12 ms·
> conference attendee information is widely sold and shared as a matter of course Is that something people get warned when buying a ticket? edit: https://www.
by BuildTheRobots 8y ago
> conference attendee information is widely sold and shared as a matter of course
Is that something people get warned when buying a ticket?
edit: https://www.blackhat.com/us-18/registration-terms.html#privacy https://www.blackhat.com/us-18/registration-terms.html#priva... links to https://legal.us.ubm.com/privacy-policy/#Choices https://legal.us.ubm.com/privacy-policy/#Choices which someone smarter than me should interpret.
- adiusmus 8y agoHaving never been to a black hat conference, I’m surprised that such people would be so easily open to attack. Surely no one gives out their real email address or phone details at these events? I hope they don’t take critical hardware with them full of secrets to be happily liberated by someone more enthusiastic. They wouldn’t have “interesting” conversations in taxi/ubers, would they? Maybe there are less black hats at these conferences than the numbers suggest.
- ghaff 8y agoThere's this mystique around Black Hat but it's a 20,000 person security trade show. I imagine the vast bulk of attendees register with their work email and phone number just like they do for every other conference they attend.
- Kalium 8y agoBlack Hat is a large, highly corporate conference. You may be thinking of DEFCON?
- adiusmus 8y agoSort of. But mostly not knowing any better and just going off the name. As others have said it’s apparently full of white hats with expense accounts. Never been to either conf. I’m just a body with a pulse.
- Kalium 8y agoYou're right! It's an easy assumption to make running entirely off of the name of the conference. It's possible that some might suggest that Black Hat Briefings might be easily googled.
- lawnchair_larry 8y agoBlack Hat is entirely corporate white hat security professionals. It has never really attracted or appealed to black hats.
- tptacek 8y agoBlack Hat is literally Defcon for people with expense accounts. The best Defcon talks are usually accepted Black Hat talks. Defcon has become this enormous nerd Burning Man event, filling Caesars armpit-to-elbow with attendees trying to fight their way to various different "villages". But as it's become that, it has become less and less "black hat", and more and more just security's Comic Con. But in the days before the two conferences diverged, it certainly was not the case that BH was more "white hat" than Defcon; BH was a way to pay offensive security people out of the expense accounts of defensive security people. And these days I have sort of a hard time believing any "real" black hat takes Defcon seriously.
- pvg 8y agoThis is a great conference promo brochure in the making. BlackHat - the Burning Man and Comic Con of information security for serious professionals. Needs to be fleshed out with a bit of Renfaire, SXSW and Anthrocon, perhaps.
- tptacek 8y agoHey, that's Defcon! I have generally positive things to say about Black Hat (not least because it's where I go drink with people every year).
- lawnchair_larry 8y agoIt's been so long since there were prolific black hats, that you seem to have confused the definition of black hat and white hat with "offensive security" and "defensive security" ;) Everyone working in offensive security is still a white hat. That's a legitimate profession. Black hats hack things without permission. That used to be big at Defcon, but I don't think it was ever really a Black Hat thing.
- cschmidt 8y agoBlack Hat is a corporate "vendor" conference. You're probably thinking of DEFCON. At DEFCON, you don't register. You pay them in cash, and they give you a (complex, hard to fake) badge. You wear the badge and they let you into the conference area. They don't want to know who you are, which nicely avoids the problems Black Hat was having.
- munin 8y ago> and they give you a (complex, hard to fake) badge Unless they run out of those, then they just give you a paper card that you wear on some string or something.
- tptacek 8y agoBlack Hat is the most important industry vulnerability research conference of the year. It is also very corporate, and for the last several years it's had a large trade-show vendor "expo". It's a big-business UBM conference and certainly makes money from vendors, but don't get confused; that stuff is all bolted on to the gigantic multi-track speaker conference. There are, so far as I know, no pay-to-play Black Hat talks; all the listed briefings were picked by the review board.
- cschmidt 8y agoThat's good to know that there isn't pay-to-play (and http://www.blackhat.com/about.html http://www.blackhat.com/about.html confirms that). I assumed anything so corporate would be.
- tptacek 8y agoIt would be a fair assumption for something like RSA, and the vendor side of Black Hat looks a bit like RSA.
- billyhoffman 8y agoOn the plus side, if you have a talk that was accepted at Black Hat, you usually can just re-submit it to RSA. It's been several years, but I remember the RSA conf held in early Spring usually had it's CFP deadline something like a 6 months before. So if you were speaking at BH, then around July/August you had everything ready to present, which was perfect timing to submit for the following year's RSA.
- walrus01 8y agoThese days pretty much anyone going to a tech conference that allows any sort of salespeople to attend, or vendor booths, should expect a high degree of spam. Email I can deal with, when they get my direct cellular number and won't take no for an answer, that's when the vendor goes on the "never buy" list.
- ghaff 8y agoI never give out my cell for any sort of general form. That's what my office number is for. Which, not coincidentally, is a number I never answer.
- ghaff 8y agoIt's probably in some fine print somewhere. You can sometimes opt out of some sharing but exhibitors scan badges, you often get scanned when you attend breakouts, etc. Assume that any information you provide when registering for a typical conference (other than payment details obviously) will be widely shared.
- StudentStuff 8y agoIs there a reason not to change the programing of the RFID tag?
- ghaff 8y agoYou may not be able to get into sessions if your badge is "bad"? Also, if you're at a show, presumably you're interested in at least of the vendors so may want to be on their lists. I get a huge amount of email from vendors because I attend so many events but it's not really that big a deal to just unsubscribe from anything I genuinely have zero interest in.
- tptacek 8y agoI don't know if they warn you when you get a ticket, but I think it's impossible to go to a conference at Black Hat's scale and not understand what's happening. Black Hat is a trade show (much more so than it used to be) --- the research component is set off from the "expo", but the expo is huge. If you're staying in the conference hotel, I think there's even direct targeted swag delivered to rooms and stuff? (I might be confusing that with RSA). It's not great to just dump contact info --- that happened to RSA Security a couple years back and it was a story then --- but it's mostly an optics problem, I think.
- phyzome 8y agoo/ I can confirm that it is possible to go to big conferences and be unaware that my contact information is being flung about! For proof of existence, I provide myself. (And I'm someone who gives out custom email addresses for all signups anyway, so I'm not totally naïve.)
- tptacek 8y agoYou've been to a conference with a vendor expo and not realized the vendors were getting access to your attendee information?
- phyzome 8y agoIndeed. I suppose if I'd been to a bunch of them I would have ended up noticing the spam and putting two and two together, but that would be a bit late.
- raesene9 8y agoEven though it is not that surprising in that we know it happens, it is a little surprising that you pay a large amount of money to attend something then you , on top of that, are essentially having your data sold on. It's one thing to attend a "free" event that makes a return by monetizing attendee data, and another to have an expensive event that does it. One of the reasons I'm such a fan of BSides events which, generally, aren't expensive to attend and don't sell your data on. (disclaimer - I've organized a couple of BSides events)
- RobLach 8y agoI mean, Black Hat is one of UBM’s products. It’s not like some underground get together.