4 ms·
Having never been to a black hat conference, I’m surprised that such people would be so easily open to attack. Surely no one gives out their real email address
by adiusmus 8y ago
Having never been to a black hat conference, I’m surprised that such people would be so easily open to attack. Surely no one gives out their real email address or phone details at these events? I hope they don’t take critical hardware with them full of secrets to be happily liberated by someone more enthusiastic. They wouldn’t have “interesting” conversations in taxi/ubers, would they?
Maybe there are less black hats at these conferences than the numbers suggest.
- ghaff 8y agoThere's this mystique around Black Hat but it's a 20,000 person security trade show. I imagine the vast bulk of attendees register with their work email and phone number just like they do for every other conference they attend.
- Kalium 8y agoBlack Hat is a large, highly corporate conference. You may be thinking of DEFCON?
- adiusmus 8y agoSort of. But mostly not knowing any better and just going off the name. As others have said it’s apparently full of white hats with expense accounts. Never been to either conf. I’m just a body with a pulse.
- Kalium 8y agoYou're right! It's an easy assumption to make running entirely off of the name of the conference. It's possible that some might suggest that Black Hat Briefings might be easily googled.
- lawnchair_larry 8y agoBlack Hat is entirely corporate white hat security professionals. It has never really attracted or appealed to black hats.
- tptacek 8y agoBlack Hat is literally Defcon for people with expense accounts. The best Defcon talks are usually accepted Black Hat talks. Defcon has become this enormous nerd Burning Man event, filling Caesars armpit-to-elbow with attendees trying to fight their way to various different "villages". But as it's become that, it has become less and less "black hat", and more and more just security's Comic Con. But in the days before the two conferences diverged, it certainly was not the case that BH was more "white hat" than Defcon; BH was a way to pay offensive security people out of the expense accounts of defensive security people. And these days I have sort of a hard time believing any "real" black hat takes Defcon seriously.
- pvg 8y agoThis is a great conference promo brochure in the making. BlackHat - the Burning Man and Comic Con of information security for serious professionals. Needs to be fleshed out with a bit of Renfaire, SXSW and Anthrocon, perhaps.
- tptacek 8y agoHey, that's Defcon! I have generally positive things to say about Black Hat (not least because it's where I go drink with people every year).
- lawnchair_larry 8y agoIt's been so long since there were prolific black hats, that you seem to have confused the definition of black hat and white hat with "offensive security" and "defensive security" ;) Everyone working in offensive security is still a white hat. That's a legitimate profession. Black hats hack things without permission. That used to be big at Defcon, but I don't think it was ever really a Black Hat thing.
- tptacek 8y agoNo, I was clear on the distinction you're talking about when I wrote that comment. We're talking about the same black hats.
- cschmidt 8y agoBlack Hat is a corporate "vendor" conference. You're probably thinking of DEFCON. At DEFCON, you don't register. You pay them in cash, and they give you a (complex, hard to fake) badge. You wear the badge and they let you into the conference area. They don't want to know who you are, which nicely avoids the problems Black Hat was having.
- munin 8y ago> and they give you a (complex, hard to fake) badge Unless they run out of those, then they just give you a paper card that you wear on some string or something.
- tptacek 8y agoBlack Hat is the most important industry vulnerability research conference of the year. It is also very corporate, and for the last several years it's had a large trade-show vendor "expo". It's a big-business UBM conference and certainly makes money from vendors, but don't get confused; that stuff is all bolted on to the gigantic multi-track speaker conference. There are, so far as I know, no pay-to-play Black Hat talks; all the listed briefings were picked by the review board.
- cschmidt 8y agoThat's good to know that there isn't pay-to-play (and http://www.blackhat.com/about.html http://www.blackhat.com/about.html confirms that). I assumed anything so corporate would be.
- tptacek 8y agoIt would be a fair assumption for something like RSA, and the vendor side of Black Hat looks a bit like RSA.
- billyhoffman 8y agoOn the plus side, if you have a talk that was accepted at Black Hat, you usually can just re-submit it to RSA. It's been several years, but I remember the RSA conf held in early Spring usually had it's CFP deadline something like a 6 months before. So if you were speaking at BH, then around July/August you had everything ready to present, which was perfect timing to submit for the following year's RSA.