Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I can verify. I was the one dragged off. I wrote the firmware for the badge. All of it.


I think it’s so amazingly awesome that you just went outside and held an unofficial talk!

Read your blog/article about the badge project yesterday and it was such a good read, even for a not-much-of-a-hardware-guy like me.


Can you please explain the timeline of events here?


Edit: someone summarized it better: https://www.reddit.com/r/Defcon/comments/1eoe4u7/so_the_guy_...

Approx:

Entropic is engaged to make hw. I am asked (unofficially) to do sw.

Entropic works for free but does charge for parts and subcontracted stuff . Eventually defcon stops paying. Entropic is uninvited from badge talk. Their logo is ground out of plastic case. Their logo hidden in publicity photos of pcb.

Tempers are high. I implement the Easter egg. This is months ago cause thats how long one needs to pre-flash chips.

Time passed. Defcon still working on their game last moment. They had volunteers reflash badges cause they didn’t make the real pre flashing deadline. I forgot about the screen entirely more or less.

Day of con. I spend all day helping debug badge issues. Push updates. Help people. Even pushed an update from plane on way to con to fix some things.

Badge talk time. Half an hour before defcon tells me no talk for me cause someone found the Easter egg screen and they are pissed. I show up anyways since it was promised.

I get dragged off stage.

I hold talk outside answering questions.

Next steps: I have no contact with defcon. They never bothered to. Normally: who cares? I get to talk, people get to play with badges. Nobody cares.

But… I got kicked out, and… they have no license to my firmware they are distributing. Likely DMCA notice.


Man. I've never been to defcon, but it's been more than a passing curiosity ever since the first real announcement[0] crossed my BBS in '93.

And recently I've had a string of bad, unalterable, and irrevocably-permanent events occur in my life. And yet, I'm very pleased to say that your write-up on your experiences with the RP2350[1] presented a small but meaningfully-positive thing for me to look forward to.

Please be well -- and don't take any guff from these swine[2].

[0] https://media.defcon.org/DEF%20CON%201/DEF%20CON%201%20annou...

[1] https://dmitry.gr/?r=06.%20Thoughts&proj=11.%20RP2350

[2] https://www.barnesandnoble.com/w/fear-and-loathing-in-las-ve...


Defcon is a waste of time. Nerds pay walled from their friends.


When I was young (in the 90s) visiting defcon was a bucket list item.

In 2024 not sure I’d really see the point, there are other conferences I’d likely enjoy more and mostly that itch is scratched by YT.

The on I’d still like to visit in person is fosdem and given I’m in the UK that one would be much easier.


Is blackhat more serious and better?


Blackhat is even more of a pay-to-play corporate event.A few years ago, someone paid to do a talk on time traveling crypto and the CEO of trail of bits(iirc) stood up and called him out on the spot over the nonsense tech.

Defcon has a lot more grassroots stuff, but it's grown to a size that it cannot avoid the corporate BS anymore. It's probably one of the biggest and most disruptive conferences in Vegas, venues don't like having 1000s of hackers hanging around slot machines.


Maybe they should just move away from Vegas. I don't know why people choose that spot. Why not some place with better view?


A friend said "getting out of vegas would mean losing half the point of going to bh/defcon (which is getting your company to pay for you to go to vegas)"


The people that go there for that reason are probably not the ones you want there anyway.

And most corp trips are to black hat, not def con.

I've been offered a trip to black hat before and asked if I could go to def con as well but no. I was thinking of just staying longer on my own dime but we got a travel ban for cost cutting reasons so the whole thing never happened. I wasn't really interested in black hat anyway so I didn't care, I hate corporate PR.

But Vegas to me is a detractor. I hate gambling. I'd love it if it were in NYC or something. Much easier from Europe too.


> And most corp trips are to black hat, not def con.

not true in the vulnerability research space.

Actual engineers are sent to defcon because blackhat talks are advertisements, not educational presentations.


Oh that's good to hear.

I worked in a "blue team" and we would only get travel approvals for black hat. Even though I've never been as I didn't want to and I was hesitant to visit the US. Black Hat doesn't interest me precisely for the reason you mentioned. I don't want sales pitches, I want unrestricted flow of technical information without marketing motives.


You’re not required to gamble. I bet I’ve spent a grand total of $20 on slots over the years of attending Def Con. It’s not my thing.


Oh I know but the whole city is about that. It just puts me off.


I get it. You’ve gotta walk past it to get to anything.


Imagine wanting to go to Las Vegas in the summer. Dumb as bricks.


“Do you want to go to a sweltering hot city filled with casinos situated in the middle of a desert, in the middle of summer?”

Any one of those things sounds unpleasant to me, let alone all 3 at once.


Oh please, it's not like nerds go outside anyway ;)


I appreciate the sarcasm because you are right, we have Toor Camp, Chaos Camp, EMF Camp, and others. I think we could use more time outside. Cheers!


It's relatively cheap to get there from most places, and they have the space and facilities for conferences of this size.


Shmoocon had it right providing Shmoo balls.


Chaos Communication Congress is the one worth going to.


True, especially because it's so much easier here in Europe.

The only problem is it's in an extremely expensive period of the year for hotel stays. For that reason I've never actually been.


Already excited for the next Chaos Camp!


And next year is WHY2025 <3


Perhaps I'll see you there! I moved to NL a year ago and have been trying to find my circle.


EMF Camp 2026 too!


Why’d they be pissed about people donating money to the people they didn’t want to pay :/

I just don’t see how they lose anything there (or rather, don’t see how they lose anything there that they lose a hundred times more of by their actual actions, namely reputation).


Every niche convention either stops existing or transitions into a business that slowly gets rid of all the fun stuff that created it in the first place.


The CCC congress is still going strong, but it wouldn't work without the many volunteers and non-profit CCC behind it.


There is not just the big end of year congress, but also lots of smaller events organised and run by regional CCC (like) groups in Europe e.g. MRMCD, EasterHegg, the Dutch camps changing the name every time (next one is WHY2025).


> Every niche convention either stops existing or transitions into a business that slowly gets rid of all the fun stuff that created it in the first place.

It parallels what Ivan Illich said about revolutions, namely that if a revolution survives it will turn into a system that stifles the same freedoms it supported.

Aka, either you die the hero, or see yourself become the corporate stooge/villain.


Hackers themselves became corpos- or worse work for the intelligence agencies.


Not really. The Dutch hacker camps have been pretty constant (save for 2021 for Covid reasons). Run by mostly volunteers yes but basically every participant is a volunteer. It's part of the fun.

They've not really shrunk or significantly grown and are really opposed to corporate and government interests (as Fox-IT found out in 2013)


The British are doing good stuff as well with EMF.


Absolutely. They're a bit more maker than hacker focused but for me that's a good thing.

I just don't really like going to the UK anymore since Brexit. It just puts me off because the main driver of it was xenophobia. I've avoided it, I have not been there at all since Brexit. I probably won't ever go there again unless there's a serious change. Of course none of this is on the EMF community which is great, I've met many of them at other things.

As for the hacker camps I only really go to the Netherlands ones. The Congress is too expensive for me with the hotels around Christmas and with my lack of car it's hard to go camping in Germany so I've never been to the chaos camp either. Within Holland it's been easier because they've recently been at locations near me.


Cop mentality.


Commercial copyright infringement has a per instance statutory minimum.

Demand the minimum for every badge distributed — as even if you later provided licenses to holders, DC had no license when distributing the copies as merchandise at their for-pay event.


Do this, but absolutely get an attorney. Careful wording is required to avoid the crime of blackmail/extortion.


Why do you think they don't have a license from Entropic in the contract they both agreed to? Unless they are utterly incompetent, their contract with Entropic covered this and if Enrtopic delivered firmware that they don't have rights to, that's on them, not on Def Con. Anything that comes to Def Con just results in a lawsuit against Entropic. Additionally, he apparently wrote the code on the plane prior to his arrival and then worked to get it on all the badges. That's going to make it pretty hard to argue that they don't have permission to distribute the badges with this code on them.


There is no firmware or software mentioned in any signed contracts actually. :popcorn:


Statutory damages are per work infringed, not per infringing copy.


You left out the part where the "Goons" physically touched you, and forcibly removed you from a location against your will. The "Goons" have no authority to carry out such an act. And there's video footage. Congratulations on winning the lawsuit!


"and forcibly removed you from a location against your will"

Not saying they were morally or ethically right, or smart to do this at all - but legally there usually is a right to remove a unwanted person from your stage with the help of your own security.


Yeah, pretty sure if you’re asked to leave an event and you refuse, they can have you escorted out even if you dig in your heels.


... but can you tell me who is legally allowed to physically touch you in that escorting process?


Under german law, it would be anyone officially acting as security on that property. (It does not have to be a professional security, it can be anyone from staff filling in that role).

The police does not want to be called, for every bouncer action.

It can get into a grey area, if violence will happen, the security may not simply beat someone out - but grabbing and forcefully moving or carrying out is legal. But if there is serious resistance and the security unable to handle it in a nonescalating way, then they would need to call the police. But usually, the bouncers would just get brutal, then. Attacking security gives them some freedom to act.

If other people are endangered by someone, very different scenario, anyone can (and must if possible) stop violence.

Source: short stunt as a professional security


In Canada, in our Criminal Code,if you order someone to leave the inside of your home, and they refuse / do not?

They have committed assault against you.

This serves two purposes. The first is, a crime has been committed. The second is, you may now defend yourself.

I'm sure there is something similar in common law for other buildings. EG control of a space.

(I know nothing of this incident, just speaking generically.)


They do have the authority to do that. They ask you to leave. If you say no then you're trespassing and can be physically removed.

How do you think bouncers work?


OK, everything aside, thank you for your absolutely amazing work and the inspiring writing you do about it!

Reading about rePalm has changed my definition of what monumental effort looks like.

(You should absolutely add that you managed to get PalmOS running on the badges in question!)


Thank you for the clarification, Defcon has some explaining to do given they make good money on the con. Things have definitely changed.


Ah, defcon drama! Old ones used to be much better anyway.


When they stopped having first time presenters to do a shot of vodka before their talks I stopped caring. That was the end of real defcon.


I don't know why people think this, you're not the first person I've heard it from either.

First, I literally saw them do shots during a talk yesterday for some first-time presenters. Secondly that WASN'T the "old defcon" either! Drinking is a relatively new tradition in the history of the con. I've spoken twice. Once at DC 17 (no shot offered) and once at DC 23 (shots were offered). There's video proof:

No drinking, DC 17: https://www.youtube.com/watch?v=okPWY0FeUoU Asked to drink, opted for a coin instead (we were asked beforehand): https://youtu.be/6dmvtbrM6hs?feature=shared&t=1153


Last years I “had to” do a shot of Malört before stepping up to the podium.

(“Had to” means a friend offered me one, laughed, and said “aw, c’mon”. I could’ve easily said no.)


The ninja badges even had games you could play where you fight other users if I recall correctly. (Mid 2000’s?)


Wild, but not surprising. Heard a lot of bad stuff from the village heads some years ago already about DC organization.


Sounds like a fiasco. Have to wonder why parts and subcontractors aren't getting paid


If that’s true, crucify them for piracy. Why would DMCA apply here?


They are Illegally distributing copies of my firmware on their badges


DMCA is probably irrelevant.

This is textbook copyright infringement. $150k statutory damages plus, at the court's discretion, legal costs and fees. And that is just the result of civil action. You could probably find a prosecutor who would love pursue criminal action against the conference to appear strong on cybersecurity.

There is a reason why even large corporations, which often play chicken with lesser laws, are extremely careful about copyright infringement. The law has real teeth if the infringer has significant wealth.

https://www.copyright.gov/title17/92chap5.html#504


If they don't have a licence to distribute your software, it's plain copyright infringement. The same as selling photocopies of a book.

The DMCA criminalises breaking DRM, or providing tools to do so, such as distributing a tool to remove the DRM from an e-book.


The Digital Millennium Copyright Act also does have provisions related to copyright infringement, not just circumvention devices.


This link is directly to the comment, I believe.

https://www.reddit.com/r/Defcon/comments/1eoe4u7/comment/lhe...


Time to make your own Defcon.

With blackjack. And...


Which black hat, and webhooks!


With black hat*


....I mean, you're already in Vegas, so...


Missed a couple crucial details

>I show up anyways since it was promised.

-you get asked to leave the stage

-you refused to leave the stage

-you told them they'd have to drag you off stage to get you to leave

>I get dragged off stage.


One part of me wants you to DMCA the living daylight out of them. The other part is currently seeding torrents and thinks copyright is kinda dumb. Anyway, shitty thing to do by the defcon people.


I have been giving out licenses to the firmware to anybody who asks in the unofficial badge hacking discord. :) also my signature on the badge acts as a nontransferable license to the firmware in source and binary. i signed maybe a thousand today at my unofficial talk outside after i was dragged out.


did they end up paying Entropic in the months that passed ?


No. But beyond money, the credit hurts more. Having your company name scratches out of plastic molds is … oof.


Sounds like there's more going on though. They must have had a reason for not paying? Especially considering the apparent anger with which they removed all references to them. I mean, if they simply ran out of money and couldn't pay they wouldn't be so angry because it was really their own fault.

I'd love to hear their sides of that story. (Both Def Con and Entropic). I'm curious now.

I'm sorry you got roped into this conflict too though. I have great respect for your work.


this is some pretty ugly stuff.

If you are in contact with any of the Entropic folks, maybe point them to this or the r/ thread so that they can provide more context.


Can I buy a badge or similar hardware after the con?


Yes, actually, if you know someone there they were selling extras:

https://defcon.org/html/links/dc-news.html


No. It's for participants.

Though I'm sure you can find them on eBay.



Oof, Defcon organizers even SWATted him?


It sounds like they called the police, that is not swatting. Swatting is a specific tactic where you abuse the minimal training and disposition to violence of US police forces to attempt to murder people by reporting that they’re armed and/or threatening violence.

Claiming the calling the police on someone is swatting, even though US police routinely execute people unprovoked attacks, is not swatting. The difference is the intent - the intent of swatting is terrorism and murder.


Come on. Calling the cops is nothing like Sweating.


It's SWATting when you try to pit the cops against innocent people.


No, it's not. Let's not dillute the term. SWATing someone is calling in a fake situation on a person that earns them a visit, specifically, from SWAT. Hostage situation, bomb threat, etc. are the usual means of doing so.

Calling the police is not SWATing someone.


I don't think so.

When people get SWATed, usually a fake call is made, were the police are told that a murder was already committed by the caller and that we will kill everyone on sight. Thus the police expect real danger, brings the big guns and their trigger happy attitude, kick the door in and are more likely to kill the victim.

It's not SWATing if the police come to handle a disturbance. The SWAT team need to be deployed for a SWATing.

Anyone could have called the cops too. A gathering of 100 people can make people nervous. But I wouldn't be surprised if Defcon called them too.


How isn't it? SWATting is nothing more then calling the police and sending them out to somewhere you known nothing is going on as an attack dog. This seems extremely similar to what has happened here.


> SWATting is nothing more then calling the police and sending them out to somewhere you known nothing is going on as an attack dog

Bullshit.

Swatting is:

> the action or practice of making a prank call to emergency services in an attempt to bring about the dispatch of a large number of armed police officers to a particular address.

The cops response for like, someone disturbing the peace or someone playing loud music in the middle of the night, is nothing like when the SWAT team comes with automatic weapon, full body armor and flash bangs, expecting to be shot at, as promised by the phrank call.


I would definitely say calling the police on someone you know is doing nothing wrong could be considered " a prank call to emergency services in an attempt to bring about the dispatch of a large number of armed police officers to a particular address.". I definitely don't think it can be waved away with bullshit. People in the US are routinely shot for no reason at all. Any contact with police should be taken extremely seriously.


I was at this talk, someone (you I guess) left at the beginning of this talk. To the audience it was not clear what happened,


Nice work keeping the easter egg spirit alive. How would one trigger the easter egg?


FN button to open menu

select "ABOUT" and press "A" to enter about screen

Press "SELECT" button there despite that not being listed as a valid input.


Yeah, after some more digging, it does appear to be you.

I do wish I had more context from the video, but at this point, it's getting hard to imagine any good reason for Defcon to do what they did. Assuming that you weren't threatening someone in the audience or something like that. Doubtful, from the way you've been talking.

Anyway, it looks like good stuff. Wish I had some Game Boy games to try it.


I threatened nobody.


Yeah, I hope it was clear that I don't think you did that.


Why is it up to you to determine who is telling the truth? Why do you need to dig or investigate?

Anyways, just seemed odd.


I would counter that by asking why would any of us not want to dig or investigate claims and assertions made in 2024? It’s hugely important to approach life with a critical mindset these days, and something we should all be doing.


I don't think that's how he meant it, but rather that we all need to read/watch and evaluate credibility on our own, because this is the internet.


You always trust what someone on the internet tells you?


I’m sorry to hear this happened to you.

One cannot lay even a finger on another person, ever, let alone jostle someone just because they don’t like what they are saying.

It doesn’t matter if they are “security”. It’s assault and battery just the same as if I shove grandma out the way to get to the bus!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: