spooks". Richard Byrne Reilly. 2014-08-12. 2017-06-07.
  77. Web site: DEF CON 17 FAQ. 2018-07-07.